allow to create a service account per app

Signed-off-by: Pascal Sthamer <pascal+github@sthamer.xyz>
This commit is contained in:
Pascal Sthamer
2026-02-02 10:36:11 +01:00
parent 1703145100
commit 138f66e27a
2 changed files with 75 additions and 16 deletions
+37 -15
View File
@@ -127,12 +127,14 @@ When `worker.enableHelmDeployment` is set, env variables for app configuration a
Configuration using env variables applies to ALL deployed apps. There is no way to assign different options (e.g. resources) to different apps, or scale apps individually.
If you want full control, you can deploy apps using helm. This has the following advantages:
- full control over the deployment using helm values
- granular control per app and version (e.g. have more replicas and resources for frequently used apps)
- avoid problems with on-demand started apps (see https://github.com/Shuffle/Shuffle/issues/1739)
To deploy apps using helm, set `apps.enabled=true`. By default, this deploys the `shuffle-tools`, `shuffle-subflow` and `http` apps.
You can also deploy your own apps. See the following values file for an example.
```yaml
app:
replicaCount: 1 # default to 1 replica per app
@@ -142,26 +144,27 @@ app:
apps:
enabled: true # Deploy apps using helm.
# Configure default apps
# Configure default apps
shuffleTools:
enabled: true # default
shuffleSubflow:
enabled: true # default
http:
enabled: true # default
# optionally override defaults from app values:
replicaCount: 1
# optionally override defaults from app values:
replicaCount: 1
resources: {}
# Deploy additional apps (e.g. opensearch)
# Deploy additional apps (e.g. opensearch)
opensearch:
enabled: true # required to actually deploy the app
name: opensearch # required. The name and version must match the values of the `api.yaml` file of the app.
version: 1.1.0 # required.
# optionally change app configuration:
# optionally change app configuration:
replicaCount: 3
resources: {}
```
The key of an app in the `apps` map does not matter, as long as it is unique. We are not using an array here, to allow overriding values in stage-specific value files or using the command line, e.g.
`helm upgrade ... --set apps.shuffleTools.replicas=3`.
@@ -173,6 +176,34 @@ It is possible to use a hybrid approach - deploy some apps using helm, while sti
If you do not want Worker to manage app deployments, set `worker.manageAppDeployments=true`. This effectively removes the required permissions from the Shuffle Worker Kubernetes Service Account.
You are required to deploy all apps that are in use by your Shuffle instance manually using Helm.
### Shuffle App Service Accounts
By default a shared `shuffle-app` service account is used for all apps.
If you are deploying apps using helm, you can choose to have a dedicated service account per app.
To enable it, set `apps.MY_APP.serviceAccount.create=true` and provide a name using `apps.MY_APP.serviceAccount.name`.
You can also set `apps.MY_APP.serviceAccount.create=false` while still providing a name to use an existing service account.
```yaml
apps:
myAppWithCustomServiceAccount:
enabled: true
name: my-custom-service-account
version: 1.0.0
serviceAccount:
create: true
name: shuffle-app-myapp
anotherAppWithExistingServiceAccount:
enabled: true
name: another-app
version: 1.0.0
serviceAccount:
create: false
name: existing-service-account-name
```
All service accounts use the `shuffle-app` role by default.
## OpenSearch
Shuffle uses OpenSearch as its database. This helm chart installs a single-node OpenSearch cluster using [the Bitnami Helm Chart](https://github.com/bitnami/charts/blob/main/bitnami/opensearch/values.yaml).
@@ -873,7 +904,6 @@ The password should be provided with the `SHUFFLE_OPENSEARCH_PASSWORD` env varia
##### Other Parameters
| Name | Description | Value |
| ----------------------------- | -------------------------------------------------- | ------- |
| `apps.enabled` | Whether apps should be deployed using helm. | `false` |
@@ -982,7 +1012,6 @@ The password should be provided with the `SHUFFLE_OPENSEARCH_PASSWORD` env varia
#### Other Parameters
| Name | Description | Value |
| ----------------------------- | -------------------------------------------------- | ------- |
| `apps.enabled` | Whether apps should be deployed using helm. | `false` |
@@ -1090,10 +1119,3 @@ The password should be provided with the `SHUFFLE_OPENSEARCH_PASSWORD` env varia
| `vault.secrets` | A list of VaultSecrets to create | `[]` |
### Other Parameters
@@ -12,6 +12,43 @@
{{- $_ := set $appValues.image "repository" ($appValues.image.repository | default (printf "%s/%s" $.Values.shuffle.appBaseImageName $appValues.name)) -}}
{{/* use app version as default tag */}}
{{- $_ := set $appValues.image "tag" ($appValues.image.tag | default $appValues.version) -}}
{{/* Only create a service account if create is explicitly enabled on that specific app ($app not $appValues). Otherwise the shared shuffle-app service account is used. */}}
{{- $shouldCreateDedicatedServiceAccount := and $app.serviceAccount.create $app.serviceAccount.name -}}
{{- if $shouldCreateDedicatedServiceAccount }}
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ $app.serviceAccount.name | trunc 63 | trimSuffix "-" }}
namespace: {{ include "common.names.namespace" $ | quote }}
labels: {{- include "shuffle.app.labels" ( dict "customLabels" $.Values.commonLabels "context" $ ) | nindent 4 }}
{{- if or $appValues.serviceAccount.annotations $.Values.commonAnnotations }}
{{- $annotations := include "common.tplvalues.merge" (dict "values" (list $appValues.serviceAccount.annotations $.Values.commonAnnotations) "context" $) }}
annotations: {{- include "common.tplvalues.render" ( dict "value" $annotations "context" $ ) | nindent 4 }}
{{- end }}
automountServiceAccountToken: {{ $appValues.serviceAccount.automountServiceAccountToken }}
{{- include "shuffle.app.serviceAccount.imagePullSecrets" $ | nindent 0 }}
{{- if $appValues.rbac.create }}
---
kind: RoleBinding
apiVersion: {{ include "common.capabilities.rbac.apiVersion" $ }}
metadata:
name: {{ $app.serviceAccount.name | trunc 63 | trimSuffix "-" }}
namespace: {{ include "common.names.namespace" $ | quote }}
labels: {{- include "shuffle.app.labels" ( dict "customLabels" $.Values.commonLabels "context" $ ) | nindent 4 }}
{{- if $.Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" $.Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
subjects:
- kind: ServiceAccount
name: {{ $app.serviceAccount.name | trunc 63 | trimSuffix "-" }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: {{ template "shuffle.app.name" $ }}
{{- end }}
{{- end }}
---
apiVersion: v1
kind: Service
@@ -28,7 +65,7 @@ spec:
ports:
- name: http
port: 80
targetPort: {{ $.Values.app.exposedContainerPort }}
targetPort: {{ $appValues.exposedContainerPort }}
protocol: TCP
appProtocol: http
{{- $podLabels := include "common.tplvalues.merge" (dict "values" (list $appValues.podLabels $.Values.commonLabels) "context" $) }}