From 2d3842101a6bbe09225fd5943a6cb4389fc14485 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Tue, 22 Sep 2026 12:07:42 +0530 Subject: [PATCH 01/24] - Add files for installing Mongo DB using ArgoCD --- cluster-applications/025-mongodb-ce/README.md | 92 +++++++ .../templates/01-namespace.yaml | 11 + .../templates/02-operator-group.yaml | 15 ++ .../templates/03-subscription.yaml | 18 ++ .../templates/04-admin-secret.yaml | 15 ++ .../templates/05-mongodb-community-cr.yaml | 51 ++++ .../templates/06-postsync-update-sm_Job.yaml | 237 ++++++++++++++++++ .../025-mongodb-ce/values.yaml | 36 +++ .../templates/025-mongodb-ce-app.yaml | 81 ++++++ .../ibm-mas-cluster-root/values.yaml | 2 + 10 files changed, 558 insertions(+) create mode 100644 cluster-applications/025-mongodb-ce/README.md create mode 100644 cluster-applications/025-mongodb-ce/templates/01-namespace.yaml create mode 100644 cluster-applications/025-mongodb-ce/templates/02-operator-group.yaml create mode 100644 cluster-applications/025-mongodb-ce/templates/03-subscription.yaml create mode 100644 cluster-applications/025-mongodb-ce/templates/04-admin-secret.yaml create mode 100644 cluster-applications/025-mongodb-ce/templates/05-mongodb-community-cr.yaml create mode 100644 cluster-applications/025-mongodb-ce/templates/06-postsync-update-sm_Job.yaml create mode 100644 cluster-applications/025-mongodb-ce/values.yaml create mode 100644 root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml diff --git a/cluster-applications/025-mongodb-ce/README.md b/cluster-applications/025-mongodb-ce/README.md new file mode 100644 index 000000000..aaa3a4623 --- /dev/null +++ b/cluster-applications/025-mongodb-ce/README.md @@ -0,0 +1,92 @@ +# MongoDB Community Operator and Instance Chart +============================================= +This chart installs the MongoDB Community Operator, deploys a MongoDB Community replica set, and automatically registers MongoDB connection details and credentials into AWS Secrets Manager so that SLS (and MAS) can consume them. + + + +## Overview + +This chart provisions a MongoDB Community Operator and a 3-node MongoDB Community replica set within the specified namespace (default: `mongoce`). It creates the necessary operator group, subscriptions, admin credential secrets, and stateful replica set. Additionally, it executes a post-sync job that automatically formats and pushes connection details, credentials, and TLS certificates to AWS Secrets Manager (`${ACCOUNT_ID}/${CLUSTER_ID}/mongo`) for seamless integration with IBM SLS and MAS. + +## Prerequisites + +- OpenShift Cluster 4.12+ +- `community-operators` CatalogSource enabled in `openshift-marketplace` +- ArgoCD / OpenShift GitOps with Cluster Admin privileges +- AWS Secrets Manager access credentials configured in the cluster environment + +## Resources Created + +| Resource Type | Resource Name | Namespace | Condition | Installed By | +|---|---|---|---|---| +| `Namespace` | `mongoce` | - | Always | `cluster_admin_role` | +| `OperatorGroup` | `mongodb-operator-group` | `mongoce` | Always | `cluster_admin_role` | +| `Subscription` | `mongodb-kubernetes-operator` | `mongoce` | Always | `cluster_admin_role` | +| `Secret` | `admin-user-credentials` | `mongoce` | Always | `cluster_admin_role` | +| `MongoDBCommunity` | `mas-mongo-ce` | `mongoce` | Always | `cluster_admin_role` | +| `Secret` | `mongo-aws-creds` | `mongoce` | When `run_sync_hooks` and `cluster_admin_role` | `cluster_admin_role` | +| `Job` | `postsync-mongo-update-sm-job-*` | `mongoce` | When `run_sync_hooks` and `cluster_admin_role` | `cluster_admin_role` | + +## Configuration + +This chart accepts the following configuration values in the ArgoCD Application values: + +```yaml +mongodb_ce: + install: "true" + channel: "v0.7" + install_plan: "Automatic" + source: "community-operators" + source_namespace: "openshift-marketplace" + namespace: "mongoce" + instance_name: "mas-mongo-ce" + version: "7.0.5" + members: 3 + admin_password: "" + storage_size: "10Gi" + storage_class: "" +``` + +## Base Cluster Values + +This chart inherits common cluster configuration values. For complete documentation of all base cluster values including optional fields like `notifications`, `custom_labels`, `devops`, and `cli_image_repo`, see the [Cluster Base Values Reference](../../docs/reference/cluster-base-values.md). + +## Examples + +### Basic MongoDB Community Deployment + +```yaml +merge-key: "my-account/my-cluster" +mongodb_ce: + install: "true" + members: 3 + version: "7.0.5" + storage_size: "10Gi" + admin_password: "" +``` + +### Secrets Manager Integration + +Upon successful deployment of the MongoDB replica set, the post-sync Job creates / updates the cluster secret at: +`${ACCOUNT_ID}/${CLUSTER_ID}/mongo` + +With the following JSON payload: +```json +{ + "docdb_host": "mas-mongo-ce-0.mas-mongo-ce-svc.mongoce.svc.cluster.local", + "docdb_port": "27017", + "username": "admin", + "password": "", + "info": "config:\n hosts:\n - host: mas-mongo-ce-0.mas-mongo-ce-svc.mongoce.svc.cluster.local\n port: 27017\n - host: mas-mongo-ce-1.mas-mongo-ce-svc.mongoce.svc.cluster.local\n port: 27017\n - host: mas-mongo-ce-2.mas-mongo-ce-svc.mongoce.svc.cluster.local\n port: 27017\n configDb: admin\n authMechanism: DEFAULT\n" +} +``` + +## Troubleshooting + +- **MongoDBCommunity CR not ready**: Verify that the operator pod in `mongoce` is running without OOM or storage binding errors. +- **Post-sync Job failure**: Check the Job pod logs in `mongoce` namespace to verify AWS credentials and secret permissions. + +## Related Documentation + +- [Cluster Base Values Reference](../../docs/reference/cluster-base-values.md) +- [IBM SLS Application Documentation](../../sls-applications/100-ibm-sls/README.md) diff --git a/cluster-applications/025-mongodb-ce/templates/01-namespace.yaml b/cluster-applications/025-mongodb-ce/templates/01-namespace.yaml new file mode 100644 index 000000000..b13e84c82 --- /dev/null +++ b/cluster-applications/025-mongodb-ce/templates/01-namespace.yaml @@ -0,0 +1,11 @@ +--- +apiVersion: v1 +kind: Namespace +metadata: + name: {{ .Values.mongodb_namespace | default "mongoce" }} + annotations: + argocd.argoproj.io/sync-wave: "021" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} diff --git a/cluster-applications/025-mongodb-ce/templates/02-operator-group.yaml b/cluster-applications/025-mongodb-ce/templates/02-operator-group.yaml new file mode 100644 index 000000000..c09c4d23a --- /dev/null +++ b/cluster-applications/025-mongodb-ce/templates/02-operator-group.yaml @@ -0,0 +1,15 @@ +--- +apiVersion: operators.coreos.com/v1 +kind: OperatorGroup +metadata: + name: mongodb-operator-group + namespace: {{ .Values.mongodb_namespace | default "mongoce" }} + annotations: + argocd.argoproj.io/sync-wave: "022" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +spec: + targetNamespaces: + - {{ .Values.mongodb_namespace | default "mongoce" }} diff --git a/cluster-applications/025-mongodb-ce/templates/03-subscription.yaml b/cluster-applications/025-mongodb-ce/templates/03-subscription.yaml new file mode 100644 index 000000000..63922eee7 --- /dev/null +++ b/cluster-applications/025-mongodb-ce/templates/03-subscription.yaml @@ -0,0 +1,18 @@ +--- +apiVersion: operators.coreos.com/v1alpha1 +kind: Subscription +metadata: + name: mongodb-kubernetes-operator + namespace: {{ .Values.mongodb_namespace | default "mongoce" }} + annotations: + argocd.argoproj.io/sync-wave: "023" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +spec: + channel: "{{ .Values.mongodb_operator_channel | default "v0.7" }}" + installPlanApproval: {{ .Values.mongodb_operator_install_plan | default "Automatic" | quote }} + name: mongodb-kubernetes-operator + source: {{ .Values.mongodb_operator_source | default "community-operators" }} + sourceNamespace: {{ .Values.mongodb_operator_source_namespace | default "openshift-marketplace" }} diff --git a/cluster-applications/025-mongodb-ce/templates/04-admin-secret.yaml b/cluster-applications/025-mongodb-ce/templates/04-admin-secret.yaml new file mode 100644 index 000000000..dd00c8816 --- /dev/null +++ b/cluster-applications/025-mongodb-ce/templates/04-admin-secret.yaml @@ -0,0 +1,15 @@ +--- +apiVersion: v1 +kind: Secret +metadata: + name: admin-user-credentials + namespace: {{ .Values.mongodb_namespace | default "mongoce" }} + annotations: + argocd.argoproj.io/sync-wave: "024" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +type: Opaque +stringData: + password: "{{ .Values.admin_password }}" diff --git a/cluster-applications/025-mongodb-ce/templates/05-mongodb-community-cr.yaml b/cluster-applications/025-mongodb-ce/templates/05-mongodb-community-cr.yaml new file mode 100644 index 000000000..71a22cf7b --- /dev/null +++ b/cluster-applications/025-mongodb-ce/templates/05-mongodb-community-cr.yaml @@ -0,0 +1,51 @@ +--- +apiVersion: mongodbcommunity.mongodb.com/v1 +kind: MongoDBCommunity +metadata: + name: {{ .Values.mongodb_instance_name | default "mas-mongo-ce" }} + namespace: {{ .Values.mongodb_namespace | default "mongoce" }} + annotations: + argocd.argoproj.io/sync-wave: "025" + argocd.argoproj.io/sync-options: SkipDryRunOnMissingResource=true +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +spec: + members: {{ .Values.mongodb_members | default 3 }} + type: ReplicaSet + version: {{ .Values.mongodb_version | default "7.0.5" | quote }} + security: + authentication: + modes: + - SCRAM + users: + - name: admin + db: admin + passwordSecretRef: + name: admin-user-credentials + roles: + - name: root + db: admin + scramCredentialsSecretName: admin-user-credentials + statefulSet: + spec: + template: + spec: + containers: + - name: mongod + resources: +{{ .Values.resources | toYaml | indent 16 }} +{{- if .Values.storage_size }} + volumeClaimTemplates: + - metadata: + name: data-volume + spec: + accessModes: [ "ReadWriteOnce" ] + {{- if .Values.storage_class }} + storageClassName: "{{ .Values.storage_class }}" + {{- end }} + resources: + requests: + storage: "{{ .Values.storage_size }}" +{{- end }} diff --git a/cluster-applications/025-mongodb-ce/templates/06-postsync-update-sm_Job.yaml b/cluster-applications/025-mongodb-ce/templates/06-postsync-update-sm_Job.yaml new file mode 100644 index 000000000..1a1ae9bb4 --- /dev/null +++ b/cluster-applications/025-mongodb-ce/templates/06-postsync-update-sm_Job.yaml @@ -0,0 +1,237 @@ +{{- if and .Values.run_sync_hooks .Values.cluster_admin_role }} + +{{- /* +Meaningful prefix for the job resource name. Must be under 52 chars in length. +*/}} +{{- $_job_name_prefix := "postsync-mongo-update-sm-job" }} + +{{- /* +CLI image digest +*/}} +{{- $_cli_image_digest := "sha256:1dc8665fddb9546b84290b0615fc7c7017e19516082b35541d41b8ea82df347b" }} + +{{- $_job_config_values := omit .Values "junitreporter" }} +{{- $_job_version := "v1" }} +{{- $_job_hash := print ($_job_config_values | toYaml) $_cli_image_digest $_job_version | adler32sum }} +{{- $_job_name := join "-" (list $_job_name_prefix $_job_hash )}} +{{- $_job_cleanup_group := cat $_job_name_prefix | sha1sum }} + +{{ $ns := .Values.mongodb_namespace | default "mongoce" }} +{{ $aws_secret := "mongo-aws-creds" }} +{{ $role_name := "postsync-mongo-update-sm-r" }} +{{ $sa_name := "postsync-mongo-update-sm-sa" }} +{{ $rb_name := "postsync-mongo-update-sm-rb" }} + +--- +kind: Secret +apiVersion: v1 +metadata: + name: {{ $aws_secret }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "026" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +data: + aws_access_key_id: {{ .Values.sm_aws_access_key_id | default "" | b64enc }} + aws_secret_access_key: {{ .Values.sm_aws_secret_access_key | default "" | b64enc }} +type: Opaque + +--- +kind: ServiceAccount +apiVersion: v1 +metadata: + name: {{ $sa_name }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "026" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} + +--- +kind: ClusterRole +apiVersion: rbac.authorization.k8s.io/v1 +metadata: + name: {{ $role_name }} + annotations: + argocd.argoproj.io/sync-wave: "026" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +rules: + - verbs: + - get + - list + - watch + apiGroups: + - "" + resources: + - secrets + - services + - pods + - verbs: + - get + - list + - watch + apiGroups: + - mongodbcommunity.mongodb.com + resources: + - mongodbcommunity + +--- +kind: ClusterRoleBinding +apiVersion: rbac.authorization.k8s.io/v1 +metadata: + name: {{ $rb_name }} + annotations: + argocd.argoproj.io/sync-wave: "027" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +subjects: + - kind: ServiceAccount + name: {{ $sa_name }} + namespace: {{ $ns }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: {{ $role_name }} + +--- +apiVersion: batch/v1 +kind: Job +metadata: + name: {{ $_job_name }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "028" + labels: + mas.ibm.com/job-cleanup-group: {{ $_job_cleanup_group }} +{{- if .Values.custom_labels }} +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +spec: + template: +{{- if .Values.custom_labels }} + metadata: + labels: +{{ .Values.custom_labels | toYaml | indent 8 }} +{{- end }} + spec: + serviceAccountName: {{ $sa_name }} + restartPolicy: Never + volumes: + - name: aws + secret: + secretName: {{ $aws_secret }} + defaultMode: 420 + optional: false + containers: + - name: run + image: {{ .Values.cli_image_repo | default "quay.io/ibmmas/cli" }}@{{ $_cli_image_digest }} + imagePullPolicy: IfNotPresent + resources: + limits: + cpu: 200m + memory: 512Mi + requests: + cpu: 10m + memory: 64Mi + volumeMounts: + - name: aws + mountPath: /etc/mas/creds/aws + env: + - name: ACCOUNT_ID + value: "{{ .Values.account_id }}" + - name: REGION_ID + value: "{{ .Values.region_id }}" + - name: CLUSTER_ID + value: "{{ .Values.cluster_id }}" + - name: MONGO_NAMESPACE + value: "{{ $ns }}" + - name: MONGO_INSTANCE_NAME + value: "{{ .Values.mongodb_instance_name | default "mas-mongo-ce" }}" + - name: MONGO_ADMIN_PASSWORD + value: "{{ .Values.admin_password }}" + - name: MONGO_MEMBERS + value: "{{ .Values.mongodb_members | default 3 }}" + command: + - /bin/bash + - -c + - > + set -e; + source /mascli/functions/gitops_utils; + SM_AWS_ACCESS_KEY_ID=$(cat /etc/mas/creds/aws/aws_access_key_id); + SM_AWS_SECRET_ACCESS_KEY=$(cat /etc/mas/creds/aws/aws_secret_access_key); + export SM_AWS_REGION=${REGION_ID}; + sm_login; + echo "Waiting for MongoDBCommunity ${MONGO_INSTANCE_NAME} in ${MONGO_NAMESPACE}"; + for (( c=1; c<=30; c++ )); do + echo "... check attempt ${c} of 30"; + PHASE=$(oc get mongodbcommunity "${MONGO_INSTANCE_NAME}" -n "${MONGO_NAMESPACE}" -o=jsonpath='{.status.phase}' 2>/dev/null || true); + echo "Current Phase: ${PHASE}"; + if [[ "${PHASE}" == "Running" ]]; then + echo "MongoDBCommunity instance is Running!"; + break; + fi; + sleep 20; + done; + PRIMARY_HOST="${MONGO_INSTANCE_NAME}-0.${MONGO_INSTANCE_NAME}-svc.${MONGO_NAMESPACE}.svc.cluster.local"; + CA_CERT=""; + CA_SECRET_NAME="${MONGO_INSTANCE_NAME}-ca"; + if oc get secret "${CA_SECRET_NAME}" -n "${MONGO_NAMESPACE}" >/dev/null 2>&1; then + CA_CERT=$(oc get secret "${CA_SECRET_NAME}" -n "${MONGO_NAMESPACE}" -o=jsonpath='{.data.ca\.crt}' | base64 -d 2>/dev/null || true); + fi; + python3 -c " + import os, json + account = os.environ.get('ACCOUNT_ID') + cluster = os.environ.get('CLUSTER_ID') + instance_name = os.environ.get('MONGO_INSTANCE_NAME') + namespace = os.environ.get('MONGO_NAMESPACE') + members = int(os.environ.get('MONGO_MEMBERS', '3')) + password = os.environ.get('MONGO_ADMIN_PASSWORD') + ca_cert = os.environ.get('CA_CERT', '') + primary_host = f'{instance_name}-0.{instance_name}-svc.{namespace}.svc.cluster.local' + info_lines = ['config:', ' hosts:'] + for i in range(members): + info_lines.append(f' - host: {instance_name}-{i}.{instance_name}-svc.{namespace}.svc.cluster.local') + info_lines.append(' port: 27017') + info_lines.append(' configDb: admin') + info_lines.append(' authMechanism: DEFAULT') + if ca_cert: + info_lines.append('certificates:') + info_lines.append(' - alias: ca') + info_lines.append(' crt: |') + for line in ca_cert.strip().split('\n'): + info_lines.append(f' {line}') + info_str = '\n'.join(info_lines) + '\n' + secret_name = f'{account}/{cluster}/mongo' + payload = { + 'docdb_host': primary_host, + 'docdb_port': '27017', + 'username': 'admin', + 'password': password, + 'info': info_str + } + tags = json.dumps([ + {'Key': 'source', 'Value': 'postsync-mongo-update-sm-job'}, + {'Key': 'account', 'Value': account}, + {'Key': 'cluster', 'Value': cluster} + ]) + with open('/tmp/secret_payload.json', 'w') as f: + f.write(json.dumps(payload)) + with open('/tmp/secret_tags.json', 'w') as f: + f.write(tags) + "; + SECRET_NAME_MONGO="${ACCOUNT_ID}/${CLUSTER_ID}/mongo"; + echo "Updating AWS Secret: ${SECRET_NAME_MONGO}"; + sm_update_secret "${SECRET_NAME_MONGO}" "$(cat /tmp/secret_payload.json)" "$(cat /tmp/secret_tags.json)" || exit $?; + echo "Successfully registered MongoDB credentials and info secret to AWS Secrets Manager!" + backoffLimit: 4 +{{- end }} diff --git a/cluster-applications/025-mongodb-ce/values.yaml b/cluster-applications/025-mongodb-ce/values.yaml new file mode 100644 index 000000000..bc097ffe7 --- /dev/null +++ b/cluster-applications/025-mongodb-ce/values.yaml @@ -0,0 +1,36 @@ +--- +# Common cluster values +account_id: "" +region_id: "" +cluster_id: "" +cluster_admin_role: true +run_sync_hooks: true +cli_image_repo: "" +sm_aws_access_key_id: "" +sm_aws_secret_access_key: "" + +# Operator settings +mongodb_operator_channel: "v0.7" +mongodb_operator_install_plan: "Automatic" +mongodb_operator_source: "community-operators" +mongodb_operator_source_namespace: "openshift-marketplace" + +# MongoDB ReplicaSet settings +mongodb_namespace: "mongoce" +mongodb_instance_name: "mas-mongo-ce" +mongodb_version: "7.0.5" +mongodb_members: 3 + +# Credentials & Storage +admin_password: "ChangeMe123!" +storage_size: "10Gi" +storage_class: "" + +# Resources +resources: + limits: + cpu: "2" + memory: "4Gi" + requests: + cpu: "500m" + memory: "1Gi" diff --git a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml new file mode 100644 index 000000000..b5291103d --- /dev/null +++ b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml @@ -0,0 +1,81 @@ +{{- if and (not (empty .Values.mongodb_ce)) (eq (.Values.mongodb_ce.install | default "true") "true") (.Values.cluster_admin_role) }} +--- +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: mongodb-ce.{{ .Values.cluster.id }} + namespace: {{ .Values.argo.namespace }} + labels: + environment: '{{ .Values.account.id }}' + region: '{{ .Values.region.id }}' + cluster: '{{ .Values.cluster.id }}' + {{- if .Values.argo.instance }} + argocd.argoproj.io/instance: '{{ .Values.argo.instance }}' + {{- end }} + annotations: + argocd.argoproj.io/sync-wave: "025" + healthCheckTimeout: "1800" + {{- if and .Values.notifications .Values.notifications.slack_channel_id }} + notifications.argoproj.io/subscribe.on-sync-failed.workspace1: {{ .Values.notifications.slack_channel_id }} + notifications.argoproj.io/subscribe.on-sync-succeeded.workspace1: {{ .Values.notifications.slack_channel_id }} + {{- end }} + finalizers: + - resources-finalizer.argocd.argoproj.io +spec: + project: "{{ .Values.argo.projects.apps }}" + destination: + server: {{ .Values.cluster.url }} + namespace: {{ .Values.mongodb_ce.namespace | default "mongoce" }} + source: + repoURL: "{{ .Values.source.repo_url }}" + path: cluster-applications/025-mongodb-ce + targetRevision: "{{ .Values.source.revision }}" + plugin: + name: {{ .Values.avp.name }} + env: + - name: {{ .Values.avp.values_varname }} + value: | + account_id: "{{ .Values.account.id }}" + region_id: "{{ .Values.region.id }}" + cluster_id: "{{ .Values.cluster.id }}" + cluster_admin_role: {{ .Values.cluster_admin_role }} + run_sync_hooks: {{ .Values.mongodb_ce.run_sync_hooks | default true }} + sm_aws_access_key_id: "{{ .Values.sm.aws_access_key_id }}" + sm_aws_secret_access_key: "{{ .Values.sm.aws_secret_access_key }}" + cli_image_repo: {{ .Values.cli_image_repo }} + mongodb_operator_channel: "{{ .Values.mongodb_ce.channel | default "v0.7" }}" + mongodb_operator_install_plan: "{{ .Values.mongodb_ce.install_plan | default "Automatic" }}" + mongodb_operator_source: "{{ .Values.mongodb_ce.source | default "community-operators" }}" + mongodb_operator_source_namespace: "{{ .Values.mongodb_ce.source_namespace | default "openshift-marketplace" }}" + mongodb_namespace: "{{ .Values.mongodb_ce.namespace | default "mongoce" }}" + mongodb_instance_name: "{{ .Values.mongodb_ce.instance_name | default "mas-mongo-ce" }}" + mongodb_version: "{{ .Values.mongodb_ce.version | default "7.0.5" }}" + mongodb_members: {{ .Values.mongodb_ce.members | default 3 }} + admin_password: "{{ .Values.mongodb_ce.admin_password }}" + storage_size: "{{ .Values.mongodb_ce.storage_size | default "10Gi" }}" + storage_class: "{{ .Values.mongodb_ce.storage_class | default "" }}" + {{- if .Values.custom_labels }} + custom_labels: {{ .Values.custom_labels | toYaml | nindent 14 }} + {{- end }} + - name: ARGOCD_APP_NAME + value: mongodbceapp + {{- if not (empty .Values.avp.secret) }} + - name: AVP_SECRET + value: {{ .Values.avp.secret }} + {{- end }} + syncPolicy: + automated: + {{- if .Values.auto_delete }} + prune: true + {{- end }} + selfHeal: true + retry: + limit: 20 + syncOptions: + - CreateNamespace=true +{{- if .Values.custom_labels }} + managedNamespaceMetadata: + labels: +{{ .Values.custom_labels | toYaml | indent 8 }} +{{- end }} +{{- end }} diff --git a/root-applications/ibm-mas-cluster-root/values.yaml b/root-applications/ibm-mas-cluster-root/values.yaml index 5dccacce9..81f218d4f 100644 --- a/root-applications/ibm-mas-cluster-root/values.yaml +++ b/root-applications/ibm-mas-cluster-root/values.yaml @@ -47,3 +47,5 @@ custom_sa: custom_sa_namespace: custom_sa_details: +mongodb_ce: {} + From aec8c3b403ed9475cacbca592db7a9eb6c023220 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Tue, 22 Sep 2026 12:13:50 +0530 Subject: [PATCH 02/24] - Add related mongo changes --- cluster-applications/025-mongodb-ce/Chart.yaml | 11 +++++++++++ .../templates/000-cluster-appset.yaml | 5 +++++ 2 files changed, 16 insertions(+) create mode 100644 cluster-applications/025-mongodb-ce/Chart.yaml diff --git a/cluster-applications/025-mongodb-ce/Chart.yaml b/cluster-applications/025-mongodb-ce/Chart.yaml new file mode 100644 index 000000000..ffb4a4d85 --- /dev/null +++ b/cluster-applications/025-mongodb-ce/Chart.yaml @@ -0,0 +1,11 @@ +apiVersion: v2 +name: mongodb-ce +description: MongoDB Community Operator and Instance +type: application +version: 1.0.0 + +dependencies: +- name: junitreporter + version: 1.0.0 + repository: "file://../../sub-charts/junitreporter/" + condition: junitreporter.devops_mongo_uri != "" diff --git a/root-applications/ibm-mas-account-root/templates/000-cluster-appset.yaml b/root-applications/ibm-mas-account-root/templates/000-cluster-appset.yaml index 7e175fbbc..f8d08e48e 100644 --- a/root-applications/ibm-mas-account-root/templates/000-cluster-appset.yaml +++ b/root-applications/ibm-mas-account-root/templates/000-cluster-appset.yaml @@ -115,6 +115,11 @@ spec: revision: "{{ .Values.generator.revision }}" files: - path: "{{ .Values.account.id }}/*/efs-csi-driver.yaml" + - git: + repoURL: "{{ .Values.generator.repo_url }}" + revision: "{{ .Values.generator.revision }}" + files: + - path: "{{ .Values.account.id }}/*/mongodb-ce.yaml" syncPolicy: applicationsSync: "{{- if .Values.auto_delete }}sync{{- else }}create-update{{- end }}" template: From 91fdb45f4c5b92bd899e3bd8652e4133f1d38040 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Thu, 24 Sep 2026 15:29:57 +0530 Subject: [PATCH 03/24] - Change related to mongo database installing --- .../025-mongodb-ce/templates/06-postsync-update-sm_Job.yaml | 2 +- .../ibm-mas-account-root/templates/000-cluster-appset.