Implement easy Bottom Turtle HA support in the charts (#816)
* Implement easy Bottom Turtle HA support in the charts Signed-off-by: Kevin Fox <[email protected]> * Add diagram Signed-off-by: Kevin Fox <[email protected]> * Update docs Signed-off-by: Kevin Fox <[email protected]> * Some fixes and tightened defaults Signed-off-by: Kevin Fox <[email protected]> * More diagrams Signed-off-by: Kevin Fox <[email protected]> * More instructions Signed-off-by: Kevin Fox <[email protected]> * More instructions Signed-off-by: Kevin Fox <[email protected]> * More instructions Signed-off-by: Kevin Fox <[email protected]> * More instructions Signed-off-by: Kevin Fox <[email protected]> * More instructions Signed-off-by: Kevin Fox <[email protected]> * Install some bottom turtle spire bits Signed-off-by: Kevin Fox <[email protected]> * Trigger in github Signed-off-by: Kevin Fox <[email protected]> * Fix path Signed-off-by: Kevin Fox <[email protected]> * Fix path Signed-off-by: Kevin Fox <[email protected]> * Fix path Signed-off-by: Kevin Fox <[email protected]> * Fix path Signed-off-by: Kevin Fox <[email protected]> * Fix path Signed-off-by: Kevin Fox <[email protected]> * Fix path Signed-off-by: Kevin Fox <[email protected]> * Fix shell code Signed-off-by: Kevin Fox <[email protected]> * Add some more testing Signed-off-by: Kevin Fox <[email protected]> * Add some more testing Signed-off-by: Kevin Fox <[email protected]> * Add some more testing Signed-off-by: Kevin Fox <[email protected]> * Add some more debug logging Signed-off-by: Kevin Fox <[email protected]> * More logging Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * Some fixes Signed-off-by: Kevin Fox <[email protected]> * More updates Signed-off-by: Kevin Fox <[email protected]> * More updates Signed-off-by: Kevin Fox <[email protected]> * More updates Signed-off-by: Kevin Fox <[email protected]> * More updates Signed-off-by: Kevin Fox <[email protected]> * More updates Signed-off-by: Kevin Fox <[email protected]> * More updates Signed-off-by: Kevin Fox <[email protected]> * More updates Signed-off-by: Kevin Fox <[email protected]> * More updates Signed-off-by: Kevin Fox <[email protected]> * More updates Signed-off-by: Kevin Fox <[email protected]> * More updates Signed-off-by: Kevin Fox <[email protected]> * More updates Signed-off-by: Kevin Fox <[email protected]> * Add x509POP support and more testing Signed-off-by: Kevin Fox <[email protected]> * x509pop attestor support and more tests Signed-off-by: Kevin Fox <[email protected]> * More updates Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Update docs Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Fix pages artifact upload Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Test some more bits Signed-off-by: Kevin Fox <[email protected]> * Initial stab at dynamic registration Signed-off-by: Kevin Fox <[email protected]> * Dynamic registration working but not integrated with test Signed-off-by: Kevin Fox <[email protected]> * Wire in dynamic registration into the test Signed-off-by: Kevin Fox <[email protected]> * Fix missing props Signed-off-by: Kevin Fox <[email protected]> * Update the svids to align Signed-off-by: Kevin Fox <[email protected]> * Update the svids to align Signed-off-by: Kevin Fox <[email protected]> * Fix service name Signed-off-by: Kevin Fox <[email protected]> * Look at data Signed-off-by: Kevin Fox <[email protected]> * Look at data Signed-off-by: Kevin Fox <[email protected]> * Look at data Signed-off-by: Kevin Fox <[email protected]> * Fix ca type Signed-off-by: Kevin Fox <[email protected]> * Test out new packages Signed-off-by: Kevin Fox <[email protected]> * Test out new packages Signed-off-by: Kevin Fox <[email protected]> * Test out new packages Signed-off-by: Kevin Fox <[email protected]> * Test out new packages Signed-off-by: Kevin Fox <[email protected]> * Test out new packages Signed-off-by: Kevin Fox <[email protected]> * Test out new packages Signed-off-by: Kevin Fox <[email protected]> * Test out new packages Signed-off-by: Kevin Fox <[email protected]> * Test out new packages Signed-off-by: Kevin Fox <[email protected]> * Test out new packages Signed-off-by: Kevin Fox <[email protected]> * Test out new packages Signed-off-by: Kevin Fox <[email protected]> * Update ports Signed-off-by: Kevin Fox <[email protected]> * Update ports Signed-off-by: Kevin Fox <[email protected]> * Work on debugging dynamic registration some more Signed-off-by: Kevin Fox <[email protected]> * Fix service account name Signed-off-by: Kevin Fox <[email protected]> * Fix service account name Signed-off-by: Kevin Fox <[email protected]> * Working... Cleanup. Signed-off-by: Kevin Fox <[email protected]> * Working... Cleanup. Signed-off-by: Kevin Fox <[email protected]> * Fix broken ssh test Signed-off-by: Kevin Fox <[email protected]> * Fix broken ssh test Signed-off-by: Kevin Fox <[email protected]> * Simplify a bit Signed-off-by: Kevin Fox <[email protected]> * Update to use the released images Signed-off-by: Kevin Fox <[email protected]> * Allow x509POP cluster name adding Signed-off-by: Kevin Fox <[email protected]> * Restrict cluster registration Signed-off-by: Kevin Fox <[email protected]> * Fix var name Signed-off-by: Kevin Fox <[email protected]> * Fix missing slash Signed-off-by: Kevin Fox <[email protected]> * Make defaults work better Signed-off-by: Kevin Fox <[email protected]> * Make defaults work better Signed-off-by: Kevin Fox <[email protected]> * Fix readme Signed-off-by: Kevin Fox <[email protected]> * updated diagram Signed-off-by: Kevin Fox <[email protected]> * Regenerate image Signed-off-by: Kevin Fox <[email protected]> * Bump spire versions Signed-off-by: Kevin Fox <[email protected]> * Fix issues identified during review Signed-off-by: Kevin Fox <[email protected]> * Update docs Signed-off-by: Kevin Fox <[email protected]> --------- Signed-off-by: Kevin Fox <[email protected]> Signed-off-by: kfox1111 <[email protected]>
This commit is contained in:
@@ -15,6 +15,38 @@ kubeadmConfigPatches:
|
|||||||
# admission-control-config-file: /etc/kubernetes/pki/admctrl/admission-control.yaml
|
# admission-control-config-file: /etc/kubernetes/pki/admctrl/admission-control.yaml
|
||||||
nodes:
|
nodes:
|
||||||
- role: control-plane
|
- role: control-plane
|
||||||
|
extraMounts:
|
||||||
|
- hostPath: /var/run/spiffe/socat/unix/k8s-spire-server-a/public
|
||||||
|
containerPath: /var/run/spiffe/socat/unix/k8s-spire-server-a/public
|
||||||
|
- hostPath: /var/run/spiffe/socat/unix/k8s-spire-server-b/public
|
||||||
|
containerPath: /var/run/spiffe/socat/unix/k8s-spire-server-b/public
|
||||||
- role: worker
|
- role: worker
|
||||||
|
extraMounts:
|
||||||
|
- hostPath: /var/run/spiffe/socat/unix/k8s-spire-server-a/public
|
||||||
|
containerPath: /var/run/spiffe/socat/unix/k8s-spire-server-a/public
|
||||||
|
- hostPath: /var/run/spiffe/socat/unix/k8s-spire-server-b/public
|
||||||
|
containerPath: /var/run/spiffe/socat/unix/k8s-spire-server-b/public
|
||||||
|
- hostPath: /var/run/spiffe/socat/unix/k8s-spire-agent-2-a/public
|
||||||
|
containerPath: /var/run/spiffe/socat/unix/k8s-spire-agent-a/public
|
||||||
|
- hostPath: /var/run/spiffe/socat/unix/k8s-spire-agent-2-b/public
|
||||||
|
containerPath: /var/run/spiffe/socat/unix/k8s-spire-agent-b/public
|
||||||
- role: worker
|
- role: worker
|
||||||
|
extraMounts:
|
||||||
|
- hostPath: /var/run/spiffe/socat/unix/k8s-spire-server-a/public
|
||||||
|
containerPath: /var/run/spiffe/socat/unix/k8s-spire-server-a/public
|
||||||
|
- hostPath: /var/run/spiffe/socat/unix/k8s-spire-server-b/public
|
||||||
|
containerPath: /var/run/spiffe/socat/unix/k8s-spire-server-b/public
|
||||||
|
- hostPath: /var/run/spiffe/socat/unix/k8s-spire-agent-3-a/public
|
||||||
|
containerPath: /var/run/spiffe/socat/unix/k8s-spire-agent-a/public
|
||||||
|
- hostPath: /var/run/spiffe/socat/unix/k8s-spire-agent-3-b/public
|
||||||
|
containerPath: /var/run/spiffe/socat/unix/k8s-spire-agent-b/public
|
||||||
- role: worker
|
- role: worker
|
||||||
|
extraMounts:
|
||||||
|
- hostPath: /var/run/spiffe/socat/unix/k8s-spire-server-a/public
|
||||||
|
containerPath: /var/run/spiffe/socat/unix/k8s-spire-server-a/public
|
||||||
|
- hostPath: /var/run/spiffe/socat/unix/k8s-spire-server-b/public
|
||||||
|
containerPath: /var/run/spiffe/socat/unix/k8s-spire-server-b/public
|
||||||
|
- hostPath: /var/run/spiffe/socat/unix/k8s-spire-agent-4-a/public
|
||||||
|
containerPath: /var/run/spiffe/socat/unix/k8s-spire-agent-a/public
|
||||||
|
- hostPath: /var/run/spiffe/socat/unix/k8s-spire-agent-4-b/public
|
||||||
|
containerPath: /var/run/spiffe/socat/unix/k8s-spire-agent-b/public
|
||||||
|
|||||||
@@ -268,7 +268,7 @@ jobs:
|
|||||||
|
|
||||||
- name: Install and test example
|
- name: Install and test example
|
||||||
run: |
|
run: |
|
||||||
if [ "${{ matrix.example }}" = "examples/federation" -o "${{ matrix.example }}" = "examples/nested-full" -o "${{ matrix.example }}" = "examples/nested-security" ]; then
|
if [ "${{ matrix.example }}" = "examples/federation" -o "${{ matrix.example }}" = "examples/nested-full" -o "${{ matrix.example }}" = "examples/nested-security" -o "${{ matrix.example }}" = "examples/bottom-turtle-ha" ]; then
|
||||||
kubectl create namespace spire-mgmt
|
kubectl create namespace spire-mgmt
|
||||||
helm install -n spire-mgmt spire-crds charts/spire-crds
|
helm install -n spire-mgmt spire-crds charts/spire-crds
|
||||||
else
|
else
|
||||||
|
|||||||
@@ -210,7 +210,7 @@ spec:
|
|||||||
hostPath:
|
hostPath:
|
||||||
path: /dev
|
path: /dev
|
||||||
- name: cid2pid
|
- name: cid2pid
|
||||||
emtpyDir: {}
|
emptyDir: {}
|
||||||
{{- if gt (len .Values.extraVolumes) 0 }}
|
{{- if gt (len .Values.extraVolumes) 0 }}
|
||||||
{{- toYaml .Values.extraVolumes | nindent 8 }}
|
{{- toYaml .Values.extraVolumes | nindent 8 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ description: >
|
|||||||
A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.
|
A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.
|
||||||
type: application
|
type: application
|
||||||
version: 0.28.5
|
version: 0.28.5
|
||||||
appVersion: "1.14.5"
|
appVersion: "1.15.1"
|
||||||
keywords: ["spiffe", "spire", "spire-server", "spire-agent", "oidc", "spire-controller-manager"]
|
keywords: ["spiffe", "spire", "spire-server", "spire-agent", "oidc", "spire-controller-manager"]
|
||||||
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
|
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
|
||||||
sources:
|
sources:
|
||||||
@@ -124,6 +124,62 @@ dependencies:
|
|||||||
condition: spire-ha-agent.enabled
|
condition: spire-ha-agent.enabled
|
||||||
tags:
|
tags:
|
||||||
- haAgentCommon
|
- haAgentCommon
|
||||||
|
- name: spire-server
|
||||||
|
alias: internal-spire-server-bottom-turtle-ha-a
|
||||||
|
condition: internal-spire-server-bottom-turtle-ha-a.enabled
|
||||||
|
tags:
|
||||||
|
- bottomTurtleHAA
|
||||||
|
repository: file://../spire/charts/spire-server
|
||||||
|
version: 0.1.0
|
||||||
|
- name: spire-agent
|
||||||
|
alias: downstream-spire-agent-bottom-turtle-ha-a
|
||||||
|
condition: downstream-spire-agent-bottom-turtle-ha-a.enabled
|
||||||
|
tags:
|
||||||
|
- bottomTurtleHAA
|
||||||
|
repository: file://../spire/charts/spire-agent
|
||||||
|
version: 0.1.0
|
||||||
|
- name: spiffe-csi-driver
|
||||||
|
alias: downstream-spiffe-csi-driver-bottom-turtle-ha-a
|
||||||
|
condition: downstream-spiffe-csi-driver-bottom-turtle-ha-a.enabled
|
||||||
|
tags:
|
||||||
|
- bottomTurtleHAA
|
||||||
|
repository: file://../spire/charts/spiffe-csi-driver
|
||||||
|
version: 0.1.0
|
||||||
|
- name: spiffe-csi-driver
|
||||||
|
alias: upstream-spiffe-csi-driver-bottom-turtle-ha-a
|
||||||
|
condition: upstream-spiffe-csi-driver-bottom-turtle-ha-a.enabled
|
||||||
|
tags:
|
||||||
|
- bottomTurtleHAA
|
||||||
|
repository: file://../spire/charts/spiffe-csi-driver
|
||||||
|
version: 0.1.0
|
||||||
|
- name: spire-server
|
||||||
|
alias: internal-spire-server-bottom-turtle-ha-b
|
||||||
|
condition: internal-spire-server-bottom-turtle-ha-b.enabled
|
||||||
|
tags:
|
||||||
|
- bottomTurtleHAB
|
||||||
|
repository: file://../spire/charts/spire-server
|
||||||
|
version: 0.1.0
|
||||||
|
- name: spire-agent
|
||||||
|
alias: downstream-spire-agent-bottom-turtle-ha-b
|
||||||
|
condition: downstream-spire-agent-bottom-turtle-ha-b.enabled
|
||||||
|
tags:
|
||||||
|
- bottomTurtleHAB
|
||||||
|
repository: file://../spire/charts/spire-agent
|
||||||
|
version: 0.1.0
|
||||||
|
- name: spiffe-csi-driver
|
||||||
|
alias: downstream-spiffe-csi-driver-bottom-turtle-ha-b
|
||||||
|
condition: downstream-spiffe-csi-driver-bottom-turtle-ha-b.enabled
|
||||||
|
tags:
|
||||||
|
- bottomTurtleHAB
|
||||||
|
repository: file://../spire/charts/spiffe-csi-driver
|
||||||
|
version: 0.1.0
|
||||||
|
- name: spiffe-csi-driver
|
||||||
|
alias: upstream-spiffe-csi-driver-bottom-turtle-ha-b
|
||||||
|
condition: upstream-spiffe-csi-driver-bottom-turtle-ha-b.enabled
|
||||||
|
tags:
|
||||||
|
- bottomTurtleHAB
|
||||||
|
repository: file://../spire/charts/spiffe-csi-driver
|
||||||
|
version: 0.1.0
|
||||||
annotations:
|
annotations:
|
||||||
artifacthub.io/category: security
|
artifacthub.io/category: security
|
||||||
artifacthub.io/license: Apache-2.0
|
artifacthub.io/license: Apache-2.0
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# spire
|
# spire
|
||||||
|
|
||||||
  
|
  
|
||||||
[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
|
[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
|
||||||
|
|
||||||
A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.
