diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml new file mode 100644 index 0000000..14d61f9 --- /dev/null +++ b/.github/workflows/ci.yaml @@ -0,0 +1,76 @@ +name: CI + +on: + push: + branches: + - main + - release-* + workflow_dispatch: {} + +env: + DOCKER_BUILDX_VERSION: 'v0.8.2' + + XPKG_ACCESS_ID: ${{ secrets.XPKG_ACCESS_ID }} + +jobs: + detect-noop: + runs-on: ubuntu-22.04 + outputs: + noop: ${{ steps.noop.outputs.should_skip }} + steps: + - name: Detect No-op Changes + id: noop + uses: fkirc/skip-duplicate-actions@v2.0.0 + with: + github_token: ${{ secrets.GITHUB_TOKEN }} + paths_ignore: '["**.md", "**.png", "**.jpg"]' + do_not_skip: '["workflow_dispatch", "schedule", "push"]' + + publish-artifacts: + runs-on: ubuntu-22.04 + needs: detect-noop + if: needs.detect-noop.outputs.noop != 'true' + + steps: + - name: Setup QEMU + uses: docker/setup-qemu-action@v1 + with: + platforms: all + + - name: Setup Docker Buildx + uses: docker/setup-buildx-action@v1 + with: + version: ${{ env.DOCKER_BUILDX_VERSION }} + install: true + + - name: Checkout + uses: actions/checkout@v2 + with: + submodules: true + + - name: Fetch History + run: git fetch --prune --unshallow + + - name: Build Artifacts + run: make -j2 build.all + env: + # We're using docker buildx, which doesn't actually load the images it + # builds by default. Specifying --load does so. + BUILD_ARGS: "--load" + + - name: Publish Artifacts to GitHub + uses: actions/upload-artifact@v2 + with: + name: output + path: _output/** + + - name: Login to Upbound + uses: docker/login-action@v1 + if: env.XPKG_ACCESS_ID != '' + with: + registry: xpkg.upbound.io + username: ${{ secrets.XPKG_ACCESS_ID }} + password: ${{ secrets.XPKG_TOKEN }} + + - name: Publish Artifacts + run: make -j2 publish BRANCH_NAME=${GITHUB_REF##*/} diff --git a/.github/workflows/e2e.yaml b/.github/workflows/e2e.yaml new file mode 100644 index 0000000..c1ccfd4 --- /dev/null +++ b/.github/workflows/e2e.yaml @@ -0,0 +1,14 @@ +name: End to End Testing + +on: + issue_comment: + types: [created] + +jobs: + e2e: + uses: upbound/uptest/.github/workflows/pr-comment-trigger.yml@main + with: + package-type: configuration + secrets: + UPTEST_CLOUD_CREDENTIALS: ${{ secrets.UPTEST_CLOUD_CREDENTIALS }} + UPTEST_DATASOURCE: ${{ secrets.UPTEST_DATASOURCE }} diff --git a/.github/workflows/tag.yml b/.github/workflows/tag.yml new file mode 100644 index 0000000..96a8af7 --- /dev/null +++ b/.github/workflows/tag.yml @@ -0,0 +1,26 @@ +name: Tag + +on: + workflow_dispatch: + inputs: + version: + description: 'Release version (e.g. v0.1.0)' + required: true + message: + description: 'Tag message' + required: true + +jobs: + create-tag: + runs-on: ubuntu-22.04 + + steps: + - name: Checkout + uses: actions/checkout@v2 + + - name: Create Tag + uses: negz/create-tag@v1 + with: + version: ${{ github.event.inputs.version }} + message: ${{ github.event.inputs.message }} + token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..12ef31c --- /dev/null +++ b/.gitignore @@ -0,0 +1,8 @@ +/.cache +/.work +/_output +/results +/.idea + +*.xpkg +kubeconfig \ No newline at end of file diff --git a/.gitmodules b/.gitmodules new file mode 100644 index 0000000..c2fad47 --- /dev/null +++ b/.gitmodules @@ -0,0 +1,3 @@ +[submodule "build"] + path = build + url = https://github.com/upbound/build diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..261eeb9 --- /dev/null +++ b/LICENSE @@ -0,0 +1,201 @@ + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright [yyyy] [name of copyright owner] + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. diff --git a/Makefile b/Makefile new file mode 100644 index 0000000..23354ed --- /dev/null +++ b/Makefile @@ -0,0 +1,75 @@ +# Project Setup +PROJECT_NAME := configuration-aws-network +PROJECT_REPO := github.com/upbound/$(PROJECT_NAME) + +# NOTE(hasheddan): the platform is insignificant here as Configuration package +# images are not architecture-specific. We constrain to one platform to avoid +# needlessly pushing a multi-arch image. +PLATFORMS ?