* 'master' of github.com:spotify/backstage: (110 commits) chore(catalog-backend): removing redudant classes and some functions chore(deps-dev): bump @types/webpack from 4.41.21 to 4.41.22 (#2765) move codecov.yml to .github feat(catalog-backend): add batch concurrency create-app: remove build step cli: simplify jest transform ignore regex feat(catalog-backend): introduce batching, speed up reading and writing of large datasets Techdocs: add Azure DevOps prepare support (#2748) feat(techdocs-header): Show breadcrumbs on docs page (#2786) changesets: add entry for create-app template location fix create-app: revert to github location type for example templates fix: make catalog filter work again Use new url scheme for techdocs feat: remove LocationProcessor.processEntity Add Dockerfile for helm chart feat: use the new UrlReader in the CodeOwnersProcessor feat: use new UrlReader in PlaceholderProcessor feat: remove the backstage.io/definition-at-location annotation Update loud-lamps-visit.md feat(proxy-backend): limit the forwarded http headers to a safe set ...
Kubernetes Backend
WORK IN PROGRESS
This is the backend part of the Kubernetes plugin.
It responds to Kubernetes requests from the frontend.
Configuration
clusterLocatorMethod
This configures how to determine which clusters a component is running in.
Currently, the only valid locator method is:
configMultiTenant
This configuration assumes that all components run on all the provided clusters.
Example:
kubernetes:
clusterLocatorMethod: 'configMultiTenant'
clusters:
- url: http://127.0.0.1:9999
name: minikube
serviceAccountToken: <TOKEN FROM STEP 4>
authProvider: 'serviceAccount'
- url: http://127.0.0.2:9999
name: gke-cluster-1
authProvider: 'google'
clusters
Used by the configMultiTenant clusterLocatorMethod to construct Kubernetes clients.
url
The base url to the Kubernetes control plane. Can be found by using the Kubernetes master result from running the kubectl cluster-info command.
name
A name to represent this cluster, this must be unique within the clusters array. Users will see this value in the Service Catalog Kubernetes plugin.
authProvider
This determines how the Kubernetes client authenticate with the Kubernetes cluster. Valid values are:
| Value | Description |
|---|---|
serviceAccount |
This will use a Kubernetes service account to access the Kubernetes API. When this is used the serviceAccountToken field should also be set. |
google |
This will use a user's google auth token from the google auth plugin to access the Kubernetes API. |
serviceAccount (optional)
The service account token to be used when using the authProvider, serviceAccount.
RBAC
The current RBAC permissions required are read-only cluster wide, for the following objects:
- pods
- services
- configmaps
- deployments
- replicasets
- horizontalpodautoscalers
- ingresses