-
Notifications
You must be signed in to change notification settings - Fork 54
Expand file tree
/
Copy pathMakefile
More file actions
261 lines (204 loc) · 10.6 KB
/
Copy pathMakefile
File metadata and controls
261 lines (204 loc) · 10.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
# BUNDLE_VERSION defines the project version for the bundle.
# Update this value when you upgrade the version of your project.
# To re-generate a bundle for another specific version without changing the standard setup, you can:
# - use the BUNDLE_VERSION as arg of the bundle target (e.g make bundle BUNDLE_VERSION=0.0.2)
# - use environment variables to overwrite this value (e.g export BUNDLE_VERSION=0.0.2)
BUNDLE_VERSION ?= $(shell cat VERSION)
# CHANNELS define the bundle channels used in the bundle.
# Add a new line here if you would like to change its default config. (E.g CHANNELS = "candidate,fast,stable")
# To re-generate a bundle for other specific channels without changing the standard setup, you can:
# - use the CHANNELS as arg of the bundle target (e.g make bundle CHANNELS=candidate,fast,stable)
# - use environment variables to overwrite this value (e.g export CHANNELS="candidate,fast,stable")
ifneq ($(origin CHANNELS), undefined)
BUNDLE_CHANNELS := --channels=$(CHANNELS)
endif
# DEFAULT_CHANNEL defines the default channel used in the bundle.
# Add a new line here if you would like to change its default config. (E.g DEFAULT_CHANNEL = "stable")
# To re-generate a bundle for any other default channel without changing the default setup, you can:
# - use the DEFAULT_CHANNEL as arg of the bundle target (e.g make bundle DEFAULT_CHANNEL=stable)
# - use environment variables to overwrite this value (e.g export DEFAULT_CHANNEL="stable")
ifneq ($(origin DEFAULT_CHANNEL), undefined)
BUNDLE_DEFAULT_CHANNEL := --default-channel=$(DEFAULT_CHANNEL)
endif
BUNDLE_METADATA_OPTS ?= $(BUNDLE_CHANNELS) $(BUNDLE_DEFAULT_CHANNEL)
# Image URL to use all building/pushing image targets
IMG ?= quay.io/openshift/origin-external-dns-operator:latest
# Used for internal registry access
TLS_VERIFY ?= true
# Produce CRDs that work back to Kubernetes 1.11 (no version conversion)
CRD_OPTIONS ?= "crd"
CONTROLLER_GEN := go tool controller-gen
SETUP_ENVTEST := go tool setup-envtest
KUSTOMIZE := go tool kustomize
K8S_ENVTEST_VERSION := 1.33.0
PACKAGE=github.com/openshift/external-dns-operator
BIN=bin/$(lastword $(subst /, ,$(PACKAGE)))
BIN_DIR=$(shell pwd)/bin
# Setting SHELL to bash allows bash commands to be executed by recipes.
# This is a requirement for 'setup-envtest.sh' in the test target.
# Options are set to exit when a recipe line exits non-zero or a piped command fails.
SHELL = /usr/bin/env bash -o pipefail
.SHELLFLAGS = -ec
CONTAINER_ENGINE ?= docker
CONTAINER_PUSH_ARGS ?= $(if $(filter ${CONTAINER_ENGINE}, docker), , --tls-verify=${TLS_VERIFY})
BUNDLE_DIR := bundle
BUNDLE_MANIFEST_DIR := $(BUNDLE_DIR)/manifests
BUNDLE_IMG ?= quay.io/external-dns-operator/external-dns-operator-bundle:latest
CATALOG_DIR := catalog
OCP_VERSION ?= 4.21
OCP_CATALOG_DIR := $(CATALOG_DIR)/v$(OCP_VERSION)
PACKAGE_DIR := $(CATALOG_DIR)/external-dns-operator
CATALOG_IMG ?= quay.io/external-dns-operator/external-dns-operator-catalog:latest
OPM_VERSION ?= v1.52.0
GOLANGCI_LINT_BIN=$(BIN_DIR)/golangci-lint
OPERATOR_SDK_BIN=$(BIN_DIR)/operator-sdk
COMMIT ?= $(shell git rev-parse HEAD)
SHORTCOMMIT ?= $(shell git rev-parse --short HEAD)
GOBUILD_VERSION_ARGS = -ldflags "-X $(PACKAGE)/pkg/version.SHORTCOMMIT=$(SHORTCOMMIT) -X $(PACKAGE)/pkg/version.COMMIT=$(COMMIT)" -tags strictfipsruntime
CHECK_PAYLOAD_IMG ?= registry.ci.openshift.org/ci/check-payload:latest
E2E_TIMEOUT ?= 1h
TEST_PKG ?= ./test/e2e
all: build
##@ General
# The help target prints out all targets with their descriptions organized
# beneath their categories. The categories are represented by '##@' and the
# target descriptions by '##'. The awk commands is responsible for reading the
# entire set of makefiles included in this invocation, looking for lines of the
# file as xyz: ## something, and then pretty-format the target and help. Then,
# if there's a line with ##@ something, that gets pretty-printed as a category.
# More info on the usage of ANSI control characters for terminal formatting:
# https://en.wikipedia.org/wiki/ANSI_escape_code#SGR_parameters
# More info on the awk command:
# http://linuxcommand.org/lc3_adv_awk.php
help: ## Display this help.
