diff --git a/deploy/oadp-configuration/hive-specific/05-oadp-schedule-admins-cluster.ClusterRole.yaml b/deploy/oadp-configuration/hive-specific/05-oadp-schedule-admins-cluster.ClusterRole.yaml new file mode 100644 index 0000000000..eb3ec837e1 --- /dev/null +++ b/deploy/oadp-configuration/hive-specific/05-oadp-schedule-admins-cluster.ClusterRole.yaml @@ -0,0 +1,25 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + labels: + managed.openshift.io/aggregate-to-dedicated-admins: "cluster" + name: oadp-schedule-admins-cluster +rules: +- apiGroups: + - velero.io + attributeRestrictions: null + resources: + - schedules + - backups + - restores + verbs: + - "*" +- apiGroups: + - oadp.openshift.io + attributeRestrictions: null + resources: + - dataprotectionapplications + verbs: + - get + - list + - watch \ No newline at end of file diff --git a/deploy/oadp-configuration/hive-specific/111-oadp.Schedules.yaml b/deploy/oadp-configuration/hive-specific/111-oadp.Schedules.yaml new file mode 100644 index 0000000000..4a86e9b234 --- /dev/null +++ b/deploy/oadp-configuration/hive-specific/111-oadp.Schedules.yaml @@ -0,0 +1,29 @@ +apiVersion: velero.io/v1 +kind: Schedule +metadata: + name: 5min-object-backup + namespace: openshift-adp +spec: + schedule: '*/5 * * * *' + template: + includedNamespaces: + - '*' + excludedResources: + - imagetags.image.openshift.io + - images.image.openshift.io + - oauthaccesstokens.oauth.openshift.io + - oauthauthorizetokens.oauth.openshift.io + - templateinstances.template.openshift.io + - clusterserviceversions.operators.coreos.com + - packagemanifests.packages.operators.coreos.com + - operatorgroups.operators.coreos.com + - subscriptions.operators.coreos.com + - servicebrokers.servicecatalog.k8s.io + - servicebindings.servicecatalog.k8s.io + - serviceclasses.servicecatalog.k8s.io + - serviceinstances.servicecatalog.k8s.io + - serviceplans.servicecatalog.k8s.io + - events.events.k8s.io + - events + snapshotVolumes: false + ttl: 0h25m0s \ No newline at end of file diff --git a/deploy/oadp-configuration/hive-specific/config.yaml b/deploy/oadp-configuration/hive-specific/config.yaml new file mode 100644 index 0000000000..2c44e7c25f --- /dev/null +++ b/deploy/oadp-configuration/hive-specific/config.yaml @@ -0,0 +1,9 @@ +deploymentMode: "SelectorSyncSet" +selectorSyncSet: + matchLabels: + ext-managed.openshift.io/hive-shard: "true" + matchExpressions: + - key: api.openshift.com/fedramp + operator: NotIn + values: + - "true" \ No newline at end of file diff --git a/hack/00-osd-managed-cluster-config-integration.yaml.tmpl b/hack/00-osd-managed-cluster-config-integration.yaml.tmpl index 197538f9c1..02fcf6b4fe 100644 --- a/hack/00-osd-managed-cluster-config-integration.yaml.tmpl +++ b/hack/00-osd-managed-cluster-config-integration.yaml.tmpl @@ -32908,6 +32908,80 @@ objects: applyMode: Sync patch: '{"spec":{"maxUnavailable":"10%"}}' patchType: merge +- apiVersion: hive.openshift.io/v1 + kind: SelectorSyncSet + metadata: + labels: + managed.openshift.io/gitHash: ${IMAGE_TAG} + managed.openshift.io/gitRepoName: ${REPO_NAME} + managed.openshift.io/osd: 'true' + name: oadp-configuration-hive-specific + spec: + clusterDeploymentSelector: + matchLabels: + api.openshift.com/managed: 'true' + ext-managed.openshift.io/hive-shard: 'true' + matchExpressions: + - key: api.openshift.com/fedramp + operator: NotIn + values: + - 'true' + resourceApplyMode: Sync + resources: + - apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + labels: + managed.openshift.io/aggregate-to-dedicated-admins: cluster + name: oadp-schedule-admins-cluster + rules: + - apiGroups: + - velero.io + attributeRestrictions: null + resources: + - schedules + - backups + - restores + verbs: + - '*' + - apiGroups: + - oadp.openshift.io + attributeRestrictions: null + resources: + - dataprotectionapplications + verbs: + - get + - list + - watch + - apiVersion: velero.io/v1 + kind: Schedule + metadata: + name: 5min-object-backup + namespace: openshift-adp + spec: + schedule: '*/5 * * * *' + template: + includedNamespaces: + - '*' + excludedResources: + - imagetags.image.openshift.io + - images.image.openshift.io + - oauthaccesstokens.oauth.openshift.io + - oauthauthorizetokens.oauth.openshift.io + - templateinstances.template.openshift.io + - clusterserviceversions.operators.coreos.com + - packagemanifests.packages.operators.coreos.com + - operatorgroups.operators.coreos.com + - subscriptions.operators.coreos.com + - servicebrokers.servicecatalog.k8s.io + - servicebindings.servicecatalog.k8s.io + - serviceclasses.servicecatalog.k8s.io + - serviceinstances.servicecatalog.k8s.io + - serviceplans.servicecatalog.k8s.io + - events.events.k8s.io + - events + snapshotVolumes: false + ttl: 0h25m0s - apiVersion: hive.openshift.io/v1 kind: SelectorSyncSet metadata: diff --git a/hack/00-osd-managed-cluster-config-production.yaml.tmpl b/hack/00-osd-managed-cluster-config-production.yaml.tmpl index 197538f9c1..02fcf6b4fe 100644 --- a/hack/00-osd-managed-cluster-config-production.yaml.tmpl +++ b/hack/00-osd-managed-cluster-config-production.yaml.tmpl @@ -32908,6 +32908,80 @@ objects: applyMode: Sync patch: '{"spec":{"maxUnavailable":"10%"}}' patchType: merge +- apiVersion: hive.openshift.io/v1 + kind: SelectorSyncSet + metadata: + labels: + managed.openshift.io/gitHash: ${IMAGE_TAG} + managed.openshift.io/gitRepoName: ${REPO_NAME} + managed.openshift.io/osd: 'true' + name: oadp-configuration-hive-specific + spec: + clusterDeploymentSelector: + matchLabels: + api.openshift.com/managed: 'true' + ext-managed.openshift.io/hive-shard: 'true' + matchExpressions: + - key: api.openshift.com/fedramp + operator: NotIn + values: + - 'true' + resourceApplyMode: Sync + resources: + - apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + labels: + managed.openshift.io/aggregate-to-dedicated-admins: cluster + name: oadp-schedule-admins-cluster + rules: + - apiGroups: + - velero.io + attributeRestrictions: null + resources: + - schedules + - backups + - restores + verbs: + - '*' + - apiGroups: + - oadp.openshift.io + attributeRestrictions: null + resources: + - dataprotectionapplications + verbs: + - get + - list + - watch + - apiVersion: velero.io/v1 + kind: Schedule + metadata: + name: 5min-object-backup + namespace: openshift-adp + spec: + schedule: '*/5 * * * *' + template: + includedNamespaces: + - '*' + excludedResources: + - imagetags.image.openshift.io + - images.image.openshift.io + - oauthaccesstokens.oauth.openshift.io + - oauthauthorizetokens.oauth.openshift.io + - templateinstances.template.openshift.io + - clusterserviceversions.operators.coreos.com + - packagemanifests.packages.operators.coreos.com + - operatorgroups.operators.coreos.com + - subscriptions.operators.coreos.com + - servicebrokers.servicecatalog.k8s.io + - servicebindings.servicecatalog.k8s.io + - serviceclasses.servicecatalog.k8s.io + - serviceinstances.servicecatalog.k8s.io + - serviceplans.servicecatalog.k8s.io + - events.events.k8s.io + - events + snapshotVolumes: false + ttl: 0h25m0s - apiVersion: hive.openshift.io/v1 kind: SelectorSyncSet metadata: diff --git a/hack/00-osd-managed-cluster-config-stage.yaml.tmpl b/hack/00-osd-managed-cluster-config-stage.yaml.tmpl index 197538f9c1..02fcf6b4fe 100644 --- a/hack/00-osd-managed-cluster-config-stage.yaml.tmpl +++ b/hack/00-osd-managed-cluster-config-stage.yaml.tmpl @@ -32908,6 +32908,80 @@ objects: applyMode: Sync patch: '{"spec":{"maxUnavailable":"10%"}}' patchType: merge +- apiVersion: hive.openshift.io/v1 + kind: SelectorSyncSet + metadata: + labels: + managed.openshift.io/gitHash: ${IMAGE_TAG} + managed.openshift.io/gitRepoName: ${REPO_NAME} + managed.openshift.io/osd: 'true' + name: oadp-configuration-hive-specific + spec: + clusterDeploymentSelector: + matchLabels: + api.openshift.com/managed: 'true' + ext-managed.openshift.io/hive-shard: 'true' + matchExpressions: + - key: api.openshift.com/fedramp + operator: NotIn + values: + - 'true' + resourceApplyMode: Sync + resources: + - apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + labels: + managed.openshift.io/aggregate-to-dedicated-admins: cluster + name: oadp-schedule-admins-cluster + rules: + - apiGroups: + - velero.io + attributeRestrictions: null + resources: + - schedules + - backups + - restores + verbs: + - '*' + - apiGroups: + - oadp.openshift.io + attributeRestrictions: null + resources: + - dataprotectionapplications + verbs: + - get + - list + - watch + - apiVersion: velero.io/v1 + kind: Schedule + metadata: + name: 5min-object-backup + namespace: openshift-adp + spec: + schedule: '*/5 * * * *' + template: + includedNamespaces: + - '*' + excludedResources: + - imagetags.image.openshift.io + - images.image.openshift.io + - oauthaccesstokens.oauth.openshift.io + - oauthauthorizetokens.oauth.openshift.io + - templateinstances.template.openshift.io + - clusterserviceversions.operators.coreos.com + - packagemanifests.packages.operators.coreos.com + - operatorgroups.operators.coreos.com + - subscriptions.operators.coreos.com + - servicebrokers.servicecatalog.k8s.io + - servicebindings.servicecatalog.k8s.io + - serviceclasses.servicecatalog.k8s.io + - serviceinstances.servicecatalog.k8s.io + - serviceplans.servicecatalog.k8s.io + - events.events.k8s.io + - events + snapshotVolumes: false + ttl: 0h25m0s - apiVersion: hive.openshift.io/v1 kind: SelectorSyncSet metadata: