Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 14 additions & 5 deletions tests/templates/kuttl/iceberg-hive/01_s3-connection.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,17 @@
apiVersion: s3.stackable.tech/v1alpha1
kind: S3Connection
metadata:
name: minio
name: garage
spec:
host: "minio.${NAMESPACE}.svc.cluster.local"
host: "garage.${NAMESPACE}.svc.cluster.local"
port: 9000
# The operators pass this on to the products (Trino: s3.region, Hive:
# fs.s3a.endpoint.region), so it has to match s3_region in 20_garage.yaml.
# Not the us-east-1 default: NiFi signs with us-east-2 here, which is the
# Hadoop S3 implementation's fallback for non-AWS endpoints and is more
# convoluted to configure from a flow, so the products follow it instead.
region:
name: us-east-2
accessStyle: Path
credentials:
secretClass: s3-credentials-class
Expand All @@ -28,9 +35,11 @@ spec:
apiVersion: v1
kind: Secret
metadata:
name: minio-credentials
name: garage-credentials
labels:
secrets.stackable.tech/class: s3-credentials-class
stringData:
accessKey: admin
secretKey: adminadmin
# Garage requires the GK<24 hex> key id format and a 64 hex char secret.
# Must match the GARAGE_DEFAULT_* variables in 20_garage.yaml.
accessKey: GK31c0ffee31c0ffee31c0ffee
secretKey: deadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeef
2 changes: 1 addition & 1 deletion tests/templates/kuttl/iceberg-hive/20-assert.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ timeout: 600
apiVersion: apps/v1
kind: Deployment
metadata:
name: minio
name: garage
status:
readyReplicas: 1
replicas: 1
Original file line number Diff line number Diff line change
Expand Up @@ -2,4 +2,4 @@
apiVersion: kuttl.dev/v1beta1
kind: TestStep
commands:
- script: kubectl -n $NAMESPACE apply -f 20_minio.yaml
- script: kubectl -n $NAMESPACE apply -f 20_garage.yaml
163 changes: 163 additions & 0 deletions tests/templates/kuttl/iceberg-hive/20_garage.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,163 @@
---
apiVersion: v1
kind: ConfigMap
metadata:
name: garage
data:
# https://garagehq.deuxfleurs.fr/documentation/reference-manual/configuration/
garage.toml: |
metadata_dir = "/var/lib/garage/meta"
data_dir = "/var/lib/garage/data"
db_engine = "lmdb"

# Single node, no redundancy. Test data is disposable (emptyDir).
replication_factor = 1

# Throwaway value, this cluster is never joined by another node.
rpc_secret = "deadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeef"
rpc_bind_addr = "[::]:3901"
rpc_public_addr = "127.0.0.1:3901"

[s3_api]
# Garage rejects requests signed for a different region, so this must match
# the region every client signs with. That region is dictated by NiFi: the
# Iceberg catalog service reaches S3 through the Hadoop S3 implementation,
# which falls back to us-east-2 when fs.s3a.endpoint.region is unset and the
# endpoint is not an AWS one. Those settings are more convoluted to configure
# from a flow, so everything else follows suit instead, see the region in
# 01_s3-connection.yaml. NiFi drops the Hadoop S3 implementation after 2.7.0,
# after which this can become a provider agnostic name.
s3_region = "us-east-2"
api_bind_addr = "[::]:3900"

[admin]
api_bind_addr = "[::]:3903"
# Garage terminates no TLS on any endpoint, so nginx does it and forwards to
# Garage on loopback. Mounted over /etc/nginx/nginx.conf, hence the full file.
nginx.conf: |
events {}
http {
server {
listen 9000 ssl;
ssl_certificate /stackable/tls/tls.crt;
ssl_certificate_key /stackable/tls/tls.key;

# Don't buffer or size-limit object uploads.
client_max_body_size 0;

location / {
proxy_pass http://127.0.0.1:3900;
# Must be the original Host, it is part of the SigV4 signature.
proxy_set_header Host $http_host;
proxy_http_version 1.1;
proxy_buffering off;
proxy_request_buffering off;
}
}
}
---
apiVersion: v1
kind: Service
metadata:
name: garage
spec:
selector:
app: garage
ports:
- name: https
port: 9000
targetPort: https
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: garage
labels:
app: garage
spec:
replicas: 1
selector:
matchLabels:
app: garage
template:
metadata:
labels:
app: garage
spec:
containers:
- name: garage
image: oci.stackable.tech/stackable/dxflrs/garage:v2.4.1
imagePullPolicy: IfNotPresent
# The image has no entrypoint. --single-node creates the cluster
# layout, --default-bucket creates the bucket and the access key from
# the GARAGE_DEFAULT_* variables below (implies --default-access-key).
command:
- /garage
- server
- --single-node
- --default-bucket
env:
- name: GARAGE_DEFAULT_BUCKET
value: demo
# Garage requires the GK<24 hex> key id format and a 64 hex char
# secret. These are also set in 01_s3-connection.yaml and in the
# NiFi flow (60_nifi-flow.json).
- name: GARAGE_DEFAULT_ACCESS_KEY
value: GK31c0ffee31c0ffee31c0ffee
- name: GARAGE_DEFAULT_SECRET_KEY
value: deadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeef
ports:
- name: rpc
containerPort: 3901
- name: admin
containerPort: 3903
readinessProbe:
httpGet:
path: /health
port: admin
volumeMounts:
- name: config
mountPath: /etc/garage.toml
subPath: garage.toml
- name: data
mountPath: /var/lib/garage
resources:
requests:
cpu: 500m
memory: 512Mi
- name: nginx
image: docker.io/library/nginx:1.29-alpine
imagePullPolicy: IfNotPresent
ports:
- name: https
containerPort: 9000
volumeMounts:
- name: config
mountPath: /etc/nginx/nginx.conf
subPath: nginx.conf
- name: tls
mountPath: /stackable/tls
resources:
requests:
cpu: 100m
memory: 128Mi
volumes:
- name: config
configMap:
name: garage
- name: data
emptyDir: {}
- name: tls
ephemeral:
volumeClaimTemplate:
metadata:
annotations:
secrets.stackable.tech/class: tls
secrets.stackable.tech/scope: service=garage
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: "1"
storageClassName: secrets.stackable.tech
Loading
Loading