Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
72 changes: 17 additions & 55 deletions .github/workflows/build-test-dev.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ on:
- main

env:
VERSION: 1.4.1
VERSION: 1.4.2
IMAGE_NAME: pubsubplus-eventbroker-operator
VAULT_ADDR: ${{ secrets.VAULT_ADDR }}
GCLOUD_PROJECT_ID_DEV: ${{ secrets.GCLOUD_PROJECT_ID }}
Expand All @@ -21,11 +21,12 @@ jobs:
contents: read
actions: read
id-token: write
packages: write
steps:
- name: Set up Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
with:
go-version: "1.24.2"
go-version: "1.26.5"

- name: Check out code
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
Expand All @@ -38,7 +39,7 @@ jobs:
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.RELEASE_GITHUB_TOKEN }}
password: ${{ secrets.GITHUB_TOKEN }}

- id: 'auth'
name: 'Authenticate to Google Cloud'
Expand Down Expand Up @@ -109,56 +110,17 @@ jobs:
if: ${{ startsWith(github.ref_name, 'dev1.') && (github.ref_name != 'main') }}
uses: docker/setup-buildx-action@885d1462b80bc1c1c7f0b00334ad271f09369c55 # v2

- name: Checkout SolaceDev/maas-build-actions
if: ${{ startsWith(github.ref_name, 'dev1.') && (github.ref_name != 'main') }}
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
repository: SolaceDev/maas-build-actions
ref: refs/heads/master
token: ${{ secrets.RELEASE_GITHUB_TOKEN }}
persist-credentials: false
path: maas-build-actions

- name: Retrieve google container registry secrets
id: docker_registry_secrets
if: ${{ startsWith(github.ref_name, 'dev1.') && (github.ref_name != 'main') }}
uses: hashicorp/vault-action@130d1f5f4fe645bb6c83e4225c04d64cfb62de6e # v2.5.0
with:
url: "${{ env.VAULT_ADDR }}"
role: github-docker-secrets-read-role
method: jwt
path: jwt-github
jwtGithubAudience: https://github.com/SolaceDev
exportToken: true
secrets: |
secret/data/development/gcp-gcr GCP_SERVICE_ACCOUNT | GCP_DEV_SERVICE_ACCOUNT
env:
VERSION: ${{ env.VERSION }}
IMAGE_NAME: pubsubplus-eventbroker-operator
VAULT_ADDR: ${{ secrets.VAULT_ADDR }}
GCLOUD_PROJECT_ID_DEV: ${{ secrets.GCLOUD_PROJECT_ID }}

- name: Log in to gcr development docker registry
uses: docker/login-action@f054a8b539a109f9f41c372932f1ae047eff08c9
if: ${{ startsWith(github.ref_name, 'dev1.') && (github.ref_name != 'main') }}
with:
registry: gcr.io
username: _json_key
password: ${{ steps.docker_registry_secrets.outputs.GCP_DEV_SERVICE_ACCOUNT }}

- name: Build image and push Google Container Registry
uses: docker/build-push-action@ac9327eae2b366085ac7f6a2d02df8aa8ead720a # v2
if: ${{ startsWith(github.ref_name, 'dev1.') && (github.ref_name != 'main') }}
with:
context: ./
tags: |
gcr.io/${{ env.GCLOUD_PROJECT_ID_DEV }}/${{ env.IMAGE_NAME }}:${{ env.VERSION }}
push: true
env:
VERSION: ${{ env.VERSION }}
IMAGE_NAME: ${{ env.IMAGE_NAME }}
VAULT_ADDR: ${{ secrets.VAULT_ADDR }}
GCLOUD_PROJECT_ID_DEV: ${{ secrets.GCLOUD_PROJECT_ID }}
# Checkout only feeds the Prisma vulnerability check below, which is disabled - skip it too
# (its RELEASE_GITHUB_TOKEN checkout was failing with no consumer left to justify fixing it)
# - name: Checkout SolaceDev/maas-build-actions
# if: ${{ startsWith(github.ref_name, 'dev1.') && (github.ref_name != 'main') }}
# uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
# with:
# repository: SolaceDev/maas-build-actions
# ref: refs/heads/master
# token: ${{ secrets.RELEASE_GITHUB_TOKEN }}
# persist-credentials: false
# path: maas-build-actions

