Skip to content

Commit

Permalink
ci: avoid using deprecated tls.secretsBackend flag
Browse files Browse the repository at this point in the history
This is a prerequisite for using Cilium 1.17 in CI.

Follow cilium/cilium#37428

Signed-off-by: Tobias Klauser <[email protected]>
  • Loading branch information
tklauser authored and michi-covalent committed Feb 14, 2025
1 parent 5e199b4 commit 1b44ea6
Show file tree
Hide file tree
Showing 7 changed files with 16 additions and 8 deletions.
3 changes: 2 additions & 1 deletion .github/workflows/aks-byocni.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -140,7 +140,8 @@ jobs:
--datapath-mode=aks-byocni \
--wait=false \
--set loadBalancer.l7.backend=envoy \
--set tls.secretsBackend=k8s \
--set=tls.readSecretsOnlyFromSecretsNamespace=true \
--set=tls.secretSync.enabled=true \
--set bpf.monitorAggregation=none \
--set ipam.operator.clusterPoolIPv4PodCIDRList=192.168.0.0/16 # To avoid clashing with the default Service CIDR of AKS (10.0.0.0/16)
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/eks-tunnel.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -142,7 +142,8 @@ jobs:
--set bpf.monitorAggregation=none \
--datapath-mode=tunnel \
--set loadBalancer.l7.backend=envoy \
--set tls.secretsBackend=k8s \
--set=tls.readSecretsOnlyFromSecretsNamespace=true \
--set=tls.secretSync.enabled=true \
--set ipam.mode=cluster-pool
# Enable Relay
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/eks.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -141,7 +141,8 @@ jobs:
--set cluster.name="${{ env.clusterName }}" \
--wait=false \
--set loadBalancer.l7.backend=envoy \
--set tls.secretsBackend=k8s \
--set=tls.readSecretsOnlyFromSecretsNamespace=true \
--set=tls.secretSync.enabled=true \
--set bpf.monitorAggregation=none
# Enable Relay
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/externalworkloads.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -165,7 +165,8 @@ jobs:
--datapath-mode=tunnel \
--set kubeProxyReplacement=true \
--set loadBalancer.l7.backend=envoy \
--set tls.secretsBackend=k8s \
--set=tls.readSecretsOnlyFromSecretsNamespace=true \
--set=tls.secretSync.enabled=true \
--set ipv4NativeRoutingCIDR="${{ steps.cluster.outputs.cluster_cidr }}"
# Enable Relay
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/gke.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -140,7 +140,8 @@ jobs:
--set cluster.name="${{ env.clusterName }}" \
--set bpf.monitorAggregation=none \
--set loadBalancer.l7.backend=envoy \
--set tls.secretsBackend=k8s \
--set=tls.readSecretsOnlyFromSecretsNamespace=true \
--set=tls.secretSync.enabled=true \
--set hubble.eventQueueSize=65536
# Enable Relay
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/kind.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,8 @@ jobs:
--set bpf.monitorAggregation=none \
--set cni.chainingMode=portmap \
--set loadBalancer.l7.backend=envoy \
--set tls.secretsBackend=k8s \
--set=tls.readSecretsOnlyFromSecretsNamespace=true \
--set=tls.secretSync.enabled=true \
--set prometheus.enabled=true \
--set localRedirectPolicy=true \
--set socketLB.enabled=true
Expand Down
6 changes: 4 additions & 2 deletions .github/workflows/multicluster.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -190,7 +190,8 @@ jobs:
--version "${{ env.cilium_version }}" \
--context "${{ steps.contexts.outputs.cluster1 }}" \
--set loadBalancer.l7.backend=envoy \
--set tls.secretsBackend=k8s \
--set=tls.readSecretsOnlyFromSecretsNamespace=true \
--set=tls.secretSync.enabled=true \
--set cluster.name="${{ env.clusterName1 }}" \
--set cluster.id=1 \
--set bpf.monitorAggregation=none \
Expand All @@ -209,7 +210,8 @@ jobs:
--version "${{ env.cilium_version }}" \
--context "${{ steps.contexts.outputs.cluster2 }}" \
--set loadBalancer.l7.backend=envoy \
--set tls.secretsBackend=k8s \
--set=tls.readSecretsOnlyFromSecretsNamespace=true \
--set=tls.secretSync.enabled=true \
--set cluster.name="${{ env.clusterName2 }}" \
--set cluster.id=2 \
--set bpf.monitorAggregation=none \
Expand Down

0 comments on commit 1b44ea6

Please sign in to comment.