|
A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.
|
||||||
@@ -234,6 +234,8 @@ Now you can interact with the Spire agent socket from your own application. The
|
|||||||
| `tags.nestedChildFull` | Set the chart mode to a child cluster with its own nested server | `false` |
|
| `tags.nestedChildFull` | Set the chart mode to a child cluster with its own nested server | `false` |
|
||||||
| `tags.nestedChildSecurity` | Set the chart mode to a child cluster for use with a security cluster | `false` |
|
| `tags.nestedChildSecurity` | Set the chart mode to a child cluster for use with a security cluster | `false` |
|
||||||
| `tags.haAgentCommon` | Set the chart mode to deploy the common portion of a spire-ha-agent setup | `false` |
|
| `tags.haAgentCommon` | Set the chart mode to deploy the common portion of a spire-ha-agent setup | `false` |
|
||||||
|
| `tags.bottomTurtleHAA` | Setup HA side A for use with a Bottom Turtle architecture | `false` |
|
||||||
|
| `tags.bottomTurtleHAB` | Setup HA side B for use with a Bottom Turtle architecture | `false` |
|
||||||
|
|
||||||
### Spire agent parameters
|
### Spire agent parameters
|
||||||
|
|
||||||
@@ -354,6 +356,137 @@ Now you can interact with the Spire agent socket from your own application. The
|
|||||||
| `external-spire-server.bundlePublisher.k8sConfigMap.enabled` | Enable local k8s bundle uploader | `false` |
|
| `external-spire-server.bundlePublisher.k8sConfigMap.enabled` | Enable local k8s bundle uploader | `false` |
|
||||||
| `external-spire-server.nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s nodeattestor | `false` |
|
| `external-spire-server.nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s nodeattestor | `false` |
|
||||||
| `external-spire-server.nodeAttestor.joinToken.enabled` | Enable the join_token nodeattestor | `true` |
|
| `external-spire-server.nodeAttestor.joinToken.enabled` | Enable the join_token nodeattestor | `true` |
|
||||||
|
| `spiffe-csi-driver.fullnameOverride` | Fullname override | `spiffe-csi-driver` |
|
||||||
| `spiffe-csi-driver.agentSocketPath` | The socket path where Spiffe CSI driver mounts agent socket | `/var/run/spire/agent-sockets/spire-agent.sock` |
|
| `spiffe-csi-driver.agentSocketPath` | The socket path where Spiffe CSI driver mounts agent socket | `/var/run/spire/agent-sockets/spire-agent.sock` |
|
||||||
| `spiffe-csi-driver.healthChecks.port` | Health check port number for upstream Spire agent | `9814` |
|
| `spiffe-csi-driver.healthChecks.port` | Health check port number for upstream Spire agent | `9814` |
|
||||||
| `spire-ha-agent` | The configuration overrides for a spire-ha-agent | `{}` |
|
| `spire-ha-agent.fullnameOverride` | Fullname override | `spire-ha-agent` |
|
||||||
|
|
||||||
|
### Upstream SPIFFE CSI Driver for Bottom Turtle HA A parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| --------------------------------------------------------------------------------- | ----------------------------------------------------------- | ----------------------------------------------------------------------- |
|
||||||
|
| `upstream-spiffe-csi-driver-bottom-turtle-ha-a.fullnameOverride` | Fullname override | `spiffe-csi-driver-upstream-a` |
|
||||||
|
| `upstream-spiffe-csi-driver-bottom-turtle-ha-a.pluginName` | The plugin name for configuring upstream Spiffe CSI driver | `upstream-a.csi.spiffe.io` |
|
||||||
|
| `upstream-spiffe-csi-driver-bottom-turtle-ha-a.agentSocketPath` | The socket path where Spiffe CSI driver mounts agent socket | `/var/run/spiffe/socat/unix/k8s-spire-server-a/public/spire-agent.sock` |
|
||||||
|
| `upstream-spiffe-csi-driver-bottom-turtle-ha-a.healthChecks.port` | The port where Spiffe CSI driver health checks are exposed | `9810` |
|
||||||
|
| `upstream-spiffe-csi-driver-bottom-turtle-ha-a.validatingAdmissionPolicy.enabled` | Flag to enable validating policy | `true` |
|
||||||
|
|
||||||
|
### Upstream SPIFFE CSI Driver for Bottom Turtle HA B parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| --------------------------------------------------------------------------------- | ----------------------------------------------------------- | ----------------------------------------------------------------------- |
|
||||||
|
| `upstream-spiffe-csi-driver-bottom-turtle-ha-b.fullnameOverride` | Fullname override | `spiffe-csi-driver-upstream-b` |
|
||||||
|
| `upstream-spiffe-csi-driver-bottom-turtle-ha-b.pluginName` | The plugin name for configuring upstream Spiffe CSI driver | `upstream-b.csi.spiffe.io` |
|
||||||
|
| `upstream-spiffe-csi-driver-bottom-turtle-ha-b.agentSocketPath` | The socket path where Spiffe CSI driver mounts agent socket | `/var/run/spiffe/socat/unix/k8s-spire-server-b/public/spire-agent.sock` |
|
||||||
|
| `upstream-spiffe-csi-driver-bottom-turtle-ha-b.healthChecks.port` | The port where Spiffe CSI driver health checks are exposed | `9812` |
|
||||||
|
| `upstream-spiffe-csi-driver-bottom-turtle-ha-b.validatingAdmissionPolicy.enabled` | Flag to enable validating policy | `true` |
|
||||||
|
|
||||||
|
### Spire server parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| ------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------- | ----------------------------------------------------------------------------- |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.nameOverride` | Overrides the name of Spire server pods | `internal-server` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.caKeyType` | Key type to use for the ca | `ec-p256` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.experimental.enabled` | enable experimental features | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.experimental.agentSPIFFEIDAsSelector` | enable adding spiffe_id selectors to all agents | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.dynamicRegistration.enabled` | Enable dynamic registration | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.dynamicRegistration.allowedIDPrefix` | The allowed ID prefix | `spire/agent/x509pop/k8s` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.dynamicRegistration.serviceAccount` | The service account to allow in for dynamic registration | `spire-a-agent` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.controllerManager.enabled` | Enable controller manager and provision CRD's | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.controllerManager.parentIDTemplate` | parent id template | `spiffe://{{ .TrustDomain }}/k8s_psat/{{ .ClusterName }}/{{ .NodeMeta.UID }}` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.autoPopulateDNSNames` | Auto populate dns entries | `false` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.type` | The type of the entry | `oidc-discovery-provider-common` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.enabled` | Enables the spire-ha-agent identity | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.persistence.type` | What type to use for peristence | `emptyDir` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.nodeAttestor.k8sPSAT.enabled` | Enable the k8s projected access token node attestor | `false` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.enabled` | Enable the x509 pop node attestor | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.svidPrefix` | What prefix to use when mode is spiffe | `/spire-exchange/k8s` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.agentPathTemplate` | Override the default agent path template | `/{{ .PluginName }}/{{ .SVIDPathTrimmed }}/k8s` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.addClusterName.svidPrefix` | Suffix the cluster name onto the svidPrefix | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.addClusterName.agentPathTemplate` | Suffix the cluster name onto the agentPathTemplate | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.enabled` | Enable upstream SPIRE server | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.upstreamDriver` | Use an upstream driver for authentication | `upstream-a.csi.spiffe.io` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.server.nameOverride` | The name override setting of the root SPIRE server | `root-server` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.server.address` | Address for upstream Spire server | `spire-server-a` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.server.port` | The port setting of the root SPIRE server | `8081` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.bundleConfigMap` | The name of the configmap to store the downstream bundle | `spire-server-a-bundle` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.trustSync.enabled` | Enable trust syncing | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-a.trustSync.domains` | the trust domains to sync | `["spire-ha"]` |
|
||||||
|
|
||||||
|
### Spire server parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| ------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------- | ----------------------------------------------------------------------------- |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.nameOverride` | Overrides the name of Spire server pods | `internal-server` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.caKeyType` | Key type to use for the ca | `ec-p256` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.experimental.enabled` | enable experimental features | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.experimental.agentSPIFFEIDAsSelector` | enable adding spiffe_id selectors to all agents | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.dynamicRegistration.enabled` | Enable dynamic registration | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.dynamicRegistration.allowedIDPrefix` | The allowed ID prefix | `spire/agent/x509pop/k8s` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.dynamicRegistration.serviceAccount` | The service account to allow in for dynamic registration | `spire-b-agent` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.controllerManager.enabled` | Enable controller manager and provision CRD's | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.controllerManager.parentIDTemplate` | parent id template | `spiffe://{{ .TrustDomain }}/k8s_psat/{{ .ClusterName }}/{{ .NodeMeta.UID }}` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.autoPopulateDNSNames` | Auto populate dns entries | `false` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.type` | The type of the entry | `oidc-discovery-provider-common` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.enabled` | Enables the spire-ha-agent identity | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.persistence.type` | What type to use for peristence | `emptyDir` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.nodeAttestor.k8sPSAT.enabled` | Enable the k8s projected access token node attestor | `false` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.enabled` | Enable the x509 pop node attestor | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.svidPrefix` | What prefix to use when mode is spiffe | `/spire-exchange/k8s` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.agentPathTemplate` | Override the default agent path template | `/{{ .PluginName }}/{{ .SVIDPathTrimmed }}/k8s` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.addClusterName.svidPrefix` | Suffix the cluster name onto the svidPrefix | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.addClusterName.agentPathTemplate` | Suffix the cluster name onto the agentPathTemplate | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.enabled` | Enable upstream SPIRE server | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.upstreamDriver` | Use an upstream driver for authentication | `upstream-b.csi.spiffe.io` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.server.nameOverride` | The name override setting of the root SPIRE server | `root-server` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.server.address` | Address for upstream Spire server | `spire-server-b` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.server.port` | The port setting of the root SPIRE server | `8081` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.bundleConfigMap` | The name of the configmap to store the downstream bundle | `spire-server-b-bundle` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.trustSync.enabled` | Enable trust syncing | `true` |
|
||||||
|
| `internal-spire-server-bottom-turtle-ha-b.trustSync.domains` | the trust domains to sync | `["spire-ha"]` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.nameOverride` | Overrides the name of Spire agent pods | `agent-downstream` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.server.nameOverride` | The name override setting of the internal SPIRE server | `internal-server` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.bundleConfigMap` | The name of the configmap that contains the downstream bundle | `spire-server-a-bundle` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.persistence.hostPath` | Which path to use on the host when persistence.type = hostPath | `/var/lib/spire/k8s/downstream-agent-a` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.dynamicRegistration.enabled` | Enable dynamic registration | `true` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.dynamicRegistration.nameOverride` | The name override to use to contact the server | `internal-server` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.nodeAttestor.k8sPSAT.enabled` | Enable the k8s projected access token node attestor | `false` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.nodeAttestor.x509POP.enabled` | Enable the x509 pop node attestor | `true` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.nodeAttestor.x509POP.spiffeEndpointSocket` | Where the socket is to use for mode spiffe | `/var/run/spiffe/socat/unix/k8s-spire-agent-a/public/api.sock` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.keyManager.memory.enabled` | Enable the memory based Key Manager | `false` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.keyManager.disk.enabled` | Enable the disk key manager | `true` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.keyManager.disk.mode` | Where the disk plugin will write out its data | `emptyDir` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.healthChecks.port` | Health check port | `9981` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.telemetry.prometheus.port` | Prometheus port to use | `9989` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.socketPath` | Socket path to use | `/var/run/spire/agent/sockets/a/csi.spiffe.io/public/spire-agent.sock` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.sockets.hostBasePath` | Path on the host