From 16583b180ff5b62bc3dbb70982c0c94ad8afcaa0 Mon Sep 17 00:00:00 2001 From: OmkarDeshpande7 Date: Tue, 15 Sep 2026 22:48:28 +0530 Subject: [PATCH] Add release v0.3.5 --- deploy/00crds.yaml | 205 ++++++------------ deploy/04ui.yaml | 5 + ...rade-all-resources.yaml => installer.yaml} | 205 +++++++++++++++++- image_builder/configs/k3s.env | 3 +- .../configs/vjailbreak-settings.yaml | 7 +- releases/v0.3.5.md | 55 +++++ 6 files changed, 334 insertions(+), 146 deletions(-) rename deploy/{upgrade-all-resources.yaml => installer.yaml} (96%) create mode 100644 releases/v0.3.5.md diff --git a/deploy/00crds.yaml b/deploy/00crds.yaml index c5768f6..317beb7 100644 --- a/deploy/00crds.yaml +++ b/deploy/00crds.yaml @@ -1043,6 +1043,9 @@ spec: type: string type: object type: array + projectName: + description: ProjectName is the name of the project in openstack + type: string secretRef: description: SecretRef is the reference to the Kubernetes secret holding OpenStack credentials @@ -2174,6 +2177,9 @@ spec: type: string type: object x-kubernetes-map-type: atomic + vcenterHost: + description: VcenterHost is the vCenter host + type: string required: - datacenter type: object @@ -2637,8 +2643,11 @@ rules: - "" resources: - configmaps + - namespaces - pods - secrets + - serviceaccounts + - services verbs: - create - delete @@ -2664,6 +2673,13 @@ rules: - get - list - watch +- apiGroups: + - "" + resources: + - pods/log + verbs: + - get + - list - apiGroups: - "" resources: @@ -2708,6 +2724,33 @@ rules: - patch - update - watch +- apiGroups: + - networking.k8s.io + resources: + - ingresses + verbs: + - create + - delete + - get + - list + - patch + - update + - watch +- apiGroups: + - rbac.authorization.k8s.io + resources: + - clusterrolebindings + - clusterroles + - rolebindings + - roles + verbs: + - create + - delete + - get + - list + - patch + - update + - watch - apiGroups: - vjailbreak.k8s.pf9.io resources: @@ -3584,6 +3627,23 @@ subjects: name: migration-controller-manager namespace: migration-system --- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + labels: + app.kubernetes.io/component: rbac + app.kubernetes.io/managed-by: kustomize + app.kubernetes.io/name: migration + name: migration-migration-controller-manager-admin +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: cluster-admin +subjects: +- kind: ServiceAccount + name: migration-controller-manager + namespace: migration-system +--- apiVersion: v1 kind: Service metadata: @@ -3598,148 +3658,6 @@ spec: app: vpwned-sdk type: ClusterIP --- -apiVersion: apps/v1 -kind: Deployment -metadata: - labels: - app.kubernetes.io/managed-by: kustomize - app.kubernetes.io/name: migration - control-plane: controller-manager - name: migration-controller-manager - namespace: migration-system -spec: - replicas: 1 - selector: - matchLabels: - control-plane: controller-manager - template: - metadata: - annotations: - kubectl.kubernetes.io/default-container: manager - labels: - control-plane: controller-manager - spec: - affinity: - nodeAffinity: - requiredDuringSchedulingIgnoredDuringExecution: - nodeSelectorTerms: - - matchExpressions: - - key: node-role.kubernetes.io/control-plane - operator: Exists - containers: - - args: - - --leader-elect=false - - --health-probe-bind-address=:8081 - command: - - /manager - env: - - name: MAX_CONCURRENT_RECONCILES - value: "5" - image: quay.io/platform9/vjailbreak-controller:v0.3.4 - imagePullPolicy: IfNotPresent - lifecycle: - preStop: - exec: - command: - - /bin/sh - - -c - - sleep 5 - livenessProbe: - httpGet: - path: /healthz - port: 8081 - initialDelaySeconds: 15 - periodSeconds: 20 - name: manager - readinessProbe: - httpGet: - path: /readyz - port: 8081 - initialDelaySeconds: 5 - periodSeconds: 10 - resources: - requests: - cpu: 200m - memory: 256Mi - volumeMounts: - - mountPath: /etc/pf9/k3s - name: master-token - - mountPath: /home/ubuntu - name: vddk - - mountPath: /etc/hosts - name: hosts-file - readOnly: true - dnsPolicy: ClusterFirstWithHostNet - hostNetwork: true - securityContext: - runAsGroup: 0 - runAsUser: 0 - serviceAccountName: migration-controller-manager - terminationGracePeriodSeconds: 30 - volumes: - - hostPath: - path: /var/lib/rancher/k3s/server - type: Directory - name: master-token - - hostPath: - path: /home/ubuntu - type: Directory - name: vddk - - hostPath: - path: /etc/hosts - type: File - name: hosts-file ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - labels: - app: vpwned-sdk - name: migration-vpwned-sdk - namespace: migration-system -spec: - progressDeadlineSeconds: 600 - replicas: 1 - revisionHistoryLimit: 10 - selector: - matchLabels: - app: vpwned-sdk - strategy: - rollingUpdate: - maxSurge: 25% - maxUnavailable: 25% - type: RollingUpdate - template: - metadata: - labels: - app: vpwned-sdk - spec: - containers: - - image: quay.io/platform9/vjailbreak-vpwned:v0.3.4 - imagePullPolicy: IfNotPresent - name: vpwned - ports: - - containerPort: 3001 - protocol: TCP - resources: {} - terminationMessagePath: /dev/termination-log - terminationMessagePolicy: File - volumeMounts: - - mountPath: /etc/hosts - name: hosts-file - readOnly: true - dnsPolicy: ClusterFirst - restartPolicy: Always - schedulerName: default-scheduler - securityContext: {} - serviceAccountName: migration-controller-manager - terminationGracePeriodSeconds: 30 - volumes: - - hostPath: - path: /etc/hosts - type: File - name: hosts-file ---- apiVersion: networking.k8s.io/v1 kind: Ingress metadata: @@ -3760,4 +3678,5 @@ spec: port: number: 80 path: /dev-api/sdk/(.*) - pathType: ImplementationSpecific \ No newline at end of file + pathType: ImplementationSpecific +--- \ No newline at end of file diff --git a/deploy/04ui.yaml b/deploy/04ui.yaml index 54fc65d..b579940 100644 --- a/deploy/04ui.yaml +++ b/deploy/04ui.yaml @@ -20,6 +20,7 @@ spec: imagePullPolicy: IfNotPresent ports: - containerPort: 80 + --- apiVersion: v1 kind: Service @@ -42,6 +43,8 @@ metadata: namespace: migration-system annotations: nginx.ingress.kubernetes.io/backend-protocol: "HTTP" + nginx.ingress.kubernetes.io/force-ssl-redirect: "true" + nginx.ingress.kubernetes.io/ssl-redirect: "true" spec: ingressClassName: nginx rules: @@ -64,6 +67,8 @@ metadata: nginx.ingress.kubernetes.io/backend-protocol: "HTTPS" nginx.ingress.kubernetes.io/rewrite-target: /$1 nginx.ingress.kubernetes.io/use-regex: "true" + nginx.ingress.kubernetes.io/force-ssl-redirect: "true" + nginx.ingress.kubernetes.io/ssl-redirect: "true" spec: ingressClassName: nginx rules: diff --git a/deploy/upgrade-all-resources.yaml b/deploy/installer.yaml similarity index 96% rename from deploy/upgrade-all-resources.yaml rename to deploy/installer.yaml index 152efa2..2306dab 100644 --- a/deploy/upgrade-all-resources.yaml +++ b/deploy/installer.yaml @@ -1043,6 +1043,9 @@ spec: type: string type: object type: array + projectName: + description: ProjectName is the name of the project in openstack + type: string secretRef: description: SecretRef is the reference to the Kubernetes secret holding OpenStack credentials @@ -2174,6 +2177,9 @@ spec: type: string type: object x-kubernetes-map-type: atomic + vcenterHost: + description: VcenterHost is the vCenter host + type: string required: - datacenter type: object @@ -2637,8 +2643,11 @@ rules: - "" resources: - configmaps + - namespaces - pods - secrets + - serviceaccounts + - services verbs: - create - delete @@ -2664,6 +2673,13 @@ rules: - get - list - watch +- apiGroups: + - "" + resources: + - pods/log + verbs: + - get + - list - apiGroups: - "" resources: @@ -2708,6 +2724,33 @@ rules: - patch - update - watch +- apiGroups: + - networking.k8s.io + resources: + - ingresses + verbs: + - create + - delete + - get + - list + - patch + - update + - watch +- apiGroups: + - rbac.authorization.k8s.io + resources: + - clusterrolebindings + - clusterroles + - rolebindings + - roles + verbs: + - create + - delete + - get + - list + - patch + - update + - watch - apiGroups: - vjailbreak.k8s.pf9.io resources: @@ -3584,6 +3627,23 @@ subjects: name: migration-controller-manager namespace: migration-system --- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + labels: + app.kubernetes.io/component: rbac + app.kubernetes.io/managed-by: kustomize + app.kubernetes.io/name: migration + name: migration-migration-controller-manager-admin +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: cluster-admin +subjects: +- kind: ServiceAccount + name: migration-controller-manager + namespace: migration-system +--- apiVersion: v1 kind: Service metadata: @@ -3598,6 +3658,150 @@ spec: app: vpwned-sdk type: ClusterIP --- +apiVersion: apps/v1 +kind: Deployment +metadata: + labels: + app.kubernetes.io/managed-by: kustomize + app.kubernetes.io/name: migration + control-plane: controller-manager + name: migration-controller-manager + namespace: migration-system +spec: + replicas: 1 + selector: + matchLabels: + control-plane: controller-manager + strategy: + type: Recreate + template: + metadata: + annotations: + kubectl.kubernetes.io/default-container: manager + labels: + control-plane: controller-manager + spec: + affinity: + nodeAffinity: + requiredDuringSchedulingIgnoredDuringExecution: + nodeSelectorTerms: + - matchExpressions: + - key: node-role.kubernetes.io/control-plane + operator: Exists + containers: + - args: + - --leader-elect=false + - --health-probe-bind-address=:8081 + command: + - /manager + env: + - name: MAX_CONCURRENT_RECONCILES + value: "5" + image: quay.io/platform9/vjailbreak-controller:v0.3.5 + imagePullPolicy: IfNotPresent + lifecycle: + preStop: + exec: + command: + - /bin/sh + - -c + - sleep 5 + livenessProbe: + httpGet: + path: /healthz + port: 8081 + initialDelaySeconds: 15 + periodSeconds: 20 + name: manager + readinessProbe: + httpGet: + path: /readyz + port: 8081 + initialDelaySeconds: 5 + periodSeconds: 10 + resources: + requests: + cpu: 200m + memory: 256Mi + volumeMounts: + - mountPath: /etc/pf9/k3s + name: master-token + - mountPath: /home/ubuntu + name: vddk + - mountPath: /etc/hosts + name: hosts-file + readOnly: true + dnsPolicy: ClusterFirstWithHostNet + hostNetwork: true + securityContext: + runAsGroup: 0 + runAsUser: 0 + serviceAccountName: migration-controller-manager + terminationGracePeriodSeconds: 30 + volumes: + - hostPath: + path: /var/lib/rancher/k3s/server + type: Directory + name: master-token + - hostPath: + path: /home/ubuntu + type: Directory + name: vddk + - hostPath: + path: /etc/hosts + type: File + name: hosts-file +--- +apiVersion: apps/v1 +kind: Deployment +metadata: + labels: + app: vpwned-sdk + name: migration-vpwned-sdk + namespace: migration-system +spec: + progressDeadlineSeconds: 600 + replicas: 1 + revisionHistoryLimit: 10 + selector: + matchLabels: + app: vpwned-sdk + strategy: + rollingUpdate: + maxSurge: 25% + maxUnavailable: 25% + type: RollingUpdate + template: + metadata: + labels: + app: vpwned-sdk + spec: + containers: + - image: quay.io/platform9/vjailbreak-vpwned:v0.3.5 + imagePullPolicy: IfNotPresent + name: vpwned + ports: + - containerPort: 3001 + protocol: TCP + resources: {} + terminationMessagePath: /dev/termination-log + terminationMessagePolicy: File + volumeMounts: + - mountPath: /etc/hosts + name: hosts-file + readOnly: true + dnsPolicy: ClusterFirst + restartPolicy: Always + schedulerName: default-scheduler + securityContext: {} + serviceAccountName: migration-controller-manager + terminationGracePeriodSeconds: 30 + volumes: + - hostPath: + path: /etc/hosts + type: File + name: hosts-file +--- apiVersion: networking.k8s.io/v1 kind: Ingress metadata: @@ -3619,4 +3823,3 @@ spec: number: 80 path: /dev-api/sdk/(.