Add nodeaffinity for cFW pods 93/102193/1
authorBin Yang <bin.yang@windriver.com>
Mon, 24 Feb 2020 04:42:24 +0000 (12:42 +0800)
committerBin Yang <bin.yang@windriver.com>
Mon, 24 Feb 2020 04:42:24 +0000 (12:42 +0800)
Change-Id: I31077bbaff99f7ffc2c13abd5899afd05cf560f9
Issue-ID: MULTICLOUD-999
Signed-off-by: Bin Yang <bin.yang@windriver.com>
starlingx/demo/firewall-host-netdevice/charts/pktgen-host-netdevice/templates/deployment.yaml
starlingx/demo/firewall-host-netdevice/charts/sink-host-netdevice/templates/deployment.yaml
starlingx/demo/firewall-host-netdevice/templates/deployment.yaml
starlingx/demo/firewall-host-netdevice/values.yaml
starlingx/demo/firewall-sriov/charts/pktgen-sriov/templates/deployment.yaml
starlingx/demo/firewall-sriov/charts/sink-sriov/templates/deployment.yaml
starlingx/demo/firewall-sriov/templates/deployment.yaml
starlingx/demo/firewall-sriov/values.yaml

index 4e48937..276b3df 100644 (file)
@@ -23,6 +23,19 @@ spec:
             "interface": "veth11" }
           ]'
     spec:
+      affinity:
+        nodeAffinity:
+          requiredDuringSchedulingIgnoredDuringExecution:
+            nodeSelectorTerms:
+            - matchExpressions:
+              {{- range .Values.global.nodeAffinity }}
+              - key: {{ .label.labelkey }}
+                operator: {{ .label.op }}
+                values:
+                {{- range .label.labelvalues }}
+                - {{ . }}
+                {{- end }}
+              {{- end }}
       containers:
       - name: {{ .Chart.Name }}
         image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
@@ -32,12 +45,10 @@ spec:
         env:
           - name: unprotectedNetCidr
             value: "{{.Values.global.unprotectedNetCidr}}"
-          - name: unprotectedNetGw
-            value: "{{.Values.global.unprotectedNetGw}}"
+          - name: unprotectedNetGwIp
+            value: "{{.Values.global.unprotectedNetGwIp}}"
           - name: protectedNetCidr
             value: "{{.Values.global.protectedNetCidr}}"
-          - name: protectedNetGw
-            value: "{{.Values.global.protectedNetGw}}"
           - name: protectedNetGwIp
             value: "{{.Values.global.protectedNetGwIp}}"
           - name: dcaeCollectorIp
index fe3d03f..eaa928a 100644 (file)
@@ -23,6 +23,19 @@ spec:
             "interface": "veth22" }
           ]'
     spec:
+      affinity:
+        nodeAffinity:
+          requiredDuringSchedulingIgnoredDuringExecution:
+            nodeSelectorTerms:
+            - matchExpressions:
+              {{- range .Values.global.nodeAffinity }}
+              - key: {{ .label.labelkey }}
+                operator: {{ .label.op }}
+                values:
+                {{- range .label.labelvalues }}
+                - {{ . }}
+                {{- end }}
+              {{- end }}
       containers:
         - name: {{ .Chart.Name }}
           image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
@@ -32,12 +45,10 @@ spec:
           env:
             - name: unprotectedNetCidr
               value: "{{.Values.global.unprotectedNetCidr}}"
-            - name: unprotectedNetGw
-              value: "{{.Values.global.unprotectedNetGw}}"
+            - name: unprotectedNetGwIp
+              value: "{{.Values.global.unprotectedNetGwIp}}"
             - name: protectedNetCidr
               value: "{{.Values.global.protectedNetCidr}}"
-            - name: protectedNetGw
-              value: "{{.Values.global.protectedNetGw}}"
             - name: protectedNetGwIp
               value: "{{.Values.global.protectedNetGwIp}}"
             - name: dcaeCollectorIp
index be0af96..e93e9da 100644 (file)
@@ -25,6 +25,19 @@ spec:
             "interface": "veth21" }
           ]'
     spec:
+      affinity:
+        nodeAffinity:
+          requiredDuringSchedulingIgnoredDuringExecution:
+            nodeSelectorTerms:
+            - matchExpressions:
+              {{- range .Values.global.nodeAffinity }}
+              - key: {{ .label.labelkey }}
+                operator: {{ .label.op }}
+                values:
+                {{- range .label.labelvalues }}
+                - {{ . }}
+                {{- end }}
+              {{- end }}
       containers:
       - name: {{ .Chart.Name }}
         image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
@@ -34,12 +47,10 @@ spec:
         env:
         - name: unprotectedNetCidr
           value: "{{.Values.global.unprotectedNetCidr}}"
-        - name: unprotectedNetGw
-          value: "{{.Values.global.unprotectedNetGw}}"
+        - name: unprotectedNetGwIp
+          value: "{{.Values.global.unprotectedNetGwIp}}"
         - name: protectedNetCidr
           value: "{{.Values.global.protectedNetCidr}}"
-        - name: protectedNetGw
-          value: "{{.Values.global.protectedNetGw}}"
         - name: protectedNetGwIp
           value: "{{.Values.global.protectedNetGwIp}}"
         - name: dcaeCollectorIp
index 199551c..0e044c1 100644 (file)
@@ -22,9 +22,16 @@ resources:
 global:
 
   nodeAffinity:
-    key: nodeName
-    values: worker-0
-    op: In
+    - label:
+        labelkey: sriovdp
+        op: In
+        labelvalues:
+          - enabled
+    - label:
+        labelkey:  kube-cpu-mgr-policy
+        op: In
+        labelvalues:
+          - static
 