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/cluster-applications/025-mongodb-ce/templates/06-postsync-update-sm_Job.yaml b/cluster-applications/025-mongodb-ce/templates/06-postsync-update-sm_Job.yaml index 1a1ae9bb4..4694f6903 100644 --- a/cluster-applications/025-mongodb-ce/templates/06-postsync-update-sm_Job.yaml +++ b/cluster-applications/025-mongodb-ce/templates/06-postsync-update-sm_Job.yaml @@ -229,7 +229,7 @@ spec: with open('/tmp/secret_tags.json', 'w') as f: f.write(tags) "; - SECRET_NAME_MONGO="${ACCOUNT_ID}/${CLUSTER_ID}/mongo"; + SECRET_NAME_MONGO="${ACCOUNT_ID}/${CLUSTER_ID}/mongodatabase"; echo "Updating AWS Secret: ${SECRET_NAME_MONGO}"; sm_update_secret "${SECRET_NAME_MONGO}" "$(cat /tmp/secret_payload.json)" "$(cat /tmp/secret_tags.json)" || exit $?; echo "Successfully registered MongoDB credentials and info secret to AWS Secrets Manager!" diff --git a/root-applications/ibm-mas-account-root/templates/000-cluster-appset.yaml b/root-applications/ibm-mas-account-root/templates/000-cluster-appset.yaml index f8d08e48e..4c4e3c3ae 100644 --- a/root-applications/ibm-mas-account-root/templates/000-cluster-appset.yaml +++ b/root-applications/ibm-mas-account-root/templates/000-cluster-appset.yaml @@ -119,7 +119,7 @@ spec: repoURL: "{{ .Values.generator.repo_url }}" revision: "{{ .Values.generator.revision }}" files: - - path: "{{ .Values.account.id }}/*/mongodb-ce.yaml" + - path: "{{ .Values.account.id }}/*/ibm-mongodb.yaml" syncPolicy: applicationsSync: "{{- if .Values.auto_delete }}sync{{- else }}create-update{{- end }}" template: From 751e3ebab4057788a4a9840113926a476f79cfe3 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Thu, 24 Sep 2026 18:06:01 +0530 Subject: [PATCH 04/24] - change the variables names based on cli --- .../templates/025-mongodb-ce-app.yaml | 29 ++++++++++--------- .../ibm-mas-cluster-root/values.yaml | 2 +- 2 files changed, 16 insertions(+), 15 deletions(-) diff --git a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml index b5291103d..d88219568 100644 --- a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml +++ b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml @@ -1,4 +1,4 @@ -{{- if and (not (empty .Values.mongodb_ce)) (eq (.Values.mongodb_ce.install | default "true") "true") (.Values.cluster_admin_role) }} +{{- if and (not (empty .Values.ibm_mongodb)) (eq (.Values.ibm_mongodb.install | default "true") "true") (.Values.cluster_admin_role) }} --- apiVersion: argoproj.io/v1alpha1 kind: Application @@ -25,7 +25,7 @@ spec: project: "{{ .Values.argo.projects.apps }}" destination: server: {{ .Values.cluster.url }} - namespace: {{ .Values.mongodb_ce.namespace | default "mongoce" }} + namespace: {{ .Values.ibm_mongodb.namespace | default "mongoce" }} source: repoURL: "{{ .Values.source.repo_url }}" path: cluster-applications/025-mongodb-ce @@ -39,21 +39,22 @@ spec: region_id: "{{ .Values.region.id }}" cluster_id: "{{ .Values.cluster.id }}" cluster_admin_role: {{ .Values.cluster_admin_role }} - run_sync_hooks: {{ .Values.mongodb_ce.run_sync_hooks | default true }} + run_sync_hooks: {{ .Values.ibm_mongodb.run_sync_hooks | default true }} sm_aws_access_key_id: "{{ .Values.sm.aws_access_key_id }}" sm_aws_secret_access_key: "{{ .Values.sm.aws_secret_access_key }}" cli_image_repo: {{ .Values.cli_image_repo }} - mongodb_operator_channel: "{{ .Values.mongodb_ce.channel | default "v0.7" }}" - mongodb_operator_install_plan: "{{ .Values.mongodb_ce.install_plan | default "Automatic" }}" - mongodb_operator_source: "{{ .Values.mongodb_ce.source | default "community-operators" }}" - mongodb_operator_source_namespace: "{{ .Values.mongodb_ce.source_namespace | default "openshift-marketplace" }}" - mongodb_namespace: "{{ .Values.mongodb_ce.namespace | default "mongoce" }}" - mongodb_instance_name: "{{ .Values.mongodb_ce.instance_name | default "mas-mongo-ce" }}" - mongodb_version: "{{ .Values.mongodb_ce.version | default "7.0.5" }}" - mongodb_members: {{ .Values.mongodb_ce.members | default 3 }} - admin_password: "{{ .Values.mongodb_ce.admin_password }}" - storage_size: "{{ .Values.mongodb_ce.storage_size | default "10Gi" }}" - storage_class: "{{ .Values.mongodb_ce.storage_class | default "" }}" + ibm_entitlement_key: "{{ .Values.ibm_mongodb.ibm_entitlement_key }}" + mongodb_operator_channel: "{{ .Values.ibm_mongodb.channel | default "v0.7" }}" + mongodb_operator_install_plan: "{{ .Values.ibm_mongodb.install_plan | default "Automatic" }}" + mongodb_operator_source: "{{ .Values.ibm_mongodb.source | default "community-operators" }}" + mongodb_operator_source_namespace: "{{ .Values.ibm_mongodb.source_namespace | default "openshift-marketplace" }}" + mongodb_namespace: "{{ .Values.ibm_mongodb.namespace | default "mongoce" }}" + mongodb_instance_name: "{{ .Values.ibm_mongodb.namespace | default "mas-mongo-ce" }}" + mongodb_version: "{{ .Values.ibm_mongodb.mongo_ce_version | default "7.0.5" }}" + mongodb_members: {{ .Values.ibm_mongodb.members | default 3 }} + admin_password: "{{ .Values.ibm_mongodb.admin_password }}" + storage_size: "{{ .Values.ibm_mongodb.storage_size | default "10Gi" }}" + storage_class: "{{ .Values.ibm_mongodb.mongo_ce_storage_class | default "" }}" {{- if .Values.custom_labels }} custom_labels: {{ .Values.custom_labels | toYaml | nindent 14 }} {{- end }} diff --git a/root-applications/ibm-mas-cluster-root/values.yaml b/root-applications/ibm-mas-cluster-root/values.yaml index 81f218d4f..14f8ee37b 100644 --- a/root-applications/ibm-mas-cluster-root/values.yaml +++ b/root-applications/ibm-mas-cluster-root/values.yaml @@ -47,5 +47,5 @@ custom_sa: custom_sa_namespace: custom_sa_details: -mongodb_ce: {} +ibm_mongodb: {} From 2a085991b21878fa3baf5738b33ee061366495cb Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Fri, 25 Sep 2026 14:24:49 +0530 Subject: [PATCH 05/24] - Mongo relate variables added --- .../025-mongodb-ce/templates/03-subscription.yaml | 2 +- cluster-applications/025-mongodb-ce/values.yaml | 2 +- .../ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml | 4 ++-- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/cluster-applications/025-mongodb-ce/templates/03-subscription.yaml b/cluster-applications/025-mongodb-ce/templates/03-subscription.yaml index 63922eee7..0358c1e17 100644 --- a/cluster-applications/025-mongodb-ce/templates/03-subscription.yaml +++ b/cluster-applications/025-mongodb-ce/templates/03-subscription.yaml @@ -11,7 +11,7 @@ metadata: {{ .Values.custom_labels | toYaml | indent 4 }} {{- end }} spec: - channel: "{{ .Values.mongodb_operator_channel | default "v0.7" }}" + channel: "{{ .Values.mongodb_operator_channel | default "stable" }}" installPlanApproval: {{ .Values.mongodb_operator_install_plan | default "Automatic" | quote }} name: mongodb-kubernetes-operator source: {{ .Values.mongodb_operator_source | default "community-operators" }} diff --git a/cluster-applications/025-mongodb-ce/values.yaml b/cluster-applications/025-mongodb-ce/values.yaml index bc097ffe7..5aa75f341 100644 --- a/cluster-applications/025-mongodb-ce/values.yaml +++ b/cluster-applications/025-mongodb-ce/values.yaml @@ -10,7 +10,7 @@ sm_aws_access_key_id: "" sm_aws_secret_access_key: "" # Operator settings -mongodb_operator_channel: "v0.7" +mongodb_operator_channel: "stable" mongodb_operator_install_plan: "Automatic" mongodb_operator_source: "community-operators" mongodb_operator_source_namespace: "openshift-marketplace" diff --git a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml index d88219568..472d0c4b5 100644 --- a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml +++ b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml @@ -44,12 +44,12 @@ spec: sm_aws_secret_access_key: "{{ .Values.sm.aws_secret_access_key }}" cli_image_repo: {{ .Values.cli_image_repo }} ibm_entitlement_key: "{{ .Values.ibm_mongodb.ibm_entitlement_key }}" - mongodb_operator_channel: "{{ .Values.ibm_mongodb.channel | default "v0.7" }}" + mongodb_operator_channel: "{{ .Values.ibm_mongodb.channel | default "stable" }}" mongodb_operator_install_plan: "{{ .Values.ibm_mongodb.install_plan | default "Automatic" }}" mongodb_operator_source: "{{ .Values.ibm_mongodb.source | default "community-operators" }}" mongodb_operator_source_namespace: "{{ .Values.ibm_mongodb.source_namespace | default "openshift-marketplace" }}" mongodb_namespace: "{{ .Values.ibm_mongodb.namespace | default "mongoce" }}" - mongodb_instance_name: "{{ .Values.ibm_mongodb.namespace | default "mas-mongo-ce" }}" + mongodb_instance_name: "{{ .Values.ibm_mongodb.instance_name | default "mas-mongo-ce" }}" mongodb_version: "{{ .Values.ibm_mongodb.mongo_ce_version | default "7.0.5" }}" mongodb_members: {{ .Values.ibm_mongodb.members | default 3 }} admin_password: "{{ .Values.ibm_mongodb.admin_password }}" From af4065c9b6572e0de6f453f957979bcb6717e689 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Mon, 28 Sep 2026 11:51:47 +0530 Subject: [PATCH 06/24] - Changes regarding Mongo installation --- .../templates/02-operator-deployment.yaml | 203 ++++++++++++++++++ .../templates/02-operator-group.yaml | 15 -- ...admin-secret.yaml => 03-admin-secret.yaml} | 0 .../templates/03-subscription.yaml | 18 -- ...y-cr.yaml => 04-mongodb-community-cr.yaml} | 0 ...ob.yaml => 05-postsync-update-sm_Job.yaml} | 0 .../025-mongodb-ce/values.yaml | 6 - .../templates/025-mongodb-ce-app.yaml | 5 - 8 files changed, 203 insertions(+), 44 deletions(-) create mode 100644 cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml delete mode 100644 cluster-applications/025-mongodb-ce/templates/02-operator-group.yaml rename cluster-applications/025-mongodb-ce/templates/{04-admin-secret.yaml => 03-admin-secret.yaml} (100%) delete mode 100644 cluster-applications/025-mongodb-ce/templates/03-subscription.yaml rename cluster-applications/025-mongodb-ce/templates/{05-mongodb-community-cr.yaml => 04-mongodb-community-cr.yaml} (100%) rename cluster-applications/025-mongodb-ce/templates/{06-postsync-update-sm_Job.yaml => 05-postsync-update-sm_Job.yaml} (100%) diff --git a/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml b/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml new file mode 100644 index 000000000..dd87fe7e0 --- /dev/null +++ b/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml @@ -0,0 +1,203 @@ +{{- /* +Deploy the MongoDB Community Operator directly from quay.io image digest. +This matches the ansible-devops mongodb community install approach (no OLM Subscription needed). +Operator: quay.io/mongodb/mongodb-kubernetes-operator:0.9.0 +*/}} +--- +# Role for the operator +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: mongodb-kubernetes-operator + namespace: {{ .Values.mongodb_namespace | default "mongoce" }} + annotations: + argocd.argoproj.io/sync-wave: "022" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +rules: + - apiGroups: [""] + resources: [pods, services, configmaps, secrets] + verbs: [create, delete, get, list, patch, update, watch] + - apiGroups: [apps] + resources: [statefulsets] + verbs: [create, delete, get, list, patch, update, watch] + - apiGroups: [mongodbcommunity.mongodb.com] + resources: [mongodbcommunity, mongodbcommunity/status, mongodbcommunity/spec, mongodbcommunity/finalizers] + verbs: [get, patch, list, update, watch] + +--- +# RoleBinding for the operator +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: mongodb-kubernetes-operator + namespace: {{ .Values.mongodb_namespace | default "mongoce" }} + annotations: + argocd.argoproj.io/sync-wave: "022" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +subjects: + - kind: ServiceAccount + name: mongodb-kubernetes-operator + namespace: {{ .Values.mongodb_namespace | default "mongoce" }} +roleRef: + kind: Role + name: mongodb-kubernetes-operator + apiGroup: rbac.authorization.k8s.io + +--- +# ServiceAccount for the operator +apiVersion: v1 +kind: ServiceAccount +metadata: + name: mongodb-kubernetes-operator + namespace: {{ .Values.mongodb_namespace | default "mongoce" }} + annotations: + argocd.argoproj.io/sync-wave: "022" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} + +--- +# Role for the database service account +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: mongodb-database + namespace: {{ .Values.mongodb_namespace | default "mongoce" }} + annotations: + argocd.argoproj.io/sync-wave: "022" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +rules: + - apiGroups: [""] + resources: [secrets] + verbs: [get] + - apiGroups: [""] + resources: [pods] + verbs: [patch, delete, get] + +--- +# RoleBinding for the database service account +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: mongodb-database + namespace: {{ .Values.mongodb_namespace | default "mongoce" }} + annotations: + argocd.argoproj.io/sync-wave: "022" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +subjects: + - kind: ServiceAccount + name: mongodb-database + namespace: {{ .Values.mongodb_namespace | default "mongoce" }} +roleRef: + kind: Role + name: mongodb-database + apiGroup: rbac.authorization.k8s.io + +--- +# ServiceAccount for the database pods +apiVersion: v1 +kind: ServiceAccount +metadata: + name: mongodb-database + namespace: {{ .Values.mongodb_namespace | default "mongoce" }} + annotations: + argocd.argoproj.io/sync-wave: "022" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} + +--- +# Operator Deployment - directly from quay.io (no OLM/Subscription required) +# Image: quay.io/mongodb/mongodb-kubernetes-operator@sha256:4e1e6f82d33211ffd164a28d811b106d02546a1ce84c95625404f30a80a0c2d1 +apiVersion: apps/v1 +kind: Deployment +metadata: + name: mongodb-kubernetes-operator + namespace: {{ .Values.mongodb_namespace | default "mongoce" }} + annotations: + argocd.argoproj.io/sync-wave: "023" + labels: + owner: mongodb +{{- if .Values.custom_labels }} +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +spec: + replicas: 1 + selector: + matchLabels: + name: mongodb-kubernetes-operator + strategy: + type: RollingUpdate + rollingUpdate: + maxUnavailable: 1 + template: + metadata: + labels: + name: mongodb-kubernetes-operator +{{- if .Values.custom_labels }} +{{ .Values.custom_labels | toYaml | indent 8 }} +{{- end }} + spec: + serviceAccountName: mongodb-kubernetes-operator + affinity: + podAntiAffinity: + requiredDuringSchedulingIgnoredDuringExecution: + - labelSelector: + matchExpressions: + - key: name + operator: In + values: + - mongodb-kubernetes-operator + topologyKey: kubernetes.io/hostname + containers: + - name: mongodb-kubernetes-operator + image: quay.io/mongodb/mongodb-kubernetes-operator@sha256:4e1e6f82d33211ffd164a28d811b106d02546a1ce84c95625404f30a80a0c2d1 + imagePullPolicy: Always + command: + - /usr/local/bin/entrypoint + resources: + limits: + cpu: 1100m + memory: 1Gi + requests: + cpu: 500m + memory: 200Mi + securityContext: + readOnlyRootFilesystem: true + runAsUser: 2000 + allowPrivilegeEscalation: false + env: + - name: WATCH_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: POD_NAME + valueFrom: + fieldRef: + fieldPath: metadata.name + - name: OPERATOR_NAME + value: mongodb-kubernetes-operator + - name: AGENT_IMAGE + value: "quay.io/mongodb/mongodb-agent@sha256:d5b34afd48568f5a6a9fce03c78660cbf8d3a96e7fd9a6fbe1d028b01112840f" + - name: VERSION_UPGRADE_HOOK_IMAGE + value: "quay.io/mongodb/mongodb-kubernetes-operator-version-upgrade-post-start-hook@sha256:893527c88d7b7acc2a5f6fe4e38d8cac5ee99bf5a8c2e4405d2fc6ed4e509bbc" + - name: READINESS_PROBE_IMAGE + value: "quay.io/mongodb/mongodb-kubernetes-readinessprobe@sha256:169c1f047b58134b82da6646c4fb75f3fd30599ccc3d54fffd16e56e61e8c01f" + - name: MONGODB_IMAGE + value: "ibmmas/mongo@sha256:34341de709b1a70f5e0339ecb1ad2aa2152ecf88e5ca825e2a764da69bbd0269" + - name: MONGODB_REPO_URL + value: "quay.io" diff --git a/cluster-applications/025-mongodb-ce/templates/02-operator-group.yaml b/cluster-applications/025-mongodb-ce/templates/02-operator-group.yaml deleted file mode 100644 index c09c4d23a..000000000 --- a/cluster-applications/025-mongodb-ce/templates/02-operator-group.yaml +++ /dev/null @@ -1,15 +0,0 @@ ---- -apiVersion: operators.coreos.com/v1 -kind: OperatorGroup -metadata: - name: mongodb-operator-group - namespace: {{ .Values.mongodb_namespace | default "mongoce" }} - annotations: - argocd.argoproj.io/sync-wave: "022" -{{- if .Values.custom_labels }} - labels: -{{ .Values.custom_labels | toYaml | indent 4 }} -{{- end }} -spec: - targetNamespaces: - - {{ .Values.mongodb_namespace | default "mongoce" }} diff --git a/cluster-applications/025-mongodb-ce/templates/04-admin-secret.yaml b/cluster-applications/025-mongodb-ce/templates/03-admin-secret.yaml similarity index 100% rename from cluster-applications/025-mongodb-ce/templates/04-admin-secret.yaml rename to cluster-applications/025-mongodb-ce/templates/03-admin-secret.yaml diff --git a/cluster-applications/025-mongodb-ce/templates/03-subscription.yaml b/cluster-applications/025-mongodb-ce/templates/03-subscription.yaml deleted file mode 100644 index 0358c1e17..000000000 --- a/cluster-applications/025-mongodb-ce/templates/03-subscription.yaml +++ /dev/null @@ -1,18 +0,0 @@ ---- -apiVersion: operators.coreos.com/v1alpha1 -kind: Subscription -metadata: - name: mongodb-kubernetes-operator - namespace: {{ .Values.mongodb_namespace | default "mongoce" }} - annotations: - argocd.argoproj.io/sync-wave: "023" -{{- if .Values.custom_labels }} - labels: -{{ .Values.custom_labels | toYaml | indent 4 }} -{{- end }} -spec: - channel: "{{ .Values.mongodb_operator_channel | default "stable" }}" - installPlanApproval: {{ .Values.mongodb_operator_install_plan | default "Automatic" | quote }} - name: mongodb-kubernetes-operator - source: {{ .Values.mongodb_operator_source | default "community-operators" }} - sourceNamespace: {{ .Values.mongodb_operator_source_namespace | default "openshift-marketplace" }} diff --git a/cluster-applications/025-mongodb-ce/templates/05-mongodb-community-cr.yaml b/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml similarity index 100% rename from cluster-applications/025-mongodb-ce/templates/05-mongodb-community-cr.yaml rename to cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml diff --git a/cluster-applications/025-mongodb-ce/templates/06-postsync-update-sm_Job.yaml b/cluster-applications/025-mongodb-ce/templates/05-postsync-update-sm_Job.yaml similarity index 100% rename from cluster-applications/025-mongodb-ce/templates/06-postsync-update-sm_Job.yaml rename to cluster-applications/025-mongodb-ce/templates/05-postsync-update-sm_Job.yaml diff --git a/cluster-applications/025-mongodb-ce/values.yaml b/cluster-applications/025-mongodb-ce/values.yaml index 5aa75f341..8db2a533a 100644 --- a/cluster-applications/025-mongodb-ce/values.yaml +++ b/cluster-applications/025-mongodb-ce/values.yaml @@ -9,12 +9,6 @@ cli_image_repo: "" sm_aws_access_key_id: "" sm_aws_secret_access_key: "" -# Operator settings -mongodb_operator_channel: "stable" -mongodb_operator_install_plan: "Automatic" -mongodb_operator_source: "community-operators" -mongodb_operator_source_namespace: "openshift-marketplace" - # MongoDB ReplicaSet settings mongodb_namespace: "mongoce" mongodb_instance_name: "mas-mongo-ce" diff --git a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml index 472d0c4b5..a612ef635 100644 --- a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml +++ b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml @@ -43,11 +43,6 @@ spec: sm_aws_access_key_id: "{{ .Values.sm.aws_access_key_id }}" sm_aws_secret_access_key: "{{ .Values.sm.aws_secret_access_key }}" cli_image_repo: {{ .Values.cli_image_repo }} - ibm_entitlement_key: "{{ .Values.ibm_mongodb.ibm_entitlement_key }}" - mongodb_operator_channel: "{{ .Values.ibm_mongodb.channel | default "stable" }}" - mongodb_operator_install_plan: "{{ .Values.ibm_mongodb.install_plan | default "Automatic" }}" - mongodb_operator_source: "{{ .Values.ibm_mongodb.source | default "community-operators" }}" - mongodb_operator_source_namespace: "{{ .Values.ibm_mongodb.source_namespace | default "openshift-marketplace" }}" mongodb_namespace: "{{ .Values.ibm_mongodb.namespace | default "mongoce" }}" mongodb_instance_name: "{{ .Values.ibm_mongodb.instance_name | default "mas-mongo-ce" }}" mongodb_version: "{{ .Values.ibm_mongodb.mongo_ce_version | default "7.0.5" }}" From bb619d6c4c11c68063e417119342f02e23037f36 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Mon, 28 Sep 2026 12:59:21 +0530 Subject: [PATCH 07/24] - changes related to mongo --- .../templates/01b-scc-anyuid.yaml | 75 +++++++++++++++++++ .../templates/02-operator-deployment.yaml | 1 - 2 files changed, 75 insertions(+), 1 deletion(-) create mode 100644 cluster-applications/025-mongodb-ce/templates/01b-scc-anyuid.yaml diff --git a/cluster-applications/025-mongodb-ce/templates/01b-scc-anyuid.yaml b/cluster-applications/025-mongodb-ce/templates/01b-scc-anyuid.yaml new file mode 100644 index 000000000..ae6f31c06 --- /dev/null +++ b/cluster-applications/025-mongodb-ce/templates/01b-scc-anyuid.yaml @@ -0,0 +1,75 @@ +{{- /* +Grant anyuid SCC to the MongoDB operator and database ServiceAccounts. +This is required on OpenShift because the operator container runs as a +non-root user (UID 2000) which falls outside the namespace-allocated UID +range enforced by restricted-v2 SCC. + +This replicates what the ansible-devops mongodb community role does with: + oc adm policy add-scc-to-user anyuid system:serviceaccount::mongodb-kubernetes-operator + oc adm policy add-scc-to-user anyuid system:serviceaccount::mongodb-database + oc adm policy add-scc-to-user anyuid system:serviceaccount::default +*/}} +{{- $ns := .Values.mongodb_namespace | default "mongoce" }} + +--- +# Grant anyuid SCC to the mongodb-kubernetes-operator ServiceAccount +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: mongodb-operator-anyuid-{{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "021" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +subjects: + - kind: ServiceAccount + name: mongodb-kubernetes-operator + namespace: {{ $ns }} +roleRef: + kind: ClusterRole + name: system:openshift:scc:anyuid + apiGroup: rbac.authorization.k8s.io + +--- +# Grant anyuid SCC to the mongodb-database ServiceAccount +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: mongodb-database-anyuid-{{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "021" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +subjects: + - kind: ServiceAccount + name: mongodb-database + namespace: {{ $ns }} +roleRef: + kind: ClusterRole + name: system:openshift:scc:anyuid + apiGroup: rbac.authorization.k8s.io + +--- +# Grant anyuid SCC to the default ServiceAccount (used by mongodb pods) +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: mongodb-default-anyuid-{{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "021" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +subjects: + - kind: ServiceAccount + name: default + namespace: {{ $ns }} +roleRef: + kind: ClusterRole + name: system:openshift:scc:anyuid + apiGroup: rbac.authorization.k8s.io diff --git a/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml b/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml index dd87fe7e0..4ef95a4ff 100644 --- a/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml +++ b/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml @@ -178,7 +178,6 @@ spec: memory: 200Mi securityContext: readOnlyRootFilesystem: true - runAsUser: 2000 allowPrivilegeEscalation: false env: - name: WATCH_NAMESPACE From 4428f3b5c575e21a5c8d616dde82c771aff3cdde Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Mon, 28 Sep 2026 13:20:14 +0530 Subject: [PATCH 08/24] Update 01b-scc-anyuid.yaml --- .../templates/01b-scc-anyuid.yaml | 18 ++++++++++++------ 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/cluster-applications/025-mongodb-ce/templates/01b-scc-anyuid.yaml b/cluster-applications/025-mongodb-ce/templates/01b-scc-anyuid.yaml index ae6f31c06..29bd20f26 100644 --- a/cluster-applications/025-mongodb-ce/templates/01b-scc-anyuid.yaml +++ b/cluster-applications/025-mongodb-ce/templates/01b-scc-anyuid.yaml @@ -4,6 +4,9 @@ This is required on OpenShift because the operator container runs as a non-root user (UID 2000) which falls outside the namespace-allocated UID range enforced by restricted-v2 SCC. +Uses RoleBinding (namespace-scoped) referencing system:openshift:scc:anyuid ClusterRole — +the same pattern used by the instana-agent-operator chart in this repo. + This replicates what the ansible-devops mongodb community role does with: oc adm policy add-scc-to-user anyuid system:serviceaccount::mongodb-kubernetes-operator oc adm policy add-scc-to-user anyuid system:serviceaccount::mongodb-database @@ -14,9 +17,10 @@ This replicates what the ansible-devops mongodb community role does with: --- # Grant anyuid SCC to the mongodb-kubernetes-operator ServiceAccount apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding +kind: RoleBinding metadata: - name: mongodb-operator-anyuid-{{ $ns }} + name: system:openshift:scc:anyuid:operator + namespace: {{ $ns }} annotations: argocd.argoproj.io/sync-wave: "021" {{- if .Values.custom_labels }} @@ -35,9 +39,10 @@ roleRef: --- # Grant anyuid SCC to the mongodb-database ServiceAccount apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding +kind: RoleBinding metadata: - name: mongodb-database-anyuid-{{ $ns }} + name: system:openshift:scc:anyuid:database + namespace: {{ $ns }} annotations: argocd.argoproj.io/sync-wave: "021" {{- if .Values.custom_labels }} @@ -56,9 +61,10 @@ roleRef: --- # Grant anyuid SCC to the default ServiceAccount (used by mongodb pods) apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding +kind: RoleBinding metadata: - name: mongodb-default-anyuid-{{ $ns }} + name: system:openshift:scc:anyuid:default + namespace: {{ $ns }} annotations: argocd.argoproj.io/sync-wave: "021" {{- if .Values.custom_labels }} From 244b3cb002cb907b654a91a9daa4c5c66c16f84c Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Mon, 28 Sep 2026 13:39:58 +0530 Subject: [PATCH 09/24] Update 02-operator-deployment.yaml --- .../025-mongodb-ce/templates/02-operator-deployment.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml b/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml index 4ef95a4ff..5abd0fddf 100644 --- a/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml +++ b/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml @@ -197,6 +197,6 @@ spec: - name: READINESS_PROBE_IMAGE value: "quay.io/mongodb/mongodb-kubernetes-readinessprobe@sha256:169c1f047b58134b82da6646c4fb75f3fd30599ccc3d54fffd16e56e61e8c01f" - name: MONGODB_IMAGE - value: "ibmmas/mongo@sha256:34341de709b1a70f5e0339ecb1ad2aa2152ecf88e5ca825e2a764da69bbd0269" + value: "ibmmas/mongo:{{ .Values.mongodb_version | default "7.0.5" }}-ubi8" - name: MONGODB_REPO_URL value: "quay.io" From c230eb9aaadef1f6d86f969acc6fa64ea4c9c742 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Mon, 28 Sep 2026 13:46:31 +0530 Subject: [PATCH 10/24] - Related to mongo image format --- .../025-mongodb-ce/templates/02-operator-deployment.yaml | 4 ++-- .../025-mongodb-ce/templates/04-mongodb-community-cr.yaml | 1 + 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml b/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml index 5abd0fddf..1b28aedc0 100644 --- a/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml +++ b/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml @@ -197,6 +197,6 @@ spec: - name: READINESS_PROBE_IMAGE value: "quay.io/mongodb/mongodb-kubernetes-readinessprobe@sha256:169c1f047b58134b82da6646c4fb75f3fd30599ccc3d54fffd16e56e61e8c01f" - name: MONGODB_IMAGE - value: "ibmmas/mongo:{{ .Values.mongodb_version | default "7.0.5" }}-ubi8" + value: "quay.io/ibmmas/mongo:{{ .Values.mongodb_version | default "7.0.5" }}-ubi8" - name: MONGODB_REPO_URL - value: "quay.io" + value: "" diff --git a/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml b/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml index 71a22cf7b..f7440a417 100644 --- a/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml +++ b/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml @@ -34,6 +34,7 @@ spec: spec: containers: - name: mongod + image: "quay.io/ibmmas/mongo:{{ .Values.mongodb_version | default "7.0.5" }}-ubi8" resources: {{ .Values.resources | toYaml | indent 16 }} {{- if .Values.storage_size }} From 72046992f4caea86172a966d0d8b452ca3ababbe Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Mon, 28 Sep 2026 15:54:41 +0530 Subject: [PATCH 11/24] - Changes related to version for mongo --- .../025-mongodb-ce/templates/02-operator-deployment.yaml | 4 ++-- .../025-mongodb-ce/templates/04-mongodb-community-cr.yaml | 4 ++-- cluster-applications/025-mongodb-ce/values.yaml | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml b/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml index 1b28aedc0..ede6a4bf2 100644 --- a/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml +++ b/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml @@ -197,6 +197,6 @@ spec: - name: READINESS_PROBE_IMAGE value: "quay.io/mongodb/mongodb-kubernetes-readinessprobe@sha256:169c1f047b58134b82da6646c4fb75f3fd30599ccc3d54fffd16e56e61e8c01f" - name: MONGODB_IMAGE - value: "quay.io/ibmmas/mongo:{{ .Values.mongodb_version | default "7.0.5" }}-ubi8" + value: "mongodb/mongodb-community-server" - name: MONGODB_REPO_URL - value: "" + value: "quay.io" diff --git a/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml b/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml index f7440a417..4675e80a4 100644 --- a/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml +++ b/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml @@ -14,7 +14,7 @@ metadata: spec: members: {{ .Values.mongodb_members | default 3 }} type: ReplicaSet - version: {{ .Values.mongodb_version | default "7.0.5" | quote }} + version: {{ .Values.mongodb_version | default "7.0.12" | quote }} security: authentication: modes: @@ -34,7 +34,7 @@ spec: spec: containers: - name: mongod - image: "quay.io/ibmmas/mongo:{{ .Values.mongodb_version | default "7.0.5" }}-ubi8" + image: "quay.io/mongodb/mongodb-community-server:{{ .Values.mongodb_version | default "7.0.12" }}-ubi8" resources: {{ .Values.resources | toYaml | indent 16 }} {{- if .Values.storage_size }} diff --git a/cluster-applications/025-mongodb-ce/values.yaml b/cluster-applications/025-mongodb-ce/values.yaml index 8db2a533a..129aa3efa 100644 --- a/cluster-applications/025-mongodb-ce/values.yaml +++ b/cluster-applications/025-mongodb-ce/values.yaml @@ -12,7 +12,7 @@ sm_aws_secret_access_key: "" # MongoDB ReplicaSet settings mongodb_namespace: "mongoce" mongodb_instance_name: "mas-mongo-ce" -mongodb_version: "7.0.5" +mongodb_version: "7.0.12" mongodb_members: 3 # Credentials & Storage From 31f84135af472b5fd052e1974e0878fd56222791 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Mon, 28 Sep 2026 16:26:26 +0530 Subject: [PATCH 12/24] - change regarding mongo version --- .../025-mongodb-ce/templates/02-operator-deployment.yaml | 1 + .../025-mongodb-ce/templates/04-mongodb-community-cr.yaml | 1 + .../ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml | 2 +- 3 files changed, 3 insertions(+), 1 deletion(-) diff --git a/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml b/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml index ede6a4bf2..df0722fbd 100644 --- a/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml +++ b/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml @@ -130,6 +130,7 @@ metadata: namespace: {{ .Values.mongodb_namespace | default "mongoce" }} annotations: argocd.argoproj.io/sync-wave: "023" + mongodb-operator-config-version: "{{ .Values.mongodb_version | default "7.0.12" }}" labels: owner: mongodb {{- if .Values.custom_labels }} diff --git a/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml b/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml index 4675e80a4..f001491ab 100644 --- a/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml +++ b/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml @@ -7,6 +7,7 @@ metadata: annotations: argocd.argoproj.io/sync-wave: "025" argocd.argoproj.io/sync-options: SkipDryRunOnMissingResource=true + mongodb-image-version: "{{ .Values.mongodb_version | default "7.0.12" }}" {{- if .Values.custom_labels }} labels: {{ .Values.custom_labels | toYaml | indent 4 }} diff --git a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml index a612ef635..4168bcfd7 100644 --- a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml +++ b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml @@ -45,7 +45,7 @@ spec: cli_image_repo: {{ .Values.cli_image_repo }} mongodb_namespace: "{{ .Values.ibm_mongodb.namespace | default "mongoce" }}" mongodb_instance_name: "{{ .Values.ibm_mongodb.instance_name | default "mas-mongo-ce" }}" - mongodb_version: "{{ .Values.ibm_mongodb.mongo_ce_version | default "7.0.5" }}" + mongodb_version: "{{ .Values.ibm_mongodb.mongo_ce_version | default "7.0.12" }}" mongodb_members: {{ .Values.ibm_mongodb.members | default 3 }} admin_password: "{{ .Values.ibm_mongodb.admin_password }}" storage_size: "{{ .Values.ibm_mongodb.storage_size | default "10Gi" }}" From 0e8001dc765fc158e872621169828c6d8ab2c7ed Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Mon, 28 Sep 2026 23:32:00 +0530 Subject: [PATCH 13/24] Update 05-postsync-update-sm_Job.yaml --- .../templates/05-postsync-update-sm_Job.yaml | 59 ++++++++++--------- 1 file changed, 32 insertions(+), 27 deletions(-) diff --git a/cluster-applications/025-mongodb-ce/templates/05-postsync-update-sm_Job.yaml b/cluster-applications/025-mongodb-ce/templates/05-postsync-update-sm_Job.yaml index 4694f6903..70b31e9b3 100644 --- a/cluster-applications/025-mongodb-ce/templates/05-postsync-update-sm_Job.yaml +++ b/cluster-applications/025-mongodb-ce/templates/05-postsync-update-sm_Job.yaml @@ -164,31 +164,34 @@ spec: command: - /bin/bash - -c - - > - set -e; - source /mascli/functions/gitops_utils; - SM_AWS_ACCESS_KEY_ID=$(cat /etc/mas/creds/aws/aws_access_key_id); - SM_AWS_SECRET_ACCESS_KEY=$(cat /etc/mas/creds/aws/aws_secret_access_key); - export SM_AWS_REGION=${REGION_ID}; - sm_login; - echo "Waiting for MongoDBCommunity ${MONGO_INSTANCE_NAME} in ${MONGO_NAMESPACE}"; + - | + set -e + source /mascli/functions/gitops_utils + SM_AWS_ACCESS_KEY_ID=$(cat /etc/mas/creds/aws/aws_access_key_id) + SM_AWS_SECRET_ACCESS_KEY=$(cat /etc/mas/creds/aws/aws_secret_access_key) + export SM_AWS_REGION=${REGION_ID} + sm_login + + echo "Waiting for MongoDBCommunity ${MONGO_INSTANCE_NAME} in ${MONGO_NAMESPACE}" for (( c=1; c<=30; c++ )); do - echo "... check attempt ${c} of 30"; - PHASE=$(oc get mongodbcommunity "${MONGO_INSTANCE_NAME}" -n "${MONGO_NAMESPACE}" -o=jsonpath='{.status.phase}' 2>/dev/null || true); - echo "Current Phase: ${PHASE}"; + echo "... check attempt ${c} of 30" + PHASE=$(oc get mongodbcommunity "${MONGO_INSTANCE_NAME}" -n "${MONGO_NAMESPACE}" -o=jsonpath='{.status.phase}' 2>/dev/null || true) + echo "Current Phase: ${PHASE}" if [[ "${PHASE}" == "Running" ]]; then - echo "MongoDBCommunity instance is Running!"; - break; - fi; - sleep 20; - done; - PRIMARY_HOST="${MONGO_INSTANCE_NAME}-0.