From 5b83f8b7d849cfd7f24f2771f3c775be048762c8 Mon Sep 17 00:00:00 2001 From: Carlos David Ramirez Date: Thu, 30 Jul 2026 23:41:50 -0500 Subject: [PATCH] Create pack elastic stack --- packs/elastic-stack-0.19.1/README.md | 132 ++++++ .../charts/eck-stack-0.19.1.tgz | Bin 0 -> 48953 bytes .../charts/eck-stack/.helmignore | 25 ++ .../charts/eck-stack/Chart.lock | 33 ++ .../charts/eck-stack/Chart.yaml | 47 ++ .../charts/eck-stack/README.md | 93 ++++ .../eck-stack/charts/eck-agent/.helmignore | 24 + .../eck-stack/charts/eck-agent/Chart.yaml | 10 + .../charts/eck-stack/charts/eck-agent/LICENSE | 93 ++++ .../eck-agent/examples/fleet-agents.yaml | 24 + .../examples/system-integration.yaml | 133 ++++++ .../charts/eck-agent/templates/NOTES.txt | 6 + .../charts/eck-agent/templates/_helpers.tpl | 51 +++ .../templates/cluster-role-binding.yaml | 33 ++ .../eck-agent/templates/cluster-role.yaml | 22 + .../eck-agent/templates/elastic-agent.yaml | 89 ++++ .../eck-agent/templates/extra-objects.yaml | 5 + .../eck-agent/templates/service-account.yaml | 22 + .../eck-stack/charts/eck-agent/values.yaml | 282 ++++++++++++ .../charts/eck-apm-server/.helmignore | 24 + .../charts/eck-apm-server/Chart.yaml | 10 + .../eck-stack/charts/eck-apm-server/LICENSE | 93 ++++ .../jaeger-with-http-configuration.yaml | 29 ++ .../charts/eck-apm-server/templates/NOTES.txt | 6 + .../eck-apm-server/templates/_helpers.tpl | 51 +++ .../eck-apm-server/templates/apmserver.yaml | 53 +++ .../templates/extra-objects.yaml | 5 + .../charts/eck-apm-server/values.yaml | 126 ++++++ .../eck-autoops-agent-policy/.helmignore | 24 + .../eck-autoops-agent-policy/Chart.yaml | 8 + .../charts/eck-autoops-agent-policy/LICENSE | 94 ++++ .../examples/basic.yaml | 16 + .../templates/NOTES.txt | 7 + .../templates/_helpers.tpl | 52 +++ .../templates/autoopsagentpolicy.yaml | 35 ++ .../templates/extra-objects.yaml | 5 + .../eck-autoops-agent-policy/values.yaml | 114 +++++ .../eck-stack/charts/eck-beats/.helmignore | 24 + .../eck-stack/charts/eck-beats/Chart.yaml | 10 + .../charts/eck-stack/charts/eck-beats/LICENSE | 93 ++++ .../eck-beats/examples/auditbeat_hosts.yaml | 110 +++++ .../examples/filebeat_no_autodiscover.yaml | 52 +++ .../examples/heartbeat_es_kb_health.yaml | 23 + .../eck-beats/examples/metricbeat_hosts.yaml | 166 +++++++ .../examples/packetbeat_dns_http.yaml | 37 ++ .../charts/eck-beats/templates/NOTES.txt | 6 + .../charts/eck-beats/templates/_helpers.tpl | 51 +++ .../charts/eck-beats/templates/beats.yaml | 75 ++++ .../templates/cluster-role-binding.yaml | 35 ++ .../eck-beats/templates/cluster-role.yaml | 22 + .../eck-beats/templates/extra-objects.yaml | 5 + .../eck-beats/templates/service-account.yaml | 23 + .../eck-stack/charts/eck-beats/values.yaml | 206 +++++++++ .../charts/eck-elasticsearch/.helmignore | 24 + .../charts/eck-elasticsearch/Chart.yaml | 10 + .../charts/eck-elasticsearch/LICENSE | 93 ++++ .../examples/hot-warm-cold.yaml | 198 +++++++++ .../ingress/elasticsearch-ingress-aks.yaml | 26 ++ .../elasticsearch-ingress-eks-alb.yaml | 37 ++ .../elasticsearch-ingress-eks-nlb.yaml | 27 ++ .../ingress/elasticsearch-ingress-gke.yaml | 36 ++ .../eck-elasticsearch/templates/NOTES.txt | 6 + .../eck-elasticsearch/templates/_helpers.tpl | 51 +++ .../templates/elasticsearch.yaml | 78 ++++ .../templates/extra-objects.yaml | 5 + .../eck-elasticsearch/templates/ingress.yaml | 48 ++ .../charts/eck-elasticsearch/values.yaml | 411 ++++++++++++++++++ .../charts/eck-enterprise-search/.helmignore | 24 + .../charts/eck-enterprise-search/Chart.yaml | 9 + .../examples/with-custom-configuration.yaml | 19 + .../templates/_helpers.tpl | 62 +++ .../templates/enterprisesearch.yaml | 62 +++ .../templates/extra-objects.yaml | 5 + .../charts/eck-enterprise-search/values.yaml | 126 ++++++ .../charts/eck-fleet-server/.helmignore | 24 + .../charts/eck-fleet-server/Chart.yaml | 11 + .../eck-stack/charts/eck-fleet-server/LICENSE | 93 ++++ .../examples/fleet-server.yaml | 17 + .../eck-fleet-server/templates/NOTES.txt | 6 + .../eck-fleet-server/templates/_helpers.tpl | 51 +++ .../templates/cluster-role-binding.yaml | 33 ++ .../templates/cluster-role.yaml | 22 + .../templates/extra-objects.yaml | 5 + .../templates/fleet-server.yaml | 64 +++ .../templates/service-account.yaml | 22 + .../charts/eck-fleet-server/values.yaml | 187 ++++++++ .../eck-stack/charts/eck-kibana/.helmignore | 24 + .../eck-stack/charts/eck-kibana/Chart.yaml | 10 + .../eck-stack/charts/eck-kibana/LICENSE | 93 ++++ .../examples/http-configuration.yaml | 36 ++ .../examples/ingress/kibana-aks.yaml | 28 ++ .../examples/ingress/kibana-eks.yaml | 48 ++ .../examples/ingress/kibana-gke.yaml | 31 ++ .../charts/eck-kibana/templates/NOTES.txt | 6 + .../charts/eck-kibana/templates/_helpers.tpl | 51 +++ .../eck-kibana/templates/extra-objects.yaml | 5 + .../charts/eck-kibana/templates/ingress.yaml | 48 ++ .../charts/eck-kibana/templates/kibana.yaml | 66 +++ .../eck-stack/charts/eck-kibana/values.yaml | 212 +++++++++ .../eck-stack/charts/eck-logstash/.helmignore | 24 + .../eck-stack/charts/eck-logstash/Chart.yaml | 10 + .../eck-stack/charts/eck-logstash/LICENSE | 93 ++++ .../eck-logstash/examples/basic-eck.yaml | 44 ++ .../charts/eck-logstash/examples/es-role.yaml | 25 ++ .../eck-logstash/examples/monitored.yaml | 49 +++ .../charts/eck-logstash/examples/multi.yaml | 78 ++++ .../charts/eck-logstash/examples/volumes.yaml | 107 +++++ .../charts/eck-logstash/templates/NOTES.txt | 6 + .../eck-logstash/templates/_helpers.tpl | 51 +++ .../eck-logstash/templates/extra-objects.yaml | 5 + .../eck-logstash/templates/logstash.yaml | 58 +++ .../eck-stack/charts/eck-logstash/values.yaml | 133 ++++++ .../charts/eck-package-registry/.helmignore | 24 + .../charts/eck-package-registry/Chart.yaml | 9 + .../charts/eck-package-registry/LICENSE | 93 ++++ .../eck-package-registry/templates/NOTES.txt | 6 + .../templates/_helpers.tpl | 51 +++ .../eck-package-registry/templates/epr.yaml | 35 ++ .../templates/extra-objects.yaml | 5 + .../charts/eck-package-registry/values.yaml | 75 ++++ .../examples/agent/fleet-agents.yaml | 122 ++++++ .../eck-stack/examples/apm-server/basic.yaml | 52 +++ .../jaeger-with-http-configuration.yaml | 60 +++ .../eck-stack/examples/autoops/basic.yaml | 30 ++ .../examples/beats/metricbeat_hosts.yaml | 225 ++++++++++ .../examples/custom-elasticsearch-kibana.yaml | 78 ++++ .../examples/elasticsearch/hot-warm-cold.yaml | 199 +++++++++ .../ingress/elasticsearch-ingress-gke.yaml | 40 ++ .../examples/enterprise-search/basic.yaml | 42 ++ .../with-custom-configuration.yaml | 52 +++ .../examples/kibana/http-configuration.yaml | 24 + .../examples/kibana/ingress/kibana-gke.yaml | 80 ++++ .../examples/logstash/basic-eck.yaml | 113 +++++ .../examples/package-registry/basic-eck.yaml | 95 ++++ .../charts/eck-stack/lint-values.yaml | 3 + .../charts/eck-stack/templates/NOTES.txt | 10 + .../charts/eck-stack/templates/_helpers.tpl | 48 ++ .../eck-stack/templates/extra-objects.yaml | 4 + .../charts/eck-stack/values.yaml | 76 ++++ packs/elastic-stack-0.19.1/logo.png | Bin 0 -> 5810 bytes packs/elastic-stack-0.19.1/pack.json | 36 ++ packs/elastic-stack-0.19.1/presets.yaml | 260 +++++++++++ packs/elastic-stack-0.19.1/values.yaml | 96 ++++ 143 files changed, 8090 insertions(+) create mode 100644 packs/elastic-stack-0.19.1/README.md create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack-0.19.1.tgz create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/.helmignore create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/Chart.lock create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/Chart.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/README.md create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/.helmignore create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/Chart.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/LICENSE create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/examples/fleet-agents.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/examples/system-integration.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/NOTES.txt create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/_helpers.tpl create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/cluster-role-binding.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/cluster-role.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/elastic-agent.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/extra-objects.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/service-account.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/values.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/.helmignore create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/Chart.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/LICENSE create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/examples/jaeger-with-http-configuration.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/NOTES.txt create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/_helpers.tpl create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/apmserver.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/extra-objects.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/values.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/.helmignore create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/Chart.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/LICENSE create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/examples/basic.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/NOTES.txt create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/_helpers.tpl create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/autoopsagentpolicy.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/extra-objects.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/values.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/.helmignore create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/Chart.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/LICENSE create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/auditbeat_hosts.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/filebeat_no_autodiscover.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/heartbeat_es_kb_health.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/metricbeat_hosts.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/packetbeat_dns_http.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/NOTES.txt create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/_helpers.tpl create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/beats.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/cluster-role-binding.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/cluster-role.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/extra-objects.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/service-account.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/values.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/.helmignore create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/Chart.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/LICENSE create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/hot-warm-cold.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-aks.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-eks-alb.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-eks-nlb.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-gke.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/NOTES.txt create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/_helpers.tpl create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/elasticsearch.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/extra-objects.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/ingress.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/values.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/.helmignore create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/Chart.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/examples/with-custom-configuration.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/templates/_helpers.tpl create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/templates/enterprisesearch.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/templates/extra-objects.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/values.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/.helmignore create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/Chart.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/LICENSE create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/examples/fleet-server.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/NOTES.txt create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/_helpers.tpl create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/cluster-role-binding.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/cluster-role.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/extra-objects.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/fleet-server.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/service-account.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/values.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/.helmignore create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/Chart.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/LICENSE create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/http-configuration.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/ingress/kibana-aks.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/ingress/kibana-eks.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/ingress/kibana-gke.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/NOTES.txt create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/_helpers.tpl create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/extra-objects.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/ingress.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/kibana.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/values.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/.helmignore create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/Chart.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/LICENSE create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/basic-eck.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/es-role.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/monitored.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/multi.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/volumes.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/NOTES.txt create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/_helpers.tpl create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/extra-objects.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/logstash.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/values.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/.helmignore create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/Chart.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/LICENSE create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/NOTES.txt create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/_helpers.tpl create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/epr.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/extra-objects.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/values.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/examples/agent/fleet-agents.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/examples/apm-server/basic.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/examples/apm-server/jaeger-with-http-configuration.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/examples/autoops/basic.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/examples/beats/metricbeat_hosts.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/examples/custom-elasticsearch-kibana.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/examples/elasticsearch/hot-warm-cold.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/examples/elasticsearch/ingress/elasticsearch-ingress-gke.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/examples/enterprise-search/basic.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/examples/enterprise-search/with-custom-configuration.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/examples/kibana/http-configuration.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/examples/kibana/ingress/kibana-gke.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/examples/logstash/basic-eck.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/examples/package-registry/basic-eck.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/lint-values.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/templates/NOTES.txt create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/templates/_helpers.tpl create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/templates/extra-objects.yaml create mode 100644 packs/elastic-stack-0.19.1/charts/eck-stack/values.yaml create mode 100644 packs/elastic-stack-0.19.1/logo.png create mode 100644 packs/elastic-stack-0.19.1/pack.json create mode 100644 packs/elastic-stack-0.19.1/presets.yaml create mode 100644 packs/elastic-stack-0.19.1/values.yaml diff --git a/packs/elastic-stack-0.19.1/README.md b/packs/elastic-stack-0.19.1/README.md new file mode 100644 index 00000000..620c3cd7 --- /dev/null +++ b/packs/elastic-stack-0.19.1/README.md @@ -0,0 +1,132 @@ +# Elastic Cloud on Kubernetes (ECK) + +Elastic Cloud on Kubernetes automates the deployment, provisioning, management, and orchestration of Elasticsearch, Kibana, APM Server, Enterprise Search, Beats, Elastic Agent, Elastic Maps Server, and Logstash on Kubernetes based on the operator pattern. + +Current features: + +* Elasticsearch, Kibana, APM Server, Enterprise Search, and Beats deployments +* TLS Certificates management +* Safe Elasticsearch cluster configuration & topology changes +* Persistent volumes usage +* Custom node configuration and attributes +* Secure settings keystore updates + +Supported versions: + +* Kubernetes 1.25-1.29 +* Elasticsearch, Kibana, APM Server: 6.8+, 7.1+, 8+, 9+ +* Enterprise Search: 7.7+, 8+ +* Beats: 7.0+, 8+, 9+ +* Elastic Agent: 7.10+ (standalone), 7.14+, 8+ (Fleet), 9+ +* Elastic Maps Server: 7.11+, 8+ +* Logstash 8.7+, 9+ + +Check the [Quickstart](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-quickstart.html) to deploy your first cluster with ECK. + +For general questions, please see the Elastic [forums](https://discuss.elastic.co/c/eck). + +# ECK-Stack + +ECK Stack is a Helm chart to assist in the deployment of Elastic Stack components, which are +managed by the [ECK Operator](https://www.elastic.co/guide/en/cloud-on-k8s/current/index.html) + +## Supported Elastic Stack Resources + +The following Elastic Stack resources are currently supported. + +- Elasticsearch +- Kibana +- Elastic Agent +- Fleet Server +- Beats +- Logstash +- APM Server + +Additional resources will be supported in future releases of this Helm Chart. + +## Upgrade + +To upgrade the stack to a newer version, follow these general steps: + +1. Check Compatibility: Ensure your Kubernetes cluster remains within the supported version range (1.25-1.29 for general ECK features). +2. Review CRDs: Verify if the new version of the ECK Operator requires updated Custom Resource Definitions. +3. Helm Upgrade: Run the standard upgrade command: helm upgrade elastic/eck-stack + +## Usage + +The chart currently supports the deployment of the following resources: + +- Elasticsearch & Kibana: Enabled by default for immediate cluster setup. +- Agents & Servers: Optional deployment of Elastic Agent, Fleet Server, Beats, Logstash, and APM Server. +- Security: Features include automated TLS Certificates management and secure settings via keystore updates. +- Persistence: Utilizes Persistent Volumes for data storage across cluster changes. + +## Prerequisites + +- Kubernetes 1.27+ +- Elastic ECK Operator + +## Installing the Chart + +### Installing the ECK Operator + +Before using this chart, the Elastic ECK Operator is required to be installed within the Kubernetes cluster. +Full installation instructions can be found within [our documentation](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-installing-eck.html) + +To install the ECK Operator using Helm. + +```sh +# Add the Elastic Helm Repository +helm repo add elastic https://helm.elastic.co && helm repo update + +# Install the ECK Operator cluster-wide +helm install elastic-operator elastic/eck-operator -n elastic-system --create-namespace +``` + +Additional ECK Operator Helm installation options can be found within [our documentation](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-install-helm.html) + +### Installing the ECK Stack Chart + +The following will install the ECK-Stack chart using the default values, which will deploy an Elasticsearch [Quickstart Cluster](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-deploy-elasticsearch.html), and a Kibana [Quickstart Instance](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-deploy-kibana.html) + +```sh +# Add the Elastic Helm Repository +helm repo add elastic https://helm.elastic.co && helm repo update + +# Install the ECK-Stack helm chart +# This will setup a 'quickstart' Elasticsearch and Kibana resource in the 'elastic-stack' namespace +helm install my-release elastic/eck-stack -n elastic-stack --create-namespace +``` + +More information on the different ways to use the ECK Stack chart to deploy Elastic Stack resources +can be found in [our documentation](https://www.elastic.co/guide/en/cloud-on-k8s/current/index.html). + +## Uninstalling the Chart + +To uninstall/delete the `my-release` deployment from the 'elastic-stack' namespace: + +```console +helm delete my-release -n elastic-stack +``` + +The command removes all the Elastic Stack resources associated with the chart and deletes the release. + +## Configuration + +The following table lists the configurable parameters of the eck-stack chart and their default values. + +| Parameter | Description | Default | +| --------- | ----------- | ------- | +| `eck-elasticsearch.enabled` | If `true`, create an Elasticsearch resource (using the eck-elasticsearch Chart) | `true` | +| `eck-kibana.enabled` | If `true`, create a Kibana resource (using the eck-kibana Chart) | `true` | +| `eck-agent.enabled` | If `true`, create an Elastic Agent resource (using the eck-agent Chart) | `false` | +| `eck-fleet-server.enabled` | If `true`, create a Fleet Server resource (using the eck-fleet-server Chart) | `false` | +| `eck-logstash.enabled` | If `true`, create a Logstash resource (using the eck-logstash Chart) | `false` | +| `eck-apm-server.enabled` | If `true`, create a standalone Elastic APM Server resource (using the eck-apm-server Chart) | `false` | + +## References + +Quickstart Guide: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-quickstart.html +Official Documentation: https://www.elastic.co/guide/en/cloud-on-k8s/current/index.html +Community Support: https://discuss.elastic.co/c/eck + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack-0.19.1.tgz b/packs/elastic-stack-0.19.1/charts/eck-stack-0.19.1.tgz new file mode 100644 index 0000000000000000000000000000000000000000..9051a400378341193cf38c149f7ab5c779daaafc GIT binary patch literal 48953 zcmYhCV~}M*gKewJwr$(4F55P{Y}>YN+h&(-n_YI7aqsju^CsTppA(Vi-^s{48GEfw z6a$S8@}B{u0iiRNQeifglIN83;^8o1(_l7J<*?FG<>6G+(BPEUw6!+2H}g_cb`X&I zWorj={r#T2)80%Kzd!Jfo@u?Gw9+xDvec;z}Aa(8nZLh)gWlkZ#Ni+D>&i%%DmuCc?iL=2PY(CX0f;FUL0@+=jJRagTrNWT>*p`Onl6 z9e2NKD!TP$VJEd1pLU>K(w96p_sY{lJE~d6A1LyZ5>s$6k~`Kl6kFxxVNh5qy6P{w z4D!zPoP1k<pn2z^#Zw#){$e4CXW@UFeznAo3tuG0=ZBW@{^|hi(r^N={7%A!3b2vG~Dwbz&ion-#e}(0!x&sfF2Jk5P&@L_Z#x( zI9X*2! zl36a} zAWKpl9Z};Y?!rSJ9xgmx(FqU}3ix^WadQDcpS*?5OPY5eh5{TZAQIsK5)k0(>8f=G zELpY(cBD|j4;vu~kg4jGqF(R>md9p%=%Zg3dAQIbV?dVxy+8g=J5IfU%1WcMm(fH8 z8zJ>&l9n_P7TRQ&S0aPAPK8qoH>t2A&!MI!^8b%JwUOj7%=T@Qs>D6UF zR9ul5Y%X$Cdu=nJd2vaj0I{i6&@kPKaAUaY;aWei4z)4w8`CX}WnJ?G^`_K-ki1`v zTO-i6`n2R$m(w%vUkrx3EY#s0ikiM6Bv^-j#=FYpc(Rd!@Y z(}Njlepzv3&%Fr6%q=d2fi}cOD$O&mE;D=yZ>nsY41H7<*e(wp&7&-1B}77_tfDMm znNk0_9!i-(2~Xd6MWp|Zw-34We^)L1t|1;QYjqyB&lK( zdzDzyS!~T#LsjmwT*i@wH{b`;V`{7oL5V*Zda>d?lSmrcVUd@Ybcd=((qa#SRsX8kU|K=Lu9w}O}R92k-^*jNrEA|N7k z`v5ZLS08Nkut~TkWQpN%7iXTe|a2$7~~5FCy}Y1 z5~0oyUv53gfQrP@29ca@l3R?Gs);XR*6rF;&MYRJ`+L5`auM0wuioXozs^QWi1IbV zEzG{mhaoPwd|AA@{WW|GhAgNCJFCet5bsp3^_hyHjf$N<1sjiwi3OJ|P0axt+?Cpe z{rb7SzMfcmKYpVms@JPE1 ziIe~J;ep+71^W0ptLOs9B_)ULzweIT-Pz`th)$Ky&jy_Om% z7dp8Se>^s_aK?Vvuzd6gYCLvypQmhjnX~ZngbH08^=2wuK&`;}Or(l8gRikHctCz& z4Any(aGe)GC|sn{hSALjJyO3Z7EgyisjL?26m4k4reV@<1ixJpwtC1&XG4eb2-D~* zm5BviN@oHM7HB&gF3PlHFsn#rCh?t~H%dz!@1$(IR5;P%4E0oQ4iAJ^Q z>srgU`&_I%n}6T`e%YG3+kWz-)#KU!@qB#OL9~=Cv5wT82x$Y!OUL9Or8j3qSyB0V zNBZTlSd&&px9cC=2Gq`S-}9_iH<{~P)f&pohACDp^AuTXJBGcO60YMKyF07?`VQru zRHZ=k0WOO6#q7;ypy<+Tm0O`-S+3BqC%GgulCs=^?bfLIELTctZl{YRrj8^(WRzP< zZKYnG%JAmW*WiJ)u~e{F*{yZac*lgVRzd4VX>~-=a4|FB)F~|O^sYbym-GgFw@wE3 zvRL}Ux+CC%XKY;ncfVeV}vtr#mT26!;=0KU5G#3^-5?V-59~jy8QVN!9%6`F_^1a z41A#$X=rhc(t_l{kfx@>FJmWDMi$^3;LeCmF+#%OIK8ttqb|||UyPj+{4z`-5=+_l zA_6!V&RF<83w^5U{rYY$go$U0!LMf(ZzPJk;@?Q1d}G~6I1%}t<<5in1oCZ&28`!6 zixgtb=f@CF@u=#tMp}wE8d9BI6A8Ogn4~BAD@ChGhob+elrA3FZ}58yJ~pfecFY$D ze!hFPO5OIwBU}NW9JL1i?cRL%s{pEb1Fuso@cDUv*7739n}fV?>F`EmwN4vNKhREM z96f!t8yVB~32g~h8pMU?+%cE77DVf{@_`R3#{q%fW0tKF;*D+5vs=VcnFU=RP#o~P zQ*e3h>}H$Mt?J3C7=jrX*0j>;M{5cZVPp+EjNpZxjtruwI&EYPdz%oY{SwHco=^Q4Y_t9^9ojRQO~TZeBI1FEQFAE zTK4dVZwDE+2o`qnB$yH@xM^roTCR_>&s=ErFCueQr-x+2xa z&E#`jCgHvgbL>B^?n}FJ{TQGumGmQ@dZGEy>mpYfvF$SX9`G11DJ-pl^LNt$w=8l^68u(*tHO;W!|;wHxU`UntUeb{1$tjaWw4M27j; z*UFh_CODthvZ5;i3!GRG>-iiUV`LBH6h=RbUB)<@yz@-svBXdrbDvFDHRf=4l?_Z~ zm63f#9Bkd6UoK-&#wx?a<;# zvKm|Lq@h)h(0;6=Y3iDOu$n8IS~G3kvD!ydGPI20Ia|Nrp)^;^5Rj&;f0s_y)XY9R zs<-IGL0(~K&?9NC>v|CCsap&uHy9MKf$8aMF6TL_+vQ^vT`~DAKlge+6DNehR!cfzK4&OUiuT% zcAveJYRPBz!%cM}nk-fBkId4o*ca<~zcJYbzP zbBN}VA55tfr_fw3d0Cpoic{5hvid`&$j}HjBamEJtJu&&Z7xO{y+wR~ipLN;wb)d2 zsQ)DNN&V1o_CnU_o%(XF*x_&LnUJ|gq~Lvizd7{%tNvXeXD%=oKH(A&P*Jix2QZ~l z#17x?)CznD(9Ls}(&o#4dW62TJK6uFHihA#+6vw2&ca~;pLsUbFmsMYJd6;m2^%gK zxjeQKF8!fyW|BP!!}YB=t}XpBOe*UTUscyIU-Gmp4#Tqk`6da_Q_D~e-Iysd1#yO%?)nMPfXiXE?v z%^(*O>xJ&I&nd{0zU)bjc`BG}G=&*N5tHmoG!gYS!TI%=vK5H2J;ytB3^Xw@Pac?Q zggeZfrPs701G&ByJ`E}6ATHIyJ=k@&56i}#<=BHM$->w~a0ad7?qzJ}+a z$~sJ+$@1}WRx!Uq^R*I}`mh`_ZE4HPu13O@oTbmYO;Rtb(`HJilI6X|RO&>a|(qH8-_X~Ro=b5z^Q-N~ zlj3+v7ozib>ROkcqp(s)5*xesROZ3G+j48Q4eW7g0)WHe?r(y+ zrU1ts7aD>50=HiS?vJjYKzktY`34APNUu?)(`Q9{hB7DntGQoQ`)t7wH30H>qevHHtLrSi*!{ z{|3US_t*)pKNU=~W8G)z^WN`3Bsp^X zoewPX(~(@&7h95#Ur5L%92HH1TfAu8VOB)8)8KMzO?Av0I&?p#$sE5m9&z*@DMYuH zed4M?Pt`EbV$G9hI(vS}2`puY`q8LcZd8dFmeD?yW!&fGV*-#S;{E&%D**k0+qZns z!Ovd-+_?CN)}I5yXTYA4vs<5mZq`jR&oc2S#%a>*)cBAw*WuIywHK;IW%lj|^QLZB zk5Q%pJ_P@+z7Lu+jjL1t%z}hAswi0G<502{VRx8wy6ery{VBuM0n5T|EQPDui4emnJ#u$)R$K3 z5az2Y8Cl7wtt#BO)o-d}i86D|Kud>q0oMs-#}HsFBI%vGz?q7r5)v4AinR@-Y(j&3 zPd}`EM8s!il%qFYY!tx_v_oC8S2NOzo`zZx{l4_xufvNf#){6izXK1kAewNe9?T10iUre|Ht&x7S;3 zSbO@~av6uqvta1Zn46G9)5MfsEQI0LcS#$gw!ZMD#4xJx7CM>{Dj7VQ!4P)d(3Vhl zQpvNf^7Dpcvc4K&xoStHE)@jyqal~W6Zs&?`%>m6hEi^JR*IoUvp?GlOm!+;pnS=K zL#p3QBb-d(nCCEY!|H4=dSh)wMJV|mVm8q2EABY6_lLQsf=N1sNi5=Ys&};-4-uNT z9Bp6nm9h?puFlz1c=MWKUK*N(XjNO5N|vC^@N&s>df7;|SJx#&(Pr?{z7%LgdRtkU zXVg*>*WJY>6yF@ofG>viB!>6VpxuKG7AKQiHS%FDK;Esj!tA+rYi+~MDoaTxlW+O? z5hD`#XfcO64>USTV|Q8R1s7QR?i@q4uhUSfpo?TAqNC}|UVtTdRdY-5O(YK))L#~N zHx$3^@yKK1;?f?n%bMaT_fDyyXh(Hgjd6~}! zhm(l_OMh2Mz^l*6ov4SK1)xXh?_K=c-Dl)J;s`9(=8|)ragRoUlaX8VjIpbn3X+Jt z-QraKi}Oqsvla0r-Y`t|0lEdtVWc@UnO0!Em`|jCAvg9b@z0u3Z=t8bSK06sBDt>m z#pc%5%@D})Wf$IQDQAh!m2s~T#RIjK3L1RZsLOHWMc>%)MQYyIcx%ICIjxZ26X)p4 zGf&$4V`S|w$2HkWMSj*13~k5h>kfN;p5K?f?xCO-jHWAa!w>-EW_B23#?WAZLO&5g zJmD*CY*CnQ?GYCA=J9jUIHO$4qe(2J^7BtZk=a^$GjxIuEVgdV-Cl8EO>HG0ck&+h zuQ+xK`#agwz~SVi@-85N8{ho}$mgYT8DRI3(GG^3^Tf0Oxq^v7%<4)B=Cw#;VOZqs zPF1hhfwcddZ=J1gyhbbkyDK7Jp~9M%{!@`nTGZA*4U1gni`JWmuIY~OUo4utVEa~R}^_hPNP=wn|?C{JsmovbEmp{OU(2xFJD7ZcYqk` z{JZvmJtwax+VCd`DuA+e(C9m)cR;ElODN@mpbaNal6kjMyE8Kzb*UcWwy<}FIjV2+ z9&W*CuH+$mG`FSH<=K8ynq669H9sTu19v@viY-|>f^F2Wr*_;u0v`S}Z~?p^*^ zdXwfwPmwCO$+pWVj2RYT`*@>G zX4p2&3?tq-ur#OtyGqh$@oF+wS(;a~(DBuJ5%52hXaTx|k5t%xD1e_wu|!>+gX7?yCyCfPt8bV;}+W?hS}_3RHI$^2iT&%qMFZ`j;6u zf`EVLo%6B!38tQ5osNW?v1KPsl=mvpkV(M^)@Gy}n4fX3icwy@dm-ME6$q9VsxOq zQrN8a^@%(t3O}{s#Cw)CAajEN=sB4}g-ARBph#!G}UV;Pzz8 zJD>wmusOuXQ1w{T{m^D@w9di%&Iv4Tfy>t|)|Wk5g6X@9Dc!;4aGRjq_bP(Meb1kc zt3TlSFyTl2mNS=eOy7h3QMrX2z%#vxET{`3C3Q^5NZ9}I0{c1lqCtb6?z-{VvE$eg z&un)sx!O+7p1iofb;x~QF$Pf3oRz4RX#-3g$?$*&?GgqG;UL(Y2@NkRV*#DG=Hu=Q zx)XKVx8{P*+7bCnvccvlnFZ4P^SYJe&~JG1>Y&1F+pX-LDo|g2d-VbIB|pZR-UKwM?gT%X5j-76(yS zV|`#Ns_)8gOS2lf146&hnvL>vGjRq`qPobVeD0{@RXAhJ2TBwzHOvN<@xxd?;4bOZ zD+HY4eybac((ax_lsURgz#S_~FK}*8H`~6|$avX^=oead#vB%+Hhv@&4rF72a@o=s zBKI<#W~TJp8Me(xjKpz_2#+*|KI%-=KZCEbUbq-GH29IIB>Xf_?PN_z%r(OM8A)ln zk|~w1qj_j$bDC$cS2q~8bp&Mx%|8O0g~i&;k+$@pFF?FKo)C|}8dM+@QN{dq?s-re zuVJy+Ads<9UQK!T4f!?G&@s2Pb+b+dZUyFEE=D3Hp$mPoh@i5~TRDUO-6E$%lGbW? zKu^YRy}Qj3b=zk9d#6bt(V`u{F{3sKHs9|j$z(mX1x_WNW~S;YsIkmL$&q~I*3T;* zOqfZM?qvH!;-+#4=5T=`E<_aEZD-GVdO{}EsR5-aC_imNH*nW>>{**X*`|i-OAQ})`~IWS#heZU&$Kjd@Bo>q zz3}p^AAfCX^J6ruf-p*G-!Pv0Ki~cltC+JhETMkE01rS{L^W$Uawr%L<1W+L{Jwv^ zO0FqMJ&s~E%s#(>5O99opHObZDO%IeqI857f7{(#@>QNzDyzmNaJ zQ-+67zyIgaZh)V`E`hs`gN6R2M_tIR1ia0x>~2!ftN3hNb|LKHpH9K=L|rU_=_a4H zd3PHjiMzSImHrEy`*Qks*}HInui`X7=>MZ}raNE6Mq^+AKXxqc3sFTL@JxZQ2iSn* z-LrN;bk)Dev!I(|8Utpa>v^x9lZ)7+o80i2exm4g)fir!2GDxvO~%!WybrNxz_xj?8=hFomfT| z1l_z+M!u{QYq^;r+7vpwvr5Y$>?$iH`(_AwPy_TO+;R{V%R-Y$%&&z@9wrGTU-)F` z(#(ZVtVg4!+)OO=QdEtE3RUyrZPJpNIf9WP?RNs4-`Q#{SbzA34K$C&>Z2#SbU zP&T7(6!NvnDu`fYEjjzM-p^It(pTLU@ka^hv-XjH^cK6eb+3G&8XWmF!EuDOGjy6n zr^X|($UJwyV(+De!WKb9O%FR>iAVS8)|R0HzLv4!<>*$D1GyL{Hl}we@MRA!;twUK z_WNY&`5l!GBxoj|tA1FAPwxI*iUwfc`TXE4sAv5{yPm_YO$DgIQm89oQzL3*bf>7E zGfRJeYqT1@{x6}j$wSkzUFB|1`Beu+cXRe`r~`JB&-9-9Igo13y7H#%(R)`Xg!d8< za(K|`4)kH?<-dLj=kwV8n|$yKiT%vVbC`w zeVSj1`80yaSpz;;%>sNpS^06?t^%--<}UW@M0_}4QAte{eq1=&cJxY!H*L>NsuYan zexKYUf#KFXxl0y06qBK)iCqCxpBoTAwV+AG1CnJ}<&y_b-tJvp*+)w$2WHQr&w>WY;6ExS?)PZR>X1jgb)w#D*KfEb6s^ zujO#HhQN};i$i6<@0x(_=Yf#_@gUeVio7QVGgoFqsHq)dSUwsmga+U%VwoCK$%AU% zsG(mHH(dw6S!~s9D%!)NQc-MQ7m#FoQUn&xMAX2F`zUDeZK_QUNOh7*1b@Q|K)=jH zMV*Qx;TItl8!;_B=-*%>>o2p5&j6aoRnj>V9k;et{ZugKV5q7I2N$aEyP?i;ne|Q6 z^-&PdYLEo|TU#ZSR?g=4qLxA+olIBggkBF^{NQv;0*2trcCJYMoKHU_2jHGyn9QJb zRy_Q^ln9{31P`>zWkbUR232$BIZdpeAnla<+%9MX1d3k?yl+n1^qR;3ew9Lwy_Sk6?2@c|DuSgUw~AV|LJk>ZthAf$j`)NDW9UHanV`_ zh%7A{b5rQ1V2u^KXH?2TzonMKwAq6hA6=^$=nrC5JxR)M*dUe(zJS!ky;vyRqCA6VQas-$Kond)OoQ_VPw zGh}CGGTc-!-D9!^u-t0bR0F|qRtE|A{T~>64qRje~@!5Q~V%({xO6~gGr7uEj5ht zqr@s{bZmH@af}alP{X{92fn5ljeFuTPFmDO9@BaK$K1RQ$epg&#Zsq+N>yJ=XWz@h zvCp}i{YObJ)}cRz-K+ZfDEcqCbTn8-_~xzWXcY7CqO7mP-6koL=rBRmoe(63h{-G5 zzROcLCQBX**NWI@y1lw?<5`M3MxSAS=acjZqIiQg>ff4cBR}3IchNIfvc0f%RXe+; zTFY>XvoOiGU|bZLa7nb}n%GA*@IV-i8Yli#$2gwjIi$S&`<+c>et7xiYHeYLIku`d z6tPnZNA6+q`w4|R4D|X{Wx;c5cxXg#sUJ6EE3&4{16oT=C<1ZAL=f`9x2d5b2CB7e zJby*IxodgQbB-y`l+iq0(>%_!p&$GH{jwmtUlcW`93soXI%Dr8mrZ$34wQSak@PGN z*Kbz=DUon27O2(dqKUV`)6BNARv-*vJ@#$2EEgLJHP?ycqe!3RIn>Cs`d-k*-!U+% z%+jj|0a`jV!9VlEMM0Y?pso_SO<2-_%t# zkqPD@Q%ru0p%B$RwBS?yhZNyu;XhVNLQ&x>@10NPkGtK$E1!zAR^7zHb?t6&l-iuO zdl7kZGa0sIYU#M7Qgc<}nOREW^dzqg_c_Ia8*s78pi|N8bqb1l1n_p%zKAWpRH--b5obQn!+-PhgsLm_UUAVO z*eZ>JW@j+W6}MT{&iWfQ3k|cJ%l50vg%7f)U^N9w`Zs#C&tVco`MIP7V3I(&qW!1U>_ zn?3c{pC2RI@AC;!=_T)N_rCriS4K9|_oBH5fm;v{P@t_tidzZED*A2+5%3teo#&j_ zkXCHxIyEKfFlQIa$!(=j1!726@g3BW+A+Cwq^DJ#szD}2Sy`%CI`&)c znpI1;O;kj=$~)Hon?dQrPo8W|NEAe5jprH%^nA1-dNkBg{sv<;!o1ONsfP}3zvyig zd_3bt4KhAip$TGzfwM5dqd}Bvpb+vgtgzdsz^w(JH(HS zoajpU2AxhIcy6<}ep3M^9fIlzB#Ja&x9BQKf=$|7;sHV?Q2qj;@lQ#V!kClo+)m$@ z;(jmk=}A35Z?UtLENYpTRlQbQ{Mn1!1JRrcszM{NbfuH72-+{^4Y+D^(*wi19Fwp$ zPbVZlv7|mR&p(_D1*^${hoCv@Q64U=G^OGrk8^i6+n7B*2)le7G_iN{y6MS8mgdKE zby?W1!m98~#k>VmpLkRSmf@kRj5a$2=`wVjJhHBd9Z5ph4eWwR-cb4=<71(=@48!#)DxK0L^}}*O>fk>A@NjXa@K3pbvASx+wS}!qcK5n><&!8tQ8$~9 zjm+nt8`+Geb*}QoKJ~CQpFbgLA5ha`d~viP9Nd(40?Rol$3i&8`IpGAVBXc5HB0^@ zUiOx@uF#zlxqofSY4O3?#Tvn5$gzB2wpQ=iM0h$CGU>;e_Oo%&G`NKb z_k&2FQX&q9zv zLIVGvspq6%^wHSi+8e!aHcyghTq<1#P1Y^cUIShrzh%9O+>71KQOT}&W7^&X)HVhF zF?o6Uhg4p__>+lFZfs-!Ax<-*{DT8G%0jT<%r5V+btH?o=V*74G?Muskg_C;%bO-C&$3JKnL`@$6 z*Q;GJaA&bRQAFZ{F;=6f%WTh%>6ww~Sdfi$W1ur7vHGXwdkosiH^#hf1Y3=m9MT&8 z`{m23hg0u}xXb|mPh|!xSN$TmszxhGi$8x5qNaIfPtczM`k_EZ@3v;wvhDe%7a=;f zc|4Uijaa+VekG=-|-bI+77oCuWHxG*UX&9qlz zXMdntGs4L?Rp~YZhhkcvw=YSAxJvETMW4e%>uxq0CGVf&&HwSIr5(JLi2)wqz6>De zFTKlYS%R3u0amjx04X8<@*w~zVmuGHu0Y7)b-+4SpLlxMk*#Hn4GF;X`s3vYw8myf z%#s%lLUO!a3wch1u5O|>Qtn{Hm`>^!El`qZ5xc>Scm2VeW3Sk?a^o`%r}2j^W@1G^ zJhtS{w!6@u_C6r3_ZZ0MdHL1%yzylnx$GOy5E2pc;l9?tI`|>b_zn3<@$f6} zGIfj`%`6sVpnXi~E=*F_lKJfF>%r9O_mWTcYCY$5R+7c(k|+|6BodL1_tRjp^c!^7 z>&t9Oa$dmMwbbI9kNymPOu+=Ix~!-`M&s*58H+S65nWiu>12+K2aRsbYyZa|pRtM@ z+WX}8Ri*c@O42!}^uh?76azznW+r_7mpILMItY0ddF2L^u-Wp;)qC9BnqCcci7v)a zf~Y-e?>r{8f>t^B0i2hZS45fnnV1{bo4byqZu_jOxwp4SXbCQoY903s?3!cLZ z)Ipd`28Bh<+kI4A*{4aytg&D#2iHxTXPS=cKLF3JavvtQZJT?4E^A-u6}Jvx5E~Mpz_t{PZaM@L=eoKB`FZj`)mt;Q9&^8!geGs`nJQ8 z>(zxvgehH=Op`v_jcn30rd#EszK|~t-*KPnuFKd9bweNs#i~A+gYbmM*4(er+BG5p z*6SE=K!;g(d!)5#uZNqH(Z$15-J|z@$x^BM`_zfs@wWPmz5}E@%Kh57Qva;ynpOSb z-`!<&?Zy$qkPoVpC41KntswdNmY1wE!8MD5znVSbe_Uu>8hF3aoYR81@2ak9u`)IF z-(j6I{7pJ6rB~HQvB27pbWqg@bZ=Yo?BXd2d2R}dR@|}D>OP7War%F}lX0thpQvtq ze79inmjxeg%M4}g<=z}@+5?d=W90T>c0K_C%=qxQpTOf|d*DFKc+Y+lZIXkatwNxX zzZk0~|8dWU-+M;+fY0rVZ5se#7{2K=lj{!%-d#Za)mcEv;z6q}u*VaZ%0&He!yV#; z(c9YJKIhi^)*owU7t4kKPwMiPtSN|7yIBARpwBwp5 z^fq0jq7e0N<=9v#Eu_f|*nHzhgx1muRb!#DiZ-XoId?2(&mkaIP=QB==Yfo*`TSo| zH4z@kMWOsD006iKb z0P#G;CH`)SxdOY?? z)eQfnW{ckt8-W=1^a*ZeLg06u%OY>0ClKc6wU!^OBLDim;;z&%$G{{oZ!~lz z1`?d{L!$#)&Y^44(B_}_X%4awX$=G12fh!0O2?x$|F&igW{<$Zstj6wpfy@DW$V~8 zf<9`pZ^~*XwB#qVltAoK$~EamR#!32g-z5q&9 z4f!mb$S&~HmX`uw9tR0r!zGB3SfU$OeWEY`@BAUI1|i&S*1CmzFPt|--At0lSnT(~ z*tN{-Po=vb^hF)5aM=>lMVqP1Gryld4hfCDv?TqEy@Yu>naY(gk1vVpiw0XLo-m&P z92F|ba+ z=usjWG0BUxl3lIvRP2JF*~e1L`}>x>r9rOCHt1A7@UxCxt1UIP!BpGxXB%cd7U`Oi zQIq7*-ARsZt5)W(ctqJqAqpc;r<<`lYg=dtjNK-qK`M%qrfq!D!Od5U3Nsi)P$rt7 zaM?q6pKFP&X-`)mR;k|==Qe}Qt8L&d0{MIyTxVmKYsS-6kDC@K&N=SWJEGUm!*0Xr zjhX8>HUcIK&?z8O(Q3j5S2BGkcu+|7yK#QD6mEg}_?#1fFj$}1Y?FmmN>gVS(M_pD z2wtU`AWx`aR%hfEQS(5`)aCRQw8-bBYh+mM*Q-MD|k7{G>BT&B^6q+~A8vB9~eLD|V?B?hA1L#707GVu&I zEitT^d?e|o&{61A-fGArR?!RVmt77u6UX6JL9P!&YOeyb5obqf!D-(QKib#M3XxFy zf8!7xvB;Hfc9w@g9(3Ahjyt3cPg~5bPFC7h4?Y849P36+C(=>;#t~g zm6(j9z+oEmQiPSCL^E5dyqg-iyWdfId$%3QO`f77o{egce(5Z*f%$JHTVKLZ@u3@} zlivBmIz^QTo3pg&JVOdbrOjv)T^R>r5CBNV`257pR@O>&%cgjWri4&XufWb0Ugnx` zRyPL;<6dj9fmUKL2TtS$AG~^8uOfB7T*>8~W$g^=r6Z*#gYNeW_%yKbRW1exj{#-qWc}+Zba3#8g6;u&I&1~qMdiE$rN~6sr`8W%8 z%8#c#4t4LDtfIZlwoFptvXy`g(O(%K072Jaiq$6S>DRtzHSL}S8(}|8^x)3;!A+I9 zRa@nEG>zh|9@f_H?089)=3la)=;tfCnzmKC!0PgGSf3BaUUOg*#U)-$25p*NHzJ{oR8IT$8$k|D- z63W^0Ks>s+XksK+ACBE(og%TvQ4WgUnt?mKMMSVMhq)@K9fPd~tdDCrc5n>d)r#Av zzA(G9lXeS{4tC42XC3QD1@_O-dlMxPuSTrO*D!Hqt1Xp!=wM}*FZ$)og+0Plzs7ZT z)m1gcT45&q6B}!il|Ul4LaU?bf9XP{RsvUX(Pz`bc5P)gaxpYwx&ca6s1wCczhs!W zx?6ropiEaHQ2Ni8WZo$G4ry|CStTTo9rIGP zT?j}NrvOPs0NfvS5d}1KSv0`EEP;(3v3R9TC#ZtcPl#=^Xz>tpb22~TL11p@TfIZS ze8^)A>^aA#)s~LQT~E`cW5PYQ9LW~T>Cy1XHI5kY{9f8K;vp*WC-F3#VWCpjobI1e z@xwqQOj$groR6WWzL~UQm5@vzN*O$PAm;zqI)sf7WrZP1fJ_)ZULIFOBudCXxIlTJ zcO17wCzj8m^c-ZR#o@ACKTtiBlwi4o6=u{T`782)y?iOXDW{f<>!|S>Z|-Fr)Esm` zHLRMOC=aenV%fQ{08+7~alX&H*Q{WoY#ieD#2Cq`rjpQgz&JkJ(1?F@2`&y9{Z~Xv z;eN>6KI}k3iprU}zWQC=MD&|2`tQ)xxcT8n8S&ETOY*khJ>K0|pp-*@hSyPVvxX;>QmHdnI_%2(vf=B2m@ z2-@~YT(=k5Z_|C8~Nb=T~aX(IUHk9=j#$wq#^OnZ(}=0)C^yi~3EX8xFUKX1~6 ze**FOB)TTgTsLPXj&};DT8r&|xOKld-i*gMFU2%dvt@H{4voxIjl|?&T$J7WvJDaRekil^)J^|SIrm4LI;9OK zv{qC8Zs7;*zbdep7bhHJ42;vW;QuY`PRaZ8Ab?>}lI?IR9e$)5EM^;GFH?1%y7Ki2 zv-_eV0LyTO%AW(u{8Vp8K-L<7hen=TT0qH=|L)?!3^Rk!f!_}-l^}3+ta=^T0`<+( zl_VuH$b)XI(7}Bs4gy1zf8d99T5eN7H9487MG1L2&Dw%6r+w8SRoj=`^LpNd7|r8r zSxY<>%3OjGz&8cUB1#a=0ICho0%PeKTJ-8%h7QeC8)d9apXNnqvQ!p>>kmiR%r`L( zjilZVjwQE2uD&qSaR}KX@k$KdyDCJ>*Mqieo<|WlEiW=xgi@&>83; z!IF@;(=Sks4<*xVO3Ebc8zbl$d2+nPJN9S2)P+=|N!J@0jiy0705KQ zqyB3kXM27f#F!u(qf$>`ac~=Y!u!LwMVvL{_wxWBo_lmHz6wm@CC90bfkia$(=QMl z&X7LmSVagFCeT49wiSnTjw){ZICIwHpQ?#xj*{HJ_{%rp`@Rn^a7?nWLe=M^+oy#H*7QmWZI*Gdlnr4t zclR#gS#ERBk1a9@@|Ta?-~Ae7R3~sc>oiV_;T$0e5FP*B^%Iy_c_c*f09(_I`sBc5 zzDq}dt~iyN>hOdHUe3arM2j}J#d`94YzOA00oRiFlsW<{B)^OM4cFi^fn41uw0ga) zir5w&44(c1Doh}4v{>j4I?gbXkaarX=JRpONF$~!YF}WDXqL(+s3hfw19iX_AEtVT zW~vN_M1o{U(5s4xAlak*JI#iu!_AC_-}^s8vQXW*O7SPEZfrNz=CS&d=J}=#W>AN5 z$XQuv zrRslB&2fqUe^K_9L3IR7xF+sSAh;wD0>Og2y9RepaCbjA!5xA_aCdhP?(XjHa?UK@ zckk}j*510c`>(6coF5}K{dV{B_7J~A=Emw{D#>*KwhD3B(v;G*LPqyI`?|wa) z`QZ8RVIWBMJQT`w$u0}97Gv}@4@44V(US>|P75?P>{DaS9q8BeNbyYKSZ4EgtsmJL z*S94c{Du@^Qe?=0(L@G`{mpzpMQO;6jNQDhx?i?%t7s^sf}%vax7jbLx~9icz^I0n z!eF)#oALma3%rnV*kKAtyO0ol2cL;w`|7J4Ff`?9~c3q z^^(!Jv&v~*w)u@w? z_^MqkdK+1%H5pUsgn;f(I+~WMo{dfR7L$GgElV>Gr@(`-A!j)-J#4`bIlX#njsRK{ z4mqw3ItpgRK^=!jRTb7H5#X2eA>Vt1htsIH6YQ2>Ym26JL`nu7RGW@ti|pe|96MHl z4i^F&R^VlQ2=Dpj;2>1`9S!vW${lm!JPxnU)+6|o2D{X5lWYmpYU7`Uv3;jN&Xx_JM$A!HH6kqK~N zErASKKI^tQj}?sdg?Ig1dCieO>?)FUdAr=5-Bogf)I~_{3a)hr100a~{R(gO;IN60 z&^O@Xd#VUiz8K!7GTcvt`JhlY;=~(lcFN(u>N6h4yRT1 zLj%%})m)wixyscoUT}*;`o-z8FL;v-*%JIhj-h}Ubq``YT6lN5+&?KY+-_A${jlNN zkLeAvr0fz6T?xWyu=Tq@rztIncXe@k$9}^DY@zAv|K{WW&Q-3{#q?t_Tk-3?TsWyj z_Pnt0K-3;I%894f^(Nu)&w-bQAKsNi7H#ke{Tv^vZXFPL$7GFuC1Wm>OJc5Ad?%S9 zfbuXGFwKabtW7;HFW@W>8shU$RgN#3^a|R8*NrArEl%$%H%G(4IxQ544?<0j#rp4P zHbTyrxGW(jTT5hWmXm4Acl{B~K)6mzY1N+P6&4EQD%COw+W7O1h8kOg74; z!&g!n5oV@bH|;Vouv9zFpdJ{}p2m}q1|bcDR^Bl|SDB3v9n!UyOazCH`Vu8bbGQ&gv;gqiZE zsj3;gvs~auxWG~g-B-C)70g3JU6$RMwoqhhztPKunmwXf)gj~@L>oOmM%>=ZhR2>E+hFOhl~f?E-(EL7Q9C%sQ?P&u zj$zQ9kuP!_*vu6xoRyovWcWF)s0&45fa_wQgsjE-p#RC{Ud1ak7JgQc2+g;!!47KZ zJ-|*lg-j&%ue)-%|-G`~ea%z}^op;)(%GRKjZkd*tNJB%?j zl(Yv|j>l4fh3Ou(#iAyQGHHVaN>pt~clYt*u>}LNevoFL5!@;l`N1FB(DN%bJt8(TlRJqFd8BwHtO2`?z^Dysoke zblZmkv1OnZh z^pIR>{2SzG(d2jkCudHD>kn-M#KhzS+D)qHg@;2>lVre(GX%s&zyarw2+BxyB!0FN=+khbZC{`>On4*DShzM&L-y`VK#u(9U&dy$TBb)DLZ7??ZC zI!5f1kUuk}g>g!~eCl70tZc30WKR@b(XT#!JqW8W?8-08D)iZ4Q}(GPom=5gg4mKg zoH#R>b#tD)3cgM}8|=13y>-#z%oW~teSyqQ4=b4gT?s{fpcf~>)hb~1v#^aefc{oA zeRcJe|DX0Y&sz}&V9|CD@}eq6KkW(w*oY!Ac%T3KpOdTX_n!sPA+v!P;1W^L$y7Ga zUD5v{?t(yQxFO_iW{>0T!Vcx0EZHRv}BVjyOg2eP{5Zog6i=<%IiWuGlyIdPIs zwOqRyz`}@|B)Mgld44&shY`GoFVqqY6H$@wLR-=n=5-^U>yK zdklV_D;7?<<{}ahHpU?3_%4a3DOI0Cc>A~L)h@bt3I|4}0p(rj`awG+U97Xi%%)8*sUfk?B#oQr~y^=z9a6=MH< zN_iEFiQTTlEWP4$OWvd8mY&yj0Aj>s(-F787NN(3@b6HH?7xlvP>D7t$*n*r;r2S0Qsa!XWP6~i zA`xS6xeYSM!sht4XlRRLG|+bRSJV9?Z<>RpO{({ly)4wP0)k0Jth|r5TP{Vs-Bdvj z<&yCesjLlX6nSEcPNhtu&D?(u?VFYfsJ@2$yyoJ>540LY0GA zJB2E3RMaW;%IxsJ55o>@CzWcb7Ts`MTkK{0R4AJ%u$jZk{mQu}@&T271?il71-(3E znsS{+vh^_2$YN20M#meKMj0zDjN zFWSd<&enHk-NPwXJn6kqC?oLPIu95>PF_FO;L-Vo9j-+Gd)N%LGOgS--jjy;<m{X|StedIXUgBetC7k)uTpiadP_QL2H54_(s zgu-qGZ5?0R9ECJA{?zq5@NY_w7UNc35Xw)mpnNJrRYK_?PeemUEFCuuJ4Np&LgO(p z%5gK{rYG_-p_2OYb!l&zbro5du8qtwa>A$>BXU|nJ#G_%GIcz1k2L;oO|7*piZl7c zqUJZTg@bLMOu{ZnRGdi%i2)efZ8=yuj)*#B4p+5K>@%&T)?kOkbIq-CzjTQrq6YgC zoEMZam^FEaG6cbmFx!U3tRGdymM=`wF#{{`w<^?9!Lx_z+cA};6|j#lJl!2DlRcf{ z#Z?Ptqqm!@fq-=4a5M3nJ%Q&Ad9@8^u zkm9nOlWT8)14|FX%A148%^NvBeb+IErHd!Yk*18J_^A}E8{X4Dqs4?ohdL`*uzF0b zm8{@uuNgx&Xk9~LXg`7ST+HVD!-6u*52dF9Do&g+1xciYqJ9(6!T8J42SX{w z2bynU$&LQShYEI{F;k*9iflrdD)Anqh5~|~cS!uIcNO1+3$(OU!1UD}y`H7>_Z*{M zcmMu!<CkHgbTDz6*fZRzkt%<20-P zVjYOLZbeOEl(`Ra;3Cjf2hAx@_wJ7qR=K@x?VqekW4&(gt>Z|}DL$o>?5TfnMkQ~- zqi$#(ZW!TbxP~B^%^>%LU%t%9ghq9#6{d5AG=7*lKx*xZ$%@OsWf(>a|Fp8nS=h}@ zqfz~hBkvmt6xpBW6BlZ>-xQh>{`+ld`j=6&!P>^A@y2z9K7v?Q-kA2~D}0#Ub~cor z|F&zVtebHIe6Q+tyq+mSnkt{$ zVU`Hg`a7QNQb*5aZLxw@iAmVwXloJLT1ncnUpk9jolDH1p)QA?X;JZ6@8mgob(R?E z=A2G>%rRhh)M^aZ2R(wC-Q3H|{=29AkE|UzUTdf;8xzfP8l`v2xSi-Cd;F7!PAf$c z!hSdsKU?WHzwVc0vB&t0^bTqj)m~4++8V?b9fJzDhOu)~}q@=)tbaXtD<7 zQ!a4!V@aJJgPXG}+RyO~Gq^754H~ZLjrfb<&ch*1j`LP?zAEG$>cb8ukL~A~AMMr@ zqi7KeZ@s>@OMV<;TK6$nX{%X@oT$1kyR$-@_R5&Oil>)9kcHV9ts>n{CGuXDfsQ2V znS#-E#Wj>m8}y07NF=Jc8emPtLYJ}X$i3q>rq(5wS{nJ;I2!viqo71Pw6Q%|6g3YP z{O%1TPTZm13V4~`IjbyC4y?h3jKFChKOQ$twRQ!*O(UjP8`VdrTUJj{C;!yWKkUEm zZnpN-3(<&-_ST;$JX-9>^M*29C|uf99n=_GUQ;%LmP(uu+w(UiwRE)eaGfjqzZp{h zKmR8~x*b3*CMuW6)PQf8%R4CL)ut9{gN6c4fT4|8$3a{=lHZ67J)~8@UA5;v#3;=n z5&zLs-F=sBgCBk~;Im_r=V#aqM7Pz651Do1QC7`MgqZANoqikA#ZyLz1dm~Q)%jA$ z+E~L$NXa|cKajr3M}TFP?KENNNrb7`k3Kc`vM63I!pX0pIY(p z%xIBmG-LaPyn_(5sNONo*_w8?61m~DPo~s1$QW=)yeqUX46?(RY_e!~_Xj;31pV>z zg)$yr4w|XP>vz+BONVg(dW3STuZxZ*UazaIlefochC+=3Y#ZzXW{jGW-3lhk&7DF5 z25Fk9EcE=jia@*N|Au}m+LO?thdZF&_&jThCC(3a5kEcn8*uNu{@U(9&BKT-wtw4I|tQn;sZ1*PCy%FKll_Z5T@W52g7s?T_z`mjj;^kq#m( z54dOn%x=MU7X1$=_icxVac>lMnnPb+WAgG^!H@RtGuyz$9&!ja53Jwhh_8^%G0FhA zOEhI5sGmhGlHC7lGkG?LS!Y}>K*_3uTULF(qMsi{*5&n8?N=UiMKQjMAirAgqfXXSvfJ(|!Fdp`^j11K6^Dxf$S0%kl(9Rc8 zZYG zKj${kKvI^2i9iXttM= zQPa4h2qqtxci~&S?u#-ipS8@z3B=H#KYy zbM@;4&TdPIzkyF0+25G#>CcHy$+%gJ*cs=mFnF2!!>S@CVFFsF)ffe})}4z+_tOT` zu#lx@#VF|8D2UyPcTC}Z1*h{yC!$|dV?8!sY{x_gZ( zZ~ScNHl^bEcL5~h12S|ag4il_ba(Ika}7u6(F)=*;839Udw zJ52s4llZ_2W30Dov0y07BW~e<|4>(Ap??Qi6@EL6H7y*(Uj-wChHDjO!l6%Sz=>zq zcn=?2Gcr^NU)d_eR%SY|?Q$iEe2k%hx((%Gfa~~#_`8l;VV@<#Q3PX(eb>TK9@i18 z*!l0DBatgAYQ$JI$BZ!AZ9fz96|=ufq&a`~M`06xP;zH}co(DaomBo22^HU;92FeL zkY$jHG}0*bS$&V8utza!Yy-dJ_qXzY9){uOY&?>P(OG9_8dVj(GAI{9ZHI#k%&7Zz zif!?Y&Gnp5nEN0eCs%&vP)>-M+P24|T;t9ET*brN ze|Sf(cA3!#s)Ui}TB%Dpe)h~UpCsrWd96=J=KZ;8*3_j{Q=j-hfh%aAum2Oc>dyK8 zAK(fKHFF;2`#)^qJ#tYyefD4f<8i8|M9(XRdHZfUH7Q!`#J+$CbX z{$2>yQi#>@U+~U{+2G=MqFs7>ZURYMoVwt&VBB-o%T8$o)KjSOYdm4pjAEiWMB$k` zsG8$Md$wPESeoPTtv_UtBk6ulb)hG24bCI zv``&I? zba{n`YcwuK%((N9v%s73o?Q}9v17w@wkb4fJhp_QJA*F_8Q_^i3JdvP@K)_%|AV*k zW6l5n%3I-Ss9IH@!84v(qsVjX6nnyCgiA11T`OVzQ3~|ef8Pa2F+^rQg?2Jm7f@XC zM#kD8ex$}3`5bNNv`aa)fR&tUez?}I=WV`p|;i4M7$ua z3`IKa#vyykxWBJ zMDF8RKTsq38y&S%;qX;Ki6Y4o?Xu~8vOt;|E$&UtP*vG2`IUC8&YLPzD|3w<2&5?g zv}E&oqcrhfLHq;ZA<2Pbg6~zimr3f8mODyH4Q?F?Y%G+M>PB`ClSQi+Ar*4NuZTWwFrGgS{|ErXjECaj`O`?4}FtyJ9eGI z>cdYT){OtbTn!q%Ggtb>=Zw7>biyRXM3$L`LhC}^j*0#Xv#Mt@4oLXN) z{`wpRo4vcUELAzFjUOKwN?u>_QPY1amr1GgMv3TEBChs=eRS$Zk4|azKSHI5D;U@~ zp1}5nu=(xb&z3aPS?8sDmAI+# z3mQ;WCX}$upfmnSob-&|Hxu0O$%>lH^=DUdt$J15#J4~-3N4)hkpd{01IKpBO^Ho? zgJE7~8U>dvVZ_l1nR!f|a#&`Ev_F6TxMv~YXy8H`@&4{ExJRR76P5X=%l3S@pl)9u z>)Vr!VqBMs4j^yh&p6AzhB z_kSJmUY*=1@a{?z<;vq@t@@~6u%meKGgf4m&_nx4&2_2IL9KG(q!(V8j`-y_e*Qb zZ-dfl6NvP?(6yA0Z@;AFqpPY{R@y4+?|0hdl)YFUr_KfH#ItfI`k3 zr@2b46r{^w#W|{7_WVL8+z9X)nq77A)JkfBUiBr=Crw$m@o=G|yNDSoR-rVtY;o?S zW6Z3I+$m)9v^Y?5$UgP2|HmR!vJeMdkLFoyBw#pVmSoqHITJgig9hh4R2UXJaKoXs zx34IV@zHiI*}^HyeAbCuG21r6v5Lk#(5~uv84l-$ZXHqXkV+^2SiPR#cIN)K-3AZM zpH-&0F>VpNKl@y%f;}FcheN)PNSWOslQ`QKUO%{O67kNO;BjZ%3%IwJRjgo6En%j- zij_8rA1O$_I)uRvG)?1|3!P`sLlSvfS?!TgfPu`Sm<*xZtRCnjv~cb-pISb z(E`olF-0wiI){gCh;_O|y)=gCM5N*-pXX8oxrf7-B7gbS@b-b@TslL}a7l`DMGafg zT*AHZ3@(r3%a)8ZoROuaU(5db;}A`dnSvW?`P!FD%c8(B7EQ(@nnFxiu@ddM1nxBSqOX*C9k| zdYr+-8)K8R0m#!d_A>-~Xh zY99Pv@AYu7(1Gp4Qv~c0wz60CLm7|m z3oVOieoc!ORoT`=!HFkV*l5i+bbc(#P*g!U=E|Rr{WVKv61z&Vqt)+7EBBiF1JM02 zR*=M^{S)kggQt5HCRS5xPl=$~!Ih(7EOg69|0FUGPvyWNUyI3zjCrWqW(|Gup%yKP ziyT3ibBc4W+Z18PP(-B%hG2TNJV(uK8hv|#z_Owo5!p{9-QQY*|C>Ff8E9yaCl}&< zfyVju57S5mN=X`XKSvPpFUw5-l-=%w;ut1Xg=AWI4e^)(4D15c-`J@VkxOM|$Kn)U zno6Rb=UDk(xA*FE!?j0n#E_$F~y_qMf^W56odMVS*?#hBvwSY+frm&`{YYPLyrz z6-iEOxm(>+GV&jUi3!T;du}4L-xoqlnleUGza}WlMt>Li5b?z^>)1)jGPh|=Yx8MR zxazV!I8dHfp&0ddwuS|ny8z{D3v=0J$}Qh7S4OTymr8Qu(wCuQL?Z4Oaf{k-8d_Q@ zR;Ds7l7HC(y?C7Gc}nGy208jG ziWE`U)bdYex+hNL&q6%s-1c*P@E#o;)w$E(gowVwZnhH~P% zhv`gXpH>3h>=i$!#4Hx2DL=BIt8v%+6JeDriZ&PcMo#sRpJ-``pnY3 z(Bke>DLfKfJJSuDd%>-sQ~%AQQC&w<^p+-#K|@n0V9Xr92yG@b36n8!IKwoR=q^is zwGKbO)>9Mzbl~G;|EJ)syZo;@BE`Ow^&3yy^R!f<3FUDw{VF;EH7)vAbib%&2UKu~ zPAd<;Q95mXzh2=|Wr{>j#e_GcitI$Nrp^rJRwS z45p6s{hE?v%o9C-W06DZU*5ej(o2w$7KdgcP$d0Dgk4iKH5>~D13FMJe_FQ!{d>a? z!d#xwRbtny@y{xgmDhY|VT*nR7vDX*x4)|7UFZAb7i*?+wdoAmub-aQhr584|4Ka7 ziT2k1E`vZG?uz1@urb4^7fo+DO@pK zKjb@Uo=ACUj&FajbjAt)nO4*MB_2my<&<6AJMo`fBwXigZGN%pr3E*17lwk+xsuH? z)aq#4!T_+A{ft=^bq(^Gf7*Yw{I zB5H_}RpI#{pqC0QTcRfSpF6J3G=huOAs zRVn9+sLj-q1}$9dA%ftin6dMwzeuaKFG-2JySLBl4=c8iu5Y)9`srr?4=@DT(2oF~ zziNyE*N2^r#DMAH`TJ0gV;KmY#ISk*e7zutN|hsTmP9LOxP)H&#C3$la(ySG52>&> z=Ud6SsT`S~XSuhm+8sQbOkr!JZi#%+S?mWowZeRKM1(oS+XThz*#~qeVC~-SE^;~# zu6CmF&4S41BnmH$l@_il3{tFOz8+dBu#T}RR?(eH!8-A>9xtcUtu8SwqaS8p% zD`wKP!;QgZgJezZv$k8LC3lzYPCt^7-FS#WnLe{D8qXA-f%@fTFQdlB2p{43lRV-k z22hK6JR~J`~4!z`M5P*slrm0){!s%V4$X_XaPyA)0W*8-)@B})LonBOtKSgbj z8pp?IM+#@xmpd;%pSz z>@1F=IxXsl=Hn0A;-)~}IGX5Yb-Sisz)KukHgCzck(RF>q7;w7qXOet(E(Zo2BgTHm#YL-70vn`4zq6q%?3e zd&J;(qkMh!Ver*N3EeuL8YOcvV-SHGbtL~YR~uGSioyi6^-jN$d?Y=7o_-*CQMJq0 zwZK@a=il!wF>oLx*Ns!1UpN$vP$=W~WS7L{%Oc3806q^SS{Vq;b)~G&6`a4V-kQige}YZ<$pNpTTO`X0H6g$$yuw8d zRh$sT$wclx#}wkxLmksx`cW!ZB@88#N%E-;*>|E(oYnt0vrwBo);v?VC=-`M&utnw zGr9+Qrj_sjBjBhw3h+%ljk^OZ%7DvCz=FqC`HGFS>POS3wC{euIiYs9gXq*Ym#_5F zkcMlq0=y)C9;U=-%f?_}VhVs;>$Xo_WPI1%;_+3!i0Vo?$G4jlGOd-2QY}m5?=>ILp2N zr{gH3c^q~&*}17)WX#IP*G)?-H`ed8!i*L9fy&8cyje89QW4f-JSPU8pC#DRV(>rx zRQ+eqwc@n+@70vq*Okpwax!$g>GjoXd;4d0@TSDB(Njv_wgE;AM)ZzdwjgkZuP|uh zI*~sVe~J`UKe^l88{C(5A!6*8?O&|H;K6@6c^vxgtY_N(+|8|6E0#r&IF+@LhRvmX zfZF1h+^EFyd+9}EO)}!+KTqerh;Q?;y%gOjT36O-jAcKnrSb8q;|lXzl%o>0p{;tQ z6&|wBF)^pV<-BN*9I<~cWqc923Ai`9J#rK%;@0{ZK-qapio|@NI3cx*TA!}%D}A#DAYI;UIZo|N)Lg@m{+WNHI!u%vczhN0ZR8O@I~R&($9c;1Y(M5l0jl?KK`Eu%y-%qB`7G-V&@ z&{}FP5T-}}n;42-_(;lTDtKO=pyO!s^2wvGY!<=YZnkUcG)EM!zC}8+rA2}slvi&4=l69@rB%y0# zXi>L(R2M^C?*ZS2lt1cE4ld0*V-0}rwNx$z_15{jJj-;)i@N4Mf#nka&--b+pih5k zf3PO+xE5+!o{ZITek}SdB{dtWLVoUtJ+_UKl@^4D^o}YivT~m;^G`C!!0-?zg#x8YrnB1XH6mqZxiaSf$?u zei+-swKTOR|01Sw7wAC6`7d9POm#R8aiRLbR)9x~<@wBd_+zJ591XW@LS&elWpC$H zKFyhE1>M;t$i>D8wY0VBc@-<^Rl8TR2TO%grxE zo7%GSHgm2V+KN}xrx$K?iS>m}J-8(OwXCsH4PPMP<(0xsPKEgKj#vJ>C~RaZ;~ec6 zerl3W$V@Se8ws-A54qKb9g1Wg!(*nYmZP%Q?cy7J>xKd`;Hh5yspn$YT~9Gy>(ZXf8VrhY;D&Ho4OCG4tV8W(2w6&|x1X^0rXb_`Hu2?4 zGoB-WEpgVTzZwm^GI!e$0I!pl*Ij*qu5W@9E*~MByzbfv&4{LcRzGAJ5ZB1FVJA3F z7e`^t#Mj~xE4A~9a5H?iW5(c{YOz*pd(>3-7l#m=&fh@f2+i^jAXs2^TmQe>G8s6Z z^s(WEtRrlmoA`4?0)c^fCodrPr#G$t^n^-py2`bM4KOXzCX2WIYc?kD<(SKom#vx& zEkpj1C!-H~ayA|YI>=G`ig3qVOFN-F6-QPXe9~yaYZ|d^e*Z22xazY?GkZ$F=WVEw zbR2St{i0t-KgcOs!hIFZ^&ev(b*^L5kUq9}E%-1meDDhg-_?1j{Cw6lTmEygGDK7F`j-MpVMMITl4$9*_nFVV-|)q9TjqmS=gw*+1R&FTj4*6ZNCk>WtmXgNGw#r3-#c z?~at{e06iIN2G{%_dyu}6mc3EZ3HTedf$6J0+# z)6R{RUCiVp06AEXm?;yHq3)xshUqWAe~2?G>-3{61gIl#XXf zGAp{9%B3>MXlLN>DfBs=dCS-Z$$}@vG_USltFs?g@`1^Tm`x&XRwe~)dMQe{GwGIQ?`OYe>G`)}iCd~U2Ua&NovI!k&kw5wTDUt3?oq2bt z`lK{|9p=@BH(@U(U?E4{@uAkxxpG6e*yM88`68w5g+PNb#k8s(5^j^k;k~X+_f@nNcQe|T6bqt3G`WnTe# zn4zmIeYP+EB?=NjKypq5DQj)42d=EANK>IWmO!EGkQngxmDYa>gGK&x!7hV2dLcIw zmi<}ZkxDI|PtqLQ(3D*aO9A&v4Era%lv?F2t}j>iVhE^8X#J7+WBVBZK3o!Ogu<+N zNO|RfT($e41XJ#o;I+8=JjluAlA-#c94n_1{~ITe{+E6IFDCUHW{Y~fv*TNzlS zoB6K4Wlk>BlzC;@&=I^fJT71+y23BNJTGXUMh#`>=BbxF$h59CWnY_*D)O0b=wipa zMGk_PaE3R2#!a*1=Pq_=R&V0VB^D7vWPv-kedhe*wkfMek*%f4HKn2T2 z@YkE3Jk8oDO@~2c)YC#}O>MIJ)$NAGC->MtYTL?=nQsF0V2eYO4VGrTgk1c6#J7;8 z{NB{mUi9ZPzEB6)=6%aL!6;P>?V%+t|H&s%l3TcaCcrmE9SHm2>4I}A%5}_g#PcOq zI(~Xien6_i2+?#|#{X)ICKk-s!kGb^-A}0&h3`;_{lA5z`gi{D#v(3mK$Genbbhh zL}Vg(e?^@WO`ba|#y6@-B`UwRk2IJl!0&-aBnsd$ui(NeM5(~dtm#BEb?8~pAa6x_ zC7i-6gJp-h;o#)vgXSff*n0}!Tl^QCb+@cvRBCC*9E0Zx^{b`jWG&BQpTAY+A=KUM4FBpCpn{pgl1Z#M zvB@|iv4D+6rkWM42qwPQBPkTQ`YLP)AI=(ty;*(B!F;`<0o60ekgcewZ&aW+_Gj{_ zkUCIeF@8G;!L$nF?|FP|yTOO!S8Tr5=XI+LoO!m3d&IK3GnxRrQkHwSgCYxDlk&*z zGf3nwoc8L*(F&ObE_avOg-x%?pPyG^P)cz5xxZwYXv*K(DS~F4P(6BGINdEf3p{Z2 zYYHGw;r{S@hYClk?5);`P})&SU!h&*;X+GYww+h0MOI0%2{NN)xK$9wH1l+ue<6@* zEf#*%zS@}j>b=6d2>7hDJ+t)t;k5kbT&vFKN zt{GID{d3Y}-|pLUklyHKugc~ciiA-=Xnum-v2*CDVd!3Ozhwjz(UYk3 z>|j0Si=sQ@D!Auz+P4a)GDC%!Hr3ii4imaX9P+W-rG5V^&p(8K%t~sD-?dBoDo~Sa zWwoN**CC~U3^PG$6O~0JI>Lor6N!(!DTN9#pC_7^=_s@WlMzKd`M~jPA6A(;(>!S zS_iVr1+AB{bJXx@Su5;L)M(!n4mHZHnF8`7j6R+bT?w^)LHgVXS`Be?bGP=@tusEu zNoBEswCA#u#dgLM%eP&R5=Be4%e%#E?rP zJiy}esF)Opaa<1uh!Ipr!Qk$-O+5Db8(-ksqbpasOMk)+%TBh_uInp%rJehedZzoxFYW-Z-h~K8r z>*`O3s@yk*<6J@dbtZaiq7vWis{lR^V`RFXkSQhsYDGG+ZpCaKlu5fYNOf8gWhx`K=D`a*r& zZu+P#TdZy=HBqH~+uw#r>+XP1sDbH9yeo=o>Vdh$mm&);F^uPiwlCEVjRCl_JbQE*5*=0LZj#wtfaiar4NQpfW zTST*C=XkTp=+0KEp;hDj*ALK~)T@_U?Gb{5^^X#oP&drZM;OJ+*jvuD!nT&r+oDWP zPI)h2UJk8vu@%^o!o49CBt1UiX}s!^-+e&(KH1#B|PI zeqGE{LxQT9Pxhee9Q_IPLm=a!6s!hG9^4DPxH&I5VZaL|yhV88RlkL=x6Tcu6sck4 z>d_#(xAdfh$zsGUhFkXxsEW{#L}oW4j`ACL?QOCzAr++A^}xNpx{P9#LP{2Qnm0ezk}kyAoy zrE|wPv99%RlkMyTtl+C-uXP{J9$v8(c+VxVfZ&&rIrxOJ_*FmP` z(XcIp=2!uR&OcRw!SA!DQ>DrrQ>bK83we&5hC4bMaSlSSM}rTI2)m!#khDdw4BoW! zfLGS!i3E#5RM#%P_f@5ml9Fm~U4e&v>VV+jJhdJAr<6T7o%FRaO^Lw>D)>h`g}iS( zzc7$~5d5S0Zek%*NK5`1%{5-$E8mbdcz4hb>hfZi9;21YM1{}yjf!cB>N!V|G7h+z z>qDBNFrqSpho-vD0e0SQbRE03W|g8qyxcSn%D;02<@cZ<;@5$Yr|bbJ2s@|gtpCf< z+lR&FZfdr|>G@BH%`Dhw4+HXKXAeVnbW7)>EidUGhuN0ElR2^w2~@vuujd_AIB@&c zhz!Py^w<%U0n-x*4s3;e{RbV!Oj!C${u9ys`!YG;Wqd^Kg$AtCsV|kvn7daQ1oUo z2G`w0OF?Ez2KS@~nidP6ImBy#o`0r!+iMo9u`C=57hF`_gRcZh|0{3Nr{ z(dX2|IsGve2FD`56L}I?e8~l~ovW*lTfAwYz6US^(vut|?}PNShf2wXeR~TdB;{ZQ zR>O;-S?EclQw^(0{>%(~30g5o%LXlDA@@LUbBv>6in~9m8!vyge0)&T?N|ccDL{#2vt@_L?0>h>G{Qe!8 zK>Q?7w+dKitIbJ0TAh3xivSH-D&`M%`OP0R9yDqrr)nOuj_0LQfP;YCSh%FT-L|6y z9bUBx_gnWbfswlalhbRI$WMenI>fvT1O%>W{(sxNWee_E)8&ey+-6YY9n5p1T*vH{mxnI<>nn4$KwMQpzP zXJKQrsX{FcAlW0Z%DC1T!BOqX zJ!K@A^p-OMol2{l6_g@P1Tw5Dc$UplTLuQ)FV%x$I@gFTOCjaPg~Kt#P2z9B3V`?W(~oi7M)yo?a1LJ!-b9yt17e;VCPxx0*~Ob zX~Gn47kfG;$4@1>hs#-PW#F(vPIw;#ok(wsDA81)1G-J$VKAaYaktbAB;d(g0Gx85-3^53fKWFl{GncMaBDHPFeMe z3pqtvHXktuWCdJi)O4QTxJSWX;LcuzX9=0~p!vwo(nU&*;Uw#ASf(jGWyMiiN~|36 zBp_)TSUD0??TUd%l0L&#D=WzcEk!&voS=--DxvgwywO%G9mEqO)vsc_iV-Q0s<)xP zwxzQJ1V$q{W09xpHNYQNQhAVqGYkasv!C776+3ToH`O6BxM+;o#1sIU#4LwV_mv~l6x2k zVcZvuKRgrK(;D(toSQ5lWGg}txPAdqHEvbfYKA_%BoI60XPjf3r${Apd^d4d?`!Om zK8~qc{~|Y5Km&4iOl!iSwuH%40vgCDdchT)c^<%X5nVBGM?60sV@ zVwhk{Z?Kv$5hP(G2d(JI7FlPa(DK5UuS*6?Mgh3Vnufh!)2jp_uT)VMzx3Rx;B+Zi z3$|d=f;FQHHTAKLH`=Y z7ef!J|FU%~U@WOmtK>tvAgs$3s2>6_*F5x-lS_Xsy!#Uz4El0y4yvLc&ZL+Svg3m~ z<;a>!+$~1pzo6_qj~m*a`-(`jUi#b`gZZsbktW+{5nYnsi=1!&Nq|!+&xsh|n4osY zD6(j$$hf(aV zopt4R^MD!+sSaO$1+mUN|k6U`25oBGh&5}oQN3yt?tI6aeK z-p5EX9I=q6CYCARBpHkBByV}qN0Tar<$0|KjbjtYw2baW%cKn<(Z8Zk*+c=o4=S71 zy+Qs#zAGKvO$5rJ9lWY)p*7&5!0vd*0Cru6B=Lq1*Cv@xRcyaYD;uw4R>E~PrpcUK zuNcmOL0hM>A0dXN>v8Xv#Tg;S zW%V(fHR}U9NW+|B2Pf|Jc$dO{9xaTqVQ3)HqHU6KPb1XJeV*Vn#_fQBPx)#S|9~_= zp7R`#u|Ln|=~2>RvNF9$gEhadIy#Vyecd9*c0{gH*CEE$aJ+Qkd2jWf=Xcm;Q!I0r zraOc^f5=HEsGKa-tVv1AxOyCy!>aUOhjiG@0~~z*do0IHXYl9nez<_0L#^9Dk`1Q3t z6}^N$C%2QM+wJ|Z!D~xCW4~x|^jxoD;lYXUfuibNoMj~=w?*9(wP7RESi{&R?b4is zuG%iz)SG4_)ATtQwcIH;wlCDVr(=`>`e)uz)3Rnv#tvD@R;@cJvEDv5{02rQ`Wv0ZxKB-$<~TI#+cFP^ zn(d_&(^!9R!|cmGp_k#uQ2~{(zkph6_}=CB(bEMGUSGAG_!AxtDw=4ud%oG{`^ByF zNp|O(ya}C;BuuG~2Q7FGRROXvf>Y$T+cAQ-{U*!bSA^CkI9*^&M7~k;F?HyiNEv8h zeMMNFf>aTbNwb?k=HK6Giw{yp(7&kD9#|*pLfmnE(V5<@KlD&C9G9}}p9bp;+1kH4 zZ6E$g^ighyZ6Siku4${0^6;4>&n-{h8Qd(ax>m>1Y$DsD*0k2*s2OoIcjufol(^H9 z^D9a29MW>tS1rM7x@5tT8NUV0+8fv`J5T`b^<%r2aH=_5Qi{3$V_9+jZK} zV|Mgp>&;=xnp}V01j?QT!2Q5#cl-!>E#Cm~4hM%d47=YzTL+sOKz4C$ySOT)i>wUA zI^F~3aK6jjfMDHbBgr_hI$qf=PNh-JYs*^)JIRQurNC4v3KQZS$xL^s8Rw}jE0jS| z2pd=6mx%nlw)$jE@HWKj_wjwSw3* z4Hg)96f(9QGgqr~wBH&1uHH^d?6*75y89;3PCMYE#_ju|fEVz_kzPjrhpvXL*S(mT z#3zoeK>VnVojf;rfD*aK;T99Txx~a7)j8^M@!-S-@rt;v`0^#rH|Z`TcATAXZl{~0 zhll(7Y}q%&b-$q-^iRqac}rh?6dxN2Ep3sQNxM0%%oxz=Vf=mQ7xxisEC2Bi+)&D5 z;K*j`e_?9!^irxZeX{IVe$)BBP*|FtbdsK_Z+mcLn!+Gd@vI)VsgCyIqBG zY)w7zMzT%!t3>xOb#?mnXH()Q%6RXm(a&8>%`FSlW|Hsl$XjGeqeq%Y@_gI;y1Qt4Du7S~+IcSLc|)wkz) zvyTh&{t!27;WqnYFjA^Q;}=0VFP&+W2%pfY3^&R6#KkI=e^1z-Zf1sAS)F37wx;kj z#W|jR7gK9#qDuKuytu*Xj=x)1dx@`O%{T1#_S~CHPAMt>>z}l~!%N46pis2s#23lV1?Ie5zZ2)l{N;wc6b?~u*J?iSzh$#1!o71<|y&i$tsyV zk#jYYcqbH&c-g~BHYnm%k~~c_Vw_Src|YEH#|}+3!UvHiL~KjZty$s}0Wo*hNf9S5 zhdq;K$?yF6;0(-s;k1@oUWNObX_20ko+ZNX&+C>=?*(O_hj7)wlQM#hVZE)bWPD;O zO;H7zED8!l^gogI9wX|T3$XrYs+&W)n>7Gu99&EE<6#83ahUY7zQjsrc=})QqeULQ4-Je6zIM;S&qU4xy z260HN8dJ3%FFfIj)Xjlr`Kt-`{Sg`Ko3<2Bsx$i+ufxqA-dFXnuk^2;9{nj|xfH6f zDsgh>QB0+ENv*-ftQ+K2w#^MkwuAdA2G7>tG3xdN-ntta9&NjPy`sZ<60>p)^zr(i zkM}i3g#NNVOR?{LtWl8TQXb~dZ8NX(;d9ScpL28CpC{rSQtf^pg3}@@q#YrTY8@rRQAA)8$R*}L8 zzUd|e(=DnD+}H86MC_`Onf6j4d;eOr**cXl_C5c~m2afY_yZYLSpFPDpLxrA#9oo? zW(9Kd7;HCBMmA`~@ijM7Z*>YZ?Q%WeIO8!2Q+AKqow5<}*(y;)!$C7o!rqWdcz2nF z9zfara92zf3@ix04av>6FII9u;J)V=yU;-k$gr05{cRNvwMQ9~dV5YEL`bQr#tv;r zNC`%wu)j9)9{W#)6rpq20rNqU)Ah;M^cS)V4M;bTIzEAX;L_C|wj%H077&6_AeB?$ z$V3YCDY`Q?aIVAAL|T&&%@;BvN-R1+~t`3h3H9&a!^n0Os!CxF3@D*42Hwn5E zY&{aWvmYsDC?qtHutjS%pu?&Z$z`Gu60yq_g)gL5Zj3QuAY(Xm3qF$RuJ(@?=;r@>x}F(sdj%p3@*)5_G!x+S113F){5WrP6CE zW;}R_f!L;`r7}^jC8%t`gK~+Y!8aEo0)RS-k3BeK!EgF2DP)AFkmAQf%7Qwc^;d?} zo*KiiOvMCKyjM6KR5$270CFQD5ufQt3p=)c7%ssu+T?FX>XgzN)X;MpPfJMoLsRz1 zhw8X&uK_xZWN=irgrXk5OMl&2s-#QPoXKE7Kd3yQYY%>WQOatN+ZvduFmfmeDFYkg zwII^p1y2>)Qf|#WE;8HOP3gb$&!MfZJvz83lVN#89t!AX=WRv-t*)eJ-{=JTwWR2L%T~Qv=+$Q zLkG2Q0=IXt6)TlCqKrYRRg`>Ba-QtwGiOfIaR#Pq3yC!I)HPOLnNhX^z-Z+)EhCe! zn*|b5)D=HL+KS_NrX~4kmi9Bzh4_vm527z{&X`ol!{Yb(LKiemF014cz-RfjAT*LH zBo1%mPIC8v--VA7f<6>4V#ZD0m@57@K$07-}(;a9V_KzLQFDGD{ocuDR% zC_jv1$EOa0+J2K$*RhbH`gu8u=vypLRCQTg%5aYha#-&h~X`t;)QE zbi4&JG?Ng5}Z4;P}_6r0J9ZDao3P)XD<12t)lfM3XcN1^I+jyfp+$IWKI9*sT-2sh57!f^&;WFY9a#Tn130eL}xxt>% zvsP}hcDI_etE;vTt=Ebb5`H?~!oTfl9-Dss)-+g+Hlt;B;DRaQEBQ<%C(n>Xxvcu^au+Tbt5c1vv3iz7pI_)7zyF6)6jus(JZFAp_`G>~YD zOgkE6XM9S6(8sd56LyU&W;8&m>WsOnt25(k+%o$Y702MaR66yf1Hq5!+;Szu>!^(X zGg?q0JuEx?<>yjyw8Y{!vhsr<-3>!7e@@&t8i@H z6n6UeTts;zz+36ozp3UkOo{lo*s}@%bZOe|-6yG=N=1vlIen3t2O$=iIq9kjst+Je z_Q)Eu9RMAS;QO4!L`kiz6Sf$?@bs7C*O|5SiyT&1g(f4r{CUG3T_Mt>Hvu-_&mWFY z-`qKUWNUW40!`nc=<1XujYkO(gL5Gap6oJdB}Sh3YD6|NO%=vss(KYd$=V3EJ5q{| zx##fka4u!GkCFsr*p*}l(yS5Y55{6xU>PV&Vp1WWjHlYl+`8K5 z3&VE*wRlg`_ajDES8D_GRf9=pHbB!_v>Bph9$a1c*VmBXPb_<6IH8HAhd300S(8G6 zB^dF%#X)s;<;P)V$9u}l0(=eSOs~*lHq6pO zDJk=suMgVx(mA|3X%MN%)UKn0`Iu~9u@Yg9JXMO-ZZGVX+s}co@GHp@;}~y=a1HDX zj4>vi#2eE4&2h-L2w6w-6QsN8I$%4=3#yXvHRqvA^q>s15-z@5yI$;e-@Lt_rDKIrS&cZ zXPPcb_ONBhR{sFS*gmE)T22S07CrTVt-7d4j-+CduKPDggjrR=_sIT?W8{*fLh=do zQ2+XaAoS!)9sJuqucp(fk)IsLylZfA^M~^B`v~M-dGsa3WKL@ubP0?pP!?3Sq(bT> zFY!NY2SU)mNLWTU0`e&|nf0fkLp^98SqC}Nb+s-P$hj|8MwOhewsu8zzg2{EkOS8`ywtW$z@WaTgZqT7prXHc?R*!lq3eRk|t<-}2 zg;sOaOf|4>>XOPV~eX zd$WlWg}?~qUtAHfOk46QJ4)7aEA{nW>8Q7?N{RXSM;F5KPUzX;@n#tnZE6Pv1G9C? zu!O<-%nby`V6Be>2-iv<(S!IMX3!*|?38+!oid_~Ytc`RTA;4BktD`KE7)Aof;FO~ z{N+2!iWpw6Iv!J098Jw4h`nff*wzdGDglO*_a&t-sPV@=XR5DLIdMabuBXaoiBPXM zpmdLz#Rhx?1wkt7AJ+gJT&)%bEGUNgHuA(U`%o=w^rgmW!sq_Zj-F;fx+dHv+Th(* z`(;02#bMC z?DI)F!#IIw(Y-HBuDKAZLn+a)iRO-pQ4-Ky0doMgw5m_M37)T-7M})>WiYGxNC>7g z2K(|h_MD0|4uxpTn_sW+L(gp)gle`NVl_5F_4MVxGc(shQZ`_w*}pBe>D?++-MS@b zoOvpuPEfVl7FL)@v;Kh)VSek*W!!0oXy|4=K7j;YS(^VE!6f;&LXx2rD6FnjG&5^h za(FqIWg4Tw^{JI{t}D7*3MRwK3ps(RjYYbZvcU^l#P>oKN(Kr7&_$w9hdynJE10Z_WN6*dZT9O1iWK7b+BF@`a#JfSP|9 zZcNBN7Lw)X4Rz>B{W-%(u9Pj;U1nSRP!G<*&rPYz^tOeC~lA~rW( zu%(G7naz{!hochR(5oD*_r&{EjUOe!twC{wBj=9%$}Q-8yei*L;w?ThN~-+EuLOkd+YnZ6|-hd z2oFJxoYT2wH%ESjIr;gl8*eOim)5C9lXU|>t8sm)>0F8K$+Uz>ZJ%%{csz^EuN5a; z0_cRnl)`0cZ(f1nrrPn+w+!gr_Yb-aR-yGHTr4*o%8LTrVsM?u9vZIKe3i$-RPQDK zE@OdVXT?-|laV{E$5YYwnZ_Vl+mj7uhqHV0T-t$CqMl4SygVVuSt#(>aAvW)-Bw!S zqhwztlPZgzXu@5&2%}>9>1GZpT63MZSqhRs{8BDc!JW&EG?P7ej6S5Iu`;Y?om(n3 zM1H2lpVRNr-LAuzpjL(cRW1jkT%D&g+X=L51c_!apsaRBpLVRx9)1wzAi`y?(6j?xJ0T!-{l?_^uAPX4-aHlVDc)21x8!J8f;BF%>WEPeMuQj6%qdph1@~I@ zT6hkw+5|dLoUS&^-sNA#QJEs`Fc=*Iib1>S>Wv0eEB4bQ znqjIKPDdRUf(~P(XG&rA`O4BW^CEGnroZA0SvI+k1CZNp5mTnqkJL(4YO#!124fqV z7#$|6s7i4?rW^pvp$Mfkh$>4I#HNF>qO@I?Dki*@D)!_ z=3Y459ddL0JD@C2RS5MfnFqDGug!!h+WBw?NMPj{>n=rkmOr9B5L?BMXrIR8l0!dn zSM6*Ov7~;&%L)qeNOD3I>r(4!^Y~xYzNi-;HBq~4tAT08xz@+$0On8f;{U7KvqR03 z#|ffYW3=m2VaOih6+$mpH{elqak}qd*d+O^IST1!1pIQ^6O~?@duo86m|7%Q>!@@7 zLQ-Dgm*bz8*m#syq_n26^lc?xmPnNR&6dh_O6@6>AWl(ZSAZyR0-yOc9@;uk@l*$L zSl|dWI$CR0#oD?&GCsVelUOAktb00!pH}Wp=NEuWvG%oq74gAg2pW_*OAz9`DXBs@ z_i8Js>>|*|!Od=tH{+pHOx|NwMsqQ2E9oG+>%SMJ&KzP)tzknFq{8`FSzQov8c|_F z!qbGE^?*ecUlF-E4`sThfmuIyb-Wq71ETa|b9MG=o>!|%pxgAH%8K+)k)KlcY6$}@ z<~(m;Wx`;%aXcs%skC(Hy{ci`O11ziS59L|#nw0l+5inzC ze0L}?g3^Cf&@)_xCl{ni0yfYI>e)%*=is{`ou%vllVa}+*)yRrsvN-eaPYUaqH7si@3bPQI4 zLEWrk?&&Q&#}a6Ap2?{r^BP-jIjj zB>^@=LZwK(jq7~-wj?HPZU_iM+lq)%QNj9h#Hk_MgwWcP$J=Lm{f}XmCi17#y z(rWqc7sSN1C)t7}?YGkDkxI&v1_3k+W_EV7!zg4q0O>#znK>~X0}7|Fih zwmp~QscNszSb z3g!hJXj)-!)y>tw?O)Up>D+cgY|DYiIyx5bmR={LKF?0^%v~bS=L;i<&;vnLS{Q%g z^C|HT(X=;hm*e+dvP*XY??+#;TAd(GP!Nutt=mg&VNfhlys; zSC-6t2J+-X(6bQyq9r3uIBF0Ro&`R>Y+=`R`3D_kg0EcUp&9uK70!wzs2`?A7b;B7 za1Jb#`GQDEi!r8^t*%WZfnr18ZydNY)QKg(2Pc&vLx*W#u%42%(Qd}5f(R6>s3p5f zy)s`}RB~kP0uEn_pXt$qtrai&?_B!=u;QCmdo_yUT3DHqlET`Y((E=gga|f@k_UU@ zPxgh%lF&@M-H9v!tt)T6?25&LqP;`FTC~zwTR&Y_qwT)#YQqZ1n`^8;u1D=|taYl( zw|2M-J$DC`8^?|I@KW$3N0PZMkIn0YRf=&nDX}=Y1^8SmKSrEN)PrY@v)xG3> z4^6!iEPGX7i_<;&X`OrjdC!ek8`tJdsHQ9GO0A@ZMxtyCo4i~_z}jW-Urei15Sw~{ zJsTih)R*#mY-qok8t^c%uV@Y6pZp1t_q>VzZcMEX0pX*PY4hIhXW5-3K>3(Z2pK@J z`=@Jt-EvPP(VAtFhGz(w7N;O#=&F**Cr6kD#g1o0kv3%xw1zIg=y7E*_8Pm0^BViq zh35e0RZ(;$u+W_jCdAdquS&Q4>R~p6?^PLS>~JSA-6Qp>1S$JNAOB^0@37{0y9M03 zt^J;v!pR4c(70JX+`$YmD>U@Jz+aJ0R+XBKmdX@~WVJ**0KY{v;dzLIm0wH&Dw)DiXB51u# zp@zKIkvB_iNP?IeY~C=uVVPnaep|G!$orBj7mU#$M%Vd#)8J&q@=o5o65ASRyRgL4Vxz~hR3Ft4TvF= zaUXPEDbqHC?c<;H9y@cu&@-}_^cDz`UoybIUHu5a$>G6ga|IY{U#_6F`0aX~vq*kj zE+44%i?TGA2L4Ibwe<79%w-!6fL!6m@U8DhO}75jhxERB^-rn($Hqcu12P_CeUFRE zDj~MJqSrd-*XH*RAq)eDA>)CeeH?G5^dtv{E9OGF3pHz6PFLZCy}Q)8A3HM@&6+Pf zi^aH<@x@ua=24dw$}-r#T>EY2=CBPs-R9}M_`Om_7a+VEVCdBhocyFY zMUW7XpsKrrL>j!ez%98Ck|z`82c;rhnax*4k3lVIgWXOtn3>{<)hGmmE3m7A_A%tt zZ>OrsI1bN359buI^Cb2tP=6&;VdcE?&W8!7^&_Y-hCLmKGnC86+3t>zRkPP9-R)p4 zokp3G<*^}h?&xk>$J%#K(vj`+DC#u<1#*J)_Bq-5f4++AZrCsZUd(B8jlr(A@7GKK zg!rmo0Pmq5HvmAfj^0zcbdek>qUxXo_|v&tLJ5DAP}> zCx|N$UGvTSE0AXXJtE90@6>?g@=5x}Apa3DIL`8_6e;4QmcTlp!GGGv(Z`eCZ4k&y z_|%r{j6x9#^}Zy6u&0m4e;NNat%N+63qF+kBqPzgTn-GpO6gkvhmPZW&0BKN1^%?*beUU*Jzi9N_7Y)@&ja zRj+`V0YFt7arP^RxJ5!E{e$6UU=1nr%;*Q*ci z{*%-CiTmvwDqj8u6>O4?DGodFRO9}T!Vcu%`Qx}+4FsC^;Dt*;OwLaF;<%D()9^7O zVTu0+iE64!r}9v3^lQ`V3|m&!OL^1j-{aEQNE`P)1J9!3f9)L6)2(HfGun{q@eu zbIr?!e;OS8o+hbo5yZgr6{>Lp^wF;J^Ronm6Y3sRrho@kj4Y@45ImE%32F`$$i|>U z>-{Kby2DEB@aQyiX*)m=olNvkhJLkcTu#Smr_q!XL?AGD^Hbfq^Vv~hW0Hs9s|Jv3 zEVYED)Q=JES~OYopoy-(vTxKi~y`EP}ym=3K=^GJQOM01_LWAhLE=d97_bpj$$bBcNDP zO_GTxSj(?-#yt2S6PIDUb;PiA_i$d0z!v|3|8#Hrc3A-;djio79_eHuBH%f9OB)Fyec+5nrPl0Z z1*b|E02`kQTx2)bl7+s-PVpk^XJRit6Pc*vgLm0j%bt6D9YF3tQWE~@AYZVloSw_Z zrcge-S1_Jm5&Bha1yhNi=7T)1vfO(Qvx^9_Z8bkX6()&1%tZ5-G?=GRopA;IVK}Lh z>nj=4C(ooGIFKy3z%$3iHGXKpc(L+SqXOj~!exrP)Y_q7lRTQ!#oB=R;W0T$c`WpfC3iqoiQUjmM-iUGSpV z%>@QX;1%a>22FdcO0A(dGW_?rZZk+Ynq*P`8Wxd;X;slXLyj3+RS&!<9@SR(Cj+%= zNDUM~0;yLy*Mw^_lvk9MxzQ#rhMQ!r|3i(IB`7S#^9iicxWn_RS7gG<=RSmr>nFE!6mr_x;e$y`x!n)6+mj6G%=m4tm{}LGG9d6DlyS8LAAyQfqse+)* z??*m2aCe`;?COf>wUTcj*UZtOxC<)lhX`d3F1^_c=P?C})L4mU4h{?C8l3YMxkdY< zqem)pFEpLB#S$*lb8jTY66|TkMkoV?s`n_7M-NuV){Xg81NXk*U|e<9g;{~qocb?M zmdN~NKDbMHj*iqoGKX({d&U0pI_U=!cI%tKLIaO0S|) z7mFN~%mE@6Cl39+VYnE!FuFu4g%oy?C9Tn7(o}$ql^iH)d82(T7E4_EKa-;WL@X3* zqnN#Rapg-JVOua%ya$9BwV7D8Co|9K&Ob7^O~kVyAaH=Y^p2OCkbzPD9M{VJ#qQ?q z3R&O>p5@M@prV7q+AIQ;rXR+8+3o`t!n;QdMom40qdl?iSbImvZ@mC>x9dAQKh&sk z`|kaJ=Q>bLG$sAW6%)mPa9A5HlKW`G$@i6^L_5zCt8sMw4Drc$uC27~kxL)8q-0h{ zYu09Yi?m2z-)d<%miax7WJ!zHV7zf-ba4e`dGr|SY?E>bRy)+N<^i1PBwwJCWGXw{ zmn&}Vp~xCY$7`HMVBC~~^1=r(Wzhs5?$?fW}i%oUo7sHg~7C+x41^^OH+(@=bo~a1)#4K1T6B^-Nvln-iZ>=#( z1MCW%rH2Ozew3?MBZS#=0GNDQ0o_difY0lH3^f`!;n)QJ{mCR|tXJ%XnYdpP)$@h2 zpIt}!G4R+ZGv_>#NXsz8csQONeL>(d&cAk}p32W||Kz>$1Q0XUr-0RS#*Xzvmr`&= z$SExu*tBoCgN1m|F+)wwmLbKN$Qs@sjErnLJCmc!(i(I(j9E`PxBD?o!_s>WFCm`^ zz~oL=KD{}G^kr9g@hoCFBecPERSxAEyKO_m*~*yDTSnZ^i+gVyoe+7{kWFK1^lurx zIbmLa8XNqr(e0F_nNYRP5XS`|mIKyPp?=zuGC+Ty0)oGa4OIdByY_Pc-pMEMM?mEg zKu|q7Sn#xG9@2iAlT-mtiYlRz>}J!gx8SVZQb+;+k0x(58F>ORuH1ry(8}`se;byT z7uyqzMBMz|Dq7x8Z*TXO>bY@y_1LLuKI9gSCP`@_Q^z~@VR{=<{XgHm;qrNTJ&$r3 zm?%IhwaUquIQgiS(DD1YNxB0>J~thS_bif+T->(YKSUV%4Xt>6UG2(t4D&VSpGT(| z-`x^Ly#^CY^-g~pmOvwv**H~Rq2hOQu?wHskD#dDDEtCQ^=2yiF2ABIFdAf5Q$lyr zxd-tuAx+{bD9q*eMY?nke*eW-A7Oi;&m`rN=_8fBN&(BUuAE1xzg-U@&U~-YeiRF_ zY6vlF2#Kq7bm-XysLAVyMbrEr>sPX;EBZ_P?u4jB!)UXLM>pVjjR{INrLPW>{H6@0qAe0o7rs`Szr%b|qnM0b2V z!O<=nyrao@yb>6Sw3>$pSq^ew?z3xpUQI~BEvQBTQ(f`YX%>hCtvzS=c)w`o*zgGR z`>?Y#Ipd(sjFI$f3yDe9VM@A5)7X9$AV8L;w3) zp6lu)UAGBYqKv)rwl2GQFdGr(G~dj_)clFlVUee8ED#XFXzwbvLG^4|p8F1vQ08|l zRlfYqda&*^i#aF`qnw{WD5vKyZx&OAf;V6cMvM|oX#~e>L+FH~`-?`AI9;Ifu!vr! z({7C}q$za(KId+FM8jY$&v>&#h2gscK4tVxpTsW=JeynyV+yzlaR=pjTMzdb&@*J{ z`qk&oXmj$zuu5G%{1-dhn`@)BKcsVmyq9x_3`VkOxL!sxC7uUqIc=u8{`_z^S=%Li zei`h^6@XM?b7|-w6%JL?x14Lu!u+#AU0L;H|ChO6wWO^PO(Uzm=lho7Yd>EF-iG~~ zsqCf>#$f1`e~VD^T&5}DEtBl;byPR8WjJ20*wZ$Rf9St9OLgnpy>cV1b1>9X5+@977(v+t7JuTzeyZfr?Q*K>jdi9f;?BJ z34FXUI~FhIWZ*)U&lh?foSWr9vgjDkecLX!t&`?I-BQ8__yY>+tTQq?5ZP`nmF6m2 zsOFm}lRo*5&KV8F+OSKhAbMON4ad!tzgz~F8lu|ne|Gco0(vr1E6>Q_;W7eq=;4fD zx*|Ud|IDEVlqBu{P^*cOc;j7rZ z7!Y^=^^v<&Lx$!8eGhj4v-QK8eTLD*lwr(Incm+eOYN;WN9~fM`0;jx#>7josx~3mdec0&ur5_F0-QBcb{n5O^ zhxj-%8&9kFz+okigup_4gqMr>lBhD7B{lSH=5a`;)o8*D{7u6+O3znK#&lB1c})CtmjMg@pKjkChBleCY{BFf{Lbx!cu@76uca_B?psNfLOWE!bf=a%!K zR-E#T)XK&VufW;Et!$8@1n z(WJ?!i*M}6-`S@si-R(4H(E3PXIe*{m@fSNTxBN~G+PUiJvrAcME2O%yrB8gBhAazu>F2@EtXqc`Sqc$* z`&vt?1m3gMLHZx-1UdB5R^d;)+`D#;@ORJ0;?vgt?6036vzp(pstK!pHz^g|E$ge;vGW`HU63J7;yi$@~hCM zu04@mk$v^*(lulzFUZP(rEX-i;k1gnwhSCAkqKSWq?vMoYByeN9jr=g_jxRy-lWXA zdt=Df42@y9%-EC}k&cBy;&XWMW%ewEcg1A-R9@}f6uiyxP1~XS+`a|%8DrNh*~E(9 zO^_(ht!{NSOvGI2m`idDue%rgcgd+Iuj?QiPr(P&*5UB-8|w!mZD$^htVBW620tom1sQv!Q`Q#Av?uY%~(JHWoV$*ft)9kC%{-&q(^<2B#vj3Dn z0ry&dvfug>ww&}4{M35&{d5=3902^#_HajkYSCUEh77rXZVxN>KM2h(9l(7Gu>HS( c^lnl2ZdvWSegc340RaGqI_5(_BH%#(7saWYzW@LL literal 0 HcmV?d00001 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/.helmignore b/packs/elastic-stack-0.19.1/charts/eck-stack/.helmignore new file mode 100644 index 00000000..9e40bf01 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/.helmignore @@ -0,0 +1,25 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +templates/tests +charts/*/templates/tests \ No newline at end of file diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/Chart.lock b/packs/elastic-stack-0.19.1/charts/eck-stack/Chart.lock new file mode 100644 index 00000000..60f9a816 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/Chart.lock @@ -0,0 +1,33 @@ +dependencies: +- name: eck-elasticsearch + repository: "" + version: 0.19.1 +- name: eck-kibana + repository: "" + version: 0.19.1 +- name: eck-agent + repository: "" + version: 0.19.1 +- name: eck-fleet-server + repository: "" + version: 0.19.1 +- name: eck-beats + repository: "" + version: 0.19.1 +- name: eck-logstash + repository: "" + version: 0.19.1 +- name: eck-apm-server + repository: "" + version: 0.19.1 +- name: eck-enterprise-search + repository: "" + version: 0.19.1 +- name: eck-autoops-agent-policy + repository: "" + version: 0.19.1 +- name: eck-package-registry + repository: "" + version: 0.19.1 +digest: sha256:313a5d7fca710c7036a9fd22b6b89569accbcb9544b9a8b481985a79939539d3 +generated: "2026-06-22T10:57:24.315993407Z" diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/Chart.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/Chart.yaml new file mode 100644 index 00000000..5e78a5e3 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/Chart.yaml @@ -0,0 +1,47 @@ +apiVersion: v2 +dependencies: +- condition: eck-elasticsearch.enabled + name: eck-elasticsearch + repository: "" + version: 0.19.1 +- condition: eck-kibana.enabled + name: eck-kibana + repository: "" + version: 0.19.1 +- condition: eck-agent.enabled + name: eck-agent + repository: "" + version: 0.19.1 +- condition: eck-fleet-server.enabled + name: eck-fleet-server + repository: "" + version: 0.19.1 +- condition: eck-beats.enabled + name: eck-beats + repository: "" + version: 0.19.1 +- condition: eck-logstash.enabled + name: eck-logstash + repository: "" + version: 0.19.1 +- condition: eck-apm-server.enabled + name: eck-apm-server + repository: "" + version: 0.19.1 +- condition: eck-enterprise-search.enabled + name: eck-enterprise-search + repository: "" + version: 0.19.1 +- condition: eck-autoops-agent-policy.enabled + name: eck-autoops-agent-policy + repository: "" + version: 0.19.1 +- condition: eck-package-registry.enabled + name: eck-package-registry + repository: "" + version: 0.19.1 +description: Elastic Stack managed by the ECK Operator +kubeVersion: '>= 1.21.0-0' +name: eck-stack +type: application +version: 0.19.1 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/README.md b/packs/elastic-stack-0.19.1/charts/eck-stack/README.md new file mode 100644 index 00000000..f301bd12 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/README.md @@ -0,0 +1,93 @@ +# ECK-Stack + +ECK Stack is a Helm chart to assist in the deployment of Elastic Stack components, which are +managed by the [ECK Operator](https://www.elastic.co/guide/en/cloud-on-k8s/current/index.html) + +## Supported Elastic Stack Resources + +The following Elastic Stack resources are currently supported. + +- Elasticsearch +- Kibana +- Elastic Agent +- Fleet Server +- Beats +- Logstash +- APM Server + +Additional resources will be supported in future releases of this Helm Chart. + +## Prerequisites + +- Kubernetes 1.21+ +- Elastic ECK Operator + +## Installing the Chart + +### Installing the ECK Operator + +Before using this chart, the Elastic ECK Operator is required to be installed within the Kubernetes cluster. +Full installation instructions can be found within [our documentation](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-installing-eck.html) + +To install the ECK Operator using Helm. + +```sh +# Add the Elastic Helm Repository +helm repo add elastic https://helm.elastic.co && helm repo update + +# Install the ECK Operator cluster-wide +helm install elastic-operator elastic/eck-operator -n elastic-system --create-namespace +``` + +Additional ECK Operator Helm installation options can be found within [our documentation](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-install-helm.html) + +### Installing the ECK Stack Chart + +The following will install the ECK-Stack chart using the default values, which will deploy an Elasticsearch [Quickstart Cluster](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-deploy-elasticsearch.html), and a Kibana [Quickstart Instance](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-deploy-kibana.html) + +```sh +# Add the Elastic Helm Repository +helm repo add elastic https://helm.elastic.co && helm repo update + +# Install the ECK-Stack helm chart +# This will setup a 'quickstart' Elasticsearch and Kibana resource in the 'elastic-stack' namespace +helm install my-release elastic/eck-stack -n elastic-stack --create-namespace +``` + +More information on the different ways to use the ECK Stack chart to deploy Elastic Stack resources +can be found in [our documentation](https://www.elastic.co/guide/en/cloud-on-k8s/current/index.html). + +## Uninstalling the Chart + +To uninstall/delete the `my-release` deployment from the 'elastic-stack' namespace: + +```console +helm delete my-release -n elastic-stack +``` + +The command removes all the Elastic Stack resources associated with the chart and deletes the release. + +## Configuration + +The following table lists the configurable parameters of the eck-stack chart and their default values. + +| Parameter | Description | Default | +| --------- | ----------- | ------- | +| `eck-elasticsearch.enabled` | If `true`, create an Elasticsearch resource (using the eck-elasticsearch Chart) | `true` | +| `eck-kibana.enabled` | If `true`, create a Kibana resource (using the eck-kibana Chart) | `true` | +| `eck-agent.enabled` | If `true`, create an Elastic Agent resource (using the eck-agent Chart) | `false` | +| `eck-fleet-server.enabled` | If `true`, create a Fleet Server resource (using the eck-fleet-server Chart) | `false` | +| `eck-logstash.enabled` | If `true`, create a Logstash resource (using the eck-logstash Chart) | `false` | +| `eck-apm-server.enabled` | If `true`, create a standalone Elastic APM Server resource (using the eck-apm-server Chart) | `false` | + +Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`. + +Alternatively, a YAML file that specifies the values for the above parameters can be provided while installing the chart. For example, + +```console +helm install my-release -f values.yaml . +``` + +## Contributing + +This chart is maintained at [github.com/elastic/cloud-on-k8s](https://github.com/elastic/cloud-on-k8s/tree/main/deploy/eck-stack). diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/.helmignore b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/.helmignore new file mode 100644 index 00000000..f1568daf --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/.helmignore @@ -0,0 +1,24 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +templates/tests diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/Chart.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/Chart.yaml new file mode 100644 index 00000000..fcba2316 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/Chart.yaml @@ -0,0 +1,10 @@ +apiVersion: v2 +description: Elastic Agent managed by the ECK operator +icon: https://images.contentstack.io/v3/assets/bltefdd0b53724fa2ce/blt77c2da6e0198746e/620ac24e6662ca0a6f617114/icon-agent-32-color.svg +kubeVersion: '>= 1.21.0-0' +name: eck-agent +sources: +- https://github.com/elastic/cloud-on-k8s +- https://github.com/elastic/elastic-agent +type: application +version: 0.19.1 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/LICENSE b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/LICENSE new file mode 100644 index 00000000..92503a72 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/LICENSE @@ -0,0 +1,93 @@ +Elastic License 2.0 + +URL: https://www.elastic.co/licensing/elastic-license + +## Acceptance + +By using the software, you agree to all of the terms and conditions below. + +## Copyright License + +The licensor grants you a non-exclusive, royalty-free, worldwide, +non-sublicensable, non-transferable license to use, copy, distribute, make +available, and prepare derivative works of the software, in each case subject to +the limitations and conditions below. + +## Limitations + +You may not provide the software to third parties as a hosted or managed +service, where the service provides users with access to any substantial set of +the features or functionality of the software. + +You may not move, change, disable, or circumvent the license key functionality +in the software, and you may not remove or obscure any functionality in the +software that is protected by the license key. + +You may not alter, remove, or obscure any licensing, copyright, or other notices +of the licensor in the software. Any use of the licensor’s trademarks is subject +to applicable law. + +## Patents + +The licensor grants you a license, under any patent claims the licensor can +license, or becomes able to license, to make, have made, use, sell, offer for +sale, import and have imported the software, in each case subject to the +limitations and conditions in this license. This license does not cover any +patent claims that you cause to be infringed by modifications or additions to +the software. If you or your company make any written claim that the software +infringes or contributes to infringement of any patent, your patent license for +the software granted under these terms ends immediately. If your company makes +such a claim, your patent license ends immediately for work on behalf of your +company. + +## Notices + +You must ensure that anyone who gets a copy of any part of the software from you +also gets a copy of these terms. + +If you modify the software, you must include in any modified copies of the +software prominent notices stating that you have modified the software. + +## No Other Rights + +These terms do not imply any licenses other than those expressly granted in +these terms. + +## Termination + +If you use the software in violation of these terms, such use is not licensed, +and your licenses will automatically terminate. If the licensor provides you +with a notice of your violation, and you cease all violation of this license no +later than 30 days after you receive that notice, your licenses will be +reinstated retroactively. However, if you violate these terms after such +reinstatement, any additional violation of these terms will cause your licenses +to terminate automatically and permanently. + +## No Liability + +*As far as the law allows, the software comes as is, without any warranty or +condition, and the licensor will not be liable to you for any damages arising +out of these terms or the use or nature of the software, under any kind of +legal claim.* + +## Definitions + +The **licensor** is the entity offering these terms, and the **software** is the +software the licensor makes available under these terms, including any portion +of it. + +**you** refers to the individual or entity agreeing to these terms. + +**your company** is any legal entity, sole proprietorship, or other kind of +organization that you work for, plus all organizations that have control over, +are under the control of, or are under common control with that +organization. **control** means ownership of substantially all the assets of an +entity, or the power to direct its management and policies by vote, contract, or +otherwise. Control can be direct or indirect. + +**your licenses** are all the licenses granted to you for the software under +these terms. + +**use** means anything you do with the software requiring one of your licenses. + +**trademark** means trademarks, service marks, and similar rights. \ No newline at end of file diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/examples/fleet-agents.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/examples/fleet-agents.yaml new file mode 100644 index 00000000..d93cb99b --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/examples/fleet-agents.yaml @@ -0,0 +1,24 @@ +# The following example should only be used in conjunction with the 'eck-fleet-server' Helm Chart, +# and shows how the Agents can be deployed as a daemonset, and controlled by Fleet Server. +# +version: 9.4.2 + +# This must match the name of an Agent policy. +policyID: eck-agent +# This must match the name of the fleet server installed from eck-fleet-server chart. +fleetServerRef: + name: eck-fleet-server +kibanaRef: + name: eck-kibana +mode: fleet +# elasticsearchRefs must be empty when fleet mode is enabled. +elasticsearchRefs: [] +daemonSet: + podTemplate: + spec: + serviceAccountName: elastic-agent + hostNetwork: true + dnsPolicy: ClusterFirstWithHostNet + automountServiceAccountToken: true + securityContext: + runAsUser: 0 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/examples/system-integration.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/examples/system-integration.yaml new file mode 100644 index 00000000..3d94c3d2 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/examples/system-integration.yaml @@ -0,0 +1,133 @@ +# The following example should only be used in Agent "standalone" mode, +# and should not be used when Agent is used with Fleet Server. +# +version: 9.4.2 +elasticsearchRefs: +- name: eck-elasticsearch +daemonSet: + podTemplate: + spec: + containers: + - name: agent + securityContext: + runAsUser: 0 + volumeMounts: + - name: agent-data + mountPath: /usr/share/elastic-agent/data/elastic-agent-08e204/run +config: + id: 488e0b80-3634-11eb-8208-57893829af4e + revision: 2 + agent: + monitoring: + enabled: true + use_output: default + logs: true + metrics: true + inputs: + - id: 4917ade0-3634-11eb-8208-57893829af4e + name: system-1 + revision: 1 + type: system/metrics + use_output: default + meta: + package: + name: system + version: 9.4.2 + data_stream: + namespace: default + streams: + - id: system/metrics-system.cpu + data_stream: + dataset: system.cpu + type: metrics + metricsets: + - cpu + cpu.metrics: + - percentages + - normalized_percentages + period: 10s + - id: system/metrics-system.diskio + data_stream: + dataset: system.diskio + type: metrics + metricsets: + - diskio + diskio.include_devices: null + period: 10s + - id: system/metrics-system.filesystem + data_stream: + dataset: system.filesystem + type: metrics + metricsets: + - filesystem + period: 1m + processors: + - drop_event.when.regexp: + system.filesystem.mount_point: ^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/) + - id: system/metrics-system.fsstat + data_stream: + dataset: system.fsstat + type: metrics + metricsets: + - fsstat + period: 1m + processors: + - drop_event.when.regexp: + system.fsstat.mount_point: ^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/) + - id: system/metrics-system.load + data_stream: + dataset: system.load + type: metrics + metricsets: + - load + period: 10s + - id: system/metrics-system.memory + data_stream: + dataset: system.memory + type: metrics + metricsets: + - memory + period: 10s + - id: system/metrics-system.network + data_stream: + dataset: system.network + type: metrics + metricsets: + - network + period: 10s + network.interfaces: null + - id: system/metrics-system.process + data_stream: + dataset: system.process + type: metrics + metricsets: + - process + period: 10s + process.include_top_n.by_cpu: 5 + process.include_top_n.by_memory: 5 + process.cmdline.cache.enabled: true + process.cgroups.enabled: false + process.include_cpu_ticks: false + processes: + - .* + - id: system/metrics-system.process_summary + data_stream: + dataset: system.process_summary + type: metrics + metricsets: + - process_summary + period: 10s + - id: system/metrics-system.socket_summary + data_stream: + dataset: system.socket_summary + type: metrics + metricsets: + - socket_summary + period: 10s + - id: system/metrics-system.uptime + data_stream: + dataset: system.uptime + type: metrics + metricsets: + - uptime + period: 10s diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/NOTES.txt b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/NOTES.txt new file mode 100644 index 00000000..cfd41883 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/NOTES.txt @@ -0,0 +1,6 @@ + +1. Check Elastic Agent status + $ kubectl get agent {{ include "elasticagent.fullname" . }} -n {{ .Release.Namespace }} + +2. Check Elastic Agent pod status + $ kubectl get pods --namespace={{ .Release.Namespace }} -l agent.k8s.elastic.co/name={{ include "elasticagent.fullname" . }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/_helpers.tpl b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/_helpers.tpl new file mode 100644 index 00000000..748ca7dd --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/_helpers.tpl @@ -0,0 +1,51 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "elasticagent.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "elasticagent.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "elasticagent.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "elasticagent.labels" -}} +helm.sh/chart: {{ include "elasticagent.chart" . }} +{{ include "elasticagent.selectorLabels" . }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- if .Values.labels }} +{{ toYaml .Values.labels }} +{{- end }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "elasticagent.selectorLabels" -}} +app.kubernetes.io/name: {{ include "elasticagent.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/cluster-role-binding.