to place sockets | `/var/run/spire/agent/sockets/a` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.sockets.admin.enabled` | Enable admin socket | `true` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.sockets.admin.mountOnHost` | Mount admin socket on host | `true` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-a.authorizedDelegates` | List of workloads able to use the delegation api | `["/spire-ha-agent"]` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.nameOverride` | Overrides the name of Spire agent pods | `agent-downstream` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.server.nameOverride` | The name override setting of the internal SPIRE server | `internal-server` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.bundleConfigMap` | The name of the configmap that contains the downstream bundle | `spire-server-b-bundle` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.persistence.hostPath` | Which path to use on the host when persistence.type = hostPath | `/var/lib/spire/k8s/downstream-agent-b` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.dynamicRegistration.enabled` | Enable dynamic registration | `true` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.dynamicRegistration.nameOverride` | The name override to use to contact the server | `internal-server` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.nodeAttestor.k8sPSAT.enabled` | Enable the k8s projected access token node attestor | `false` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.nodeAttestor.x509POP.enabled` | Enable the x509 pop node attestor | `true` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.nodeAttestor.x509POP.spiffeEndpointSocket` | Where the socket is to use for mode spiffe | `/var/run/spiffe/socat/unix/k8s-spire-agent-b/public/api.sock` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.keyManager.memory.enabled` | Enable the memory based Key Manager | `false` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.keyManager.disk.enabled` | Enable the disk key manager | `true` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.keyManager.disk.mode` | Where the disk plugin will write out its data | `emptyDir` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.healthChecks.port` | Health check port | `9982` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.telemetry.prometheus.port` | Prometheus port to use | `9990` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.socketPath` | Socket path to use | `/var/run/spire/agent/sockets/b/csi.spiffe.io/public/spire-agent.sock` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.sockets.hostBasePath` | Path on the host to place sockets | `/var/run/spire/agent/sockets/b` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.sockets.admin.enabled` | Enable admin socket | `true` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.sockets.admin.mountOnHost` | Mount admin socket on host | `true` |
|
||||||
|
| `downstream-spire-agent-bottom-turtle-ha-b.authorizedDelegates` | List of workloads able to use the delegation api | `["/spire-ha-agent"]` |
|
||||||
|
| `downstream-spiffe-csi-driver-bottom-turtle-ha-a.fullnameOverride` | Fullname override | `spiffe-csi-driver-downstream-a` |
|
||||||
|
| `downstream-spiffe-csi-driver-bottom-turtle-ha-a.agentSocketPath` | path to agent socket | `/var/run/spire/agent/sockets/a/csi.spiffe.io/public/spire-agent.sock` |
|
||||||
|
| `downstream-spiffe-csi-driver-bottom-turtle-ha-a.pluginName` | The name of the plugin instance | `a.csi.spiffe.io` |
|
||||||
|
| `downstream-spiffe-csi-driver-bottom-turtle-ha-a.healthChecks.port` | The health check port | `9814` |
|
||||||
|
| `downstream-spiffe-csi-driver-bottom-turtle-ha-b.fullnameOverride` | Fullname override | `spiffe-csi-driver-downstream-b` |
|
||||||
|
| `downstream-spiffe-csi-driver-bottom-turtle-ha-b.agentSocketPath` | path to agent socket | `/var/run/spire/agent/sockets/b/csi.spiffe.io/public/spire-agent.sock` |
|
||||||
|
| `downstream-spiffe-csi-driver-bottom-turtle-ha-b.pluginName` | The name of the plugin instance | `b.csi.spiffe.io` |
|
||||||
|
| `downstream-spiffe-csi-driver-bottom-turtle-ha-b.healthChecks.port` | The health check port | `9816` |
|
||||||
|
|||||||
@@ -103,6 +103,10 @@ tags:
|
|||||||
nestedChildSecurity: false
|
nestedChildSecurity: false
|
||||||
## @param tags.haAgentCommon Set the chart mode to deploy the common portion of a spire-ha-agent setup
|
## @param tags.haAgentCommon Set the chart mode to deploy the common portion of a spire-ha-agent setup
|
||||||
haAgentCommon: false
|
haAgentCommon: false
|
||||||
|
## @param tags.bottomTurtleHAA Setup HA side A for use with a Bottom Turtle architecture
|
||||||
|
bottomTurtleHAA: false
|
||||||
|
## @param tags.bottomTurtleHAB Setup HA side B for use with a Bottom Turtle architecture
|
||||||
|
bottomTurtleHAB: false
|
||||||
|
|
||||||
## subcharts
|
## subcharts
|
||||||
|
|
||||||
@@ -401,13 +405,350 @@ external-spire-server:
|
|||||||
# Used with tags [haAgentCommon]
|
# Used with tags [haAgentCommon]
|
||||||
spiffe-csi-driver:
|
spiffe-csi-driver:
|
||||||
# enabled: true
|
# enabled: true
|
||||||
|
## @param spiffe-csi-driver.fullnameOverride Fullname override
|
||||||
|
fullnameOverride: spiffe-csi-driver
|
||||||
## @param spiffe-csi-driver.agentSocketPath The socket path where Spiffe CSI driver mounts agent socket
|
## @param spiffe-csi-driver.agentSocketPath The socket path where Spiffe CSI driver mounts agent socket
|
||||||
agentSocketPath: /var/run/spire/agent-sockets/spire-agent.sock
|
agentSocketPath: /var/run/spire/agent-sockets/spire-agent.sock
|
||||||
healthChecks:
|
healthChecks:
|
||||||
## @param spiffe-csi-driver.healthChecks.port Health check port number for upstream Spire agent
|
## @param spiffe-csi-driver.healthChecks.port Health check port number for upstream Spire agent
|
||||||
port: 9814
|
port: 9814
|
||||||
|
|
||||||
## @param spire-ha-agent The configuration overrides for a spire-ha-agent
|
|
||||||
# Used with tags [haAgentCommon]
|
# Used with tags [haAgentCommon]
|
||||||
spire-ha-agent: {}
|
spire-ha-agent:
|
||||||
# enabled: true
|
# enabled: true
|
||||||
|
## @param spire-ha-agent.fullnameOverride Fullname override
|
||||||
|
fullnameOverride: spire-ha-agent
|
||||||
|
|
||||||
|
## @section Upstream SPIFFE CSI Driver for Bottom Turtle HA A parameters
|
||||||
|
## Parameter values for upstream spiffe-csi-driver-bottom-turtle-ha-a
|
||||||
|
##
|
||||||
|
# Used with tags [bottomTurtleHAA]
|
||||||
|
upstream-spiffe-csi-driver-bottom-turtle-ha-a:
|
||||||
|
# enabled: true
|
||||||
|
## @param upstream-spiffe-csi-driver-bottom-turtle-ha-a.fullnameOverride Fullname override
|
||||||
|
fullnameOverride: spiffe-csi-driver-upstream-a
|
||||||
|
## @param upstream-spiffe-csi-driver-bottom-turtle-ha-a.pluginName The plugin name for configuring upstream Spiffe CSI driver
|
||||||
|
pluginName: upstream-a.csi.spiffe.io
|
||||||
|
## @param upstream-spiffe-csi-driver-bottom-turtle-ha-a.agentSocketPath The socket path where Spiffe CSI driver mounts agent socket
|
||||||
|
agentSocketPath: /var/run/spiffe/socat/unix/k8s-spire-server-a/public/spire-agent.sock
|
||||||
|
healthChecks:
|
||||||
|
## @param upstream-spiffe-csi-driver-bottom-turtle-ha-a.healthChecks.port The port where Spiffe CSI driver health checks are exposed
|
||||||
|
port: 9810
|
||||||
|
validatingAdmissionPolicy:
|
||||||
|
## @param upstream-spiffe-csi-driver-bottom-turtle-ha-a.validatingAdmissionPolicy.enabled Flag to enable validating policy
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
## @section Upstream SPIFFE CSI Driver for Bottom Turtle HA B parameters
|
||||||
|
## Parameter values for upstream spiffe-csi-driver-bottom-turtle-ha-b
|
||||||
|
##
|
||||||
|
# Used with tags [bottomTurtleHAB]
|
||||||
|
upstream-spiffe-csi-driver-bottom-turtle-ha-b:
|
||||||
|
# enabled: true
|
||||||
|
## @param upstream-spiffe-csi-driver-bottom-turtle-ha-b.fullnameOverride Fullname override
|
||||||
|
fullnameOverride: spiffe-csi-driver-upstream-b
|
||||||
|
## @param upstream-spiffe-csi-driver-bottom-turtle-ha-b.pluginName The plugin name for configuring upstream Spiffe CSI driver
|
||||||
|
pluginName: upstream-b.csi.spiffe.io
|
||||||
|
## @param upstream-spiffe-csi-driver-bottom-turtle-ha-b.agentSocketPath The socket path where Spiffe CSI driver mounts agent socket
|
||||||
|
agentSocketPath: /var/run/spiffe/socat/unix/k8s-spire-server-b/public/spire-agent.sock
|
||||||
|
healthChecks:
|
||||||
|
## @param upstream-spiffe-csi-driver-bottom-turtle-ha-b.healthChecks.port The port where Spiffe CSI driver health checks are exposed
|
||||||
|
port: 9812
|
||||||
|
validatingAdmissionPolicy:
|
||||||
|
## @param upstream-spiffe-csi-driver-bottom-turtle-ha-b.validatingAdmissionPolicy.enabled Flag to enable validating policy
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
## @section Spire server parameters
|
||||||
|
## Parameter values for Spire server
|
||||||
|
##
|
||||||
|
# Used with tags [bottomTurtleHAA]
|
||||||
|
internal-spire-server-bottom-turtle-ha-a:
|
||||||
|
# enabled: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.nameOverride Overrides the name of Spire server pods
|
||||||
|
nameOverride: internal-server
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.caKeyType Key type to use for the ca
|
||||||
|
caKeyType: ec-p256
|
||||||
|
experimental:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.experimental.enabled enable experimental features
|
||||||
|
enabled: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.experimental.agentSPIFFEIDAsSelector enable adding spiffe_id selectors to all agents
|
||||||
|
agentSPIFFEIDAsSelector: true
|
||||||
|
dynamicRegistration:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.dynamicRegistration.enabled Enable dynamic registration
|
||||||
|
enabled: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.dynamicRegistration.allowedIDPrefix The allowed ID prefix
|
||||||
|
allowedIDPrefix: "spire/agent/x509pop/k8s"
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.dynamicRegistration.serviceAccount The service account to allow in for dynamic registration
|
||||||
|
serviceAccount: spire-a-agent
|
||||||
|
controllerManager:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.controllerManager.enabled Enable controller manager and provision CRD's
|
||||||
|
enabled: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.controllerManager.parentIDTemplate parent id template
|
||||||
|
parentIDTemplate: "spiffe://{{ .TrustDomain }}/k8s_psat/{{ .ClusterName }}/{{ .NodeMeta.UID }}"
|
||||||
|
identities:
|
||||||
|
clusterSPIFFEIDs:
|
||||||
|
oidc-discovery-provider:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.autoPopulateDNSNames Auto populate dns entries
|
||||||
|
autoPopulateDNSNames: false
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.type The type of the entry
|
||||||
|
type: oidc-discovery-provider-common
|
||||||
|
spire-ha-agent:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.enabled Enables the spire-ha-agent identity
|
||||||
|
enabled: true
|
||||||
|
persistence:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.persistence.type What type to use for peristence
|
||||||
|
type: emptyDir
|
||||||
|
nodeAttestor:
|
||||||
|
k8sPSAT:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.nodeAttestor.k8sPSAT.enabled Enable the k8s projected access token node attestor
|
||||||
|
enabled: false
|
||||||
|
x509POP:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.enabled Enable the x509 pop node attestor
|
||||||
|
enabled: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.svidPrefix What prefix to use when mode is spiffe
|
||||||
|
svidPrefix: /spire-exchange/k8s
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.agentPathTemplate Override the default agent path template
|
||||||
|
agentPathTemplate: "/{{ .PluginName }}/{{ .SVIDPathTrimmed }}/k8s"
|
||||||
|
addClusterName:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.addClusterName.svidPrefix Suffix the cluster name onto the svidPrefix
|
||||||
|
svidPrefix: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.addClusterName.agentPathTemplate Suffix the cluster name onto the agentPathTemplate
|
||||||
|
agentPathTemplate: true
|
||||||
|
upstreamAuthority:
|
||||||
|
spire:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.enabled Enable upstream SPIRE server
|
||||||
|
enabled: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.upstreamDriver Use an upstream driver for authentication
|
||||||
|
upstreamDriver: upstream-a.csi.spiffe.io
|
||||||
|
server:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.server.nameOverride The name override setting of the root SPIRE server
|
||||||
|
nameOverride: root-server
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.server.address Address for upstream Spire server
|
||||||
|
address: "spire-server-a"
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.server.port The port setting of the root SPIRE server
|
||||||
|
port: 8081
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.bundleConfigMap The name of the configmap to store the downstream bundle
|
||||||
|
bundleConfigMap: spire-server-a-bundle
|
||||||
|
trustSync:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.trustSync.enabled Enable trust syncing
|
||||||
|
enabled: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-a.trustSync.domains the trust domains to sync
|
||||||
|
domains:
|
||||||
|
- spire-ha
|
||||||
|
|
||||||
|
## @section Spire server parameters
|
||||||
|
## Parameter values for Spire server
|
||||||
|
##
|
||||||
|
# Used with tags [bottomTurtleHAB]
|
||||||
|
internal-spire-server-bottom-turtle-ha-b:
|
||||||
|
# enabled: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.nameOverride Overrides the name of Spire server pods
|
||||||
|
nameOverride: internal-server
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.caKeyType Key type to use for the ca
|
||||||
|
caKeyType: ec-p256
|
||||||
|
experimental:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.experimental.enabled enable experimental features
|
||||||
|
enabled: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.experimental.agentSPIFFEIDAsSelector enable adding spiffe_id selectors to all agents
|
||||||
|
agentSPIFFEIDAsSelector: true
|
||||||
|
dynamicRegistration:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.dynamicRegistration.enabled Enable dynamic registration
|
||||||
|
enabled: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.dynamicRegistration.allowedIDPrefix The allowed ID prefix
|
||||||
|
allowedIDPrefix: "spire/agent/x509pop/k8s"
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.dynamicRegistration.serviceAccount The service account to allow in for dynamic registration
