diff --git a/docs/tekton.md b/docs/tekton.md index f3354e6..de9c17c 100644 --- a/docs/tekton.md +++ b/docs/tekton.md @@ -18,15 +18,15 @@ event-to-run translation, and Tekton's native execution object is the ## Required cluster setup -* Tekton Pipelines is installed in the cluster. -* Tack is deployed inside the same cluster. -* The target Tekton `Pipeline` objects already exist in the namespace +- Tekton Pipelines is installed in the cluster. +- Tack is deployed inside the same cluster. +- The target Tekton `Pipeline` objects already exist in the namespace tack is configured to use. -* Tack's Kubernetes service account has RBAC to: - * create, get, list, and watch `tekton.dev` `pipelineruns` - * get, list, and watch `tekton.dev` `taskruns` - * get and list pods - * get pod logs via `pods/log` +- Tack's Kubernetes service account has RBAC to: + - create, get, list, and watch `tekton.dev` `pipelineruns` + - get, list, and watch `tekton.dev` `taskruns` + - get and list pods + - get pod logs via `pods/log` Example RBAC: @@ -53,10 +53,10 @@ rules: ## Configure Tack -| Env var | Description | -| ------------------------ | --------------------------------------------------------- | -| `TACK_TEKTON_ENABLED` | Set to `1` to enable the Tekton provider | -| `TACK_TEKTON_NAMESPACE` | Namespace for created `PipelineRun`s (default `default`) | +| Env var | Description | +| ----------------------- | -------------------------------------------------------- | +| `TACK_TEKTON_ENABLED` | Set to `1` to enable the Tekton provider | +| `TACK_TEKTON_NAMESPACE` | Namespace for created `PipelineRun`s (default `default`) | The provider uses Kubernetes in-cluster service account credentials. It will not run from a local kubeconfig. @@ -65,11 +65,11 @@ It will not run from a local kubeconfig. There are three separate names: -* Tack workflow name: the Tangled workflow filename/name, e.g. `ci.yml`. +- Tack workflow name: the Tangled workflow filename/name, e.g. `ci.yml`. This remains the Tangled-facing workflow identity in status records. -* Tekton `Pipeline` name: the existing in-cluster pipeline definition, +- Tekton `Pipeline` name: the existing in-cluster pipeline definition, e.g. `repo-ci`. This is written to `spec.pipelineRef.name`. -* Tekton `PipelineRun` name: generated by tack per trigger/workflow, +- Tekton `PipelineRun` name: generated by tack per trigger/workflow, e.g. `tack-ci-yml-`. This is the concrete execution object tack watches and stores. @@ -92,6 +92,12 @@ tack: service_account: pipeline-runner params: image: example/app + workspaces: + - name: repo-data + access_modes: ["ReadWriteOnce"] + storage: 1Gi + - name: go-mod-cache + pvc: go-mod-cache ``` `params` are forwarded as string Tekton params. Tack also stores the @@ -99,6 +105,11 @@ knot, pipeline rkey, workflow name, actor DID, commit, and branch as `PipelineRun` annotations, so operators can inspect the Kubernetes object and connect it back to the Tangled trigger. +Workspaces correlate to +[Tekton workspaces](https://tekton.dev/docs/pipelines/workspaces/) and +are useful for creating a temporary PVC with git clones, intermediate +build products, or other build artifacts. + ## Example Pipeline ```yaml