${MONGO_INSTANCE_NAME}-svc.${MONGO_NAMESPACE}.svc.cluster.local"; - CA_CERT=""; - CA_SECRET_NAME="${MONGO_INSTANCE_NAME}-ca"; + echo "MongoDBCommunity instance is Running!" + break + fi + sleep 20 + done + + CA_CERT="" + CA_SECRET_NAME="${MONGO_INSTANCE_NAME}-ca" if oc get secret "${CA_SECRET_NAME}" -n "${MONGO_NAMESPACE}" >/dev/null 2>&1; then - CA_CERT=$(oc get secret "${CA_SECRET_NAME}" -n "${MONGO_NAMESPACE}" -o=jsonpath='{.data.ca\.crt}' | base64 -d 2>/dev/null || true); - fi; - python3 -c " + CA_CERT=$(oc get secret "${CA_SECRET_NAME}" -n "${MONGO_NAMESPACE}" -o=jsonpath='{.data.ca\.crt}' | base64 -d 2>/dev/null || true) + fi + export CA_CERT + + cat > /tmp/build_secret.py << 'PYEOF' import os, json account = os.environ.get('ACCOUNT_ID') cluster = os.environ.get('CLUSTER_ID') @@ -211,7 +214,6 @@ spec: for line in ca_cert.strip().split('\n'): info_lines.append(f' {line}') info_str = '\n'.join(info_lines) + '\n' - secret_name = f'{account}/{cluster}/mongo' payload = { 'docdb_host': primary_host, 'docdb_port': '27017', @@ -228,10 +230,13 @@ spec: f.write(json.dumps(payload)) with open('/tmp/secret_tags.json', 'w') as f: f.write(tags) - "; - SECRET_NAME_MONGO="${ACCOUNT_ID}/${CLUSTER_ID}/mongodatabase"; - echo "Updating AWS Secret: ${SECRET_NAME_MONGO}"; - sm_update_secret "${SECRET_NAME_MONGO}" "$(cat /tmp/secret_payload.json)" "$(cat /tmp/secret_tags.json)" || exit $?; + PYEOF + + python3 /tmp/build_secret.py + + SECRET_NAME_MONGO="${ACCOUNT_ID}/${CLUSTER_ID}/mongodatabase" + echo "Updating AWS Secret: ${SECRET_NAME_MONGO}" + sm_update_secret "${SECRET_NAME_MONGO}" "$(cat /tmp/secret_payload.json)" "$(cat /tmp/secret_tags.json)" || exit $? echo "Successfully registered MongoDB credentials and info secret to AWS Secrets Manager!" backoffLimit: 4 {{- end }} From f0c261d5a77d87c6f32027e86fc4f9f90cf98669 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Tue, 29 Sep 2026 12:40:27 +0530 Subject: [PATCH 14/24] - Added required files for mongo --- .../025-mongodb-ce/templates/01-crd.yaml | 582 ++++++++++++++++++ .../{01-namespace.yaml => 02-namespace.yaml} | 0 .../templates/03-admin-secret.yaml | 15 - ...01b-scc-anyuid.yaml => 03-scc-anyuid.yaml} | 0 .../templates/04-mongodb-community-cr.yaml | 53 -- ...yment.yaml => 04-operator-deployment.yaml} | 0 .../templates/05-password-gen-job.yaml | 170 +++++ .../templates/05-postsync-update-sm_Job.yaml | 242 -------- .../templates/06-tls-certs.yaml | 102 +++ .../templates/07-ca-configmap-job.yaml | 148 +++++ .../templates/08-mongodb-community-cr.yaml | 100 +++ .../templates/09-postsync-update-sm_Job.yaml | 318 ++++++++++ .../025-mongodb-ce/values.yaml | 4 +- .../templates/025-mongodb-ce-app.yaml | 2 +- 14 files changed, 1423 insertions(+), 313 deletions(-) create mode 100644 cluster-applications/025-mongodb-ce/templates/01-crd.yaml rename cluster-applications/025-mongodb-ce/templates/{01-namespace.yaml => 02-namespace.yaml} (100%) delete mode 100644 cluster-applications/025-mongodb-ce/templates/03-admin-secret.yaml rename cluster-applications/025-mongodb-ce/templates/{01b-scc-anyuid.yaml => 03-scc-anyuid.yaml} (100%) delete mode 100644 cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml rename cluster-applications/025-mongodb-ce/templates/{02-operator-deployment.yaml => 04-operator-deployment.yaml} (100%) create mode 100644 cluster-applications/025-mongodb-ce/templates/05-password-gen-job.yaml delete mode 100644 cluster-applications/025-mongodb-ce/templates/05-postsync-update-sm_Job.yaml create mode 100644 cluster-applications/025-mongodb-ce/templates/06-tls-certs.yaml create mode 100644 cluster-applications/025-mongodb-ce/templates/07-ca-configmap-job.yaml create mode 100644 cluster-applications/025-mongodb-ce/templates/08-mongodb-community-cr.yaml create mode 100644 cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml diff --git a/cluster-applications/025-mongodb-ce/templates/01-crd.yaml b/cluster-applications/025-mongodb-ce/templates/01-crd.yaml new file mode 100644 index 000000000..090152839 --- /dev/null +++ b/cluster-applications/025-mongodb-ce/templates/01-crd.yaml @@ -0,0 +1,582 @@ +{{- /* +Install the MongoDBCommunity CRD before the operator and CR. +Sourced from: github.com/mongodb/mongodb-kubernetes-operator/blob/v0.9.0/config/crd/bases/mongodbcommunity.mongodb.com_mongodbcommunity.yaml +Wave 020 ensures it is registered before the operator Deployment (022) and the MongoDBCommunity CR (025). +*/}} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + name: mongodbcommunity.mongodbcommunity.mongodb.com + annotations: + controller-gen.kubebuilder.io/version: v0.11.3 + service.binding: path={.metadata.name}-{.spec.users[0].db}-{.spec.users[0].name},objectType=Secret + service.binding/connectionString: path={.metadata.name}-{.spec.users[0].db}-{.spec.users[0].name},objectType=Secret,sourceKey=connectionString.standardSrv + service.binding/password: path={.metadata.name}-{.spec.users[0].db}-{.spec.users[0].name},objectType=Secret,sourceKey=password + service.binding/provider: community + service.binding/type: mongodb + service.binding/username: path={.metadata.name}-{.spec.users[0].db}-{.spec.users[0].name},objectType=Secret,sourceKey=username + argocd.argoproj.io/sync-wave: "020" +spec: + group: mongodbcommunity.mongodb.com + names: + kind: MongoDBCommunity + listKind: MongoDBCommunityList + plural: mongodbcommunity + shortNames: + - mdbc + singular: mongodbcommunity + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: Current state of the MongoDB deployment + jsonPath: .status.phase + name: Phase + type: string + - description: Version of MongoDB server + jsonPath: .status.version + name: Version + type: string + name: v1 + schema: + openAPIV3Schema: + description: MongoDBCommunity is the Schema for the mongodbs API + properties: + apiVersion: + description: 'APIVersion defines the versioned schema of this representation + of an object. Servers should convert recognized schemas to the latest + internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources' + type: string + kind: + description: 'Kind is a string value representing the REST resource this + object represents. Servers may infer this from the endpoint the client + submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds' + type: string + metadata: + type: object + spec: + description: MongoDBCommunitySpec defines the desired state of MongoDB + properties: + additionalConnectionStringConfig: + description: Additional options to be appended to the connection string. + These options apply to the entire resource and to each user. + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + additionalMongodConfig: + description: 'AdditionalMongodConfig is additional configuration that + can be passed to each data-bearing mongod at runtime. Uses the same + structure as the mongod configuration file: https://www.mongodb.com/docs/manual/reference/configuration-options/' + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + agent: + description: AgentConfiguration sets options for the MongoDB automation + agent + properties: + logFile: + type: string + logLevel: + type: string + logRotate: + description: LogRotate if enabled, will enable LogRotate for all + processes. + properties: + includeAuditLogsWithMongoDBLogs: + description: set to 'true' to have the Automation Agent rotate + the audit files along with mongodb log files + type: boolean + numTotal: + description: maximum number of log files to have total + type: integer + numUncompressed: + description: maximum number of log files to leave uncompressed + type: integer + percentOfDiskspace: + description: Maximum percentage of the total disk space these + log files should take up. The string needs to be able to + be converted to float64 + type: string + sizeThresholdMB: + description: Maximum size for an individual log file before + rotation. The string needs to be able to be converted to + float64. Fractional values of MB are supported. + type: string + timeThresholdHrs: + description: maximum hours for an individual log file before + rotation + type: integer + required: + - sizeThresholdMB + - timeThresholdHrs + type: object + maxLogFileDurationHours: + type: integer + systemLog: + description: SystemLog configures system log of mongod + properties: + destination: + type: string + logAppend: + type: boolean + path: + type: string + required: + - destination + - logAppend + - path + type: object + type: object + arbiters: + description: 'Arbiters is the number of arbiters to add to the Replica + Set. It is not recommended to have more than one arbiter per Replica + Set. More info: https://www.mongodb.com/docs/manual/tutorial/add-replica-set-arbiter/' + type: integer + automationConfig: + description: AutomationConfigOverride is merged on top of the operator + created automation config. Processes are merged by name. Currently + Only the process.disabled field is supported. + properties: + processes: + items: + description: OverrideProcess contains fields that we can override + on the AutomationConfig processes. + properties: + disabled: + type: boolean + logRotate: + description: CrdLogRotate is the crd definition of LogRotate + including fields in strings while the agent supports them + as float64 + properties: + includeAuditLogsWithMongoDBLogs: + description: set to 'true' to have the Automation Agent + rotate the audit files along with mongodb log files + type: boolean + numTotal: + description: maximum number of log files to have total + type: integer + numUncompressed: + description: maximum number of log files to leave uncompressed + type: integer + percentOfDiskspace: + description: Maximum percentage of the total disk space + these log files should take up. The string needs to + be able to be converted to float64 + type: string + sizeThresholdMB: + description: Maximum size for an individual log file + before rotation. The string needs to be able to be + converted to float64. Fractional values of MB are + supported. + type: string + timeThresholdHrs: + description: maximum hours for an individual log file + before rotation + type: integer + required: + - sizeThresholdMB + - timeThresholdHrs + type: object + name: + type: string + required: + - disabled + - name + type: object + type: array + required: + - processes + type: object + featureCompatibilityVersion: + description: FeatureCompatibilityVersion configures the feature compatibility + version that will be set for the deployment + type: string + members: + description: Members is the number of members in the replica set + type: integer + prometheus: + description: Prometheus configurations. + properties: + metricsPath: + description: Indicates path to the metrics endpoint. + pattern: ^\/[a-z0-9]+$ + type: string + passwordSecretRef: + description: Name of a Secret containing a HTTP Basic Auth Password. + properties: + key: + description: Key is the key in the secret storing this password. + Defaults to "password" + type: string + name: + description: Name is the name of the secret storing this user's + password + type: string + required: + - name + type: object + port: + description: Port where metrics endpoint will bind to. Defaults + to 9216. + type: integer + tlsSecretKeyRef: + description: Name of a Secret (type kubernetes.io/tls) holding + the certificates to use in the Prometheus endpoint. + properties: + key: + description: Key is the key in the secret storing this password. + Defaults to "password" + type: string + name: + description: Name is the name of the secret storing this + user's password + type: string + required: + - name + type: object + username: + description: HTTP Basic Auth Username for metrics endpoint. + type: string + required: + - passwordSecretRef + - username + type: object + replicaSetHorizons: + description: ReplicaSetHorizons Add this parameter and values if you + need your database to be accessed outside of Kubernetes. This setting + allows you to provide different DNS settings within the Kubernetes + cluster and to the Kubernetes cluster. The Kubernetes Operator uses + split horizon DNS for replica set members. This feature allows communication + both within the Kubernetes cluster and from outside Kubernetes. + items: + additionalProperties: + type: string + type: object + type: array + security: + description: Security configures security features, such as TLS, and + authentication settings for a deployment + properties: + authentication: + properties: + agentCertificateSecretRef: + description: 'AgentCertificateSecret is a reference to a Secret + containing the certificate and the key for the automation + agent The secret needs to have available: - certificate + under key: "tls.crt" - private key under key: "tls.key" + If additionally, tls.pem is present, then it needs to be + equal to the concatenation of tls.crt and tls.key' + properties: + name: + description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + TODO: Add other useful fields. apiVersion, kind, uid?' + type: string + type: object + x-kubernetes-map-type: atomic + agentMode: + description: AgentMode contains the authentication mode used + by the automation agent. + enum: + - SCRAM + - SCRAM-SHA-256 + - SCRAM-SHA-1 + - X509 + type: string + ignoreUnknownUsers: + default: true + nullable: true + type: boolean + modes: + description: Modes is an array specifying which authentication + methods should be enabled. + items: + enum: + - SCRAM + - SCRAM-SHA-256 + - SCRAM-SHA-1 + - X509 + type: string + type: array + required: + - modes + type: object + roles: + description: User-specified custom MongoDB roles that should be + configured in the deployment. + items: + description: CustomRole defines a custom MongoDB role. + properties: + authenticationRestrictions: + description: The authentication restrictions the server + enforces on the role. + items: + description: AuthenticationRestriction specifies a list + of IP addresses and CIDR ranges users are allowed to + connect to or from. + properties: + clientSource: + items: + type: string + type: array + serverAddress: + items: + type: string + type: array + required: + - clientSource + - serverAddress + type: object + type: array + db: + description: The database of the role. + type: string + privileges: + description: The privileges to grant the role. + items: + description: Privilege defines the actions a role is allowed + to perform on a given resource. + properties: + actions: + items: + type: string + type: array + resource: + description: Resource specifies specifies the resources + upon which a privilege permits actions. See https://www.mongodb.com/docs/manual/reference/resource-document + for more. + properties: + anyResource: + type: boolean + cluster: + type: boolean + collection: + type: string + db: + type: string + type: object + required: + - actions + - resource + type: object + type: array + role: + description: The name of the role. + type: string + roles: + description: An array of roles from which this role inherits + privileges. + items: + description: Role is the database role this user should + have + properties: + db: + description: DB is the database the role can act on + type: string + name: + description: Name is the name of the role + type: string + required: + - db + - name + type: object + type: array + required: + - db + - privileges + - role + type: object + type: array + tls: + description: TLS configuration for both client-server and server-server + communication + properties: + caCertificateSecretRef: + description: CaCertificateSecret is a reference to a Secret + containing the certificate for the CA which signed the server + certificates The certificate is expected to be available + under the key "ca.crt" + properties: + name: + description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + TODO: Add other useful fields. apiVersion, kind, uid?' + type: string + type: object + x-kubernetes-map-type: atomic + caConfigMapRef: + description: CaConfigMap is a reference to a ConfigMap containing + the certificate for the CA which signed the server certificates + The certificate is expected to be available under the key + "ca.crt" This field is ignored when CaCertificateSecretRef + is configured + properties: + name: + description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + TODO: Add other useful fields. apiVersion, kind, uid?' + type: string + type: object + x-kubernetes-map-type: atomic + certificateKeySecretRef: + description: CertificateKeySecret is a reference to a Secret + containing a private key and certificate to use for TLS. + The key and cert are expected to be PEM encoded and available + at "tls.key" and "tls.crt". This is the same format used + for the standard "kubernetes.io/tls" Secret type, but no + specific type is required. Alternatively, an entry tls.pem, + containing the concatenation of cert and key, can be provided. + If all of tls.pem, tls.crt and tls.key are present, the + tls.pem one needs to be equal to the concatenation of tls.crt + and tls.key + properties: + name: + description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + TODO: Add other useful fields. apiVersion, kind, uid?' + type: string + type: object + x-kubernetes-map-type: atomic + enabled: + type: boolean + optional: + description: Optional configures if TLS should be required + or optional for connections + type: boolean + required: + - enabled + type: object + type: object + statefulSet: + description: StatefulSetConfiguration holds the optional custom StatefulSet + that should be merged into the operator created one. + properties: + metadata: + description: StatefulSetMetadataWrapper is a wrapper around Labels + and Annotations + properties: + annotations: + additionalProperties: + type: string + type: object + labels: + additionalProperties: + type: string + type: object + type: object + spec: + type: object + x-kubernetes-preserve-unknown-fields: true + required: + - spec + type: object + type: + description: Type defines which type of MongoDB deployment the resource + should create + enum: + - ReplicaSet + type: string + users: + description: Users specifies the MongoDB users that should be configured + in your deployment + items: + properties: + additionalConnectionStringConfig: + description: Additional options to be appended to the connection + string. These options apply only to this user and will override + any existing options in the resource. + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + connectionStringSecretName: + description: ConnectionStringSecretName is the name of the secret + object created by the operator which exposes the connection + strings for the user. If provided, this secret must be different + for each user in a deployment. + type: string + db: + default: admin + description: DB is the database the user is stored in. Defaults + to "admin" + type: string + name: + description: Name is the username of the user + type: string + passwordSecretRef: + description: PasswordSecretRef is a reference to the secret + containing this user's password + properties: + key: + description: Key is the key in the secret storing this password. + Defaults to "password" + type: string + name: + description: Name is the name of the secret storing this + user's password + type: string + required: + - name + type: object + roles: + description: Roles is an array of roles assigned to this user + items: + description: Role is the database role this user should have + properties: + db: + description: DB is the database the role can act on + type: string + name: + description: Name is the name of the role + type: string + required: + - db + - name + type: object + type: array + scramCredentialsSecretName: + description: ScramCredentialsSecretName appended by string "scram-credentials" + is the name of the secret object created by the mongoDB operator + for storing SCRAM credentials These secrets names must be + different for each user in a deployment. + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + required: + - name + - roles + type: object + type: array + version: + description: Version defines which version of MongoDB will be used + type: string + required: + - security + - type + - users + type: object + status: + description: MongoDBCommunityStatus defines the observed state of MongoDB + properties: + currentMongoDBArbiters: + type: integer + currentMongoDBMembers: + type: integer + currentStatefulSetArbitersReplicas: + type: integer + currentStatefulSetReplicas: + type: integer + message: + type: string + mongoUri: + type: string + phase: + type: string + version: + type: string + required: + - currentMongoDBMembers + - currentStatefulSetReplicas + - mongoUri + - phase + type: object + type: object + served: true + storage: true + subresources: + status: {} diff --git a/cluster-applications/025-mongodb-ce/templates/01-namespace.yaml b/cluster-applications/025-mongodb-ce/templates/02-namespace.yaml similarity index 100% rename from cluster-applications/025-mongodb-ce/templates/01-namespace.yaml rename to cluster-applications/025-mongodb-ce/templates/02-namespace.yaml diff --git a/cluster-applications/025-mongodb-ce/templates/03-admin-secret.yaml b/cluster-applications/025-mongodb-ce/templates/03-admin-secret.yaml deleted file mode 100644 index dd00c8816..000000000 --- a/cluster-applications/025-mongodb-ce/templates/03-admin-secret.yaml +++ /dev/null @@ -1,15 +0,0 @@ ---- -apiVersion: v1 -kind: Secret -metadata: - name: admin-user-credentials - namespace: {{ .Values.mongodb_namespace | default "mongoce" }} - annotations: - argocd.argoproj.io/sync-wave: "024" -{{- if .Values.custom_labels }} - labels: -{{ .Values.custom_labels | toYaml | indent 4 }} -{{- end }} -type: Opaque -stringData: - password: "{{ .Values.admin_password }}" diff --git a/cluster-applications/025-mongodb-ce/templates/01b-scc-anyuid.yaml b/cluster-applications/025-mongodb-ce/templates/03-scc-anyuid.yaml similarity index 100% rename from cluster-applications/025-mongodb-ce/templates/01b-scc-anyuid.yaml rename to cluster-applications/025-mongodb-ce/templates/03-scc-anyuid.yaml diff --git a/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml b/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml deleted file mode 100644 index f001491ab..000000000 --- a/cluster-applications/025-mongodb-ce/templates/04-mongodb-community-cr.yaml +++ /dev/null @@ -1,53 +0,0 @@ ---- -apiVersion: mongodbcommunity.mongodb.com/v1 -kind: MongoDBCommunity -metadata: - name: {{ .Values.mongodb_instance_name | default "mas-mongo-ce" }} - namespace: {{ .Values.mongodb_namespace | default "mongoce" }} - annotations: - argocd.argoproj.io/sync-wave: "025" - argocd.argoproj.io/sync-options: SkipDryRunOnMissingResource=true - mongodb-image-version: "{{ .Values.mongodb_version | default "7.0.12" }}" -{{- if .Values.custom_labels }} - labels: -{{ .Values.custom_labels | toYaml | indent 4 }} -{{- end }} -spec: - members: {{ .Values.mongodb_members | default 3 }} - type: ReplicaSet - version: {{ .Values.mongodb_version | default "7.0.12" | quote }} - security: - authentication: - modes: - - SCRAM - users: - - name: admin - db: admin - passwordSecretRef: - name: admin-user-credentials - roles: - - name: root - db: admin - scramCredentialsSecretName: admin-user-credentials - statefulSet: - spec: - template: - spec: - containers: - - name: mongod - image: "quay.io/mongodb/mongodb-community-server:{{ .Values.mongodb_version | default "7.0.12" }}-ubi8" - resources: -{{ .Values.resources | toYaml | indent 16 }} -{{- if .Values.storage_size }} - volumeClaimTemplates: - - metadata: - name: data-volume - spec: - accessModes: [ "ReadWriteOnce" ] - {{- if .Values.storage_class }} - storageClassName: "{{ .Values.storage_class }}" - {{- end }} - resources: - requests: - storage: "{{ .Values.storage_size }}" -{{- end }} diff --git a/cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml b/cluster-applications/025-mongodb-ce/templates/04-operator-deployment.yaml similarity index 100% rename from cluster-applications/025-mongodb-ce/templates/02-operator-deployment.yaml rename to cluster-applications/025-mongodb-ce/templates/04-operator-deployment.yaml diff --git a/cluster-applications/025-mongodb-ce/templates/05-password-gen-job.yaml