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/cluster-role-binding.yaml new file mode 100644 index 00000000..762a59dc --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/cluster-role-binding.yaml @@ -0,0 +1,33 @@ +{{- with .Values.clusterRoleBinding }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: {{ .name }} + labels: + {{- include "elasticagent.labels" $ | nindent 4 }} + {{- with .labels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if or $.Values.annotations .annotations }} + annotations: + {{- with $.Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- end }} +{{- with .subjects }} +subjects: +{{- range . }} + - kind: {{ .kind }} + name: {{ .name }} + namespace: {{ .namespace | default $.Release.Namespace | quote }} +{{- end }} +{{- end }} +roleRef: + kind: {{ .roleRef.kind }} + name: {{ .roleRef.name }} + apiGroup: {{ .roleRef.apiGroup }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/cluster-role.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/cluster-role.yaml new file mode 100644 index 00000000..5d97ec7a --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/cluster-role.yaml @@ -0,0 +1,22 @@ +{{- with .Values.clusterRole }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: {{ .name }} + labels: + {{- include "elasticagent.labels" $ | nindent 4 }} + {{- with .labels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if or $.Values.annotations .annotations }} + annotations: + {{- with $.Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- end }} +rules: {{- toYaml .rules | nindent 2 }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/elastic-agent.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/elastic-agent.yaml new file mode 100644 index 00000000..9017e5bb --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/elastic-agent.yaml @@ -0,0 +1,89 @@ +--- +apiVersion: agent.k8s.elastic.co/v1alpha1 +kind: Agent +metadata: + name: {{ include "elasticagent.fullname" . }} + labels: + {{- include "elasticagent.labels" $ | nindent 4 }} + annotations: + eck.k8s.elastic.co/license: basic + {{- with .Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + version: {{ required "An Elastic Agent version is required" (or ((.Values.spec).version) (.Values.version)) }} + {{- $daemonSet := (or (hasKey (.Values.spec) "daemonSet") (hasKey .Values "daemonSet")) }} + {{- $deployment := (or (hasKey (.Values.spec) "deployment") (hasKey .Values "deployment")) }} + {{- $statefulSet := (or (hasKey (.Values.spec) "statefulSet") (hasKey .Values "statefulSet")) }} + {{- if and (not $daemonSet) (not $deployment) (not $statefulSet) }} + {{ fail "At least one of daemonSet, deployment or statefulSet is required" }} + {{- end }} + {{- if $daemonSet }} + {{- $ds := or ((.Values.spec).daemonSet) (.Values.daemonSet) }} + daemonSet: + {{- /* This is required to render the empty daemonset ( {} ) properly */}} + {{- $ds | default dict | toYaml | nindent 4 }} + {{- end }} + {{- if $deployment }} + {{- $deploy := or ((.Values.spec).deployment) (.Values.deployment) }} + deployment: + {{- /* This is required to render the empty deployment ( {} ) properly */}} + {{- $deploy | default dict | toYaml | nindent 4 }} + {{- end }} + {{- if $statefulSet }} + {{- $sts := or ((.Values.spec).statefulSet) (.Values.statefulSet) }} + statefulSet: + {{- /* This is required to render the empty statefulSet ( {} ) properly */}} + {{- $sts | default dict | toYaml | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).image) (.Values.image) }} + image: {{ . }} + {{- end }} + {{- with or ((.Values.spec).elasticsearchRefs) (.Values.elasticsearchRefs) }} + elasticsearchRefs: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).kibanaRef) (.Values.kibanaRef) }} + kibanaRef: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).fleetServerRef) (.Values.fleetServerRef) }} + fleetServerRef: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- $config := or ((.Values.spec).config) (.Values.config) }} + {{- $configRef := or ((.Values.spec).configRef) (.Values.configRef) }} + {{- if and $config $configRef }} + {{ fail "Only one of config and configRef can be specified" }} + {{- end }} + {{- with $config }} + config: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with $configRef }} + configRef: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).mode) (.Values.mode) }} + mode: {{ . }} + {{- end }} + {{- with or ((.Values.spec).fleetServerEnabled) (.Values.fleetServerEnabled) }} + fleetServerEnabled: {{ . }} + {{- end }} + {{- with or ((.Values.spec).http) (.Values.http) }} + http: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).policyID) (.Values.policyID) }} + policyID: {{ . }} + {{- end }} + {{- with or ((.Values.spec).secureSettings) (.Values.secureSettings) }} + secureSettings: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).revisionHistoryLimit) (.Values.revisionHistoryLimit) }} + revisionHistoryLimit: {{ . }} + {{- end }} + {{- with or (((.Values.spec).serviceAccount).name) ((.Values.serviceAccount).name) }} + serviceAccountName: {{ . }} + {{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/extra-objects.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/extra-objects.yaml new file mode 100644 index 00000000..c385106c --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/extra-objects.yaml @@ -0,0 +1,5 @@ +{{- range .Values.extraObjects }} +--- +{{ tpl . $ }} +{{- end }} + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/service-account.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/service-account.yaml new file mode 100644 index 00000000..e8bdf0b5 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/templates/service-account.yaml @@ -0,0 +1,22 @@ +{{- with .Values.serviceAccount }} +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ .name }} + namespace: {{ .namespace | default $.Release.Namespace | quote }} + labels: + {{- include "elasticagent.labels" $ | nindent 4 }} + {{- with .labels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if or $.Values.annotations .annotations }} + annotations: + {{- with $.Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- end }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/values.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/values.yaml new file mode 100644 index 00000000..a52c37ac --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-agent/values.yaml @@ -0,0 +1,282 @@ +--- +# Default values for eck-agent. +# This is a YAML-formatted file. + +# Overridable names of the Elastic Agent resource. +# By default, this is the Release name set for the chart, +# followed by 'eck-agent'. +# +# nameOverride will override the name of the Chart with the name set here, +# so nameOverride: quickstart, would convert to '{{ Release.name }}-quickstart' +# +# nameOverride: "quickstart" +# +# fullnameOverride will override both the release name, and the chart name, +# and will name the Fleet Agent resource exactly as specified. +# +# fullnameOverride: "quickstart" + +# Version of Elastic Agent. +# +version: 9.4.2 + +# Labels that will be applied to Elastic Agent. +# +labels: {} + +# Annotations that will be applied to Elastic Agent. +# +annotations: {} + +# Elastic Agent image to deploy. +# Supports both tag and digest formats. +# image: docker.elastic.co/beats/elastic-agent:9.4.2 +# image: docker.elastic.co/beats/elastic-agent:9.4.2@sha256: +# image: docker.elastic.co/beats/elastic-agent@sha256: + +# ** Deprecation Notice ** +# The previous versions of this Helm Chart simply used the `spec` field here +# and allowed the user to specify any fields below `spec` that were templated directly +# into the final Kibana manifest. This is no longer the preferred way to specify these +# fields and each field that is supported underneath `spec` is now directly specified +# in this values file. Currently both patterns are supported for backwards compatibility +# but we plan to remove the `spec` field in the future. +# spec: {} + +# Referenced resources are below and depending on the setup, at least one is required for a functional Agent. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-configuration.html#k8s-elastic-agent-fleet-configuration-setting-referenced-resources +# +# Reference to ECK-managed Kibana instance. +# +# kibanaRef: +# name: quickstart + # Optional namespace reference to Kibana instance. + # If not specified, then the namespace of the Agent instance + # will be assumed. + # + # namespace: default + +# Reference to ECK-managed Elasticsearch instance. +# +elasticsearchRefs: +- name: eck-elasticsearch + # Optional namespace reference to Elasticsearch instance. + # If not specified, then the namespace of the Agent instance + # will be assumed. + # + # namespace: default + # + # Optional secretName referencing an existing Kubernetes secret that contains connection information + # for associating an Agent instance to a remote Elasticsearch instance not managed by ECK. + # The referenced secret must contain the following: + # - `url`: the URL to reach the Elastic resource + # - `username`: the username of the user to be authenticated to the Elastic resource + # - `password`: the password of the user to be authenticated to the Elastic resource + # - `ca.crt`: the CA certificate in PEM format (optional) + # - `api-key`: the key to authenticate against the Elastic resource instead of a username and password + # This field cannot be used in combination with the other fields name, namespace or serviceName. + # + # secretName: my-remote-es-credentials + +# Reference to ECK-managed Fleet Server instance. +# +# fleetServerRef: +# name: eck-fleet-server + # Optional namespace reference to Fleet Server instance. + # If not specified, then the namespace of the Agent instance + # will be assumed. + # + # namespace: default + +# The Elastic Agent configuration, the ECK equivalent to agent.yml +# NOTE: The `config` and `configRef` fields are mutually exclusive. Only one of them should be defined at a time, +# as using both may cause conflicts. +# +# Configuration of Agent, specifically used in Agent standalone mode. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-configuration.html +# +config: null + +# Reference a configuration in a Secret. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-configuration.html +# +# configRef: +# secretName: "" + +# The mode of Agent to use. Only set to "fleet" when Fleet Server is enabled. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-configuration.html#k8s-elastic-agent-fleet-configuration-fleet-mode-and-fleet-server +# +# mode: "fleet" + +# fleetServerEnabled determines whether the Agent will be run as the Fleet Server. +# +# NOTE: Both `mode: fleet` and `fleetServerEnabled: true` need to be set for Fleet Server to be enabled. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-configuration.html#k8s-elastic-agent-fleet-configuration-fleet-mode-and-fleet-server +# +fleetServerEnabled: false + +# The HTTP layer configuration for the Fleet Server Service. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-configuration.html#k8s-elastic-agent-fleet-configuration-customize-fleet-server-service +# +# http: + +# policyID determines into which Agent Policy this Agent will be enrolled. +# policyID: eck-agent + +# DaemonSet, StatefulSet, or Deployment specification for Agent. +# At least one is required of [daemonSet, deployment, statefulSet]. +# No default is currently set, refer to https://github.com/elastic/cloud-on-k8s/issues/7429. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-configuration.html#k8s-elastic-agent-fleet-configuration-chose-the-deployment-model +# +# deployment: +# podTemplate: +# spec: +# containers: +# - name: agent +# securityContext: +# runAsUser: 0 +# daemonSet: +# podTemplate: +# spec: +# containers: +# - name: agent +# securityContext: +# runAsUser: 0 +# statefulSet: +# podTemplate: +# spec: +# containers: +# - name: agent +# securityContext: +# runAsUser: 0 + +# SecureSettings is a list of references to Kubernetes Secrets containing sensitive configuration options for Elastic Agent. +secureSettings: [] +# - secretName: my-secret-with-secure-settings + +# Number of revisions to retain to allow rollback in the underlying Deployment. +# If not set Kubernetes sets this to 10 by default. +# +# revisionHistoryLimit: 2 + +# ServiceAccount to be used by Elastic Agent. Some Elastic Agent features, such as the Kubernetes integration, +# require that Agent Pods interact with Kubernetes APIs. This functionality requires specific permissions +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-configuration.html#k8s-elastic-agent-fleet-configuration-role-based-access-control +# +serviceAccount: + name: elastic-agent + # { .Release.Namespace } is used here by default, but can be specified. + # namespace: optional-namespace + +# ClusterRoleBinding to be used by Elastic Agent. Similar to ServiceAccount, this is required in some scenarios. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-configuration.html#k8s-elastic-agent-fleet-configuration-role-based-access-control +# +clusterRoleBinding: + name: elastic-agent + subjects: + - kind: ServiceAccount + name: elastic-agent + # { .Release.Namespace } is used here by default, but can be specified. + # namespace: default + roleRef: + kind: ClusterRole + name: elastic-agent + apiGroup: rbac.authorization.k8s.io + +# ClusterRole to be used by Elastic Agent. Similar to ServiceAccount, this is required in some scenarios. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-configuration.html#k8s-elastic-agent-fleet-configuration-role-based-access-control +# +clusterRole: + name: elastic-agent + rules: + - apiGroups: [""] + resources: + - pods + - nodes + - namespaces + - events + - services + - configmaps + verbs: + - get + - watch + - list + - apiGroups: ["events.k8s.io"] + resources: + - events + verbs: + - get + - watch + - list + - apiGroups: ["coordination.k8s.io"] + resources: + - leases + verbs: + - get + - create + - update + - nonResourceURLs: + - "/metrics" + verbs: + - get + - apiGroups: ["extensions"] + resources: + - replicasets + verbs: + - "get" + - "list" + - "watch" + - apiGroups: + - "apps" + resources: + - statefulsets + - deployments + - replicasets + - daemonsets + verbs: + - "get" + - "list" + - "watch" + - apiGroups: + - "" + resources: + - nodes/stats + verbs: + - get + - nonResourceURLs: + - "/metrics" + verbs: + - get + - apiGroups: + - "batch" + resources: + - jobs + - cronjobs + verbs: + - "get" + - "list" + - "watch" + - apiGroups: + - "storage.k8s.io" + resources: + - storageclasses + verbs: + - "get" + - "list" + - "watch" + +# extraObjects allows injecting additional Kubernetes resources into the chart. +# These resources will be created/deleted alongside the chart release. +# The value is a list of strings, each string is a YAML manifest. +# Helm templating is supported within each manifest. +# Example: +# extraObjects: +# - | +# apiVersion: v1 +# kind: ConfigMap +# metadata: +# name: {{ include "elasticagent.fullname" . }}-extra-config +# namespace: {{ .Release.Namespace }} +# data: +# key: value +extraObjects: [] diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/.helmignore b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/.helmignore new file mode 100644 index 00000000..f1568daf --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/.helmignore @@ -0,0 +1,24 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +templates/tests diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/Chart.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/Chart.yaml new file mode 100644 index 00000000..f8b6dd84 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/Chart.yaml @@ -0,0 +1,10 @@ +apiVersion: v2 +description: Elastic APM Server managed by the ECK operator +icon: https://helm.elastic.co/icons/apm.png +kubeVersion: '>= 1.21.0-0' +name: eck-apm-server +sources: +- https://github.com/elastic/cloud-on-k8s +- https://github.com/elastic/apm-server +type: application +version: 0.19.1 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/LICENSE b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/LICENSE new file mode 100644 index 00000000..92503a72 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/LICENSE @@ -0,0 +1,93 @@ +Elastic License 2.0 + +URL: https://www.elastic.co/licensing/elastic-license + +## Acceptance + +By using the software, you agree to all of the terms and conditions below. + +## Copyright License + +The licensor grants you a non-exclusive, royalty-free, worldwide, +non-sublicensable, non-transferable license to use, copy, distribute, make +available, and prepare derivative works of the software, in each case subject to +the limitations and conditions below. + +## Limitations + +You may not provide the software to third parties as a hosted or managed +service, where the service provides users with access to any substantial set of +the features or functionality of the software. + +You may not move, change, disable, or circumvent the license key functionality +in the software, and you may not remove or obscure any functionality in the +software that is protected by the license key. + +You may not alter, remove, or obscure any licensing, copyright, or other notices +of the licensor in the software. Any use of the licensor’s trademarks is subject +to applicable law. + +## Patents + +The licensor grants you a license, under any patent claims the licensor can +license, or becomes able to license, to make, have made, use, sell, offer for +sale, import and have imported the software, in each case subject to the +limitations and conditions in this license. This license does not cover any +patent claims that you cause to be infringed by modifications or additions to +the software. If you or your company make any written claim that the software +infringes or contributes to infringement of any patent, your patent license for +the software granted under these terms ends immediately. If your company makes +such a claim, your patent license ends immediately for work on behalf of your +company. + +## Notices + +You must ensure that anyone who gets a copy of any part of the software from you +also gets a copy of these terms. + +If you modify the software, you must include in any modified copies of the +software prominent notices stating that you have modified the software. + +## No Other Rights + +These terms do not imply any licenses other than those expressly granted in +these terms. + +## Termination + +If you use the software in violation of these terms, such use is not licensed, +and your licenses will automatically terminate. If the licensor provides you +with a notice of your violation, and you cease all violation of this license no +later than 30 days after you receive that notice, your licenses will be +reinstated retroactively. However, if you violate these terms after such +reinstatement, any additional violation of these terms will cause your licenses +to terminate automatically and permanently. + +## No Liability + +*As far as the law allows, the software comes as is, without any warranty or +condition, and the licensor will not be liable to you for any damages arising +out of these terms or the use or nature of the software, under any kind of +legal claim.* + +## Definitions + +The **licensor** is the entity offering these terms, and the **software** is the +software the licensor makes available under these terms, including any portion +of it. + +**you** refers to the individual or entity agreeing to these terms. + +**your company** is any legal entity, sole proprietorship, or other kind of +organization that you work for, plus all organizations that have control over, +are under the control of, or are under common control with that +organization. **control** means ownership of substantially all the assets of an +entity, or the power to direct its management and policies by vote, contract, or +otherwise. Control can be direct or indirect. + +**your licenses** are all the licenses granted to you for the software under +these terms. + +**use** means anything you do with the software requiring one of your licenses. + +**trademark** means trademarks, service marks, and similar rights. \ No newline at end of file diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/examples/jaeger-with-http-configuration.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/examples/jaeger-with-http-configuration.yaml new file mode 100644 index 00000000..61ae9345 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/examples/jaeger-with-http-configuration.yaml @@ -0,0 +1,29 @@ +--- +# Version of APM Server. +# +version: 9.4.2 + +# Count of APM Server replicas to create. +# +count: 1 + +config: + name: elastic-apm + apm-server.jaeger.grpc.enabled: true + apm-server.jaeger.grpc.host: "0.0.0.0:14250" + +# Reference to ECK-managed Elasticsearch resource. +# +elasticsearchRef: + name: eck-elasticsearch +http: + service: + spec: + ports: + - name: http + port: 8200 + targetPort: 8200 + - name: grpc + port: 14250 + targetPort: 14250 + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/NOTES.txt b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/NOTES.txt new file mode 100644 index 00000000..42ab52cb --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/NOTES.txt @@ -0,0 +1,6 @@ + +1. Check APM Server status + $ kubectl get apmserver {{ include "apm-server.fullname" . }} -n {{ .Release.Namespace }} + +2. Check APM Server pod status + $ kubectl get pods --namespace={{ .Release.Namespace }} -l apm.k8s.elastic.co/name={{ include "apm-server.fullname" . }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/_helpers.tpl b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/_helpers.tpl new file mode 100644 index 00000000..d06ca3f4 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/_helpers.tpl @@ -0,0 +1,51 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "apm-server.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "apm-server.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "apm-server.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "apm-server.labels" -}} +helm.sh/chart: {{ include "apm-server.chart" . }} +{{ include "apm-server.selectorLabels" . }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- if .Values.labels }} +{{ toYaml .Values.labels }} +{{- end }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "apm-server.selectorLabels" -}} +app.kubernetes.io/name: {{ include "apm-server.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/apmserver.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/apmserver.yaml new file mode 100644 index 00000000..f3dd5ba9 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/apmserver.yaml @@ -0,0 +1,53 @@ +--- +apiVersion: apm.k8s.elastic.co/v1 +kind: ApmServer +metadata: + name: {{ include "apm-server.fullname" . }} + labels: + {{- include "apm-server.labels" . | nindent 4 }} + annotations: + eck.k8s.elastic.co/license: basic + {{- with .Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + version: {{ required "An APM Server version is required" .Values.version }} + count: {{ required "A pod count is required" .Values.count }} + {{- with .Values.image }} + image: {{ . }} + {{- end }} + {{- with .Values.serviceAccountName }} + serviceAccountName: {{ . }} + {{- end }} + {{- with .Values.revisionHistoryLimit }} + revisionHistoryLimit: {{ . }} + {{- end }} + + {{- with .Values.config }} + config: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .Values.http }} + http: + {{- toYaml . | nindent 4 }} + {{- end }} + + {{- with .Values.elasticsearchRef }} + elasticsearchRef: + {{- toYaml . | nindent 4 }} + {{- end }} + + {{- with .Values.kibanaRef }} + kibanaRef: + {{- toYaml . | nindent 4 }} + {{- end }} + + {{- with .Values.podTemplate }} + podTemplate: + {{- toYaml . | nindent 4 }} + {{- end }} + + {{- with .Values.secureSettings }} + secureSettings: + {{- toYaml . | nindent 2 }} + {{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/extra-objects.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/extra-objects.yaml new file mode 100644 index 00000000..c385106c --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/templates/extra-objects.yaml @@ -0,0 +1,5 @@ +{{- range .Values.extraObjects }} +--- +{{ tpl . $ }} +{{- end }} + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/values.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/values.yaml new file mode 100644 index 00000000..ecb13470 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-apm-server/values.yaml @@ -0,0 +1,126 @@ +--- +# Default values for eck-apm-server. +# This is a YAML-formatted file. + +# Overridable names of the APM Server resource. +# By default, this is the Release name set for the chart, +# followed by 'eck-apm-server'. +# +# nameOverride will override the name of the Chart with the name set here, +# so nameOverride: quickstart, would convert to '{{ Release.name }}-quickstart' +# +# nameOverride: "quickstart" +# +# fullnameOverride will override both the release name, and the chart name, +# and will name the APM Server resource exactly as specified. +# +# fullnameOverride: "quickstart" + +# Version of APM Server. +# +version: 9.4.2 + +# APM Server Docker image to deploy. +# Supports both tag and digest formats. +# image: docker.elastic.co/apm/apm-server:9.4.2-SNAPSHOT +# image: docker.elastic.co/apm/apm-server:9.4.2-SNAPSHOT@sha256: +# image: docker.elastic.co/apm/apm-server@sha256: + +# Used to check access from the current resource to a resource (for ex. a remote Elasticsearch cluster) in a different namespace. +# Can only be used if ECK is enforcing RBAC on references. +# +# serviceAccountName: "" + +# Labels that will be applied to APM Server. +# +labels: {} + +# Annotations that will be applied to APM Server. +# +annotations: {} + +# Count of APM Server replicas to create. +# +count: 1 + +# The APM Server configuration, the ECK equivalent to apm-server.yml +# ref: https://www.elastic.co/guide/en/apm/server/current/configuring-howto-apm-server.html +# +config: {} + +# Settings to control how APM Server will be accessed. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-accessing-elastic-services.html +# +http: {} + # service: + # metadata: + # labels: + # my-custom: label + # spec: + # ports: + # - name: http + # port: 8200 + # targetPort: 8200 + +# Reference to ECK-managed Elasticsearch resource. +# +elasticsearchRef: {} + # name: eck-elasticsearch + # Optional namespace reference to Elasticsearch resource. + # If not specified, then the namespace of the APM Server resource + # will be assumed. + # + # namespace: default + # + # Optional secretName referencing an existing Kubernetes secret that contains connection information + # for associating an APM Server instance to a remote Elasticsearch instance not managed by ECK. + # The referenced secret must contain the following: + # - `url`: the URL to reach the Elastic resource + # - `username`: the username of the user to be authenticated to the Elastic resource + # - `password`: the password of the user to be authenticated to the Elastic resource + # - `ca.crt`: the CA certificate in PEM format (optional) + # This field cannot be used in combination with the other fields name, namespace or serviceName. + # + # secretName: my-remote-es-credentials + +# Optional reference to ECK-managed Kibana resource which allows ECK to +# automatically configure the Kibana endpoint as described in +# https://www.elastic.co/guide/en/apm/server/current/setup-kibana-endpoint.html +# +# kibanaRef: +# name: eck-kibana +# # Optional namespace reference to Kibana resource. +# # If not specified, then the namespace of the APM Server resource +# # will be assumed. +# # +# # namespace: default + +# Set podTemplate to customize the pod used by APM Server +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-customize-pods.html +# +podTemplate: {} + +# Number of revisions to retain to allow rollback in the underlying Deployment. +# If not set Kubernetes sets this to 10 by default. +# +# revisionHistoryLimit: 2 + +# SecureSettings is a list of references to Kubernetes Secrets containing sensitive configuration options for APM Server. +secureSettings: [] +# - secretName: my-secret-with-secure-settings + +# extraObjects allows injecting additional Kubernetes resources into the chart. +# These resources will be created/deleted alongside the chart release. +# The value is a list of strings, each string is a YAML manifest. +# Helm templating is supported within each manifest. +# Example: +# extraObjects: +# - | +# apiVersion: v1 +# kind: ConfigMap +# metadata: +# name: {{ include "apm-server.fullname" . }}-extra-config +# namespace: {{ .Release.Namespace }} +# data: +# key: value +extraObjects: [] diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/.helmignore b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/.helmignore new file mode 100644 index 00000000..f1568daf --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/.helmignore @@ -0,0 +1,24 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +templates/tests diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/Chart.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/Chart.yaml new file mode 100644 index 00000000..f56f87cc --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/Chart.yaml @@ -0,0 +1,8 @@ +apiVersion: v2 +description: AutoOps Agent Policy managed by the ECK operator +kubeVersion: '>= 1.21.0-0' +name: eck-autoops-agent-policy +sources: +- https://github.com/elastic/cloud-on-k8s +type: application +version: 0.19.1 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/LICENSE b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/LICENSE new file mode 100644 index 00000000..7be32fc6 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/LICENSE @@ -0,0 +1,94 @@ +Elastic License 2.0 + +URL: https://www.elastic.co/licensing/elastic-license + +## Acceptance + +By using the software, you agree to all of the terms and conditions below. + +## Copyright License + +The licensor grants you a non-exclusive, royalty-free, worldwide, +non-sublicensable, non-transferable license to use, copy, distribute, make +available, and prepare derivative works of the software, in each case subject to +the limitations and conditions below. + +## Limitations + +You may not provide the software to third parties as a hosted or managed +service, where the service provides users with access to any substantial set of +the features or functionality of the software. + +You may not move, change, disable, or circumvent the license key functionality +in the software, and you may not remove or obscure any functionality in the +software that is protected by the license key. + +You may not alter, remove, or obscure any licensing, copyright, or other notices +of the licensor in the software. Any use of the licensor's trademarks is subject +to applicable law. + +## Patents + +The licensor grants you a license, under any patent claims the licensor can +license, or becomes able to license, to make, have made, use, sell, offer for +sale, import and have imported the software, in each case subject to the +limitations and conditions in this license. This license does not cover any +patent claims that you cause to be infringed by modifications or additions to +the software. If you or your company make any written claim that the software +infringes or contributes to infringement of any patent, your patent license for +the software granted under these terms ends immediately. If your company makes +such a claim, your patent license ends immediately for work on behalf of your +company. + +## Notices + +You must ensure that anyone who gets a copy of any part of the software from you +also gets a copy of these terms. + +If you modify the software, you must include in any modified copies of the +software prominent notices stating that you have modified the software. + +## No Other Rights + +These terms do not imply any licenses other than those expressly granted in +these terms. + +## Termination + +If you use the software in violation of these terms, such use is not licensed, +and your licenses will automatically terminate. If the licensor provides you +with a notice of your violation, and you cease all violation of this license no +later than 30 days after you receive that notice, your licenses will be +reinstated retroactively. However, if you violate these terms after such +reinstatement, any additional violation of these terms will cause your licenses +to terminate automatically and permanently. + +## No Liability + +*As far as the law allows, the software comes as is, without any warranty or +condition, and the licensor will not be liable to you for any damages arising +out of these terms or the use or nature of the software, under any kind of +legal claim.* + +## Definitions + +The **licensor** is the entity offering these terms, and the **software** is the +software the licensor makes available under these terms, including any portion +of it. + +**you** refers to the individual or entity agreeing to these terms. + +**your company** is any legal entity, sole proprietorship, or other kind of +organization that you work for, plus all organizations that have control over, +are under the control of, or are under common control with that +organization. **control** means ownership of substantially all the assets of an +entity, or the power to direct its management and policies by vote, contract, or +otherwise. Control can be direct or indirect. + +**your licenses** are all the licenses granted to you for the software under +these terms. + +**use** means anything you do with the software requiring one of your licenses. + +**trademark** means trademarks, service marks, and similar rights. + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/examples/basic.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/examples/basic.yaml new file mode 100644 index 00000000..47831447 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/examples/basic.yaml @@ -0,0 +1,16 @@ +--- +# Version of AutoOps Agent Policy. +# +version: 9.4.2 + +# Reference an existing Kubernetes secret holding the AutoOps configuration. +autoOpsRef: + secretName: autoops-secret + +# ResourceSelector is a label selector for the resources to be configured. +# Any Elasticsearch instances that match the selector will be configured to send data to AutoOps. +# +resourceSelector: + matchLabels: + autoops: enabled + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/NOTES.txt b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/NOTES.txt new file mode 100644 index 00000000..a2eaeece --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/NOTES.txt @@ -0,0 +1,7 @@ + +1. Check AutoOps Agent Policy status + $ kubectl get autoops {{ include "autoops.fullname" . }} -n {{ .Release.Namespace }} + +2. Check AutoOps Agent Policy details + $ kubectl describe autoops {{ include "autoops.fullname" . }} -n {{ .Release.Namespace }} + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/_helpers.tpl b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/_helpers.tpl new file mode 100644 index 00000000..c19efe59 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/_helpers.tpl @@ -0,0 +1,52 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "autoops.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "autoops.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "autoops.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "autoops.labels" -}} +helm.sh/chart: {{ include "autoops.chart" . }} +{{ include "autoops.selectorLabels" . }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- if .Values.labels }} +{{ toYaml .Values.labels }} +{{- end }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "autoops.selectorLabels" -}} +app.kubernetes.io/name: {{ include "autoops.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/autoopsagentpolicy.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/autoopsagentpolicy.yaml new file mode 100644 index 00000000..81a67b55 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/autoopsagentpolicy.yaml @@ -0,0 +1,35 @@ +--- +apiVersion: autoops.k8s.elastic.co/v1alpha1 +kind: AutoOpsAgentPolicy +metadata: + name: {{ include "autoops.fullname" . }} + labels: + {{- include "autoops.labels" . | nindent 4 }} + annotations: + {{- with .Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + version: {{ required "An AutoOps Agent Policy version is required" .Values.version }} + {{- with .Values.image }} + image: {{ . }} + {{- end }} + {{- with .Values.revisionHistoryLimit }} + revisionHistoryLimit: {{ . }} + {{- end }} + {{- with .Values.serviceAccountName }} + serviceAccountName: {{ . }} + {{- end }} + {{- with .Values.podTemplate }} + podTemplate: + {{- toYaml . | nindent 4 }} + {{- end }} + autoOpsRef: + secretName: {{ required "autoOpsRef.secretName is required to reference the AutoOps configuration secret" .Values.autoOpsRef.secretName }} + resourceSelector: + {{- required "resourceSelector is required" .Values.resourceSelector | toYaml | nindent 4 }} + {{- with .Values.namespaceSelector }} + namespaceSelector: + {{- toYaml . | nindent 4 }} + {{- end }} + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/extra-objects.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/extra-objects.yaml new file mode 100644 index 00000000..c385106c --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/templates/extra-objects.yaml @@ -0,0 +1,5 @@ +{{- range .Values.extraObjects }} +--- +{{ tpl . $ }} +{{- end }} + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/values.