|
||||||
|
serviceAccount: spire-b-agent
|
||||||
|
controllerManager:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.controllerManager.enabled Enable controller manager and provision CRD's
|
||||||
|
enabled: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.controllerManager.parentIDTemplate parent id template
|
||||||
|
parentIDTemplate: "spiffe://{{ .TrustDomain }}/k8s_psat/{{ .ClusterName }}/{{ .NodeMeta.UID }}"
|
||||||
|
identities:
|
||||||
|
clusterSPIFFEIDs:
|
||||||
|
oidc-discovery-provider:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.autoPopulateDNSNames Auto populate dns entries
|
||||||
|
autoPopulateDNSNames: false
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.type The type of the entry
|
||||||
|
type: oidc-discovery-provider-common
|
||||||
|
spire-ha-agent:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.enabled Enables the spire-ha-agent identity
|
||||||
|
enabled: true
|
||||||
|
persistence:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.persistence.type What type to use for peristence
|
||||||
|
type: emptyDir
|
||||||
|
nodeAttestor:
|
||||||
|
k8sPSAT:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.nodeAttestor.k8sPSAT.enabled Enable the k8s projected access token node attestor
|
||||||
|
enabled: false
|
||||||
|
x509POP:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.enabled Enable the x509 pop node attestor
|
||||||
|
enabled: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.svidPrefix What prefix to use when mode is spiffe
|
||||||
|
svidPrefix: /spire-exchange/k8s
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.agentPathTemplate Override the default agent path template
|
||||||
|
agentPathTemplate: "/{{ .PluginName }}/{{ .SVIDPathTrimmed }}/k8s"
|
||||||
|
addClusterName:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.addClusterName.svidPrefix Suffix the cluster name onto the svidPrefix
|
||||||
|
svidPrefix: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.addClusterName.agentPathTemplate Suffix the cluster name onto the agentPathTemplate
|
||||||
|
agentPathTemplate: true
|
||||||
|
upstreamAuthority:
|
||||||
|
spire:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.enabled Enable upstream SPIRE server
|
||||||
|
enabled: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.upstreamDriver Use an upstream driver for authentication
|
||||||
|
upstreamDriver: upstream-b.csi.spiffe.io
|
||||||
|
server:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.server.nameOverride The name override setting of the root SPIRE server
|
||||||
|
nameOverride: root-server
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.server.address Address for upstream Spire server
|
||||||
|
address: "spire-server-b"
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.server.port The port setting of the root SPIRE server
|
||||||
|
port: 8081
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.bundleConfigMap The name of the configmap to store the downstream bundle
|
||||||
|
bundleConfigMap: spire-server-b-bundle
|
||||||
|
trustSync:
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.trustSync.enabled Enable trust syncing
|
||||||
|
enabled: true
|
||||||
|
## @param internal-spire-server-bottom-turtle-ha-b.trustSync.domains the trust domains to sync
|
||||||
|
domains:
|
||||||
|
- spire-ha
|
||||||
|
|
||||||
|
# Used with tags [bottomTurtleHAA]
|
||||||
|
downstream-spire-agent-bottom-turtle-ha-a:
|
||||||
|
# enabled: true
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.nameOverride Overrides the name of Spire agent pods
|
||||||
|
nameOverride: agent-downstream
|
||||||
|
server:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.server.nameOverride The name override setting of the internal SPIRE server
|
||||||
|
nameOverride: internal-server
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.bundleConfigMap The name of the configmap that contains the downstream bundle
|
||||||
|
bundleConfigMap: spire-server-a-bundle
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.persistence.hostPath Which path to use on the host when persistence.type = hostPath
|
||||||
|
persistence:
|
||||||
|
hostPath: /var/lib/spire/k8s/downstream-agent-a
|
||||||
|
dynamicRegistration:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.dynamicRegistration.enabled Enable dynamic registration
|
||||||
|
enabled: true
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.dynamicRegistration.nameOverride The name override to use to contact the server
|
||||||
|
nameOverride: internal-server
|
||||||
|
nodeAttestor:
|
||||||
|
k8sPSAT:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.nodeAttestor.k8sPSAT.enabled Enable the k8s projected access token node attestor
|
||||||
|
enabled: false
|
||||||
|
x509POP:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.nodeAttestor.x509POP.enabled Enable the x509 pop node attestor
|
||||||
|
enabled: true
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.nodeAttestor.x509POP.spiffeEndpointSocket Where the socket is to use for mode spiffe
|
||||||
|
spiffeEndpointSocket: /var/run/spiffe/socat/unix/k8s-spire-agent-a/public/api.sock
|
||||||
|
keyManager:
|
||||||
|
memory:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.keyManager.memory.enabled Enable the memory based Key Manager
|
||||||
|
enabled: false
|
||||||
|
disk:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.keyManager.disk.enabled Enable the disk key manager
|
||||||
|
enabled: true
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.keyManager.disk.mode Where the disk plugin will write out its data
|
||||||
|
mode: emptyDir
|
||||||
|
healthChecks:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.healthChecks.port Health check port
|
||||||
|
port: 9981
|
||||||
|
telemetry:
|
||||||
|
prometheus:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.telemetry.prometheus.port Prometheus port to use
|
||||||
|
port: 9989
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.socketPath Socket path to use
|
||||||
|
socketPath: /var/run/spire/agent/sockets/a/csi.spiffe.io/public/spire-agent.sock
|
||||||
|
sockets:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.sockets.hostBasePath Path on the host to place sockets
|
||||||
|
hostBasePath: /var/run/spire/agent/sockets/a
|
||||||
|
admin:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.sockets.admin.enabled Enable admin socket
|
||||||
|
enabled: true
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.sockets.admin.mountOnHost Mount admin socket on host
|
||||||
|
mountOnHost: true
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-a.authorizedDelegates List of workloads able to use the delegation api
|
||||||
|
authorizedDelegates:
|
||||||
|
- /spire-ha-agent
|
||||||
|
|
||||||
|
# Used with tags [bottomTurtleHAB]
|
||||||
|
downstream-spire-agent-bottom-turtle-ha-b:
|
||||||
|
# enabled: true
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.nameOverride Overrides the name of Spire agent pods
|
||||||
|
nameOverride: agent-downstream
|
||||||
|
server:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.server.nameOverride The name override setting of the internal SPIRE server
|
||||||
|
nameOverride: internal-server
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.bundleConfigMap The name of the configmap that contains the downstream bundle
|
||||||
|
bundleConfigMap: spire-server-b-bundle
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.persistence.hostPath Which path to use on the host when persistence.type = hostPath
|
||||||
|
persistence:
|
||||||
|
hostPath: /var/lib/spire/k8s/downstream-agent-b
|
||||||
|
dynamicRegistration:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.dynamicRegistration.enabled Enable dynamic registration
|
||||||
|
enabled: true
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.dynamicRegistration.nameOverride The name override to use to contact the server
|
||||||
|
nameOverride: internal-server
|
||||||
|
nodeAttestor:
|
||||||
|
k8sPSAT:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.nodeAttestor.k8sPSAT.enabled Enable the k8s projected access token node attestor
|
||||||
|
enabled: false
|
||||||
|
x509POP:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.nodeAttestor.x509POP.enabled Enable the x509 pop node attestor
|
||||||
|
enabled: true
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.nodeAttestor.x509POP.spiffeEndpointSocket Where the socket is to use for mode spiffe
|
||||||
|
spiffeEndpointSocket: /var/run/spiffe/socat/unix/k8s-spire-agent-b/public/api.sock
|
||||||
|
keyManager:
|
||||||
|
memory:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.keyManager.memory.enabled Enable the memory based Key Manager
|
||||||
|
enabled: false
|
||||||
|
disk:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.keyManager.disk.enabled Enable the disk key manager
|
||||||
|
enabled: true
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.keyManager.disk.mode Where the disk plugin will write out its data
|
||||||
|
mode: emptyDir
|
||||||
|
healthChecks:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.healthChecks.port Health check port
|
||||||
|
port: 9982
|
||||||
|
telemetry:
|
||||||
|
prometheus:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.telemetry.prometheus.port Prometheus port to use
|
||||||
|
port: 9990
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.socketPath Socket path to use
|
||||||
|
socketPath: /var/run/spire/agent/sockets/b/csi.spiffe.io/public/spire-agent.sock
|
||||||
|
sockets:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.sockets.hostBasePath Path on the host to place sockets
|
||||||
|
hostBasePath: /var/run/spire/agent/sockets/b
|
||||||
|
admin:
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.sockets.admin.enabled Enable admin socket
|
||||||
|
enabled: true
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.sockets.admin.mountOnHost Mount admin socket on host
|
||||||
|
mountOnHost: true
|
||||||
|
## @param downstream-spire-agent-bottom-turtle-ha-b.authorizedDelegates List of workloads able to use the delegation api
|
||||||
|
authorizedDelegates:
|
||||||
|
- /spire-ha-agent
|
||||||
|
|
||||||
|
# Used with tags [bottomTurtleHAA]
|
||||||
|
downstream-spiffe-csi-driver-bottom-turtle-ha-a:
|
||||||
|
# enabled: true
|
||||||
|
## @param downstream-spiffe-csi-driver-bottom-turtle-ha-a.fullnameOverride Fullname override
|
||||||
|
fullnameOverride: spiffe-csi-driver-downstream-a
|
||||||
|
## @param downstream-spiffe-csi-driver-bottom-turtle-ha-a.agentSocketPath path to agent socket
|
||||||
|
agentSocketPath: /var/run/spire/agent/sockets/a/csi.spiffe.io/public/spire-agent.sock
|
||||||
|
## @param downstream-spiffe-csi-driver-bottom-turtle-ha-a.pluginName The name of the plugin instance
|
||||||
|
pluginName: a.csi.spiffe.io
|
||||||
|
healthChecks:
|
||||||
|
## @param downstream-spiffe-csi-driver-bottom-turtle-ha-a.healthChecks.port The health check port
|
||||||
|
port: 9814
|
||||||
|
|
||||||
|
# Used with tags [bottomTurtleHAB]
|
||||||
|
downstream-spiffe-csi-driver-bottom-turtle-ha-b:
|
||||||
|
# enabled: true
|
||||||
|
## @param downstream-spiffe-csi-driver-bottom-turtle-ha-b.fullnameOverride Fullname override
|
||||||
|
fullnameOverride: spiffe-csi-driver-downstream-b
|
||||||
|
## @param downstream-spiffe-csi-driver-bottom-turtle-ha-b.agentSocketPath path to agent socket
|
||||||
|
agentSocketPath: /var/run/spire/agent/sockets/b/csi.spiffe.io/public/spire-agent.sock
|
||||||
|
## @param downstream-spiffe-csi-driver-bottom-turtle-ha-b.pluginName The name of the plugin instance
|
||||||
|
pluginName: b.csi.spiffe.io
|
||||||
|
healthChecks:
|
||||||
|
## @param downstream-spiffe-csi-driver-bottom-turtle-ha-b.healthChecks.port The health check port
|
||||||
|
port: 9816
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# spire
|
# spire
|
||||||
|
|
||||||
  
|
  
|
||||||
[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
|
[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
|
||||||
|
|
||||||
A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.
|
A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ name: spiffe-oidc-discovery-provider
|
|||||||
description: A Helm chart to install the SPIFFE OIDC discovery provider.
|
description: A Helm chart to install the SPIFFE OIDC discovery provider.
|
||||||
type: application
|
type: application
|
||||||
version: 0.1.0
|
version: 0.1.0
|
||||||
appVersion: "1.14.5"
|
appVersion: "1.15.1"
|
||||||
keywords: ["spiffe", "oidc"]
|
keywords: ["spiffe", "oidc"]
|
||||||
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
|
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
|
||||||
sources:
|
sources:
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ name: spire-agent
|
|||||||
description: A Helm chart to install the SPIRE agent.
|
description: A Helm chart to install the SPIRE agent.
|
||||||
type: application
|
type: application
|
||||||
version: 0.1.0
|
version: 0.1.0
|
||||||
appVersion: "1.14.5"
|
appVersion: "1.15.1"
|
||||||
keywords: ["spiffe", "spire-agent"]
|
keywords: ["spiffe", "spire-agent"]
|
||||||
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
|
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
|
||||||
sources:
|
sources:
|
||||||
|
|||||||
@@ -25,134 +25,148 @@ A Helm chart to install the SPIRE agent.
|
|||||||
|
|
||||||
### Chart parameters
|
### Chart parameters
|
||||||
|
|
||||||
| Name | Description | Value |
|
| Name | Description | Value |
|
||||||
| ------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- |
|
| ------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- |
|
||||||
| `image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
| `image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
||||||
| `image.repository` | The repository within the registry | `spiffe/spire-agent` |
|
| `image.repository` | The repository within the registry | `spiffe/spire-agent` |
|
||||||
| `image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
| `image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
|
| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
|
||||||
| `imagePullSecrets` | Pull secrets for images | `[]` |
|
| `imagePullSecrets` | Pull secrets for images | `[]` |
|
||||||
| `nameOverride` | Name override | `""` |
|
| `nameOverride` | Name override | `""` |
|
||||||
| `namespaceOverride` | Namespace override | `""` |
|
| `namespaceOverride` | Namespace override | `""` |
|
||||||
| `fullnameOverride` | Fullname override | `""` |
|
| `fullnameOverride` | Fullname override | `""` |
|
||||||
| `serviceAccount.create` | Specifies whether a service account should be created | `true` |
