Skip to content

Commit 40f2bed

Browse files
Herbaerttuunit
authored andcommitted
Add clusterctl/stackit CLI to devcontainer, persist dev state, update quick-start docs
- .devcontainer/devcontainer.json: add named volumes for bash history (/commandhistory) and docker-in-docker state (/var/lib/docker) so both survive container rebuilds; set HISTFILE accordingly - .devcontainer/post-install.sh: install clusterctl and the stackit CLI (with bash completions), flush bash history after every command via PROMPT_COMMAND, verify both tools at the end of setup - .gitignore: ignore local dev/debug artifacts (.DS_Store, cluster.yaml, kind-config.yaml, devcontainer-lock.json) - docs/src/quick-start.md: document the .stackit/ service-account key convention, add the STACKIT_SSH_KEY_NAME env var (used by the bastion cluster template), add an optional kind-config.yaml section for enterprise TLS-intercepting proxies (e.g. Zscaler), and write the generated cluster manifest to a file before applying it
1 parent ba2a21f commit 40f2bed

4 files changed

Lines changed: 98 additions & 6 deletions

File tree

‎.devcontainer/devcontainer.json‎

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,10 @@
1313
},
1414

1515
"runArgs": ["--privileged", "--init"],
16+
"mounts": [
17+
"source=${localWorkspaceFolderBasename}-bashhistory,target=/commandhistory,type=volume",
18+
"source=${localWorkspaceFolderBasename}-docker,target=/var/lib/docker,type=volume"
19+
],
1620

1721
"customizations": {
1822
"vscode": {
@@ -27,7 +31,8 @@
2731
},
2832

2933
"remoteEnv": {
30-
"GO111MODULE": "on"
34+
"GO111MODULE": "on",
35+
"HISTFILE": "/commandhistory/.bash_history"
3136
},
3237

3338
"onCreateCommand": "bash .devcontainer/post-install.sh"

‎.devcontainer/post-install.sh‎

Lines changed: 49 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -42,6 +42,15 @@ if ! grep -q "source /usr/share/bash-completion/bash_completion" ~/.bashrc 2>/de
4242
echo "Added bash-completion to .bashrc"
4343
fi
4444

45+
# Persist bash history on the /commandhistory volume (HISTFILE is set via
46+
# devcontainer.json remoteEnv) and flush it after every command instead of
47+
# only on a clean shell exit.
48+
mkdir -p /commandhistory
49+
if ! grep -q "PROMPT_COMMAND='history -a'" ~/.bashrc 2>/dev/null; then
50+
echo "PROMPT_COMMAND='history -a'" >> ~/.bashrc
51+
echo "Added persistent bash history to .bashrc"
52+
fi
53+
4554
echo ""
4655
echo "------------------------------------"
4756
echo "Installing development tools..."
@@ -99,6 +108,44 @@ if command -v kubectl &> /dev/null; then
99108
fi
100109
fi
101110

111+
# Install clusterctl
112+
if ! command -v clusterctl &> /dev/null; then
113+
echo "Installing clusterctl..."
114+
curl -Lo /usr/local/bin/clusterctl "https://github.com/kubernetes-sigs/cluster-api/releases/latest/download/clusterctl-linux-${ARCH}"
115+
chmod +x /usr/local/bin/clusterctl
116+
echo "clusterctl installed successfully"
117+
fi
118+
119+
# Generate clusterctl bash completion
120+
if command -v clusterctl &> /dev/null; then
121+
if clusterctl completion bash > "${BASH_COMPLETIONS_DIR}/clusterctl" 2>/dev/null; then
122+
echo "clusterctl completion installed"
123+
else
124+
echo "WARNING: Failed to generate clusterctl completion"
125+
fi
126+
fi
127+
128+
# Install stackit CLI
129+
if ! command -v stackit &> /dev/null; then
130+
echo "Installing stackit CLI..."
131+
STACKIT_CLI_VERSION=$(curl -Ls https://api.github.com/repos/stackitcloud/stackit-cli/releases/latest | grep '"tag_name"' | cut -d '"' -f4 | sed 's/^v//')
132+
curl -Lo /tmp/stackit-cli.tar.gz "https://github.com/stackitcloud/stackit-cli/releases/download/v${STACKIT_CLI_VERSION}/stackit-cli_${STACKIT_CLI_VERSION}_linux_${ARCH}.tar.gz"
133+
tar -xzf /tmp/stackit-cli.tar.gz -C /tmp stackit
134+
mv /tmp/stackit /usr/local/bin/stackit
135+
chmod +x /usr/local/bin/stackit
136+
rm -f /tmp/stackit-cli.tar.gz
137+
echo "stackit CLI installed successfully"
138+
fi
139+
140+
# Generate stackit CLI bash completion
141+
if command -v stackit &> /dev/null; then
142+
if stackit completion bash > "${BASH_COMPLETIONS_DIR}/stackit" 2>/dev/null; then
143+
echo "stackit completion installed"
144+
else
145+
echo "WARNING: Failed to generate stackit completion"
146+
fi
147+
fi
148+
102149
# Generate Docker bash completion
103150
if command -v docker &> /dev/null; then
104151
if docker completion bash > "${BASH_COMPLETIONS_DIR}/docker" 2>/dev/null; then
@@ -142,6 +189,8 @@ echo "------------------------------------"
142189
kind version
143190
kubebuilder version
144191
kubectl version --client
192+
clusterctl version
193+
stackit --version
145194
docker --version
146195
go version
147196