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/values.yaml new file mode 100644 index 00000000..2f201375 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-autoops-agent-policy/values.yaml @@ -0,0 +1,114 @@ +--- +# Default values for eck-autoops-agent-policy. +# This is a YAML-formatted file. + +# Overridable names of the AutoOps Agent Policy resource. +# By default, this is the Release name set for the chart, +# followed by 'eck-autoops-agent-policy'. +# +# nameOverride will override the name of the Chart with the name set here, +# so nameOverride: quickstart, would convert to '{{ Release.name }}-quickstart' +# +# nameOverride: "quickstart" +# +# fullnameOverride will override both the release name, and the chart name, +# and will name the AutoOps Agent Policy resource exactly as specified. +# +# fullnameOverride: "quickstart" + +# Version of AutoOps Agent Policy. +# +version: 9.4.2 + +# Labels that will be applied to AutoOps Agent Policy. +# +labels: {} + +# Annotations that will be applied to AutoOps Agent Policy. +# +annotations: {} + +# Reference an existing Kubernetes secret holding the AutoOps configuration. +# +# All of the following items can be obtained the Elastic Cloud Console (https://cloud.elastic.co/connect-cluster-services-portal) +# by selecting the ECK connect wizard and following the instructions. +# +# The referenced secret must contain the following: +# - `cloud-connected-mode-api-key`: the Cloud Connected Mode API key. This is used to register the Agent with Elastic Cloud AutoOps. +# - `autoops-otel-url`: the URL of the AutoOps OTel endpoint. This is used to send Agent data to the AutoOps platform and is region specific. +# Example: "https://otel-auto-ops.us-east-2.aws.svc.elastic.cloud" +# - `autoops-token`: the token to authenticate against the AutoOps platform and is how AutoOps knows how to connect Agent data to the +# relevant Elastic Cloud organization +# - `cloud-connected-mode-api-url`: the URL of the Cloud Connected Mode API (optional) +# +autoOpsRef: {} + # secretName: "" + +# Config holds the AutoOps Agent configuration for Elasticsearch monitoring. +# This configuration is intended to override parts of the autoops_es.yml configmap. +# See: https://github.com/elastic/elastic-agent/blob/c6eaa3c903d4357824d345ee2002123fdffbec91/internal/pkg/otel/samples/linux/autoops_es.yml +# +kubebuilder:pruning:PreserveUnknownFields +# config: {} + +# Image is the AutoOps Agent Docker image to deploy. +# Supports both tag and digest formats. +# image: "docker.elastic.co/elastic-agent/elastic-otel-collector-wolfi:9.4.2" +# image: "docker.elastic.co/elastic-agent/elastic-otel-collector-wolfi:9.4.2@sha256:" +# image: "docker.elastic.co/elastic-agent/elastic-otel-collector-wolfi@sha256:" + +# RevisionHistoryLimit is the number of revisions to retain to allow rollback in the underlying Deployment. +# revisionHistoryLimit: 2 + +# PodTemplate provides customisation options (labels, annotations, affinity rules, resource requests, and so on) for the Agent pods +# +kubebuilder:validation:Optional +# +kubebuilder:pruning:PreserveUnknownFields +# podTemplate: +# spec: +# containers: +# - name: autoops-agent +# resources: +# limits: +# memory: 400Mi +# cpu: 200m +# requests: +# memory: 400Mi +# cpu: 200m + +# ResourceSelector is a label selector for the resources to be configured. +# Any Elasticsearch instances that match the selector will be configured to send data to AutoOps. +# +resourceSelector: + matchLabels: + autoops: enabled + +# NamespaceSelector is a namespace selector for the resources to be configured. +# Any Elasticsearch instances belonging to the selected namespaces will be configured to send data to AutoOps. +# If not specified, all namespaces are selected. +# +# namespaceSelector: +# matchLabels: +# kubernetes.io/metadata.name: team-a + +# ServiceAccountName is used for RBAC checks when accessing Elasticsearch clusters +# in different namespaces. The policy can only target Elasticsearch clusters that +# the specified service account has permission to access (via 'get' verb). +# Defaults to "default" if not specified. Only enforced if operator is running with --enforce-rbac-on-refs. +# +# serviceAccountName: "" + + +# extraObjects allows injecting additional Kubernetes resources into the chart. +# These resources will be created/deleted alongside the chart release. +# The value is a list of strings, each string is a YAML manifest. +# Helm templating is supported within each manifest. +# Example: +# extraObjects: +# - | +# apiVersion: v1 +# kind: ConfigMap +# metadata: +# name: {{ include "autoops.fullname" . }}-extra-config +# namespace: {{ .Release.Namespace }} +# data: +# key: value +extraObjects: [] diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/.helmignore b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/.helmignore new file mode 100644 index 00000000..f1568daf --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/.helmignore @@ -0,0 +1,24 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +templates/tests diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/Chart.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/Chart.yaml new file mode 100644 index 00000000..568d8edf --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/Chart.yaml @@ -0,0 +1,10 @@ +apiVersion: v2 +description: Elastic Beats managed by the ECK operator +icon: https://helm.elastic.co/icons/beats.png +kubeVersion: '>= 1.20.0-0' +name: eck-beats +sources: +- https://github.com/elastic/cloud-on-k8s +- https://github.com/elastic/beats +type: application +version: 0.19.1 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/LICENSE b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/LICENSE new file mode 100644 index 00000000..92503a72 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/LICENSE @@ -0,0 +1,93 @@ +Elastic License 2.0 + +URL: https://www.elastic.co/licensing/elastic-license + +## Acceptance + +By using the software, you agree to all of the terms and conditions below. + +## Copyright License + +The licensor grants you a non-exclusive, royalty-free, worldwide, +non-sublicensable, non-transferable license to use, copy, distribute, make +available, and prepare derivative works of the software, in each case subject to +the limitations and conditions below. + +## Limitations + +You may not provide the software to third parties as a hosted or managed +service, where the service provides users with access to any substantial set of +the features or functionality of the software. + +You may not move, change, disable, or circumvent the license key functionality +in the software, and you may not remove or obscure any functionality in the +software that is protected by the license key. + +You may not alter, remove, or obscure any licensing, copyright, or other notices +of the licensor in the software. Any use of the licensor’s trademarks is subject +to applicable law. + +## Patents + +The licensor grants you a license, under any patent claims the licensor can +license, or becomes able to license, to make, have made, use, sell, offer for +sale, import and have imported the software, in each case subject to the +limitations and conditions in this license. This license does not cover any +patent claims that you cause to be infringed by modifications or additions to +the software. If you or your company make any written claim that the software +infringes or contributes to infringement of any patent, your patent license for +the software granted under these terms ends immediately. If your company makes +such a claim, your patent license ends immediately for work on behalf of your +company. + +## Notices + +You must ensure that anyone who gets a copy of any part of the software from you +also gets a copy of these terms. + +If you modify the software, you must include in any modified copies of the +software prominent notices stating that you have modified the software. + +## No Other Rights + +These terms do not imply any licenses other than those expressly granted in +these terms. + +## Termination + +If you use the software in violation of these terms, such use is not licensed, +and your licenses will automatically terminate. If the licensor provides you +with a notice of your violation, and you cease all violation of this license no +later than 30 days after you receive that notice, your licenses will be +reinstated retroactively. However, if you violate these terms after such +reinstatement, any additional violation of these terms will cause your licenses +to terminate automatically and permanently. + +## No Liability + +*As far as the law allows, the software comes as is, without any warranty or +condition, and the licensor will not be liable to you for any damages arising +out of these terms or the use or nature of the software, under any kind of +legal claim.* + +## Definitions + +The **licensor** is the entity offering these terms, and the **software** is the +software the licensor makes available under these terms, including any portion +of it. + +**you** refers to the individual or entity agreeing to these terms. + +**your company** is any legal entity, sole proprietorship, or other kind of +organization that you work for, plus all organizations that have control over, +are under the control of, or are under common control with that +organization. **control** means ownership of substantially all the assets of an +entity, or the power to direct its management and policies by vote, contract, or +otherwise. Control can be direct or indirect. + +**your licenses** are all the licenses granted to you for the software under +these terms. + +**use** means anything you do with the software requiring one of your licenses. + +**trademark** means trademarks, service marks, and similar rights. \ No newline at end of file diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/auditbeat_hosts.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/auditbeat_hosts.yaml new file mode 100644 index 00000000..420013d7 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/auditbeat_hosts.yaml @@ -0,0 +1,110 @@ +name: auditbeat +version: 9.4.2 +type: auditbeat +elasticsearchRef: + name: eck-elasticsearch +kibanaRef: + name: eck-kibana +config: + auditbeat.modules: + - module: file_integrity + paths: + - /hostfs/bin + - /hostfs/usr/bin + - /hostfs/sbin + - /hostfs/usr/sbin + - /hostfs/etc + exclude_files: + - '(?i)\.sw[nop]$' + - '~$' + - '/\.git($|/)' + scan_at_start: true + scan_rate_per_sec: 50 MiB + max_file_size: 100 MiB + hash_types: [sha1] + recursive: true + - module: auditd + audit_rules: | + # Executions + -a always,exit -F arch=b64 -S execve,execveat -k exec + + # Unauthorized access attempts (amd64 only) + -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -k access + -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -k access + + processors: + - add_cloud_metadata: {} + - add_host_metadata: {} + - add_process_metadata: + match_pids: ['process.pid'] +daemonSet: + podTemplate: + spec: + hostPID: true # Required by auditd module + dnsPolicy: ClusterFirstWithHostNet + hostNetwork: true # Allows to provide richer host metadata + automountServiceAccountToken: true # some older Beat versions are depending on this settings presence in k8s context + securityContext: + runAsUser: 0 + volumes: + - name: bin + hostPath: + path: /bin + - name: usrbin + hostPath: + path: /usr/bin + - name: sbin + hostPath: + path: /sbin + - name: usrsbin + hostPath: + path: /usr/sbin + - name: etc + hostPath: + path: /etc + - name: run-containerd + hostPath: + path: /run/containerd + type: DirectoryOrCreate + # Uncomment the below when running on GKE. See https://github.com/elastic/beats/issues/8523 for more context. + #- name: run + # hostPath: + # path: /run + #initContainers: + #- name: cos-init + # image: docker.elastic.co/beats/auditbeat:8.3.3 + # volumeMounts: + # - name: run + # mountPath: /run + # command: ['sh', '-c', 'export SYSTEMD_IGNORE_CHROOT=1 && systemctl stop systemd-journald-audit.socket && systemctl mask systemd-journald-audit.socket && systemctl restart systemd-journald'] + containers: + - name: auditbeat + securityContext: + capabilities: + add: + # Capabilities needed for auditd module + - 'AUDIT_READ' + - 'AUDIT_WRITE' + - 'AUDIT_CONTROL' + volumeMounts: + - name: bin + mountPath: /hostfs/bin + readOnly: true + - name: sbin + mountPath: /hostfs/sbin + readOnly: true + - name: usrbin + mountPath: /hostfs/usr/bin + readOnly: true + - name: usrsbin + mountPath: /hostfs/usr/sbin + readOnly: true + - name: etc + mountPath: /hostfs/etc + readOnly: true + # Directory with root filesystems of containers executed with containerd, this can be + # different with other runtimes. This volume is needed to monitor the file integrity + # of files in containers. + - name: run-containerd + mountPath: /run/containerd + readOnly: true diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/filebeat_no_autodiscover.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/filebeat_no_autodiscover.yaml new file mode 100644 index 00000000..084b70ef --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/filebeat_no_autodiscover.yaml @@ -0,0 +1,52 @@ +name: filebeat +version: 9.4.2 +type: filebeat +elasticsearchRef: + name: eck-elasticsearch +kibanaRef: + name: eck-kibana +config: + filebeat.inputs: + - type: filestream + paths: + - /var/log/containers/*.log + parsers: + - container: ~ + prospector: + scanner: + fingerprint.enabled: true + symlinks: true + file_identity.fingerprint: ~ + processors: + - add_host_metadata: {} + - add_cloud_metadata: {} +daemonSet: + podTemplate: + spec: + automountServiceAccountToken: true + terminationGracePeriodSeconds: 30 + dnsPolicy: ClusterFirstWithHostNet + hostNetwork: true # Allows to provide richer host metadata + containers: + - name: filebeat + securityContext: + runAsUser: 0 + # If using Red Hat OpenShift uncomment this: + #privileged: true + volumeMounts: + - name: varlogcontainers + mountPath: /var/log/containers + - name: varlogpods + mountPath: /var/log/pods + - name: varlibdockercontainers + mountPath: /var/lib/docker/containers + volumes: + - name: varlogcontainers + hostPath: + path: /var/log/containers + - name: varlogpods + hostPath: + path: /var/log/pods + - name: varlibdockercontainers + hostPath: + path: /var/lib/docker/containers diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/heartbeat_es_kb_health.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/heartbeat_es_kb_health.yaml new file mode 100644 index 00000000..f0034360 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/heartbeat_es_kb_health.yaml @@ -0,0 +1,23 @@ +name: heartbeat +version: 9.4.2 +type: heartbeat +elasticsearchRef: + name: eck-elasticsearch +config: + heartbeat.monitors: + - type: tcp + schedule: '@every 5s' + # This should directly match the name of the Elasticsearch instance + # with "-es-http" appended to the name. + hosts: ["elasticsearch-es-http.default.svc:9200"] + - type: tcp + schedule: '@every 5s' + # This should directly match the names of the Kibana instance + # with "-kb-http" appended to the name. + hosts: ["eck-kibana-kb-http.default.svc:5601"] +deployment: + replicas: 1 + podTemplate: + spec: + securityContext: + runAsUser: 0 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/metricbeat_hosts.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/metricbeat_hosts.yaml new file mode 100644 index 00000000..5d4ec98e --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/metricbeat_hosts.yaml @@ -0,0 +1,166 @@ +name: metricbeat +type: metricbeat +version: 9.4.2 +elasticsearchRef: + name: eck-elasticsearch +kibanaRef: + name: eck-kibana +config: + metricbeat: + autodiscover: + providers: + - hints: + default_config: {} + enabled: "true" + node: ${NODE_NAME} + type: kubernetes + modules: + - module: system + period: 10s + metricsets: + - cpu + - load + - memory + - network + - process + - process_summary + process: + include_top_n: + by_cpu: 5 + by_memory: 5 + processes: + - .* + - module: system + period: 1m + metricsets: + - filesystem + - fsstat + processors: + - drop_event: + when: + regexp: + system: + filesystem: + mount_point: ^/(sys|cgroup|proc|dev|etc|host|lib)($|/) + - module: kubernetes + period: 10s + node: ${NODE_NAME} + hosts: + - https://${NODE_NAME}:10250 + bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token + ssl: + verification_mode: none + metricsets: + - node + - system + - pod + - container + - volume + processors: + - add_cloud_metadata: {} + - add_host_metadata: {} +daemonSet: + podTemplate: + spec: + serviceAccountName: metricbeat + automountServiceAccountToken: true # some older Beat versions are depending on this settings presence in k8s context + containers: + - args: + - -e + - -c + - /etc/beat.yml + - --system.hostfs=/hostfs + name: metricbeat + volumeMounts: + - mountPath: /hostfs/sys/fs/cgroup + name: cgroup + - mountPath: /var/run/docker.sock + name: dockersock + - mountPath: /hostfs/proc + name: proc + env: + - name: NODE_NAME + valueFrom: + fieldRef: + fieldPath: spec.nodeName + dnsPolicy: ClusterFirstWithHostNet + hostNetwork: true # Allows to provide richer host metadata + securityContext: + runAsUser: 0 + terminationGracePeriodSeconds: 30 + volumes: + - hostPath: + path: /sys/fs/cgroup + name: cgroup + - hostPath: + path: /var/run/docker.sock + name: dockersock + - hostPath: + path: /proc + name: proc + +clusterRole: + # permissions needed for metricbeat + # source: https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-module-kubernetes.html + name: metricbeat + rules: + - apiGroups: + - "" + resources: + - nodes + - namespaces + - events + - pods + verbs: + - get + - list + - watch + - apiGroups: + - events.k8s.io + resources: + - events + verbs: + - get + - list + - watch + - apiGroups: + - "extensions" + resources: + - replicasets + verbs: + - get + - list + - watch + - apiGroups: + - apps + resources: + - statefulsets + - deployments + - replicasets + verbs: + - get + - list + - watch + - apiGroups: + - "" + resources: + - nodes/stats + verbs: + - get + - nonResourceURLs: + - /metrics + verbs: + - get + +serviceAccount: + name: metricbeat + +clusterRoleBinding: + name: metricbeat + subjects: + - kind: ServiceAccount + name: metricbeat + roleRef: + kind: ClusterRole + name: metricbeat + apiGroup: rbac.authorization.k8s.io diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/packetbeat_dns_http.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/packetbeat_dns_http.yaml new file mode 100644 index 00000000..bb428b53 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/examples/packetbeat_dns_http.yaml @@ -0,0 +1,37 @@ +name: packetbeat +type: packetbeat +version: 9.4.2 +elasticsearchRef: + name: eck-elasticsearch +kibanaRef: + name: eck-kibana +config: + packetbeat.interfaces.device: any + packetbeat.protocols: + - type: dns + ports: [53] + include_authorities: true + include_additionals: true + - type: http + ports: [80, 8000, 8080, 9200] + packetbeat.flows: + timeout: 30s + period: 10s + processors: + - add_cloud_metadata: {} + - add_host_metadata: {} +daemonSet: + podTemplate: + spec: + terminationGracePeriodSeconds: 30 + hostNetwork: true + automountServiceAccountToken: true # some older Beat versions are depending on this settings presence in k8s context + dnsPolicy: ClusterFirstWithHostNet + containers: + - name: packetbeat + securityContext: + runAsUser: 0 + capabilities: + add: + - NET_ADMIN + volumes: [] diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/NOTES.txt b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/NOTES.txt new file mode 100644 index 00000000..10d2dac5 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/NOTES.txt @@ -0,0 +1,6 @@ + +1. Check Beat status + $ kubectl get beat {{ include "beat.fullname" . }} -n {{ .Release.Namespace }} + +2. Check Beat pod status + $ kubectl get pods --namespace={{ .Release.Namespace }} -l beat.k8s.elastic.co/name={{ include "beat.fullname" . }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/_helpers.tpl b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/_helpers.tpl new file mode 100644 index 00000000..5e20af14 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/_helpers.tpl @@ -0,0 +1,51 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "beat.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "beat.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "beat.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "beat.labels" -}} +helm.sh/chart: {{ include "beat.chart" . }} +{{ include "beat.selectorLabels" . }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- if .Values.labels }} +{{ toYaml .Values.labels }} +{{- end }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "beat.selectorLabels" -}} +app.kubernetes.io/name: {{ include "beat.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/beats.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/beats.yaml new file mode 100644 index 00000000..a70ac9a6 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/beats.yaml @@ -0,0 +1,75 @@ +--- +apiVersion: beat.k8s.elastic.co/v1beta1 +kind: Beat +metadata: + name: {{ include "beat.fullname" . }} + labels: + {{- include "beat.labels" . | nindent 4 }} + annotations: + eck.k8s.elastic.co/license: basic + {{- with .Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + version: {{ required "A Beat version is required" (or ((.Values.spec).version) (.Values.version)) }} + {{- $daemonSet := (or (hasKey (.Values.spec) "daemonSet") (hasKey .Values "daemonSet")) }} + {{- $deployment := (or (hasKey (.Values.spec) "deployment") (hasKey .Values "deployment")) }} + {{- if and (not $daemonSet) (not $deployment) }} + {{ fail "At least one of daemonSet or deployment is required for a functional Beat" }} + {{- end }} + {{- if not (or ((.Values.spec).type) (.Values.type)) }}{{ fail "A Beat type is required" }}{{- end }} + type: {{ or ((.Values.spec).type) (.Values.type) }} + {{- if $daemonSet }} + {{- $ds := or ((.Values.spec).daemonSet) (.Values.daemonSet) }} + daemonSet: + {{- /* This is required to render the empty daemonset ( {} ) properly */}} + {{- $ds | default dict | toYaml | nindent 4 }} + {{- end }} + {{- if $deployment }} + {{- $deploy := or ((.Values.spec).deployment) (.Values.deployment) }} + deployment: + {{- /* This is required to render the empty deployment ( {} ) properly */}} + {{- $deploy | default dict | toYaml | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).image) (.Values.image) }} + image: {{ . }} + {{- end }} + {{- with or ((.Values.spec).elasticsearchRef) (.Values.elasticsearchRef) }} + elasticsearchRef: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).kibanaRef) (.Values.kibanaRef) }} + kibanaRef: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- $config := or ((.Values.spec).config) (.Values.config) }} + {{- $configRef := or ((.Values.spec).configRef) (.Values.configRef) }} + {{- if and $config $configRef }} + {{ fail "Only one of config and configRef can be specified" }} + {{- end }} + {{- with $config }} + config: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with $configRef }} + configRef: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).http) (.Values.http) }} + http: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).monitoring) (.Values.monitoring) }} + monitoring: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).secureSettings) (.Values.secureSettings) }} + secureSettings: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).revisionHistoryLimit) (.Values.revisionHistoryLimit) }} + revisionHistoryLimit: {{ . }} + {{- end }} + {{- with or (((.Values.spec).serviceAccount).name) ((.Values.serviceAccount).name) }} + serviceAccountName: {{ . }} + {{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/cluster-role-binding.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/cluster-role-binding.yaml new file mode 100644 index 00000000..d8fca15f --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/cluster-role-binding.yaml @@ -0,0 +1,35 @@ +{{- with .Values.clusterRoleBinding }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: {{ .name }} + labels: + {{- include "beat.labels" $ | nindent 4 }} + {{- with .labels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if or $.Values.annotations .annotations }} + annotations: + {{- with $.Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- end }} +{{- with .subjects }} +subjects: +{{- range . }} + - kind: {{ .kind }} + name: {{ .name }} + namespace: {{ .namespace | default $.Release.Namespace | quote }} +{{- end }} +{{- end }} +{{- with .roleRef }} +roleRef: + kind: {{ .kind }} + name: {{ .name }} + apiGroup: {{ .apiGroup }} +{{- end }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/cluster-role.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/cluster-role.yaml new file mode 100644 index 00000000..66406f63 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/cluster-role.yaml @@ -0,0 +1,22 @@ +{{- with .Values.clusterRole }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: {{ .name }} + labels: + {{- include "beat.labels" $ | nindent 4 }} + {{- with .labels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if or $.Values.annotations .annotations }} + annotations: + {{- with $.Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- end }} +rules: {{- toYaml .rules | nindent 2 }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/extra-objects.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/extra-objects.yaml new file mode 100644 index 00000000..c385106c --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/extra-objects.yaml @@ -0,0 +1,5 @@ +{{- range .Values.extraObjects }} +--- +{{ tpl . $ }} +{{- end }} + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/service-account.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/service-account.yaml new file mode 100644 index 00000000..08f21f7e --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/templates/service-account.yaml @@ -0,0 +1,23 @@ + +{{- with .Values.serviceAccount }} +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ .name }} + namespace: {{ .namespace | default $.Release.Namespace | quote }} + labels: + {{- include "beat.labels" $ | nindent 4 }} + {{- with .labels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if or $.Values.annotations .annotations }} + annotations: + {{- with $.Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- end }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/values.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/values.yaml new file mode 100644 index 00000000..5c6c89c3 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-beats/values.yaml @@ -0,0 +1,206 @@ +--- +# Default values for eck-beats. +# This is a YAML-formatted file. + +# Overridable names of the Beats resource. +# By default, this is the Release name set for the chart, +# followed by 'eck-beats'. +# +# nameOverride will override the name of the Chart with the name set here, +# so nameOverride: quickstart, would convert to '{{ Release.name }}-quickstart' +# +# nameOverride: "quickstart" +# +# fullnameOverride will override both the release name, and the chart name, +# and will name the Beats resource exactly as specified. +# +# fullnameOverride: "quickstart" + +# Version of Elastic Beats. +# +version: 9.4.2 + +# Labels that will be applied to Elastic Beats. +# +labels: {} + +# Annotations that will be applied to Elastic Beats. +# +annotations: {} + +# ** Deprecation Notice ** +# The previous versions of this Helm Chart simply used the `spec` field here +# and allowed the user to specify any fields below spec that were templated directly +# into the final Beats manifest. This is no longer the preferred way to specify these +# fields and each field that is supported underneath `spec` is now directly specified +# in this values file. Currently both patterns are supported for backwards compatibility +# but we plan to remove the `spec` field in the future. +# spec: {} + +# Type of Elastic Beats. Standard types of Beat are [filebeat,metricbeat,heartbeat,auditbeat,packetbeat,journalbeat]. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-beat-configuration.html#k8s-beat-deploy-elastic-beat +# +# Note: This is required to be set, or the release install will fail. +# +type: "" + +# Beats image to deploy. +# Supports both tag and digest formats. +# image: docker.elastic.co/beats/metricbeat:9.4.2 +# image: docker.elastic.co/beats/metricbeat:9.4.2@sha256: +# image: docker.elastic.co/beats/metricbeat@sha256: + +# Referenced resources are below and depending on the setup, at least elasticsearchRef is required for a functional Beat. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-beat-configuration.html#k8s-beat-connect-es +# +# Reference to ECK-managed Kibana instance. +# +# kibanaRef: +# name: quickstart + # Optional namespace reference to Kibana instance. + # If not specified, then the namespace of the Beats instance + # will be assumed. + # + # namespace: default + +# Reference to ECK-managed Elasticsearch instance. +# *Note* If Beat's output is intended to go to Elasticsearch and not something like Logstash, +# this elasticsearchRef must be updated to the name of the Elasticsearch instance. +# +elasticsearchRef: {} + # name: elasticsearch + # Optional namespace reference to Elasticsearch instance. + # If not specified, then the namespace of the Beats instance + # will be assumed. + # + # namespace: default + # + # Optional secretName referencing an existing Kubernetes secret that contains connection information + # for associating a Beat instance to a remote Elasticsearch instance not managed by ECK. + # The referenced secret must contain the following: + # - `url`: the URL to reach the Elastic resource + # - `username`: the username of the user to be authenticated to the Elastic resource + # - `password`: the password of the user to be authenticated to the Elastic resource + # - `ca.crt`: the CA certificate in PEM format (optional) + # - `api-key`: the key to authenticate against the Elastic resource instead of a username and password + # This field cannot be used in combination with the other fields name, namespace or serviceName. + # + # secretName: my-remote-es-credentials + +# Daemonset, or Deployment specification for the type of Beat specified. +# At least one is required of [daemonSet, deployment]. +# No default is currently set, refer to https://github.com/elastic/cloud-on-k8s/issues/7429. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-beat-configuration.html#k8s-beat-chose-the-deployment-model +# +# deployment: +# podTemplate: +# spec: +# securityContext: +# runAsUser: 0 +# daemonSet: +# podTemplate: +# spec: +# securityContext: +# runAsUser: 0 + +# Configuration of Beat, which is dependent on the `type` of Beat specified. +# NOTE: The `config` and `configRef` fields are mutually exclusive. Only one of them should be defined at a time, +# as using both may cause conflicts. +# +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-beat-configuration.html#k8s-beat-custom-configuration +# +config: {} + +# Reference a configuration in a Secret. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-beat-configuration.html#k8s-beat-custom-configuration +# +# configRef: +# secretName: "" + +# The HTTP layer configuration for the Beats Service. +# +# http: + +# Settings for configuring stack monitoring. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-stack-monitoring.html +# +# monitoring: {} + # metrics: + # elasticsearchRefs: + # - name: monitoring + # namespace: observability + # logs: + # elasticsearchRefs: + # - name: monitoring + # namespace: observability + +# SecureSettings is a list of references to Kubernetes Secrets containing sensitive configuration options for Elastic Beats. +secureSettings: [] +# - secretName: my-secret-with-secure-settings + +# Number of revisions to retain to allow rollback in the underlying Deployment. +# If not set Kubernetes sets this to 10 by default. +# +# revisionHistoryLimit: 2 + +# ServiceAccount to be used by Elastic Beats. Some Beats features (such as autodiscover or Kubernetes module metricsets) +# require that Beat Pods interact with Kubernetes APIs. This functionality requires specific permissions +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-beat-configuration.html#k8s-beat-role-based-access-control-for-beats +# +serviceAccount: {} +# name: elastic-beat-filebeat-quickstart +# namespace: optional-namespace + +# ClusterRoleBinding to be used by Elastic Beats. Similar to ServiceAccount, this is required in some scenarios. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-beat-configuration.html#k8s-beat-role-based-access-control-for-beats +# +clusterRoleBinding: {} +# name: elastic-beat-autodiscover-binding +# subjects: +# - kind: ServiceAccount +# name: elastic-beat-filebeat-quickstart +# namespace: default +# roleRef: +# kind: ClusterRole +# name: elastic-beat-autodiscover +# apiGroup: rbac.authorization.k8s.io + +# ClusterRole to be used by Elastic Beats. Similar to ServiceAccount, this is required in some scenarios. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-beat-configuration.html#k8s-beat-role-based-access-control-for-beats +# +clusterRole: {} +# name: elastic-beat-autodiscover +# rules: +# - apiGroups: [""] +# resources: +# - events +# - pods +# - namespaces +# - nodes +# verbs: +# - get +# - watch +# - list +# - apiGroups: ["events.k8s.io"] +# resources: +# - events +# verbs: +# - get +# - watch +# - list + +# extraObjects allows injecting additional Kubernetes resources into the chart. +# These resources will be created/deleted alongside the chart release. +# The value is a list of strings, each string is a YAML manifest. +# Helm templating is supported within each manifest. +# Example: +# extraObjects: +# - | +# apiVersion: v1 +# kind: ConfigMap +# metadata: +# name: {{ include "beat.fullname" . }}-extra-config +# namespace: {{ .Release.Namespace }} +# data: +# key: value +extraObjects: [] diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/.helmignore b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/.helmignore new file mode 100644 index 00000000..f1568daf --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/.helmignore @@ -0,0 +1,24 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +templates/tests diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/Chart.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/Chart.yaml new file mode 100644 index 00000000..6773557b --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/Chart.yaml @@ -0,0 +1,10 @@ +apiVersion: v2 +description: Elasticsearch managed by the ECK operator +icon: https://helm.elastic.co/icons/elasticsearch.png +kubeVersion: '>= 1.21.0-0' +name: eck-elasticsearch +sources: +- https://github.com/elastic/cloud-on-k8s +- https://github.com/elastic/elasticsearch/ +type: application +version: 0.19.1 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/LICENSE b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/LICENSE new file mode 100644 index 00000000..92503a72 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/LICENSE @@ -0,0 +1,93 @@ +Elastic License 2.0 + +URL: https://www.elastic.co/licensing/elastic-license + +## Acceptance + +By using the software, you agree to all of the terms and conditions below. + +## Copyright License + +The licensor grants you a non-exclusive, royalty-free, worldwide, +non-sublicensable, non-transferable license to use, copy, distribute, make +available, and prepare derivative works of the software, in each case subject to +the limitations and conditions below. + +## Limitations + +You may not provide the software to third parties as a hosted or managed +service, where the service provides users with access to any substantial set of +the features or functionality of the software. + +You may not move, change, disable, or circumvent the license key functionality +in the software, and you may not remove or obscure any functionality in the +software that is protected by the license key. + +You may not alter, remove, or obscure any licensing, copyright, or other notices +of the licensor in the software. Any use of the licensor’s trademarks is subject +to applicable law. + +## Patents + +The licensor grants you a license, under any patent claims the licensor can +license, or becomes able to license, to make, have made, use, sell, offer for +sale, import and have imported the software, in each case subject to the +limitations and conditions in this license. This license does not cover any +patent claims that you cause to be infringed by modifications or additions to +the software. If you or your company make any written claim that the software +infringes or contributes to infringement of any patent, your patent license for +the software granted under these terms ends immediately. If your company makes +such a claim, your patent license ends immediately for work on behalf of your +company. + +## Notices + +You must ensure that anyone who gets a copy of any part of the software from you +also gets a copy of these terms. + +If you modify the software, you must include in any modified copies of the +software prominent notices stating that you have modified the software. + +## No Other Rights + +These terms do not imply any licenses other than those expressly granted in +these terms. + +## Termination + +If you use the software in violation of these terms, such use is not licensed, +and your licenses will automatically terminate. If the licensor provides you +with a notice of your violation, and you cease all violation of this license no +later than 30 days after you receive that notice, your licenses will be +reinstated retroactively. However, if you violate these terms after such +reinstatement, any additional violation of these terms will cause your licenses +to terminate automatically and permanently. + +## No Liability + +*As far as the law allows, the software comes as is, without any warranty or +condition, and the licensor will not be liable to you for any damages arising +out of these terms or the use or nature of the software, under any kind of +legal claim.* + +## Definitions + +The **licensor** is the entity offering these terms, and the **software** is the +software the licensor makes available under these terms, including any portion +of it. + +**you** refers to the individual or entity agreeing to these terms. + +**your company** is any legal entity, sole proprietorship, or other kind of +organization that you work for, plus all organizations that have control over, +are under the control of, or are under common control with that +organization. **control** means ownership of substantially all the assets of an +entity, or the power to direct its management and policies by vote, contract, or +otherwise. Control can be direct or indirect. + +**your licenses** are all the licenses granted to you for the software under +these terms. + +**use** means anything you do with the software requiring one of your licenses. + +**trademark** means trademarks, service marks, and similar rights. \ No newline at end of file diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/hot-warm-cold.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/hot-warm-cold.yaml new file mode 100644 index 00000000..4eb99e60 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/hot-warm-cold.yaml @@ -0,0 +1,198 @@ +--- +nodeSets: +- name: masters + count: 1 + config: + node.roles: ["master"] + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-virtual-memory.html + # + node.store.allow_mmap: false + podTemplate: + spec: + containers: + - name: elasticsearch + resources: + limits: + memory: 8Gi + cpu: 2 + # Affinity/Anti-affinity settings for controlling the 'spreading' of Elasticsearch + # pods across existing hosts. + # ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-advanced-node-scheduling.html#k8s-affinity-options + # + # affinity: + # nodeAffinity: + # requiredDuringSchedulingIgnoredDuringExecution: + # nodeSelectorTerms: + # - matchExpressions: + # - key: beta.kubernetes.io/instance-type + # operator: In + # # This should be adjusted to the instance type according to your setup + # # + # values: + # - highio + # Volume Claim settings. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-volume-claim-templates.html + # + volumeClaimTemplates: + - metadata: + name: elasticsearch-data + spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 1Ti + # Adjust to your storage class name + # + # storageClassName: local-storage +- name: hot + count: 1 + config: + node.roles: ["data_hot", "data_content", "ingest"] + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-virtual-memory.html + # + node.store.allow_mmap: false + podTemplate: + spec: + containers: + - name: elasticsearch + resources: + limits: + memory: 16Gi + cpu: 4 + # Affinity/Anti-affinity settings for controlling the 'spreading' of Elasticsearch + # pods across existing hosts. + # ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-advanced-node-scheduling.html#k8s-affinity-options + # + # affinity: + # nodeAffinity: + # requiredDuringSchedulingIgnoredDuringExecution: + # nodeSelectorTerms: + # - matchExpressions: + # - key: beta.kubernetes.io/instance-type + # operator: In + # # This should be adjusted to the instance type according to your setup + # # + # values: + # - highio + # Volume Claim settings. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-volume-claim-templates.html + # + volumeClaimTemplates: + - metadata: + name: elasticsearch-data + spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 1Ti + # Adjust to your storage class name + # + # storageClassName: local-storage +- name: warm + count: 1 + config: + node.roles: ["data_warm"] + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-virtual-memory.html + # + node.store.allow_mmap: false + podTemplate: + spec: + containers: + - name: elasticsearch + resources: + limits: + memory: 16Gi + cpu: 2 + # Affinity/Anti-affinity settings for controlling the 'spreading' of Elasticsearch + # pods across existing hosts. + # ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-advanced-node-scheduling.html#k8s-affinity-options + # + # affinity: + # nodeAffinity: + # requiredDuringSchedulingIgnoredDuringExecution: + # nodeSelectorTerms: + # - matchExpressions: + # - key: beta.kubernetes.io/instance-type + # operator: In + # # This should be adjusted to the instance type according to your setup + # # + # values: + # - highstorage + # Volume Claim settings. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-volume-claim-templates.html + # + volumeClaimTemplates: + - metadata: + name: elasticsearch-data + spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 10Ti + # Adjust to your storage class name + # + # storageClassName: local-storage +- name: cold + count: 1 + config: + node.roles: ["data_cold"] + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-virtual-memory.html + # + node.store.allow_mmap: false + podTemplate: + spec: + containers: + - name: elasticsearch + resources: + limits: + memory: 8Gi + cpu: 2 + # Affinity/Anti-affinity settings for controlling the 'spreading' of Elasticsearch + # pods across existing hosts. + # ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-advanced-node-scheduling.html#k8s-affinity-options + # + # affinity: + # nodeAffinity: + # requiredDuringSchedulingIgnoredDuringExecution: + # nodeSelectorTerms: + # - matchExpressions: + # - key: beta.kubernetes.io/instance-type + # operator: In + # # This should be adjusted to the instance type according to your setup + # # + # values: + # - highstorage + # Volume Claim settings. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-volume-claim-templates.html + # + volumeClaimTemplates: + - metadata: + name: elasticsearch-data + spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 20Ti + # Adjust to your storage class name + # + # storageClassName: local-storage diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-aks.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-aks.yaml new file mode 100644 index 00000000..0ca310c3 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-aks.yaml @@ -0,0 +1,26 @@ +--- +# The following is an example of an Elasticsearch resource that is configured to use an Ingress resource in an AKS cluster. +# +ingress: + enabled: true + className: webapprouting.kubernetes.azure.com + annotations: + # This is required for AKS Loadbalancing to understand that it's communicating with + # an HTTPS backend. + nginx.ingress.kubernetes.io/backend-protocol: "HTTPS" + labels: + my: label + pathType: Prefix + hosts: + - host: "elasticsearch.company.dev" + path: "/" +nodeSets: +- name: default + count: 3 + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + config: + node.store.allow_mmap: false diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-eks-alb.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-eks-alb.yaml new file mode 100644 index 00000000..d3cc4041 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-eks-alb.yaml @@ -0,0 +1,37 @@ +--- +# The following is an example of an Elasticsearch resource that is configured to use an Ingress resource in an EKS cluster +# which provisions an application load balancer. +# +ingress: + enabled: true + className: alb + annotations: + alb.ingress.kubernetes.io/scheme: "internet-facing" + alb.ingress.kubernetes.io/listen-ports: '[{"HTTPS":443}]' + alb.ingress.kubernetes.io/backend-protocol: "HTTPS" + alb.ingress.kubernetes.io/target-type: "ip" + # To use an ALB with ECK, you must provide a valid ACM certificate ARN or use certificate discovery. + # There are 2 options for EKS: + # 1. Create a valid ACM certificate, and uncomment the following annotation and update it to the correct ARN. + # 2. Create a valid ACM certificate and ensure that the hosts[0].host matches the certificate's Common Name (CN) and + # certificate discovery *should* find the certificate automatically and use it. + # + # ref: https://kubernetes-sigs.github.io/aws-load-balancer-controller/v2.8/guide/ingress/cert_discovery/ + # + # alb.ingress.kubernetes.io/certificate-arn: "arn:aws:acm:us-east-1:00000000000:certificate/b65be571-8220-4f2e-8cb1-94194535d877" + labels: + my: label + pathType: Prefix + hosts: + - host: "elasticsearch.company.dev" + path: "/" +nodeSets: +- name: default + count: 3 + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + config: + node.store.allow_mmap: false diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-eks-nlb.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-eks-nlb.yaml new file mode 100644 index 00000000..3809e871 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-eks-nlb.yaml @@ -0,0 +1,27 @@ +--- +# The following is an example of an Elasticsearch resource that is configured to deploy a +# network load balancer (NLB) in an EKS cluster. To provision an NLB "ingress" for the +# Elasticsearch cluster, you are required to set annotations on the service, +# and not an Ingress resource. +ingress: + enabled: false +http: + service: + metadata: + annotations: + service.beta.kubernetes.io/aws-load-balancer-type: external + service.beta.kubernetes.io/aws-load-balancer-nlb-target-type: ip + service.beta.kubernetes.io/aws-load-balancer-scheme: internet-facing + service.beta.kubernetes.io/aws-load-balancer-backend-protocol: ssl + spec: + type: LoadBalancer +nodeSets: +- name: default + count: 3 + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + config: + node.store.allow_mmap: false diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-gke.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-gke.yaml new file mode 100644 index 00000000..3adbd29c --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/examples/ingress/elasticsearch-ingress-gke.yaml @@ -0,0 +1,36 @@ +--- +# The following is an example of an Elasticsearch resource that is configured to use an Ingress resource in a GKE cluster. +# +ingress: + enabled: true + annotations: + my: annotation + labels: + my: label + pathType: Prefix + hosts: + - host: "elasticsearch.company.dev" + path: "/" +http: + service: + metadata: + annotations: + # This is required for `ClusterIP` services (which are the default ECK service type) to be used with Ingress in GKE clusters. + cloud.google.com/neg: '{"ingress": true}' + # This is required to enable the GKE Ingress Controller to use HTTPS as the backend protocol. + cloud.google.com/app-protocols: '{"https":"HTTPS"}' +nodeSets: +- name: default + count: 3 + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + config: + node.store.allow_mmap: false + # Enable anonymous access to allow GCLB health probes to succeed + xpack.security.authc: + anonymous: + username: anon + roles: monitoring_user diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/NOTES.txt b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/NOTES.txt new file mode 100644 index 00000000..f6ab0020 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/NOTES.txt @@ -0,0 +1,6 @@ + +1. Check Elasticsearch resource status + $ kubectl get es {{ include "elasticsearch.fullname" . }} -n {{ .Release.Namespace }} + +2. Check Elasticsearch pod status + $ kubectl get pods --namespace={{ .Release.Namespace }} -l elasticsearch.k8s.elastic.co/cluster-name={{ include "elasticsearch.fullname" . }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/_helpers.tpl b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/_helpers.tpl new file mode 100644 index 00000000..8fbf57b3 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/_helpers.tpl @@ -0,0 +1,51 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "elasticsearch.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "elasticsearch.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "elasticsearch.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "elasticsearch.labels" -}} +helm.sh/chart: {{ include "elasticsearch.chart" . }} +{{ include "elasticsearch.selectorLabels" . }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- if .Values.labels }} +{{ toYaml .Values.labels }} +{{- end }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "elasticsearch.selectorLabels" -}} +app.kubernetes.io/name: {{ include "elasticsearch.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/elasticsearch.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/elasticsearch.yaml new file mode 100644 index 00000000..4a4d7465 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/elasticsearch.yaml @@ -0,0 +1,78 @@ +--- +apiVersion: elasticsearch.k8s.elastic.co/v1 +kind: Elasticsearch +metadata: + name: {{ include "elasticsearch.fullname" . }} + labels: + {{- include "elasticsearch.labels" . | nindent 4 }} + annotations: + eck.k8s.elastic.co/license: basic + {{- with .Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + {{- with .Values.auth }} + auth: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .Values.updateStrategy }} + updateStrategy: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .Values.secureSettings }} + secureSettings: + {{- toYaml . | nindent 2 }} + {{- end }} + {{- with .Values.transport }} + transport: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .Values.http }} + http: + {{- toYaml . | nindent 4 }} + {{- end }} + version: {{ required "An Elasticsearch version is required" .Values.version }} + {{- with .Values.monitoring }} + monitoring: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .Values.remoteClusters }} + remoteClusters: + {{- toYaml . | nindent 2 }} + {{- end }} + {{- with .Values.remoteClusterServer }} + remoteClusterServer: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .Values.volumeClaimDeletePolicy }} + volumeClaimDeletePolicy: + {{- if and (not (eq . "DeleteOnScaledownOnly")) (not (eq . "DeleteOnScaledownAndClusterDeletion")) }} + {{ fail "volumeClaimDeletePolicy can only be one of 'DeleteOnScaledownOnly' or 'DeleteOnScaledownAndClusterDeletion'" }} + {{- end }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if eq (len .Values.nodeSets) 0 }} + {{ fail "At least one nodeSet is required" }} + {{- end }} + nodeSets: + {{ toYaml .Values.nodeSets | nindent 4 }} + {{- with .Values.image }} + image: {{ . }} + {{- end }} + {{- with .Values.podDisruptionBudget }} + {{- if .disabled }} + podDisruptionBudget: {} + {{- else }} + {{- with .spec }} + podDisruptionBudget: + spec: + {{- toYaml . | nindent 6 }} + {{- end }} + {{- end }} + {{- end }} + {{- with .Values.serviceAccountName }} + serviceAccountName: {{ . }} + {{- end }} + {{- with .Values.revisionHistoryLimit }} + revisionHistoryLimit: {{ . }} + {{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/extra-objects.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/extra-objects.yaml new file mode 100644 index 00000000..c385106c --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/extra-objects.yaml @@ -0,0 +1,5 @@ +{{- range .Values.extraObjects }} +--- +{{ tpl . $ }} +{{- end }} + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/ingress.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/ingress.yaml new file mode 100644 index 00000000..99aa1813 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/templates/ingress.yaml @@ -0,0 +1,48 @@ +{{- if .Values.ingress.enabled -}} +{{- $pathType := .Values.ingress.pathType | default "Prefix" -}} +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: {{ include "elasticsearch.fullname" . }} + labels: + {{- include "elasticsearch.labels" . | nindent 4 }} + {{- with .Values.ingress.labels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if .Values.ingress.annotations }} + annotations: + {{- with .Values.ingress.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- end }} +spec: + {{- if .Values.ingress.className }} + ingressClassName: {{ .Values.ingress.className | quote }} + {{- end }} + {{- if .Values.ingress.tls.enabled }} + tls: + - hosts: + {{- range .Values.ingress.hosts }} + - {{ .host | quote }} + {{- end }} + {{- if .Values.ingress.tls.secretName }} + secretName: {{ .Values.ingress.tls.secretName }} + {{- else }} + secretName: {{ include "elasticsearch.fullname" . }}-es-http-certs-internal + {{- end }} + {{- end }} + rules: + {{- range .Values.ingress.hosts }} + {{- $hostPath := .path | default "/" }} + - host: {{ .host | quote }} + http: + paths: + - path: {{ $hostPath }} + pathType: {{ $pathType }} + backend: + service: + name: {{ include "elasticsearch.fullname" $ }}-es-http + port: + number: 9200 + {{- end }} +{{ end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/values.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/values.yaml new file mode 100644 index 00000000..71b7772a --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-elasticsearch/values.yaml @@ -0,0 +1,411 @@ +--- +# Default values for eck-elasticsearch. +# This is a YAML-formatted file. + +# Overridable names of the Elasticsearch resource. +# By default, this is the Release name set for the chart, +# followed by 'eck-elasticsearch'. +# +# nameOverride will override the name of the Chart with the name set here, +# so nameOverride: quickstart, would convert to '{{ Release.name }}-quickstart' +# +# nameOverride: "quickstart" +# +# fullnameOverride will override both the release name, and the chart name, +# and will name the Elasticsearch resource exactly as specified. +# +# fullnameOverride: "quickstart" + +# Version of Elasticsearch. +# +version: 9.4.2 + +# Elasticsearch Docker image to deploy. +# Supports both tag and digest formats. +# image: docker.elastic.co/elasticsearch/elasticsearch:9.4.2-SNAPSHOT +# image: docker.elastic.co/elasticsearch/elasticsearch:9.4.2-SNAPSHOT@sha256: +# image: docker.elastic.co/elasticsearch/elasticsearch@sha256: + +# Labels that will be applied to Elasticsearch. +# +labels: {} + +# Annotations that will be applied to Elasticsearch. +# +annotations: {} + +# Settings for configuring Elasticsearch users and roles. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-users-and-roles.html +# +auth: {} + +# Settings for configuring stack monitoring. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-stack-monitoring.html +# +monitoring: {} + # metrics: + # elasticsearchRefs: + # - name: monitoring + # namespace: observability + # logs: + # elasticsearchRefs: + # - name: monitoring + # namespace: observability + +# Control the Elasticsearch transport module used for internal communication between nodes. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-transport-settings.html +# +transport: {} + # service: + # metadata: + # labels: + # my-custom: label + # spec: + # type: LoadBalancer + # tls: + # subjectAltNames: + # - ip: 1.2.3.4 + # - dns: hulk.example.com + # certificate: + # secretName: custom-ca + +# Settings to control how Elasticsearch will be accessed. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-accessing-elastic-services.html +# +http: {} + # service: + # metadata: + # labels: + # my-custom: label + # spec: + # type: LoadBalancer + # tls: + # selfSignedCertificate: + # # To fully disable TLS for the HTTP layer of Elasticsearch, simply + # # set the below field to 'true', removing all other fields. + # disabled: false + # subjectAltNames: + # - ip: 1.2.3.4 + # - dns: hulk.example.com + # certificate: + # secretName: custom-ca + +# Control Elasticsearch Secure Settings. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-es-secure-settings.html#k8s-es-secure-settings +# +secureSettings: [] + # - secretName: one-secure-settings-secret + # Projection of secret keys to specific paths + # - secretName: gcs-secure-settings + # entries: + # - key: gcs.client.default.credentials_file + # - key: gcs_client_1 + # path: gcs.client.client_1.credentials_file + # - key: gcs_client_2 + # path: gcs.client.client_2.credentials_file + +# Settings for limiting the number of simultaneous changes to an Elasticsearch resource. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-update-strategy.html +# +updateStrategy: {} + # changeBudget: + # maxSurge: 3 + # maxUnavailable: 1 + +# Controlling of connectivity between remote clusters within the same kubernetes cluster. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-remote-clusters.html +# +remoteClusters: {} + # - name: cluster-two + # elasticsearchRef: + # name: cluster-two + # namespace: ns-two + +# RemoteClusterServer specifies if the remote cluster server should be enabled. +# This must be enabled if this cluster is a remote cluster which is expected to be accessed using API key authentication. +# +remoteClusterServer: {} +# enabled: true + +# VolumeClaimDeletePolicy sets the policy for handling deletion of PersistentVolumeClaims for all NodeSets. +# Possible values are DeleteOnScaledownOnly and DeleteOnScaledownAndClusterDeletion. +# By default, if not set or empty, the operator sets DeleteOnScaledownAndClusterDeletion. +# +volumeClaimDeletePolicy: "" + +# Settings to limit the disruption when pods need to be rescheduled for some reason such as upgrades or routine maintenance. +# By default, if not set, the operator sets a budget that doesn't allow any pod to be removed in case the cluster is not green or if there is only one node of type `data` or `master`. +# In all other cases the default PodDisruptionBudget sets `minAvailable` equal to the total number of nodes minus 1. +# To completely disable the pod disruption budget set `disabled` to true. +# +# podDisruptionBudget: +# spec: +# minAvailable: 2 +# selector: +# matchLabels: +# elasticsearch.k8s.elastic.co/cluster-name: quickstart +# disabled: true + +# Used to check access from the current resource to a resource (for ex. a remote Elasticsearch cluster) in a different namespace. +# Can only be used if ECK is enforcing RBAC on references. +# +# serviceAccountName: "" + +# Number of revisions to retain to allow rollback in the underlying StatefulSets. +# By default, if not set, Kubernetes sets 10. +# +# revisionHistoryLimit: 2 + +# Node configuration settings. +# The node roles which can be configured here are: +# - "master" +# - "data_hot" +# - "data_cold" +# - "data_frozen" +# - "data_content" +# - "ml" +# - "ingest" +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-node-configuration.html +# +nodeSets: +- name: default + count: 1 + config: + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-virtual-memory.html + # + node.store.allow_mmap: false + podTemplate: + # The following spec is exactly the Kubernetes Core V1 PodTemplateSpec. Any fields within the PodTemplateSpec + # are supported within the 'spec' field below. Please see below documentation for the exhaustive list of fields. + # + # https://v1-24.docs.kubernetes.io/docs/reference/generated/kubernetes-api/v1.24/#podtemplatespec-v1-core + # + # Only the commonly overridden/used fields will be noted below. + # + spec: + + # If specified, the pod's scheduling constraints + # https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-advanced-node-scheduling.html + # https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/ + # affinity: + # nodeAffinity: + # requiredDuringSchedulingIgnoredDuringExecution: + # nodeSelectorTerms: + # - matchExpressions: + # - key: topology.kubernetes.io/zone + # operator: In + # values: + # - antarctica-east1 + # - antarctica-west1 + + # Containers array. Should only be used to customize the 'elasticsearch' container using the following fields. + containers: + - name: elasticsearch + + # List of environment variables to set in the 'elasticsearch' container. + # https://kubernetes.io/docs/tasks/inject-data-application/define-environment-variable-container/ + # env: + # - name: "my-env-var" + # value: "my-value" + + # Compute Resources required by this container. + resources: + # Requests describes the minimum amount of compute resources required. If Requests is omitted for a container, + # it defaults to Limits if that is explicitly specified, otherwise to an implementation-defined value. + # + # Defaults used by the ECK Operator, if not specified, are below + limits: + # cpu: 1 + memory: 2Gi + requests: + # cpu: 1 + memory: 2Gi + + # Example increasing both the requests and limits values: + # limits: + # cpu: 4 + # memory: 8Gi + # requests: + # cpu: 1 + # memory: 8Gi + + # SecurityContext defines the security options the container should be run with. + # If set, the fields of SecurityContext override the equivalent fields of PodSecurityContext. + # + # These typically are set automatically by the ECK Operator, and should only be adjusted + # with the full knowledge of the effects of each field. + # + # securityContext: + + # Whether this container has a read-only root filesystem. Default is false. + # readOnlyRootFilesystem: false + + # The GID to run the entrypoint of the container process. Uses runtime default if unset. + # runAsGroup: 1000 + + # Indicates that the container must run as a non-root user. If true, the Kubelet will validate the image at runtime to ensure + # that it does not run as UID 0 (root) and fail to start the container if it does. If unset or false, no such validation will be performed. + # runAsNonRoot: true + + # The UID to run the entrypoint of the container process. Defaults to user specified in image metadata if unspecified. + # runAsUser: 1000 + + # ImagePullSecrets is an optional list of references to secrets in the same namespace to use for pulling any of the images used by this PodSpec. + # https://kubernetes.io/docs/concepts/containers/images#specifying-imagepullsecrets-on-a-pod + # imagePullSecrets: + # - name: "image-pull-secret" + + # List of initialization containers belonging to the pod. + # + # Common initContainers include setting sysctl, or in 7.x versions of Elasticsearch, + # installing Elasticsearch plugins. + # + # https://kubernetes.io/docs/concepts/workloads/pods/init-containers/ + # initContainers: + # - command: + # - sh + # - "-c" + # - sysctl -w vm.max_map_count=262144 + # name: sysctl + # securityContext: + # privileged: true + # - command: + # - sh + # - "-c" + # - bin/elasticsearch-plugin remove --purge analysis-icu ; bin/elasticsearch-plugin install --batch analysis-icu + # name: install-plugins + # securityContext: + # privileged: true + + + # NodeSelector is a selector which must be true for the pod to fit on a node. Selector which must match a node's labels for the pod to be scheduled on that node. + # https://kubernetes.io/docs/concepts/configuration/assign-pod-node/ + # https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-advanced-node-scheduling.html + # nodeSelector: + # diskType: ssd + # environment: production + + # If specified, indicates the pod's priority. "system-node-critical" and "system-cluster-critical" are two special keywords which indicate the highest priorities with the former being the highest priority. + # Any other name must be defined by creating a PriorityClass object with that name. If not specified, the pod priority will be default or zero if there is no default. + # https://kubernetes.io/docs/concepts/scheduling-eviction/pod-priority-preemption/ + # priorityClassName: "" + + # SecurityContext holds pod-level security attributes and common container settings. Optional: Defaults to empty. See type description for default values of each field. + # See previously defined 'securityContext' within 'podTemplate' for all available fields. + # securityContext: {} + + # ServiceAccountName is the name of the ServiceAccount to use to run this pod. + # https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/ + # serviceAccountName: "" + + # Optional duration in seconds to wait for the Elasticsearch pod to terminate gracefully. + # terminationGracePeriodSeconds: 30s + + # If specified, the pod's tolerations that will apply to all containers within the pod. + # https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/ + # tolerations: + # - key: "node-role.kubernetes.io/elasticsearch" + # effect: "NoSchedule" + # operator: "Exists" + + # TopologySpreadConstraints describes how a group of pods ought to spread across topology domains. + # Scheduler will schedule pods in a way which abides by the constraints. All topologySpreadConstraints are ANDed. + # + # These settings are generally applied within each `nodeSets[].podTemplate` field to apply to a specific Elasticsearch nodeset. + # + # https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-advanced-node-scheduling.html + # topologySpreadConstraints: {} + + # List of volumes that can be mounted by containers belonging to the pod. + # https://kubernetes.io/docs/concepts/storage/volumes + # volumes: [] + +# Settings for controlling Elasticsearch ingress. Enabling ingress will expose your Elasticsearch instance +# to the public internet, and as such is disabled by default. +# +# Each Cloud Service Provider has different requirements for setting up Ingress. Some links to common documentation are: +# - AWS: https://docs.aws.amazon.com/eks/latest/userguide/alb-ingress.html +# - GCP: https://cloud.google.com/kubernetes-engine/docs/concepts/ingress +# - Azure: https://learn.microsoft.com/en-us/azure/aks/app-routing +# - Nginx: https://kubernetes.github.io/ingress-nginx/ +# +ingress: + enabled: false + + # Annotations that will be applied to the Ingress resource. Note that some ingress controllers are controlled via annotations. + # + # Nginx Annotations: https://kubernetes.github.io/ingress-nginx/user-guide/nginx-configuration/annotations/ + # + # Common annotations: + # kubernetes.io/ingress.class: gce # Configures the Ingress resource to use the GCE ingress controller and create an external Application Load Balancer. + # kubernetes.io/ingress.class: gce-internal # Configures the Ingress resource to use the GCE ingress controller and create an internal Application Load Balancer. + # kubernetes.io/ingress.class: nginx # Configures the Ingress resource to use the NGINX ingress controller. + # + annotations: {} + + # Labels that will be applied to the Ingress resource. + # + labels: {} + + # Some ingress controllers require the use of a specific class name to route traffic to the correct controller, notably AKS and EKS, which + # replaces the use of the 'kubernetes.io/ingress.class' annotation. + # + # className: webapprouting.kubernetes.azure.com | alb + + # Ingress paths are required to have a corresponding path type. Defaults to 'Prefix'. + # + # There are 3 supported path types: + # - ImplementationSpecific + # - Prefix + # - Exact + # + # ref: https://kubernetes.io/docs/concepts/services-networking/ingress/#path-types + # + pathType: Prefix + + # Hosts are a list of hosts included in the Ingress definition, with a corresponding path at which the default Elasticsearch service + # will be exposed. Each host in the list should be a fully qualified DNS name that will resolve to the exposed Ingress object. + # + # ref: https://kubernetes.io/docs/concepts/services-networking/ingress/#name-based-virtual-hosting + # + hosts: + - host: chart-example.local + path: / + + # TLS defines whether TLS will be enabled on the Ingress resource. + # + # *NOTE* Many Cloud Service Providers handle TLS in a custom manner, and as such, it is recommended to consult their documentation. + # Notably GKE and Nginx Ingress Controllers seems to respect the Ingress TLS settings, AKS and EKS ignore it. + # + # - AKS: https://learn.microsoft.com/en-us/azure/aks/app-routing-dns-ssl + # - GKE: https://cloud.google.com/kubernetes-engine/docs/concepts/ingress#options_for_providing_ssl_certificates + # - EKS: https://aws.amazon.com/blogs/containers/serve-distinct-domains-with-tls-powered-by-acm-on-amazon-eks/ + # - Nginx: https://kubernetes.github.io/ingress-nginx/user-guide/tls/ + # + # Kubernetes ingress TLS documentation: + # ref: https://kubernetes.io/docs/concepts/services-networking/ingress/#tls + # + tls: + enabled: false + # Optional Kubernetes secret name that contains a base64 encoded PEM certificate and private key that corresponds to the above 'hosts' definitions. + # If tls is enabled, but this field is not set, the self-signed certificate and key created by the ECK operator will be used. + # secretName: chart-example-tls + +# extraObjects allows injecting additional Kubernetes resources into the chart. +# These resources will be created/deleted alongside the chart release. +# The value is a list of strings, each string is a YAML manifest. +# Helm templating is supported within each manifest. +# Example: +# extraObjects: +# - | +# apiVersion: v1 +# kind: ConfigMap +# metadata: +# name: {{ include "elasticsearch.fullname" . }}-extra-config +# namespace: {{ .Release.Namespace }} +# data: +# key: value +extraObjects: [] diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/.helmignore b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/.helmignore new file mode 100644 index 00000000..f1568daf --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/.helmignore @@ -0,0 +1,24 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +templates/tests diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/Chart.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/Chart.yaml new file mode 100644 index 00000000..3af66774 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/Chart.yaml @@ -0,0 +1,9 @@ +apiVersion: v2 +description: Elastic Enterprise Search managed by the ECK operator +icon: https://github.com/elastic/ent-search/blob/main/public/app-search-favicon-196x196.png +kubeVersion: '>= 1.21.0-0' +name: eck-enterprise-search +sources: +- https://github.com/elastic/cloud-on-k8s +type: application +version: 0.19.1 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/examples/with-custom-configuration.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/examples/with-custom-configuration.yaml new file mode 100644 index 00000000..4216a112 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/examples/with-custom-configuration.yaml @@ -0,0 +1,19 @@ +config: + # define the exposed URL at which users will reach Enterprise Search + ent_search.external_url: https://my-custom-domain:3002 + # define the exposed URL at which users will reach Kibana + kibana.host: https://kibana.my-custom-domain:5601 + # configure app search document size limit + app_search.engine.document_size.limit: 100kb + +http: + service: + metadata: + labels: + my-custom: label + tls: + certificate: + secretName: my-cert + +elasticsearchRef: + name: eck-elasticsearch diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/templates/_helpers.tpl b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/templates/_helpers.tpl new file mode 100644 index 00000000..21025dc7 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/templates/_helpers.tpl @@ -0,0 +1,62 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "eck-enterprise-search.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "eck-enterprise-search.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "eck-enterprise-search.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "eck-enterprise-search.labels" -}} +helm.sh/chart: {{ include "eck-enterprise-search.chart" . }} +{{ include "eck-enterprise-search.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "eck-enterprise-search.selectorLabels" -}} +app.kubernetes.io/name: {{ include "eck-enterprise-search.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} + +{{/* +Create the name of the service account to use +*/}} +{{- define "eck-enterprise-search.serviceAccountName" -}} +{{- if .Values.serviceAccount.create }} +{{- default (include "eck-enterprise-search.fullname" .) .Values.serviceAccount.name }} +{{- else }} +{{- default "default" .Values.serviceAccount.name }} +{{- end }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/templates/enterprisesearch.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/templates/enterprisesearch.yaml new file mode 100644 index 00000000..af224e35 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/templates/enterprisesearch.yaml @@ -0,0 +1,62 @@ +--- +apiVersion: enterprisesearch.k8s.elastic.co/v1 +kind: EnterpriseSearch +metadata: + name: {{ include "eck-enterprise-search.fullname" . }} + labels: + {{- include "eck-enterprise-search.labels" . | nindent 4 }} + {{- with .Values.labels }} + {{- toYaml . | nindent 4 }} + {{- end }} + annotations: + eck.k8s.elastic.co/license: basic + {{- with .Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + version: {{ required "An Enterprise Search version is required" .Values.version }} + count: {{ required "A pod count is required" .Values.count }} + + {{- /* + This is complicated, but seems required to catch both the situations where the key does not exist (commented out), and the key exists but is an empty map. + */ -}} + {{- if and (or (and (hasKey .Values "configRef") (eq 0 (len .Values.configRef))) (not (hasKey .Values "configRef"))) (or (and (hasKey .Values "elasticsearchRef") (eq 0 (len .Values.elasticsearchRef))) (not (hasKey .Values "elasticsearchRef"))) }} + {{ fail "At least one of configRef or elasticsearchRef is required" }} + {{- end }} + + {{- with .Values.image }} + image: {{ . }} + {{- end }} + + {{- with .Values.serviceAccountName }} + serviceAccountName: {{ . }} + {{- end }} + + {{- with .Values.revisionHistoryLimit }} + revisionHistoryLimit: {{ . }} + {{- end }} + + {{- with .Values.config }} + config: + {{- toYaml . | nindent 4 }} + {{- end }} + + {{- with .Values.http }} + http: + {{- toYaml . | nindent 4 }} + {{- end }} + + {{- with .Values.elasticsearchRef }} + elasticsearchRef: + {{- toYaml . | nindent 4 }} + {{- end }} + + {{- with .Values.podTemplate }} + podTemplate: + {{- toYaml . | nindent 4 }} + {{- end }} + + {{- with .Values.configRef }} + configRef: + {{- toYaml . | nindent 2 }} + {{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/templates/extra-objects.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/templates/extra-objects.yaml new file mode 100644 index 00000000..c385106c --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/templates/extra-objects.yaml @@ -0,0 +1,5 @@ +{{- range .Values.extraObjects }} +--- +{{ tpl . $ }} +{{- end }} + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/values.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/values.yaml new file mode 100644 index 00000000..5e67dd04 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-enterprise-search/values.yaml @@ -0,0 +1,126 @@ +--- +# Default values for eck-enterprise-search. +# This is a YAML-formatted file. + +# Overridable names of the Enterprise Search resource. +# By default, this is the Release name set for the chart, +# followed by 'eck-enterprise-search'. +# +# nameOverride will override the name of the Chart with the name set here, +# so nameOverride: quickstart, would convert to '{{ Release.name }}-quickstart' +# +# nameOverride: "quickstart" +# +# fullnameOverride will override both the release name, and the chart name, +# and will name the Enterprise Search resource exactly as specified. +# +# fullnameOverride: "quickstart" + +# Version of Enterprise Search. +# +# 8.19 should be the last minor version in the 8 line. +version: 8.19.0 + +# Enterprise Search Docker image to deploy. +# Supports both tag and digest formats. +# image: docker.elastic.co/enterprise-search/enterprise-search:8.19.0-SNAPSHOT +# image: docker.elastic.co/enterprise-search/enterprise-search:8.19.0-SNAPSHOT@sha256: +# image: docker.elastic.co/enterprise-search/enterprise-search@sha256: + +# Used to check access from the current resource to a resource (for ex. a remote Elasticsearch cluster) in a different namespace. +# Can only be used if ECK is enforcing RBAC on references. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-restrict-cross-namespace-associations.html +# +# serviceAccountName: "" + +# Labels that will be applied to Enterprise Search. +# +labels: {} + +# Annotations that will be applied to Enterprise Search. +# +annotations: {} + +# Count of Enterprise Search replicas to create. +# +count: 1 + +# The Enterprise Search configuration, the ECK equivalent to enterprise-search.yml +# ref: https://www.elastic.co/guide/en/enterprise-search/current/configuration.html#configuration-configure +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-enterprise-search-configuration.html +# +# At a minimum, you must specify the external URL and Kibana host. +# +config: {} + # define the exposed URL at which users will reach Enterprise Search + # ent_search.external_url: https://my-custom-domain:3002 + # define the exposed URL at which users will reach Kibana + # kibana.host: https://kibana.my-custom-domain:5601 + +# Settings to control how Enterprise Search will be accessed. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-accessing-elastic-services.html +# +http: {} + # tls: + # certificate: + # secretName: my-cert + # service: + # metadata: + # labels: + # my-custom: label + +# Reference to ECK-managed Elasticsearch resource. +# +elasticsearchRef: {} + # name: eck-elasticsearch + # Optional namespace reference to Elasticsearch resource. + # If not specified, then the namespace of the Enterprise Search resource + # will be assumed. + # + # namespace: default + # + # Optional secretName referencing an existing Kubernetes secret that contains connection information + # for associating an Enterprise Search instance to a remote Elasticsearch instance not managed by ECK. + # The referenced secret must contain the following: + # - `url`: the URL to reach the Elastic resource + # - `username`: the username of the user to be authenticated to the Elastic resource + # - `password`: the password of the user to be authenticated to the Elastic resource + # - `ca.crt`: the CA certificate in PEM format (optional) + # This field cannot be used in combination with the other fields name, namespace or serviceName. + # + # secretName: my-remote-es-credentials + +# Set podTemplate to customize the pod used by Enterprise Search +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-customize-pods.html +# +podTemplate: {} + +# Number of revisions to retain to allow rollback in the underlying Deployment. +# If not set Kubernetes sets this to 10 by default. +# +# revisionHistoryLimit: 2 + +# If you would prefer your sensitive data to be stored in a Secret, you can specify the name of the Secret reference. +# In addition, if you do not want to use the `elasticsearchRef` mechanism or if you want to connect to an Elasticsearch +# cluster not managed by ECK, you can manually configure Enterprise Search to access any available Elasticsearch cluster: +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-enterprise-search-configuration.html#k8s-enterprise-search-secret-configuration +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-enterprise-search-configuration.html#k8s-enterprise-search-connect-non-eck-es +# +configRef: {} + # secretName: enterprise-search-config + +# extraObjects allows injecting additional Kubernetes resources into the chart. +# These resources will be created/deleted alongside the chart release. +# The value is a list of strings, each string is a YAML manifest. +# Helm templating is supported within each manifest. +# Example: +# extraObjects: +# - | +# apiVersion: v1 +# kind: ConfigMap +# metadata: +# name: {{ include "eck-enterprise-search.fullname" . }}-extra-config +# namespace: {{ .Release.Namespace }} +# data: +# key: value +extraObjects: [] diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/.helmignore b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/.helmignore new file mode 100644 index 00000000..f1568daf --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/.helmignore @@ -0,0 +1,24 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +templates/tests diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/Chart.