|
| `serviceAccount.create` | Specifies whether a service account should be created | `true` |
|
||||||
| `serviceAccount.annotations` | Annotations to add to the service account | `{}` |
|
| `serviceAccount.annotations` | Annotations to add to the service account | `{}` |
|
||||||
| `serviceAccount.name` | The name of the service account to use. | `""` |
|
| `serviceAccount.name` | The name of the service account to use. | `""` |
|
||||||
| `configMap.annotations` | Annotations to add to the SPIRE Agent ConfigMap | `{}` |
|
| `configMap.annotations` | Annotations to add to the SPIRE Agent ConfigMap | `{}` |
|
||||||
| `podAnnotations` | Annotations to add to pods | `{}` |
|
| `podAnnotations` | Annotations to add to pods | `{}` |
|
||||||
| `podLabels` | Labels to add to pods | `{}` |
|
| `podLabels` | Labels to add to pods | `{}` |
|
||||||
| `podSecurityContext` | Pod security context | `{}` |
|
| `podSecurityContext` | Pod security context | `{}` |
|
||||||
| `securityContext` | Security context | `{}` |
|
| `securityContext` | Security context | `{}` |
|
||||||
| `resources` | Resource requests and limits for the spire-agent container and all its initContainers | `{}` |
|
| `resources` | Resource requests and limits for the spire-agent container and all its initContainers | `{}` |
|
||||||
| `nodeSelector` | Node selector | `{}` |
|
| `nodeSelector` | Node selector | `{}` |
|
||||||
| `tolerations` | List of tolerations | `[]` |
|
| `tolerations` | List of tolerations | `[]` |
|
||||||
| `affinity` | Node affinity | `{}` |
|
| `affinity` | Node affinity | `{}` |
|
||||||
| `authorizedDelegates` | A list of the authorized delegates SPIFFE IDs. See Delegated Identity API for more information. | `[]` |
|
| `authorizedDelegates` | A list of the authorized delegates SPIFFE IDs. See Delegated Identity API for more information. | `[]` |
|
||||||
| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `info` |
|
| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `info` |
|
||||||
| `logFormat` | The log format, valid values are "text" and "json" | `text` |
|
| `logFormat` | The log format, valid values are "text" and "json" | `text` |
|
||||||
| `clusterName` | The name of the Kubernetes cluster (`kubeadm init --service-dns-domain`) | `example-cluster` |
|
| `clusterName` | The name of the Kubernetes cluster (`kubeadm init --service-dns-domain`) | `example-cluster` |
|
||||||
| `trustDomain` | The trust domain to be used for the SPIFFE identifiers | `example.org` |
|
| `trustDomain` | The trust domain to be used for the SPIFFE identifiers | `example.org` |
|
||||||
| `trustBundleURL` | If set, obtain trust bundle from url instead of Kubernetes ConfigMap | `""` |
|
| `trustBundleURL` | If set, obtain trust bundle from url instead of Kubernetes ConfigMap | `""` |
|
||||||
| `trustBundleFormat` | If using trustBundleURL, what format is the url. Choices are "pem" and "spiffe" | `spiffe` |
|
| `trustBundleFormat` | If using trustBundleURL, what format is the url. Choices are "pem" and "spiffe" | `spiffe` |
|
||||||
| `trustBundleHostPath` | If set, obtain trust bundle from a file on the host instead of from the ConfigMap | `""` |
|
| `trustBundleHostPath` | If set, obtain trust bundle from a file on the host instead of from the ConfigMap | `""` |
|
||||||
| `bundleConfigMap` | Configmap name for Spire bundle | `spire-bundle` |
|
| `bundleConfigMap` | Configmap name for Spire bundle | `spire-bundle` |
|
||||||
| `availabilityTarget` | The minimum amount of time desired to gracefully handle SPIRE Server or Agent downtime. This configurable influences how aggressively X509 SVIDs should be rotated. If set, must be at least 24h. | `""` |
|
| `availabilityTarget` | The minimum amount of time desired to gracefully handle SPIRE Server or Agent downtime. This configurable influences how aggressively X509 SVIDs should be rotated. If set, must be at least 24h. | `""` |
|
||||||
| `rebootstrapMode` | How the agent will behave when seeing an unknown x509 cert from the server. It can be set to never, auto, or always | `always` |
|
| `rebootstrapMode` | How the agent will behave when seeing an unknown x509 cert from the server. It can be set to never, auto, or always | `always` |
|
||||||
| `rebootstrapDelay` | The agent will rebootstrap after configured amount of time on unknown x509 cert from the server | `10m` |
|
| `rebootstrapDelay` | The agent will rebootstrap after configured amount of time on unknown x509 cert from the server | `10m` |
|
||||||
| `server.address` | Address for Spire server | `""` |
|
| `server.address` | Address for Spire server | `""` |
|
||||||
| `server.port` | Port number for Spire server | `443` |
|
| `server.port` | Port number for Spire server | `443` |
|
||||||
| `server.namespaceOverride` | Override the namespace for Spire server | `""` |
|
| `server.namespaceOverride` | Override the namespace for Spire server | `""` |
|
||||||
| `server.nameOverride` | Override the name for Spire server. Should only be changed when building your own nested chart to ensure names align. | `""` |
|
| `server.nameOverride` | Override the name for Spire server. Should only be changed when building your own nested chart to ensure names align. | `""` |
|
||||||
| `healthChecks.port` | override the host port used for health checking | `9982` |
|
| `healthChecks.port` | override the host port used for health checking | `9982` |
|
||||||
| `updateStrategy.type` | The update strategy to use to replace existing DaemonSet pods with new pods. Can be RollingUpdate or OnDelete. | `RollingUpdate` |
|
| `updateStrategy.type` | The update strategy to use to replace existing DaemonSet pods with new pods. Can be RollingUpdate or OnDelete. | `RollingUpdate` |
|
||||||
| `updateStrategy.rollingUpdate.maxUnavailable` | Max unavailable pods during update. Can be a number or a percentage. | `1` |
|
| `updateStrategy.rollingUpdate.maxUnavailable` | Max unavailable pods during update. Can be a number or a percentage. | `1` |
|
||||||
| `livenessProbe.initialDelaySeconds` | Initial delay seconds for probe | `15` |
|
| `livenessProbe.initialDelaySeconds` | Initial delay seconds for probe | `15` |
|
||||||
| `livenessProbe.periodSeconds` | Period seconds for probe | `60` |
|
| `livenessProbe.periodSeconds` | Period seconds for probe | `60` |
|
||||||
| `readinessProbe.initialDelaySeconds` | Initial delay seconds for probe | `10` |
|
| `readinessProbe.initialDelaySeconds` | Initial delay seconds for probe | `10` |
|
||||||
| `readinessProbe.periodSeconds` | Period seconds for probe | `30` |
|
| `readinessProbe.periodSeconds` | Period seconds for probe | `30` |
|
||||||
| `fsGroupFix.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
|
| `fsGroupFix.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
|
||||||
| `fsGroupFix.image.repository` | The repository within the registry | `chainguard/bash` |
|
| `fsGroupFix.image.repository` | The repository within the registry | `chainguard/bash` |
|
||||||
| `fsGroupFix.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
| `fsGroupFix.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:90041f375e30f41aa7e0390075d8a69dc61900771d52fa98d63ee5d03d866a58` |
|
| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:90041f375e30f41aa7e0390075d8a69dc61900771d52fa98d63ee5d03d866a58` |
|
||||||
| `keyManager.memory.enabled` | Enable the memory based Key Manager | `true` |
|
| `keyManager.memory.enabled` | Enable the memory based Key Manager | `true` |
|
||||||
| `keyManager.disk.enabled` | Enable the disk based Key Manager (must have persistence.type set to hostPath when enabled) | `false` |
|
| `keyManager.disk.enabled` | Enable the disk based Key Manager (must have persistence.type set to hostPath when enabled) | `false` |
|
||||||
| `nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s Node Attestor | `true` |
|
| `keyManager.disk.mode` | Where to store the data. Supported options are hostPath and emptyDir | `hostPath` |
|
||||||
| `nodeAttestor.httpChallenge.enabled` | Enable the http challenge Node Attestor | `false` |
|
| `nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s Node Attestor | `true` |
|
||||||
| `nodeAttestor.httpChallenge.agentname` | Name of this agent. Useful if you have multiple agents bound to different spire servers on the same host and sharing the same port. | `default` |
|
| `nodeAttestor.httpChallenge.enabled` | Enable the http challenge Node Attestor | `false` |
|
||||||
| `nodeAttestor.httpChallenge.port` | The port to listen on. If 0, a random value will be used. | `0` |
|
| `nodeAttestor.httpChallenge.agentname` | Name of this agent. Useful if you have multiple agents bound to different spire servers on the same host and sharing the same port. | `default` |
|
||||||
| `nodeAttestor.httpChallenge.advertisedPort` | The port to tell the server to call back on. Set only if your using an http proxy on the hosts. If 0, will use the port setting. | `0` |
|
| `nodeAttestor.httpChallenge.port` | The port to listen on. If 0, a random value will be used. | `0` |
|
||||||
| `nodeAttestor.tpmDirect.enabled` | Enable the direct TPM node attestor, a 3rd party plugin by Boxboat. This plugin is experimental. | `false` |
|
| `nodeAttestor.httpChallenge.advertisedPort` | The port to tell the server to call back on. Set only if your using an http proxy on the hosts. If 0, will use the port setting. | `0` |
|
||||||
| `nodeAttestor.tpmDirect.plugin.image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
| `nodeAttestor.tpmDirect.enabled` | Enable the direct TPM node attestor, a 3rd party plugin by Boxboat. This plugin is experimental. | `false` |
|
||||||
| `nodeAttestor.tpmDirect.plugin.image.repository` | The repository within the registry | `spiffe/spire-tpm-plugin-tpm-attestor-agent` |
|
| `nodeAttestor.tpmDirect.plugin.image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
||||||
| `nodeAttestor.tpmDirect.plugin.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
| `nodeAttestor.tpmDirect.plugin.image.repository` | The repository within the registry | `spiffe/spire-tpm-plugin-tpm-attestor-agent` |
|
||||||
| `nodeAttestor.tpmDirect.plugin.image.tag` | Overrides the image tag | `v1.9.0` |
|
| `nodeAttestor.tpmDirect.plugin.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
| `nodeAttestor.tpmDirect.plugin.checksum` | The sha256 checksum of the plugin binary | `22f67063f1699330e70cdedc9b923e517688f5ae71085a26bd9b83b3060ee86e` |
|
| `nodeAttestor.tpmDirect.plugin.image.tag` | Overrides the image tag | `v1.9.0` |
|
||||||
| `nodeAttestor.tpmDirect.plugin.path` | The filename in the container of the plugin | `/app/tpm_attestor_agent` |
|
| `nodeAttestor.tpmDirect.plugin.checksum` | The sha256 checksum of the plugin binary | `22f67063f1699330e70cdedc9b923e517688f5ae71085a26bd9b83b3060ee86e` |
|
||||||
| `nodeAttestor.tpmDirect.pubHash.enabled` | Display pubhash in logs | `true` |
|
| `nodeAttestor.tpmDirect.plugin.path` | The filename in the container of the plugin | `/app/tpm_attestor_agent` |
|
||||||
| `nodeAttestor.tpmDirect.pubHash.image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
| `nodeAttestor.tpmDirect.pubHash.enabled` | Display pubhash in logs | `true` |
|
||||||
| `nodeAttestor.tpmDirect.pubHash.image.repository` | The repository within the registry | `spiffe/spire-tpm-plugin-get-tpm-pubhash` |
|
| `nodeAttestor.tpmDirect.pubHash.image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
||||||
| `nodeAttestor.tpmDirect.pubHash.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
| `nodeAttestor.tpmDirect.pubHash.image.repository` | The repository within the registry | `spiffe/spire-tpm-plugin-get-tpm-pubhash` |
|
||||||
| `nodeAttestor.tpmDirect.pubHash.image.tag` | Overrides the image tag | `v1.9.0` |
|
| `nodeAttestor.tpmDirect.pubHash.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
| `nodeAttestor.awsIID.enabled` | Enable the aws_iid Node Attestor | `false` |
|
| `nodeAttestor.tpmDirect.pubHash.image.tag` | Overrides the image tag | `v1.9.0` |
|
||||||
| `nodeAttestor.gcpIIT.enabled` | Enable the gcp_iit Node Attestor | `false` |
|
| `nodeAttestor.awsIID.enabled` | Enable the aws_iid Node Attestor | `false` |
|
||||||
| `workloadAttestors.unix.enabled` | Enables the Unix workload attestor | `false` |
|
| `nodeAttestor.gcpIIT.enabled` | Enable the gcp_iit Node Attestor | `false` |
|
||||||
| `workloadAttestors.k8s.enabled` | Enables the Kubernetes workload attestor | `true` |
|
| `nodeAttestor.x509POP.enabled` | Enable the x509_pop Node Attestor | `false` |
|
||||||
| `workloadAttestors.k8s.verification.type` | What kind of verification to do against kubelet. auto will first attempt to use hostCert, and then fall back to apiServerCA. Valid options are [auto, hostCert, apiServerCA, skip] | `skip` |
|
| `nodeAttestor.x509POP.mode` | Which mode to use. Currently only spiffe is supported | `spiffe` |
|
||||||
| `workloadAttestors.k8s.verification.hostCert.basePath` | Path where kubelet places its certificates | `/var/lib/kubelet/pki` |
|
| `nodeAttestor.x509POP.spiffeEndpointSocket` | Where the socket is to use for mode spiffe | `/var/run/spiffe/socat/unix/k8s-spire-agent/public/api.sock` |
|
||||||
| `workloadAttestors.k8s.verification.hostCert.fileName` | File name where kubelet places its certificates. If blank, it will be auto detected. | `""` |
|
| `workloadAttestors.unix.enabled` | Enables the Unix workload attestor | `false` |
|
||||||
| `workloadAttestors.k8s.disableContainerSelectors` | Set to true if using holdApplicationUntilProxyStarts in Istio | `false` |
|
| `workloadAttestors.k8s.enabled` | Enables the Kubernetes workload attestor | `true` |
|
||||||
| `workloadAttestors.k8s.useNewContainerLocator` | If true, enables the new container locator algorithm that has support for cgroups v2. Defaults to true | `true` |
|
| `workloadAttestors.k8s.verification.type` | What kind of verification to do against kubelet. auto will first attempt to use hostCert, and then fall back to apiServerCA. Valid options are [auto, hostCert, apiServerCA, skip] | `skip` |
|
||||||
| `workloadAttestors.k8s.verboseContainerLocatorLogs` | If true, enables verbose logging of mountinfo and cgroup information used to locate containers. Defaults to false | `false` |
|
| `workloadAttestors.k8s.verification.hostCert.basePath` | Path where kubelet places its certificates | `/var/lib/kubelet/pki` |
|
||||||
| `sds.enabled` | Enables Envoy SDS configuration | `false` |
|
| `workloadAttestors.k8s.verification.hostCert.fileName` | File name where kubelet places its certificates. If blank, it will be auto detected. | `""` |
|
||||||
| `sds.defaultSVIDName` | The TLS Certificate resource name to use for the default X509-SVID with Envoy SDS | `default` |
