diff --git a/charts/emissary-ingress/Chart.lock b/charts/emissary-ingress/Chart.lock index dc3c07f03e3..7ee7a554014 100644 --- a/charts/emissary-ingress/Chart.lock +++ b/charts/emissary-ingress/Chart.lock @@ -1,6 +1,6 @@ dependencies: - name: ambassador-agent repository: https://s3.amazonaws.com/datawire-static-files/charts - version: 1.0.16 -digest: sha256:7b123f62267cfea698be6025f4a29518df8396f189701e4b9cc836ca254173ff -generated: "2023-10-31T15:03:28.875453-04:00" + version: 1.0.17 +digest: sha256:d31c3d571810b7cfbb14a1e28aebd1bab7182e30c9a87f69902777aefc3c64c2 +generated: "2023-11-03T11:15:13.929684-04:00" diff --git a/charts/emissary-ingress/Chart.yaml.in b/charts/emissary-ingress/Chart.yaml.in index cb11cca333d..dc710a07b91 100644 --- a/charts/emissary-ingress/Chart.yaml.in +++ b/charts/emissary-ingress/Chart.yaml.in @@ -28,7 +28,7 @@ maintainers: email: thigashi@datawire.io dependencies: - name: ambassador-agent - version: 1.0.16 + version: 1.0.17 repository: https://s3.amazonaws.com/datawire-static-files/charts condition: agent.enabled alias: agent diff --git a/k8s-config/emissary-defaultns/require.yaml b/k8s-config/emissary-defaultns/require.yaml index 06f1817bf1a..62e7f53e7f8 100644 --- a/k8s-config/emissary-defaultns/require.yaml +++ b/k8s-config/emissary-defaultns/require.yaml @@ -16,6 +16,7 @@ resources: - { kind: ClusterRole, name: emissary-ingress-agent-default-ns } - { kind: ClusterRole, name: emissary-ingress-agent-deployments } - { kind: ClusterRole, name: emissary-ingress-agent-endpoints } + - { kind: ClusterRole, name: emissary-ingress-agent-configmaps } - { kind: ClusterRole, name: emissary-ingress-agent-ingresses } - { kind: ClusterRole, name: emissary-ingress-agent-pods } - { kind: ClusterRole, name: emissary-ingress-agent-rollouts } diff --git a/k8s-config/emissary-emissaryns/require.yaml b/k8s-config/emissary-emissaryns/require.yaml index 33ee997a809..f31f4276953 100644 --- a/k8s-config/emissary-emissaryns/require.yaml +++ b/k8s-config/emissary-emissaryns/require.yaml @@ -17,6 +17,7 @@ resources: - { kind: ClusterRole, name: emissary-ingress-agent-deployments } - { kind: ClusterRole, name: emissary-ingress-agent-endpoints } - { kind: ClusterRole, name: emissary-ingress-agent-ingresses } + - { kind: ClusterRole, name: emissary-ingress-agent-configmaps } - { kind: ClusterRole, name: emissary-ingress-agent-pods } - { kind: ClusterRole, name: emissary-ingress-agent-rollouts } - { kind: ClusterRole, name: emissary-ingress-agent } diff --git a/manifests/emissary/emissary-defaultns.yaml.in b/manifests/emissary/emissary-defaultns.yaml.in index 62ce3582de8..f3dcf02f9f2 100644 --- a/manifests/emissary/emissary-defaultns.yaml.in +++ b/manifests/emissary/emissary-defaultns.yaml.in @@ -439,8 +439,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 rbac.getambassador.io/role-group: emissary-ingress-agent name: emissary-ingress-agent-applications rules: @@ -460,8 +460,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 rbac.getambassador.io/role-group: emissary-ingress-agent name: emissary-ingress-agent-default-ns rules: @@ -481,8 +481,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 rbac.getambassador.io/role-group: emissary-ingress-agent name: emissary-ingress-agent-deployments rules: @@ -503,8 +503,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 rbac.getambassador.io/role-group: emissary-ingress-agent name: emissary-ingress-agent-endpoints rules: @@ -525,8 +525,29 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 + rbac.getambassador.io/role-group: emissary-ingress-agent + name: emissary-ingress-agent-configmaps +rules: +- apiGroups: + - "" + resources: + - configmaps + verbs: + - get + - list + - watch +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + labels: + app.kubernetes.io/instance: emissary-ingress + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: agent + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 rbac.getambassador.io/role-group: emissary-ingress-agent name: emissary-ingress-agent-ingresses rules: @@ -547,8 +568,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 rbac.getambassador.io/role-group: emissary-ingress-agent name: emissary-ingress-agent-pods rules: @@ -568,8 +589,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 rbac.getambassador.io/role-group: emissary-ingress-agent name: emissary-ingress-agent-rollouts rules: @@ -595,8 +616,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent rules: [] --- @@ -607,8 +628,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent roleRef: apiGroup: rbac.authorization.k8s.io @@ -626,8 +647,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent namespace: default spec: @@ -654,7 +675,7 @@ spec: value: emissary-ingress-agent-cloud-token - name: RPC_CONNECTION_ADDRESS value: https://app.getambassador.io/ - image: docker.io/ambassador/ambassador-agent:1.0.16 + image: docker.io/ambassador/ambassador-agent:1.0.17 imagePullPolicy: IfNotPresent name: agent ports: @@ -672,8 +693,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent-config namespace: default rules: @@ -704,8 +725,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent-leaderelection namespace: default rules: @@ -723,8 +744,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent-config namespace: default roleRef: @@ -743,8 +764,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent-leaderelection namespace: default roleRef: @@ -763,8 +784,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent namespace: default spec: @@ -784,7 +805,7 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent namespace: default diff --git a/manifests/emissary/emissary-emissaryns.yaml.in b/manifests/emissary/emissary-emissaryns.yaml.in index 38021600148..ac4c54a4e84 100644 --- a/manifests/emissary/emissary-emissaryns.yaml.in +++ b/manifests/emissary/emissary-emissaryns.yaml.in @@ -439,8 +439,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 rbac.getambassador.io/role-group: emissary-ingress-agent name: emissary-ingress-agent-applications rules: @@ -460,8 +460,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 rbac.getambassador.io/role-group: emissary-ingress-agent name: emissary-ingress-agent-default-ns rules: @@ -481,8 +481,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 rbac.getambassador.io/role-group: emissary-ingress-agent name: emissary-ingress-agent-deployments rules: @@ -503,8 +503,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 rbac.getambassador.io/role-group: emissary-ingress-agent name: emissary-ingress-agent-endpoints rules: @@ -525,8 +525,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 rbac.getambassador.io/role-group: emissary-ingress-agent name: emissary-ingress-agent-ingresses rules: @@ -547,8 +547,29 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 + rbac.getambassador.io/role-group: emissary-ingress-agent + name: emissary-ingress-agent-configmaps +rules: +- apiGroups: + - "" + resources: + - configmaps + verbs: + - get + - list + - watch +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + labels: + app.kubernetes.io/instance: emissary-ingress + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: agent + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 rbac.getambassador.io/role-group: emissary-ingress-agent name: emissary-ingress-agent-pods rules: @@ -568,8 +589,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 rbac.getambassador.io/role-group: emissary-ingress-agent name: emissary-ingress-agent-rollouts rules: @@ -595,8 +616,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent rules: [] --- @@ -607,8 +628,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent roleRef: apiGroup: rbac.authorization.k8s.io @@ -626,8 +647,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent namespace: emissary spec: @@ -654,7 +675,7 @@ spec: value: emissary-ingress-agent-cloud-token - name: RPC_CONNECTION_ADDRESS value: https://app.getambassador.io/ - image: docker.io/ambassador/ambassador-agent:1.0.16 + image: docker.io/ambassador/ambassador-agent:1.0.17 imagePullPolicy: IfNotPresent name: agent ports: @@ -672,8 +693,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent-config namespace: emissary rules: @@ -704,8 +725,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent-leaderelection namespace: emissary rules: @@ -723,8 +744,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent-config namespace: emissary roleRef: @@ -743,8 +764,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent-leaderelection namespace: emissary roleRef: @@ -763,8 +784,8 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent namespace: emissary spec: @@ -784,7 +805,7 @@ metadata: app.kubernetes.io/instance: emissary-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: agent - app.kubernetes.io/version: 1.0.16 - helm.sh/chart: agent-1.0.16 + app.kubernetes.io/version: 1.0.17 + helm.sh/chart: agent-1.0.17 name: emissary-ingress-agent namespace: emissary