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/Chart.yaml new file mode 100644 index 00000000..8123f45e --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/Chart.yaml @@ -0,0 +1,11 @@ +apiVersion: v2 +description: Elastic Fleet Server as an Agent managed by the ECK operator +kubeVersion: '>= 1.21.0-0' +name: eck-fleet-server +sources: +- https://github.com/elastic/cloud-on-k8s +- https://github.com/elastic/elastic-agent +- https://github.com/elastic/fleet-server +- https://www.elastic.co/guide/en/fleet/current/fleet-overview.html +type: application +version: 0.19.1 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/LICENSE b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/LICENSE new file mode 100644 index 00000000..92503a72 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/LICENSE @@ -0,0 +1,93 @@ +Elastic License 2.0 + +URL: https://www.elastic.co/licensing/elastic-license + +## Acceptance + +By using the software, you agree to all of the terms and conditions below. + +## Copyright License + +The licensor grants you a non-exclusive, royalty-free, worldwide, +non-sublicensable, non-transferable license to use, copy, distribute, make +available, and prepare derivative works of the software, in each case subject to +the limitations and conditions below. + +## Limitations + +You may not provide the software to third parties as a hosted or managed +service, where the service provides users with access to any substantial set of +the features or functionality of the software. + +You may not move, change, disable, or circumvent the license key functionality +in the software, and you may not remove or obscure any functionality in the +software that is protected by the license key. + +You may not alter, remove, or obscure any licensing, copyright, or other notices +of the licensor in the software. Any use of the licensor’s trademarks is subject +to applicable law. + +## Patents + +The licensor grants you a license, under any patent claims the licensor can +license, or becomes able to license, to make, have made, use, sell, offer for +sale, import and have imported the software, in each case subject to the +limitations and conditions in this license. This license does not cover any +patent claims that you cause to be infringed by modifications or additions to +the software. If you or your company make any written claim that the software +infringes or contributes to infringement of any patent, your patent license for +the software granted under these terms ends immediately. If your company makes +such a claim, your patent license ends immediately for work on behalf of your +company. + +## Notices + +You must ensure that anyone who gets a copy of any part of the software from you +also gets a copy of these terms. + +If you modify the software, you must include in any modified copies of the +software prominent notices stating that you have modified the software. + +## No Other Rights + +These terms do not imply any licenses other than those expressly granted in +these terms. + +## Termination + +If you use the software in violation of these terms, such use is not licensed, +and your licenses will automatically terminate. If the licensor provides you +with a notice of your violation, and you cease all violation of this license no +later than 30 days after you receive that notice, your licenses will be +reinstated retroactively. However, if you violate these terms after such +reinstatement, any additional violation of these terms will cause your licenses +to terminate automatically and permanently. + +## No Liability + +*As far as the law allows, the software comes as is, without any warranty or +condition, and the licensor will not be liable to you for any damages arising +out of these terms or the use or nature of the software, under any kind of +legal claim.* + +## Definitions + +The **licensor** is the entity offering these terms, and the **software** is the +software the licensor makes available under these terms, including any portion +of it. + +**you** refers to the individual or entity agreeing to these terms. + +**your company** is any legal entity, sole proprietorship, or other kind of +organization that you work for, plus all organizations that have control over, +are under the control of, or are under common control with that +organization. **control** means ownership of substantially all the assets of an +entity, or the power to direct its management and policies by vote, contract, or +otherwise. Control can be direct or indirect. + +**your licenses** are all the licenses granted to you for the software under +these terms. + +**use** means anything you do with the software requiring one of your licenses. + +**trademark** means trademarks, service marks, and similar rights. \ No newline at end of file diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/examples/fleet-server.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/examples/fleet-server.yaml new file mode 100644 index 00000000..b2ec9483 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/examples/fleet-server.yaml @@ -0,0 +1,17 @@ +version: 9.4.2 +deployment: + replicas: 1 + podTemplate: + spec: + serviceAccountName: fleet-server + automountServiceAccountToken: true +elasticsearchRefs: +- name: eck-elasticsearch +kibanaRef: + name: eck-kibana +http: + service: + spec: + type: ClusterIP +serviceAccount: + name: fleet-server diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/NOTES.txt b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/NOTES.txt new file mode 100644 index 00000000..eb3c879d --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/NOTES.txt @@ -0,0 +1,6 @@ + +1. Check Fleet Server status + $ kubectl get agent {{ include "fleet-server.fullname" . }} -n {{ .Release.Namespace }} + +2. Check Fleet Server pod status + $ kubectl get pods --namespace={{ .Release.Namespace }} -l fleet-server.k8s.elastic.co/name={{ include "fleet-server.fullname" . }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/_helpers.tpl b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/_helpers.tpl new file mode 100644 index 00000000..173f5089 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/_helpers.tpl @@ -0,0 +1,51 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "fleet-server.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "fleet-server.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "fleet-server.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "fleet-server.labels" -}} +helm.sh/chart: {{ include "fleet-server.chart" . }} +{{ include "fleet-server.selectorLabels" . }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- if .Values.labels }} +{{ toYaml .Values.labels }} +{{- end }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "fleet-server.selectorLabels" -}} +app.kubernetes.io/name: {{ include "fleet-server.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/cluster-role-binding.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/cluster-role-binding.yaml new file mode 100644 index 00000000..e5fee457 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/cluster-role-binding.yaml @@ -0,0 +1,33 @@ +{{- with .Values.clusterRoleBinding }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: {{ .name }} + labels: + {{- include "fleet-server.labels" $ | nindent 4 }} + {{- with .labels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if or $.Values.annotations .annotations }} + annotations: + {{- with $.Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- end }} +{{- with .subjects }} +subjects: +{{- range . }} + - kind: {{ .kind }} + name: {{ .name }} + namespace: {{ .namespace | default $.Release.Namespace | quote }} +{{- end }} +{{- end }} +roleRef: + kind: {{ .roleRef.kind }} + name: {{ .roleRef.name }} + apiGroup: {{ .roleRef.apiGroup }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/cluster-role.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/cluster-role.yaml new file mode 100644 index 00000000..f067b628 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/cluster-role.yaml @@ -0,0 +1,22 @@ +{{- with .Values.clusterRole }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: {{ .name }} + labels: + {{- include "fleet-server.labels" $ | nindent 4 }} + {{- with .labels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if or $.Values.annotations .annotations }} + annotations: + {{- with $.Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- end }} +rules: {{- toYaml .rules | nindent 2 }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/extra-objects.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/extra-objects.yaml new file mode 100644 index 00000000..c385106c --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/extra-objects.yaml @@ -0,0 +1,5 @@ +{{- range .Values.extraObjects }} +--- +{{ tpl . $ }} +{{- end }} + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/fleet-server.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/fleet-server.yaml new file mode 100644 index 00000000..2eb3b0d3 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/fleet-server.yaml @@ -0,0 +1,64 @@ +--- +apiVersion: agent.k8s.elastic.co/v1alpha1 +kind: Agent +metadata: + name: {{ include "fleet-server.fullname" . }} + labels: + {{- include "fleet-server.labels" . | nindent 4 }} + annotations: + eck.k8s.elastic.co/license: basic + {{- with .Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + version: {{ required "A Fleet Server version is required" (or ((.Values.spec).version) (.Values.version)) }} + mode: fleet + fleetServerEnabled: true + {{- if (or (hasKey (.Values.spec) "mode") (hasKey .Values "mode")) }} + {{- fail "mode cannot be changed" }} + {{- end }} + {{- if (or (hasKey (.Values.spec) "fleetServerEnabled") (hasKey .Values "fleetServerEnabled"))}} + {{- fail "fleetServerEnabled cannot be changed" }} + {{- end }} + + {{- $statefulSet := (or (hasKey (.Values.spec) "statefulSet") (hasKey .Values "statefulSet")) }} + {{- $deployment := (or (hasKey (.Values.spec) "deployment") (hasKey .Values "deployment")) }} + {{- if and (not $statefulSet) (not $deployment) }} + {{ fail "At least one of statefulSet or deployment is required" }} + {{- end }} + {{- if $statefulSet }} + {{- $ss := or ((.Values.spec).statefulSet) (.Values.statefulSet) }} + statefulSet: + {{- /* This is required to render the empty statefulSet ( {} ) properly */}} + {{- $ss | default dict | toYaml | nindent 4 }} + {{- end }} + {{- if $deployment }} + {{- $deploy := or ((.Values.spec).deployment) (.Values.deployment) }} + deployment: + {{- /* This is required to render the empty deployment ( {} ) properly */}} + {{- $deploy | default dict | toYaml | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).image) (.Values.image) }} + image: {{ . }} + {{- end }} + {{- with or ((.Values.spec).elasticsearchRefs) (.Values.elasticsearchRefs) }} + elasticsearchRefs: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).kibanaRef) (.Values.kibanaRef) }} + kibanaRef: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).policyID) (.Values.policyID) }} + policyID: {{ . }} + {{- end }} + {{- with or ((.Values.spec).http) (.Values.http) }} + http: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).revisionHistoryLimit) (.Values.revisionHistoryLimit) }} + revisionHistoryLimit: {{ . }} + {{- end }} + {{- with or (((.Values.spec).serviceAccount).name) ((.Values.serviceAccount).name) }} + serviceAccountName: {{ . }} + {{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/service-account.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/service-account.yaml new file mode 100644 index 00000000..0f8901d9 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/templates/service-account.yaml @@ -0,0 +1,22 @@ +{{- with .Values.serviceAccount }} +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ .name }} + namespace: {{ .namespace | default $.Release.Namespace | quote }} + labels: + {{- include "fleet-server.labels" $ | nindent 4 }} + {{- with .labels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if or $.Values.annotations .annotations }} + annotations: + {{- with $.Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- end }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/values.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/values.yaml new file mode 100644 index 00000000..d28ff7bd --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-fleet-server/values.yaml @@ -0,0 +1,187 @@ +--- +# Default values for eck-fleet-server. +# This is a YAML-formatted file. + +# Overridable names of the Fleet Server resource. +# By default, this is the Release name set for the chart, +# followed by 'eck-fleet-server'. +# +# nameOverride will override the name of the Chart with the name set here, +# so nameOverride: quickstart, would convert to '{{ Release.name }}-quickstart' +# +# nameOverride: "quickstart" +# +# fullnameOverride will override both the release name, and the chart name, +# and will name the Fleet Server resource exactly as specified. +# +# fullnameOverride: "quickstart" + +# Version of Elastic Fleet Server. +# +version: 9.4.2 + +# Labels that will be applied to Elastic Fleet Server. +# +labels: {} + +# Annotations that will be applied to Elastic Fleet Server. +# +annotations: {} + +# Elastic Fleet Server Agent image to deploy. +# Supports both tag and digest formats. +# image: docker.elastic.co/beats/elastic-agent:9.4.2 +# image: docker.elastic.co/beats/elastic-agent:9.4.2@sha256: +# image: docker.elastic.co/beats/elastic-agent@sha256: + +# ** Deprecation Notice ** +# The previous versions of this Helm Chart simply used the `spec` field here +# and allowed the user to specify any fields below `spec` that were templated directly +# into the final Agent/Fleet Server manifest. This is no longer the preferred way to specify these +# fields and each field that is supported underneath `spec` is now directly specified +# in this values file. Currently both patterns are supported for backwards compatibility +# but we plan to remove the `spec` field in the future. +# spec: {} + +# Referenced resources are below and both elasticsearchRefs and kibanaRef are required for a functional Fleet Server. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-configuration.html#k8s-elastic-agent-fleet-configuration-setting-referenced-resources +# +# Reference to ECK-managed Kibana instance. +# This is required for Fleet Server. +# +# kibanaRef: +# name: quickstart + # Optional namespace reference to Kibana instance. + # If not specified, then the namespace of the Fleet Server resource + # will be assumed. + # + # namespace: default + +# Reference to ECK-managed Elasticsearch instance. +# This is required for Fleet Server. +# +elasticsearchRefs: [] +# - name: eck-elasticsearch + # Optional namespace reference to Elasticsearch instance. + # If not specified, then the namespace of the Fleet Server resource + # will be assumed. + # + # namespace: default + # + # Optional secretName referencing an existing Kubernetes secret that contains connection information + # for associating a Fleet Server instance to a remote Elasticsearch instance not managed by ECK. + # The referenced secret must contain the following: + # - `url`: the URL to reach the Elastic resource + # - `username`: the username of the user to be authenticated to the Elastic resource + # - `password`: the password of the user to be authenticated to the Elastic resource + # - `ca.crt`: the CA certificate in PEM format (optional) + # - `api-key`: the key to authenticate against the Elastic resource instead of a username and password + # This field cannot be used in combination with the other fields name, namespace or serviceName. + # + # secretName: my-remote-es-credentials + +# policyID determines into which Agent Policy this Fleet Server will be enrolled. +policyID: eck-fleet-server + +# The HTTP layer configuration for the Fleet Server Service. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-configuration.html#k8s-elastic-agent-fleet-configuration-customize-fleet-server-service +# +# http: + +# Deployment or StatefulSet specification for Fleet Server. +# At least one is required of [deployment, statefulSet]. +# No default is currently set, refer to https://github.com/elastic/cloud-on-k8s/issues/7429. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-configuration.html#k8s-elastic-agent-fleet-configuration-chose-the-deployment-model +# +# deployment: +# replicas: 1 +# podTemplate: +# spec: +# serviceAccountName: fleet-server +# automountServiceAccountToken: true +# +# statefulSet: +# podTemplate: +# spec: +# serviceAccountName: fleet-server +# automountServiceAccountToken: true + +# Number of revisions to retain to allow rollback in the underlying Deployment. +# If not set Kubernetes sets this to 10 by default. +# +# revisionHistoryLimit: 2 + +# ServiceAccount to be used by Elastic Fleet Server. Some Fleet Server features (such as autodiscover or Kubernetes module metricsets) +# require that Fleet Server Pods interact with Kubernetes APIs. This functionality requires specific permissions +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-configuration.html#k8s-elastic-agent-fleet-configuration-role-based-access-control +# +serviceAccount: + name: fleet-server + # namespace: optional-namespace + +# ClusterRoleBinding to be used by Elastic Fleet Server. Similar to ServiceAccount, this is required in some scenarios. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-configuration.html#k8s-elastic-agent-fleet-configuration-role-based-access-control +# +clusterRoleBinding: + name: fleet-server + subjects: + - kind: ServiceAccount + name: fleet-server + # namespace: default + roleRef: + kind: ClusterRole + name: fleet-server + apiGroup: rbac.authorization.k8s.io + +# ClusterRole to be used by Elastic Fleet Server. Similar to ServiceAccount, this is required in some scenarios. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-configuration.html#k8s-elastic-agent-fleet-configuration-role-based-access-control +# +clusterRole: + name: fleet-server + rules: + - apiGroups: [""] + resources: + - pods + - namespaces + - nodes + verbs: + - get + - watch + - list + - apiGroups: ["apps"] + resources: + - replicasets + verbs: + - get + - watch + - list + - apiGroups: ["batch"] + resources: + - jobs + verbs: + - get + - watch + - list + - apiGroups: ["coordination.k8s.io"] + resources: + - leases + verbs: + - get + - create + - update + +# extraObjects allows injecting additional Kubernetes resources into the chart. +# These resources will be created/deleted alongside the chart release. +# The value is a list of strings, each string is a YAML manifest. +# Helm templating is supported within each manifest. +# Example: +# extraObjects: +# - | +# apiVersion: v1 +# kind: ConfigMap +# metadata: +# name: {{ include "fleet-server.fullname" . }}-extra-config +# namespace: {{ .Release.Namespace }} +# data: +# key: value +extraObjects: [] diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/.helmignore b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/.helmignore new file mode 100644 index 00000000..f1568daf --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/.helmignore @@ -0,0 +1,24 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +templates/tests diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/Chart.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/Chart.yaml new file mode 100644 index 00000000..45eab7a1 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/Chart.yaml @@ -0,0 +1,10 @@ +apiVersion: v2 +description: Kibana managed by the ECK operator +icon: https://helm.elastic.co/icons/kibana.png +kubeVersion: '>= 1.21.0-0' +name: eck-kibana +sources: +- https://github.com/elastic/cloud-on-k8s +- https://github.com/elastic/kibana +type: application +version: 0.19.1 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/LICENSE b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/LICENSE new file mode 100644 index 00000000..92503a72 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/LICENSE @@ -0,0 +1,93 @@ +Elastic License 2.0 + +URL: https://www.elastic.co/licensing/elastic-license + +## Acceptance + +By using the software, you agree to all of the terms and conditions below. + +## Copyright License + +The licensor grants you a non-exclusive, royalty-free, worldwide, +non-sublicensable, non-transferable license to use, copy, distribute, make +available, and prepare derivative works of the software, in each case subject to +the limitations and conditions below. + +## Limitations + +You may not provide the software to third parties as a hosted or managed +service, where the service provides users with access to any substantial set of +the features or functionality of the software. + +You may not move, change, disable, or circumvent the license key functionality +in the software, and you may not remove or obscure any functionality in the +software that is protected by the license key. + +You may not alter, remove, or obscure any licensing, copyright, or other notices +of the licensor in the software. Any use of the licensor’s trademarks is subject +to applicable law. + +## Patents + +The licensor grants you a license, under any patent claims the licensor can +license, or becomes able to license, to make, have made, use, sell, offer for +sale, import and have imported the software, in each case subject to the +limitations and conditions in this license. This license does not cover any +patent claims that you cause to be infringed by modifications or additions to +the software. If you or your company make any written claim that the software +infringes or contributes to infringement of any patent, your patent license for +the software granted under these terms ends immediately. If your company makes +such a claim, your patent license ends immediately for work on behalf of your +company. + +## Notices + +You must ensure that anyone who gets a copy of any part of the software from you +also gets a copy of these terms. + +If you modify the software, you must include in any modified copies of the +software prominent notices stating that you have modified the software. + +## No Other Rights + +These terms do not imply any licenses other than those expressly granted in +these terms. + +## Termination + +If you use the software in violation of these terms, such use is not licensed, +and your licenses will automatically terminate. If the licensor provides you +with a notice of your violation, and you cease all violation of this license no +later than 30 days after you receive that notice, your licenses will be +reinstated retroactively. However, if you violate these terms after such +reinstatement, any additional violation of these terms will cause your licenses +to terminate automatically and permanently. + +## No Liability + +*As far as the law allows, the software comes as is, without any warranty or +condition, and the licensor will not be liable to you for any damages arising +out of these terms or the use or nature of the software, under any kind of +legal claim.* + +## Definitions + +The **licensor** is the entity offering these terms, and the **software** is the +software the licensor makes available under these terms, including any portion +of it. + +**you** refers to the individual or entity agreeing to these terms. + +**your company** is any legal entity, sole proprietorship, or other kind of +organization that you work for, plus all organizations that have control over, +are under the control of, or are under common control with that +organization. **control** means ownership of substantially all the assets of an +entity, or the power to direct its management and policies by vote, contract, or +otherwise. Control can be direct or indirect. + +**your licenses** are all the licenses granted to you for the software under +these terms. + +**use** means anything you do with the software requiring one of your licenses. + +**trademark** means trademarks, service marks, and similar rights. \ No newline at end of file diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/http-configuration.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/http-configuration.yaml new file mode 100644 index 00000000..ecd74115 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/http-configuration.yaml @@ -0,0 +1,36 @@ +--- +# Version of Kibana. +# +version: 9.4.2 + +# Labels that will be applied to Kibana. +# +labels: {} + # key: value + +# Annotations that will be applied to Kibana. +# +annotations: {} + # key: value + +# Count of Kibana replicas to create. +# +count: 1 + +# Reference to ECK-managed Elasticsearch resource, ideally from {{ "elasticsearch.fullname" }} +# +elasticsearchRef: + name: eck-elasticsearch + # namespace: default +http: + service: + spec: + # Type of service to deploy for Kibana. + # This deploys a load balancer in a cloud service provider, where supported. + # + type: LoadBalancer + # tls: + # selfSignedCertificate: + # subjectAltNames: + # - ip: 1.2.3.4 + # - dns: kibana.example.com diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/ingress/kibana-aks.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/ingress/kibana-aks.yaml new file mode 100644 index 00000000..b7363dd0 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/ingress/kibana-aks.yaml @@ -0,0 +1,28 @@ +# The following is an example of a Kibana resource that is configured to use an Ingress resource in an AKS cluster. +# + +# Name of the Kibana instance. +# +fullnameOverride: kibana + +# Reference to ECK-managed Elasticsearch instance, ideally from {{ "elasticsearch.fullname" }} +# +elasticsearchRef: + name: elasticsearch +config: + server: + publicBaseUrl: "https://kibana.company.dev" + +ingress: + enabled: true + className: webapprouting.kubernetes.azure.com + annotations: + # This is required for AKS Loadbalancing to understand that it's communicating with + # an HTTPS backend. + nginx.ingress.kubernetes.io/backend-protocol: "HTTPS" + labels: + my: label + pathType: Prefix + hosts: + - host: "kibana.company.dev" + path: "/" diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/ingress/kibana-eks.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/ingress/kibana-eks.yaml new file mode 100644 index 00000000..c5f2f43b --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/ingress/kibana-eks.yaml @@ -0,0 +1,48 @@ +# The following is an example of a Kibana resource that is configured to use an Ingress resource in an EKS cluster. +# + +# Name of the Kibana instance. +# +fullnameOverride: kibana + +# Reference to ECK-managed Elasticsearch instance, ideally from {{ "elasticsearch.fullname" }} +# +elasticsearchRef: + name: elasticsearch +config: + server: + publicBaseUrl: "https://kibana.company.dev" + +ingress: + enabled: true + className: alb + annotations: + alb.ingress.kubernetes.io/scheme: "internet-facing" + alb.ingress.kubernetes.io/listen-ports: '[{"HTTPS":443}]' + alb.ingress.kubernetes.io/backend-protocol: "HTTPS" + alb.ingress.kubernetes.io/target-type: "ip" + # To use an ALB with ECK, you must provide a valid ACM certificate ARN or use certificate discovery. + # There are 2 options for EKS: + # 1. Create a valid ACM certificate, and uncomment the following annotation and update it to the correct ARN. + # 2. Create a valid ACM certificate and ensure that the hosts[0].host matches the certificate's Common Name (CN) and + # certificate discovery *should* find the certificate automatically and use it. + # + # ref: https://kubernetes-sigs.github.io/aws-load-balancer-controller/v2.8/guide/ingress/cert_discovery/ + # + # alb.ingress.kubernetes.io/certificate-arn: "arn:aws:acm:us-east-1:00000000000:certificate/b65be571-8220-4f2e-8cb1-94194535d877" + labels: + my: label + pathType: Prefix + hosts: + - host: "kibana.company.dev" + path: "/" +nodeSets: +- name: default + count: 3 + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + config: + node.store.allow_mmap: false diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/ingress/kibana-gke.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/ingress/kibana-gke.yaml new file mode 100644 index 00000000..61427581 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/examples/ingress/kibana-gke.yaml @@ -0,0 +1,31 @@ +# The following is an example of a Kibana resource that is configured to use an Ingress resource in a GKE cluster. +# + +# Name of the Kibana instance. +# +fullnameOverride: kibana + +# Reference to ECK-managed Elasticsearch instance, ideally from {{ "elasticsearch.fullname" }} +# +elasticsearchRef: + name: elasticsearch +config: + server: + publicBaseUrl: "https://kibana.company.dev" +http: + service: + metadata: + annotations: + # This is required for `ClusterIP` services (which are the default ECK service type) to be used with Ingress in GKE clusters. + cloud.google.com/neg: '{"ingress": true}' + # This is required to enable the GKE Ingress Controller to use HTTPS as the backend protocol. + cloud.google.com/app-protocols: '{"https":"HTTPS"}' + +ingress: + enabled: true + pathType: Prefix + hosts: + - host: "kibana.company.dev" + path: "/" + tls: + enabled: true diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/NOTES.txt b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/NOTES.txt new file mode 100644 index 00000000..9652161c --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/NOTES.txt @@ -0,0 +1,6 @@ + +1. Check Kibana status + $ kubectl get kibana {{ include "kibana.fullname" . }} -n {{ .Release.Namespace }} + +2. Check Kibana pod status + $ kubectl get pods --namespace={{ .Release.Namespace }} -l kibana.k8s.elastic.co/name={{ include "kibana.fullname" . }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/_helpers.tpl b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/_helpers.tpl new file mode 100644 index 00000000..eba5497d --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/_helpers.tpl @@ -0,0 +1,51 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "kibana.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "kibana.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "kibana.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "kibana.labels" -}} +helm.sh/chart: {{ include "kibana.chart" . }} +{{ include "kibana.selectorLabels" . }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- if .Values.labels }} +{{ toYaml .Values.labels }} +{{- end }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "kibana.selectorLabels" -}} +app.kubernetes.io/name: {{ include "kibana.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/extra-objects.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/extra-objects.yaml new file mode 100644 index 00000000..c385106c --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/extra-objects.yaml @@ -0,0 +1,5 @@ +{{- range .Values.extraObjects }} +--- +{{ tpl . $ }} +{{- end }} + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/ingress.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/ingress.yaml new file mode 100644 index 00000000..171463c0 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/ingress.yaml @@ -0,0 +1,48 @@ +{{- if .Values.ingress.enabled -}} +{{- $pathType := .Values.ingress.pathType | default "Prefix" -}} +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: {{ include "kibana.fullname" . }} + labels: + {{- include "kibana.labels" . | nindent 4 }} + {{- with .Values.ingress.labels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if .Values.ingress.annotations }} + annotations: + {{- with .Values.ingress.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- end }} +spec: + {{- if .Values.ingress.className }} + ingressClassName: {{ .Values.ingress.className | quote }} + {{- end }} + {{- if .Values.ingress.tls.enabled }} + tls: + - hosts: + {{- range .Values.ingress.hosts }} + - {{ .host | quote }} + {{- end }} + {{- if .Values.ingress.tls.secretName }} + secretName: {{ .Values.ingress.tls.secretName }} + {{- else }} + secretName: {{ include "kibana.fullname" . }}-kb-http-certs-internal + {{- end }} + {{- end }} + rules: + {{- range .Values.ingress.hosts }} + {{- $hostPath := .path | default "/" }} + - host: {{ .host | quote }} + http: + paths: + - path: {{ $hostPath }} + pathType: {{ $pathType }} + backend: + service: + name: {{ include "kibana.fullname" $ }}-kb-http + port: + number: 5601 + {{- end }} +{{ end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/kibana.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/kibana.yaml new file mode 100644 index 00000000..81a6293f --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/templates/kibana.yaml @@ -0,0 +1,66 @@ +--- +apiVersion: kibana.k8s.elastic.co/v1 +kind: Kibana +metadata: + name: {{ include "kibana.fullname" . }} + labels: + {{- include "kibana.labels" . | nindent 4 }} + annotations: + eck.k8s.elastic.co/license: basic + {{- with .Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + version: {{ required "A Kibana version is required" .Values.version }} + {{- /* + The following templates with 'or' are to allow both .spec.field and .field to be set for backwards + compatibility purposes. See https://github.com/elastic/cloud-on-k8s/pull/8192 for details. + */ -}} + {{- with or ((.Values.spec).image) (.Values.image) }} + image: {{ . }} + {{- end }} + {{- with or ((.Values.spec).count) (.Values.count) }} + count: {{ . }} + {{- end }} + {{- $esRef := or ((.Values.spec).elasticsearchRef) (.Values.elasticsearchRef) }} +{{- if not (or ($esRef).name ($esRef).secretName) }} + {{ fail "An elasticsearchRef name or secretName is required" }} + {{- end }} + elasticsearchRef: + {{- toYaml $esRef | nindent 4 }} + {{- $entsearchRef := or ((.Values.spec).enterpriseSearchRef) (.Values.enterpriseSearchRef) }} + {{- if $entsearchRef }} + enterpriseSearchRef: + {{- toYaml $entsearchRef | nindent 4 }} + {{- end }} + {{- $eprRef := or ((.Values.spec).packageRegistryRef) (.Values.packageRegistryRef) }} + {{- if $eprRef }} + packageRegistryRef: + {{- toYaml $eprRef | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).config) (.Values.config) }} + config: + {{ toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).http) (.Values.http) }} + http: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).podTemplate) (.Values.podTemplate) }} + podTemplate: + {{ toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).revisionHistoryLimit) (.Values.revisionHistoryLimit) }} + revisionHistoryLimit: {{ . }} + {{- end }} + {{- with or ((.Values.spec).secureSettings) (.Values.secureSettings) }} + secureSettings: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with or ((.Values.spec).serviceAccountName) (.Values.serviceAccountName) }} + serviceAccountName: {{ . }} + {{- end }} + {{- with or ((.Values.spec).monitoring) (.Values.monitoring) }} + monitoring: + {{- toYaml . | nindent 4 }} + {{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/values.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/values.yaml new file mode 100644 index 00000000..83a11f73 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-kibana/values.yaml @@ -0,0 +1,212 @@ +--- +# Default values for eck-kibana. +# This is a YAML-formatted file. + +# Overridable names of the Kibana resource. +# By default, this is the Release name set for the chart, +# followed by 'eck-kibana'. +# +# nameOverride will override the name of the Chart with the name set here, +# so nameOverride: quickstart, would convert to '{{ Release.name }}-quickstart' +# +# nameOverride: "quickstart" +# +# fullnameOverride will override both the release name, and the chart name, +# and will name the Kibana resource exactly as specified. +# +# fullnameOverride: "quickstart" + +# Version of Kibana. +# +version: 9.4.2 + +# Kibana Docker image to deploy. +# Supports both tag and digest formats. +# image: docker.elastic.co/kibana/kibana:9.4.2 +# image: docker.elastic.co/kibana/kibana:9.4.2@sha256: +# image: docker.elastic.co/kibana/kibana@sha256: + +# Labels that will be applied to Kibana. +# +labels: {} + +# Annotations that will be applied to Kibana. +# +annotations: {} + +# ** Deprecation Notice ** +# The previous versions of this Helm Chart simply used the `spec` field here +# and allowed the user to specify any fields below spec that were templated directly +# into the final Kibana manifest. This is no long the preferred way to specify these +# fields and each field that is supported underneath `spec` is now directly specified +# in this values file. Currently both patterns are supported for backwards compatibility +# but we plan to remove the `spec` field in the future. +# spec: {} + +# Count of Kibana replicas to create. +# +count: 1 + +# Reference to ECK-managed Elasticsearch resource. +# +elasticsearchRef: {} + # name: eck-elasticsearch + # Optional namespace reference to Elasticsearch resource. + # If not specified, then the namespace of the Kibana resource + # will be assumed. + # + # namespace: default + # + # Optional secretName referencing an existing Kubernetes secret that contains connection information + # for associating a Kibana instance to a remote Elasticsearch instance not managed by ECK. + # The referenced secret must contain the following: + # - `url`: the URL to reach the Elastic resource + # - `username`: the username of the user to be authenticated to the Elastic resource + # - `password`: the password of the user to be authenticated to the Elastic resource + # - `ca.crt`: the CA certificate in PEM format (optional) + # This field cannot be used in combination with the other fields name, namespace or serviceName. + # + # secretName: my-remote-es-credentials + +# Reference to an EnterpriseSearch running in the same Kubernetes cluster +# +# enterpriseSearchRef: + +# Reference to an PackageRegistry running in the same Kubernetes cluster +# +# packageRegistryRef: + +# The Kibana configuration (kibana.yml) +# ref: https://www.elastic.co/guide/en/kibana/current/settings.html +# +config: null + +# The HTTP layer configuration for Kibana. +# +# http: + +# PodTemplate provides customisation options (labels, annotations, affinity rules, +# resource requests, and so on) for the Kibana pods +# +# podTemplate: + +# Number of revisions to retain to allow rollback in the underlying deployment. +# By default, if not set, Kubernetes sets 10. +# +# revisionHistoryLimit: 2 + +# Control Kibana Secure Settings. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-kibana-secure-settings.html +# +secureSettings: [] + +# Used to check access from the current resource to a resource (for ex. Elasticsearch) in a different namespace. +# Can only be used if ECK is enforcing RBAC on references. +# +# serviceAccountName: "" + +# Settings for configuring stack monitoring. +# ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-stack-monitoring.html +# +monitoring: {} + # metrics: + # elasticsearchRefs: + # - name: monitoring + # namespace: observability + # logs: + # elasticsearchRefs: + # - name: monitoring + # namespace: observability + +# Settings for controlling Kibana ingress. Enabling ingress will expose your Kibana instance +# to the public internet, and as such is disabled by default. +# +# *NOTE* when configuring Kibana Ingress, ensure that `config.server.publicBaseUrl` setting for +# Kibana is also set, as it is required when exposing Kibana behind a load balancer/ingress. +# Also of note are `server.basePath`, and `server.rewriteBasePath` settings in the Kibana configuration. +# +# ref: https://www.elastic.co/guide/en/kibana/current/settings.html +# +# Each Cloud Service Provider has different requirements for setting up Ingress. Some links to common documentation are: +# - AWS: https://docs.aws.amazon.com/eks/latest/userguide/alb-ingress.html +# - GCP: https://cloud.google.com/kubernetes-engine/docs/concepts/ingress +# - Azure: https://learn.microsoft.com/en-us/azure/aks/app-routing +# - Nginx: https://kubernetes.github.io/ingress-nginx/ +# +ingress: + enabled: false + + # Annotations that will be applied to the Ingress resource. Note that some ingress controllers are controlled via annotations. + # + # Nginx Annotations: https://kubernetes.github.io/ingress-nginx/user-guide/nginx-configuration/annotations/ + # + # Common annotations: + # kubernetes.io/ingress.class: gce # Configures the Ingress resource to use the GCE ingress controller and create an external Application Load Balancer. + # kubernetes.io/ingress.class: gce-internal # Configures the Ingress resource to use the GCE ingress controller and create an internal Application Load Balancer. + # kubernetes.io/ingress.class: nginx # Configures the Ingress resource to use the NGINX ingress controller. + # + annotations: {} + + # Labels that will be applied to the Ingress resource. + # + labels: {} + + # Some ingress controllers require the use of a specific class name to route traffic to the correct controller, notably AKS and EKS, which + # replaces the use of the 'kubernetes.io/ingress.class' annotation. + # + # className: webapprouting.kubernetes.azure.com | alb + + # Ingress paths are required to have a corresponding path type. Defaults to 'Prefix'. + # + # There are 3 supported path types: + # - ImplementationSpecific + # - Prefix + # - Exact + # + # ref: https://kubernetes.io/docs/concepts/services-networking/ingress/#path-types + # + pathType: Prefix + + # Hosts are a list of hosts included in the Ingress definition, with a corresponding path at which the Kibana service + # will be exposed. Each host in the list should be a fully qualified DNS name that will resolve to the exposed Ingress object. + # + # ref: https://kubernetes.io/docs/concepts/services-networking/ingress/#name-based-virtual-hosting + # + hosts: + - host: chart-example.local + path: / + + # TLS defines whether TLS will be enabled on the Ingress resource. + # + # *NOTE* Many Cloud Service Providers handle TLS in a custom manner, and as such, it is recommended to consult their documentation. + # Notably GKE and Nginx Ingress Controllers seems to respect the Ingress TLS settings, AKS and EKS ignore it. + # + # - AKS: https://learn.microsoft.com/en-us/azure/aks/app-routing-dns-ssl + # - GKE: https://cloud.google.com/kubernetes-engine/docs/concepts/ingress#options_for_providing_ssl_certificates + # - EKS: https://aws.amazon.com/blogs/containers/serve-distinct-domains-with-tls-powered-by-acm-on-amazon-eks/ + # - Nginx: https://kubernetes.github.io/ingress-nginx/user-guide/tls/ + # + # Kubernetes ingress TLS documentation: + # ref: https://kubernetes.io/docs/concepts/services-networking/ingress/#tls + # + tls: + enabled: false + # Optional Kubernetes secret name that contains a base64 encoded PEM certificate and private key that corresponds to the above 'hosts' definitions. + # If tls is enabled, but this field is not set, the self-signed certificate and key created by the ECK operator will be used. + # secretName: chart-example-tls + +# extraObjects allows injecting additional Kubernetes resources into the chart. +# These resources will be created/deleted alongside the chart release. +# The value is a list of strings, each string is a YAML manifest. +# Helm templating is supported within each manifest. +# Example: +# extraObjects: +# - | +# apiVersion: v1 +# kind: ConfigMap +# metadata: +# name: {{ include "kibana.fullname" . }}-extra-config +# namespace: {{ .Release.Namespace }} +# data: +# key: value +extraObjects: [] diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/.helmignore b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/.helmignore new file mode 100644 index 00000000..f1568daf --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/.helmignore @@ -0,0 +1,24 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +templates/tests diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/Chart.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/Chart.yaml new file mode 100644 index 00000000..f1696e26 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/Chart.yaml @@ -0,0 +1,10 @@ +apiVersion: v2 +description: Logstash managed by the ECK operator +icon: https://helm.elastic.co/icons/logstash.png +kubeVersion: '>= 1.21.0-0' +name: eck-logstash +sources: +- https://github.com/elastic/cloud-on-k8s +- https://github.com/elastic/logstash +type: application +version: 0.19.1 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/LICENSE b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/LICENSE new file mode 100644 index 00000000..92503a72 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/LICENSE @@ -0,0 +1,93 @@ +Elastic License 2.0 + +URL: https://www.elastic.co/licensing/elastic-license + +## Acceptance + +By using the software, you agree to all of the terms and conditions below. + +## Copyright License + +The licensor grants you a non-exclusive, royalty-free, worldwide, +non-sublicensable, non-transferable license to use, copy, distribute, make +available, and prepare derivative works of the software, in each case subject to +the limitations and conditions below. + +## Limitations + +You may not provide the software to third parties as a hosted or managed +service, where the service provides users with access to any substantial set of +the features or functionality of the software. + +You may not move, change, disable, or circumvent the license key functionality +in the software, and you may not remove or obscure any functionality in the +software that is protected by the license key. + +You may not alter, remove, or obscure any licensing, copyright, or other notices +of the licensor in the software. Any use of the licensor’s trademarks is subject +to applicable law. + +## Patents + +The licensor grants you a license, under any patent claims the licensor can +license, or becomes able to license, to make, have made, use, sell, offer for +sale, import and have imported the software, in each case subject to the +limitations and conditions in this license. This license does not cover any +patent claims that you cause to be infringed by modifications or additions to +the software. If you or your company make any written claim that the software +infringes or contributes to infringement of any patent, your patent license for +the software granted under these terms ends immediately. If your company makes +such a claim, your patent license ends immediately for work on behalf of your +company. + +## Notices + +You must ensure that anyone who gets a copy of any part of the software from you +also gets a copy of these terms. + +If you modify the software, you must include in any modified copies of the +software prominent notices stating that you have modified the software. + +## No Other Rights + +These terms do not imply any licenses other than those expressly granted in +these terms. + +## Termination + +If you use the software in violation of these terms, such use is not licensed, +and your licenses will automatically terminate. If the licensor provides you +with a notice of your violation, and you cease all violation of this license no +later than 30 days after you receive that notice, your licenses will be +reinstated retroactively. However, if you violate these terms after such +reinstatement, any additional violation of these terms will cause your licenses +to terminate automatically and permanently. + +## No Liability + +*As far as the law allows, the software comes as is, without any warranty or +condition, and the licensor will not be liable to you for any damages arising +out of these terms or the use or nature of the software, under any kind of +legal claim.* + +## Definitions + +The **licensor** is the entity offering these terms, and the **software** is the +software the licensor makes available under these terms, including any portion +of it. + +**you** refers to the individual or entity agreeing to these terms. + +**your company** is any legal entity, sole proprietorship, or other kind of +organization that you work for, plus all organizations that have control over, +are under the control of, or are under common control with that +organization. **control** means ownership of substantially all the assets of an +entity, or the power to direct its management and policies by vote, contract, or +otherwise. Control can be direct or indirect. + +**your licenses** are all the licenses granted to you for the software under +these terms. + +**use** means anything you do with the software requiring one of your licenses. + +**trademark** means trademarks, service marks, and similar rights. \ No newline at end of file diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/basic-eck.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/basic-eck.yaml new file mode 100644 index 00000000..f22fe426 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/basic-eck.yaml @@ -0,0 +1,44 @@ +--- +# values corresponding to config/recipes/logstash/logstash-eck.yaml +version: 9.4.2 + +elasticsearchRefs: + - clusterName: eck + name: elasticsearch + +pipelines: + - pipeline.id: main + config.string: | + input { + beats { + port => 5044 + } + } + filter { + grok { + match => { "message" => "%{HTTPD_COMMONLOG}"} + } + geoip { + source => "[source][address]" + target => "[source]" + } + } + output { + elasticsearch { + hosts => [ "${ECK_ES_HOSTS}" ] + user => "${ECK_ES_USER}" + password => "${ECK_ES_PASSWORD}" + ssl_certificate_authorities => "${ECK_ES_SSL_CERTIFICATE_AUTHORITY}" + } + } + +services: + - name: beats + service: + spec: + type: ClusterIP + ports: + - port: 5044 + name: "filebeat" + protocol: TCP + targetPort: 5044 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/es-role.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/es-role.yaml new file mode 100644 index 00000000..e03d7cdc --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/es-role.yaml @@ -0,0 +1,25 @@ +--- +# values corresponding to config/recipes/logstash/logstash-es-role.yaml +version: 9.4.2 + +elasticsearchRefs: + - clusterName: eck + name: elasticsearch + +pipelines: + - pipeline.id: main + config.string: | + input { exec { command => "uptime" interval => 10 } } + output { + elasticsearch { + hosts => [ "${ECK_ES_HOSTS}" ] + ssl_enabled => true + ssl_certificate_authorities => "${ECK_ES_SSL_CERTIFICATE_AUTHORITY}" + user => "${ECK_ES_USER}" + password => "${ECK_ES_PASSWORD}" + index => "my-index" + data_stream => false + ilm_enabled => false + manage_template => false + } + } diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/monitored.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/monitored.yaml new file mode 100644 index 00000000..c7dbafe7 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/monitored.yaml @@ -0,0 +1,49 @@ +--- +# values corresponding to config/recipes/logstash/logstash-monitored.yaml +version: 9.4.2 + +monitoring: + metrics: + elasticsearchRefs: + - name: elasticsearch-monitoring + +pipelines: + - pipeline.id: main + config.string: | + input { + beats { + port => 5044 + } + } + filter { + grok { + match => { "message" => "%{HTTPD_COMMONLOG}"} + } + geoip { + source => "[source][address]" + target => "[source]" + } + } + output { + elasticsearch { + hosts => [ "${ECK_ES_HOSTS}" ] + user => "${ECK_ES_USER}" + password => "${ECK_ES_PASSWORD}" + ssl_certificate_authorities => "${ECK_ES_SSL_CERTIFICATE_AUTHORITY}" + } + } + +elasticsearchRefs: + - clusterName: eck + name: elasticsearch + +services: + - name: beats + service: + spec: + type: ClusterIP + ports: + - port: 5044 + name: "filebeat" + protocol: TCP + targetPort: 5044 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/multi.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/multi.yaml new file mode 100644 index 00000000..cced33d8 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/multi.yaml @@ -0,0 +1,78 @@ +--- +# values corresponding to config/recipes/logstash/logstash-multi.yaml +version: 9.4.2 + +pipelines: + - pipeline.id: main + config.string: | + input { + beats { + port => 5044 + } + } + filter { + grok { + match => { "message" => "%{HTTPD_COMMONLOG}"} + } + geoip { + source => "[source][address]" + target => "[source]" + } + } + output { + pipeline { + send_to => 'prod' + } + pipeline { + send_to => 'qa' + } + } + - pipeline.id: production + config.string: | + input { + pipeline { + address => 'prod' + } + } + output { + elasticsearch { + hosts => [ "${PROD_ES_ES_HOSTS}" ] + user => "${PROD_ES_ES_USER}" + password => "${PROD_ES_ES_PASSWORD}" + ssl_certificate_authorities => "${PROD_ES_ES_SSL_CERTIFICATE_AUTHORITY}" + } + } + - pipeline.id: qa + config.string: | + input { + pipeline { + address => 'qa' + } + } + output { + elasticsearch { + hosts => [ "${QA_ES_ES_HOSTS}" ] + user => "${QA_ES_ES_USER}" + password => "${QA_ES_ES_PASSWORD}" + ssl_certificate_authorities => "${QA_ES_ES_SSL_CERTIFICATE_AUTHORITY}" + } + } + +elasticsearchRefs: + - clusterName: prod-es + name: production + - clusterName: qa-es + name: qa + namespace: qa + +services: + - name: beats + service: + spec: + type: ClusterIP + ports: + - port: 5044 + name: "filebeat" + protocol: TCP + targetPort: 5044 + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/volumes.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/volumes.yaml new file mode 100644 index 00000000..02df0fd0 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/examples/volumes.yaml @@ -0,0 +1,107 @@ +--- +# values corresponding to config/recipes/logstash/logstash-volumes.yaml +version: 9.4.2 + +config: + log.level: info + queue.type: persisted + path.queue: /usr/share/logstash/pq + +podTemplate: + spec: + containers: + - name: logstash + volumeMounts: + - mountPath: /usr/share/logstash/pq + name: pq + readOnly: false + - mountPath: /usr/share/logstash/dlq + name: dlq + readOnly: false + +pipelines: + - pipeline.id: dlq_read + dead_letter_queue.enable: false + config.string: | + input { + dead_letter_queue { + path => "/usr/share/logstash/dlq" + commit_offsets => true + pipeline_id => "beats" + clean_consumed => true + } + } + filter { + mutate { + remove_field => "[geoip][location]" + } + } + output { + elasticsearch { + hosts => [ "${ECK_ES_HOSTS}" ] + user => "${ECK_ES_USER}" + password => "${ECK_ES_PASSWORD}" + ssl_certificate_authorities => "${ECK_ES_SSL_CERTIFICATE_AUTHORITY}" + } + } + - pipeline.id: beats + dead_letter_queue.enable: true + path.dead_letter_queue: /usr/share/logstash/dlq + config.string: | + input { + beats { + port => 5044 + } + } + filter { + grok { + match => { "message" => "%{HTTPD_COMMONLOG}"} + } + geoip { + source => "[source][address]" + target => "[source]" + } + } + output { + elasticsearch { + hosts => [ "${ECK_ES_HOSTS}" ] + user => "${ECK_ES_USER}" + password => "${ECK_ES_PASSWORD}" + ssl_certificate_authorities => "${ECK_ES_SSL_CERTIFICATE_AUTHORITY}" + } + } + +volumeClaimTemplates: + - metadata: + name: pq + spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 10Gi + - metadata: + name: dlq + spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 5Gi + + +elasticsearchRefs: + - clusterName: eck + name: elasticsearch + +services: + - name: beats + service: + spec: + type: ClusterIP + ports: + - port: 5044 + name: "filebeat" + protocol: TCP + targetPort: 5044 + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/NOTES.txt b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/NOTES.txt new file mode 100644 index 00000000..c2f255af --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/NOTES.txt @@ -0,0 +1,6 @@ + +1. Check Logstash status + $ kubectl get logstash {{ include "logstash.fullname" . }} -n {{ .Release.Namespace }} + +2. Check Logstash pod status + $ kubectl get pods --namespace={{ .Release.Namespace }} -l logstash.k8s.elastic.co/name={{ include "logstash.fullname" . }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/_helpers.tpl b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/_helpers.tpl new file mode 100644 index 00000000..7efd669f --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/_helpers.tpl @@ -0,0 +1,51 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "logstash.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "logstash.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "logstash.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "logstash.labels" -}} +helm.sh/chart: {{ include "logstash.chart" . }} +{{ include "logstash.selectorLabels" . }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- if .Values.labels }} +{{ toYaml .Values.labels }} +{{- end }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "logstash.selectorLabels" -}} +app.kubernetes.io/name: {{ include "logstash.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/extra-objects.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/extra-objects.yaml new file mode 100644 index 00000000..c385106c --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/extra-objects.yaml @@ -0,0 +1,5 @@ +{{- range .Values.extraObjects }} +--- +{{ tpl . $ }} +{{- end }} + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/logstash.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/logstash.yaml new file mode 100644 index 00000000..8ba52ef6 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/templates/logstash.yaml @@ -0,0 +1,58 @@ +--- +apiVersion: logstash.k8s.elastic.co/v1alpha1 +kind: Logstash +metadata: + name: {{ include "logstash.fullname" . }} + labels: + {{- include "logstash.labels" . | nindent 4 }} + annotations: + eck.k8s.elastic.co/license: basic + {{- with .Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + version: {{ required "A Logstash version is required" .Values.version }} + count: {{ required "A pod count is required" .Values.count }} + {{- with .Values.image }} + image: {{ . }} + {{- end }} + {{- with .Values.serviceAccountName }} + serviceAccountName: {{ . }} + {{- end }} + {{- with .Values.revisionHistoryLimit }} + revisionHistoryLimit: {{ . }} + {{- end }} + + {{- if and .Values.config .Values.configRef }} + {{- fail "config and configRef are mutually exclusive!" }} + {{- end }} + {{- with .Values.config }} + config: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .Values.configRef }} + configRef: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .Values.podTemplate }} + podTemplate: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .Values.monitoring }} + monitoring: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if and .Values.pipelines .Values.pipelinesRef }} + {{- fail "pipelines and pipelinesRef are mutually exclusive!" }} + {{- end }} + {{- with .Values.pipelinesRef }} + pipelinesRef: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if .Values.pipelines }} + pipelines: {{ toYaml .Values.pipelines | nindent 4 }} + {{- end }} + volumeClaimTemplates: {{ toYaml .Values.volumeClaimTemplates | nindent 4 }} + elasticsearchRefs: {{ toYaml .Values.elasticsearchRefs | nindent 4 }} + services: {{ toYaml .Values.services | nindent 4 }} + secureSettings: {{ toYaml .Values.secureSettings | nindent 4 }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/values.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/values.yaml new file mode 100644 index 00000000..e72dbac1 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-logstash/values.yaml @@ -0,0 +1,133 @@ +--- +# Default values for eck-logstash. +# This is a YAML-formatted file. + +# Overridable names of the Logstash resource. +# By default, this is the Release name set for the chart, +# followed by 'eck-logstash'. +# +# nameOverride will override the name of the Chart with the name set here, +# so nameOverride: quickstart, would convert to '{{ Release.name }}-quickstart' +# +# nameOverride: "quickstart" +# +# fullnameOverride will override both the release name, and the chart name, +# and will name the Logstash resource exactly as specified. +# +# fullnameOverride: "quickstart" + +# Version of Logstash. +# +version: 9.4.2 + +# Logstash Docker image to deploy. +# Supports both tag and digest formats. +# image: docker.elastic.co/logstash/logstash:9.4.2-SNAPSHOT +# image: docker.elastic.co/logstash/logstash:9.4.2-SNAPSHOT@sha256: +# image: docker.elastic.co/logstash/logstash@sha256: + +# Used to check access from the current resource to a resource (for ex. a remote Elasticsearch cluster) in a different namespace. +# Can only be used if ECK is enforcing RBAC on references. +# +# serviceAccountName: "" + +# Labels that will be applied to Logstash. +# +labels: {} + +# Annotations that will be applied to Logstash. +# +annotations: {} + +# Number of revisions to retain to allow rollback in the underlying StatefulSets. +# By default, if not set, Kubernetes sets 10. +# +# revisionHistoryLimit: 2 + +# Controlling the number of pods. +# ref: https://www.elastic.co/docs/deploy-manage/deploy/cloud-on-k8s/logstash-plugins#k8s-logstash-working-with-plugins-scaling +# +count: 1 + +# The logstash configuration, the ECK equivalent to logstash.yml +# +# NOTE: The `config` and `configRef` fields are mutually exclusive. Only one of them should be defined at a time, +# as using both may cause conflicts. +# ref: https://www.elastic.co/docs/deploy-manage/deploy/cloud-on-k8s/configuration-logstash#k8s-logstash-configuring-logstash +# +config: {} + +# Reference a configuration in a Secret. +# ref: https://www.elastic.co/docs/deploy-manage/deploy/cloud-on-k8s/configuration-logstash#k8s-logstash-configuring-logstash +# +# configRef: +# secretName: '' + +# Set podTemplate to customize the pod used by Logstash +# ref: https://www.elastic.co/docs/deploy-manage/deploy/cloud-on-k8s/customize-pods +# +podTemplate: {} + +# Settings for configuring stack monitoring. +# ref: https://www.elastic.co/docs/deploy-manage/monitor/stack-monitoring/eck-stack-monitoring +# +monitoring: {} + # metrics: + # elasticsearchRefs: + # - name: monitoring + # namespace: observability + # logs: + # elasticsearchRefs: + # - name: monitoring + # namespace: observability + +# The Logstash pipelines, the ECK equivalent to pipelines.yml +# +# NOTE: The `pipelines` and `pipelinesRef` fields are mutually exclusive. Only one of them should be defined at a time, +# as using both may cause conflicts. +# ref: https://www.elastic.co/docs/deploy-manage/deploy/cloud-on-k8s/configuration-logstash#k8s-logstash-pipelines +# +pipelines: [] + +# Reference a pipelines configuration in a Secret. +# ref: https://www.elastic.co/docs/deploy-manage/deploy/cloud-on-k8s/configuration-logstash#k8s-logstash-pipelines +# +# pipelinesRef: +# secretName: '' + +# volumeClaimTemplates +# ref: https://www.elastic.co/docs/deploy-manage/deploy/cloud-on-k8s/configuration-logstash#k8s-volume-claim-settings +# +volumeClaimTemplates: [] + +# ElasticsearchRefs are references to Elasticsearch clusters running in the same Kubernetes cluster. +# Ensure that the 'clusterName' field matches what is referenced in the pipeline. +# ref: https://www.elastic.co/docs/deploy-manage/deploy/cloud-on-k8s/configuration-logstash#k8s-logstash-pipelines-es +# +elasticsearchRefs: [] +# - namespace: '' +# name: '' +# clusterName: '' +# serviceName: '' +# secretName: '' + +services: [] + +# SecureSettings is a list of references to Kubernetes Secrets containing sensitive configuration options for the Logstash +secureSettings: [] + +# extraObjects allows injecting additional Kubernetes resources into the chart. +# These resources will be created/deleted alongside the chart release. +# The value is a list of strings, each string is a YAML manifest. +# Helm templating is supported within each manifest. +# Example: +# extraObjects: +# - | +# apiVersion: v1 +# kind: ConfigMap +# metadata: +# name: {{ include "logstash.fullname" . }}-extra-config +# namespace: {{ .Release.Namespace }} +# data: +# key: value +extraObjects: [] diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/.helmignore b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/.helmignore new file mode 100644 index 00000000..f1568daf --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/.helmignore @@ -0,0 +1,24 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +templates/tests diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/Chart.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/Chart.yaml new file mode 100644 index 00000000..0362730a --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/Chart.yaml @@ -0,0 +1,9 @@ +apiVersion: v2 +description: Elastic Package Registry managed by the ECK operator +kubeVersion: '>= 1.21.0-0' +name: eck-package-registry +sources: +- https://github.com/elastic/cloud-on-k8s +- https://github.com/elastic/package-registry +type: application +version: 0.19.1 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/LICENSE b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/LICENSE new file mode 100644 index 00000000..92503a72 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/LICENSE @@ -0,0 +1,93 @@ +Elastic License 2.0 + +URL: https://www.elastic.co/licensing/elastic-license + +## Acceptance + +By using the software, you agree to all of the terms and conditions below. + +## Copyright License + +The licensor grants you a non-exclusive, royalty-free, worldwide, +non-sublicensable, non-transferable license to use, copy, distribute, make +available, and prepare derivative works of the software, in each case subject to +the limitations and conditions below. + +## Limitations + +You may not provide the software to third parties as a hosted or managed +service, where the service provides users with access to any substantial set of +the features or functionality of the software. + +You may not move, change, disable, or circumvent the license key functionality +in the software, and you may not remove or obscure any functionality in the +software that is protected by the license key. + +You may not alter, remove, or obscure any licensing, copyright, or other notices +of the licensor in the software. Any use of the licensor’s trademarks is subject +to applicable law. + +## Patents + +The licensor grants you a license, under any patent claims the licensor can +license, or becomes able to license, to make, have made, use, sell, offer for +sale, import and have imported the software, in each case subject to the +limitations and conditions in this license. This license does not cover any +patent claims that you cause to be infringed by modifications or additions to +the software. If you or your company make any written claim that the software +infringes or contributes to infringement of any patent, your patent license for +the software granted under these terms ends immediately. If your company makes +such a claim, your patent license ends immediately for work on behalf of your +company. + +## Notices + +You must ensure that anyone who gets a copy of any part of the software from you +also gets a copy of these terms. + +If you modify the software, you must include in any modified copies of the +software prominent notices stating that you have modified the software. + +## No Other Rights + +These terms do not imply any licenses other than those expressly granted in +these terms. + +## Termination + +If you use the software in violation of these terms, such use is not licensed, +and your licenses will automatically terminate. If the licensor provides you +with a notice of your violation, and you cease all violation of this license no +later than 30 days after you receive that notice, your licenses will be +reinstated retroactively. However, if you violate these terms after such +reinstatement, any additional violation of these terms will cause your licenses +to terminate automatically and permanently. + +## No Liability + +*As far as the law allows, the software comes as is, without any warranty or +condition, and the licensor will not be liable to you for any damages arising +out of these terms or the use or nature of the software, under any kind of +legal claim.* + +## Definitions + +The **licensor** is the entity offering these terms, and the **software** is the +software the licensor makes available under these terms, including any portion +of it. + +**you** refers to the individual or entity agreeing to these terms. + +**your company** is any legal entity, sole proprietorship, or other kind of +organization that you work for, plus all organizations that have control over, +are under the control of, or are under common control with that +organization. **control** means ownership of substantially all the assets of an +entity, or the power to direct its management and policies by vote, contract, or +otherwise. Control can be direct or indirect. + +**your licenses** are all the licenses granted to you for the software under +these terms. + +**use** means anything you do with the software requiring one of your licenses. + +**trademark** means trademarks, service marks, and similar rights. \ No newline at end of file diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/NOTES.txt b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/NOTES.txt new file mode 100644 index 00000000..51943d84 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/NOTES.txt @@ -0,0 +1,6 @@ + +1. Check Package Registry status + $ kubectl get epr {{ include "epr.fullname" . }} -n {{ .Release.Namespace }} + +2. Check Package Registry pod status + $ kubectl get pods --namespace={{ .Release.Namespace }} -l packageregistry.k8s.elastic.co/name={{ include "epr.fullname" . }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/_helpers.tpl b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/_helpers.tpl new file mode 100644 index 00000000..1bb771b1 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/_helpers.tpl @@ -0,0 +1,51 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "epr.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "epr.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "epr.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "epr.labels" -}} +helm.sh/chart: {{ include "epr.chart" . }} +{{ include "epr.selectorLabels" . }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- if .Values.labels }} +{{ toYaml .Values.labels }} +{{- end }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "epr.selectorLabels" -}} +app.kubernetes.io/name: {{ include "epr.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/epr.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/epr.yaml new file mode 100644 index 00000000..2cfb90c1 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/epr.yaml @@ -0,0 +1,35 @@ +--- +apiVersion: packageregistry.k8s.elastic.co/v1alpha1 +kind: PackageRegistry +metadata: + name: {{ include "epr.fullname" . }} + labels: + {{- include "epr.labels" . | nindent 4 }} + annotations: + eck.k8s.elastic.co/license: basic + {{- with .Values.annotations }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + version: {{ required "A Elastic Package Registry version is required" .Values.version }} + {{- with (.Values.image) }} + image: {{ . }} + {{- end }} + {{- with (.Values.count) }} + count: {{ . }} + {{- end }} + {{- with (.Values.config) }} + config: + {{ toYaml . | nindent 4 }} + {{- end }} + {{- with (.Values.http) }} + http: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with (.Values.podTemplate) }} + podTemplate: + {{ toYaml . | nindent 4 }} + {{- end }} + {{- with (.Values.revisionHistoryLimit) }} + revisionHistoryLimit: {{ . }} + {{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/extra-objects.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/extra-objects.yaml new file mode 100644 index 00000000..c385106c --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/templates/extra-objects.yaml @@ -0,0 +1,5 @@ +{{- range .Values.extraObjects }} +--- +{{ tpl . $ }} +{{- end }} + diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/values.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/values.yaml new file mode 100644 index 00000000..4025bc8f --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/charts/eck-package-registry/values.yaml @@ -0,0 +1,75 @@ +--- +# Default values for eck-package-registry. +# This is a YAML-formatted file. + +# Overridable names of the PackageRegistry resource. +# By default, this is the Release name set for the chart, +# followed by 'eck-epr'. +# +# nameOverride will override the name of the Chart with the name set here, +# so nameOverride: quickstart, would convert to '{{ Release.name }}-quickstart' +# +# nameOverride: "quickstart" +# +# fullnameOverride will override both the release name, and the chart name, +# and will name the PackageRegistry resource exactly as specified. +# +# fullnameOverride: "quickstart" + +# Version of Package Registry. +# +version: 9.2.2 + +# Elastic Package Registry Docker image to deploy. +# Supports both tag and digest formats. +# image: docker.elastic.co/package-registry/distribution:lite-9.2.2 +# image: docker.elastic.co/package-registry/distribution:lite-9.2.2@sha256: +# image: docker.elastic.co/package-registry/distribution@sha256: + +# Labels that will be applied to Package Registry. +# +labels: {} + +# Annotations that will be applied to Package Registry. +# +annotations: {} + + +# Count of Package Registry replicas to create. +# +count: 1 + +# The Package Registry configuration (config.yml) +# ref: https://github.com/elastic/package-registry/blob/main/config.reference.yml +# +config: null + +# The HTTP layer configuration for Package Registry. +# +# http: + +# PodTemplate provides customisation options (labels, annotations, affinity rules, +# resource requests, and so on) for the EPR pods +# +# podTemplate: + +# Number of revisions to retain to allow rollback in the underlying deployment. +# By default, if not set, Kubernetes sets 10. +# +# revisionHistoryLimit: 2 + +# extraObjects allows injecting additional Kubernetes resources into the chart. +# These resources will be created/deleted alongside the chart release. +# The value is a list of strings, each string is a YAML manifest. +# Helm templating is supported within each manifest. +# Example: +# extraObjects: +# - | +# apiVersion: v1 +# kind: ConfigMap +# metadata: +# name: {{ include "epr.fullname" . }}-extra-config +# namespace: {{ .Release.Namespace }} +# data: +# key: value +extraObjects: [] diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/examples/agent/fleet-agents.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/agent/fleet-agents.yaml new file mode 100644 index 00000000..4358b6f6 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/agent/fleet-agents.yaml @@ -0,0 +1,122 @@ +--- +eck-elasticsearch: + enabled: true + + # Name of the Elasticsearch instance. + # + fullnameOverride: elasticsearch + + nodeSets: + - name: default + count: 3 + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + config: + node.store.allow_mmap: false + +eck-kibana: + enabled: true + + # Name of the Kibana instance. + # + fullnameOverride: kibana + + # Reference to ECK-managed Elasticsearch instance, ideally from {{ "elasticsearch.fullname" }} + # + elasticsearchRef: + name: elasticsearch + + config: + # Note that these are specific to the namespace into which this example is installed, and are + # using `elastic-stack` as configured here and detailed in the README when installing: + # + # `helm install es-kb-quickstart elastic/eck-stack -n elastic-stack` + # + # If installed outside of the `elastic-stack` namespace, the following 2 lines need modification. + xpack.fleet.agents.elasticsearch.hosts: ["https://elasticsearch-es-http.elastic-stack.svc:9200"] + xpack.fleet.agents.fleet_server.hosts: ["https://fleet-server-agent-http.elastic-stack.svc:8220"] + xpack.fleet.packages: + - name: system + version: latest + - name: elastic_agent + version: latest + - name: fleet_server + version: latest + - name: kubernetes + version: latest + xpack.fleet.agentPolicies: + - name: Fleet Server on ECK policy + id: eck-fleet-server + namespace: default + is_managed: true + monitoring_enabled: + - logs + - metrics + package_policies: + - name: fleet_server-1 + id: fleet_server-1 + package: + name: fleet_server + - name: Elastic Agent on ECK policy + id: eck-agent + namespace: default + is_managed: true + monitoring_enabled: + - logs + - metrics + unenroll_timeout: 900 + package_policies: + - package: + name: system + name: system-1 + - package: + name: kubernetes + name: kubernetes-1 + +eck-agent: + enabled: true + + # Agent policy to be used. + policyID: eck-agent + # Reference to ECK-managed Kibana instance. + # + kibanaRef: + name: kibana + elasticsearchRefs: [] + # Reference to ECK-managed Fleet instance. + # + fleetServerRef: + name: fleet-server + + mode: fleet + daemonSet: + podTemplate: + spec: + serviceAccountName: elastic-agent + hostNetwork: true + dnsPolicy: ClusterFirstWithHostNet + automountServiceAccountToken: true + securityContext: + runAsUser: 0 + +eck-fleet-server: + enabled: true + + fullnameOverride: "fleet-server" + + deployment: + replicas: 1 + podTemplate: + spec: + serviceAccountName: fleet-server + automountServiceAccountToken: true + + # Agent policy to be used. + policyID: eck-fleet-server + kibanaRef: + name: kibana + elasticsearchRefs: + - name: elasticsearch diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/examples/apm-server/basic.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/apm-server/basic.yaml new file mode 100644 index 00000000..227b5825 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/apm-server/basic.yaml @@ -0,0 +1,52 @@ +--- +eck-elasticsearch: + enabled: true + + # Name of the Elasticsearch instance. + # + fullnameOverride: elasticsearch + + nodeSets: + - name: default + count: 3 + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + config: + node.store.allow_mmap: false + +eck-kibana: + enabled: true + + # Name of the Kibana instance. + # + fullnameOverride: kibana + + spec: + config: + xpack.fleet.packages: + - name: apm + version: latest + +eck-apm-server: + enabled: true + + # Count of APM Server replicas to create. + # + count: 1 + + # Reference to ECK-managed Elasticsearch resource. + # + elasticsearchRef: + name: elasticsearch + kibanaRef: + name: kibana + http: + service: + spec: + ports: + - name: http + port: 8200 + targetPort: 8200 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/examples/apm-server/jaeger-with-http-configuration.