‎.gitignore‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,13 @@
22
.env
33
.stackit
44

5+
# Local dev/debug artifacts
6+
.DS_Store
7+
/cluster*.yaml
8+
/kind-config.yaml
9+
.devcontainer/devcontainer-lock.json
10+
.ssh/
11+
512
# Binaries for programs and plugins
613
*.exe
714
*.exe~

‎docs/src/quick-start.md‎

Lines changed: 36 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -8,23 +8,53 @@ image, and machine type.
88

99
Furthermore, make sure that the provided service-account has [an appropriate set of permissions](./topics/iam-permissions.md).
1010

11+
Place the downloaded service-account JSON key at `.stackit/cluster-api-provider-stackit.json`
12+
inside the repo (create the `.stackit/` directory if it does not exist yet). It is listed in
13+
`.gitignore`, so the key is never committed, and the path works identically for every
14+
contributor regardless of where the repo is checked out.
15+
1116
```sh
1217
export STACKIT_PROJECT_ID=<project-uuid>
1318
export STACKIT_REGION=eu01
1419
export STACKIT_NETWORK_ID=<network-uuid>
1520
export STACKIT_IMAGE_ID=<image-uuid>
16-
export STACKIT_MACHINE_TYPE=c2i.2
21+
export STACKIT_MACHINE_TYPE=c2i.4
22+
export STACKIT_SSH_KEY_NAME=""
1723
export STACKIT_SERVICE_ACCOUNT_JSON_FILE=./.stackit/cluster-api-provider-stackit.json
1824
export STACKIT_SERVICE_ACCOUNT_JSON_B64="$(base64 < "${STACKIT_SERVICE_ACCOUNT_JSON_FILE}" | tr -d '\n')"
1925
export STACKIT_CLOUD_CONTROLLER_MANAGER_IMAGE=ghcr.io/stackitcloud/cloud-provider-stackit/cloud-controller-manager:v1.35.3
2026
```
2127

22-
The default template does not configure SSH access. To use an SSH key, add
23-
`sshKeyName: <key-name>` to the `StackitMachineTemplate` specs before creating
24-
the workload cluster.
28+
The default template (`templates/cluster-template.yaml`) does not configure SSH access. To use
29+
an SSH key, add `sshKeyName: <key-name>` to the `StackitMachineTemplate` specs before creating
30+
the workload cluster. If you use the bastion variant instead
31+
(`templates/cluster-template-bastion.yaml`), set `STACKIT_SSH_KEY_NAME` above to your key name,
32+
it is substituted into that template directly.
2533

2634
## Create the management cluster
2735

36+
### Optional: `kind-config.yaml` for enterprise proxies (e.g. Zscaler)
37+
38+
If your machine sits behind a TLS-intercepting enterprise proxy such as Zscaler, outbound HTTPS
39+
calls made from inside the `kind` node container (pulling images, talking to the STACKIT API,
40+
etc.) will fail certificate validation. The node runs as its own container with its own OS
41+
certificate store, which does not include the proxy's root CA even though your host already
42+
trusts it. Mount the host's CA bundle into the node at the same path it expects:
43+
44+
```yaml
45+
kind: Cluster
46+
apiVersion: kind.x-k8s.io/v1alpha4
47+
nodes:
48+
- role: control-plane
49+
extraMounts:
50+
- hostPath: /etc/ssl/certs/ca-certificates.crt
51+
containerPath: /etc/ssl/certs/ca-certificates.crt
52+
readOnly: true
53+
```
54+
55+
Save this as `kind-config.yaml` in the repo root before running `kind create cluster` below. If
56+
you are not behind such a proxy, drop the `--config kind-config.yaml` flag from the command.
57+
2858
```sh
2959
kind create cluster --name capi-stackit
3060
kubectl config use-context kind-capi-stackit
@@ -68,7 +98,8 @@ clusterctl init \
6898
clusterctl generate cluster "${CLUSTER_NAME}" \
6999
--from templates/cluster-template.yaml \
70100
--target-namespace "${NAMESPACE}" \
71-
| kubectl apply -f -
101+
> cluster.yaml
102+
kubectl apply -f cluster.yaml
72103
```
73104

74105
Watch progress:

0 commit comments

Comments
 (0)