This commit is contained in:
alessandro
2026-07-17 09:42:52 +02:00
commit 20d506407a
93 changed files with 14526 additions and 0 deletions

197
add-on/tekton.sh Normal file
View File

@@ -0,0 +1,197 @@
kubectl create namespace tekton-pipelines
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.7.0/release.yaml
kubectl edit cm feature-flags -n tekton-pipelines
data:
enable-api-fields: "stable"
disable-affinity-assistant: "false"
enable-tekton-oci-bundles: "true"
enable-custom-tasks: "true"
kubectl edit cm config-defaults -n tekton-pipelines
data:
default-timeout-minutes: "60"
default-service-account: "tekton-sa"
cat <<EOF | cat > tekton-sa.yaml -
apiVersion: v1
kind: ServiceAccount
metadata:
name: tekton-sa
namespace: tekton-pipelines
EOF
kubectl apply -f tekton-sa.yaml
#STEP 1 Creare Robot Account in Harbor
#Harbor UI → Projects → (es. library o apps) → Robot Accounts
#Nome: k8s-pull
#Permessi:
#✔️ FULL permission
kubectl create secret docker-registry harbor-regcred \
-n tekton-pipelines \
--docker-server=harbor.italiadatacenter.com \
--docker-username=robot$tekton \
--docker-password=pyyMRe2kRIp6LQmIh8jaSWquL1mDtz04 \
--docker-email=harbor@italiadatacenter.com
cat <<EOF > config.json
{
"auths": {
"harbor.italiadatacenter.com": {
"username": "robot\$tekton",
"password": "pyyMRe2kRIp6LQmIh8jaSWquL1mDtz04",
"email": "harbor@italiadatacenter.com",
"auth": "$(echo -n 'robot$tekton:pyyMRe2kRIp6LQmIh8jaSWquL1mDtz04' | base64)"
}
}
}
EOF
kubectl create secret generic harbor-push-secret -n tekton-pipelines --from-file=config.json=config.json
kubectl patch sa tekton-sa \
-n tekton-pipelines \
-p '{"imagePullSecrets":[{"name":"harbor-regcred"}]}'
cat <<EOF | cat > tekton-workspace.yaml -
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: tekton-workspace
namespace: tekton-pipelines
spec:
accessModes:
- ReadWriteOnce
storageClassName: csi-rbdfs-sc
resources:
requests:
storage: 10Gi
EOF
kubectl apply -f tekton-workspace.yaml -n tekton-pipelines
#Tekton Triggers
kubectl apply -f https://storage.googleapis.com/tekton-releases/triggers/latest/release.yaml -n tekton-pipelines
#Tekton Dashboard
kubectl apply -f https://storage.googleapis.com/tekton-releases/dashboard/latest/release.yaml -n tekton-pipelines
cat <<EOF | cat > tekton-ingress.yaml -
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: tekton-dashboard
namespace: tekton-pipelines
annotations:
kubernetes.io/ingress.class: "nginx"
cert-manager.io/cluster-issuer: "letsencrypt-production"
spec:
tls:
- hosts:
- tekton.pigreco66.it
secretName: myapp-tls
rules:
- host: tekton.pigreco66.it
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: tekton-dashboard
port:
number: 9097
EOF
cat <<EOF | cat > tekton-httproute.yaml -
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: tekton
namespace: tekton-pipelines
spec:
hostnames:
- tekton.italiadatacenter.com
parentRefs:
- name: main-gateway
namespace: nginx-gateway
rules:
- matches:
- path:
type: PathPrefix
value: /
backendRefs:
- name: tekton-dashboard
port: 9097
EOF
kubectl apply -f tekton-httproute.yaml -n tekton-pipelines
kubectl label namespace tekton-pipelines \
pod-security.kubernetes.io/enforce=privileged \
pod-security.kubernetes.io/audit=privileged \
pod-security.kubernetes.io/warn=privileged \
--overwrite
#installazione cli
curl -LO https://github.com/tektoncd/cli/releases/download/v0.43.0/tkn_0.43.0_Linux_x86_64.tar.gz
tar xvf tkn_0.43.0_Linux_x86_64.tar.gz
sudo mv tkn /usr/local/bin/
#TEST
cat <<EOF | cat > tekton-test.yaml -
apiVersion: tekton.dev/v1
kind: Task
metadata:
name: hello
namespace: tekton-pipelines
spec:
steps:
- name: echo
image: alpine
script: |
echo "Tekton OK"
---
apiVersion: tekton.dev/v1
kind: Pipeline
metadata:
name: hello-pipeline
namespace: tekton-pipelines
spec:
tasks:
- name: hello
taskRef:
name: hello
---
apiVersion: tekton.dev/v1
kind: PipelineRun
metadata:
name: hello-pipeline-run
spec:
pipelineRef:
name: hello-pipeline
params:
- name: username
value: "Tekton"
EOF
kubectl apply -f tekton-test.yaml -n tekton-pipelines