b/cluster-applications/025-mongodb-ce/templates/05-password-gen-job.yaml new file mode 100644 index 000000000..af9e4544c --- /dev/null +++ b/cluster-applications/025-mongodb-ce/templates/05-password-gen-job.yaml @@ -0,0 +1,170 @@ +{{- /* +Generates random passwords for MongoDB and stores them as K8s Secrets. + +Mirrors what ansible does with: + lookup('password', '/tmp/mongoce-password.txt chars=ascii_letters,digits length=16') + +This Job runs at wave 023 (PreSync hook, BeforeHookCreation delete policy) so it +fires before the admin secret (wave 024) and MongoDBCommunity CR (wave 025). + +Idempotent: if Secret mas-mongo-ce-admin-password already exists and has a +non-empty password key, this job skips generation and exits 0. This means +the password is generated ONCE on first install and never rotated by re-syncs. +*/}} +{{- $ns := .Values.mongodb_namespace | default "mongoce" }} +{{- $instance := .Values.mongodb_instance_name | default "mas-mongo-ce" }} +{{- $sa_name := "mongo-password-gen-sa" }} +{{- $role_name := "mongo-password-gen-role" }} +{{- $rb_name := "mongo-password-gen-rb" }} + +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ $sa_name }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/hook: PreSync + argocd.argoproj.io/hook-delete-policy: BeforeHookCreation +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} + +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: {{ $role_name }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/hook: PreSync + argocd.argoproj.io/hook-delete-policy: BeforeHookCreation +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +rules: + - apiGroups: [""] + resources: [secrets] + verbs: [get, create, patch] + +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: {{ $rb_name }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/hook: PreSync + argocd.argoproj.io/hook-delete-policy: BeforeHookCreation +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +subjects: + - kind: ServiceAccount + name: {{ $sa_name }} + namespace: {{ $ns }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: {{ $role_name }} + +--- +apiVersion: batch/v1 +kind: Job +metadata: + name: mongo-password-gen-job + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/hook: PreSync + argocd.argoproj.io/hook-delete-policy: BeforeHookCreation +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +spec: + backoffLimit: 3 + template: + spec: + serviceAccountName: {{ $sa_name }} + restartPolicy: OnFailure + containers: + - name: generate-passwords + image: quay.io/openshift/origin-cli:latest + imagePullPolicy: IfNotPresent + resources: + limits: + cpu: 100m + memory: 128Mi + requests: + cpu: 10m + memory: 32Mi + env: + - name: MONGO_NAMESPACE + value: "{{ $ns }}" + - name: INSTANCE_NAME + value: "{{ $instance }}" + command: + - /bin/bash + - -c + - | + set -e + NS="${MONGO_NAMESPACE}" + ADMIN_SECRET="mas-mongo-ce-admin-password" + METRICS_SECRET="mas-mongo-ce-metrics-endpoint-secret" + + # ----------------------------------------------------------------------- + # Generate admin password + # Idempotent: skip if secret already exists with a non-empty password. + # Mirrors ansible: lookup('password', '/tmp/mongoce-password.txt + # chars=ascii_letters,digits length=16') + # ----------------------------------------------------------------------- + EXISTING=$(oc get secret "${ADMIN_SECRET}" -n "${NS}" \ + -o jsonpath='{.data.password}' 2>/dev/null || true) + + if [[ -n "${EXISTING}" ]]; then + echo "Secret ${ADMIN_SECRET} already exists — skipping password generation (idempotent)" + else + echo "Generating random admin password for ${ADMIN_SECRET} ..." + # Generate 16-char alphanumeric password (same charset as ansible lookup) + ADMIN_PASSWORD=$(cat /dev/urandom \ + | tr -dc 'A-Za-z0-9' \ + | head -c 16) + + oc create secret generic "${ADMIN_SECRET}" \ + -n "${NS}" \ + --from-literal=password="${ADMIN_PASSWORD}" \ + --dry-run=client -o yaml \ + | oc apply -f - + + echo "Secret ${ADMIN_SECRET} created with generated password" + fi + + # ----------------------------------------------------------------------- + # Generate metrics endpoint password + # Idempotent: skip if secret already exists with a non-empty password. + # ----------------------------------------------------------------------- + EXISTING_METRICS=$(oc get secret "${METRICS_SECRET}" -n "${NS}" \ + -o jsonpath='{.data.password}' 2>/dev/null || true) + + if [[ -n "${EXISTING_METRICS}" ]]; then + echo "Secret ${METRICS_SECRET} already exists — skipping (idempotent)" + else + echo "Generating random metrics password for ${METRICS_SECRET} ..." + METRICS_PASSWORD=$(cat /dev/urandom \ + | tr -dc 'A-Za-z0-9' \ + | head -c 16) + + oc create secret generic "${METRICS_SECRET}" \ + -n "${NS}" \ + --from-literal=username="metrics-endpoint-user" \ + --from-literal=password="${METRICS_PASSWORD}" \ + --dry-run=client -o yaml \ + | oc apply -f - + + echo "Secret ${METRICS_SECRET} created with generated password" + fi + + echo "Done." diff --git a/cluster-applications/025-mongodb-ce/templates/05-postsync-update-sm_Job.yaml b/cluster-applications/025-mongodb-ce/templates/05-postsync-update-sm_Job.yaml deleted file mode 100644 index 70b31e9b3..000000000 --- a/cluster-applications/025-mongodb-ce/templates/05-postsync-update-sm_Job.yaml +++ /dev/null @@ -1,242 +0,0 @@ -{{- if and .Values.run_sync_hooks .Values.cluster_admin_role }} - -{{- /* -Meaningful prefix for the job resource name. Must be under 52 chars in length. -*/}} -{{- $_job_name_prefix := "postsync-mongo-update-sm-job" }} - -{{- /* -CLI image digest -*/}} -{{- $_cli_image_digest := "sha256:1dc8665fddb9546b84290b0615fc7c7017e19516082b35541d41b8ea82df347b" }} - -{{- $_job_config_values := omit .Values "junitreporter" }} -{{- $_job_version := "v1" }} -{{- $_job_hash := print ($_job_config_values | toYaml) $_cli_image_digest $_job_version | adler32sum }} -{{- $_job_name := join "-" (list $_job_name_prefix $_job_hash )}} -{{- $_job_cleanup_group := cat $_job_name_prefix | sha1sum }} - -{{ $ns := .Values.mongodb_namespace | default "mongoce" }} -{{ $aws_secret := "mongo-aws-creds" }} -{{ $role_name := "postsync-mongo-update-sm-r" }} -{{ $sa_name := "postsync-mongo-update-sm-sa" }} -{{ $rb_name := "postsync-mongo-update-sm-rb" }} - ---- -kind: Secret -apiVersion: v1 -metadata: - name: {{ $aws_secret }} - namespace: {{ $ns }} - annotations: - argocd.argoproj.io/sync-wave: "026" -{{- if .Values.custom_labels }} - labels: -{{ .Values.custom_labels | toYaml | indent 4 }} -{{- end }} -data: - aws_access_key_id: {{ .Values.sm_aws_access_key_id | default "" | b64enc }} - aws_secret_access_key: {{ .Values.sm_aws_secret_access_key | default "" | b64enc }} -type: Opaque - ---- -kind: ServiceAccount -apiVersion: v1 -metadata: - name: {{ $sa_name }} - namespace: {{ $ns }} - annotations: - argocd.argoproj.io/sync-wave: "026" -{{- if .Values.custom_labels }} - labels: -{{ .Values.custom_labels | toYaml | indent 4 }} -{{- end }} - ---- -kind: ClusterRole -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: {{ $role_name }} - annotations: - argocd.argoproj.io/sync-wave: "026" -{{- if .Values.custom_labels }} - labels: -{{ .Values.custom_labels | toYaml | indent 4 }} -{{- end }} -rules: - - verbs: - - get - - list - - watch - apiGroups: - - "" - resources: - - secrets - - services - - pods - - verbs: - - get - - list - - watch - apiGroups: - - mongodbcommunity.mongodb.com - resources: - - mongodbcommunity - ---- -kind: ClusterRoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: {{ $rb_name }} - annotations: - argocd.argoproj.io/sync-wave: "027" -{{- if .Values.custom_labels }} - labels: -{{ .Values.custom_labels | toYaml | indent 4 }} -{{- end }} -subjects: - - kind: ServiceAccount - name: {{ $sa_name }} - namespace: {{ $ns }} -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: {{ $role_name }} - ---- -apiVersion: batch/v1 -kind: Job -metadata: - name: {{ $_job_name }} - namespace: {{ $ns }} - annotations: - argocd.argoproj.io/sync-wave: "028" - labels: - mas.ibm.com/job-cleanup-group: {{ $_job_cleanup_group }} -{{- if .Values.custom_labels }} -{{ .Values.custom_labels | toYaml | indent 4 }} -{{- end }} -spec: - template: -{{- if .Values.custom_labels }} - metadata: - labels: -{{ .Values.custom_labels | toYaml | indent 8 }} -{{- end }} - spec: - serviceAccountName: {{ $sa_name }} - restartPolicy: Never - volumes: - - name: aws - secret: - secretName: {{ $aws_secret }} - defaultMode: 420 - optional: false - containers: - - name: run - image: {{ .Values.cli_image_repo | default "quay.io/ibmmas/cli" }}@{{ $_cli_image_digest }} - imagePullPolicy: IfNotPresent - resources: - limits: - cpu: 200m - memory: 512Mi - requests: - cpu: 10m - memory: 64Mi - volumeMounts: - - name: aws - mountPath: /etc/mas/creds/aws - env: - - name: ACCOUNT_ID - value: "{{ .Values.account_id }}" - - name: REGION_ID - value: "{{ .Values.region_id }}" - - name: CLUSTER_ID - value: "{{ .Values.cluster_id }}" - - name: MONGO_NAMESPACE - value: "{{ $ns }}" - - name: MONGO_INSTANCE_NAME - value: "{{ .Values.mongodb_instance_name | default "mas-mongo-ce" }}" - - name: MONGO_ADMIN_PASSWORD - value: "{{ .Values.admin_password }}" - - name: MONGO_MEMBERS - value: "{{ .Values.mongodb_members | default 3 }}" - command: - - /bin/bash - - -c - - | - set -e - source /mascli/functions/gitops_utils - SM_AWS_ACCESS_KEY_ID=$(cat /etc/mas/creds/aws/aws_access_key_id) - SM_AWS_SECRET_ACCESS_KEY=$(cat /etc/mas/creds/aws/aws_secret_access_key) - export SM_AWS_REGION=${REGION_ID} - sm_login - - echo "Waiting for MongoDBCommunity ${MONGO_INSTANCE_NAME} in ${MONGO_NAMESPACE}" - for (( c=1; c<=30; c++ )); do - echo "... check attempt ${c} of 30" - PHASE=$(oc get mongodbcommunity "${MONGO_INSTANCE_NAME}" -n "${MONGO_NAMESPACE}" -o=jsonpath='{.status.phase}' 2>/dev/null || true) - echo "Current Phase: ${PHASE}" - if [[ "${PHASE}" == "Running" ]]; then - echo "MongoDBCommunity instance is Running!" - break - fi - sleep 20 - done - - CA_CERT="" - CA_SECRET_NAME="${MONGO_INSTANCE_NAME}-ca" - if oc get secret "${CA_SECRET_NAME}" -n "${MONGO_NAMESPACE}" >/dev/null 2>&1; then - CA_CERT=$(oc get secret "${CA_SECRET_NAME}" -n "${MONGO_NAMESPACE}" -o=jsonpath='{.data.ca\.crt}' | base64 -d 2>/dev/null || true) - fi - export CA_CERT - - cat > /tmp/build_secret.py << 'PYEOF' - import os, json - account = os.environ.get('ACCOUNT_ID') - cluster = os.environ.get('CLUSTER_ID') - instance_name = os.environ.get('MONGO_INSTANCE_NAME') - namespace = os.environ.get('MONGO_NAMESPACE') - members = int(os.environ.get('MONGO_MEMBERS', '3')) - password = os.environ.get('MONGO_ADMIN_PASSWORD') - ca_cert = os.environ.get('CA_CERT', '') - primary_host = f'{instance_name}-0.{instance_name}-svc.{namespace}.svc.cluster.local' - info_lines = ['config:', ' hosts:'] - for i in range(members): - info_lines.append(f' - host: {instance_name}-{i}.{instance_name}-svc.{namespace}.svc.cluster.local') - info_lines.append(' port: 27017') - info_lines.append(' configDb: admin') - info_lines.append(' authMechanism: DEFAULT') - if ca_cert: - info_lines.append('certificates:') - info_lines.append(' - alias: ca') - info_lines.append(' crt: |') - for line in ca_cert.strip().split('\n'): - info_lines.append(f' {line}') - info_str = '\n'.join(info_lines) + '\n' - payload = { - 'docdb_host': primary_host, - 'docdb_port': '27017', - 'username': 'admin', - 'password': password, - 'info': info_str - } - tags = json.dumps([ - {'Key': 'source', 'Value': 'postsync-mongo-update-sm-job'}, - {'Key': 'account', 'Value': account}, - {'Key': 'cluster', 'Value': cluster} - ]) - with open('/tmp/secret_payload.json', 'w') as f: - f.write(json.dumps(payload)) - with open('/tmp/secret_tags.json', 'w') as f: - f.write(tags) - PYEOF - - python3 /tmp/build_secret.py - - SECRET_NAME_MONGO="${ACCOUNT_ID}/${CLUSTER_ID}/mongodatabase" - echo "Updating AWS Secret: ${SECRET_NAME_MONGO}" - sm_update_secret "${SECRET_NAME_MONGO}" "$(cat /tmp/secret_payload.json)" "$(cat /tmp/secret_tags.json)" || exit $? - echo "Successfully registered MongoDB credentials and info secret to AWS Secrets Manager!" - backoffLimit: 4 -{{- end }} diff --git a/cluster-applications/025-mongodb-ce/templates/06-tls-certs.yaml b/cluster-applications/025-mongodb-ce/templates/06-tls-certs.yaml new file mode 100644 index 000000000..1556f0901 --- /dev/null +++ b/cluster-applications/025-mongodb-ce/templates/06-tls-certs.yaml @@ -0,0 +1,102 @@ +{{- /* +TLS certificate chain for MongoDB Community — mirrors what the ansible-devops +mongodb role creates in steps 7 of install-mongo.yml: + - issuer.yml → mongo-issuer (selfSigned Issuer) + - ca-cert.yml → mongo-ca-crt (CA Certificate → produces mongo-ca-secret) + - server-cert-issuer.yml → mongo-server-cert-issuer (Issuer backed by mongo-ca-secret) + - server-cert.yml → mongo-server (server Certificate → produces mongo-server-cert) + - tls.yml → mas-mongo-ce-cert-map (ConfigMap with ca.crt extracted from mongo-server-cert) + +The MongoDBCommunity CR references: + security.tls.certificateKeySecretRef.name: mongo-server-cert + security.tls.caConfigMapRef.name: mas-mongo-ce-cert-map +*/}} +{{- $ns := .Values.mongodb_namespace | default "mongoce" }} +{{- $instance := .Values.mongodb_instance_name | default "mas-mongo-ce" }} + +--- +# Self-signed root Issuer +apiVersion: cert-manager.io/v1 +kind: Issuer +metadata: + name: mongo-issuer + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "023" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +spec: + selfSigned: {} + +--- +# CA Certificate — cert-manager creates Secret 'mongo-ca-secret' from this +apiVersion: cert-manager.io/v1 +kind: Certificate +metadata: + name: mongo-ca-crt + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "023" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +spec: + isCA: true + commonName: mongo-ca-crt + secretName: mongo-ca-secret + duration: 175200h # 20 years + privateKey: + algorithm: ECDSA + size: 256 + dnsNames: + - "*.{{ $instance }}-svc.{{ $ns }}.svc.cluster.local" + - "127.0.0.1" + - "localhost" + issuerRef: + name: mongo-issuer + kind: Issuer + group: cert-manager.io + +--- +# Server certificate Issuer — backed by the CA secret produced above +apiVersion: cert-manager.io/v1 +kind: Issuer +metadata: + name: mongo-server-cert-issuer + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "024" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +spec: + ca: + secretName: mongo-ca-secret + +--- +# Server TLS Certificate — cert-manager creates Secret 'mongo-server-cert' from this +apiVersion: cert-manager.io/v1 +kind: Certificate +metadata: + name: mongo-server + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "024" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +spec: + duration: 8760h # 365 days + renewBefore: 360h # 15 days + dnsNames: + - "*.{{ $instance }}-svc.{{ $ns }}.svc.cluster.local" + - "127.0.0.1" + - "localhost" + issuerRef: + name: mongo-server-cert-issuer + secretName: mongo-server-cert diff --git a/cluster-applications/025-mongodb-ce/templates/07-ca-configmap-job.yaml b/cluster-applications/025-mongodb-ce/templates/07-ca-configmap-job.yaml new file mode 100644 index 000000000..2a7301728 --- /dev/null +++ b/cluster-applications/025-mongodb-ce/templates/07-ca-configmap-job.yaml @@ -0,0 +1,148 @@ +{{- /* +Extract ca.crt from the cert-manager-generated Secret 'mongo-ca-secret' and write it into +ConfigMap 'mas-mongo-ce-cert-map' — exactly what the ansible role does in tls.yml after +reading mongodb_ca_lookup.resources[0].data['ca.crt']. + +The ConfigMap is referenced by the MongoDBCommunity CR at: + spec.security.tls.caConfigMapRef.name: mas-mongo-ce-cert-map + +This must run AFTER cert-manager has issued mongo-ca-secret (waves 023-024) and +BEFORE the MongoDBCommunity CR (wave 025). +*/}} +{{- $ns := .Values.mongodb_namespace | default "mongoce" }} +{{- $sa_name := "mongo-ca-configmap-sa" }} +{{- $role_name := "mongo-ca-configmap-role" }} +{{- $rb_name := "mongo-ca-configmap-rb" }} +{{- $job_name := "mongo-ca-configmap-job" }} + +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ $sa_name }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "024" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} + +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: {{ $role_name }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "024" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +rules: + - apiGroups: [""] + resources: [secrets] + verbs: [get] + - apiGroups: [""] + resources: [configmaps] + verbs: [get, create, update, patch] + +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: {{ $rb_name }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "024" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +subjects: + - kind: ServiceAccount + name: {{ $sa_name }} + namespace: {{ $ns }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: {{ $role_name }} + +--- +# Job: extract ca.crt from mongo-ca-secret → create mas-mongo-ce-cert-map ConfigMap +apiVersion: batch/v1 +kind: Job +metadata: + name: {{ $job_name }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "024" + argocd.argoproj.io/hook: Sync + argocd.argoproj.io/hook-delete-policy: BeforeHookCreation +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +spec: + backoffLimit: 10 + template: + spec: + serviceAccountName: {{ $sa_name }} + restartPolicy: OnFailure + containers: + - name: create-ca-configmap + image: quay.io/openshift/origin-cli:latest + imagePullPolicy: IfNotPresent + resources: + limits: + cpu: 100m + memory: 128Mi + requests: + cpu: 10m + memory: 32Mi + command: + - /bin/bash + - -c + - | + set -e + NS="{{ $ns }}" + INSTANCE="{{ .Values.mongodb_instance_name | default "mas-mongo-ce" }}" + CA_SECRET="mongo-ca-secret" + CM_NAME="mas-mongo-ce-cert-map" + + echo "Waiting for cert-manager to issue ${CA_SECRET} ..." + for (( i=1; i<=30; i++ )); do + if oc get secret "${CA_SECRET}" -n "${NS}" >/dev/null 2>&1; then + echo " secret found on attempt ${i}" + break + fi + echo " attempt ${i}/30 — not ready yet, sleeping 10s ..." + sleep 10 + done + + CA_CRT=$(oc get secret "${CA_SECRET}" -n "${NS}" \ + -o jsonpath='{.data.ca\.crt}' | base64 -d) + + if [[ -z "${CA_CRT}" ]]; then + echo "ERROR: ca.crt is empty in secret ${CA_SECRET}" + exit 1 + fi + + echo "Extracted CA certificate (${#CA_CRT} bytes), creating ConfigMap ${CM_NAME} ..." + + # Write literal YAML so the cert indentation is preserved correctly + CA_CRT_INDENTED=$(echo "${CA_CRT}" | sed 's/^/ /') + + oc apply -n "${NS}" -f - << YAML + apiVersion: v1 + kind: ConfigMap + metadata: + name: ${CM_NAME} + namespace: ${NS} + data: + ca.crt: | + ${CA_CRT_INDENTED} + YAML + + echo "SUCCESS: ConfigMap ${CM_NAME} created/updated" diff --git a/cluster-applications/025-mongodb-ce/templates/08-mongodb-community-cr.yaml b/cluster-applications/025-mongodb-ce/templates/08-mongodb-community-cr.yaml new file mode 100644 index 000000000..0709af5a3 --- /dev/null +++ b/cluster-applications/025-mongodb-ce/templates/08-mongodb-community-cr.yaml @@ -0,0 +1,100 @@ +{{- /* +MongoDBCommunity CR — mirrors ansible-devops: templates/community/0.9.0/cr.yml.j2 +Key alignments vs previous version: + - security.tls enabled, referencing mongo-server-cert + mas-mongo-ce-cert-map + - authentication modes: SCRAM-SHA-256 + SCRAM-SHA-1 (MAS 8.5 compat) + - prometheus metrics endpoint referencing mas-mongo-ce-metrics-endpoint-secret + - passwordSecretRef: mas-mongo-ce-admin-password (matches ansible) + - scramCredentialsSecretName: mas-mongo-ce-scram (matches ansible) + - user roles: clusterAdmin, userAdminAnyDatabase, dbOwner, readWriteAnyDatabase + - statefulSet.spec.serviceName: mas-mongo-ce-svc + - additionalMongodConfig: snappy journal compression + TLS invalid cert allowances + - volumeClaimTemplates: data-volume + logs-volume (matches ansible) +*/}} +{{- $ns := .Values.mongodb_namespace | default "mongoce" }} +{{- $instance := .Values.mongodb_instance_name | default "mas-mongo-ce" }} +--- +apiVersion: mongodbcommunity.mongodb.com/v1 +kind: MongoDBCommunity +metadata: + name: {{ $instance }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "025" + argocd.argoproj.io/sync-options: SkipDryRunOnMissingResource=true + mongodb-image-version: "{{ .Values.mongodb_version | default "7.0.12" }}" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +spec: + members: {{ .Values.mongodb_members | default 3 }} + type: ReplicaSet + version: "{{ .Values.mongodb_version | default "7.0.12" }}" + featureCompatibilityVersion: "{{ .Values.mongodb_version | default "7.0.12" | splitList "." | initial | join "." }}" + security: + tls: + enabled: true + certificateKeySecretRef: + name: mongo-server-cert + caConfigMapRef: + name: mas-mongo-ce-cert-map + authentication: + modes: + - SCRAM-SHA-256 + - SCRAM-SHA-1 + prometheus: + username: metrics-endpoint-user + passwordSecretRef: + name: mas-mongo-ce-metrics-endpoint-secret + users: + - name: admin + db: admin + passwordSecretRef: + name: mas-mongo-ce-admin-password + roles: + - name: clusterAdmin + db: admin + - name: userAdminAnyDatabase + db: admin + - name: dbOwner + db: admin + - name: readWriteAnyDatabase + db: admin + scramCredentialsSecretName: mas-mongo-ce-scram + additionalMongodConfig: + storage.wiredTiger.engineConfig.journalCompressor: snappy + net.tls.allowInvalidCertificates: true + net.tls.allowInvalidHostnames: true + statefulSet: + spec: + serviceName: {{ $instance }}-svc + selector: {} + template: + spec: + containers: + - name: mongod + image: "quay.io/mongodb/mongodb-community-server:{{ .Values.mongodb_version | default "7.0.12" }}-ubi8" + resources: +{{ .Values.resources | toYaml | indent 16 }} + volumeClaimTemplates: + - metadata: + name: data-volume + spec: + accessModes: ["ReadWriteOnce"] + {{- if .Values.storage_class }} + storageClassName: "{{ .Values.storage_class }}" + {{- end }} + resources: + requests: + storage: "{{ .Values.storage_size | default "10Gi" }}" + - metadata: + name: logs-volume + spec: + accessModes: ["ReadWriteOnce"] + {{- if .Values.storage_class }} + storageClassName: "{{ .Values.storage_class }}" + {{- end }} + resources: + requests: + storage: "{{ .Values.logs_storage_size | default "1Gi" }}" diff --git a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml new file mode 100644 index 000000000..7a8fc284d --- /dev/null +++ b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml @@ -0,0 +1,318 @@ +{{- if and .Values.run_sync_hooks .Values.cluster_admin_role }} + +{{- /* +Meaningful prefix for the job resource name. Must be under 52 chars in length. +*/}} +{{- $_job_name_prefix := "postsync-mongo-update-sm-job" }} + +{{- /* +CLI image digest +*/}} +{{- $_cli_image_digest := "sha256:1dc8665fddb9546b84290b0615fc7c7017e19516082b35541d41b8ea82df347b" }} + +{{- $_job_config_values := omit .Values "junitreporter" }} +{{- $_job_version := "v1" }} +{{- $_job_hash := print ($_job_config_values | toYaml) $_cli_image_digest $_job_version | adler32sum }} +{{- $_job_name := join "-" (list $_job_name_prefix $_job_hash )}} +{{- $_job_cleanup_group := cat $_job_name_prefix | sha1sum }} + +{{ $ns := .Values.mongodb_namespace | default "mongoce" }} +{{ $aws_secret := "mongo-aws-creds" }} +{{ $role_name := "postsync-mongo-update-sm-r" }} +{{ $sa_name := "postsync-mongo-update-sm-sa" }} +{{ $rb_name := "postsync-mongo-update-sm-rb" }} + +--- +kind: Secret +apiVersion: v1 +metadata: + name: {{ $aws_secret }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "026" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +data: + aws_access_key_id: {{ .Values.sm_aws_access_key_id | default "" | b64enc }} + aws_secret_access_key: {{ .Values.sm_aws_secret_access_key | default "" | b64enc }} +type: Opaque + +--- +kind: ServiceAccount +apiVersion: v1 +metadata: + name: {{ $sa_name }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "026" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} + +--- +kind: ClusterRole +apiVersion: rbac.authorization.k8s.io/v1 +metadata: + name: {{ $role_name }} + annotations: + argocd.argoproj.io/sync-wave: "026" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +rules: + - verbs: + - get + - list + - watch + apiGroups: + - "" + resources: + - secrets + - services + - pods + - verbs: + - get + - list + - watch + apiGroups: + - mongodbcommunity.mongodb.com + resources: + - mongodbcommunity + +--- +kind: ClusterRoleBinding +apiVersion: rbac.authorization.k8s.io/v1 +metadata: + name: {{ $rb_name }} + annotations: + argocd.argoproj.io/sync-wave: "027" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +subjects: + - kind: ServiceAccount + name: {{ $sa_name }} + namespace: {{ $ns }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: {{ $role_name }} + +--- +apiVersion: batch/v1 +kind: Job +metadata: + name: {{ $_job_name }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "028" + labels: + mas.ibm.com/job-cleanup-group: {{ $_job_cleanup_group }} +{{- if .Values.custom_labels }} +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +spec: + template: +{{- if .Values.custom_labels }} + metadata: + labels: +{{ .Values.custom_labels | toYaml | indent 8 }} +{{- end }} + spec: + serviceAccountName: {{ $sa_name }} + restartPolicy: Never + volumes: + - name: aws + secret: + secretName: {{ $aws_secret }} + defaultMode: 420 + optional: false + containers: + - name: run + image: {{ .Values.cli_image_repo | default "quay.io/ibmmas/cli" }}@{{ $_cli_image_digest }} + imagePullPolicy: IfNotPresent + resources: + limits: + cpu: 200m + memory: 512Mi + requests: + cpu: 10m + memory: 64Mi + volumeMounts: + - name: aws + mountPath: /etc/mas/creds/aws + env: + - name: AVP_TYPE + value: "aws" + - name: ACCOUNT_ID + value: "{{ .Values.account_id }}" + - name: REGION_ID + value: "{{ .Values.region_id }}" + - name: CLUSTER_ID + value: "{{ .Values.cluster_id }}" + - name: MONGO_NAMESPACE + value: "{{ $ns }}" + - name: MONGO_INSTANCE_NAME + value: "{{ .Values.mongodb_instance_name | default "mas-mongo-ce" }}" + - name: MONGO_MEMBERS + value: "{{ .Values.mongodb_members | default 3 }}" + command: + - /bin/bash + - -c + - | + set -e + + SM_AWS_ACCESS_KEY_ID=$(cat /etc/mas/creds/aws/aws_access_key_id) + SM_AWS_SECRET_ACCESS_KEY=$(cat /etc/mas/creds/aws/aws_secret_access_key) + export SM_AWS_REGION="${REGION_ID}" + + # --------------------------------------------------------------------------- + # Wait for MongoDBCommunity CR to reach Running phase + # Mirrors: ansible install-mongo.yml step 11 — wait for StatefulSet ready + # --------------------------------------------------------------------------- + echo "Waiting for MongoDBCommunity/${MONGO_INSTANCE_NAME} in namespace ${MONGO_NAMESPACE} ..." + PHASE="" + for (( c=1; c<=30; c++ )); do + echo " attempt ${c}/30 ..." + PHASE=$(oc get mongodbcommunity "${MONGO_INSTANCE_NAME}" -n "${MONGO_NAMESPACE}" \ + -o jsonpath='{.status.phase}' 2>/dev/null || true) + echo " phase=${PHASE}" + [[ "${PHASE}" == "Running" ]] && break + sleep 20 + done + if [[ "${PHASE}" != "Running" ]]; then + echo "ERROR: MongoDBCommunity did not reach Running phase after 10 minutes. Aborting." + exit 1 + fi + + # --------------------------------------------------------------------------- + # Read the admin password from the operator-generated secret. + # Mirrors: ansible install-mongo.yml step 14 — + # "Lookup admin password" from secret mas-mongo-ce-admin-admin + # (name pattern: -- = mas-mongo-ce-admin-admin) + # The MongoDBCommunity operator creates this secret automatically after the + # CR reaches Running state. It contains the real working password. + # --------------------------------------------------------------------------- + ADMIN_SECRET_NAME="${MONGO_INSTANCE_NAME}-admin-admin" + echo "Reading admin password from operator-generated secret: ${ADMIN_SECRET_NAME}" + MONGO_ADMIN_PASSWORD="" + for (( c=1; c<=30; c++ )); do + echo " attempt ${c}/30 ..." + MONGO_ADMIN_PASSWORD=$(oc get secret "${ADMIN_SECRET_NAME}" -n "${MONGO_NAMESPACE}" \ + -o jsonpath='{.data.password}' 2>/dev/null | base64 -d 2>/dev/null || true) + if [[ -n "${MONGO_ADMIN_PASSWORD}" ]]; then + echo " admin password retrieved (${#MONGO_ADMIN_PASSWORD} chars)" + break + fi + sleep 20 + done + if [[ -z "${MONGO_ADMIN_PASSWORD}" ]]; then + echo "ERROR: Could not read admin password from secret ${ADMIN_SECRET_NAME} after 10 minutes." + exit 1 + fi + + # --------------------------------------------------------------------------- + # Fetch CA certificate from cert-manager-generated secret 'mongo-ca-secret' + # This is what the ansible role reads from mongodb_ca_lookup (mongo-server-cert) + # and writes into mas-mongo-ce-cert-map ConfigMap / suite_mongocfg.yml.j2 + # --------------------------------------------------------------------------- + CA_CERT_PEM="" + # Primary: use the CA secret created by cert-manager Certificate 'mongo-ca-crt' + for CA_SECRET_NAME in "mongo-ca-secret" "${MONGO_INSTANCE_NAME}-ca"; do + if oc get secret "${CA_SECRET_NAME}" -n "${MONGO_NAMESPACE}" >/dev/null 2>&1; then + echo "Found CA secret ${CA_SECRET_NAME}, extracting certificate ..." + CA_CERT_PEM=$(oc get secret "${CA_SECRET_NAME}" -n "${MONGO_NAMESPACE}" \ + -o jsonpath='{.data.ca\.crt}' | base64 -d 2>/dev/null || true) + if [[ -n "${CA_CERT_PEM}" ]]; then + echo "CA certificate extracted from ${CA_SECRET_NAME} (${#CA_CERT_PEM} bytes)" + break + fi + fi + done + if [[ -z "${CA_CERT_PEM}" ]]; then + echo "WARNING: No CA certificate found - secret will be written without TLS certificate" + fi + + # --------------------------------------------------------------------------- + # Build the 'info' YAML block (hosts + optional CA cert) using pure bash + # --------------------------------------------------------------------------- + INFO_YAML="config:"$'\n'" hosts:" + for (( i=0; i on subsequent syncs. + # This mirrors the ansible flow where the password is readable from K8s + # secret mas-mongo-ce-admin-admin after the operator sets it up. + # --------------------------------------------------------------------------- + PRIMARY_HOST="${MONGO_INSTANCE_NAME}-0.