- name: Build image and push GitHub Container Registry
run: make docker-push
Expand All @@ -174,7 +136,7 @@ jobs:


- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # v0.30.0
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
if: ${{ startsWith(github.ref_name, 'dev1.') && (github.ref_name != 'main') }}
with:
image-ref: ghcr.io/solacedev/${{ env.IMAGE_NAME }}:${{ env.VERSION }}
Expand All @@ -191,7 +153,7 @@ jobs:
trivy-results.sarif

- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # v0.30.0
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
if: ${{ startsWith(github.ref_name, 'dev1.') && (github.ref_name != 'main') }}
with:
image-ref: ghcr.io/solacedev/${{ env.IMAGE_NAME }}:${{ env.VERSION }}
Expand Down
53 changes: 44 additions & 9 deletions .github/workflows/main-branch-only.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,25 +9,50 @@ jobs:
test:
name: Deploy Operator then deploy broker
runs-on: ubuntu-latest
permissions:
contents: 'read'
id-token: 'write'
steps:
- name: Set env
run: |
echo "TESTNAMESPACE=main-branch-$(date +%s)" >> $GITHUB_ENV

- name: Check out code
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4

- name: Create k8s Kind Cluster
uses: helm/kind-action@d08cf6ff1575077dee99962540d77ce91c62387d # v1.3.0
- id: 'auth'
name: 'Authenticate to Google Cloud'
uses: google-github-actions/auth@ef5d53e30bbcd8d0836f4288f5e50ff3e086997d # v1.0.0
with:
service_account: ${{ secrets.GCP_SERVICE_ACCOUNT }}
workload_identity_provider: ${{ secrets.GCP_WORKLOAD_IDENTITY_PROVIDER }}
access_token_lifetime: 600s

- name: Use the GKE Autopilot test cluster
uses: google-github-actions/get-gke-credentials@ef10cc0013c465a6ea0b8e36c24064576ec25f87 # v1.0.0
with:
cluster_name: 'dev-integrationtesting'
location: 'us-central1'

- name: Testing operator deployment
run: |
kubectl cluster-info
kubectl get pods -n kube-system
echo "current-context:" $(kubectl config current-context)
echo "environment-kubeconfig:" ${KUBECONFIG}
kubectl apply -f deploy/deploy.yaml
kubectl rollout status deployment pubsubplus-eventbroker-operator -n pubsubplus-operator-system --timeout=30s
for i in {1..3}; do
kubectl apply -f deploy/deploy.yaml
kubectl rollout status deployment pubsubplus-eventbroker-operator -n pubsubplus-operator-system --timeout=240s
if [ $? -eq 0 ]; then
break
else
echo "Rollout status check failed, retrying in 20 seconds..."
sleep 20
fi
done
kubectl get crd | grep eventbrokers

- name: Deploy and test broker - nonHA Minimal
run: |
kubectl create ns $TESTNAMESPACE && kubectl config set-context --current --namespace=$TESTNAMESPACE
echo "
apiVersion: pubsubplus.solace.com/v1beta1
kind: PubSubPlusEventBroker
Expand All @@ -38,7 +63,15 @@ jobs:
# Then apply it
kubectl apply -f developer.yaml | grep "test-broker created"
sleep 25 ; kubectl get all
kubectl wait pods --selector app.kubernetes.io/instance=test-broker --for condition=Ready --timeout=120s
for i in {1..3}; do
kubectl wait pods --selector app.kubernetes.io/instance=test-broker --for condition=Ready --timeout=300s
if [ $? -eq 0 ]; then
break
else
echo "Waiting for pods failed, retrying in 15 seconds..."
sleep 15
fi
done
kubectl get po --show-labels | grep test-broker | grep "1/1"
kubectl get po --show-labels | grep test-broker | grep active=true
kubectl get sts | grep test-broker
Expand All @@ -48,6 +81,8 @@ jobs:
tar -xvf SDKPERF_C_LINUX64
pubSubTools/sdkperf_c -cip=tcp://localhost:55555 -mn=1000 -mr=0 -ptl=t1 -stl=t1 | grep "Total Messages"