*) pathType: ImplementationSpecific ---- \ No newline at end of file diff --git a/image_builder/configs/k3s.env b/image_builder/configs/k3s.env index 76b2e4d..4db9a9b 100644 --- a/image_builder/configs/k3s.env +++ b/image_builder/configs/k3s.env @@ -1,3 +1,4 @@ export IS_MASTER=true export MASTER_IP= -export K3S_TOKEN= \ No newline at end of file +export K3S_TOKEN= +export INSTALL_K3S_EXEC="server --secrets-encryption" \ No newline at end of file diff --git a/image_builder/configs/vjailbreak-settings.yaml b/image_builder/configs/vjailbreak-settings.yaml index 89b6d55..705c5bb 100644 --- a/image_builder/configs/vjailbreak-settings.yaml +++ b/image_builder/configs/vjailbreak-settings.yaml @@ -11,4 +11,9 @@ data: VCENTER_SCAN_CONCURRENCY_LIMIT: "10" # max number of vms to scan at the same time CLEANUP_VOLUMES_AFTER_CONVERT_FAILURE: "false" # cleanup volumes after disk convert failure POPULATE_VMWARE_MACHINE_FLAVORS: "true" # automatically populate VMwareMachine objects with OpenStack flavors - VCENTER_LOGIN_RETRY_LIMIT: "5" # number of retries for vcenter login \ No newline at end of file + VOLUME_AVAILABLE_WAIT_INTERVAL_SECONDS: "10" # interval to wait for volume to become available + VOLUME_AVAILABLE_WAIT_RETRY_LIMIT: "15" # number of retries to wait for volume to become available + VCENTER_LOGIN_RETRY_LIMIT: "5" # number of retries for vcenter login + OPENSTACK_CREDS_REQUEUE_AFTER_MINUTES: "60" # number of minutes to requeue after for openstack creds + VMWARE_CREDS_REQUEUE_AFTER_MINUTES: "60" # number of minutes to requeue after for vmware creds + DEPLOYMENT_NAME: vJailbreak diff --git a/releases/v0.3.5.md b/releases/v0.3.5.md new file mode 100644 index 0000000..8c2ec08 --- /dev/null +++ b/releases/v0.3.5.md @@ -0,0 +1,55 @@ +# v0.3.5 + +- **Tag:** `v0.3.5` +- **Published:** 2025-10-17T10:14:05Z +- **Source release:** https://github.com/platform9/vjailbreak/releases/tag/v0.3.5 + +## Release Notes + +## What's Changed +* Cache OpenStack instance metadata for performance and reliability by @spai-p9 in https://github.com/platform9/vjailbreak/pull/913 +* disabled upgrade button while migrations are in progress by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/934 +* disabled docs update workflow to run on release event by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/935 +* Updated CRD Upgrade logic with missing permissions by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/933 +* Bugfix: Added vmwaresession logged out, after retrieving data from vmware by @rishabh625 in https://github.com/platform9/vjailbreak/pull/939 +* Changed description of a advanced option - Fallback to DHCP by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/948 +* feat: View Migration pod logs from UI by @rishabh625 in https://github.com/platform9/vjailbreak/pull/942 +* Add support to display rdm disk and populate rdm disk details in UI by @patil-pratik-87 in https://github.com/platform9/vjailbreak/pull/926 +* Refactor : VMwareMachine retrieval and validation in migration plan reconciliation by @rishabh625 in https://github.com/platform9/vjailbreak/pull/947 +* Custom header for a vjailbreak deployment through configmap by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/958 +* add creds requeue config to vjailbreak settings by @OmkarDeshpande7 in https://github.com/platform9/vjailbreak/pull/965 +* feat: Implement RDM disks validation