   #Networks
   #unprotectedNetworkName: unprotected-private-net
@@ -34,7 +41,8 @@ global:
   unprotectedNetPortVpg: veth11
   unprotectedNetPortVfw: veth12
   unprotectedNetCidr: 10.10.1.0/24
-  unprotectedNetGw: 10.10.1.1/24
+  #unprotectedNetGw: 10.10.1.1/24
+  unprotectedNetGwIp: 10.10.1.1
 
   #onapPrivateNetworkName: onap-private-net
   #onapPrivateNetCidr: 10.10.0.0/16
@@ -48,7 +56,7 @@ global:
   protectedNetPortVsn: veth22
   protectedNetCidr: 10.10.2.0/24
   protectedNetGwIp: 10.10.2.1
-  protectedNetGw: 10.10.2.1/24
+  #protectedNetGw: 10.10.2.1/24
 
   #vFirewall container
   #vfwPrivateIp0: 192.168.10.3
index 6c7000a..53c306f 100644 (file)
@@ -23,6 +23,19 @@ spec:
             "interface": "veth11" }
           ]'
     spec:
+      affinity:
+        nodeAffinity:
+          requiredDuringSchedulingIgnoredDuringExecution:
+            nodeSelectorTerms:
+            - matchExpressions:
+              {{- range .Values.global.nodeAffinity }}
+              - key: {{ .label.labelkey }}
+                operator: {{ .label.op }}
+                values:
+                {{- range .label.labelvalues }}
+                - {{ . }}
+                {{- end }}
+              {{- end }}
       containers:
       - name: {{ .Chart.Name }}
         image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
@@ -46,6 +59,10 @@ spec:
             value: "{{.Values.global.unprotectedNetProviderDriver}}"
           - name: protectedNetProviderDriver
             value: "{{.Values.global.protectedNetProviderDriver}}"
+          - name: unprotectedNetProviderVlan
+            value: "{{.Values.global.unprotectedNetProviderVlan}}"
+          - name: protectedNetProviderVlan
+            value: "{{.Values.global.protectedNetProviderVlan}}"
         command: ["/bin/bash", "/opt/vpg_start.sh"]
         securityContext:
             privileged: true
index f3c29f0..45b3ecb 100644 (file)
@@ -23,6 +23,19 @@ spec:
             "interface": "veth22" }
           ]'
     spec:
+      affinity:
+        nodeAffinity:
+          requiredDuringSchedulingIgnoredDuringExecution:
+            nodeSelectorTerms:
+            - matchExpressions:
+              {{- range .Values.global.nodeAffinity }}
+              - key: {{ .label.labelkey }}
+                operator: {{ .label.op }}
+                values:
+                {{- range .label.labelvalues }}
+                - {{ . }}
+                {{- end }}
+              {{- end }}
       containers:
         - name: {{ .Chart.Name }}
           image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
@@ -46,6 +59,10 @@ spec:
               value: "{{.Values.global.unprotectedNetProviderDriver}}"
             - name: protectedNetProviderDriver
               value: "{{.Values.global.protectedNetProviderDriver}}"
+            - name: unprotectedNetProviderVlan
+              value: "{{.Values.global.unprotectedNetProviderVlan}}"
+            - name: protectedNetProviderVlan
+              value: "{{.Values.global.protectedNetProviderVlan}}"
           command: ["/bin/bash", "/opt/vsn_start.sh"]
           securityContext:
               privileged: true
index 9067716..d4b5957 100644 (file)
@@ -25,6 +25,19 @@ spec:
             "interface": "veth21" }
           ]'
     spec:
+      affinity:
+        nodeAffinity:
+          requiredDuringSchedulingIgnoredDuringExecution:
+            nodeSelectorTerms:
+            - matchExpressions:
+              {{- range .Values.global.nodeAffinity }}
+              - key: {{ .label.labelkey }}
+                operator: {{ .label.op }}
+                values:
+                {{- range .label.labelvalues }}
+                - {{ . }}
+                {{- end }}
+              {{- end }}
       containers:
       - name: {{ .Chart.Name }}
         image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
@@ -48,6 +61,10 @@ spec:
           value: "{{.Values.global.unprotectedNetProviderDriver}}"
         - name: protectedNetProviderDriver
           value: "{{.Values.global.protectedNetProviderDriver}}"
+        - name: unprotectedNetProviderVlan
+          value: "{{.Values.global.unprotectedNetProviderVlan}}"
+        - name: protectedNetProviderVlan
+          value: "{{.Values.global.protectedNetProviderVlan}}"
         command: ["/bin/bash", "/opt/vfw_start.sh"]
         securityContext:
             privileged: true
index 53aa9de..94a858c 100644 (file)
@@ -21,9 +21,16 @@ resources:
 global:
 
   nodeAffinity:
-    key: nodeName
-    values: worker-0
-    op: In
+    - label:
+        labelkey: sriovdp
+        op: In
+        labelvalues:
+          - enabled
+    - label:
+        labelkey:  kube-cpu-mgr-policy
+        op: In
+        labelvalues:
+          - static
 
   #Networks
   #unprotectedNetworkName: unprotected-private-net