${MONGO_INSTANCE_NAME}-svc.${MONGO_NAMESPACE}.svc.cluster.local" + + # Read metrics password from the metrics-endpoint secret (operator leaves it as-is) + MONGO_METRICS_PASSWORD=$(oc get secret "mas-mongo-ce-metrics-endpoint-secret" \ + -n "${MONGO_NAMESPACE}" -o jsonpath='{.data.password}' 2>/dev/null \ + | base64 -d 2>/dev/null || true) + + SECRET_VALUE=$(jq -n \ + --arg docdb_host "${PRIMARY_HOST}" \ + --arg docdb_port "27017" \ + --arg username "admin" \ + --arg password "${MONGO_ADMIN_PASSWORD}" \ + --arg admin_password "${MONGO_ADMIN_PASSWORD}" \ + --arg metrics_password "${MONGO_METRICS_PASSWORD}" \ + --arg info "${INFO_YAML}" \ + '{docdb_host: $docdb_host, docdb_port: $docdb_port, username: $username, password: $password, admin_password: $admin_password, metrics_password: $metrics_password, info: $info}') + + TAGS=$(jq -n \ + --arg account "${ACCOUNT_ID}" \ + --arg cluster "${CLUSTER_ID}" \ + '[ + {"Key":"source", "Value":"postsync-mongo-update-sm-job"}, + {"Key":"account", "Value":$account}, + {"Key":"cluster", "Value":$cluster} + ]') + + echo "${SECRET_VALUE}" > /tmp/secret_payload.json + echo "${TAGS}" > /tmp/secret_tags.json + + # --------------------------------------------------------------------------- + # Login to AWS SM and upsert the secret + # --------------------------------------------------------------------------- + source /mascli/functions/gitops_utils + sm_login + + SECRET_NAME_MONGO="${ACCOUNT_ID}/${CLUSTER_ID}/mongodatabase" + echo "Upserting AWS Secrets Manager secret: ${SECRET_NAME_MONGO}" + sm_update_secret \ + "${SECRET_NAME_MONGO}" \ + "$(cat /tmp/secret_payload.json)" \ + "$(cat /tmp/secret_tags.json)" || exit $? + + echo "SUCCESS: MongoDB credentials stored at ${SECRET_NAME_MONGO}" + backoffLimit: 4 +{{- end }} diff --git a/cluster-applications/025-mongodb-ce/values.yaml b/cluster-applications/025-mongodb-ce/values.yaml index 129aa3efa..9fa1957b4 100644 --- a/cluster-applications/025-mongodb-ce/values.yaml +++ b/cluster-applications/025-mongodb-ce/values.yaml @@ -15,9 +15,9 @@ mongodb_instance_name: "mas-mongo-ce" mongodb_version: "7.0.12" mongodb_members: 3 -# Credentials & Storage -admin_password: "ChangeMe123!" +# Storage storage_size: "10Gi" +logs_storage_size: "1Gi" storage_class: "" # Resources diff --git a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml index 4168bcfd7..e4584bac9 100644 --- a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml +++ b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml @@ -47,8 +47,8 @@ spec: mongodb_instance_name: "{{ .Values.ibm_mongodb.instance_name | default "mas-mongo-ce" }}" mongodb_version: "{{ .Values.ibm_mongodb.mongo_ce_version | default "7.0.12" }}" mongodb_members: {{ .Values.ibm_mongodb.members | default 3 }} - admin_password: "{{ .Values.ibm_mongodb.admin_password }}" storage_size: "{{ .Values.ibm_mongodb.storage_size | default "10Gi" }}" + logs_storage_size: "{{ .Values.ibm_mongodb.logs_storage_size | default "1Gi" }}" storage_class: "{{ .Values.ibm_mongodb.mongo_ce_storage_class | default "" }}" {{- if .Values.custom_labels }} custom_labels: {{ .Values.custom_labels | toYaml | nindent 14 }} From 6dabed8a69b294a51a9b8ad74923ce2ef5341557 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Tue, 29 Sep 2026 14:50:30 +0530 Subject: [PATCH 15/24] - Changes for mongo --- .../templates/09-postsync-update-sm_Job.yaml | 10 +++++----- .../templates/025-mongodb-ce-app.yaml | 7 +++++++ 2 files changed, 12 insertions(+), 5 deletions(-) diff --git a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml index 7a8fc284d..e2ae5fc97 100644 --- a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml +++ b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml @@ -16,11 +16,11 @@ CLI image digest {{- $_job_name := join "-" (list $_job_name_prefix $_job_hash )}} {{- $_job_cleanup_group := cat $_job_name_prefix | sha1sum }} -{{ $ns := .Values.mongodb_namespace | default "mongoce" }} -{{ $aws_secret := "mongo-aws-creds" }} -{{ $role_name := "postsync-mongo-update-sm-r" }} -{{ $sa_name := "postsync-mongo-update-sm-sa" }} -{{ $rb_name := "postsync-mongo-update-sm-rb" }} +{{- $ns := .Values.mongodb_namespace | default "mongoce" }} +{{- $aws_secret := "mongo-aws-creds" }} +{{- $role_name := "postsync-mongo-update-sm-r" }} +{{- $sa_name := "postsync-mongo-update-sm-sa" }} +{{- $rb_name := "postsync-mongo-update-sm-rb" }} --- kind: Secret diff --git a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml index e4584bac9..fce2b2ab2 100644 --- a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml +++ b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml @@ -50,6 +50,13 @@ spec: storage_size: "{{ .Values.ibm_mongodb.storage_size | default "10Gi" }}" logs_storage_size: "{{ .Values.ibm_mongodb.logs_storage_size | default "1Gi" }}" storage_class: "{{ .Values.ibm_mongodb.mongo_ce_storage_class | default "" }}" + resources: + limits: + cpu: "2" + memory: "4Gi" + requests: + cpu: "500m" + memory: "1Gi" {{- if .Values.custom_labels }} custom_labels: {{ .Values.custom_labels | toYaml | nindent 14 }} {{- end }} From c536b40bc2822d663ce1bb46b0ddb3b464b75dc9 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Tue, 29 Sep 2026 19:17:46 +0530 Subject: [PATCH 16/24] Update 09-postsync-update-sm_Job.yaml --- .../templates/09-postsync-update-sm_Job.yaml | 217 ++++++++++-------- 1 file changed, 115 insertions(+), 102 deletions(-) diff --git a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml index e2ae5fc97..c44990d2e 100644 --- a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml +++ b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml @@ -1,26 +1,74 @@ {{- if and .Values.run_sync_hooks .Values.cluster_admin_role }} {{- /* -Meaningful prefix for the job resource name. Must be under 52 chars in length. +Meaningful prefix for the job resource name. Must be under 52 chars in length to leave room for the 11 chars reserved for '-' and $_job_hash. */}} {{- $_job_name_prefix := "postsync-mongo-update-sm-job" }} {{- /* -CLI image digest +Use the build/bin/set-cli-image-digest.sh script to update this value across all charts. +Included in $_job_hash (see below). */}} {{- $_cli_image_digest := "sha256:1dc8665fddb9546b84290b0615fc7c7017e19516082b35541d41b8ea82df347b" }} +{{- /* +A dict of values that influence the behaviour of the job in some way. +Any changes to values in this dict will trigger a rerun of the job. +*/}} {{- $_job_config_values := omit .Values "junitreporter" }} -{{- $_job_version := "v1" }} + +{{- /* +Increment this value whenever you make a change to an immutable field of the Job resource. +*/}} +{{- $_job_version := "v2" }} + +{{- /* +10 char hash appended to the job name taking into account $_job_config_values, $_job_version and $_cli_image_digest +*/}} {{- $_job_hash := print ($_job_config_values | toYaml) $_cli_image_digest $_job_version | adler32sum }} + {{- $_job_name := join "-" (list $_job_name_prefix $_job_hash )}} + +{{- /* +Set as the value for the mas.ibm.com/job-cleanup-group label on the Job resource. +*/}} {{- $_job_cleanup_group := cat $_job_name_prefix | sha1sum }} -{{- $ns := .Values.mongodb_namespace | default "mongoce" }} -{{- $aws_secret := "mongo-aws-creds" }} -{{- $role_name := "postsync-mongo-update-sm-r" }} -{{- $sa_name := "postsync-mongo-update-sm-sa" }} -{{- $rb_name := "postsync-mongo-update-sm-rb" }} + + +{{ $ns := .Values.mongodb_namespace | default "mongoce" }} +{{ $aws_secret := "aws" }} +{{ $np_name := "postsync-mongo-update-sm-np" }} +{{ $role_name := "postsync-mongo-update-sm-r" }} +{{ $sa_name := "postsync-mongo-update-sm-sa" }} +{{ $rb_name := "postsync-mongo-update-sm-rb" }} +{{ $job_label := "postsync-mongo-update-sm-job" }} + + + +--- +# Permit outbound communication by the Job pods +# (Needed to communicate with the K8S HTTP API and AWS SM) +kind: NetworkPolicy +apiVersion: networking.k8s.io/v1 +metadata: + name: {{ $np_name }} + namespace: {{ $ns }} + annotations: + argocd.argoproj.io/sync-wave: "026" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +spec: + podSelector: + matchLabels: + app: {{ $job_label }} + egress: + - {} + policyTypes: + - Egress + --- kind: Secret @@ -35,8 +83,8 @@ metadata: {{ .Values.custom_labels | toYaml | indent 4 }} {{- end }} data: - aws_access_key_id: {{ .Values.sm_aws_access_key_id | default "" | b64enc }} - aws_secret_access_key: {{ .Values.sm_aws_secret_access_key | default "" | b64enc }} + aws_access_key_id: {{ .Values.sm_aws_access_key_id | b64enc }} + aws_secret_access_key: {{ .Values.sm_aws_secret_access_key | b64enc }} type: Opaque --- @@ -53,10 +101,11 @@ metadata: {{- end }} --- -kind: ClusterRole +kind: Role apiVersion: rbac.authorization.k8s.io/v1 metadata: name: {{ $role_name }} + namespace: {{ $ns }} annotations: argocd.argoproj.io/sync-wave: "026" {{- if .Values.custom_labels }} @@ -66,28 +115,19 @@ metadata: rules: - verbs: - get - - list - - watch apiGroups: - "" resources: - secrets - - services - - pods - - verbs: - - get - - list - - watch - apiGroups: - - mongodbcommunity.mongodb.com - resources: - - mongodbcommunity + + --- -kind: ClusterRoleBinding +kind: RoleBinding apiVersion: rbac.authorization.k8s.io/v1 metadata: name: {{ $rb_name }} + namespace: {{ $ns }} annotations: argocd.argoproj.io/sync-wave: "027" {{- if .Values.custom_labels }} @@ -100,7 +140,7 @@ subjects: namespace: {{ $ns }} roleRef: apiGroup: rbac.authorization.k8s.io - kind: ClusterRole + kind: Role name: {{ $role_name }} --- @@ -111,6 +151,7 @@ metadata: namespace: {{ $ns }} annotations: argocd.argoproj.io/sync-wave: "028" + argocd.argoproj.io/sync-options: Prune=true labels: mas.ibm.com/job-cleanup-group: {{ $_job_cleanup_group }} {{- if .Values.custom_labels }} @@ -118,20 +159,13 @@ metadata: {{- end }} spec: template: -{{- if .Values.custom_labels }} metadata: labels: + app: {{ $job_label }} +{{- if .Values.custom_labels }} {{ .Values.custom_labels | toYaml | indent 8 }} {{- end }} spec: - serviceAccountName: {{ $sa_name }} - restartPolicy: Never - volumes: - - name: aws - secret: - secretName: {{ $aws_secret }} - defaultMode: 420 - optional: false containers: - name: run image: {{ .Values.cli_image_repo | default "quay.io/ibmmas/cli" }}@{{ $_cli_image_digest }} @@ -143,37 +177,46 @@ spec: requests: cpu: 10m memory: 64Mi - volumeMounts: - - name: aws - mountPath: /etc/mas/creds/aws env: - - name: AVP_TYPE - value: "aws" - name: ACCOUNT_ID - value: "{{ .Values.account_id }}" + value: {{ .Values.account_id }} - name: REGION_ID - value: "{{ .Values.region_id }}" + value: {{ .Values.region_id }} - name: CLUSTER_ID - value: "{{ .Values.cluster_id }}" + value: {{ .Values.cluster_id }} - name: MONGO_NAMESPACE - value: "{{ $ns }}" + value: {{ $ns }} - name: MONGO_INSTANCE_NAME - value: "{{ .Values.mongodb_instance_name | default "mas-mongo-ce" }}" + value: {{ .Values.mongodb_instance_name | default "mas-mongo-ce" }} - name: MONGO_MEMBERS value: "{{ .Values.mongodb_members | default 3 }}" + # Hard-coded for now: + - name: AVP_TYPE + value: "aws" + volumeMounts: + - name: aws + mountPath: /etc/mas/creds/aws command: - - /bin/bash + - /bin/sh - -c - | + set -e + # NOTE: cannot just render AWS secrets into here, as it will be exposed in the ArgoCD UI + # Instead, we pass them into a secret (ArgoCD knows to hide any data fields in k8s secrets), + # mount the secret on the jobs filesystem, and read them in here SM_AWS_ACCESS_KEY_ID=$(cat /etc/mas/creds/aws/aws_access_key_id) SM_AWS_SECRET_ACCESS_KEY=$(cat /etc/mas/creds/aws/aws_secret_access_key) - export SM_AWS_REGION="${REGION_ID}" + + # might as well take advantage of gitops_utils for sm_ functions as we're using the cli image + source /mascli/functions/gitops_utils + + export SM_AWS_REGION=${REGION_ID} + sm_login # --------------------------------------------------------------------------- # Wait for MongoDBCommunity CR to reach Running phase - # Mirrors: ansible install-mongo.yml step 11 — wait for StatefulSet ready # --------------------------------------------------------------------------- echo "Waiting for MongoDBCommunity/${MONGO_INSTANCE_NAME} in namespace ${MONGO_NAMESPACE} ..." PHASE="" @@ -192,14 +235,10 @@ spec: # --------------------------------------------------------------------------- # Read the admin password from the operator-generated secret. - # Mirrors: ansible install-mongo.yml step 14 — - # "Lookup admin password" from secret mas-mongo-ce-admin-admin - # (name pattern: -- = mas-mongo-ce-admin-admin) - # The MongoDBCommunity operator creates this secret automatically after the - # CR reaches Running state. It contains the real working password. + # Name pattern: -admin-admin (e.g. mas-mongo-ce-admin-admin) # --------------------------------------------------------------------------- ADMIN_SECRET_NAME="${MONGO_INSTANCE_NAME}-admin-admin" - echo "Reading admin password from operator-generated secret: ${ADMIN_SECRET_NAME}" + echo "Reading admin password from secret: ${ADMIN_SECRET_NAME}" MONGO_ADMIN_PASSWORD="" for (( c=1; c<=30; c++ )); do echo " attempt ${c}/30 ..." @@ -217,12 +256,16 @@ spec: fi # --------------------------------------------------------------------------- - # Fetch CA certificate from cert-manager-generated secret 'mongo-ca-secret' - # This is what the ansible role reads from mongodb_ca_lookup (mongo-server-cert) - # and writes into mas-mongo-ce-cert-map ConfigMap / suite_mongocfg.yml.j2 + # Read metrics password from the operator-generated metrics secret. + # --------------------------------------------------------------------------- + MONGO_METRICS_PASSWORD=$(oc get secret "${MONGO_INSTANCE_NAME}-metrics-endpoint-secret" \ + -n "${MONGO_NAMESPACE}" -o jsonpath='{.data.password}' 2>/dev/null \ + | base64 -d 2>/dev/null || true) + + # --------------------------------------------------------------------------- + # Fetch CA certificate # --------------------------------------------------------------------------- CA_CERT_PEM="" - # Primary: use the CA secret created by cert-manager Certificate 'mongo-ca-crt' for CA_SECRET_NAME in "mongo-ca-secret" "${MONGO_INSTANCE_NAME}-ca"; do if oc get secret "${CA_SECRET_NAME}" -n "${MONGO_NAMESPACE}" >/dev/null 2>&1; then echo "Found CA secret ${CA_SECRET_NAME}, extracting certificate ..." @@ -239,7 +282,7 @@ spec: fi # --------------------------------------------------------------------------- - # Build the 'info' YAML block (hosts + optional CA cert) using pure bash + # Build the 'info' YAML block (hosts + optional CA cert) # --------------------------------------------------------------------------- INFO_YAML="config:"$'\n'" hosts:" for (( i=0; i on subsequent syncs. - # This mirrors the ansible flow where the password is readable from K8s - # secret mas-mongo-ce-admin-admin after the operator sets it up. + # Build JSON payload and write to AWS Secrets Manager # --------------------------------------------------------------------------- PRIMARY_HOST="${MONGO_INSTANCE_NAME}-0.${MONGO_INSTANCE_NAME}-svc.${MONGO_NAMESPACE}.svc.cluster.local" - # Read metrics password from the metrics-endpoint secret (operator leaves it as-is) - MONGO_METRICS_PASSWORD=$(oc get secret "mas-mongo-ce-metrics-endpoint-secret" \ - -n "${MONGO_NAMESPACE}" -o jsonpath='{.data.password}' 2>/dev/null \ - | base64 -d 2>/dev/null || true) + SECRET_NAME_MONGO="${ACCOUNT_ID}/${CLUSTER_ID}/mongodatabase" + TAGS="[{\"Key\": \"source\", \"Value\": \"postsync-mongo-update-sm-job\"}, {\"Key\": \"account\", \"Value\": \"${ACCOUNT_ID}\"}, {\"Key\": \"cluster\", \"Value\": \"${CLUSTER_ID}\"}]" - SECRET_VALUE=$(jq -n \ - --arg docdb_host "${PRIMARY_HOST}" \ - --arg docdb_port "27017" \ - --arg username "admin" \ - --arg password "${MONGO_ADMIN_PASSWORD}" \ - --arg admin_password "${MONGO_ADMIN_PASSWORD}" \ - --arg metrics_password "${MONGO_METRICS_PASSWORD}" \ - --arg info "${INFO_YAML}" \ - '{docdb_host: $docdb_host, docdb_port: $docdb_port, username: $username, password: $password, admin_password: $admin_password, metrics_password: $metrics_password, info: $info}') - - TAGS=$(jq -n \ - --arg account "${ACCOUNT_ID}" \ - --arg cluster "${CLUSTER_ID}" \ - '[ - {"Key":"source", "Value":"postsync-mongo-update-sm-job"}, - {"Key":"account", "Value":$account}, - {"Key":"cluster", "Value":$cluster} - ]') - - echo "${SECRET_VALUE}" > /tmp/secret_payload.json - echo "${TAGS}" > /tmp/secret_tags.json + sm_update_secret $SECRET_NAME_MONGO "{\"docdb_host\": \"${PRIMARY_HOST}\", \"docdb_port\": \"27017\", \"username\": \"admin\", \"password\": \"${MONGO_ADMIN_PASSWORD}\", \"admin_password\": \"${MONGO_ADMIN_PASSWORD}\", \"metrics_password\": \"${MONGO_METRICS_PASSWORD}\", \"info\": \"${INFO_YAML}\"}" "${TAGS}" - # --------------------------------------------------------------------------- - # Login to AWS SM and upsert the secret - # --------------------------------------------------------------------------- - source /mascli/functions/gitops_utils - sm_login + echo "SUCCESS: MongoDB credentials stored at ${SECRET_NAME_MONGO}" - SECRET_NAME_MONGO="${ACCOUNT_ID}/${CLUSTER_ID}/mongodatabase" - echo "Upserting AWS Secrets Manager secret: ${SECRET_NAME_MONGO}" - sm_update_secret \ - "${SECRET_NAME_MONGO}" \ - "$(cat /tmp/secret_payload.json)" \ - "$(cat /tmp/secret_tags.json)" || exit $? + restartPolicy: Never + + serviceAccountName: {{ $sa_name }} + volumes: + - name: aws + secret: + secretName: {{ $aws_secret }} + defaultMode: 420 + optional: false - echo "SUCCESS: MongoDB credentials stored at ${SECRET_NAME_MONGO}" backoffLimit: 4 {{- end }} From 3ed492246b12b65e0602c0ad60b216a07282a582 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Tue, 29 Sep 2026 19:57:37 +0530 Subject: [PATCH 17/24] Update 09-postsync-update-sm_Job.yaml --- .../templates/09-postsync-update-sm_Job.yaml | 45 +++++++++++++++++-- 1 file changed, 42 insertions(+), 3 deletions(-) diff --git a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml index c44990d2e..ec098193d 100644 --- a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml +++ b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml @@ -20,7 +20,7 @@ Any changes to values in this dict will trigger a rerun of the job. {{- /* Increment this value whenever you make a change to an immutable field of the Job resource. */}} -{{- $_job_version := "v2" }} +{{- $_job_version := "v3" }} {{- /* 10 char hash appended to the job name taking into account $_job_config_values, $_job_version and $_cli_image_digest @@ -101,6 +101,7 @@ metadata: {{- end }} --- +# Namespace-scoped Role: allows the job to read secrets (admin password, metrics password) kind: Role apiVersion: rbac.authorization.k8s.io/v1 metadata: @@ -120,8 +121,6 @@ rules: resources: - secrets - - --- kind: RoleBinding apiVersion: rbac.authorization.k8s.io/v1 @@ -143,6 +142,46 @@ roleRef: kind: Role name: {{ $role_name }} +--- +# ClusterRole: allows the job to read the MongoDBCommunity CR (cluster-scoped CRD) +kind: ClusterRole +apiVersion: rbac.authorization.k8s.io/v1 +metadata: + name: {{ $role_name }}-cr + annotations: + argocd.argoproj.io/sync-wave: "026" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +rules: + - verbs: + - get + apiGroups: + - mongodbcommunity.mongodb.com + resources: + - mongodbcommunity + +--- +kind: ClusterRoleBinding +apiVersion: rbac.authorization.k8s.io/v1 +metadata: + name: {{ $rb_name }}-cr + annotations: + argocd.argoproj.io/sync-wave: "027" +{{- if .Values.custom_labels }} + labels: +{{ .Values.custom_labels | toYaml | indent 4 }} +{{- end }} +subjects: + - kind: ServiceAccount + name: {{ $sa_name }} + namespace: {{ $ns }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: {{ $role_name }}-cr + --- apiVersion: batch/v1 kind: Job From 89f5e4c833fe95c56a1398248dd7ae41d9cf9cb2 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Tue, 29 Sep 2026 21:03:11 +0530 Subject: [PATCH 18/24] Update 09-postsync-update-sm_Job.yaml --- .../templates/09-postsync-update-sm_Job.yaml | 19 ++++++++++++++++--- 1 file changed, 16 insertions(+), 3 deletions(-) diff --git a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml index ec098193d..6f6245171 100644 --- a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml +++ b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml @@ -20,7 +20,7 @@ Any changes to values in this dict will trigger a rerun of the job. {{- /* Increment this value whenever you make a change to an immutable field of the Job resource. */}} -{{- $_job_version := "v3" }} +{{- $_job_version := "v5" }} {{- /* 10 char hash appended to the job name taking into account $_job_config_values, $_job_version and $_cli_image_digest @@ -345,14 +345,27 @@ spec: echo "-----------------" # --------------------------------------------------------------------------- - # Build JSON payload and write to AWS Secrets Manager + # Build JSON payload using jq to safely escape all field values, + # then write to AWS Secrets Manager. + # jq --arg handles newlines and special characters in INFO_YAML correctly, + # storing info as plain text (not encoded) in AWS Secrets Manager. # --------------------------------------------------------------------------- PRIMARY_HOST="${MONGO_INSTANCE_NAME}-0.${MONGO_INSTANCE_NAME}-svc.${MONGO_NAMESPACE}.svc.cluster.local" + SECRET_VALUE=$(jq -n \ + --arg docdb_host "${PRIMARY_HOST}" \ + --arg docdb_port "27017" \ + --arg username "admin" \ + --arg password "${MONGO_ADMIN_PASSWORD}" \ + --arg admin_password "${MONGO_ADMIN_PASSWORD}" \ + --arg metrics_password "${MONGO_METRICS_PASSWORD}" \ + --arg info "${INFO_YAML}" \ + '{docdb_host: $docdb_host, docdb_port: $docdb_port, username: $username, password: $password, admin_password: $admin_password, metrics_password: $metrics_password, info: $info}') + SECRET_NAME_MONGO="${ACCOUNT_ID}/${CLUSTER_ID}/mongodatabase" TAGS="[{\"Key\": \"source\", \"Value\": \"postsync-mongo-update-sm-job\"}, {\"Key\": \"account\", \"Value\": \"${ACCOUNT_ID}\"}, {\"Key\": \"cluster\", \"Value\": \"${CLUSTER_ID}\"}]" - sm_update_secret $SECRET_NAME_MONGO "{\"docdb_host\": \"${PRIMARY_HOST}\", \"docdb_port\": \"27017\", \"username\": \"admin\", \"password\": \"${MONGO_ADMIN_PASSWORD}\", \"admin_password\": \"${MONGO_ADMIN_PASSWORD}\", \"metrics_password\": \"${MONGO_METRICS_PASSWORD}\", \"info\": \"${INFO_YAML}\"}" "${TAGS}" + sm_update_secret $SECRET_NAME_MONGO "${SECRET_VALUE}" "${TAGS}" echo "SUCCESS: MongoDB credentials stored at ${SECRET_NAME_MONGO}" From 0301a87df4d441598f28815a82209160d16a1294 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Tue, 29 Sep 2026 21:55:09 +0530 Subject: [PATCH 19/24] Update 09-postsync-update-sm_Job.yaml --- .../025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml index 6f6245171..ad972a205 100644 --- a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml +++ b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml @@ -362,7 +362,7 @@ spec: --arg info "${INFO_YAML}" \ '{docdb_host: $docdb_host, docdb_port: $docdb_port, username: $username, password: $password, admin_password: $admin_password, metrics_password: $metrics_password, info: $info}') - SECRET_NAME_MONGO="${ACCOUNT_ID}/${CLUSTER_ID}/mongodatabase" + SECRET_NAME_MONGO="${ACCOUNT_ID}/${CLUSTER_ID}/mongo" TAGS="[{\"Key\": \"source\", \"Value\": \"postsync-mongo-update-sm-job\"}, {\"Key\": \"account\", \"Value\": \"${ACCOUNT_ID}\"}, {\"Key\": \"cluster\", \"Value\": \"${CLUSTER_ID}\"}]" sm_update_secret $SECRET_NAME_MONGO "${SECRET_VALUE}" "${TAGS}" From a02889eda5072d5b0269d785d8b5671b2356f50a Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Tue, 29 Sep 2026 22:03:31 +0530 Subject: [PATCH 20/24] Update 09-postsync-update-sm_Job.yaml --- .../templates/09-postsync-update-sm_Job.yaml | 23 ++++++------------- 1 file changed, 7 insertions(+), 16 deletions(-) diff --git a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml index ad972a205..0991f9a24 100644 --- a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml +++ b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml @@ -20,7 +20,7 @@ Any changes to values in this dict will trigger a rerun of the job. {{- /* Increment this value whenever you make a change to an immutable field of the Job resource. */}} -{{- $_job_version := "v5" }} +{{- $_job_version := "v6" }} {{- /* 10 char hash appended to the job name taking into account $_job_config_values, $_job_version and $_cli_image_digest @@ -294,13 +294,6 @@ spec: exit 1 fi - # --------------------------------------------------------------------------- - # Read metrics password from the operator-generated metrics secret. - # --------------------------------------------------------------------------- - MONGO_METRICS_PASSWORD=$(oc get secret "${MONGO_INSTANCE_NAME}-metrics-endpoint-secret" \ - -n "${MONGO_NAMESPACE}" -o jsonpath='{.data.password}' 2>/dev/null \ - | base64 -d 2>/dev/null || true) - # --------------------------------------------------------------------------- # Fetch CA certificate # --------------------------------------------------------------------------- @@ -353,14 +346,12 @@ spec: PRIMARY_HOST="${MONGO_INSTANCE_NAME}-0.${MONGO_INSTANCE_NAME}-svc.