- name: Delete broker
- name: Delete broker deployment
if: always()
run: |
kubectl delete eventbroker test-broker | grep deleted
kubectl delete eventbroker test-broker --ignore-not-found | grep deleted || true
kubectl delete ns $TESTNAMESPACE --ignore-not-found
4 changes: 2 additions & 2 deletions .github/workflows/prep-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ on:
release_tag:
description: 'Release tag'
required: true
default: '1.4.1'
default: '1.4.2'
prep_internal_release:
# Need to distinguish between internal and external releases
# Internal release: Will use default internal location for created images (ghcr.io) and will tag and push operator candidate there
Expand All @@ -24,7 +24,7 @@ jobs:
- name: Set up Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
with:
go-version: 1.24.2
go-version: 1.26.5

- name: Login to Github Packages
uses: docker/login-action@465a07811f14bebb1938fbed4728c6a1ff8901fc # v2
Expand Down
15 changes: 8 additions & 7 deletions .github/workflows/vulncheck_periodic.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ on:
- cron: '0 */ * * *'

env:
VERSION: 1.4.1
VERSION: 1.4.2
IMAGE_NAME: pubsubplus-eventbroker-operator
VAULT_ADDR: ${{ secrets.VAULT_ADDR }}
GCLOUD_PROJECT_ID_DEV: ${{ secrets.GCLOUD_PROJECT_ID }}
Expand All @@ -23,11 +23,12 @@ jobs:
contents: read
actions: read
id-token: write
packages: write
steps:
- name: Set up Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
with:
go-version: "1.24.2"
go-version: "1.26.5"

- name: Check out code
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
Expand All @@ -37,7 +38,7 @@ jobs:
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.RELEASE_GITHUB_TOKEN }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Set up Docker Buildx
id: buildx
Expand Down Expand Up @@ -65,7 +66,7 @@ jobs:
secrets: |
secret/data/development/gcp-gcr GCP_SERVICE_ACCOUNT | GCP_DEV_SERVICE_ACCOUNT
env:
VERSION: 1.4.1
VERSION: 1.4.2
IMAGE_NAME: pubsubplus-eventbroker-operator
VAULT_ADDR: ${{ secrets.VAULT_ADDR }}
GCLOUD_PROJECT_ID_DEV: ${{ secrets.GCLOUD_PROJECT_ID }}
Expand All @@ -85,7 +86,7 @@ jobs:
gcr.io/${{ env.GCLOUD_PROJECT_ID_DEV }}/${{ env.IMAGE_NAME }}:${{ env.VERSION }}
push: true
env:
VERSION: 1.4.1
VERSION: 1.4.2
IMAGE_NAME: pubsubplus-eventbroker-operator
VAULT_ADDR: ${{ secrets.VAULT_ADDR }}
GCLOUD_PROJECT_ID_DEV: ${{ secrets.GCLOUD_PROJECT_ID }}
Expand All @@ -103,7 +104,7 @@ jobs:
run: make docker-push

- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # v0.30.0
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
with:
image-ref: ghcr.io/solacedev/${{ env.IMAGE_NAME }}:${{ env.VERSION }}
format: 'sarif'
Expand All @@ -118,7 +119,7 @@ jobs:
trivy-results.sarif

- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # v0.30.0
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
with:
image-ref: ghcr.io/solacedev/${{ env.IMAGE_NAME }}:${{ env.VERSION }}
format: 'sarif'
Expand Down
11 changes: 7 additions & 4 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# Build the manager binary
FROM golang:1.24.2 as builder
FROM golang:1.26.5 as builder

WORKDIR /workspace
# Copy the Go Modules manifests
Expand All @@ -19,13 +19,16 @@ RUN CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -a -o manager main.go

# Use distroless as minimal base image to package the manager binary
# Refer to https://github.com/GoogleContainerTools/distroless for more details
FROM registry.access.redhat.com/ubi9/ubi-minimal:9.6-1754000177
FROM registry.access.redhat.com/ubi10/ubi-minimal:10.2-1785778687