|
| `workloadAttestors.k8s.disableContainerSelectors` | Set to true if using holdApplicationUntilProxyStarts in Istio | `false` |
|
||||||
| `sds.defaultBundleName` | The Validation Context resource name to use for the default X.509 bundle with Envoy SDS | `ROOTCA` |
|
| `workloadAttestors.k8s.useNewContainerLocator` | If true, enables the new container locator algorithm that has support for cgroups v2. Defaults to true | `true` |
|
||||||
| `sds.defaultAllBundlesName` | The Validation Context resource name to use for all bundles (including federated) with Envoy SDS | `ALL` |
|
| `workloadAttestors.k8s.verboseContainerLocatorLogs` | If true, enables verbose logging of mountinfo and cgroup information used to locate containers. Defaults to false | `false` |
|
||||||
| `sds.disableSPIFFECertValidation` | Disable Envoy SDS custom validation | `false` |
|
| `dynamicRegistration.enabled` | Deploys the sidecar helper for dynamic registration | `false` |
|
||||||
| `telemetry.prometheus.enabled` | Flag to enable prometheus monitoring | `false` |
|
| `dynamicRegistration.image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
||||||
| `telemetry.prometheus.port` | Port for prometheus metrics | `9988` |
|
| `dynamicRegistration.image.repository` | The repository within the registry | `spiffe/spire-controller-manager-dynamic-registration/spire-controller-manager-dynamic-registration-agent` |
|
||||||
| `telemetry.prometheus.host` | Host for prometheus metrics | `0.0.0.0` |
|
| `dynamicRegistration.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
| `telemetry.prometheus.podMonitor.enabled` | Enable podMonitor for prometheus | `false` |
|
| `dynamicRegistration.image.tag` | Overrides the image tag to be whatever you need it to be. It will always be the flag you set without modifications | `0.1.0` |
|
||||||
| `telemetry.prometheus.podMonitor.namespace` | Override where to install the podMonitor, if not set will use the same namespace as the spire-agent | `""` |
|
| `dynamicRegistration.audience` | The audience to get the k8s psat for | `spire-controller-manager-dynamic-registration` |
|
||||||
| `telemetry.prometheus.podMonitor.labels` | Pod labels to filter for prometheus monitoring | `{}` |
|
| `dynamicRegistration.serverSPIFFEID` | Expected SPIFFE ID of the server. If blank, it will use a sane default. | `""` |
|
||||||
| `telemetry.datadog.enabled` | Flag to enable datadog monitoring | `false` |
|
| `dynamicRegistration.address` | Address for Spire server | `""` |
|
||||||
| `telemetry.datadog.address` | The address of the datadog service to send metrics to. The default URL for services are `<service-name>.<namespace>.svc` | `datadog.kube-system.svc` |
|
| `dynamicRegistration.nameOverride` | Override the name for Spire server. Should only be changed when building your own nested chart to ensure names align. | `""` |
|
||||||
| `telemetry.datadog.port` | The port of the datadog service to send metrics to | `8125` |
|
| `dynamicRegistration.securityContext` | Security context | `{}` |
|
||||||
| `kubeletConnectByHostname` | (DEPRECATED) Use kubeletAddress.mode instead. If true, connect to kubelet using the nodes hostname. If false, uses localhost. If unset, defaults to true on OpenShift and false otherwise. | `""` |
|
| `sds.enabled` | Enables Envoy SDS configuration | `false` |
|
||||||
| `kubeletAddress.mode` | How to connect to kubelet for workload attestation | `auto` |
|
| `sds.defaultSVIDName` | The TLS Certificate resource name to use for the default X509-SVID with Envoy SDS | `default` |
|
||||||
| `hostNetwork` | Enable hostNetwork for the DaemonSet. If auto or empty, auto-disables when kubeletAddress.mode is hostname/hostip. Set true/false to override. | `""` |
|
| `sds.defaultBundleName` | The Validation Context resource name to use for the default X.509 bundle with Envoy SDS | `ROOTCA` |
|
||||||
| `dnsPolicy` | DNS policy for the DaemonSet. If empty, uses ClusterFirstWithHostNet when hostNetwork is enabled. See https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-s-dns-policy | `""` |
|
| `sds.defaultAllBundlesName` | The Validation Context resource name to use for all bundles (including federated) with Envoy SDS | `ALL` |
|
||||||
| `socketPath` | The unix socket path to the spire-agent | `/run/spire/agent-sockets/spire-agent.sock` |
|
| `sds.disableSPIFFECertValidation` | Disable Envoy SDS custom validation | `false` |
|
||||||
| `socketAlternate.names` | List of alternate names for the socket that workloads might expect to be able to access in the driver mount. | `["socket","spire-agent.sock","api.sock"]` |
|
| `telemetry.prometheus.enabled` | Flag to enable prometheus monitoring | `false` |
|
||||||
| `socketAlternate.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
|
| `telemetry.prometheus.port` | Port for prometheus metrics | `9988` |
|
||||||
| `socketAlternate.image.repository` | The repository within the registry | `chainguard/bash` |
|
| `telemetry.prometheus.host` | Host for prometheus metrics | `0.0.0.0` |
|
||||||
| `socketAlternate.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
| `telemetry.prometheus.podMonitor.enabled` | Enable podMonitor for prometheus | `false` |
|
||||||
| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:90041f375e30f41aa7e0390075d8a69dc61900771d52fa98d63ee5d03d866a58` |
|
| `telemetry.prometheus.podMonitor.namespace` | Override where to install the podMonitor, if not set will use the same namespace as the spire-agent | `""` |
|
||||||
| `hostCert.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
|
| `telemetry.prometheus.podMonitor.labels` | Pod labels to filter for prometheus monitoring | `{}` |
|
||||||
| `hostCert.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` |
|
| `telemetry.datadog.enabled` | Flag to enable datadog monitoring | `false` |
|
||||||
| `hostCert.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
| `telemetry.datadog.address` | The address of the datadog service to send metrics to. The default URL for services are `<service-name>.<namespace>.svc` | `datadog.kube-system.svc` |
|
||||||
| `hostCert.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9e45e6836c28489a6e57ca1210ec66927e88eca2409e403616a1278e210e86c9` |
|
| `telemetry.datadog.port` | The port of the datadog service to send metrics to | `8125` |
|
||||||
| `priorityClassName` | Priority class assigned to daemonset pods. Can be auto set with global.recommendations.priorityClassName. | `""` |
|
| `kubeletConnectByHostname` | (DEPRECATED) Use kubeletAddress.mode instead. If true, connect to kubelet using the nodes hostname. If false, uses localhost. If unset, defaults to true on OpenShift and false otherwise. | `""` |
|
||||||
| `extraEnvVars` | Extra environment variables to be added to the Spire Agent container and init containers | `[]` |
|
| `kubeletAddress.mode` | How to connect to kubelet for workload attestation | `auto` |
|
||||||
| `extraVolumes` | Extra volumes to be mounted on Spire Agent pods | `[]` |
|
| `hostNetwork` | Enable hostNetwork for the DaemonSet. If auto or empty, auto-disables when kubeletAddress.mode is hostname/hostip. Set true/false to override. | `""` |
|
||||||
| `extraVolumeMounts` | Extra volume mounts for Spire Agent pods | `[]` |
|
| `dnsPolicy` | DNS policy for the DaemonSet. If empty, uses ClusterFirstWithHostNet when hostNetwork is enabled. See https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-s-dns-policy | `""` |
|
||||||
| `extraContainers` | Additional containers to create with Spire Agent pods | `[]` |
|
| `socketPath` | The unix socket path to the spire-agent | `/run/spire/agent-sockets/spire-agent.sock` |
|
||||||
| `initContainers` | Additional init containers to create with Spire Agent pods | `[]` |
|
| `socketAlternate.names` | List of alternate names for the socket that workloads might expect to be able to access in the driver mount. | `["socket","spire-agent.sock","api.sock"]` |
|
||||||
| `hostAliases` | Customize /etc/hosts file as described here https://kubernetes.io/docs/tasks/network/customize-hosts-file-for-pods/ | `[]` |
|
| `socketAlternate.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
|
||||||
| `customPlugins.keyManager` | Custom plugins of type KeyManager are configured here | `{}` |
|
| `socketAlternate.image.repository` | The repository within the registry | `chainguard/bash` |
|
||||||
| `customPlugins.nodeAttestor` | Custom plugins of type NodeAttestor are configured here | `{}` |
|
| `socketAlternate.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
| `customPlugins.svidStore` | Custom plugins of type SVIDStore are configured here | `{}` |
|
| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:90041f375e30f41aa7e0390075d8a69dc61900771d52fa98d63ee5d03d866a58` |
|
||||||
| `customPlugins.workloadAttestor` | Custom plugins of type WorkloadAttestor are configured here | `{}` |
|
| `hostCert.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
|
||||||
| `experimental.enabled` | Allow configuration of experimental features | `false` |
|
| `hostCert.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` |
|
||||||
| `experimental.syncInterval` | Sync interval with SPIRE server with exponential backoff | `5s` |
|
| `hostCert.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
| `experimental.requirePQKEM` | Require use of a post-quantum-safe key exchange method for TLS handshakes. | `false` |
|
| `hostCert.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9e45e6836c28489a6e57ca1210ec66927e88eca2409e403616a1278e210e86c9` |
|
||||||
| `experimental.featureFlags` | List of developer feature flags | `[]` |
|
| `priorityClassName` | Priority class assigned to daemonset pods. Can be auto set with global.recommendations.priorityClassName. | `""` |
|
||||||
| `agents` | Configure multiple agent DaemonSets. Useful when you have different node types and nodeAttestors | `{}` |
|
| `extraEnvVars` | Extra environment variables to be added to the Spire Agent container and init containers | `[]` |
|
||||||
| `tools.kubectl.image.registry` | The OCI registry to pull the image from | `registry.k8s.io` |
|
| `extraVolumes` | Extra volumes to be mounted on Spire Agent pods | `[]` |
|
||||||
| `tools.kubectl.image.repository` | The repository within the registry | `kubectl` |
|
| `extraVolumeMounts` | Extra volume mounts for Spire Agent pods | `[]` |
|
||||||
| `tools.kubectl.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
| `extraContainers` | Additional containers to create with Spire Agent pods | `[]` |
|
||||||
| `tools.kubectl.image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
|
| `initContainers` | Additional init containers to create with Spire Agent pods | `[]` |
|
||||||
| `sockets.hostBasePath` | Path on which the agent socket is made available when admin.mountOnHost is true | `/run/spire/agent/sockets` |
|
| `hostAliases` | Customize /etc/hosts file as described here https://kubernetes.io/docs/tasks/network/customize-hosts-file-for-pods/ | `[]` |
|
||||||
| `sockets.admin.enabled` | Enable the admin socket. Useful for admin tasks or the Delegated Identity API. | `false` |
|
| `customPlugins.keyManager` | Custom plugins of type KeyManager are configured here | `{}` |
|
||||||
| `sockets.admin.mountOnHost` | Enable the admin socket to be visible on the host. | `false` |
|
| `customPlugins.nodeAttestor` | Custom plugins of type NodeAttestor are configured here | `{}` |
|
||||||
| `persistence.type` | What type of volume to use for persistence. Valid options emptyDir (reattestable node attestors) or hostPath (nonr-reattestable node attestors) | `emptyDir` |
|
| `customPlugins.svidStore` | Custom plugins of type SVIDStore are configured here | `{}` |
|
||||||
| `persistence.hostPath` | Which path to use on the host when persistence.type = hostPath | `/var/lib/spire/k8s/agent` |
|
| `customPlugins.workloadAttestor` | Custom plugins of type WorkloadAttestor are configured here | `{}` |
|
||||||
|
| `experimental.enabled` | Allow configuration of experimental features | `false` |
|
||||||
|
| `experimental.syncInterval` | Sync interval with SPIRE server with exponential backoff | `5s` |
|
||||||
|
| `experimental.requirePQKEM` | Require use of a post-quantum-safe key exchange method for TLS handshakes. | `false` |
|
||||||
|
| `experimental.featureFlags` | List of developer feature flags | `[]` |
|
||||||
|
| `agents` | Configure multiple agent DaemonSets. Useful when you have different node types and nodeAttestors | `{}` |
|
||||||
|
| `tools.kubectl.image.registry` | The OCI registry to pull the image from | `registry.k8s.io` |
|
||||||
|
| `tools.kubectl.image.repository` | The repository within the registry | `kubectl` |
|
||||||
|
| `tools.kubectl.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
|
| `tools.kubectl.image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
|
||||||
|
| `sockets.hostBasePath` | Path on which the agent socket is made available when admin.mountOnHost is true | `/run/spire/agent/sockets` |
|
||||||
|
| `sockets.admin.enabled` | Enable the admin socket. Useful for admin tasks or the Delegated Identity API. | `false` |
|
||||||
|
| `sockets.admin.mountOnHost` | Enable the admin socket to be visible on the host. | `false` |
|
||||||
|
| `persistence.type` | What type of volume to use for persistence. Valid options emptyDir (reattestable node attestors) or hostPath (nonr-reattestable node attestors) | `emptyDir` |
|
||||||
|
| `persistence.hostPath` | Which path to use on the host when persistence.type = hostPath | `/var/lib/spire/k8s/agent` |
|
||||||
|
|||||||
@@ -110,6 +110,18 @@ Create the name of the service account to use
|
|||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|
||||||
|
{{- define "spire-agent.dynamic-registration-address" }}
|
||||||
|
{{- if and (ne (len (dig "spire" "upstreamDynamicRegistrationAddress" "" .Values.global)) 0) .Values.upstream }}
|
||||||
|
{{- print .Values.global.spire.upstreamDynamicRegistrationAddress }}
|
||||||
|
{{- else if .Values.dynamicRegistration.address }}
|
||||||
|
{{- .Values.dynamicRegistration.address }}
|
||||||
|
{{- else if .Values.dynamicRegistration.nameOverride }}
|
||||||
|
{{- .Release.Name }}-{{ .Values.dynamicRegistration.nameOverride }}.{{ include "spire-agent.server.namespace" . }}
|
||||||
|
{{- else }}
|
||||||
|
{{- .Release.Name }}-server.{{ include "spire-agent.server.namespace" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
{{- define "spire-agent.socket-path" -}}
|
{{- define "spire-agent.socket-path" -}}
|
||||||
{{- print .Values.socketPath }}
|
{{- print .Values.socketPath }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
{{- define "spire-agent.check-config-values" -}}