= linux_amd64 +-include build/makelib/common.mk + +# ==================================================================================== +# Setup Kubernetes tools + +UP_VERSION = v0.19.1 +UP_CHANNEL = stable +UPTEST_VERSION = v0.6.1 + +-include build/makelib/k8s_tools.mk +# ==================================================================================== +# Setup XPKG +XPKG_DIR = $(shell pwd) +XPKG_IGNORE = .github/workflows/*.yaml,.github/workflows/*.yml,examples/*.yaml,.work/uptest-datasource.yaml +XPKG_REG_ORGS ?= xpkg.upbound.io/upbound +# NOTE(hasheddan): skip promoting on xpkg.upbound.io as channel tags are +# inferred. +XPKG_REG_ORGS_NO_PROMOTE ?= xpkg.upbound.io/upbound +XPKGS = $(PROJECT_NAME) +-include build/makelib/xpkg.mk + +CROSSPLANE_NAMESPACE = upbound-system +CROSSPLANE_ARGS = "--enable-usages" +-include build/makelib/local.xpkg.mk +-include build/makelib/controlplane.mk + +# ==================================================================================== +# Targets + +# run `make help` to see the targets and options + +# We want submodules to be set up the first time `make` is run. +# We manage the build/ folder and its Makefiles as a submodule. +# The first time `make` is run, the includes of build/*.mk files will +# all fail, and this target will be run. The next time, the default as defined +# by the includes will be run instead. +fallthrough: submodules + @echo Initial setup complete. Running make again . . . + @make + +# Update the submodules, such as the common build scripts. +submodules: + @git submodule sync + @git submodule update --init --recursive + +# We must ensure up is installed in tool cache prior to build as including the k8s_tools machinery prior to the xpkg +# machinery sets UP to point to tool cache. +build.init: $(UP) + +# ==================================================================================== +# End to End Testing + +# This target requires the following environment variables to be set: +# - UPTEST_CLOUD_CREDENTIALS, cloud credentials for the provider being tested, e.g. export UPTEST_CLOUD_CREDENTIALS=$(cat ~/.aws/credentials) +# - To ensure the proper functioning of the end-to-end test resource pre-deletion hook, it is crucial to arrange your resources appropriately. +# You can check the basic implementation here: https://github.com/upbound/uptest/blob/main/internal/templates/01-delete.yaml.tmpl. +# - UPTEST_DATASOURCE_PATH (optional), see https://github.com/upbound/uptest#injecting-dynamic-values-and-datasource +uptest: $(UPTEST) $(KUBECTL) $(KUTTL) + @$(INFO) running automated tests + @KUBECTL=$(KUBECTL) KUTTL=$(KUTTL) $(UPTEST) e2e examples/network-xr.yaml --data-source="${UPTEST_DATASOURCE_PATH}" --setup-script=test/setup.sh --default-timeout=2400 || $(FAIL) + @$(OK) running automated tests + +# This target requires the following environment variables to be set: +# - UPTEST_CLOUD_CREDENTIALS, cloud credentials for the provider being tested, e.g. export UPTEST_CLOUD_CREDENTIALS=$(cat ~/.aws/credentials) +e2e: build controlplane.up local.xpkg.deploy.configuration.$(PROJECT_NAME) uptest + +.PHONY: uptest e2e diff --git a/README.md b/README.md new file mode 100644 index 0000000..3f7a69a --- /dev/null +++ b/README.md @@ -0,0 +1,4 @@ +# AWS Network Configuration + +AWS Network Configuration is reusable Configuration designed to be primarily used in +higher level Configurations. diff --git a/apis/basic/composition.yaml b/apis/basic/composition.yaml new file mode 100644 index 0000000..dbba86c --- /dev/null +++ b/apis/basic/composition.yaml @@ -0,0 +1,461 @@ +apiVersion: apiextensions.crossplane.io/v1 +kind: Composition +metadata: + name: xnetworks.aws.platform.upbound.io + labels: + provider: aws + type: basic +spec: + writeConnectionSecretsToNamespace: upbound-system + compositeTypeRef: + apiVersion: aws.platform.upbound.io/v1alpha1 + kind: XNetwork + patchSets: + - name: providerConfigRef + patches: + - type: FromCompositeFieldPath + fromFieldPath: spec.parameters.providerConfigName + toFieldPath: spec.providerConfigRef.name + - name: deletionPolicy + patches: + - type: FromCompositeFieldPath + fromFieldPath: spec.parameters.deletionPolicy + toFieldPath: spec.deletionPolicy + - name: network-id + patches: + - type: FromCompositeFieldPath + fromFieldPath: spec.parameters.id + toFieldPath: metadata.labels[networks.aws.platform.upbound.io/network-id] + - name: region + patches: + - type: FromCompositeFieldPath + fromFieldPath: spec.parameters.region + toFieldPath: spec.forProvider.region + resources: + - name: vpc + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: VPC + spec: + forProvider: + cidrBlock: 192.168.0.0/16 + enableDnsSupport: true + enableDnsHostnames: true + tags: + Name: "" + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - fromFieldPath: metadata.name + toFieldPath: spec.forProvider.tags["Name"] + - name: internetGateway + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: InternetGateway + spec: + forProvider: + vpcIdSelector: + matchControllerRef: true + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - name: subnetPublicA + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: Subnet + metadata: + labels: + access: public + spec: + forProvider: + mapPublicIpOnLaunch: true + cidrBlock: 192.168.0.0/18 + vpcIdSelector: + matchControllerRef: true + tags: + kubernetes.io/role/elb: "1" + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - fromFieldPath: spec.parameters.region + toFieldPath: spec.forProvider.availabilityZone + transforms: + - type: string + string: + fmt: "%sa" + - fromFieldPath: spec.parameters.region + toFieldPath: metadata.labels[zone] + transforms: + - type: string + string: + fmt: "%sa" + - type: ToCompositeFieldPath + fromFieldPath: metadata.annotations[crossplane.io/external-name] + toFieldPath: status.subnetIds[0] + - name: subnetPublicB + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: Subnet + metadata: + labels: + access: public + spec: + forProvider: + mapPublicIpOnLaunch: true + cidrBlock: 192.168.64.0/18 + vpcIdSelector: + matchControllerRef: true + tags: + kubernetes.io/role/elb: "1" + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - fromFieldPath: spec.parameters.region + toFieldPath: spec.forProvider.availabilityZone + transforms: + - type: string + string: + fmt: "%sb" + - fromFieldPath: spec.parameters.region + toFieldPath: metadata.labels[zone] + transforms: + - type: string + string: + fmt: "%sb" + - type: ToCompositeFieldPath + fromFieldPath: metadata.annotations[crossplane.io/external-name] + toFieldPath: status.subnetIds[1] + - name: subnetPrivateA + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: Subnet + metadata: + labels: + access: private + spec: + forProvider: + cidrBlock: 192.168.128.0/18 + vpcIdSelector: + matchControllerRef: true + tags: + kubernetes.io/role/internal-elb: "1" + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - fromFieldPath: spec.parameters.region + toFieldPath: spec.forProvider.availabilityZone + transforms: + - type: string + string: + fmt: "%sa" + - fromFieldPath: spec.parameters.region + toFieldPath: metadata.labels[zone] + transforms: + - type: string + string: + fmt: "%sa" + - type: ToCompositeFieldPath + fromFieldPath: metadata.annotations[crossplane.io/external-name] + toFieldPath: status.subnetIds[2] + - name: subnetPrivateB + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: Subnet + metadata: + labels: + access: private + spec: + forProvider: + cidrBlock: 192.168.192.0/18 + vpcIdSelector: + matchControllerRef: true + tags: + kubernetes.io/role/internal-elb: "1" + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - fromFieldPath: spec.parameters.region + toFieldPath: spec.forProvider.availabilityZone + transforms: + - type: string + string: + fmt: "%sb" + - fromFieldPath: spec.parameters.region + toFieldPath: metadata.labels[zone] + transforms: + - type: string + string: + fmt: "%sb" + - type: ToCompositeFieldPath + fromFieldPath: metadata.annotations[crossplane.io/external-name] + toFieldPath: status.subnetIds[3] + - name: routeTable + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: RouteTable + spec: + forProvider: + vpcIdSelector: + matchControllerRef: true + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - name: route + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: Route + spec: + forProvider: + destinationCidrBlock: 0.0.0.0/0 + gatewayIdSelector: + matchControllerRef: true + routeTableIdSelector: + matchControllerRef: true + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - name: mainRouteTableAssociation + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: MainRouteTableAssociation + spec: + forProvider: + routeTableIdSelector: + matchControllerRef: true + vpcIdSelector: + matchControllerRef: true + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - name: routeTableAssociationPublicA + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: RouteTableAssociation + spec: + forProvider: + routeTableIdSelector: + matchControllerRef: true + subnetIdSelector: + matchControllerRef: true + matchLabels: + access: public + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - fromFieldPath: spec.parameters.region + toFieldPath: spec.forProvider.subnetIdSelector.matchLabels[zone] + transforms: + - type: string + string: + fmt: "%sa" + - name: routeTableAssociationPublicB + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: RouteTableAssociation + spec: + forProvider: + routeTableIdSelector: + matchControllerRef: true + subnetIdSelector: + matchControllerRef: true + matchLabels: + access: public + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - fromFieldPath: spec.parameters.region + toFieldPath: spec.forProvider.subnetIdSelector.matchLabels[zone] + transforms: + - type: string + string: + fmt: "%sb" + - name: routeTableAssociationPrivateA + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: RouteTableAssociation + spec: + forProvider: + routeTableIdSelector: + matchControllerRef: true + subnetIdSelector: + matchControllerRef: true + matchLabels: + access: private + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - fromFieldPath: spec.parameters.region + toFieldPath: spec.forProvider.subnetIdSelector.matchLabels[zone] + transforms: + - type: string + string: + fmt: "%sa" + - name: routeTableAssociationPrivateB + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: RouteTableAssociation + spec: + forProvider: + routeTableIdSelector: + matchControllerRef: true + subnetIdSelector: + matchControllerRef: true + matchLabels: + access: private + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - fromFieldPath: spec.parameters.region + toFieldPath: spec.forProvider.subnetIdSelector.matchLabels[zone] + transforms: + - type: string + string: + fmt: "%sb" + - name: securityGroup + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: SecurityGroup + spec: + forProvider: + vpcIdSelector: + matchControllerRef: true + name: platform-ref-aws-cluster + description: Allow access to databases + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - type: ToCompositeFieldPath + fromFieldPath: metadata.annotations[crossplane.io/external-name] + toFieldPath: status.securityGroupIds[0] + - name: securityGroupRulePostgres + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: SecurityGroupRule + spec: + forProvider: + type: ingress + fromPort: 5432 + toPort: 5432 + protocol: tcp + cidrBlocks: + - 0.0.0.0/0 + securityGroupIdSelector: + matchControllerRef: true + description: Everywhere + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region + - name: securityGroupRuleMysql + base: + apiVersion: ec2.aws.upbound.io/v1beta1 + kind: SecurityGroupRule + spec: + forProvider: + type: ingress + fromPort: 3306 + toPort: 3306 + protocol: tcp + cidrBlocks: + - 0.0.0.0/0 + securityGroupIdSelector: + matchControllerRef: true + description: Everywhere + patches: + - type: PatchSet + patchSetName: providerConfigRef + - type: PatchSet + patchSetName: deletionPolicy + - type: PatchSet + patchSetName: network-id + - type: PatchSet + patchSetName: region diff --git a/apis/definition.yaml b/apis/definition.yaml new file mode 100644 index 0000000..14ac502 --- /dev/null +++ b/apis/definition.yaml @@ -0,0 +1,59 @@ +apiVersion: apiextensions.crossplane.io/v1 +kind: CompositeResourceDefinition +metadata: + name: xnetworks.aws.platform.upbound.io +spec: + group: aws.platform.upbound.io + names: + kind: XNetwork + plural: xnetworks + versions: + - name: v1alpha1 + served: true + referenceable: true + schema: + openAPIV3Schema: + type: object + properties: + spec: + type: object + properties: + parameters: + description: Network Parameters + properties: + id: + type: string + description: ID of this Network that other objects will use to refer to it. + region: + type: string + description: Region is the region you'd like your resource to be created in. + deletionPolicy: + description: Delete the external resources when the Claim/XR is deleted. Defaults to Delete + enum: + - Delete + - Orphan + type: string + default: Delete + providerConfigName: + description: Crossplane ProviderConfig to use for provisioning this resources + type: string + default: default + required: + - deletionPolicy + - providerConfigName + - id + - region + type: object + required: + - parameters + status: + type: object + properties: + subnetIds: + type: array + items: + type: string + securityGroupIds: + type: array + items: + type: string diff --git a/build b/build new file mode 160000 index 0000000..2672eeb --- /dev/null +++ b/build @@ -0,0 +1 @@ +Subproject commit 2672eeb767636ec837aa7c63cd7e26e6089fa810 diff --git a/crossplane.yaml b/crossplane.yaml new file mode 100644 index 0000000..975dfc1 --- /dev/null +++ b/crossplane.yaml @@ -0,0 +1,14 @@ +apiVersion: meta.pkg.crossplane.io/v1alpha1 +kind: Configuration +metadata: + name: configuration-aws-network + annotations: + meta.crossplane.io/maintainer: Upbound + meta.crossplane.io/source: github.com/upbound/configuration-aws-network + meta.crossplane.io/license: Apache-2.0 +spec: + crossplane: + version: ">=v1.13.2-0" + dependsOn: + - provider: xpkg.upbound.io/upbound/provider-aws-ec2 + version: ">=v0.42.0" diff --git a/examples/configuration.yaml b/examples/configuration.yaml new file mode 100644 index 0000000..927c088 --- /dev/null +++ b/examples/configuration.yaml @@ -0,0 +1,6 @@ +apiVersion: pkg.crossplane.io/v1 +kind: Configuration +metadata: + name: cofiguration-aws-network +spec: + package: xpkg.upbound.io/upbound/platform-aws-network:0.1.0 diff --git a/examples/network-xr.yaml b/examples/network-xr.yaml new file mode 100644 index 0000000..2c15b49 --- /dev/null +++ b/examples/network-xr.yaml @@ -0,0 +1,8 @@ +apiVersion: aws.platform.upbound.io/v1alpha1 +kind: XNetwork +metadata: + name: ref-aws-network +spec: + parameters: + id: platform-ref-aws + region: us-west-2 diff --git a/test/setup.sh b/test/setup.sh new file mode 100755 index 0000000..09be403 --- /dev/null +++ b/test/setup.sh @@ -0,0 +1,35 @@ +#!/usr/bin/env bash +set -aeuo pipefail + +echo "Running setup.sh" +echo "Waiting until configuration package is healthy/installed..." +"${KUBECTL}" wait configuration.pkg configuration-aws-network --for=condition=Healthy --timeout 5m +"${KUBECTL}" wait configuration.pkg configuration-aws-network --for=condition=Installed --timeout 5m + +echo "Creating cloud credential secret..." +"${KUBECTL}" -n upbound-system create secret generic aws-creds --from-literal=credentials="${UPTEST_CLOUD_CREDENTIALS}" \ + --dry-run=client -o yaml | "${KUBECTL}" apply -f - + +echo "Waiting until all installed provider packages are healthy..." +"${KUBECTL}" wait provider.pkg --all --for condition=Healthy --timeout 5m + +echo "Waiting for all pods to come online..." +"${KUBECTL}" -n upbound-system wait --for=condition=Available deployment --all --timeout=5m + +echo "Waiting for all XRDs to be established..." +"${KUBECTL}" wait xrd --all --for condition=Established + +echo "Creating a default provider config..." +cat <