@awk 'BEGIN {FS = ":.*##"; printf "\nUsage:\n make \033[36m<target>\033[0m\n"} /^[a-zA-Z_0-9-]+:.*?##/ { printf " \033[36m%-15s\033[0m %s\n", $$1, $$2 } /^##@/ { printf "\n\033[1m%s\033[0m\n", substr($$0, 5) } ' $(MAKEFILE_LIST)
##@ Development
manifests: ## Generate WebhookConfiguration, ClusterRole and CustomResourceDefinition objects.
$(CONTROLLER_GEN) $(CRD_OPTIONS) rbac:roleName=external-dns-operator webhook paths="./..." output:crd:artifacts:config=config/crd/bases
generate: ## Generate code containing DeepCopy, DeepCopyInto, and DeepCopyObject method implementations.
$(CONTROLLER_GEN) object:headerFile="hack/boilerplate.go.txt" paths="./..."
fmt: ## Run go fmt against code.
go fmt ./...
vet: ## Run go vet against code.
go vet ./...
ENVTEST_ASSETS_DIR ?= $(shell pwd)/testbin
test: manifests generate fmt vet ## Run tests.
mkdir -p "$(ENVTEST_ASSETS_DIR)"
KUBEBUILDER_ASSETS="$(shell $(SETUP_ENVTEST) use "$(K8S_ENVTEST_VERSION)" --print path --bin-dir "$(ENVTEST_ASSETS_DIR)")" CGO_ENABLED=1 go test ./... -race -covermode=atomic -coverprofile coverage.out
.PHONY: test-e2e
test-e2e:
go test \
$(GOBUILD_VERSION_ARGS) \
-timeout $(E2E_TIMEOUT) \
-count 1 \
-v \
-tags e2e \
-run "$(TEST)" \
$(TEST_PKG)
.PHONY: test-e2e-sharedvpc
test-e2e-sharedvpc:
TEST_PKG=./test/e2e_sharedvpc make test-e2e
verify: lint
hack/verify-gofmt.sh
hack/verify-deps.sh
hack/verify-generated.sh
hack/verify-olm.sh
hack/verify-version.sh
##@ Build
GO=GO111MODULE=on GOFLAGS=-mod=vendor go
build-operator: ## Build operator binary, no additional checks or code generation
$(GO) build $(GOBUILD_VERSION_ARGS) -o $(BIN) $(PACKAGE)
build: generate build-operator fmt vet ## Build operator binary.
run: manifests generate fmt vet ## Run a controller from your host.
go run $(PACKAGE)
image-build: test ## Build container image with the operator.
$(CONTAINER_ENGINE) build -t ${IMG} .
image-push: ## Push container image with the operator.
$(CONTAINER_ENGINE) push ${IMG} ${CONTAINER_PUSH_ARGS}
.PHONY: image-fips-scan
image-fips-scan:
$(CONTAINER_ENGINE) run --privileged $(CHECK_PAYLOAD_IMG) scan operator --spec $(IMG)
$(BIN_DIR)/fips_enabled:
echo -n "1" > $(BIN_DIR)/fips_enabled
.PHONY: image-fips-runtime-smoke-test
image-fips-runtime-smoke-test: image-build $(BIN_DIR)/fips_enabled ## Test that the operator starts in FIPS mode.
$(CONTAINER_ENGINE) run --rm -v $(BIN_DIR)/fips_enabled:/proc/sys/crypto/fips_enabled:ro $(IMG) --help > /dev/null 2>&1
.PHONY: konflux-rpm-lock
konflux-rpm-lock: ## Regenerate .konflux/rpms.lock.yaml from rpms.in.yaml.
cd .konflux && rpm-lockfile-prototype rpms.in.yaml
##@ Deployment
install: manifests ## Install CRDs into the K8s cluster specified in ~/.kube/config.
$(KUSTOMIZE) build config/crd | kubectl apply -f -
uninstall: manifests ## Uninstall CRDs from the K8s cluster specified in ~/.kube/config.
$(KUSTOMIZE) build config/crd | kubectl delete -f -
deploy: manifests ## Deploy controller to the K8s cluster specified in ~/.kube/config.