|
{{- define "spire-agent.check-config-values" -}}
|
||||||
{{- include "spire-lib.check-strict-mode" (list . "clusterName must be set" (eq (include "spire-lib.cluster-name" .) "example-cluster"))}}
|
{{- include "spire-lib.check-strict-mode" (list . "clusterName must be set" (eq (include "spire-lib.cluster-name" .) "example-cluster"))}}
|
||||||
{{- include "spire-lib.check-strict-mode" (list . "trustDomain must be set" (eq (include "spire-lib.trust-domain" .) "example.org"))}}
|
{{- $trustDomain := include "spire-lib.trust-domain" . }}
|
||||||
|
{{- include "spire-lib.check-strict-mode" (list . "trustDomain must be set" (eq $trustDomain "example.org"))}}
|
||||||
{{- range $type, $tvals := .Values.customPlugins }}
|
{{- range $type, $tvals := .Values.customPlugins }}
|
||||||
{{- if not (has $type (list "keyManager" "nodeAttestor" "svidStore" "workloadAttestor")) }}
|
{{- if not (has $type (list "keyManager" "nodeAttestor" "svidStore" "workloadAttestor")) }}
|
||||||
{{- fail (printf "Unknown plugin type specified: %s" $type) }}
|
{{- fail (printf "Unknown plugin type specified: %s" $type) }}
|
||||||
@@ -19,7 +20,7 @@
|
|||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if and .Values.keyManager.disk.enabled (ne .Values.persistence.type "hostPath") }}
|
{{- if and .Values.keyManager.disk.enabled (ne .Values.persistence.type "hostPath") (eq .Values.keyManager.disk.mode "hostPath") }}
|
||||||
{{- fail "keyManager.disk.enabled is true but persistence.type is not hostPath. Ensure persistence.type is hostPath when keyManager.disk.enabled is true." }}
|
{{- fail "keyManager.disk.enabled is true but persistence.type is not hostPath. Ensure persistence.type is hostPath when keyManager.disk.enabled is true." }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if hasPrefix (.Values.socketPath | dir | clean) (.Values.sockets.hostBasePath | clean) }}
|
{{- if hasPrefix (.Values.socketPath | dir | clean) (.Values.sockets.hostBasePath | clean) }}
|
||||||
@@ -37,13 +38,20 @@
|
|||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- define "spire-agent.yaml-config" -}}
|
{{- define "spire-agent.yaml-config" -}}
|
||||||
|
{{- $trustDomain := include "spire-lib.trust-domain" . }}
|
||||||
agent:
|
agent:
|
||||||
{{- if .Values.sockets.admin.enabled }}
|
{{- if .Values.sockets.admin.enabled }}
|
||||||
admin_socket_path: /tmp/spire-agent/private/admin.sock
|
admin_socket_path: /tmp/spire-agent/private/admin.sock
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- with .Values.authorizedDelegates }}
|
{{- with .Values.authorizedDelegates }}
|
||||||
authorized_delegates:
|
authorized_delegates:
|
||||||
{{- toYaml . | nindent 4 }}
|
{{- range . }}
|
||||||
|
{{- if hasPrefix "/" . }}
|
||||||
|
- spiffe://{{ $trustDomain }}{{ . }}
|
||||||
|
{{- else }}
|
||||||
|
- {{ . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
data_dir: "/var/lib/spire"
|
data_dir: "/var/lib/spire"
|
||||||
log_level: {{ .Values.logLevel | quote }}
|
log_level: {{ .Values.logLevel | quote }}
|
||||||
@@ -120,6 +128,14 @@ plugins:
|
|||||||
{{- $nodeAttestorUsed = add1 $nodeAttestorUsed }}
|
{{- $nodeAttestorUsed = add1 $nodeAttestorUsed }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
{{- with .Values.nodeAttestor.x509POP }}
|
||||||
|
{{- if eq (.enabled | toString) "true" }}
|
||||||
|
x509pop:
|
||||||
|
plugin_data:
|
||||||
|
spiffe_endpoint_socket: unix://{{ .spiffeEndpointSocket }}
|
||||||
|
{{- $nodeAttestorUsed = add1 $nodeAttestorUsed }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
{{- with .Values.nodeAttestor.awsIID }}
|
{{- with .Values.nodeAttestor.awsIID }}
|
||||||
{{- if eq (.enabled | toString) "true" }}
|
{{- if eq (.enabled | toString) "true" }}
|
||||||
aws_iid:
|
aws_iid:
|
||||||
@@ -147,7 +163,11 @@ plugins:
|
|||||||
{{- if .Values.keyManager.disk.enabled }}
|
{{- if .Values.keyManager.disk.enabled }}
|
||||||
disk:
|
disk:
|
||||||
plugin_data:
|
plugin_data:
|
||||||
|
{{- if eq .Values.keyManager.disk.mode "hostPath" }}
|
||||||
directory: {{ .Values.persistence.hostPath }}
|
directory: {{ .Values.persistence.hostPath }}
|
||||||
|
{{- else if eq .Values.keyManager.disk.mode "emptyDir" }}
|
||||||
|
directory: /key-manager
|
||||||
|
{{- end }}
|
||||||
{{- $keyManagerUsed = add1 $keyManagerUsed }}
|
{{- $keyManagerUsed = add1 $keyManagerUsed }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if ne $keyManagerUsed 1 }}
|
{{- if ne $keyManagerUsed 1 }}
|
||||||
|
|||||||
@@ -9,7 +9,7 @@
|
|||||||
{{- if hasKey .Values.sds "disableSpiffeCertValidation" }}
|
{{- if hasKey .Values.sds "disableSpiffeCertValidation" }}
|
||||||
{{- fail "disableSpiffeCertValidation was renamed to disableSPIFFECertValidation. Please update your config." }}
|
{{- fail "disableSpiffeCertValidation was renamed to disableSPIFFECertValidation. Please update your config." }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if and .Values.keyManager.disk.enabled (ne .Values.persistence.type "hostPath") }}
|
{{- if and .Values.keyManager.disk.enabled (ne .Values.persistence.type "hostPath") (eq .Values.keyManager.disk.mode "hostPath") }}
|
||||||
{{- fail "keyManager.disk.enabled is true but persistence.type is not hostPath. Ensure persistence.type is hostPath when keyManager.disk.enabled is true." }}
|
{{- fail "keyManager.disk.enabled is true but persistence.type is not hostPath. Ensure persistence.type is hostPath when keyManager.disk.enabled is true." }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- range $name := (concat (list "default") (keys .Values.agents)) | uniq }}
|
{{- range $name := (concat (list "default") (keys .Values.agents)) | uniq }}
|
||||||
@@ -303,7 +303,11 @@ spec:
|
|||||||
readOnly: true
|
readOnly: true
|
||||||
{{- if .Values.keyManager.disk.enabled }}
|
{{- if .Values.keyManager.disk.enabled }}
|
||||||
- name: spire-key-manager
|
- name: spire-key-manager
|
||||||
|
{{- if eq .Values.keyManager.disk.mode "emptyDir" }}
|
||||||
|
mountPath: /key-manager
|
||||||
|
{{- else }}
|
||||||
mountPath: {{ .Values.persistence.hostPath }}
|
mountPath: {{ .Values.persistence.hostPath }}
|
||||||
|
{{- end }}
|
||||||
readOnly: false
|
readOnly: false
|
||||||
{{- end }}
|
{{- end }}
|
||||||
- name: spire-agent-persistence
|
- name: spire-agent-persistence
|
||||||
@@ -340,6 +344,10 @@ spec:
|
|||||||
mountPath: /hostCert
|
mountPath: /hostCert
|
||||||
readOnly: true
|
readOnly: true
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
{{- if .Values.nodeAttestor.x509POP.enabled }}
|
||||||
|
- name: x509pop-upstream
|
||||||
|
mountPath: {{ .Values.nodeAttestor.x509POP.spiffeEndpointSocket | dir }}
|
||||||
|
{{- end }}
|
||||||
{{- if gt (len .Values.extraVolumeMounts) 0 }}
|
{{- if gt (len .Values.extraVolumeMounts) 0 }}
|
||||||
{{- toYaml .Values.extraVolumeMounts | nindent 12 }}
|
{{- toYaml .Values.extraVolumeMounts | nindent 12 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
@@ -355,6 +363,33 @@ spec:
|
|||||||
{{- toYaml .Values.readinessProbe | nindent 12 }}
|
{{- toYaml .Values.readinessProbe | nindent 12 }}
|
||||||
resources:
|
resources:
|
||||||
{{- toYaml .Values.resources | nindent 12 }}
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
|
{{- if eq (.Values.dynamicRegistration.enabled | toString) "true" }}
|
||||||
|
- name: dynamic-registration
|
||||||
|
securityContext:
|
||||||
|
{{- include "spire-lib.securitycontext-extended" (dict "root" . "securityContext" .Values.dynamicRegistration.securityContext) | nindent 12 }}
|
||||||
|
image: {{ template "spire-lib.image" (dict "appVersion" .Values.dynamicRegistration.image.tag "image" .Values.dynamicRegistration.image "global" .Values.global "ubi" false) }}
|
||||||
|
imagePullPolicy: {{ .Values.dynamicRegistration.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
- name: TOKENFILE
|
||||||
|
value: /var/run/secrets/tokens/dynamic-registration-agent
|
||||||
|
- name: SPIFFE_TRUST_DOMAIN
|
||||||
|
value: {{ include "spire-lib.trust-domain" . | quote }}
|
||||||
|
- name: SERVERSPIFFEID
|
||||||
|
value: {{ .Values.dynamicRegistration.serverSPIFFEID | quote }}
|
||||||
|
- name: APIURL
|
||||||
|
value: {{ include "spire-agent.dynamic-registration-address" . | quote }}
|
||||||
|
- name: KEYFILE
|
||||||
|
value: /key-manager/keys.json
|
||||||
|
- name: APIPORT
|
||||||
|
value: "8931"
|
||||||
|
volumeMounts:
|
||||||
|
- name: spire-agent-persistence
|
||||||
|
mountPath: /var/lib/spire
|
||||||
|
- name: dynamic-registration-psat
|
||||||
|
mountPath: /var/run/secrets/tokens
|
||||||
|
- name: spire-key-manager
|
||||||
|
mountPath: /key-manager
|
||||||
|
{{- end }}
|
||||||
{{- if gt (len .Values.extraContainers) 0 }}
|
{{- if gt (len .Values.extraContainers) 0 }}
|
||||||
{{- toYaml .Values.extraContainers | nindent 8 }}
|
{{- toYaml .Values.extraContainers | nindent 8 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
@@ -376,9 +411,13 @@ spec:
|
|||||||
name: {{ include "spire-agent.fullname" . }}
|
name: {{ include "spire-agent.fullname" . }}
|
||||||
{{- if .Values.keyManager.disk.enabled }}
|
{{- if .Values.keyManager.disk.enabled }}
|
||||||
- name: spire-key-manager
|
- name: spire-key-manager
|
||||||
|
{{- if eq .Values.keyManager.disk.mode "hostPath" }}
|
||||||
hostPath:
|
hostPath:
|
||||||
path: {{ .Values.persistence.hostPath }}
|
path: {{ .Values.persistence.hostPath }}
|
||||||
type: DirectoryOrCreate
|
type: DirectoryOrCreate
|
||||||
|
{{- else }}
|
||||||
|
emptyDir: {}
|
||||||
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if .Values.sockets.admin.mountOnHost }}
|
{{- if .Values.sockets.admin.mountOnHost }}
|
||||||
- name: spire-agent-admin-socket-dir
|
- name: spire-agent-admin-socket-dir
|
||||||
@@ -420,6 +459,21 @@ spec:
|
|||||||
- name: tpm-direct
|
- name: tpm-direct
|
||||||
emptyDir: {}
|
emptyDir: {}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
{{- if .Values.nodeAttestor.x509POP.enabled }}
|
||||||
|
- name: x509pop-upstream
|
||||||
|
hostPath:
|
||||||
|
path: {{ .Values.nodeAttestor.x509POP.spiffeEndpointSocket | dir }}
|
||||||
|
type: DirectoryOrCreate
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq (.Values.dynamicRegistration.enabled | toString) "true" }}
|
||||||
|
- name: dynamic-registration-psat
|
||||||
|
projected:
|
||||||
|
sources:
|
||||||
|
- serviceAccountToken:
|
||||||
|
path: dynamic-registration-agent
|
||||||
|
expirationSeconds: 7200
|
||||||
|
audience: {{ .Values.dynamicRegistration.audience | quote }}
|
||||||
|
{{- end }}
|
||||||
- name: spire-token
|
- name: spire-token
|
||||||
projected:
|
projected:
|
||||||
sources:
|
sources:
|
||||||
|
|||||||
@@ -168,6 +168,8 @@ keyManager:
|
|||||||
disk:
|
disk:
|
||||||
## @param keyManager.disk.enabled Enable the disk based Key Manager (must have persistence.type set to hostPath when enabled)
|
## @param keyManager.disk.enabled Enable the disk based Key Manager (must have persistence.type set to hostPath when enabled)
|
||||||
enabled: false
|
enabled: false
|
||||||
|
## @param keyManager.disk.mode Where to store the data. Supported options are hostPath and emptyDir
|
||||||
|
mode: hostPath
|
||||||
|
|
||||||
nodeAttestor:
|
nodeAttestor:
|
||||||
k8sPSAT:
|
k8sPSAT:
|
||||||
@@ -219,6 +221,13 @@ nodeAttestor:
|
|||||||
gcpIIT:
|
gcpIIT:
|
||||||
## @param nodeAttestor.gcpIIT.enabled Enable the gcp_iit Node Attestor
|
## @param nodeAttestor.gcpIIT.enabled Enable the gcp_iit Node Attestor
|
||||||
enabled: false
|
enabled: false
|
||||||
|
x509POP:
|
||||||
|
## @param nodeAttestor.x509POP.enabled Enable the x509_pop Node Attestor
|
||||||
|
enabled: false
|
||||||
|
## @param nodeAttestor.x509POP.mode Which mode to use. Currently only spiffe is supported
|
||||||
|
mode: spiffe
|
||||||
|
## @param nodeAttestor.x509POP.spiffeEndpointSocket Where the socket is to use for mode spiffe
|
||||||
|
spiffeEndpointSocket: "/var/run/spiffe/socat/unix/k8s-spire-agent/public/api.sock"
|
||||||
|
|
||||||
# workloadAttestors determine a workload's properties and then generate a set of selectors associated with it.
|
# workloadAttestors determine a workload's properties and then generate a set of selectors associated with it.
|
||||||
workloadAttestors:
|
workloadAttestors:
|
||||||
@@ -244,6 +253,34 @@ workloadAttestors:
|
|||||||
## @param workloadAttestors.k8s.verboseContainerLocatorLogs If true, enables verbose logging of mountinfo and cgroup information used to locate containers. Defaults to false
|
## @param workloadAttestors.k8s.verboseContainerLocatorLogs If true, enables verbose logging of mountinfo and cgroup information used to locate containers. Defaults to false
|
||||||
verboseContainerLocatorLogs: false
|
verboseContainerLocatorLogs: false
|
||||||
|
|
||||||
|
dynamicRegistration:
|
||||||
|
## @param dynamicRegistration.enabled Deploys the sidecar helper for dynamic registration
|
||||||
|
enabled: false
|
||||||
|
## @param dynamicRegistration.image.registry The OCI registry to pull the image from
|
||||||
|
## @param dynamicRegistration.image.repository The repository within the registry
|
||||||
|
## @param dynamicRegistration.image.pullPolicy The image pull policy
|
||||||
|
## @param dynamicRegistration.image.tag Overrides the image tag to be whatever you need it to be. It will always be the flag you set without modifications
|
||||||
|
##
|
||||||
|
image:
|
||||||
|
registry: ghcr.io
|
||||||
|
repository: spiffe/spire-controller-manager-dynamic-registration/spire-controller-manager-dynamic-registration-agent
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
tag: "0.1.0"
|
||||||
|
|
||||||
|
## @param dynamicRegistration.audience The audience to get the k8s psat for
|
||||||
|
audience: spire-controller-manager-dynamic-registration
|
||||||
|
|
||||||
|
## @param dynamicRegistration.serverSPIFFEID Expected SPIFFE ID of the server. If blank, it will use a sane default.
|
||||||
|
serverSPIFFEID: ""
|
||||||
|
|
||||||
|
## @param dynamicRegistration.address Address for Spire server
|
||||||
|
address: ""
|
||||||
|
## @param dynamicRegistration.nameOverride Override the name for Spire server. Should only be changed when building your own nested chart to ensure names align.
|
||||||
|
nameOverride: ""
|
||||||
|
|
||||||
|
## @param dynamicRegistration.securityContext [object] Security context
|
||||||
|
securityContext: {}
|
||||||
|
|
||||||
sds:
|
sds:
|
||||||
## @param sds.enabled Enables Envoy SDS configuration
|
## @param sds.enabled Enables Envoy SDS configuration
|
||||||
enabled: false
|
enabled: false
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ name: spire-server
|
|||||||
description: A Helm chart to install the SPIRE server.
|
description: A Helm chart to install the SPIRE server.