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/apm-server/jaeger-with-http-configuration.yaml new file mode 100644 index 00000000..b694955f --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/apm-server/jaeger-with-http-configuration.yaml @@ -0,0 +1,60 @@ +--- +eck-elasticsearch: + enabled: true + + # Name of the Elasticsearch instance. + # + fullnameOverride: elasticsearch + + nodeSets: + - name: default + count: 3 + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + config: + node.store.allow_mmap: false + +eck-kibana: + enabled: true + + # Name of the Kibana instance. + # + fullnameOverride: kibana + + spec: + config: + xpack.fleet.packages: + - name: apm + version: latest + +eck-apm-server: + enabled: true + + # Count of APM Server replicas to create. + # + count: 1 + + config: + name: elastic-apm + apm-server.jaeger.grpc.enabled: true + apm-server.jaeger.grpc.host: "0.0.0.0:14250" + + # Reference to ECK-managed Elasticsearch resource. + # + elasticsearchRef: + name: elasticsearch + kibanaRef: + name: kibana + http: + service: + spec: + ports: + - name: http + port: 8200 + targetPort: 8200 + - name: grpc + port: 14250 + targetPort: 14250 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/examples/autoops/basic.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/autoops/basic.yaml new file mode 100644 index 00000000..cea15ba1 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/autoops/basic.yaml @@ -0,0 +1,30 @@ +--- +eck-autoops-agent-policy: + enabled: true + autoOpsRef: + secretName: "autoops-secret" + resourceSelector: + matchLabels: + autoops: enabled + +eck-elasticsearch: + enabled: true + + # This label is used to select the Elasticsearch instance for AutoOps integration. + labels: + autoops: enabled + + # Name of the Elasticsearch instance. + # + fullnameOverride: elasticsearch + + nodeSets: + - name: default + count: 1 + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + config: + node.store.allow_mmap: false diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/examples/beats/metricbeat_hosts.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/beats/metricbeat_hosts.yaml new file mode 100644 index 00000000..afd8c61b --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/beats/metricbeat_hosts.yaml @@ -0,0 +1,225 @@ +eck-elasticsearch: + enabled: true + + # Name of the Elasticsearch resource. + # + fullnameOverride: quickstart + + # Version of Elasticsearch. + # + version: 9.4.2 + + nodeSets: + - name: default + count: 3 + config: + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + node.store.allow_mmap: false + volumeClaimTemplates: + - metadata: + name: elasticsearch-data + spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 100Gi + # Adjust to your storage class name + # + # storageClassName: local-storage + +eck-kibana: + enabled: true + + # Name of the Kibana resource. + # + fullnameOverride: quickstart + + # Version of Kibana. + # + version: 9.4.2 + + spec: + # Count of Kibana replicas to create. + # + count: 1 + + # Reference to ECK-managed Elasticsearch resource, ideally from {{ "elasticsearch.fullname" }} + # + elasticsearchRef: + name: quickstart + +eck-beats: + enabled: true + name: metricbeat + type: metricbeat + version: 9.4.2 + elasticsearchRef: + name: quickstart + kibanaRef: + name: quickstart + config: + # Since filebeat is used in the default values, this needs to be removed with an empty list. + filebeat.inputs: [] + metricbeat: + autodiscover: + providers: + - hints: + default_config: {} + enabled: "true" + node: ${NODE_NAME} + type: kubernetes + modules: + - module: system + period: 10s + metricsets: + - cpu + - load + - memory + - network + - process + - process_summary + process: + include_top_n: + by_cpu: 5 + by_memory: 5 + processes: + - .* + - module: system + period: 1m + metricsets: + - filesystem + - fsstat + processors: + - drop_event: + when: + regexp: + system: + filesystem: + mount_point: ^/(sys|cgroup|proc|dev|etc|host|lib)($|/) + - module: kubernetes + period: 10s + node: ${NODE_NAME} + hosts: + - https://${NODE_NAME}:10250 + bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token + ssl: + verification_mode: none + metricsets: + - node + - system + - pod + - container + - volume + processors: + - add_cloud_metadata: {} + - add_host_metadata: {} + daemonSet: + podTemplate: + spec: + serviceAccountName: metricbeat + automountServiceAccountToken: true # some older Beat versions are depending on this settings presence in k8s context + containers: + - args: + - -e + - -c + - /etc/beat.yml + - --system.hostfs=/hostfs + name: metricbeat + volumeMounts: + - mountPath: /hostfs/sys/fs/cgroup + name: cgroup + - mountPath: /var/run/docker.sock + name: dockersock + - mountPath: /hostfs/proc + name: proc + env: + - name: NODE_NAME + valueFrom: + fieldRef: + fieldPath: spec.nodeName + dnsPolicy: ClusterFirstWithHostNet + hostNetwork: true # Allows to provide richer host metadata + securityContext: + runAsUser: 0 + terminationGracePeriodSeconds: 30 + volumes: + - hostPath: + path: /sys/fs/cgroup + name: cgroup + - hostPath: + path: /var/run/docker.sock + name: dockersock + - hostPath: + path: /proc + name: proc + + clusterRole: + # permissions needed for metricbeat + # source: https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-module-kubernetes.html + name: metricbeat + rules: + - apiGroups: + - "" + resources: + - nodes + - namespaces + - events + - pods + verbs: + - get + - list + - watch + - apiGroups: + - events.k8s.io + resources: + - events + verbs: + - get + - list + - watch + - apiGroups: + - "extensions" + resources: + - replicasets + verbs: + - get + - list + - watch + - apiGroups: + - apps + resources: + - statefulsets + - deployments + - replicasets + verbs: + - get + - list + - watch + - apiGroups: + - "" + resources: + - nodes/stats + verbs: + - get + - nonResourceURLs: + - /metrics + verbs: + - get + + serviceAccount: + name: metricbeat + + clusterRoleBinding: + name: metricbeat + subjects: + - kind: ServiceAccount + name: metricbeat + roleRef: + kind: ClusterRole + name: metricbeat + apiGroup: rbac.authorization.k8s.io diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/examples/custom-elasticsearch-kibana.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/custom-elasticsearch-kibana.yaml new file mode 100644 index 00000000..8953c5da --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/custom-elasticsearch-kibana.yaml @@ -0,0 +1,78 @@ +--- +eck-elasticsearch: + # Name of the Elasticsearch resource. + # + fullnameOverride: quickstart + + # Version of Elasticsearch. + # + version: 9.4.2 + + nodeSets: + - name: default + count: 1 + config: + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-virtual-memory.html + # + node.store.allow_mmap: false + volumeClaimTemplates: + - metadata: + name: elasticsearch-data + spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 100Gi + # Adjust to your storage class name + # + # storageClassName: local-storage + +eck-kibana: + # Name of the Kibana resource. + # + fullnameOverride: quickstart + + # Version of Kibana. + # + version: 9.4.2 + + spec: + # Count of Kibana replicas to create. + # + count: 1 + + # Reference to ECK-managed Elasticsearch resource, ideally from {{ "elasticsearch.fullname" }} + # + elasticsearchRef: + name: quickstart + # namespace: default + http: + service: + spec: + # Type of service to deploy for Kibana. + # This deploys a load balancer in a cloud service provider, where supported. + # + type: LoadBalancer + # tls: + # selfSignedCertificate: + # subjectAltNames: + # - ip: 1.2.3.4 + # - dns: kibana.example.com + podTemplate: + spec: + containers: + - name: kibana + env: + - name: NODE_OPTIONS + value: "--max-old-space-size=2048" + resources: + requests: + memory: 1Gi + cpu: 0.5 + limits: + memory: 2.5Gi + cpu: 2 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/examples/elasticsearch/hot-warm-cold.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/elasticsearch/hot-warm-cold.yaml new file mode 100644 index 00000000..919cb4c7 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/elasticsearch/hot-warm-cold.yaml @@ -0,0 +1,199 @@ +--- +eck-elasticsearch: + nodeSets: + - name: masters + count: 1 + config: + node.roles: ["master"] + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-virtual-memory.html + # + node.store.allow_mmap: false + podTemplate: + spec: + containers: + - name: elasticsearch + resources: + limits: + memory: 8Gi + cpu: 2 + # Affinity/Anti-affinity settings for controlling the 'spreading' of Elasticsearch + # pods across existing hosts. + # ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-advanced-node-scheduling.html#k8s-affinity-options + # + # affinity: + # nodeAffinity: + # requiredDuringSchedulingIgnoredDuringExecution: + # nodeSelectorTerms: + # - matchExpressions: + # - key: beta.kubernetes.io/instance-type + # operator: In + # # This should be adjusted to the instance type according to your setup + # # + # values: + # - highio + # Volume Claim settings. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-volume-claim-templates.html + # + volumeClaimTemplates: + - metadata: + name: elasticsearch-data + spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 1Ti + # Adjust to your storage class name + # + # storageClassName: local-storage + - name: hot + count: 1 + config: + node.roles: ["data_hot", "data_content", "ingest"] + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-virtual-memory.html + # + node.store.allow_mmap: false + podTemplate: + spec: + containers: + - name: elasticsearch + resources: + limits: + memory: 16Gi + cpu: 4 + # Affinity/Anti-affinity settings for controlling the 'spreading' of Elasticsearch + # pods across existing hosts. + # ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-advanced-node-scheduling.html#k8s-affinity-options + # + # affinity: + # nodeAffinity: + # requiredDuringSchedulingIgnoredDuringExecution: + # nodeSelectorTerms: + # - matchExpressions: + # - key: beta.kubernetes.io/instance-type + # operator: In + # # This should be adjusted to the instance type according to your setup + # # + # values: + # - highio + # Volume Claim settings. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-volume-claim-templates.html + # + volumeClaimTemplates: + - metadata: + name: elasticsearch-data + spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 1Ti + # Adjust to your storage class name + # + # storageClassName: local-storage + - name: warm + count: 1 + config: + node.roles: ["data_warm"] + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-virtual-memory.html + # + node.store.allow_mmap: false + podTemplate: + spec: + containers: + - name: elasticsearch + resources: + limits: + memory: 16Gi + cpu: 2 + # Affinity/Anti-affinity settings for controlling the 'spreading' of Elasticsearch + # pods across existing hosts. + # ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-advanced-node-scheduling.html#k8s-affinity-options + # + # affinity: + # nodeAffinity: + # requiredDuringSchedulingIgnoredDuringExecution: + # nodeSelectorTerms: + # - matchExpressions: + # - key: beta.kubernetes.io/instance-type + # operator: In + # # This should be adjusted to the instance type according to your setup + # # + # values: + # - highstorage + # Volume Claim settings. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-volume-claim-templates.html + # + volumeClaimTemplates: + - metadata: + name: elasticsearch-data + spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 10Ti + # Adjust to your storage class name + # + # storageClassName: local-storage + - name: cold + count: 1 + config: + node.roles: ["data_cold"] + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-virtual-memory.html + # + node.store.allow_mmap: false + podTemplate: + spec: + containers: + - name: elasticsearch + resources: + limits: + memory: 8Gi + cpu: 2 + # Affinity/Anti-affinity settings for controlling the 'spreading' of Elasticsearch + # pods across existing hosts. + # ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-advanced-node-scheduling.html#k8s-affinity-options + # + # affinity: + # nodeAffinity: + # requiredDuringSchedulingIgnoredDuringExecution: + # nodeSelectorTerms: + # - matchExpressions: + # - key: beta.kubernetes.io/instance-type + # operator: In + # # This should be adjusted to the instance type according to your setup + # # + # values: + # - highstorage + # Volume Claim settings. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-volume-claim-templates.html + # + volumeClaimTemplates: + - metadata: + name: elasticsearch-data + spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 20Ti + # Adjust to your storage class name + # + # storageClassName: local-storage diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/examples/elasticsearch/ingress/elasticsearch-ingress-gke.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/elasticsearch/ingress/elasticsearch-ingress-gke.yaml new file mode 100644 index 00000000..0ca2e8a5 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/elasticsearch/ingress/elasticsearch-ingress-gke.yaml @@ -0,0 +1,40 @@ +# The following is an example of an Elasticsearch resource that is configured to use an Ingress resource in a GKE cluster. +# Additional examples of exposing Elasticsearch with Ingress resources can be found in the following location: +# https://github.com/elastic/cloud-on-k8s/tree/main/deploy/eck-stack/charts/eck-elasticsearch/examples/ingress +# +eck-elasticsearch: + enabled: true + + ingress: + enabled: true + annotations: + my: annotation + labels: + my: label + pathType: Prefix + hosts: + - host: "elasticsearch.company.dev" + path: "/" + http: + service: + metadata: + annotations: + # This is required for `ClusterIP` services (which are the default ECK service type) to be used with Ingress in GKE clusters. + cloud.google.com/neg: '{"ingress": true}' + # This is required to enable the GKE Ingress Controller to use HTTPS as the backend protocol. + cloud.google.com/app-protocols: '{"https":"HTTPS"}' + nodeSets: + - name: default + count: 3 + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + config: + node.store.allow_mmap: false + # Enable anonymous access to allow GCLB health probes to succeed + xpack.security.authc: + anonymous: + username: anon + roles: monitoring_user diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/examples/enterprise-search/basic.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/enterprise-search/basic.yaml new file mode 100644 index 00000000..aeb61b06 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/enterprise-search/basic.yaml @@ -0,0 +1,42 @@ +--- +eck-elasticsearch: + enabled: true + + # Name of the Elasticsearch instance. + # + fullnameOverride: elasticsearch + + nodeSets: + - name: default + count: 3 + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + config: + node.store.allow_mmap: false + +eck-kibana: + enabled: true + + # Name of the Kibana instance. + # + fullnameOverride: kibana + + elasticsearchRef: + name: elasticsearch + + spec: + enterpriseSearchRef: + name: enterprise-search + +eck-enterprise-search: + enabled: true + + # Name of the Enterprise Search instance. + # + fullnameOverride: enterprise-search + + elasticsearchRef: + name: elasticsearch diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/examples/enterprise-search/with-custom-configuration.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/enterprise-search/with-custom-configuration.yaml new file mode 100644 index 00000000..a7c3ad49 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/enterprise-search/with-custom-configuration.yaml @@ -0,0 +1,52 @@ +--- +eck-elasticsearch: + enabled: true + + # Name of the Elasticsearch instance. + # + fullnameOverride: elasticsearch + + nodeSets: + - name: default + count: 3 + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + config: + node.store.allow_mmap: false + +eck-kibana: + enabled: true + + # Name of the Kibana instance. + # + fullnameOverride: kibana + + elasticsearchRef: + name: elasticsearch + + spec: + enterpriseSearchRef: + name: enterprise-search + +eck-enterprise-search: + enabled: true + + # Name of the Enterprise Search instance. + # + fullnameOverride: enterprise-search + + config: + # configure app search document size limit + app_search.engine.document_size.limit: 100kb + + http: + service: + metadata: + labels: + my-custom: label + + elasticsearchRef: + name: elasticsearch diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/examples/kibana/http-configuration.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/kibana/http-configuration.yaml new file mode 100644 index 00000000..e3798a28 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/kibana/http-configuration.yaml @@ -0,0 +1,24 @@ +--- +eck-kibana: + # Count of Kibana replicas to create. + # + count: 1 + + # Reference to ECK-managed Elasticsearch resource, ideally from {{ "elasticsearch.fullname" }} + # Leave commented when using eck-stack with Elasticsearch enabled (chart handles this automatically) + # Uncomment only when deploying eck-kibana standalone or eck-stack without Elasticsearch + # elasticsearchRef: + # name: + # namespace: default + http: + service: + spec: + # Type of service to deploy for Kibana. + # This deploys a load balancer in a cloud service provider, where supported. + # + type: LoadBalancer + # tls: + # selfSignedCertificate: + # subjectAltNames: + # - ip: 1.2.3.4 + # - dns: kibana.example.com diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/examples/kibana/ingress/kibana-gke.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/kibana/ingress/kibana-gke.yaml new file mode 100644 index 00000000..4aa1dc06 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/kibana/ingress/kibana-gke.yaml @@ -0,0 +1,80 @@ +# The following is an example of a Kibana resource that is configured to use an Ingress resource in a GKE cluster. +# Additional examples of exposing Kibana with Ingress resources can be found in the following location: +# https://github.com/elastic/cloud-on-k8s/tree/main/deploy/eck-stack/charts/eck-kibana/examples/ingress +# +eck-elasticsearch: + enabled: true + + # Name of the Elasticsearch instance. + # + fullnameOverride: elasticsearch + + ingress: + enabled: true + annotations: + my: annotation + labels: + my: label + pathType: Prefix + hosts: + - host: "elasticsearch.company.dev" + path: "/" + tls: + enabled: true + + http: + service: + metadata: + annotations: + # This is required for `ClusterIP` services (which are the default ECK service type) to be used with Ingress in GKE clusters. + cloud.google.com/neg: '{"ingress": true}' + cloud.google.com/app-protocols: '{"https":"HTTPS"}' + + nodeSets: + - name: default + count: 3 + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + config: + node.store.allow_mmap: false + # Enable anonymous access to allow GCLB health probes to succeed + xpack.security.authc: + anonymous: + username: anon + roles: monitoring_user + +eck-kibana: + enabled: true + + # Name of the Kibana instance. + # + fullnameOverride: kibana + + # Reference to ECK-managed Elasticsearch instance, ideally from {{ "elasticsearch.fullname" }} + # + elasticsearchRef: + name: elasticsearch + + config: + server: + publicBaseUrl: "https://kibana.company.dev" + + http: + service: + metadata: + annotations: + # This is required for `ClusterIP` services (which are the default ECK service type) to be used with Ingress in GKE clusters. + cloud.google.com/neg: '{"ingress": true}' + cloud.google.com/app-protocols: '{"https":"HTTPS"}' + + ingress: + enabled: true + pathType: Prefix + hosts: + - host: "kibana.company.dev" + path: "/" + tls: + enabled: true diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/examples/logstash/basic-eck.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/logstash/basic-eck.yaml new file mode 100644 index 00000000..8c2afa22 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/logstash/basic-eck.yaml @@ -0,0 +1,113 @@ +--- +eck-elasticsearch: + nodeSets: + - name: default + count: 3 + config: + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-virtual-memory.html + # + node.store.allow_mmap: false + podTemplate: + spec: + containers: + - name: elasticsearch + resources: + limits: + memory: 2Gi + requests: + memory: 2Gi +eck-kibana: + enabled: true + spec: + count: 1 + elasticsearchRef: + name: elasticsearch +eck-beats: + enabled: true + deployment: + podTemplate: + spec: + automountServiceAccountToken: true + initContainers: + - name: download-tutorial + image: curlimages/curl + command: ["/bin/sh"] + args: ["-c", "curl -L https://download.elastic.co/demos/logstash/gettingstarted/logstash-tutorial.log.gz | gunzip -c > /data/logstash-tutorial.log"] + volumeMounts: + - name: data + mountPath: /data + containers: + - name: filebeat + securityContext: + runAsUser: 1000 + volumeMounts: + - name: data + mountPath: /data + - name: beat-data + mountPath: /usr/share/filebeat/data + volumes: + - name: data + emptydir: {} + - name: beat-data + emptydir: {} + type: filebeat + config: + filebeat.inputs: + - type: filestream + id: logstash-tutorial + paths: + - /data/logstash-tutorial.log + processors: + - add_host_metadata: {} + - add_cloud_metadata: {} + output.logstash: + # This needs to be {{logstash-name}}-ls-beats:5044 + hosts: ["logstash-ls-beats-ls-beats:5044"] +eck-logstash: + enabled: true + # This is required to be able to set the logstash + # output of beats in a consistent manner. + fullnameOverride: "logstash-ls-beats" + elasticsearchRefs: + # This clusterName is required to match the environment variables + # used in the below config.string output section. + - clusterName: eck + name: elasticsearch + pipelines: + - pipeline.id: main + config.string: | + input { + beats { + port => 5044 + } + } + filter { + grok { + match => { "message" => "%{HTTPD_COMMONLOG}"} + } + geoip { + source => "[source][address]" + target => "[source]" + } + } + output { + elasticsearch { + hosts => [ "${ECK_ES_HOSTS}" ] + user => "${ECK_ES_USER}" + password => "${ECK_ES_PASSWORD}" + ssl_certificate_authorities => "${ECK_ES_SSL_CERTIFICATE_AUTHORITY}" + } + } + services: + - name: beats + service: + spec: + type: ClusterIP + ports: + - port: 5044 + name: "filebeat" + protocol: TCP + targetPort: 5044 diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/examples/package-registry/basic-eck.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/package-registry/basic-eck.yaml new file mode 100644 index 00000000..c9ffd8e6 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/examples/package-registry/basic-eck.yaml @@ -0,0 +1,95 @@ +--- +eck-package-registry: + enabled: true + # Name of the Package Registry instance. + # + fullnameOverride: registry + +eck-elasticsearch: + enabled: true + + # Name of the Elasticsearch instance. + # + fullnameOverride: elasticsearch + + nodeSets: + - name: default + count: 1 + # Comment out when setting the vm.max_map_count via initContainer, as these are mutually exclusive. + # For production workloads, it is strongly recommended to increase the kernel setting vm.max_map_count to 262144 + # and leave node.store.allow_mmap unset. + # ref: https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-virtual-memory.html + # + config: + node.store.allow_mmap: false + +eck-kibana: + enabled: true + + # Name of the Kibana instance. + # + fullnameOverride: kibana + + # Reference to ECK-managed Elasticsearch instance, ideally from {{ "elasticsearch.fullname" }} + # + elasticsearchRef: + name: elasticsearch + + # Reference to ECK-managed Package Registry instance, ideally from {{ "epr.fullname" }} + # + packageRegistryRef: + name: registry + + config: + # Note that these are specific to the namespace into which this example is installed, and are + # using `elastic-stack` as configured here and detailed in the README when installing: + # + # `helm install es-kb-quickstart elastic/eck-stack -n elastic-stack` + # + # If installed outside of the `elastic-stack` namespace, the following 2 lines need modification. + xpack.fleet.agents.elasticsearch.hosts: ["https://elasticsearch-es-http.elastic-stack.svc:9200"] + xpack.fleet.agents.fleet_server.hosts: ["https://fleet-server-agent-http.elastic-stack.svc:8220"] + xpack.fleet.packages: + - name: system + version: latest + - name: elastic_agent + version: latest + - name: fleet_server + version: latest + - name: kubernetes + version: latest + xpack.fleet.agentPolicies: + - name: Fleet Server on ECK policy + id: eck-fleet-server + namespace: default + is_managed: true + monitoring_enabled: + - logs + - metrics + package_policies: + - name: fleet_server-1 + id: fleet_server-1 + package: + name: fleet_server + +eck-agent: + enabled: false + +eck-fleet-server: + enabled: true + + fullnameOverride: "fleet-server" + + deployment: + replicas: 1 + podTemplate: + spec: + serviceAccountName: fleet-server + automountServiceAccountToken: true + + # Agent policy to be used. + policyID: eck-fleet-server + kibanaRef: + name: kibana + elasticsearchRefs: + - name: elasticsearch diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/lint-values.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/lint-values.yaml new file mode 100644 index 00000000..88136bd5 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/lint-values.yaml @@ -0,0 +1,3 @@ +eck-autoops-agent-policy: + configRef: + secretName: "test-secret" diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/templates/NOTES.txt b/packs/elastic-stack-0.19.1/charts/eck-stack/templates/NOTES.txt new file mode 100644 index 00000000..65cdae60 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/templates/NOTES.txt @@ -0,0 +1,10 @@ +Elasticsearch ECK-Stack {{ .Chart.Version }} has been deployed successfully! + +To see status of all resources, run + +kubectl get elastic -n {{ .Release.Namespace }} -l "app.kubernetes.io/instance"={{ .Release.Name }} + +More information on the Elastic ECK Operator, and its Helm chart can be found +within our documentation. + +https://www.elastic.co/guide/en/cloud-on-k8s/current/index.html diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/templates/_helpers.tpl b/packs/elastic-stack-0.19.1/charts/eck-stack/templates/_helpers.tpl new file mode 100644 index 00000000..cef61bdb --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/templates/_helpers.tpl @@ -0,0 +1,48 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "eck-stack.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "eck-stack.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "eck-stack.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "eck-stack.labels" -}} +helm.sh/chart: {{ include "eck-stack.chart" . }} +{{ include "eck-stack.selectorLabels" . }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "eck-stack.selectorLabels" -}} +app.kubernetes.io/name: {{ include "eck-stack.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/templates/extra-objects.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/templates/extra-objects.yaml new file mode 100644 index 00000000..13e05963 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/templates/extra-objects.yaml @@ -0,0 +1,4 @@ +{{- range .Values.extraObjects }} +--- +{{ tpl . $ }} +{{- end }} diff --git a/packs/elastic-stack-0.19.1/charts/eck-stack/values.yaml b/packs/elastic-stack-0.19.1/charts/eck-stack/values.yaml new file mode 100644 index 00000000..55739610 --- /dev/null +++ b/packs/elastic-stack-0.19.1/charts/eck-stack/values.yaml @@ -0,0 +1,76 @@ +--- +# Default values for eck-stack. +# This is a YAML-formatted file. + +# If enabled, will use the eck-elasticsearch chart and deploy an Elasticsearch resource. +# +eck-elasticsearch: + enabled: true + # This is adjusting the full name of the elasticsearch resource so that both the eck-elasticsearch + # and the eck-kibana chart work together by default in the eck-stack chart. + fullnameOverride: elasticsearch + +# If enabled, will use the eck-kibana chart and deploy a Kibana resource. +# +eck-kibana: + enabled: true + # This is also adjusting the kibana reference to the elasticsearch resource named previously so that + # both the eck-elasticsearch and the eck-kibana chart work together by default in the eck-stack chart. + elasticsearchRef: + name: elasticsearch + +# If enabled, will use the eck-agent chart and deploy an Elastic Agent instance. +# +eck-agent: + enabled: false + +# If enabled, will use the eck-fleet-server chart and deploy a Fleet Server resource. +# +eck-fleet-server: + enabled: false + +# If enabled, will use the eck-beats chart and deploy a Beats resource. +# +eck-beats: + enabled: false + +# If enabled, will use the eck-logstash chart and deploy a Logstash resource. +# +eck-logstash: + enabled: false + +# If enabled, will use the eck-apm-server chart and deploy a standalone APM Server resource. +# +eck-apm-server: + enabled: false + +# If enabled, will use the eck-enterprise-search chart and deploy a Enterprise Search resource. +# +eck-enterprise-search: + enabled: false + +# If enabled, will use the eck-autoops-agent-policy chart and deploy an AutoOps Agent. +# +eck-autoops-agent-policy: + enabled: false + +# If enabled, will use the eck-package-registry chart and deploy a Package Registry resource. +# +eck-package-registry: + enabled: false + +# extraObjects allows injecting additional Kubernetes resources into the chart. +# These resources will be created/deleted alongside the chart release. +# The value is a list of strings, each string is a YAML manifest. +# Helm templating is supported within each manifest. +# Example: +# extraObjects: +# - | +# apiVersion: v1 +# kind: ConfigMap +# metadata: +# name: {{ include "eck-stack.fullname" . }}-extra-config +# namespace: {{ .Release.Namespace }} +# data: +# key: value +extraObjects: [] diff --git a/packs/elastic-stack-0.19.1/logo.png b/packs/elastic-stack-0.19.1/logo.png new file mode 100644 index 0000000000000000000000000000000000000000..fa70b78daa45585ec0f802dfe637e4ce2172d6f8 GIT binary patch literal 5810 zcmV;j7ES4iP)) zEw)vQ)`8Z7U<(>65YRj(4Mo6Nreakf33Yf32_SRsaMt@Hh#~jfCBW^ant1RI-2$F+Ls!$`IZMeGSXJF1;$Zc-LF^Xx0Xx8|Z+YmWN0# zFa&7fqWH}y&!gsf>35{eMY*ohEDb<6ruRVYNvMnm+IX!F^fj=4BUwjY_gGiGX;ucH z8`FDW>r~(}z$Cr{tih6e>0P-j;ku*HEDS)`(2~~v$-rdX9p)R#EBLHirPtwqC%Yp} z-T-uci}S&L7RXF?Uuv)))qA9G@R?+GqRAS7D#C{JiJ-p+e97)lRD}721J_GG_9jPt z6GT6vEtUS6z~#yAON?wr`vWUk>z3c3|N1A^r@I9BinrIFoc8>H3y_pDQ2{Qn_vcTFMsK_yJg;sgpdN?#*?F z;#zfV@IQd^%Q(83ifra^puY@YpO;EJHGsV%rk`nxJp&;t4ly?H%MOJ%KO~6OtUS8T zUkX@p=txywl&ruQFBN!Z02L#jzEOlHfOI$Hsq#Oa7EUrx zxft0HQ6`+_x}H=+IRRhjVXwryY5)}@o*IDgsGBmsLdCZ(vecaEg|3uCxklIf&hw`C=P3mIIJ+6y%Lx}j(#u9q~ zW&KeH128m~;lDb=byMrEZVGhk6X2<{Le<_FS!$a83Lp|6;m}w&1;%Xv+lS3=4GeUl zFVP4eZc+Kq$YO0CD}b7)UhAf~xD6mJ{XlQP??PXq@yRJK{p@h{f}<0_|MF00D$~!+ z&p_M;AVNqeKq>&3gj)H5$xtLrmNT(Ein1_JD(@ z&IQyExdYfdJ%EuItF0?y+z=wL!VNhQ*pZt+&C~-JiRuY%h;d~GZ~SS$3I#%MgANoS z8>NpMvMn5fK+r}Q^X~=f%CUA=4B%)i|BFZe*gkA_Yk%v*{jkG>P{~FZ2-MeK5Z<4D zXjAoqsu)0eyV2(+KtzCSLrBQE0KKxn+I?i_>BjiZQe_aL*}!+}cuDoGb)57KJ|C}`gq)g{m-52ErlWte0d`$B{XeX*_6G)mW&>w){GP%$9>CfV z3A!OBJ_Aq{9ze*KdM^XJ%)9CTfJI0D*m>oXZTvy&9JMuDMFxuUR>VVM&U9(yYy1d@ z>uwZ_mA)HF)Uh4p4Mdk)Mwac!%P6hq^8o0^wEo!gZbP1Jf~=FQfGf-4x(%SX z*w<-C=A)u|TTJcirUbMYF~z7UE+2d97qL8~>(al2=!Z1TGl2C#R^zYCl{2VtMOtl@ zoeMu|%b^x?KreMeSrkfu)X!aG#QmB21R7;H0Q8KYwO}b00>I z00nAw4wuaXMmAKai@aVwHuJdfC*9P#E1}?4pjDFklt?O3#!25mLDUvgW}av>c;-eMwR1n3;zHkH(P`2gp4e4%te^#bX2a68Hq$?8x7*^SycwY_}n-seUd zkrlv+3WHRnz?^nyqwl_%Lt|BP+z8O=g{^0cnm0+UnRa3M*vwJY3v?~*G5!*~JdKoG zNb-mb30r1LL}^;!F;M6Kq{fP}fM8%q)R%wzBiANvjlfV_ypF@t-_s;5MwLM`uP~WqGZETT3 z>)z)a=XD04lf5mMXnFfm14}J)XGCec%BO%&BbzrW6nH?gf|Dc<=h^$uXJ;C8l`7c{ z)Ztfnfho^LY^NIlvGukF3Qio#kE)zgUn7|uLG{XHjo0#{2`AU|r0DKpPDVf#(s z^f-03G$Jo^?~LP;YMHJDo4X(kj#GFdNJm0Hizp2RXMj8dL}n37Z7NVZN3sGhL~Bre zndgp5?IvQTS1&Q4kS~YSTJ}Xp%}s4*eb%XZk@P1hS(OtA2TlbZ0Ev5xGy#+%WJ}-B zs%QPvC(1v{xcsxcQ)=A_lhde_ ztl(_=1ilM05=cna?HE~tKX8HcKDfiNHh*RdbMLGdQ2B39d!d|Rbxt1(Rg=I}yGy4g zs>gdl%mci>Vvo&Ap0Q~uV$3dj;5FF_r; z5kNZ6Dcy(Q$}uAk2q1EO`IwBq)vV}QRCI!!c0fvo=EZzESvRHkBxK(XawE{v)t=U( z7I?7Mnf}jbXPU5GMEo=TdSQ#{EuH6<1i|Ao{taWF8vF8!t9mT2S&>ovYF7yci-6OB z86wsrB|}HVdIkqM zkxR&>L%I{PP-bFyQnfIH`#;Oqoq&i zAJH0ElV|0s(K#e(Yg^zA=`^>rR3IZ69f-nKvBDSa%Ig_%`EvJV3wo=v7^v-R{A!ek zONZsY5^H#R)r}+Rmw?_6oYTO5SEmfaaOoZRSF{G^zUOX5nMQJ#;76qM+_HC5DCh3m zJ}We0d){fgYF2bxTsXuST>!*(DpuKm;gOCVcFcXh|4lKUqS1A}Y{X0kE}>yTup7X- zM6wP$ZfW!Y6k!H|z|GPh z=g}tr*^XAgH(xci-0t$N7q<P*#br0Lg#-U*yiy^0iF=EZ{aEZUsD_e^ri(-91-y;pbe-v;xN*2nGrElP`Q6EU^GOum~p!3|a=fT|^v~_S$ zY{}boO-518ik?M9>0w`RHfW+eVgTz99_!|7H)n;zXUGXvgnza?S$ZFi8jq0dWnL@@ z96R^7GC?|bV4F+Iuj%%F&5B;d1#J!m)8>K19M$SFWeU$22|QCD52F()vdpWKW6PY* zb4oWMb!P2|m(513i+7GWb!*LvYTmt6h)diDJQuXA-+p$%h^R-^97(ZdUR@kBfG%@O zu2AG94|Tn31;dx_7}ql*;4zAKFBJ#?FNO_M|D7}H!#Z2%&un2TWfqCs(21Ml935Te zmM&2k=7Ex>+N$!3^4!xScEV!x?j@U}u4bK9k~1n|Z{isF&vrDGzEWa!RwbX3)3`O^6ajzWtTX<{H60RP*_cBzkC3L>ZNM4EOW_%H9eNhcg|Imf5UFz@x*p5 z4n!9pX8^me?zTyhpSmU=9xfk~aif!ir`ys6qZN4tO}UMz+7Z5QBQwa)cXUkI>7mEK z+Y6uF!q{eh#6O~9Y{rua)14lu2Vr2suCbYs2Rf+o?iu(y4RP(J0z#k6fmv5O)-|3{ z;KR_=aj!XAak)7(QD9jE1s_E0QRQPZpK+?pSh`@c3QywEy~T+`e$}(6$T3fWovx1n zG4DGh13~`)qRuZNuUBA~b?8zcdLV-{yNxjymXGQ2N<>XTfz^HKf~P%j?Iw$EwiUR= zu_k}~Uf_?3?M}Ve89vhbuTa~sFt1mjd`!l*AipQJ6z`* z=Onp;!+-IgrOlwe>bso~o7k`}f^iQ`YL6+zI5xss{l%c>VP zIPYK2qRr`BF76p{io0th-aR)7TeivCa?!|55jFWU+nY)$1==URTgOlly*~WV_~&X? zGZRvv1 zrfTWfI2}B3V%u{5wu^F$qc)f_qq}8Hw!$E)&iZ@3`+7u_>%&ujG&foU*9^e5*uBQh zJEcQ&2gIB${r*|swp0hHG6={9vT!ec;8R=ma;A>2^_+w&29U9&aEypXwX)`fqW#K- zjgGwSEEevX-5QI2Ms$#hW(y3W{+ZBhglBEP?{4z1t#bw9&XF)<4@DDl`%J2%b|7tA zgP;EWxP!nd8&&}iYkskhKxrSNCL4~85>e+?BCHIHxszXydoNa%uDrF(WeZlKoa=_H zM$Wd<{ijxTS)J%2gLGG>s9WD5*Z=!M84TkJ>q_4vqJR_eel z1NaE#Ki!bk$XQrAY*cQ|!l&NI?hy2u3ab9U_kq3xvRW{!+8$xm_#rDAp57+E*hhYB zfvirr^9j(@je1Qi;&_8<(2_Ix`p0$xNDh#r*z9XTXxf`USg+`6R92agy<+0vHzJP4 zMJ0}x5ALNPNyX#k2}i`~rgK2dS+(q^`9RMSI1ABFV{T|Y<+8OiBpBZ znQ{JnYkoE=r@b}!?H0a+IXCrxKdu-~x12TyU6RvyQ8tpFACbf8sW-AasQX!1(@_Q= zs%#VYv3|DHT6LI?MZc;n07=RHgBAr{aLdEg>?`vgyHUT_J+>>ut44`D# zh|NGVo(G8I_OIF=4*vi`%*ipM;ac#9K=eqMCXYt(0D2q{tJHmDy$)P60J|y(v{|CI zZged7asmh_vLap?t{Fh6ZD1iOdJ@KC_Lf~VD&q5(fC*sO3Wr{eSBPr{@Y%q;!yqra zC9m-y>z!f%y`BInEWJH@^%wEVaW#O`sLpUxUZX&rJ%C@ya(yCuwZ11KFfdMQ3m8CE<%ZkOSy}3qKu->Fh%f<&D^{&BAn&AaQ< zR!&9D#Xwmc8bT<4@|m>nP8_guX&iED#q;xAnac`qL-h%-^&}F357Q3IfRA%?Yu$~T z{@z(>heNGKipovE`NVeca|g&A+ZX=hPtRWE`3Rbj1AQ4w3ZD`=J~c@rW{((qKuOMJ zpVa4}hgS`1+rpUdshD#F{kA|SMLU6f3G5Q&Ut(mcxf(`71bk)hj$<~qmzHBu6m z%wfy$;gy{_?id9;pD3L!vIE<`psBrlNZ<%?3{~mAY~fTz?@o&TdZMr5MZ@xSvk#4^u=W+$^BH4*q6k%=Wk zbLS6kwtN~Q#q(zHbrKg9o z1vy`p!3bv%d+yysDC;q-1>O#b{p#mAmsNP!-9|;DFaReqmlvK$NWX)Tt|Hn-(Kezc w4beTet$PsNgQo2$`||K+^70bqTW@UqKfDL0=G%K /data/logstash-tutorial.log"] + volumeMounts: + - name: data + mountPath: /data + containers: + - name: filebeat + securityContext: + runAsUser: 1000 + volumeMounts: + - name: data + mountPath: /data + - name: beat-data + mountPath: /usr/share/filebeat/data + volumes: + - name: data + emptydir: {} + - name: beat-data + emptydir: {} + eck-logstash: + enabled: true + # This is required to be able to set the logstash + # output of beats in a consistent manner. + fullnameOverride: "logstash-ls-beats" + elasticsearchRefs: + # This clusterName is required to match the environment variables + # used in the below config.string output section. + - clusterName: eck + name: elasticsearch + pipelines: + - pipeline.id: main + config.string: | + input { + beats { + port => 5044 + } + } + filter { + grok { + match => { "message" => "%{HTTPD_COMMONLOG}"} + } + geoip { + source => "[source][address]" + target => "[source]" + } + } + output { + elasticsearch { + hosts => [ "${ECK_ES_HOSTS}" ] + user => "${ECK_ES_USER}" + password => "${ECK_ES_PASSWORD}" + ssl_certificate_authorities => "${ECK_ES_SSL_CERTIFICATE_AUTHORITY}" + } + } + services: + - name: beats + service: + spec: + type: ClusterIP + ports: + - port: 5044 + name: "filebeat" + protocol: TCP + targetPort: 5044 \ No newline at end of file diff --git a/packs/elastic-stack-0.19.1/values.yaml b/packs/elastic-stack-0.19.1/values.yaml new file mode 100644 index 00000000..81582c07 --- /dev/null +++ b/packs/elastic-stack-0.19.1/values.yaml @@ -0,0 +1,96 @@ +# Default values for eck-elastic-operator +# This is a YAML-formatted file +pack: + content: + images: + - image: docker.elastic.co/kibana/kibana:9.4.2 + - image: docker.elastic.co/elasticsearch/elasticsearch:9.4.2 + - image: docker.elastic.co/logstash/logstash:9.4.2 + - image: docker.elastic.co/beats/filebeat:9.4.2 + - image: docker.io/curlimages/curl:8.19.0 + + charts: + - repo: https://helm.elastic.co/ + name: eck-stack + version: 0.19.1 + #The namespace (on the target cluster) to install this chart + #When not found, a new namespace will be created + namespace: "elastic-stack" + +charts: + eck-stack: + # Default values for eck-stack. + # This is a YAML-formatted file. + + # If enabled, will use the eck-elasticsearch chart and deploy an Elasticsearch resource. + # + eck-elasticsearch: + enabled: true + # This is adjusting the full name of the elasticsearch resource so that both the eck-elasticsearch + # and the eck-kibana chart work together by default in the eck-stack chart. + fullnameOverride: elasticsearch + + # If enabled, will use the eck-kibana chart and deploy a Kibana resource. + # + eck-kibana: + enabled: true + # This is also adjusting the kibana reference to the elasticsearch resource named previously so that + # both the eck-elasticsearch and the eck-kibana chart work together by default in the eck-stack chart. + elasticsearchRef: + name: elasticsearch + + # If enabled, will use the eck-agent chart and deploy an Elastic Agent instance. + # + eck-agent: + enabled: false + + # If enabled, will use the eck-fleet-server chart and deploy a Fleet Server resource. + # + eck-fleet-server: + enabled: false + + # If enabled, will use the eck-beats chart and deploy a Beats resource. + # + eck-beats: + enabled: false + + # If enabled, will use the eck-logstash chart and deploy a Logstash resource. + # + eck-logstash: + enabled: false + + # If enabled, will use the eck-apm-server chart and deploy a standalone APM Server resource. + # + eck-apm-server: + enabled: false + + # If enabled, will use the eck-enterprise-search chart and deploy a Enterprise Search resource. + # + eck-enterprise-search: + enabled: false + + # If enabled, will use the eck-autoops-agent-policy chart and deploy an AutoOps Agent. + # + eck-autoops-agent-policy: + enabled: false + + # If enabled, will use the eck-package-registry chart and deploy a Package Registry resource. + # + eck-package-registry: + enabled: false + + # extraObjects allows injecting additional Kubernetes resources into the chart. + # These resources will be created/deleted alongside the chart release. + # The value is a list of strings, each string is a YAML manifest. + # Helm templating is supported within each manifest. + # Example: + # extraObjects: + # - | + # apiVersion: v1 + # kind: ConfigMap + # metadata: + # name: {{ include "eck-stack.fullname" . }}-extra-config + # namespace: {{ .Release.Namespace }} + # data: + # key: value + extraObjects: []