# do not commit the following 2 changes
cd config/manager && $(KUSTOMIZE) edit set image quay.io/openshift/origin-external-dns-operator=${IMG}
# webhook volume and service are added explicilty so that they don't land in the bundle where it's managed by OLM
cd config/default && $(KUSTOMIZE) edit add patch --path=manager_webhook_volume_patch.yaml
# disable tls config in service monitor
cd config/prometheus && $(KUSTOMIZE) edit add patch --path=insecure_tls_patch.yaml
# consume certificate from the service serving certificate
cd config/default && $(KUSTOMIZE) edit add patch --path=manager_insecure_tls_auth_proxy_patch.yaml
$(KUSTOMIZE) build config/default | kubectl apply -f -
undeploy: ## Undeploy controller from the K8s cluster specified in ~/.kube/config.
$(KUSTOMIZE) build config/default | kubectl delete -f -
.PHONY: bundle
bundle: $(OPERATOR_SDK_BIN) manifests
$(OPERATOR_SDK_BIN) generate kustomize manifests -q
cd config/manager && $(KUSTOMIZE) edit set image quay.io/openshift/origin-external-dns-operator=$(IMG)
$(KUSTOMIZE) build config/manifests | $(OPERATOR_SDK_BIN) generate bundle -q --overwrite=false --version $(BUNDLE_VERSION) $(BUNDLE_METADATA_OPTS)
@# Generate skipRange from BUNDLE_VERSION
sed -i "s/\(olm\.skipRange: <\).*/\1$(BUNDLE_VERSION)/" bundle/manifests/external-dns-operator.clusterserviceversion.yaml
$(OPERATOR_SDK_BIN) bundle validate $(BUNDLE_DIR)
.PHONY: set-version
set-version: ## Sync VERSION from upstream to all OpenShift Containerfiles.
@./hack/sync-version.sh
.PHONY: bundle-image-build
bundle-image-build: bundle
$(CONTAINER_ENGINE) build -t $(BUNDLE_IMG) -f Dockerfile.bundle .
.PHONY: bundle-image-push
bundle-image-push:
$(CONTAINER_ENGINE) push $(BUNDLE_IMG)
OCP_VERSION_MAJOR := $(shell echo $(OCP_VERSION) | cut -d. -f1)
OCP_VERSION_MINOR := $(shell echo $(OCP_VERSION) | cut -d. -f2)
MIGRATE_LEVEL_FLAG := $(shell [ $(OCP_VERSION_MAJOR) -ge 5 ] || ([ $(OCP_VERSION_MAJOR) -eq 4 ] && [ $(OCP_VERSION_MINOR) -ge 17 ]) && echo --migrate-level bundle-object-to-csv-metadata)
generate-catalog: opm ## Generate OCP version-based catalog for the Konflux-built operator
mkdir -p $(OCP_CATALOG_DIR)
$(OPM) alpha render-template basic $(MIGRATE_LEVEL_FLAG) -o yaml $(OCP_CATALOG_DIR)/catalog-template.yaml > $(OCP_CATALOG_DIR)/catalog.yaml
.PHONY: catalog
catalog: opm
# TODO: make opm use the bundle image built locally
$(OPM) render $(BUNDLE_IMG) --migrate-level bundle-object-to-csv-metadata -o yaml > $(PACKAGE_DIR)/bundle.yaml
sed -i "s/external-dns-operator\.v[0-9]\+\.[0-9]\+\.[0-9]\+/$$(grep '^name:' $(PACKAGE_DIR)/bundle.yaml | cut -d' ' -f2)/g" $(PACKAGE_DIR)/channel.yaml
$(OPM) validate $(PACKAGE_DIR)
.PHONY: catalog-image-build
catalog-image-build: catalog
$(CONTAINER_ENGINE) build -t $(CATALOG_IMG) -f Dockerfile.catalog .
.PHONY: catalog-image-push
catalog-image-push:
$(CONTAINER_ENGINE) push $(CATALOG_IMG)
OPM=$(BIN_DIR)/opm
opm: ## Download opm locally if necessary.
$(call get-bin,$(OPM),$(BIN_DIR),https://github.com/operator-framework/operator-registry/releases/download/$(OPM_VERSION)/linux-amd64-opm)
define get-bin
@[ -f "$(1)" ] || { \
[ ! -d "$(2)" ] && mkdir -p "$(2)" || true ;\
echo "Downloading $(3)" ;\
curl -fL $(3) -o "$(1)" ;\
chmod +x "$(1)" ;\
}
endef
.PHONY: lint
## Checks the code with golangci-lint
lint: $(GOLANGCI_LINT_BIN)
$(GOLANGCI_LINT_BIN) run -c .golangci.yaml
$(GOLANGCI_LINT_BIN):
mkdir -p $(BIN_DIR)
hack/golangci-lint.sh $(GOLANGCI_LINT_BIN)
$(OPERATOR_SDK_BIN):
mkdir -p $(BIN_DIR)
hack/operator-sdk.sh $(OPERATOR_SDK_BIN)
clean:
$(GO) clean
rm -f $(BIN)