Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PWX-35477 : Support Openshift Prometheus for portworx monitoring on OCP 4.14 #1410

Merged
merged 19 commits into from
Feb 1, 2024
Merged
Show file tree
Hide file tree
Changes from 16 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions cmd/operator/operator.go
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@ import (
"github.com/libopenstorage/operator/pkg/version"
ocp_configv1 "github.com/openshift/api/config/v1"
consolev1 "github.com/openshift/api/console/v1"
routev1 "github.com/openshift/api/route/v1"
monitoringv1 "github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring/v1"
log "github.com/sirupsen/logrus"
"github.com/urfave/cli"
Expand Down Expand Up @@ -228,6 +229,10 @@ func run(c *cli.Context) {
log.Fatalf("Failed to add cluster API resources to the scheme: %v", err)
}

if err := routev1.AddToScheme(mgr.GetScheme()); err != nil {
log.Fatalf("Failed to add cluster API resources to the scheme: %v", err)
}

// Create Service and ServiceMonitor objects to expose the metrics to Prometheus
metricsPort := c.Int(flagMetricsPort)
metricsServicePorts := []v1.ServicePort{
Expand Down
149 changes: 145 additions & 4 deletions drivers/storage/portworx/component/autopilot.go
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,8 @@ import (
"sort"
"strings"

"github.com/sirupsen/logrus"

"github.com/hashicorp/go-version"
pxutil "github.com/libopenstorage/operator/drivers/storage/portworx/util"
corev1 "github.com/libopenstorage/operator/pkg/apis/core/v1"
Expand Down Expand Up @@ -45,7 +47,12 @@ const (
AutopilotDefaultProviderEndpoint = "http://px-prometheus:9090"
// AutopilotDefaultReviewersKey is a key for default reviewers array in gitops config map
AutopilotDefaultReviewersKey = "defaultReviewers"
defaultAutopilotCPU = "0.1"
// OCPPrometheusUserWorkloadSecretPrefix name of OCP user-workload Prometheus secret
OCPPrometheusUserWorkloadSecretPrefix = "prometheus-user-workload-token"
// Autopilot Secret name for prometheus-user-workload-token
AutopilotSecretName = "autopilot-prometheus-auth"
defaultAutopilotCPU = "0.1"
OpenshiftPrometheusSupportedVersion = "4.14"
nikita-bhatia marked this conversation as resolved.
Show resolved Hide resolved
)

var (
Expand Down Expand Up @@ -80,12 +87,49 @@ var (
},
},
}

openshiftDeploymentVolume = []corev1.VolumeSpec{
{
Name: "token-volume",
MountPath: "/var/local/secrets",
ReadOnly: true,
VolumeSource: v1.VolumeSource{
Secret: &v1.SecretVolumeSource{
SecretName: AutopilotSecretName,
Items: []v1.KeyToPath{
{
Key: "token",
Path: "token",
},
},
},
},
},
{
Name: "ca-cert-volume",
MountPath: "/etc/ssl/certs",
ReadOnly: true,
VolumeSource: v1.VolumeSource{
Secret: &v1.SecretVolumeSource{
SecretName: AutopilotSecretName,
Items: []v1.KeyToPath{
{
Key: "cacert",
Path: "ca-certificates.crt",
},
},
},
},
},
}
)

type autopilot struct {
isCreated bool
k8sClient client.Client
k8sVersion version.Version
isCreated bool
k8sClient client.Client
k8sVersion version.Version
isUserWorkloadSupported *bool
isVolumeMounted bool
}

func (c *autopilot) Name() string {
Expand Down Expand Up @@ -128,6 +172,11 @@ func (c *autopilot) Reconcile(cluster *corev1.StorageCluster) error {
if err := c.createClusterRoleBinding(cluster.Namespace); err != nil {
return err
}
if c.isOCPUserWorkloadSupported() {
if err := c.createSecret(cluster.Namespace, ownerRef); err != nil {
piyush-nimbalkar marked this conversation as resolved.
Show resolved Hide resolved
return err
}
}
if err := c.createDeployment(cluster, ownerRef); err != nil {
return err
}
Expand All @@ -151,12 +200,20 @@ func (c *autopilot) Delete(cluster *corev1.StorageCluster) error {
if err := k8sutil.DeleteDeployment(c.k8sClient, AutopilotDeploymentName, cluster.Namespace, *ownerRef); err != nil {
return err
}
if c.isOCPUserWorkloadSupported() {
if err := k8sutil.DeleteSecret(c.k8sClient, AutopilotSecretName, cluster.Namespace, *ownerRef); err != nil {
return err
}
}

c.MarkDeleted()
return nil
}

func (c *autopilot) MarkDeleted() {
c.isCreated = false
c.isUserWorkloadSupported = nil
c.isVolumeMounted = false
}

func (c *autopilot) createConfigMap(
Expand Down Expand Up @@ -248,6 +305,30 @@ func (c *autopilot) createConfigMap(
return err
}

func (c *autopilot) createSecret(clusterNamespace string, ownerRef *metav1.OwnerReference) error {

token, cert, err := c.getPrometheusTokenAndCert()
if err != nil {
return err
}

return k8sutil.CreateOrUpdateSecret(
c.k8sClient,
&v1.Secret{
ObjectMeta: metav1.ObjectMeta{
Name: AutopilotSecretName,
Namespace: clusterNamespace,
OwnerReferences: []metav1.OwnerReference{*ownerRef},
},
Data: map[string][]byte{
"token": []byte(token),
"cacert": []byte(cert),
},
},
ownerRef,
)
}

func (c *autopilot) createServiceAccount(
clusterNamespace string,
ownerRef *metav1.OwnerReference,
Expand Down Expand Up @@ -643,6 +724,12 @@ func (c *autopilot) getDesiredVolumesAndMounts(
cluster *corev1.StorageCluster,
) ([]v1.Volume, []v1.VolumeMount) {
volumeSpecs := make([]corev1.VolumeSpec, 0)

if c.isOCPUserWorkloadSupported() && !c.isVolumeMounted {
c.isVolumeMounted = true
piyush-nimbalkar marked this conversation as resolved.
Show resolved Hide resolved
autopilotDeploymentVolumes = append(autopilotDeploymentVolumes, openshiftDeploymentVolume...)
}

for _, v := range autopilotDeploymentVolumes {
vCopy := v.DeepCopy()
volumeSpecs = append(volumeSpecs, *vCopy)
Expand All @@ -659,6 +746,60 @@ func (c *autopilot) getDesiredVolumesAndMounts(
return volumes, volumeMounts
}

func (c *autopilot) getPrometheusTokenAndCert() (encodedToken, caCert string, err error) {
secrets := &v1.SecretList{}
err = c.k8sClient.List(
context.TODO(),
secrets,
client.InNamespace("openshift-user-workload-monitoring"),
)

if err != nil {
return "", "", err
}

// Iterate through the secrets list to process prometheus-user-workload-token secret
var secretFound bool
for _, secret := range secrets.Items {

if strings.HasPrefix(secret.Name, OCPPrometheusUserWorkloadSecretPrefix) {
secretFound = true
// Retrieve the token data from the secret as []byte
tokenBytes, ok := secret.Data["token"]
if !ok {
return encodedToken, caCert, fmt.Errorf("token not found in secret")
}

// Retrieve the ca.cert data from the secret as []byte
cert, ok := secret.Data["ca.crt"]
if !ok {
return encodedToken, caCert, fmt.Errorf("cert not found in secret")
}

encodedToken = string(tokenBytes)
caCert = string(cert)
piyush-nimbalkar marked this conversation as resolved.
Show resolved Hide resolved
break
}
}

if !secretFound {
return "", "", fmt.Errorf("prometheus-user-workload-token not found. Please make sure that user workload monitoring is enabled in openshift")
}
return encodedToken, caCert, nil
}

func (c *autopilot) isOCPUserWorkloadSupported() bool {
if c.isUserWorkloadSupported == nil {
isSupported, err := pxutil.IsSupportedOCPVersion(c.k8sClient, OpenshiftPrometheusSupportedVersion)
if err != nil {
logrus.Errorf("Failed to check if OCP user workload monitoring is supported: %v", err)
return false
}
c.isUserWorkloadSupported = &isSupported
}
return *c.isUserWorkloadSupported
}

// RegisterAutopilotComponent registers the Autopilot component
func RegisterAutopilotComponent() {
Register(AutopilotComponentName, &autopilot{})
Expand Down
8 changes: 4 additions & 4 deletions drivers/storage/portworx/component/plugin.go
Original file line number Diff line number Diff line change
Expand Up @@ -113,7 +113,7 @@ func (p *plugin) IsEnabled(cluster *corev1.StorageCluster) bool {
}

for _, v := range operator.Status.Versions {
if v.Name == OpenshiftAPIServer && isVersionSupported(v.Version) {
if v.Name == OpenshiftAPIServer && isVersionSupported(v.Version, OpenshiftSupportedVersion) {
p.isPluginSupported = boolPtr(true)
return true
}
Expand Down Expand Up @@ -349,14 +349,14 @@ func updateDataIfNginxConfigMap(cm *v1.ConfigMap, storageNs string) {
}
}

func isVersionSupported(v string) bool {
targetVersion, err := version.NewVersion(OpenshiftSupportedVersion)
func isVersionSupported(current, target string) bool {
targetVersion, err := version.NewVersion(target)
if err != nil {
logrus.Errorf("Error during parsing version : %s ", err)
return false
}

currentVersion, err := version.NewVersion(v)
currentVersion, err := version.NewVersion(current)
if err != nil {
logrus.Errorf("Error during parsing version : %s ", err)
return false
Expand Down
Loading
Loading