and query integration in migration workflow by @rishabh625 in https://github.com/platform9/vjailbreak/pull/963 +* feat: Set owner reference for RDM disks to ensure proper deletion with VMwareCreds by @rishabh625 in https://github.com/platform9/vjailbreak/pull/967 +* feat: Enhance RDM validation to include configuration checks and improve error messaging by @rishabh625 in https://github.com/platform9/vjailbreak/pull/972 +* fix: Update RDM disk migration retry logic and error handling by @rishabh625 in https://github.com/platform9/vjailbreak/pull/970 +* Add a default password for Ubuntu user that needs to be changed on first boot by @sharma-tapas in https://github.com/platform9/vjailbreak/pull/976 +* List udev/fstab rules to preserve device mapping after migrations by @sharma-tapas in https://github.com/platform9/vjailbreak/pull/905 +* Disable selection of older date and time while scheduling cutover by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/960 +* tls: remove cert trust logic, rely on OS_INSECURE for skipping verification by @jessicaralhan in https://github.com/platform9/vjailbreak/pull/863 +* change controller rollout policy to re-create by @OmkarDeshpande7 in https://github.com/platform9/vjailbreak/pull/979 +* Fixed the bug where the script was not passed to the backend + update… by @patil-pratik-87 in https://github.com/platform9/vjailbreak/pull/980 +* feat: Enhance RDM disk info population by validating disk name before updating volume reference by @rishabh625 in https://github.com/platform9/vjailbreak/pull/984 +* disabled log icon in ui (release) by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/986 +* disabled rdm config in UI (release) by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/987 +* enable k3s encryption at rest by @OmkarDeshpande7 in https://github.com/platform9/vjailbreak/pull/990 +* Added htpasswd based authentification for ui by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/994 +* cache cred info for UI by @OmkarDeshpande7 in https://github.com/platform9/vjailbreak/pull/996 +* Removed secrets GET calls from UI by @OmkarDeshpande7 in https://github.com/platform9/vjailbreak/pull/995 +* Added command line utility to change and manage the user credentials for UI by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/1002 +* bugfix: add limit to log streaming - limit number of bytes by @rishabh625 in https://github.com/platform9/vjailbreak/pull/988 +* Implemented automated HTTPS with Cert-Manager (release) by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/1005 +* removed nonce from CSP by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/1006 +* Vjbctl - utility to add and manage users by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/1003 +* Vjbctl by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/1010 +* cronjob fix by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/1013 +* Add host entries to migration-vpwned-ingress by @spai-p9 in https://github.com/platform9/vjailbreak/pull/1015 +* Implemented HTTPS with Cert-Manager by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/1021 +* Updated default username from ubuntu to admin by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/1023 +* added --no-restart to the utility to vjbctl by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/1024 +* fixed count of selected vm by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/1022 +* Custom title on browser tab for each vjailbreak VM deployment by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/1026 + +## New Contributors +* @meghansh-pf9 made their first contribution in https://github.com/platform9/vjailbreak/pull/958 + +**Full Changelog**: https://github.com/platform9/vjailbreak/compare/v0.3.4...v0.3.5