GPU-Live/network-operator/values.yaml

310 lines
11 KiB
YAML

# Copyright 2020 NVIDIA
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
# Default values for network-operator.
# This is a YAML-formatted file.
nfd:
# -- Deploy Node Feature Discovery operator.
enabled: true
# -- Deploy Node Feature Rules to label the nodes with the discovered features.
deployNodeFeatureRules: true
# -- Enable CRDs upgrade with helm pre-install and pre-upgrade hooks.
upgradeCRDs: true
sriovNetworkOperator:
# -- Deploy SR-IOV Network Operator.
enabled: false
nicConfigurationOperator:
# -- Deploy NIC Configuration Operator.
enabled: false
maintenanceOperator:
# -- Deploy Maintenance Operator.
enabled: false
# Set both enableNodeFeatureApi and NodeFeatureAPI feature gate to false to disable.
node-feature-discovery:
# -- The Node Feature API enable communication between nfd master and worker
# through NodeFeature CRs. Otherwise communication is through gRPC.
enableNodeFeatureApi: true
featureGates:
NodeFeatureAPI: true
# -- NFD master deployment configuration.
# @notationType -- yaml
master:
serviceAccount:
name: node-feature-discovery
create: true
config:
extraLabelNs: ["nvidia.com"]
gc:
# -- Specifies whether the NFD Garbage Collector should be created
enable: true
# -- Specifies the number of replicas for the NFD Garbage Collector
replicaCount: 1
serviceAccount:
# -- The name of the service account for garbage collector to use.
# If not set and create is true, a name is generated using the fullname
# template and -gc suffix.
name: node-feature-discovery
# -- disable creation to avoid duplicate serviceaccount creation by master
# spec above.
create: false
# -- NFD worker daemonset configuration.
# @notationType -- yaml
worker:
serviceAccount:
# disable creation to avoid duplicate serviceaccount creation by master spec
# above
name: node-feature-discovery
create: false
tolerations:
- key: "node-role.kubernetes.io/master"
operator: "Exists"
effect: "NoSchedule"
- key: "node-role.kubernetes.io/control-plane"
operator: "Exists"
effect: "NoSchedule"
- key: nvidia.com/gpu
operator: Exists
effect: NoSchedule
config:
sources:
pci:
deviceClassWhitelist:
- "0300"
- "0302"
deviceLabelFields:
- vendor
# SR-IOV Network Operator chart related values.
sriov-network-operator:
operator:
# -- Prefix to be used for resources names.
resourcePrefix: "nvidia.com"
# -- Enable admission controller.
# @notationType -- yaml
admissionControllers:
enabled: false
certificates:
secretNames:
operator: "operator-webhook-cert"
injector: "network-resources-injector-cert"
certManager:
# -- When enabled, makes use of certificates managed by cert-manager.
enabled: true
# -- When enabled, certificates are generated via cert-manager and then
# name will match the name of the secrets defined above.
generateSelfSigned: true
# -- If not specified, no secret is created and secrets with the names
# defined above are expected to exist in the cluster. In that case,
# the ca.crt must be base64 encoded twice since it ends up being an env variable.
custom:
enabled: false
# operator:
# caCrt: |
# -----BEGIN CERTIFICATE-----
# MIIMIICLDCCAdKgAwIBAgIBADAKBggqhkjOPQQDAjB9MQswCQYDVQQGEwJCRTEPMA0G
# ...
# -----END CERTIFICATE-----
# tlsCrt: |
# -----BEGIN CERTIFICATE-----
# MIIMIICLDCCAdKgAwIBAgIBADAKBggqhkjOPQQDAjB9MQswCQYDVQQGEwJCRTEPMA0G
# ...
# -----END CERTIFICATE-----
# tlsKey: |
# -----BEGIN EC PRIVATE KEY-----
# MHcl4wOuDwKQa+upc8GftXE2C//4mKANBC6It01gUaTIpo=
# ...
# -----END EC PRIVATE KEY-----
# injector:
# caCrt: |
# -----BEGIN CERTIFICATE-----
# MIIMIICLDCCAdKgAwIBAgIBADAKBggqhkjOPQQDAjB9MQswCQYDVQQGEwJCRTEPMA0G
# ...
# -----END CERTIFICATE-----
# tlsCrt: |
# -----BEGIN CERTIFICATE-----
# MIIMIICLDCCAdKgAwIBAgIBADAKBggqhkjOPQQDAjB9MQswCQYDVQQGEwJCRTEPMA0G
# ...
# -----END CERTIFICATE-----
# tlsKey: |
# -----BEGIN EC PRIVATE KEY-----
# MHcl4wOuDwKQa+upc8GftXE2C//4mKANBC6It01gUaTIpo=
# ...
# -----END EC PRIVATE KEY-----
# Image URIs for sriov-network-operator components.
images:
operator: nvcr.io/nvidia/mellanox/sriov-network-operator:network-operator-25.1.0
sriovConfigDaemon: nvcr.io/nvidia/mellanox/sriov-network-operator-config-daemon:network-operator-25.1.0
sriovCni: ghcr.io/k8snetworkplumbingwg/sriov-cni:v2.8.1
ibSriovCni: ghcr.io/k8snetworkplumbingwg/ib-sriov-cni:v1.1.1
ovsCni: ghcr.io/k8snetworkplumbingwg/ovs-cni-plugin:v0.37.0
# rdmaCni: ghcr.io/k8snetworkplumbingwg/rdma-cni:v1.2.0
sriovDevicePlugin: ghcr.io/k8snetworkplumbingwg/sriov-network-device-plugin:v3.9.0
resourcesInjector: ghcr.io/k8snetworkplumbingwg/network-resources-injector:v1.7.0
webhook: nvcr.io/nvidia/mellanox/sriov-network-operator-webhook:network-operator-25.1.0
# imagePullSecrest for SR-IOV Network Operator related images
# imagePullSecrets: []
sriovOperatorConfig:
# -- Deploy ``SriovOperatorConfig`` custom resource
deploy: true
# -- Selects the nodes to be configured
# @notationType -- yaml
configDaemonNodeSelector:
beta.kubernetes.io/os: "linux"
network.nvidia.com/operator.mofed.wait: "false"
# Nic Configuration Operator chart related values.
nic-configuration-operator-chart:
operator:
image:
repository: ghcr.io/mellanox
name: nic-configuration-operator
tag: v0.1.17
configDaemon:
image:
repository: ghcr.io/mellanox
name: nic-configuration-operator-daemon
tag: v0.1.17
# Maintenance Operator chart related values.
maintenance-operator-chart:
operator:
image:
repository: ghcr.io/mellanox
name: maintenance-operator
tag: v0.2.0
admissionController:
# -- enable admission controller of the operator
enable: false
certificates:
secretNames:
# -- secret name containing certificates for the operator admission controller
operator: "maintenance-webhook-cert"
certManager:
# -- use cert-manager for certificates
enable: false
# -- generate self-signed certificates with cert-manager
generateSelfSigned: false
custom:
# -- enable custom certificates using secrets
enable: false
# General Operator related values
# The operator element allows to deploy network operator from an alternate location
operator:
# -- Optional `resource requests and limits <https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/>`_
# for the operator.
# @notationType -- yaml
resources:
limits:
cpu: 500m
memory: 128Mi
requests:
cpu: 5m
memory: 64Mi
# -- Set additional tolerations for various Daemonsets deployed by the operator.
# @notationType -- yaml
tolerations:
- key: "node-role.kubernetes.io/master"
operator: "Equal"
value: ""
effect: "NoSchedule"
- key: "node-role.kubernetes.io/control-plane"
operator: "Equal"
value: ""
effect: "NoSchedule"
# -- Configure node selector settings for the operator.
nodeSelector: {}
affinity:
# -- Configure node affinity settings for the operator.
# @notationType -- yaml
nodeAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 1
preference:
matchExpressions:
- key: "node-role.kubernetes.io/master"
operator: In
values: [""]
- weight: 1
preference:
matchExpressions:
- key: "node-role.kubernetes.io/control-plane"
operator: In
values: [ "" ]
# -- Network Operator image repository.
repository: nvcr.io/nvidia/cloud-native
# -- Network Operator image name
image: network-operator
# imagePullSecrets: []
# -- Name to be used as part of objects name generation.
nameOverride: ""
# -- Name to be used to replace generated names.
fullnameOverride: ""
# tag, if defined will use the given image tag, else Chart. AppVersion will be used.
# tag
# -- Directory, where CNI binaries will be deployed on the nodes. Setting for
# the sriov-network-operator is set with ``sriov-network-operator.cniBinPath``
# parameter. Note that the CNI bin directory should be aligned with the CNI bin
# directory in the container runtime.
cniBinDirectory: /opt/cni/bin
# -- Enable the use of Driver ToolKit to compile DOCA Drivers (OpenShift only).
useDTK: true
admissionController:
# -- Deploy with admission controller.
enabled: false
# -- Use cert-manager for generating self-signed certificate.
useCertManager: true
# certificate:
# caCrt: |
# -----BEGIN CERTIFICATE-----
# MIIMIICLDCCAdKgAwIBAgIBADAKBggqhkjOPQQDAjB9MQswCQYDVQQGEwJCRTEPMA0G
# ...
# -----END CERTIFICATE-----
# tlsCrt: |
# -----BEGIN CERTIFICATE-----
# MIIMIICLDCCAdKgAwIBAgIBADAKBggqhkjOPQQDAjB9MQswCQYDVQQGEwJCRTEPMA0G
# ...
# -----END CERTIFICATE-----
# tlsKey: |
# -----BEGIN EC PRIVATE KEY-----
# MHcl4wOuDwKQa+upc8GftXE2C//4mKANBC6It01gUaTIpo=
# ...
# -----END EC PRIVATE KEY-----
ofedDriver:
initContainer:
# -- Deploy init container.
enable: true
# -- Init container image repository.
repository: ghcr.io/mellanox
# -- Init container image name.
image: network-operator-init-container
# -- Init container image version.
version: v0.0.3
# -- An optional list of references to secrets to use for pulling any of the
# Network Operator images.
imagePullSecrets: []
# @ignore
test:
pf: ens2f0