RUN microdnf update -y --nodocs && \
microdnf clean all

LABEL name="solace/pubsubplus-eventbroker-operator"
LABEL maintainer="Solace Corporation"
LABEL vendor="Solace Corporation"
LABEL version="1.4.1"
LABEL release="1.4.1"
LABEL version="1.4.2"
LABEL release="1.4.2"
LABEL summary="Solace PubSub+ Event Broker Kubernetes Operator"
LABEL description="The Solace PubSub+ Event Broker Kubernetes Operator deploys and manages the lifecycle of PubSub+ Event Brokers"

Expand Down
4 changes: 2 additions & 2 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
# To re-generate a bundle for another specific version without changing the standard setup, you can:
# - use the VERSION as arg of the bundle target (e.g make bundle VERSION=0.0.2)
# - use environment variables to overwrite this value (e.g export VERSION=0.0.2)
VERSION ?= 1.4.1
VERSION ?= 1.4.2

# API_VERSION defines the API version for the PubSubPlusEventBroker CRD
API_VERSION ?= v1beta1
Expand Down Expand Up @@ -182,7 +182,7 @@ ENVTEST ?= $(LOCALBIN)/setup-envtest

## Tool Versions
KUSTOMIZE_VERSION ?= v4.5.7
CONTROLLER_TOOLS_VERSION ?= v0.14.0
CONTROLLER_TOOLS_VERSION ?= v0.17.0

KUSTOMIZE_INSTALL_SCRIPT ?= "https://raw.githubusercontent.com/kubernetes-sigs/kustomize/master/hack/install_kustomize.sh"
.PHONY: kustomize
Expand Down
2 changes: 2 additions & 0 deletions api/v1beta1/eventbroker_types.go
Original file line number Diff line number Diff line change
Expand Up @@ -152,6 +152,7 @@ type BrokerPort struct {
// Unique name for the port that can be referred to by services.
Name string `json:"name"`
//+kubebuilder:validation:Enum=TCP;UDP;SCTP
//+kubebuilder:default:=TCP
// Protocol for port. Must be UDP, TCP, or SCTP.
Protocol corev1.Protocol `json:"protocol"`
//+kubebuilder:validation:Type:=number
Expand Down Expand Up @@ -500,6 +501,7 @@ type MonitoringMetricsEndpoint struct {
ListenTLS bool `json:"listenTLS"`
//+optional
//+kubebuilder:validation:Enum=TCP;UDP;SCTP
//+kubebuilder:default:=TCP
// Protocol for port. Must be UDP, TCP, or SCTP.
Protocol corev1.Protocol `json:"protocol"`
//+optional
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ metadata:
certified: "true"
com.redhat.delivery.operator.bundle: "true"
com.redhat.openshift.versions: v4.10
containerImage: docker.io/solace/pubsubplus-eventbroker-operator:1.4.1
containerImage: docker.io/solace/pubsubplus-eventbroker-operator:1.4.2
createdAt: "2025-07-31T19:48:36Z"
description: The Solace PubSub+ Event Broker Operator deploys and manages the
lifecycle of PubSub+ Event Brokers
Expand All @@ -29,7 +29,7 @@ metadata:
operators.operatorframework.io/project_layout: go.kubebuilder.io/v3
repository: https://github.com/SolaceProducts/pubsubplus-kubernetes-quickstart
support: Solace Products
name: pubsubplus-eventbroker-operator.v1.4.1
name: pubsubplus-eventbroker-operator.v1.4.2
namespace: placeholder
spec:
apiservicedefinitions: {}
Expand Down Expand Up @@ -296,7 +296,7 @@ spec:
valueFrom:
fieldRef:
fieldPath: metadata.annotations['olm.targetNamespaces']
image: docker.io/solace/pubsubplus-eventbroker-operator:1.4.1
image: docker.io/solace/pubsubplus-eventbroker-operator:1.4.2
imagePullPolicy: Always
livenessProbe:
httpGet:
Expand Down Expand Up @@ -411,4 +411,4 @@ spec:
provider:
name: Solace Corporation
url: www.solace.com
version: 1.4.1
version: 1.4.2
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.14.0
labels:
app.kubernetes.io/version: v1.4.1
app.kubernetes.io/version: v1.4.2
name: pubsubpluseventbrokers.pubsubplus.solace.com
spec:
group: pubsubplus.solace.com
Expand Down
Loading
Loading