${MONGO_NAMESPACE}.svc.cluster.local" SECRET_VALUE=$(jq -n \ - --arg docdb_host "${PRIMARY_HOST}" \ - --arg docdb_port "27017" \ - --arg username "admin" \ - --arg password "${MONGO_ADMIN_PASSWORD}" \ - --arg admin_password "${MONGO_ADMIN_PASSWORD}" \ - --arg metrics_password "${MONGO_METRICS_PASSWORD}" \ - --arg info "${INFO_YAML}" \ - '{docdb_host: $docdb_host, docdb_port: $docdb_port, username: $username, password: $password, admin_password: $admin_password, metrics_password: $metrics_password, info: $info}') + --arg docdb_host "${PRIMARY_HOST}" \ + --arg docdb_port "27017" \ + --arg username "admin" \ + --arg password "${MONGO_ADMIN_PASSWORD}" \ + --arg info "${INFO_YAML}" \ + '{docdb_host: $docdb_host, docdb_port: $docdb_port, username: $username, password: $password, info: $info}') SECRET_NAME_MONGO="${ACCOUNT_ID}/${CLUSTER_ID}/mongo" TAGS="[{\"Key\": \"source\", \"Value\": \"postsync-mongo-update-sm-job\"}, {\"Key\": \"account\", \"Value\": \"${ACCOUNT_ID}\"}, {\"Key\": \"cluster\", \"Value\": \"${CLUSTER_ID}\"}]" From c95a5cbf5680264b3d74b7ad071a5c4dc972e882 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Thu, 1 Oct 2026 19:14:32 +0530 Subject: [PATCH 21/24] - Change ibm_mongo to mongoce as per PR comments --- .../templates/000-cluster-appset.yaml | 2 +- .../templates/025-mongodb-ce-app.yaml | 20 +++++++++---------- .../ibm-mas-cluster-root/values.yaml | 2 +- 3 files changed, 12 insertions(+), 12 deletions(-) diff --git a/root-applications/ibm-mas-account-root/templates/000-cluster-appset.yaml b/root-applications/ibm-mas-account-root/templates/000-cluster-appset.yaml index 4c4e3c3ae..d2c81fee3 100644 --- a/root-applications/ibm-mas-account-root/templates/000-cluster-appset.yaml +++ b/root-applications/ibm-mas-account-root/templates/000-cluster-appset.yaml @@ -119,7 +119,7 @@ spec: repoURL: "{{ .Values.generator.repo_url }}" revision: "{{ .Values.generator.revision }}" files: - - path: "{{ .Values.account.id }}/*/ibm-mongodb.yaml" + - path: "{{ .Values.account.id }}/*/mongoce.yaml" syncPolicy: applicationsSync: "{{- if .Values.auto_delete }}sync{{- else }}create-update{{- end }}" template: diff --git a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml index fce2b2ab2..3b52e21fc 100644 --- a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml +++ b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml @@ -1,4 +1,4 @@ -{{- if and (not (empty .Values.ibm_mongodb)) (eq (.Values.ibm_mongodb.install | default "true") "true") (.Values.cluster_admin_role) }} +{{- if and (not (empty .Values.mongoce)) (eq (.Values.mongoce.install | default "true") "true") (.Values.cluster_admin_role) }} --- apiVersion: argoproj.io/v1alpha1 kind: Application @@ -25,7 +25,7 @@ spec: project: "{{ .Values.argo.projects.apps }}" destination: server: {{ .Values.cluster.url }} - namespace: {{ .Values.ibm_mongodb.namespace | default "mongoce" }} + namespace: {{ .Values.mongoce.namespace | default "mongoce" }} source: repoURL: "{{ .Values.source.repo_url }}" path: cluster-applications/025-mongodb-ce @@ -39,17 +39,17 @@ spec: region_id: "{{ .Values.region.id }}" cluster_id: "{{ .Values.cluster.id }}" cluster_admin_role: {{ .Values.cluster_admin_role }} - run_sync_hooks: {{ .Values.ibm_mongodb.run_sync_hooks | default true }} + run_sync_hooks: {{ .Values.mongoce.run_sync_hooks | default true }} sm_aws_access_key_id: "{{ .Values.sm.aws_access_key_id }}" sm_aws_secret_access_key: "{{ .Values.sm.aws_secret_access_key }}" cli_image_repo: {{ .Values.cli_image_repo }} - mongodb_namespace: "{{ .Values.ibm_mongodb.namespace | default "mongoce" }}" - mongodb_instance_name: "{{ .Values.ibm_mongodb.instance_name | default "mas-mongo-ce" }}" - mongodb_version: "{{ .Values.ibm_mongodb.mongo_ce_version | default "7.0.12" }}" - mongodb_members: {{ .Values.ibm_mongodb.members | default 3 }} - storage_size: "{{ .Values.ibm_mongodb.storage_size | default "10Gi" }}" - logs_storage_size: "{{ .Values.ibm_mongodb.logs_storage_size | default "1Gi" }}" - storage_class: "{{ .Values.ibm_mongodb.mongo_ce_storage_class | default "" }}" + mongodb_namespace: "{{ .Values.mongoce.namespace | default "mongoce" }}" + mongodb_instance_name: "{{ .Values.mongoce.instance_name | default "mas-mongo-ce" }}" + mongodb_version: "{{ .Values.mongoce.mongo_ce_version | default "7.0.12" }}" + mongodb_members: {{ .Values.mongoce.members | default 3 }} + storage_size: "{{ .Values.mongoce.storage_size | default "10Gi" }}" + logs_storage_size: "{{ .Values.mongoce.logs_storage_size | default "1Gi" }}" + storage_class: "{{ .Values.mongoce.mongo_ce_storage_class | default "" }}" resources: limits: cpu: "2" diff --git a/root-applications/ibm-mas-cluster-root/values.yaml b/root-applications/ibm-mas-cluster-root/values.yaml index 14f8ee37b..84bb1a2f6 100644 --- a/root-applications/ibm-mas-cluster-root/values.yaml +++ b/root-applications/ibm-mas-cluster-root/values.yaml @@ -47,5 +47,5 @@ custom_sa: custom_sa_namespace: custom_sa_details: -ibm_mongodb: {} +mongoce: {} From b9c008715182667460039592c54b923c2c0a3173 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Thu, 1 Oct 2026 22:22:12 +0530 Subject: [PATCH 22/24] - Version change for mongo --- .../025-mongodb-ce/templates/04-operator-deployment.yaml | 2 +- .../025-mongodb-ce/templates/08-mongodb-community-cr.yaml | 8 ++++---- cluster-applications/025-mongodb-ce/values.yaml | 2 +- .../templates/025-mongodb-ce-app.yaml | 2 +- 4 files changed, 7 insertions(+), 7 deletions(-) diff --git a/cluster-applications/025-mongodb-ce/templates/04-operator-deployment.yaml b/cluster-applications/025-mongodb-ce/templates/04-operator-deployment.yaml index df0722fbd..cb695d40e 100644 --- a/cluster-applications/025-mongodb-ce/templates/04-operator-deployment.yaml +++ b/cluster-applications/025-mongodb-ce/templates/04-operator-deployment.yaml @@ -130,7 +130,7 @@ metadata: namespace: {{ .Values.mongodb_namespace | default "mongoce" }} annotations: argocd.argoproj.io/sync-wave: "023" - mongodb-operator-config-version: "{{ .Values.mongodb_version | default "7.0.12" }}" + mongodb-operator-config-version: "{{ .Values.mongodb_version | default "8.0.30" }}" labels: owner: mongodb {{- if .Values.custom_labels }} diff --git a/cluster-applications/025-mongodb-ce/templates/08-mongodb-community-cr.yaml b/cluster-applications/025-mongodb-ce/templates/08-mongodb-community-cr.yaml index 0709af5a3..3cf23a0f8 100644 --- a/cluster-applications/025-mongodb-ce/templates/08-mongodb-community-cr.yaml +++ b/cluster-applications/025-mongodb-ce/templates/08-mongodb-community-cr.yaml @@ -22,7 +22,7 @@ metadata: annotations: argocd.argoproj.io/sync-wave: "025" argocd.argoproj.io/sync-options: SkipDryRunOnMissingResource=true - mongodb-image-version: "{{ .Values.mongodb_version | default "7.0.12" }}" + mongodb-image-version: "{{ .Values.mongodb_version | default "8.0.30" }}" {{- if .Values.custom_labels }} labels: {{ .Values.custom_labels | toYaml | indent 4 }} @@ -30,8 +30,8 @@ metadata: spec: members: {{ .Values.mongodb_members | default 3 }} type: ReplicaSet - version: "{{ .Values.mongodb_version | default "7.0.12" }}" - featureCompatibilityVersion: "{{ .Values.mongodb_version | default "7.0.12" | splitList "." | initial | join "." }}" + version: "{{ .Values.mongodb_version | default "8.0.30" }}" + featureCompatibilityVersion: "{{ .Values.mongodb_version | default "8.0.30" | splitList "." | initial | join "." }}" security: tls: enabled: true @@ -74,7 +74,7 @@ spec: spec: containers: - name: mongod - image: "quay.io/mongodb/mongodb-community-server:{{ .Values.mongodb_version | default "7.0.12" }}-ubi8" + image: "quay.io/mongodb/mongodb-community-server:{{ .Values.mongodb_version | default "8.0.30" }}-ubi8" resources: {{ .Values.resources | toYaml | indent 16 }} volumeClaimTemplates: diff --git a/cluster-applications/025-mongodb-ce/values.yaml b/cluster-applications/025-mongodb-ce/values.yaml index 9fa1957b4..b17959e25 100644 --- a/cluster-applications/025-mongodb-ce/values.yaml +++ b/cluster-applications/025-mongodb-ce/values.yaml @@ -12,7 +12,7 @@ sm_aws_secret_access_key: "" # MongoDB ReplicaSet settings mongodb_namespace: "mongoce" mongodb_instance_name: "mas-mongo-ce" -mongodb_version: "7.0.12" +mongodb_version: "8.0.30" mongodb_members: 3 # Storage diff --git a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml index 3b52e21fc..773a7205b 100644 --- a/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml +++ b/root-applications/ibm-mas-cluster-root/templates/025-mongodb-ce-app.yaml @@ -45,7 +45,7 @@ spec: cli_image_repo: {{ .Values.cli_image_repo }} mongodb_namespace: "{{ .Values.mongoce.namespace | default "mongoce" }}" mongodb_instance_name: "{{ .Values.mongoce.instance_name | default "mas-mongo-ce" }}" - mongodb_version: "{{ .Values.mongoce.mongo_ce_version | default "7.0.12" }}" + mongodb_version: "{{ .Values.mongoce.mongo_ce_version | default "8.0.30" }}" mongodb_members: {{ .Values.mongoce.members | default 3 }} storage_size: "{{ .Values.mongoce.storage_size | default "10Gi" }}" logs_storage_size: "{{ .Values.mongoce.logs_storage_size | default "1Gi" }}" From 23c58259fecf93115ce7f6289e38d594d319831f Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Mon, 5 Oct 2026 13:40:47 +0530 Subject: [PATCH 23/24] - Updated README file for verify the lint helm chart --- README.md | 33 ++++++++++++++++ build/bin/tests/README.md | 20 ++++++++++ .../000-efs-csi-driver/README.md | 7 +++- .../000-ibm-operator-catalog/README.md | 7 +++- .../000-image-mirroring/README.md | 7 +++- .../000-job-cleaner/README.md | 13 +++++++ .../010-redhat-cert-manager/README.md | 7 +++- .../020-ibm-cis-cert-manager/README.md | 36 +++++++++++++++++ cluster-applications/025-mongodb-ce/README.md | 15 +++++-- .../031-ibm-dro-public/README.md | 13 +++++++ .../032-ibm-dro-cleanup/README.md | 15 +++++++ .../040-cis-compliance/README.md | 7 +++- .../041-cis-compliance-cleanup/README.md | 15 +++++++ .../050-nfd-operator/README.md | 19 +++++++++ .../051-nvidia-gpu-operator/README.md | 13 +++++++ .../052-group-sync-operator/README.md | 7 +++- .../053-falcon-operator/README.md | 7 +++- .../054-cluster-logging-operator/README.md | 13 +++++++ .../055-instana-agent-operator/README.md | 7 +++- cluster-applications/060-custom-sa/README.md | 13 +++++++ cluster-applications/061-ibm-rbac/README.md | 13 +++++++ .../200-cluster-promotion/README.md | 13 +++++++ .../300-mas-provisioner/README.md | 13 +++++++ .../000-ibm-sync-resources/README.md | 14 +++++++ .../010-ibm-sync-jobs/README.md | 14 +++++++ instance-applications/100-ibm-sls/README.md | 11 ++++++ .../101-ibm-sync-jobs-cp4d/README.md | 14 +++++++ .../110-ibm-cp4d-operators/README.md | 15 +++++++ instance-applications/110-ibm-cp4d/README.md | 15 +++++++ .../110-ibm-cs-control/README.md | 15 +++++++ instance-applications/110-ibm-db2u/README.md | 15 +++++++ instance-applications/112-ibm-odh/README.md | 14 +++++++ instance-applications/116-ibm-rhoai/README.md | 14 +++++++ .../120-ibm-dbs-rds-database/README.md | 15 +++++++ instance-applications/120-ibm-spark/README.md | 15 +++++++ instance-applications/120-ibm-spss/README.md | 15 +++++++ instance-applications/120-ibm-wml/README.md | 15 +++++++ instance-applications/120-ibm-wsl/README.md | 15 +++++++ .../README.md | 14 +++++++ .../README.md | 25 ++++++++++++ .../130-ibm-jdbc-config/README.md | 14 +++++++ .../130-ibm-kafka-config/README.md | 14 +++++++ .../130-ibm-mas-aicfg-config/README.md | 14 +++++++ .../130-ibm-mas-bas-config/README.md | 14 +++++++ .../130-ibm-mas-idp-config/README.md | 14 +++++++ .../130-ibm-mas-mongo-config/README.md | 14 +++++++ .../130-ibm-mas-sls-config/README.md | 14 +++++++ .../130-ibm-mas-smtp-config/README.md | 16 ++++++++ .../130-ibm-mas-suite/README.md | 15 +++++++ .../130-ibm-objectstorage-config/README.md | 15 +++++++ .../130-ibm-watson-studio-config/README.md | 14 +++++++ .../220-ibm-mas-workspace/README.md | 15 +++++++ .../README.md | 16 ++++++++ .../README.md | 15 +++++++ .../550-ibm-mas-addons-config/README.md | 14 +++++++ .../600-application-admin-rbac/README.md | 9 +++++ .../600-ibm-post-sync-jobs/README.md | 23 +++++++++++ rbac/README.md | 26 +++++++++++++ rbac/kustomize/README.md | 30 ++++++++++++++ .../ibm-mas-account-root/README.md | 24 ++++++++++++ .../ibm-mas-cluster-root/README.md | 31 ++++++++++++++- root-applications/ibm-mas-sls-root/README.md | 25 ++++++++++++ sls-applications/100-ibm-sls/README.md | 24 ++++++++++++ sub-charts/junitreporter/README.md | 39 ++++++++++++++++++- 64 files changed, 1003 insertions(+), 14 deletions(-) diff --git a/README.md b/README.md index f0f2ecb4d..ddcdd4d6f 100644 --- a/README.md +++ b/README.md @@ -3,6 +3,39 @@ Maximo Application Suite GitOps A GitOps approach to managing Maximo Application Suite using ArgoCD and Helm. +## Overview + +This repository contains all Helm charts, ArgoCD Application definitions, and supporting scripts for deploying and managing IBM Maximo Application Suite (MAS) using a GitOps approach with ArgoCD. It implements an **App of Apps** hierarchy that manages cluster prerequisites, MAS instances, Suite License Service, and AI Service deployments. + +## Configuration + +Configuration for each cluster and MAS instance is stored in a separate **config repository**. The GitOps charts in this repository consume those config files via ArgoCD ApplicationSet generators. See the [Configuration Repository](https://ibm-mas.github.io/gitops/configrepo/) documentation for details on the required file structure and field names. + +## Resources Created + +This repository does not deploy resources directly. Resources are deployed by the Helm charts in the `cluster-applications/`, `instance-applications/`, `sls-applications/`, and `root-applications/` directories. See the README in each chart directory for the specific resources it creates. + +## Examples + +### Deploy the Account Root Application + +```yaml +# values.yaml passed to the ibm-mas-account-root chart +account: + id: "production" +generator: + repo_url: "https://github.com/myorg/mas-config" + revision: "main" +source: + repo_url: "https://github.com/ibm-mas/gitops" + revision: "main" +argo: + namespace: "openshift-gitops" + projects: + rootapps: "mas" + apps: "mas" +``` + ## Repository Structure This repository is organized into several key directories that work together to deploy and manage MAS/SLS/AIService instances: diff --git a/build/bin/tests/README.md b/build/bin/tests/README.md index 6db844a53..98e4f4025 100644 --- a/build/bin/tests/README.md +++ b/build/bin/tests/README.md @@ -2,6 +2,26 @@ This directory contains comprehensive unit tests for the Python scripts in `build/bin/`. +## Configuration + +This directory contains pytest unit and integration tests for the Python scripts in `build/bin/`. No additional configuration is required — run `pytest` from the repository root. + +## Resources Created + +This is a test directory, not a Helm chart. No Kubernetes resources are created. The tests validate the build scripts themselves. + +## Examples + +### Run the full test suite + +```bash +# From repository root +pytest build/bin/tests/ -v + +# With coverage +pytest build/bin/tests/ --cov=build/bin --cov-report=term +``` + ## Overview The test suite provides coverage for: diff --git a/cluster-applications/000-efs-csi-driver/README.md b/cluster-applications/000-efs-csi-driver/README.md index 4d9eb9eda..c8ec9d7ee 100644 --- a/cluster-applications/000-efs-csi-driver/README.md +++ b/cluster-applications/000-efs-csi-driver/README.md @@ -3,6 +3,10 @@ EFS CSI Driver +## Overview + +This chart installs the AWS EFS CSI Driver operator to enable EFS-backed persistent volumes in OpenShift. It creates the necessary `OperatorGroup`, `Subscription`, `ClusterCSIDriver`, IAM credential `Secret`, and optional custom `StorageClass` definitions. + Installs the AWS EFS CSI Driver operator to enable EFS-backed persistent volumes in OpenShift. @@ -74,7 +78,8 @@ sm: # Secrets Manager configuration For complete documentation of all base cluster values including optional fields like `notifications`, `custom_labels`, `devops`, and `cli_image_repo`, see the [Cluster Base Values Reference](../../docs/reference/cluster-base-values.md). -### Usage Examples +## Examples + **Basic configuration with IAM role:** ```yaml diff --git a/cluster-applications/000-ibm-operator-catalog/README.md b/cluster-applications/000-ibm-operator-catalog/README.md index 9eefe4c69..043d33730 100644 --- a/cluster-applications/000-ibm-operator-catalog/README.md +++ b/cluster-applications/000-ibm-operator-catalog/README.md @@ -3,6 +3,10 @@ IBM Maximo Operator Catalog Installs the `ibm-operator-catalog` `CatalogSource` into the `openshift-marketplace` namespace +## Overview + +This chart installs the `ibm-operator-catalog` `CatalogSource` into the `openshift-marketplace` namespace and creates the IBM entitlement key `Secret` required for pulling IBM container images. + ## Configuration @@ -50,7 +54,8 @@ sm: # Secrets Manager configuration For complete documentation of all base cluster values including optional fields like `notifications`, `custom_labels`, `devops`, and `cli_image_repo`, see the [Cluster Base Values Reference](../../docs/reference/cluster-base-values.md). -### Usage Examples +## Examples + **Basic configuration with entitlement key:** ```yaml diff --git a/cluster-applications/000-image-mirroring/README.md b/cluster-applications/000-image-mirroring/README.md index 5d788234a..bed194069 100644 --- a/cluster-applications/000-image-mirroring/README.md +++ b/cluster-applications/000-image-mirroring/README.md @@ -3,6 +3,10 @@ MAS Image Mirroring +## Overview + +This chart establishes resources for MAS image mirroring via an `ImageDigestMirrorSet`. It deploys an ECR token rotator `CronJob` that refreshes the global pull-secret and an `ImageDigestMirrorSet` that redirects image pulls from `icr.io` and `cp.icr.io` to ECR. + Establishes resources necessary to support image mirroring via an ImageDigestMirrorSet: @@ -72,7 +76,8 @@ sm: # Secrets Manager configuration For complete documentation of all base cluster values including optional fields like `notifications`, `custom_labels`, `devops`, and `cli_image_repo`, see the [Cluster Base Values Reference](../../docs/reference/cluster-base-values.md). -### Usage Examples +## Examples + **Basic ECR mirroring configuration:** ```yaml diff --git a/cluster-applications/000-job-cleaner/README.md b/cluster-applications/000-job-cleaner/README.md index d64018165..dbcc2abc7 100644 --- a/cluster-applications/000-job-cleaner/README.md +++ b/cluster-applications/000-job-cleaner/README.md @@ -3,6 +3,10 @@ MAS SaaS Job Cleaner +## Overview + +This chart installs a `CronJob` that periodically removes completed and failed `Job` resources from the cluster to prevent resource accumulation over time. + Deploys the `mas-saas-job-cleaner-cron` CronJob, responsible for cleaning up orphaned Job resources in the cluster. It works by grouping Jobs in the cluster according to the `mas.ibm.com/job-cleanup-group` label, then deleting all Jobs from each group except for the one with the latest `creationTimestamp`. @@ -21,6 +25,15 @@ This chart has no configurable values. It deploys with default settings that wor The CronJob runs on a schedule and automatically cleans up orphaned Job resources that have the `mas.ibm.com/job-cleanup-group` label. +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +# No additional values required. +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/cluster-applications/010-redhat-cert-manager/README.md b/cluster-applications/010-redhat-cert-manager/README.md index 8dba62296..74109b026 100644 --- a/cluster-applications/010-redhat-cert-manager/README.md +++ b/cluster-applications/010-redhat-cert-manager/README.md @@ -3,6 +3,10 @@ Redhat OpenShift cert-manager Operator Installs Redhat OpenShift cert-manager Operator in cert-manager-operator namespace +## Overview + +This chart installs the Red Hat OpenShift cert-manager Operator into the `cert-manager-operator` namespace. It creates the `OperatorGroup`, `Subscription`, cluster-scoped RBAC, and an optional post-sync `Job` that updates AWS Secrets Manager with cluster TLS information. + ## Configuration @@ -49,7 +53,8 @@ sm: # Secrets Manager configuration For complete documentation of all base cluster values including optional fields like `notifications`, `custom_labels`, `devops`, and `cli_image_repo`, see the [Cluster Base Values Reference](../../docs/reference/cluster-base-values.md). -### Usage Examples +## Examples + **Basic configuration with automatic updates:** ```yaml diff --git a/cluster-applications/020-ibm-cis-cert-manager/README.md b/cluster-applications/020-ibm-cis-cert-manager/README.md index 15d5c8559..f2ffc2b0b 100644 --- a/cluster-applications/020-ibm-cis-cert-manager/README.md +++ b/cluster-applications/020-ibm-cis-cert-manager/README.md @@ -3,6 +3,10 @@ IBM CIS Cert Manager Deploy and configure IBM CIS Cert Manager related resources +## Overview + +This chart deploys the IBM Cloud Internet Services (CIS) webhook for cert-manager on an OpenShift cluster. When `dns_provider` is set to `"cis"`, it provisions the webhook RBAC resources, PKI certificates, operator deployment, API service registration, CIS API key secret, and an optional public ingress controller. A placeholder `ConfigMap` is always created so ArgoCD has at least one resource to track when CIS is not enabled. + ## Configuration @@ -97,6 +101,38 @@ When using IBM CIS as the DNS provider: 3. **Domain** configured in IBM CIS 4. **cert-manager** operator installed (via redhat-cert-manager chart) +## Examples + +### Minimal CIS configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_cis_cert_manager: + dns_provider: "cis" + ocp_cluster_domain: "apps.prod-cluster.example.com" + cis_apikey: "" +``` + +### With public domain and ingress controller + +```yaml +merge-key: "my-account/my-cluster" +ibm_cis_cert_manager: + dns_provider: "cis" + ocp_cluster_domain: "apps.prod-cluster.example.com" + ocp_public_cluster_domain: "public.example.com" + cis_apikey: "" + ingress: true +``` + +### Non-CIS DNS provider (placeholder only) + +```yaml +merge-key: "my-account/my-cluster" +ibm_cis_cert_manager: + dns_provider: "route53" +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/cluster-applications/025-mongodb-ce/README.md b/cluster-applications/025-mongodb-ce/README.md index aaa3a4623..43a451e67 100644 --- a/cluster-applications/025-mongodb-ce/README.md +++ b/cluster-applications/025-mongodb-ce/README.md @@ -19,12 +19,21 @@ This chart provisions a MongoDB Community Operator and a 3-node MongoDB Communit | Resource Type | Resource Name | Namespace | Condition | Installed By | |---|---|---|---|---| +| `CustomResourceDefinition` | `mongodbcommunity.mongodbcommunity.mongodb.com` | - | Always | `cluster_admin_role` | | `Namespace` | `mongoce` | - | Always | `cluster_admin_role` | -| `OperatorGroup` | `mongodb-operator-group` | `mongoce` | Always | `cluster_admin_role` | -| `Subscription` | `mongodb-kubernetes-operator` | `mongoce` | Always | `cluster_admin_role` | -| `Secret` | `admin-user-credentials` | `mongoce` | Always | `cluster_admin_role` | +| `RoleBinding` | `mongodb-*` | `mongoce` | Always | `cluster_admin_role` | +| `Role` | `mongodb-*` | `mongoce` | Always | `cluster_admin_role` | +| `ServiceAccount` | `mongodb-*` | `mongoce` | Always | `cluster_admin_role` | +| `Deployment` | `mongodb-kubernetes-operator` | `mongoce` | Always | `cluster_admin_role` | +| `Job` | `mongodb-password-gen-*` | `mongoce` | Always | `cluster_admin_role` | +| `Issuer` | `mongodb-*-issuer` | `mongoce` | Always | `cluster_admin_role` | +| `Certificate` | `mongodb-*-cert` | `mongoce` | Always | `cluster_admin_role` | +| `ConfigMap` | `mongodb-ca-configmap` | `mongoce` | Always | `cluster_admin_role` | | `MongoDBCommunity` | `mas-mongo-ce` | `mongoce` | Always | `cluster_admin_role` | +| `NetworkPolicy` | `mongodb-network-policy` | `mongoce` | When `run_sync_hooks` and `cluster_admin_role` | `cluster_admin_role` | | `Secret` | `mongo-aws-creds` | `mongoce` | When `run_sync_hooks` and `cluster_admin_role` | `cluster_admin_role` | +| `ClusterRole` | `mongodb-postsync-*` | - | When `run_sync_hooks` and `cluster_admin_role` | `cluster_admin_role` | +| `ClusterRoleBinding` | `mongodb-postsync-*` | - | When `run_sync_hooks` and `cluster_admin_role` | `cluster_admin_role` | | `Job` | `postsync-mongo-update-sm-job-*` | `mongoce` | When `run_sync_hooks` and `cluster_admin_role` | `cluster_admin_role` | ## Configuration diff --git a/cluster-applications/031-ibm-dro-public/README.md b/cluster-applications/031-ibm-dro-public/README.md index 10fabd4a7..80cdaf5ca 100644 --- a/cluster-applications/031-ibm-dro-public/README.md +++ b/cluster-applications/031-ibm-dro-public/README.md @@ -3,10 +3,23 @@ IBM DRO Public Route Expose the IBM Data Reporter Operator (DRO) metrics endpoint through a public OpenShift route. +## Overview + +This chart deploys the public-facing components of IBM Data Reporter Operator (DRO), enabling product usage reporting to IBM through the IBM Software Central endpoint. + This chart creates the public `Route` used to expose DRO externally when IBM Cloud Internet Services (CIS) is the configured DNS provider. It is intended to be rendered by the cluster root application template [`031-ibm-dro-public.yaml`](https://github.com/ibm-mas/gitops/tree/main/root-applications/ibm-mas-cluster-root/templates/031-ibm-dro-public.yaml). +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +# No additional values required. +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/cluster-applications/032-ibm-dro-cleanup/README.md b/cluster-applications/032-ibm-dro-cleanup/README.md index baffab2e0..4ac62e07a 100644 --- a/cluster-applications/032-ibm-dro-cleanup/README.md +++ b/cluster-applications/032-ibm-dro-cleanup/README.md @@ -3,6 +3,10 @@ IBM DRO Cleanup Contains a PostDelete hook that issues deletes for MarketplaceConfig CRs to allow ibm-dro application uninstall to proceed. +## Overview + +This chart provides a PostDelete hook that deletes `MarketplaceConfig` CRs so the IBM DRO application can uninstall cleanly. It must be managed by an ArgoCD Application in a later sync-wave than `030-ibm-dro`. + This chart must be managed by an Application in a later syncwave than ibm-dro to ensure the PostDelete hook can complete before the ibm dro application is removed (otherwise the pods responsible for managing the MarketplaceConfig @@ -16,6 +20,17 @@ This chart has no configurable values. It automatically handles cleanup of Marke The cleanup job runs in the same namespace as the DRO installation (`ibm-software-central` by default). +## Examples + +### Enabling DRO cleanup + +This chart requires no configuration values: + +```yaml +merge-key: "my-account/my-cluster" +# No additional values required — cleanup is automatic on deletion. +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/cluster-applications/040-cis-compliance/README.md b/cluster-applications/040-cis-compliance/README.md index 1f3bbce1a..ae3a01e84 100644 --- a/cluster-applications/040-cis-compliance/README.md +++ b/cluster-applications/040-cis-compliance/README.md @@ -3,6 +3,10 @@ IBM CIS Compliance Installs IBM Compliance Operator into the `openshift-compliance` namespace and add disable rules in tailoredprofile for limitation on ROSA +## Overview + +This chart installs the OpenShift Compliance Operator into the `openshift-compliance` namespace and configures CIS benchmark scans with `TailoredProfile` resources tailored for ROSA environments that disable rules inapplicable to managed OpenShift services. + ## Configuration @@ -45,7 +49,8 @@ sm: # Secrets Manager configuration For complete documentation of all base cluster values including optional fields like `notifications`, `custom_labels`, `devops`, and `cli_image_repo`, see the [Cluster Base Values Reference](../../docs/reference/cluster-base-values.md). -### Usage Examples +## Examples + **Basic configuration with automatic updates:** ```yaml diff --git a/cluster-applications/041-cis-compliance-cleanup/README.md b/cluster-applications/041-cis-compliance-cleanup/README.md index 96b642983..d351f02cc 100644 --- a/cluster-applications/041-cis-compliance-cleanup/README.md +++ b/cluster-applications/041-cis-compliance-cleanup/README.md @@ -3,6 +3,10 @@ IBM CIS Compliance Cleanup Contains a PostDelete hook that issues deletes for ProfileBundle CRs to allow cis-compliance operator uninstall to proceed. +## Overview + +This chart provides a PostDelete hook that deletes `ProfileBundle` CRs so the CIS Compliance operator can uninstall cleanly. It must be managed by an ArgoCD Application in a later sync-wave than `040-cis-compliance` to ensure finalizers are cleared before operator pods are removed. + This chart must be managed by an Application in a later syncwave than cis-compliance to ensure the PostDelete hook can complete before the cis-compliance operator is removed (otherwise the pods responsible for managing the ProfileBundle @@ -16,6 +20,17 @@ This chart has no configurable values. It automatically handles cleanup of Profi The cleanup job runs in the `openshift-compliance` namespace. +## Examples + +### Enabling CIS compliance cleanup + +This chart requires no configuration values. It is enabled automatically when the parent `040-cis-compliance` application is present: + +```yaml +merge-key: "my-account/my-cluster" +# No additional values required — cleanup is automatic on deletion. +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/cluster-applications/050-nfd-operator/README.md b/cluster-applications/050-nfd-operator/README.md index c3aa08a7e..4fad96db6 100644 --- a/cluster-applications/050-nfd-operator/README.md +++ b/cluster-applications/050-nfd-operator/README.md @@ -3,7 +3,26 @@ NFD Operator Installs the Redhat Node Feature Discovery required for the nvidia gpu operator +## Overview +This chart installs the Node Feature Discovery (NFD) operator, which detects hardware features and capabilities on cluster nodes and exposes them as node labels for use by workload scheduling. + + + +## Configuration + +### Values + +This chart uses default NFD operator settings. No additional configuration values are required for a standard installation. + +## Examples + +### Default NFD operator installation + +```yaml +merge-key: "my-account/my-cluster" +# No additional values required. +``` ## Resources Created diff --git a/cluster-applications/051-nvidia-gpu-operator/README.md b/cluster-applications/051-nvidia-gpu-operator/README.md index cbfb43ffa..2a19ff24a 100644 --- a/cluster-applications/051-nvidia-gpu-operator/README.md +++ b/cluster-applications/051-nvidia-gpu-operator/README.md @@ -3,6 +3,10 @@ Nvidia GPU Operator Installs the Nvidia GPU Operator +## Overview + +This chart installs the NVIDIA GPU Operator, which automates the management of GPU drivers, device plugins, and monitoring components required for GPU-accelerated workloads on OpenShift. + ## Configuration @@ -113,6 +117,15 @@ nvidia_gpu_operator: - Sufficient cluster resources for GPU workloads - Node Feature Discovery (NFD) operator (automatically installed by this chart) +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +# No additional values required. +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/cluster-applications/052-group-sync-operator/README.md b/cluster-applications/052-group-sync-operator/README.md index 21fdba478..b7f1df616 100644 --- a/cluster-applications/052-group-sync-operator/README.md +++ b/cluster-applications/052-group-sync-operator/README.md @@ -3,6 +3,10 @@ Group Sync Operator Installs the Group Sync Operator. Minimum required version: 0.0.31 +## Overview + +This chart installs the Group Sync Operator (minimum version 0.0.31) and configures it to synchronize user groups from IBM Security Verify into OpenShift on a defined cron schedule. + ## Configuration @@ -59,7 +63,8 @@ sm: # Secrets Manager configuration For complete documentation of all base cluster values including optional fields like `notifications`, `custom_labels`, `devops`, and `cli_image_repo`, see the [Cluster Base Values Reference](../../docs/reference/cluster-base-values.md). -### Usage Examples +## Examples + **Basic group sync configuration:** ```yaml diff --git a/cluster-applications/053-falcon-operator/README.md b/cluster-applications/053-falcon-operator/README.md index 12c0c0680..5239c1416 100644 --- a/cluster-applications/053-falcon-operator/README.md +++ b/cluster-applications/053-falcon-operator/README.md @@ -3,6 +3,10 @@ CrowdStrike Falcon Operator Installs the CrowdStrike Falcon Operator for node monitoring. See https://github.com/CrowdStrike/falcon-operator +## Overview + +This chart installs the CrowdStrike Falcon Operator and deploys a `FalconNodeSensor` on every cluster node for runtime threat detection and response. It requires a valid CrowdStrike Falcon API client ID and secret. + ## Configuration @@ -64,7 +68,8 @@ sm: # Secrets Manager configuration For complete documentation of all base cluster values including optional fields like `notifications`, `custom_labels`, `devops`, and `cli_image_repo`, see the [Cluster Base Values Reference](../../docs/reference/cluster-base-values.md). -### Usage Examples +## Examples + **Basic Falcon operator installation:** ```yaml diff --git a/cluster-applications/054-cluster-logging-operator/README.md b/cluster-applications/054-cluster-logging-operator/README.md index bf4323b87..57e043145 100644 --- a/cluster-applications/054-cluster-logging-operator/README.md +++ b/cluster-applications/054-cluster-logging-operator/README.md @@ -3,6 +3,10 @@ Cluster Logging Operator Installs the Cluster Logging Operator. For further info see https://docs.openshift.com/container-platform/4.12/observability/logging/cluster-logging.html (replace version in URL with OpenShift version) +## Overview + +This chart installs the OpenShift Cluster Logging Operator and configures log collection and forwarding for cluster-level logs including application, infrastructure, and audit log streams. + Also installs log forwarder for non-MCSP accounts or when indicated. @@ -144,6 +148,15 @@ cluster_logging_operator: For more information, see the [OpenShift Cluster Logging documentation](https://docs.openshift.com/container-platform/latest/observability/logging/cluster-logging.html). +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +# No additional values required. +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/cluster-applications/055-instana-agent-operator/README.md b/cluster-applications/055-instana-agent-operator/README.md index 8004482aa..937e54324 100644 --- a/cluster-applications/055-instana-agent-operator/README.md +++ b/cluster-applications/055-instana-agent-operator/README.md @@ -3,6 +3,10 @@ Instana Agent Operator Installs the Instana Agent Operator. Additionally, a cron job is installed that +## Overview + +This chart installs the Instana Agent Operator and deploys an `InstanaAgent` CR that monitors all nodes. It also creates a `CronJob` that automatically discovers DB2 instances in the cluster and updates the Instana agent configuration with their connection details. + is responsible for updating the Instana agent custom resource with the connection information for each DB2 instance in the cluster. @@ -69,7 +73,8 @@ sm: # Secrets Manager configuration For complete documentation of all base cluster values including optional fields like `notifications`, `custom_labels`, `devops`, and `cli_image_repo`, see the [Cluster Base Values Reference](../../docs/reference/cluster-base-values.md). -### Usage Examples +## Examples + **Basic Instana agent installation:** ```yaml diff --git a/cluster-applications/060-custom-sa/README.md b/cluster-applications/060-custom-sa/README.md index 27e5697ce..a08f2c36d 100644 --- a/cluster-applications/060-custom-sa/README.md +++ b/cluster-applications/060-custom-sa/README.md @@ -3,6 +3,10 @@ Custom Service Accounts Creates configurable service accounts with assigned rbac +## Overview + +This chart creates custom `ServiceAccount` resources required by MAS cluster operations. It provisions the service accounts and associated RBAC resources needed for privileged cluster tasks. + ## Configuration @@ -93,6 +97,15 @@ custom_sa: - `cluster-admin` - Full cluster access - `cluster-reader` - Read-only cluster access +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +# No additional values required. +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/cluster-applications/061-ibm-rbac/README.md b/cluster-applications/061-ibm-rbac/README.md index 66e80b67b..b0389667f 100644 --- a/cluster-applications/061-ibm-rbac/README.md +++ b/cluster-applications/061-ibm-rbac/README.md @@ -3,6 +3,10 @@ IBM Resource-Based Access Control (RBAC) Installs the IBM RBAC roles and role bindings. Groups are managed by the Group Sync Operator. +## Overview + +This chart provisions cluster-level RBAC resources required by IBM MAS operations, including `ClusterRole` and `ClusterRoleBinding` objects for MAS operators and service accounts. + ## Configuration @@ -115,6 +119,15 @@ This chart creates the following custom ClusterRoles: - Groups synchronized from IBM Security Verify or other identity provider - Groups must exist in OpenShift before bindings are created +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +# No additional values required. +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/cluster-applications/200-cluster-promotion/README.md b/cluster-applications/200-cluster-promotion/README.md index 5391e2997..4a4fb9a19 100644 --- a/cluster-applications/200-cluster-promotion/README.md +++ b/cluster-applications/200-cluster-promotion/README.md @@ -3,6 +3,10 @@ Cluster Promotion Takes cluster level changes and promotes them to the next level +## Overview + +This chart manages cluster promotion workflows, enabling controlled promotion of MAS deployments from one environment to another (e.g. dev → staging → production) through GitOps automation. + ## Configuration @@ -138,6 +142,15 @@ target_pr_title: "Automated cluster promotion - Production" This enables automated promotion of cluster configurations from one environment to another (e.g., dev → staging → production). +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +# No additional values required. +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/cluster-applications/300-mas-provisioner/README.md b/cluster-applications/300-mas-provisioner/README.md index 6a830f01c..99a7d0962 100644 --- a/cluster-applications/300-mas-provisioner/README.md +++ b/cluster-applications/300-mas-provisioner/README.md @@ -3,6 +3,10 @@ IBM MAS Provisioner (For Internal Use Only) Installs the MAS Provisioner service which sends a notification when an order comes through AWS market place. The MAS provisioner service broker is intended for internal use only. +## Overview + +This chart installs the MAS Provisioner, which automates the provisioning lifecycle for IBM Maximo Application Suite instances including installation, upgrade, and deprovisioning operations. + ## Configuration @@ -203,6 +207,15 @@ mas_provisioner: - **Monitoring**: Enable Instana integration for production deployments - **Alerting**: Configure OCM alerts for critical notifications +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +# No additional values required. +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/000-ibm-sync-resources/README.md b/instance-applications/000-ibm-sync-resources/README.md index 1d264fa0e..04122598f 100644 --- a/instance-applications/000-ibm-sync-resources/README.md +++ b/instance-applications/000-ibm-sync-resources/README.md @@ -3,6 +3,10 @@ IBM MAS Sync Resources Instantiated by the /gitops/root-applications/ibm-mas-instance-root/templates/90-ibm-sync-resources.yaml root application. +## Overview + +This chart provisions the foundational cluster resources needed before MAS synchronization begins, including namespaces, RBAC, and Secrets Manager credential resources. + Various resources required to run Jobs contained in the 91-ibm-sync-jobs chart. @@ -10,6 +14,16 @@ This application has a lower syncwave (90) than that of the 91-ibm-sync-jobs app This is to ensure that the resources to persist long enough for the PostDelete hooks in that 91-ibm-sync-jobs to complete, while still being cleaned up successfully when MAS instance is deprovisioned. +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_sync_resources: + run_sync_hooks: true +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/010-ibm-sync-jobs/README.md b/instance-applications/010-ibm-sync-jobs/README.md index 040ed591f..fa2727418 100644 --- a/instance-applications/010-ibm-sync-jobs/README.md +++ b/instance-applications/010-ibm-sync-jobs/README.md @@ -3,6 +3,10 @@ IBM MAS Sync Jobs Instantiated by the /gitops/root-applications/ibm-mas-instance-root/templates/91-ibm-sync-jobs.yaml root application. +## Overview + +This chart runs synchronization Jobs that transfer configuration and secrets into the cluster from AWS Secrets Manager before the main MAS installation proceeds. + Defines Jobs to perform various tasks that need to happen before ibm-sls and the suite are installed, and after they are removed. It also performs various tasks for CP4D when it is set to be installed or upgraded. @@ -10,6 +14,16 @@ Defines Jobs to perform various tasks that need to happen before ibm-sls and the Supporting resources are defined in the 90-ibm-sync-resources chart which is managed by an application with a lower syncwave (90). This is to ensure that these resources perist long enough for any PostDelete hooks in this chart to complete. +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_sync_jobs: + run_sync_hooks: true +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/100-ibm-sls/README.md b/instance-applications/100-ibm-sls/README.md index 8653c49e0..1a9e6fe2d 100644 --- a/instance-applications/100-ibm-sls/README.md +++ b/instance-applications/100-ibm-sls/README.md @@ -9,6 +9,17 @@ Installs the `ibm-sls` operator and creates an instance of the `LicenseService`. Contains a job that runs last (`07-postsync-update-sm_Job.yaml`). This registers the `${ACCOUNT_ID}/${CLUSTER_ID}/${INSTANCE_ID}/sls` secret in the **Secrets Vault** used to share some information that is generated at runtime with other ArgoCD Applications. +## Examples + +### Minimal SLS configuration + +```yaml +merge-key: "my-account/my-cluster/inst1" +ibm_sls: + sls_url: "https://sls.example.com" + sls_tls_crt_local_file_path: "/tmp/sls.crt" +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/101-ibm-sync-jobs-cp4d/README.md b/instance-applications/101-ibm-sync-jobs-cp4d/README.md index e12f8fcb3..d3479c0f8 100644 --- a/instance-applications/101-ibm-sync-jobs-cp4d/README.md +++ b/instance-applications/101-ibm-sync-jobs-cp4d/README.md @@ -3,12 +3,26 @@ IBM Sync Jobs CP4D Instantiated by the [`101-ibm-sync-jobs-cp4d.yaml`](https://github.com/ibm-mas/gitops/tree/main/root-applications/ibm-mas-instance-root/templates/101-ibm-sync-jobs-cp4d.yaml) root application. +## Overview + +This chart runs synchronization Jobs that transfer CP4D-specific configuration and credentials into AWS Secrets Manager before CP4D services are provisioned. + Defines prerequisite catalog sources and a presync Job used to prepare Cloud Pak for Data (CP4D) dependencies before CP4D resources are installed for a MAS instance. The chart creates version-specific `CatalogSource` resources in the CP4D operators namespace and runs a presync Job that gathers operator dependency channel and version information for later use. +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_sync_jobs_cp4d: + run_sync_hooks: true +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/110-ibm-cp4d-operators/README.md b/instance-applications/110-ibm-cp4d-operators/README.md index 7099909f1..6403dc85f 100644 --- a/instance-applications/110-ibm-cp4d-operators/README.md +++ b/instance-applications/110-ibm-cp4d-operators/README.md @@ -3,7 +3,22 @@ IBM Cloud Pak for Data Operator (CPD) Deploys and configures CPD Platform Operator +## Overview +This chart installs the IBM Cloud Pak for Data operators into the cluster, providing the operator framework required before CP4D and its services can be deployed. + + + +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_cp4d_operators: + channel: v4.8 + install_plan: Automatic +``` ## Resources Created diff --git a/instance-applications/110-ibm-cp4d/README.md b/instance-applications/110-ibm-cp4d/README.md index 8b90c5487..2d638c907 100644 --- a/instance-applications/110-ibm-cp4d/README.md +++ b/instance-applications/110-ibm-cp4d/README.md @@ -3,7 +3,22 @@ IBM Cloud Pak for Data (CP4D) Deploys and configures CP4D needed for `MAS Assist` and `MAS Predict`. Deploys the CP4D platform operator and its dependencies. +## Overview +This chart installs IBM Cloud Pak for Data (CP4D) on the cluster, which serves as the AI and data platform foundation for MAS applications that require Watson services and advanced analytics. + + + +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_cp4d: + channel: v4.8 + install_plan: Automatic +``` ## Resources Created diff --git a/instance-applications/110-ibm-cs-control/README.md b/instance-applications/110-ibm-cs-control/README.md index b4515fb8f..80237de19 100644 --- a/instance-applications/110-ibm-cs-control/README.md +++ b/instance-applications/110-ibm-cs-control/README.md @@ -3,7 +3,22 @@ IBM CommonServices Control (CS) Deploys and configures IBM CS Control that is required for IBM CPD +## Overview +This chart installs IBM Common Services Control (CS Control), providing the foundational IBM Cloud Pak shared services including IAM, licensing, and monitoring prerequisites for MAS. + + + +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_cs_control: + channel: v3 + install_plan: Automatic +``` ## Resources Created diff --git a/instance-applications/110-ibm-db2u/README.md b/instance-applications/110-ibm-db2u/README.md index 62b17de3f..49ba7a582 100644 --- a/instance-applications/110-ibm-db2u/README.md +++ b/instance-applications/110-ibm-db2u/README.md @@ -3,7 +3,22 @@ IBM DB2U Deploy and configure db2 operator with configurable version +## Overview +This chart installs the IBM Db2u Operator on the cluster, which is the prerequisite for creating Db2 database instances used by MAS applications such as Manage. + + + +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_db2u: + channel: v110508.0 + install_plan: Automatic +``` ## Resources Created diff --git a/instance-applications/112-ibm-odh/README.md b/instance-applications/112-ibm-odh/README.md index a36d0bdd2..4da3e15de 100644 --- a/instance-applications/112-ibm-odh/README.md +++ b/instance-applications/112-ibm-odh/README.md @@ -3,6 +3,10 @@ IBM ODH Deploy and configure ODH with configurable version +## Overview + +This chart installs Open Data Hub (ODH) on the cluster, providing the open-source AI/ML platform components including Jupyter Hub, model serving, and data science pipeline infrastructure. + ## Migration to RHOAI @@ -10,6 +14,16 @@ Deploy and configure ODH with configurable version Shared resources (aiservice namespace, ServiceMesh, Authorino, Serverless operators, and NetworkPolicies) have ArgoCD protection annotations that prevent deletion during ODH uninstallation, ensuring a safe migration path to RHOAI. +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_odh: + channel: fast +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/116-ibm-rhoai/README.md b/instance-applications/116-ibm-rhoai/README.md index c51f8c751..d0eb7c4e3 100644 --- a/instance-applications/116-ibm-rhoai/README.md +++ b/instance-applications/116-ibm-rhoai/README.md @@ -3,6 +3,10 @@ IBM RHOAI (Red Hat OpenShift AI) Deploy and configure Red Hat OpenShift AI with configurable version +## Overview + +This chart installs Red Hat OpenShift AI (RHOAI) on the cluster, providing a managed AI/ML platform with Jupyter notebooks, model serving, and data science pipeline capabilities. + ## Migration from ODH to RHOAI @@ -16,6 +20,16 @@ To migrate from OpenDataHub (ODH) to Red Hat OpenShift AI (RHOAI): **Note**: The migration is safe because shared resources (aiservice namespace, ServiceMesh, Authorino, Serverless operators, and NetworkPolicies) have ArgoCD protection annotations (`Prune=false,Delete=false`) that prevent deletion during ODH uninstallation. RHOAI will reuse these existing resources. +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_rhoai: + install: true +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/120-ibm-dbs-rds-database/README.md b/instance-applications/120-ibm-dbs-rds-database/README.md index c2223fbf2..36bad0d48 100644 --- a/instance-applications/120-ibm-dbs-rds-database/README.md +++ b/instance-applications/120-ibm-dbs-rds-database/README.md @@ -3,7 +3,22 @@ IBM DB2U Database Create a Db2RDS database for a MAS app. +## Overview +This chart provisions and configures an Amazon RDS database instance for use with IBM MAS, including the creation of the RDS instance, parameter groups, subnet groups, and Secrets Manager integration. + + + +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_dbs_rds_database: + db_instance_class: db.t3.medium + engine_version: "14.10" +``` ## Resources Created diff --git a/instance-applications/120-ibm-spark/README.md b/instance-applications/120-ibm-spark/README.md index 9798b6a59..a9adfae57 100644 --- a/instance-applications/120-ibm-spark/README.md +++ b/instance-applications/120-ibm-spark/README.md @@ -3,9 +3,24 @@ IBM Analytics Engine Powered by Apache Spark (Spark) Deploys and configures the CP4D Service, IBM Analytics Engine Powered by Apache Spark (Spark). Deploys the Spark operator and its dependencies. +## Overview + +This chart installs IBM Analytics Engine powered by Apache Spark on Cloud Pak for Data, enabling large-scale distributed data processing for MAS analytics and AI workloads. + Spark extends jupyter notebooks features inside Watson Studio notebooks which can be leveraged by Maximo Predict data sets. +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_spark: + channel: v4.8 + install_plan: Automatic +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/120-ibm-spss/README.md b/instance-applications/120-ibm-spss/README.md index 094e3e453..c699ebd98 100644 --- a/instance-applications/120-ibm-spss/README.md +++ b/instance-applications/120-ibm-spss/README.md @@ -3,10 +3,25 @@ SPSS Modeler Deploys and configures the CP4D Service, SPSS Modeler. +## Overview + +This chart installs IBM SPSS Statistics on IBM Cloud Pak for Data as part of a MAS deployment, enabling advanced statistical analysis capabilities for MAS applications. + [SPSS Modeler](https://www.ibm.com/docs/en/cloud-paks/cp-data/4.8.x?topic=modeler-installing) optional dependency for [Predict](https://www.ibm.com/docs/en/mas-cd/mhmpmh-and-p-u/continuous-delivery) +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_spss: + channel: v8.1 + install_plan: Automatic +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/120-ibm-wml/README.md b/instance-applications/120-ibm-wml/README.md index ae239a251..6c6c9865c 100644 --- a/instance-applications/120-ibm-wml/README.md +++ b/instance-applications/120-ibm-wml/README.md @@ -3,9 +3,24 @@ IBM Watson Machine Learning (WML) Deploys and configures the CP4D Service, Watson Machine Learning (WML) needed for `MAS Predict`. Deploys WML operator and its dependencies. +## Overview +This chart installs IBM Watson Machine Learning (WML) on IBM Cloud Pak for Data as part of a MAS deployment, enabling ML model training, deployment, and inference capabilities for MAS applications. + + +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_wml: + channel: v4.8 + install_plan: Automatic +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/120-ibm-wsl/README.md b/instance-applications/120-ibm-wsl/README.md index 953c16262..ac9f91850 100644 --- a/instance-applications/120-ibm-wsl/README.md +++ b/instance-applications/120-ibm-wsl/README.md @@ -3,7 +3,22 @@ IBM Watson Studio Local (WSL) Deploys and configures the CP4D Service, Watson Studio Local (WSL) needed for `MAS Predict`. Deploys WSL operator and its dependencies. +## Overview +This chart installs IBM Watson Studio Local (WSL) on Cloud Pak for Data, providing an interactive data science environment with notebook authoring and model development capabilities. + + + +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_wsl: + channel: v4.8 + install_plan: Automatic +``` ## Resources Created diff --git a/instance-applications/121-ibm-post-sync-job-cp4d-services/README.md b/instance-applications/121-ibm-post-sync-job-cp4d-services/README.md index 0be90a7ee..47b94bf79 100644 --- a/instance-applications/121-ibm-post-sync-job-cp4d-services/README.md +++ b/instance-applications/121-ibm-post-sync-job-cp4d-services/README.md @@ -3,12 +3,26 @@ IBM Post Sync Job CP4D Services Instantiated by the [`121-ibm-post-sync-job-cp4d-services.yaml`](https://github.com/ibm-mas/gitops/tree/main/root-applications/ibm-mas-instance-root/templates/121-ibm-post-sync-job-cp4d-services.yaml) root application. +## Overview + +This chart runs post-sync Jobs that configure CP4D services after installation, including provisioning service instances and updating AWS Secrets Manager with connection credentials. + Defines a post-sync Job used to perform CP4D service follow-up operations after selected CP4D services such as Watson Studio Local (WSL), Watson Machine Learning (WML), or SPSS Modeler are installed. The chart creates namespaced RBAC and a Job in the CP4D operators namespace. The Job waits for CP4D service resources to become ready and applies any required post-install adjustments. +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_post_sync_job_cp4d_services: + run_sync_hooks: true +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/130-ibm-db2u-jdbc-config-rotate-password/README.md b/instance-applications/130-ibm-db2u-jdbc-config-rotate-password/README.md index 478776ab6..8c30733cd 100644 --- a/instance-applications/130-ibm-db2u-jdbc-config-rotate-password/README.md +++ b/instance-applications/130-ibm-db2u-jdbc-config-rotate-password/README.md @@ -3,7 +3,32 @@ IBM DB2U JDBC rotate password Configuration Rotate DB2 user password +## Overview +This chart rotates the Db2u JDBC password for a MAS instance and updates the corresponding JDBC configuration in MAS and AWS Secrets Manager to ensure continued database connectivity. + + + +## Configuration + +### Values + +```yaml +ibm_db2u_jdbc_config_rotate_password: + mas_instance_id: inst1 + jdbc_config_id: system +``` + +## Examples + +### Rotate Db2 JDBC password + +```yaml +merge-key: "my-account/my-cluster/inst1" +ibm_db2u_jdbc_config_rotate_password: + mas_instance_id: inst1 + jdbc_config_id: system +``` ## Resources Created diff --git a/instance-applications/130-ibm-jdbc-config/README.md b/instance-applications/130-ibm-jdbc-config/README.md index 3a77672da..4aace8d3a 100644 --- a/instance-applications/130-ibm-jdbc-config/README.md +++ b/instance-applications/130-ibm-jdbc-config/README.md @@ -3,6 +3,10 @@ IBM JDBC Configuration +## Overview + +This chart configures JDBC database connection settings for a MAS instance, registering database connection details and credentials so MAS applications can connect to relational databases. + Create a JdbcCfg CR instance and associated credentials secret for use by MAS. @@ -10,6 +14,16 @@ Contains a post-delete hook (`postdelete-delete-cr.yaml`) that will ensure the c If using incluster-db2, a pre-sync hook (`00-presync-create-db2-user_Job.yaml`) will run that sets up an LDAP user in DB2 with the credentials provided in the JDBC config. +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_jdbc_config: + jdbc_url: "jdbc:db2://db2.example.com:50000/BLUDB" +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/130-ibm-kafka-config/README.md b/instance-applications/130-ibm-kafka-config/README.md index ca3655605..d19e65dc6 100644 --- a/instance-applications/130-ibm-kafka-config/README.md +++ b/instance-applications/130-ibm-kafka-config/README.md @@ -3,11 +3,25 @@ Kafka Configuration for MAS Core Platform Create a KafkaCfg CR instance and associated credentials secret for use by MAS. +## Overview + +This chart configures the Apache Kafka connection settings for a MAS instance, registering the Kafka endpoint and credentials so MAS IoT and other applications can publish and consume events. + Contains a post-delete hook (`postdelete-delete-cr.yaml`) that will ensure the config CR is deleted when the ArgoCD application managing this chart is deleted (this will not happen by default as the config CR is asserted to be owned by the `Suite` CR by the MAS entity managers). +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_kafka_config: + kafka_bootstrap_server: kafka.example.com:9093 +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/130-ibm-mas-aicfg-config/README.md b/instance-applications/130-ibm-mas-aicfg-config/README.md index 3b306abf3..3ad9e7946 100644 --- a/instance-applications/130-ibm-mas-aicfg-config/README.md +++ b/instance-applications/130-ibm-mas-aicfg-config/README.md @@ -3,10 +3,24 @@ AI Service Configuration for MAS Core Platform Create an AiCfg CR instance and associated credentials secret for use by MAS. +## Overview + +This chart configures the AI Service connection settings for a MAS instance, enabling MAS applications to integrate with the IBM AI broker service. + Contains a post-delete hook (`postdelete-delete-cr.yaml`) that will ensure the config CR is deleted when the ArgoCD application managing this chart is deleted (this will not happen by default as the config CR is asserted to be owned by the `Suite` CR by the MAS entity managers). +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_mas_aicfg_config: + ai_service_url: "https://aiservice.example.com" +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/130-ibm-mas-bas-config/README.md b/instance-applications/130-ibm-mas-bas-config/README.md index edf4136bd..f3052cc9a 100644 --- a/instance-applications/130-ibm-mas-bas-config/README.md +++ b/instance-applications/130-ibm-mas-bas-config/README.md @@ -3,10 +3,24 @@ BAS Configuration for MAS Core Platform Create a BasCfg CR instance and associated credentials secret for use by MAS. +## Overview + +This chart configures the IBM Behavior Analysis Service (BAS) connection for a MAS instance, registering the BAS endpoint for telemetry and usage analytics. + Contains a post-delete hook (`postdelete-delete-cr.yaml`) that will ensure the config CR is deleted when the ArgoCD application managing this chart is deleted (this will not happen by default as the config CR is asserted to be owned by the `Suite` CR by the MAS entity managers). +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_mas_bas_config: + bas_url: "https://bas.example.com" +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/130-ibm-mas-idp-config/README.md b/instance-applications/130-ibm-mas-idp-config/README.md index 0059a3485..b07c172f7 100644 --- a/instance-applications/130-ibm-mas-idp-config/README.md +++ b/instance-applications/130-ibm-mas-idp-config/README.md @@ -3,11 +3,25 @@ IDP Configuration for MAS Core Platform Create a IdpCfg CR instance and associated credentials secret for use by MAS. +## Overview + +This chart configures the Identity Provider (IDP) settings for a MAS instance, enabling SAML or LDAP-based single sign-on integration with the MAS authentication system. + Currently only supports LDAP. Contains a post-delete hook (`postdelete-delete-cr.yaml`) that will ensure the config CR is deleted when the ArgoCD application managing this chart is deleted (this will not happen by default as the config CR is asserted to be owned by the `Suite` CR by the MAS entity managers). +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_mas_idp_config: + idp_type: ldap +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/130-ibm-mas-mongo-config/README.md b/instance-applications/130-ibm-mas-mongo-config/README.md index 285509e2d..9a0d2b650 100644 --- a/instance-applications/130-ibm-mas-mongo-config/README.md +++ b/instance-applications/130-ibm-mas-mongo-config/README.md @@ -3,10 +3,24 @@ Mongo Configuration for MAS Core Platform Create a MongoCfg CR instance and associated credentials secret for use by MAS. +## Overview + +This chart configures the MongoDB connection settings for a MAS instance, registering the MongoDB endpoint and credentials so MAS can connect to its document database. + Contains a post-delete hook (`postdelete-delete-cr.yaml`) that will ensure the config CR is deleted when the ArgoCD application managing this chart is deleted (this will not happen by default as the config CR is asserted to be owned by the `Suite` CR by the MAS entity managers). +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_mas_mongo_config: + mongodb_provider: yaml +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/130-ibm-mas-sls-config/README.md b/instance-applications/130-ibm-mas-sls-config/README.md index f18a91dcf..4a81b6e9b 100644 --- a/instance-applications/130-ibm-mas-sls-config/README.md +++ b/instance-applications/130-ibm-mas-sls-config/README.md @@ -3,10 +3,24 @@ SLS Configuration for MAS Core Platform Create a SlsCfg CR instance and associated credentials secret for use by MAS. +## Overview + +This chart configures the IBM Suite License Service (SLS) connection for a MAS instance, registering the SLS endpoint and credentials so MAS can validate entitlements. + Contains a post-delete hook (`postdelete-delete-cr.yaml`) that will ensure the config CR is deleted when the ArgoCD application managing this chart is deleted (this will not happen by default as the config CR is asserted to be owned by the `Suite` CR by the MAS entity managers). +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_mas_sls_config: + sls_url: "https://sls.example.com" +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/130-ibm-mas-smtp-config/README.md b/instance-applications/130-ibm-mas-smtp-config/README.md index 469f5a68e..70d4d09ac 100644 --- a/instance-applications/130-ibm-mas-smtp-config/README.md +++ b/instance-applications/130-ibm-mas-smtp-config/README.md @@ -3,10 +3,26 @@ SMTP Configuration for MAS Core Platform Create a SmtpCfg CR instance and associated credentials secret for use by MAS. +## Overview + +This chart configures the SMTP connection settings for IBM MAS, enabling the suite to send email notifications and alerts through an external mail server. + Contains a post-delete hook (`postdelete-delete-cr.yaml`) that will ensure the config CR is deleted when the ArgoCD application managing this chart is deleted (this will not happen by default as the config CR is asserted to be owned by the `Suite` CR by the MAS entity managers). +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_mas_smtp_config: + smtp_host: smtp.example.com + smtp_port: "587" + from_address: mas@example.com +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/130-ibm-mas-suite/README.md b/instance-applications/130-ibm-mas-suite/README.md index 0e44e079e..58a5b5d73 100644 --- a/instance-applications/130-ibm-mas-suite/README.md +++ b/instance-applications/130-ibm-mas-suite/README.md @@ -3,7 +3,22 @@ MAS Core Platform Installs the `ibm-mas` operator and creates an instance of the `Suite`. +## Overview +This chart installs and configures the IBM Maximo Application Suite (MAS) core operator and `Suite` CR, which is the foundation for all MAS applications and workspaces. + + + +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_mas_suite: + mas_instance_id: inst1 + mas_domain: mas.example.com +``` ## Resources Created diff --git a/instance-applications/130-ibm-objectstorage-config/README.md b/instance-applications/130-ibm-objectstorage-config/README.md index c381d9eb9..63753667d 100644 --- a/instance-applications/130-ibm-objectstorage-config/README.md +++ b/instance-applications/130-ibm-objectstorage-config/README.md @@ -3,10 +3,25 @@ ObjectStorage Configuration for MAS Core Platform Create a ObjectStorageCfg CR instance and associated credentials secret for use by MAS. +## Overview + +This chart configures the object storage connection settings for a MAS instance, registering an IBM Cloud Object Storage or S3-compatible endpoint for use by MAS applications. + Contains a post-delete hook (`postdelete-delete-cr.yaml`) that will ensure the config CR is deleted when the ArgoCD application managing this chart is deleted (this will not happen by default as the config CR is asserted to be owned by the `Suite` CR by the MAS entity managers). +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_objectstorage_config: + storage_provider: aws + bucket_name: mas-inst1 +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/130-ibm-watson-studio-config/README.md b/instance-applications/130-ibm-watson-studio-config/README.md index 40fd77d3e..ed4bf9e13 100644 --- a/instance-applications/130-ibm-watson-studio-config/README.md +++ b/instance-applications/130-ibm-watson-studio-config/README.md @@ -3,7 +3,21 @@ WatsonStudio Configuration for MAS Core Platform Create a WatsonStudioCfg CR instance and associated credentials secret for use by MAS. +## Overview +This chart configures the IBM Watson Studio connection for a MAS instance, enabling data science project integration and notebook-driven analytics within the MAS platform. + + + +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_watson_studio_config: + watson_studio_url: "https://cpd.example.com/watson-studio" +``` ## Resources Created diff --git a/instance-applications/220-ibm-mas-workspace/README.md b/instance-applications/220-ibm-mas-workspace/README.md index be60e58ef..9e224c93b 100644 --- a/instance-applications/220-ibm-mas-workspace/README.md +++ b/instance-applications/220-ibm-mas-workspace/README.md @@ -3,7 +3,22 @@ MAS Core Platform workspace Installs the workspace needed for the `Suite`. +## Overview +This chart creates and configures IBM MAS workspaces, which define the tenant-level logical grouping for users, applications, and data within a MAS instance. + + + +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_mas_workspace: + mas_instance_id: inst1 + mas_workspace_id: masdev +``` ## Resources Created diff --git a/instance-applications/500-540-ibm-mas-suite-app-install/README.md b/instance-applications/500-540-ibm-mas-suite-app-install/README.md index 947864940..2518a38fc 100644 --- a/instance-applications/500-540-ibm-mas-suite-app-install/README.md +++ b/instance-applications/500-540-ibm-mas-suite-app-install/README.md @@ -3,9 +3,25 @@ MAS Application Install Generic chart for installing a MAS Application. +## Overview + +This chart installs IBM MAS applications (Manage, Monitor, IoT, Assist, Visual Inspection, etc.) into a MAS instance by applying the application `Subscription` and `MasApp` custom resources. + Certain templates are enabled only for specific MAS editions (`mas_edition`) and/or applications (`mas_app_id`). +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_mas_suite_app_install: + mas_instance_id: inst1 + mas_app_id: manage + mas_app_channel: 9.0.x +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/510-550-ibm-mas-suite-app-config/README.md b/instance-applications/510-550-ibm-mas-suite-app-config/README.md index f73859f38..49c1d3ec3 100644 --- a/instance-applications/510-550-ibm-mas-suite-app-config/README.md +++ b/instance-applications/510-550-ibm-mas-suite-app-config/README.md @@ -3,9 +3,24 @@ MAS Application Configuration Generic chart for configuring a workspace for a MAS application (a.k.a "activating" the MAS application). +## Overview + +This chart applies application-level configuration to IBM MAS applications (Manage, Monitor, IoT, etc.) after they have been installed, including workspace binding, database, and integration settings. + Certain templates are enabled only for specific MAS applications (`mas_app_id`). +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_mas_suite_app_config: + mas_instance_id: inst1 + mas_app_id: manage +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/550-ibm-mas-addons-config/README.md b/instance-applications/550-ibm-mas-addons-config/README.md index 19a2804c6..0b80bda70 100644 --- a/instance-applications/550-ibm-mas-addons-config/README.md +++ b/instance-applications/550-ibm-mas-addons-config/README.md @@ -3,12 +3,26 @@ MAS Addons Configuration Instantiated by the [`550-ibm-mas-addons-config.yaml`](https://github.com/ibm-mas/gitops/tree/main/root-applications/ibm-mas-instance-root/templates/550-ibm-mas-addons-config.yaml) root application. +## Overview + +This chart applies add-on configuration to IBM MAS applications, enabling optional feature modules and integration settings beyond the base application installation. + Creates MAS add-on configuration custom resources for optional platform capabilities such as allow lists, additional VPN configuration, enhanced disaster recovery, extensions, replica databases, nonshared cluster settings, application configuration, additional resources, and production database access. This chart also includes a post-delete cleanup Job that removes generated `GenericAddon` custom resources when ArgoCD deletes the application and post-delete hooks are enabled. +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +ibm_mas_addons_config: + mas_instance_id: inst1 +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/600-application-admin-rbac/README.md b/instance-applications/600-application-admin-rbac/README.md index 3cf148c1c..dda5abbef 100644 --- a/instance-applications/600-application-admin-rbac/README.md +++ b/instance-applications/600-application-admin-rbac/README.md @@ -11,6 +11,15 @@ This chart dynamically detects which namespaces exist for a MAS instance and app - **ClusterRole**: Provides read-only access to cluster-level resources (nodes, namespaces, storageclasses) - **ClusterRoleBinding**: Binds the ClusterRole to the ArgoCD service account +## Examples + +### Minimal configuration + +```yaml +merge-key: "my-account/my-cluster" +# No additional values required. +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/instance-applications/600-ibm-post-sync-jobs/README.md b/instance-applications/600-ibm-post-sync-jobs/README.md index 51cec4226..5a0677947 100644 --- a/instance-applications/600-ibm-post-sync-jobs/README.md +++ b/instance-applications/600-ibm-post-sync-jobs/README.md @@ -3,10 +3,33 @@ IBM MAS Post Sync Jobs Instantiated by the /gitops/root-applications/ibm-mas-instance-root/templates/600-ibm-post-sync-jobs.yaml root application. +## Overview + +This chart runs post-sync Jobs after the MAS instance installation completes, performing tasks such as updating AWS Secrets Manager with instance credentials and triggering downstream configuration hooks. + Defines Jobs to perform various tasks that need to happen after MAS applications are installed and ready. +## Configuration + +### Values + +```yaml +ibm_post_sync_jobs: + run_sync_hooks: true +``` + +## Examples + +### Default post-sync job configuration + +```yaml +merge-key: "my-account/my-cluster/inst1" +ibm_post_sync_jobs: + run_sync_hooks: true +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/rbac/README.md b/rbac/README.md index 8537c84fa..e20d9155c 100644 --- a/rbac/README.md +++ b/rbac/README.md @@ -105,6 +105,32 @@ See [`kustomize/README.md`](https://github.com/ibm-mas/gitops/tree/main/rbac/kus | `mas-{inst}-visualinspection` | `mas-dev2-visualinspection` | +## Configuration + +RBAC overlays are generated using `generate_rbac_overlays.py`. No Helm values are required — overlays are committed to Git and applied via `kubectl apply -k`. + +## Resources Created + +| Resource Type | Scope | Description | +|---|---|---| +| `Role` | Namespace-scoped | Full permissions for MAS resources in each instance namespace | +| `RoleBinding` | Namespace-scoped | Binds the Role to the ArgoCD service account | +| `ClusterRole` | Cluster-scoped | Read-only access to cluster-level resources | +| `ClusterRoleBinding` | Cluster-scoped | Binds the ClusterRole to the ArgoCD service account | + +## Examples + +### Generate and apply RBAC for a single MAS instance + +```bash +# Generate overlays for instance dev2 +./rbac/generate_rbac_overlays.py \ + --service-account mas-argocd-argocd-application-controller dev2 + +# Apply the generated overlays +kubectl apply -k rbac/kustomize/overlays/mas-argocd-argocd-application-controller +``` + ## Permissions Included ### Namespace-scoped Resources diff --git a/rbac/kustomize/README.md b/rbac/kustomize/README.md index efe85f898..51da02a8d 100644 --- a/rbac/kustomize/README.md +++ b/rbac/kustomize/README.md @@ -5,6 +5,36 @@ This directory contains RBAC configurations for MAS GitOps deployments. There ar 1. **Automated (Recommended)**: Helm chart deployed via ArgoCD when `cluster_admin_role=true` 2. **Manual**: Kustomize-based approach for pre-installation or custom scenarios +## Overview + +This directory provides Kustomize-based namespace-scoped RBAC for MAS GitOps deployments running in Application Admin Mode (`cluster_admin_role=false`, `application_admin_role=true`). When using the automated approach with `cluster_admin_role=true`, the `600-application-admin-rbac` Helm chart handles RBAC automatically — this directory is only required when using the pre-install repository. + +## Configuration + +RBAC overlays are generated per MAS instance using `generate_rbac_overlays.py`. The script creates a `kustomize/overlays//` directory structure with one subdirectory per namespace. No additional Helm values are required. + +## Resources Created + +| Resource Type | Scope | Description | +|---|---|---| +| `Role` | Namespace-scoped | Full permissions for MAS resources in each instance namespace | +| `RoleBinding` | Namespace-scoped | Binds the Role to the ArgoCD service account | +| `ClusterRole` | Cluster-scoped (read-only) | Read access to CRDs, Subscriptions, ArgoCD Applications | +| `ClusterRoleBinding` | Cluster-scoped | Binds the ClusterRole to the ArgoCD service account | + +## Examples + +### Generate and apply RBAC for a MAS instance + +```bash +# Generate overlays for instance dev2 +./rbac/generate_rbac_overlays.py \ + --service-account mas-argocd-argocd-application-controller dev2 + +# Apply +kubectl apply -k rbac/kustomize/overlays/mas-argocd-argocd-application-controller +``` + ## Automated Approach (Recommended) When deploying with `cluster_admin_role=true`, RBAC is automatically installed via the Helm chart at [`instance-applications/600-application-admin-rbac/`](../../instance-applications/600-application-admin-rbac/). diff --git a/root-applications/ibm-mas-account-root/README.md b/root-applications/ibm-mas-account-root/README.md index 58ab7b89f..07e917143 100644 --- a/root-applications/ibm-mas-account-root/README.md +++ b/root-applications/ibm-mas-account-root/README.md @@ -28,6 +28,10 @@ Installs the Cluster Root ArgoCD ApplicationSet [`000-cluster-appset.yaml`](temp - [Sample Configuration File Structure](#sample-configuration-file-structure) +## Overview + +The IBM MAS Account Root Application is the top-level entry point of the GitOps App-of-Apps hierarchy. It installs the Cluster Root ArgoCD ApplicationSet which generates one IBM MAS Cluster Root Application per cluster defined in the configuration repository. + This is the top-level application in the **App of Apps** hierarchy: @@ -202,6 +206,26 @@ Each cluster configuration generates an application named: `cluster.{cluster.id} Where `{cluster.id}` comes from the `cluster.id` field in the configuration files. + +## Examples + +### Minimal values.yaml + +```yaml +account: + id: "production" +generator: + repo_url: "https://github.com/myorg/mas-config" + revision: "main" +source: + repo_url: "https://github.com/ibm-mas/gitops" + revision: "main" +argo: + namespace: "openshift-gitops" + projects: + rootapps: "mas" + apps: "mas" +``` ## Example Configuration ### Minimal values.yaml diff --git a/root-applications/ibm-mas-cluster-root/README.md b/root-applications/ibm-mas-cluster-root/README.md index c7ff111f7..757915a6e 100644 --- a/root-applications/ibm-mas-cluster-root/README.md +++ b/root-applications/ibm-mas-cluster-root/README.md @@ -31,6 +31,10 @@ Manages cluster-level prerequisites, operators, and generates instance root appl - [Related Documentation](#related-documentation) +## Overview + +The IBM MAS Cluster Root Application manages cluster-level prerequisites, operators, and generates instance root applications for MAS deployments on a specific OpenShift cluster. It is generated by the Account Root ApplicationSet and itself renders ArgoCD Applications and ApplicationSets for all cluster-scoped resources. + This application is part of the **App of Apps** hierarchy: @@ -221,6 +225,7 @@ The following table lists all ArgoCD applications and ApplicationSets defined in | [`000-job-cleaner.yaml`](templates/000-job-cleaner.yaml) | job-cleaner | ✓ | | | | [`010-ibm-redhat-cert-manager-app.yaml`](templates/010-ibm-redhat-cert-manager-app.yaml) | redhat-cert-manager | ✓ | | | | [`020-ibm-cis-cert-manager.yaml`](templates/020-ibm-cis-cert-manager.yaml) | ibm-cis-cert-manager | ✓ | | | +| [`025-mongodb-ce-app.yaml`](templates/025-mongodb-ce-app.yaml) | mongodb-ce | ✓ | | | | [`030-ibm-dro-app.yaml`](templates/030-ibm-dro-app.yaml) | dro | ✓ | | | | [`031-ibm-dro-public.yaml`](templates/031-ibm-dro-public.yaml) | ibm-dro-public | ✓ | | | | [`032-ibm-dro-cleanup.yaml`](templates/032-ibm-dro-cleanup.yaml) | ibm-dro-cleanup | ✓ | | | @@ -243,7 +248,7 @@ The following table lists all ArgoCD applications and ApplicationSets defined in ### Role Conditions -- **Cluster Admin Role**: Applications that require `cluster_admin_role` to be set (21 applications) +- **Cluster Admin Role**: Applications that require `cluster_admin_role` to be set (22 applications) - **Both Roles**: Applications/ApplicationSets rendered regardless of role settings (2 ApplicationSets) **Note**: Most applications have additional conditions beyond role requirements (e.g., specific values must be defined). Refer to individual template files for complete rendering logic. @@ -291,6 +296,30 @@ The AI Service Instance ApplicationSet ([`099-aiservice-instance-appset.yaml`](t **Generated Application Naming:** `aiservice-instance.{cluster.id}.{instance.id}` + +## Examples + +### Minimal values.yaml (local testing) + +```yaml +account: + id: "production" +region: + id: "us-east-1" +cluster: + id: "cluster-east-1" +generator: + repo_url: "https://github.com/myorg/mas-config" + revision: "main" +source: + repo_url: "https://github.com/ibm-mas/gitops" + revision: "main" +argo: + namespace: "openshift-gitops" + projects: + rootapps: "mas" + apps: "mas" +``` ## Example Configuration ### Minimal values.yaml (for local testing) diff --git a/root-applications/ibm-mas-sls-root/README.md b/root-applications/ibm-mas-sls-root/README.md index bb0c9a277..1c8e0d5a7 100644 --- a/root-applications/ibm-mas-sls-root/README.md +++ b/root-applications/ibm-mas-sls-root/README.md @@ -27,6 +27,10 @@ Manages standalone Suite License Service (SLS) instances on a specific OpenShift - [Related Documentation](#related-documentation) +## Overview + +The IBM MAS SLS Root Application manages standalone Suite License Service (SLS) instances on a specific OpenShift cluster. It is generated by the SLS ApplicationSet in the Cluster Root Application and directly renders the SLS ArgoCD Application based on values passed from the parent. + This application is part of the **App of Apps** hierarchy: @@ -214,6 +218,27 @@ The SLS Application ([`100-ibm-sls-app.yaml`](templates/100-ibm-sls-app.yaml)) d **Application Naming:** `sls.{ibm_customer_number | lower}.{subscription_id}` + +## Examples + +### Minimal values.yaml (local testing) + +```yaml +account: + id: "production" +region: + id: "us-east-1" +cluster: + id: "cluster-east-1" +source: + repo_url: "https://github.com/ibm-mas/gitops" + revision: "main" +argo: + namespace: "openshift-gitops" + projects: + rootapps: "mas" + apps: "mas" +``` ## Example Configuration ### Minimal values.yaml (for local testing) diff --git a/sls-applications/100-ibm-sls/README.md b/sls-applications/100-ibm-sls/README.md index bec850ba4..eb77bd70f 100644 --- a/sls-applications/100-ibm-sls/README.md +++ b/sls-applications/100-ibm-sls/README.md @@ -7,6 +7,30 @@ Installs the `ibm-sls` operator and creates an instance of the `LicenseService`. Contains a job that runs last (`07-postsync-update-sm_Job.yaml`). This registers the `${ACCOUNT_ID}/${ICN}/${SAAS_SUB_ID}/sls` secret in the **Secrets Vault** used to share some information that is generated at runtime with other ArgoCD Applications. +## Configuration + +### Values + +```yaml +ibm_sls: + sls_namespace: ibm-sls + sls_channel: 3.x + sls_install_plan: Automatic +``` + +## Examples + +### Minimal SLS installation + +```yaml +merge-key: "my-account/icn/my-cluster/sls1" +ibm_sls: + sls_namespace: ibm-sls + sls_channel: 3.x + sls_install_plan: Automatic + mongo_admin_password: "" +``` + ## Resources Created | Resource Type | Resource Name | Namespace | Condition | Installed By | diff --git a/sub-charts/junitreporter/README.md b/sub-charts/junitreporter/README.md index 6483b665a..2f6d40d04 100644 --- a/sub-charts/junitreporter/README.md +++ b/sub-charts/junitreporter/README.md @@ -1,3 +1,38 @@ -Junitreporter +# Junitreporter =============================================================================== -Updates the devops database when a argo app is first synched and then marks it complete along with a junit xml test result. \ No newline at end of file +Updates the devops database when an ArgoCD app is first synced and then marks it complete along with a JUnit XML test result. + +## Overview + +This sub-chart updates the DevOps tracking database at two ArgoCD sync lifecycle points: once when the application sync begins (to mark it in-progress) and again on completion (to record the JUnit XML test result and mark it done). It is used as a dependency by parent charts that require DevOps pipeline integration. + +## Configuration + +### Values + +```yaml +junitreporter: + # DevOps database connection URI + devops_mongo_uri: "" + # Build number for tracking + devops_build_number: "" +``` + +## Resources Created + +| Resource Type | Resource Name | Namespace | Condition | Installed By | +|---|---|---|---|---| +| `Job` | `junitreporter-presync-*` | parent namespace | PreSync hook | `cluster_admin_role` | +| `Job` | `junitreporter-postsync-*` | parent namespace | PostSync hook | `cluster_admin_role` | + +## Examples + +### Include as a sub-chart dependency + +```yaml +# In parent chart's Chart.yaml +dependencies: + - name: junitreporter + version: "1.0.0" + repository: "file://../junitreporter" +``` From 732f15211d5043f1abb4afdee4cc6a2a77135152 Mon Sep 17 00:00:00 2001 From: Jaydip Golviya Date: Mon, 5 Oct 2026 13:54:12 +0530 Subject: [PATCH 24/24] Update 09-postsync-update-sm_Job.yaml --- .../025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml index 0991f9a24..5d1c0a93b 100644 --- a/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml +++ b/cluster-applications/025-mongodb-ce/templates/09-postsync-update-sm_Job.yaml @@ -9,7 +9,7 @@ Meaningful prefix for the job resource name. Must be under 52 chars in length to Use the build/bin/set-cli-image-digest.sh script to update this value across all charts. Included in $_job_hash (see below). */}} -{{- $_cli_image_digest := "sha256:1dc8665fddb9546b84290b0615fc7c7017e19516082b35541d41b8ea82df347b" }} +{{- $_cli_image_digest := "sha256:020f1925421de13beaf439aa09181209875ed3791824bcaaf1daaf910c725266" }} {{- /* A dict of values that influence the behaviour of the job in some way.