|
||||||
type: application
|
type: application
|
||||||
version: 0.1.0
|
version: 0.1.0
|
||||||
appVersion: "1.14.5"
|
appVersion: "1.15.1"
|
||||||
keywords: ["spiffe", "spire-server", "spire-controller-manager"]
|
keywords: ["spiffe", "spire-server", "spire-controller-manager"]
|
||||||
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
|
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
|
||||||
sources:
|
sources:
|
||||||
|
|||||||
@@ -79,400 +79,425 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr
|
|||||||
|
|
||||||
### Chart parameters
|
### Chart parameters
|
||||||
|
|
||||||
| Name | Description | Value |
|
| Name | Description | Value |
|
||||||
| -------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- |
|
| -------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
|
||||||
| `replicaCount` | SPIRE server currently runs with a sqlite database. Scaling to multiple instances will not work until we use an external database. | `1` |
|
| `replicaCount` | SPIRE server currently runs with a sqlite database. Scaling to multiple instances will not work until we use an external database. | `1` |
|
||||||
| `image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
| `image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
||||||
| `image.repository` | The repository within the registry | `spiffe/spire-server` |
|
| `image.repository` | The repository within the registry | `spiffe/spire-server` |
|
||||||
| `image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
| `image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
|
| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
|
||||||
| `kind` | Define SPIRE server deployment type. Can be statefulset/deployment. Defaults to statefulset if not set. This feature is experimental. | `statefulset` |
|
| `kind` | Define SPIRE server deployment type. Can be statefulset/deployment. Defaults to statefulset if not set. This feature is experimental. | `statefulset` |
|
||||||
| `externalServer` | Deploy only the bundle ConfigMap, RBAC rules, and identity documents but not the server. Use in a nested setup where the server is external. | `false` |
|
| `externalServer` | Deploy only the bundle ConfigMap, RBAC rules, and identity documents but not the server. Use in a nested setup where the server is external. | `false` |
|
||||||
| `imagePullSecrets` | Pull secrets for images | `[]` |
|
| `imagePullSecrets` | Pull secrets for images | `[]` |
|
||||||
| `nameOverride` | Name override | `""` |
|
| `nameOverride` | Name override | `""` |
|
||||||
| `crNameOverride` | Name override for any custom resources | `""` |
|
| `crNameOverride` | Name override for any custom resources | `""` |
|
||||||
| `namespaceOverride` | Namespace override | `""` |
|
| `namespaceOverride` | Namespace override | `""` |
|
||||||
| `fullnameOverride` | Fullname override | `""` |
|
| `fullnameOverride` | Fullname override | `""` |
|
||||||
| `serviceAccount.create` | Specifies whether a service account should be created | `true` |
|
| `serviceAccount.create` | Specifies whether a service account should be created | `true` |
|
||||||
| `serviceAccount.annotations` | Annotations to add to the service account | `{}` |
|
| `serviceAccount.annotations` | Annotations to add to the service account | `{}` |
|
||||||
| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` |
|
| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` |
|
||||||
| `podAnnotations` | Annotations to add to pods | `{}` |
|
| `podAnnotations` | Annotations to add to pods | `{}` |
|
||||||
| `podLabels` | Labels to add to pods | `{}` |
|
| `podLabels` | Labels to add to pods | `{}` |
|
||||||
| `podSecurityContext` | Pod security context | `{}` |
|
| `podSecurityContext` | Pod security context | `{}` |
|
||||||
| `securityContext` | Security context | `{}` |
|
| `securityContext` | Security context | `{}` |
|
||||||
| `priorityClassName` | Priority class assigned to statefulset pods. Can be auto set with global.recommendations.priorityClassName. | `""` |
|
| `priorityClassName` | Priority class assigned to statefulset pods. Can be auto set with global.recommendations.priorityClassName. | `""` |
|
||||||
| `service.type` | Type of the Spire server service created | `ClusterIP` |
|
| `service.type` | Type of the Spire server service created | `ClusterIP` |
|
||||||
| `service.port` | Port for the created service | `443` |
|
| `service.port` | Port for the created service | `443` |
|
||||||
| `service.annotations` | Annotations to add to the service object | `{}` |
|
| `service.annotations` | Annotations to add to the service object | `{}` |
|
||||||
| `service.loadBalancerIP` | IP address to assign to load balancer (if supported) | `""` |
|
| `service.loadBalancerIP` | IP address to assign to load balancer (if supported) | `""` |
|
||||||
| `configMap.annotations` | Annotations to add to the SPIRE Server ConfigMap | `{}` |
|
| `configMap.annotations` | Annotations to add to the SPIRE Server ConfigMap | `{}` |
|
||||||
| `resources` | Resource requests and limits | `{}` |
|
| `resources` | Resource requests and limits | `{}` |
|
||||||
| `autoscaling.enabled` | Flag to enable autoscaling | `false` |
|
| `autoscaling.enabled` | Flag to enable autoscaling | `false` |
|
||||||
| `autoscaling.minReplicas` | Minimum replicas for autoscaling | `1` |
|
| `autoscaling.minReplicas` | Minimum replicas for autoscaling | `1` |
|
||||||
| `autoscaling.maxReplicas` | Maximum replicas for autoscaling | `100` |
|
| `autoscaling.maxReplicas` | Maximum replicas for autoscaling | `100` |
|
||||||
| `autoscaling.scaleOnSPIREServerOnly` | Flag to only consider the main SPIRE container for autoscaling purposes | `false` |
|
| `autoscaling.scaleOnSPIREServerOnly` | Flag to only consider the main SPIRE container for autoscaling purposes | `false` |
|
||||||
| `autoscaling.targetCPUUtilizationPercentage` | Target CPU utilization that triggers autoscaling | `80` |
|
| `autoscaling.targetCPUUtilizationPercentage` | Target CPU utilization that triggers autoscaling | `80` |
|
||||||
| `nodeSelector` | Select specific nodes to run on (currently only amd64 is supported by Tornjak) | `{}` |
|
| `nodeSelector` | Select specific nodes to run on (currently only amd64 is supported by Tornjak) | `{}` |
|
||||||
| `tolerations` | List of tolerations | `[]` |
|
| `tolerations` | List of tolerations | `[]` |
|
||||||
| `affinity` | List of node affinities | `{}` |
|
| `affinity` | List of node affinities | `{}` |
|
||||||
| `topologySpreadConstraints` | Topology spread constraints for resilience | `[]` |
|
| `topologySpreadConstraints` | Topology spread constraints for resilience | `[]` |
|
||||||
| `livenessProbe.failureThreshold` | Failure threshold count for livenessProbe | `2` |
|
| `livenessProbe.failureThreshold` | Failure threshold count for livenessProbe | `2` |
|
||||||
| `livenessProbe.initialDelaySeconds` | Initial delay seconds for livenessProbe | `15` |
|
| `livenessProbe.initialDelaySeconds` | Initial delay seconds for livenessProbe | `15` |
|
||||||
| `livenessProbe.periodSeconds` | Period seconds for livenessProbe | `60` |
|
| `livenessProbe.periodSeconds` | Period seconds for livenessProbe | `60` |
|
||||||
| `livenessProbe.timeoutSeconds` | Timeout in seconds for livenessProbe | `3` |
|
| `livenessProbe.timeoutSeconds` | Timeout in seconds for livenessProbe | `3` |
|
||||||
| `readinessProbe.initialDelaySeconds` | Initial delay seconds for readinessProbe | `5` |
|
| `readinessProbe.initialDelaySeconds` | Initial delay seconds for readinessProbe | `5` |
|
||||||
| `readinessProbe.periodSeconds` | Period seconds for readinessProbe | `5` |
|
| `readinessProbe.periodSeconds` | Period seconds for readinessProbe | `5` |
|
||||||
| `persistence.type` | What type of volume to use for persistence. Valid options pvc (recommended), hostPath, emptyDir (testing only) | `pvc` |
|
| `persistence.type` | What type of volume to use for persistence. Valid options pvc (recommended), hostPath, emptyDir (testing or nested child only) | `pvc` |
|
||||||
| `persistence.size` | What size volume to use for persistence | `1Gi` |
|
| `persistence.size` | What size volume to use for persistence | `1Gi` |
|
||||||
| `persistence.accessMode` | What access mode to use for persistence. Valid options are ReadWriteOnce (recommended), ReadWriteOncePod, ReadWriteMany (not recommended) | `ReadWriteOnce` |
|
| `persistence.accessMode` | What access mode to use for persistence. Valid options are ReadWriteOnce (recommended), ReadWriteOncePod, ReadWriteMany (not recommended) | `ReadWriteOnce` |
|
||||||
| `persistence.storageClass` | What storage class to use for persistence | `nil` |
|
| `persistence.storageClass` | What storage class to use for persistence | `nil` |
|
||||||
| `persistence.hostPath` | Which path to use on the host when persistence.type = hostPath | `""` |
|
| `persistence.hostPath` | Which path to use on the host when persistence.type = hostPath | `""` |
|
||||||
| `dataStore.sql.databaseType` | Other supported databases are ["postgres", "mysql", "aws_postgresql", "aws_mysql", "gcp_mysql_sa_iam"]. Note: aws type databases are still experimental. gcp_mysql_sa_iam uses IAM authentication by default. | `sqlite3` |
|
| `dataStore.sql.databaseType` | Other supported databases are ["postgres", "mysql", "aws_postgresql", "aws_mysql", "gcp_mysql_sa_iam"]. Note: aws type databases are still experimental. gcp_mysql_sa_iam uses IAM authentication by default. | `sqlite3` |
|
||||||
| `dataStore.sql.databaseName` | Only used when type != "sqlite3" | `spire` |
|
| `dataStore.sql.databaseName` | Only used when type != "sqlite3" | `spire` |
|
||||||
| `dataStore.sql.host` | Only used when type != "sqlite3" | `""` |
|
| `dataStore.sql.host` | Only used when type != "sqlite3" | `""` |
|
||||||
| `dataStore.sql.port` | If 0 (default), it will auto set to 5432 for postgres and 3306 for mysql. Only used by those databases. | `0` |
|
| `dataStore.sql.port` | If 0 (default), it will auto set to 5432 for postgres and 3306 for mysql. Only used by those databases. | `0` |
|
||||||
| `dataStore.sql.username` | Only used when type != "sqlite3" | `spire` |
|
| `dataStore.sql.username` | Only used when type != "sqlite3" | `spire` |
|
||||||
| `dataStore.sql.password` | Only used when type != "sqlite3" | `""` |
|
| `dataStore.sql.password` | Only used when type != "sqlite3" | `""` |
|
||||||
| `dataStore.sql.file` | Data source file. Only used when type == "sqlite3" | `/run/spire/data/datastore.sqlite3` |
|
| `dataStore.sql.file` | Data source file. Only used when type == "sqlite3" | `/run/spire/data/datastore.sqlite3` |
|
||||||
| `dataStore.sql.options` | takes an array of objects of form {<key>: <value>} to use when building the database connection string | `[]` |
|
| `dataStore.sql.options` | takes an array of objects of form {<key>: <value>} to use when building the database connection string | `[]` |
|
||||||
| `dataStore.sql.rootCAPath` | Path to Root CA bundle (MySQL only) | `""` |
|
| `dataStore.sql.rootCAPath` | Path to Root CA bundle (MySQL only) | `""` |
|
||||||
| `dataStore.sql.clientCertPath` | Path to client certificate (MySQL only) | `""` |
|
| `dataStore.sql.clientCertPath` | Path to client certificate (MySQL only) | `""` |
|
||||||
| `dataStore.sql.clientKeyPath` | Path to private key for client certificate (MySQL only) | `""` |
|
| `dataStore.sql.clientKeyPath` | Path to private key for client certificate (MySQL only) | `""` |
|
||||||
| `dataStore.sql.externalSecret.enabled` | Enable external secret for datastore creds | `false` |
|
| `dataStore.sql.externalSecret.enabled` | Enable external secret for datastore creds | `false` |
|
||||||
| `dataStore.sql.externalSecret.name` | The name of the secret object | `""` |
|
| `dataStore.sql.externalSecret.name` | The name of the secret object | `""` |
|
||||||
| `dataStore.sql.externalSecret.key` | The key of the secret object whose value is the dataStore.sql password | `""` |
|
| `dataStore.sql.externalSecret.key` | The key of the secret object whose value is the dataStore.sql password | `""` |
|
||||||
| `dataStore.sql.maxOpenConns` | The maximum number of open db connections | `100` |
|
| `dataStore.sql.maxOpenConns` | The maximum number of open db connections | `100` |
|
||||||
| `dataStore.sql.maxIdleConns` | The maximum number of idle connections in the pool | `2` |
|
| `dataStore.sql.maxIdleConns` | The maximum number of idle connections in the pool | `2` |
|
||||||
| `dataStore.sql.connMaxLifetime` | The maximum amount of time a connection may be reused. Supports duration strings (e.g., "1h", "30m", "3600s") or 0 for unlimited. Duration strings are recommended to prevent connection accumulation. | `0` |
|
| `dataStore.sql.connMaxLifetime` | The maximum amount of time a connection may be reused. Supports duration strings (e.g., "1h", "30m", "3600s") or 0 for unlimited. Duration strings are recommended to prevent connection accumulation. | `0` |
|
||||||
| `dataStore.sql.disableMigration` | True to disable auto-migration functionality | `false` |
|
| `dataStore.sql.disableMigration` | True to disable auto-migration functionality | `false` |
|
||||||
| `dataStore.sql.region` | Region to use when database type is either aws_mysql or aws_postgresql | `""` |
|
| `dataStore.sql.region` | Region to use when database type is either aws_mysql or aws_postgresql | `""` |
|
||||||
| `dataStore.sql.readOnly.enabled` | Set to true to configure a readOnly dartabase connection | `false` |
|
| `dataStore.sql.readOnly.enabled` | Set to true to configure a readOnly dartabase connection | `false` |
|
||||||
| `dataStore.sql.readOnly.host` | Only used when type != "sqlite3" | `""` |
|
| `dataStore.sql.readOnly.host` | Only used when type != "sqlite3" | `""` |
|
||||||
| `dataStore.sql.readOnly.port` | If 0 (default), it will auto set to 5432 for postgres and 3306 for mysql. Only used by those databases. | `0` |
|
| `dataStore.sql.readOnly.port` | If 0 (default), it will auto set to 5432 for postgres and 3306 for mysql. Only used by those databases. | `0` |
|
||||||
| `dataStore.sql.readOnly.username` | Only used when type != "sqlite3" | `spire` |
|
| `dataStore.sql.readOnly.username` | Only used when type != "sqlite3" | `spire` |
|
||||||
| `dataStore.sql.readOnly.password` | Only used when type != "sqlite3" | `""` |
|
| `dataStore.sql.readOnly.password` | Only used when type != "sqlite3" | `""` |
|
||||||
| `dataStore.sql.readOnly.options` | Only used when type != "sqlite3" | `[]` |
|
| `dataStore.sql.readOnly.options` | Only used when type != "sqlite3" | `[]` |
|
||||||
| `dataStore.sql.readOnly.externalSecret.enabled` | Enable external secret for datastore creds | `false` |
|
| `dataStore.sql.readOnly.externalSecret.enabled` | Enable external secret for datastore creds | `false` |
|
||||||
| `dataStore.sql.readOnly.externalSecret.name` | The name of the secret object | `""` |
|
| `dataStore.sql.readOnly.externalSecret.name` | The name of the secret object | `""` |
|
||||||
| `dataStore.sql.readOnly.externalSecret.key` | The key of the secret object whose value is the dataStore.sql password | `""` |
|
| `dataStore.sql.readOnly.externalSecret.key` | The key of the secret object whose value is the dataStore.sql password | `""` |
|
||||||
| `adminIDs` | SPIFFE IDs that, when present in a caller’s X509-SVID, grant that caller admin privileges. | `[]` |
|
| `adminIDs` | SPIFFE IDs that, when present in a caller’s X509-SVID, grant that caller admin privileges. | `[]` |
|
||||||
| `auditLogEnabled` | If true, enables audit logging | `false` |
|
| `auditLogEnabled` | If true, enables audit logging | `false` |
|
||||||
| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `info` |
|
| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `info` |
|
||||||
| `logFormat` | The log format, valid values are "text" and "json" | `text` |
|
| `logFormat` | The log format, valid values are "text" and "json" | `text` |
|
||||||
| `jwtIssuer` | The JWT issuer domain. Defaults to oidc-discovery.$trustDomain if unset | `""` |
|
| `jwtIssuer` | The JWT issuer domain. Defaults to oidc-discovery.$trustDomain if unset | `""` |
|
||||||
| `clusterName` | Set the name of the Kubernetes cluster. (`kubeadm init --service-dns-domain`) | `example-cluster` |
|
| `clusterName` | Set the name of the Kubernetes cluster. (`kubeadm init --service-dns-domain`) | `example-cluster` |
|
||||||
| `trustDomain` | Set the trust domain to be used for the SPIFFE identifiers | `example.org` |
|
| `trustDomain` | Set the trust domain to be used for the SPIFFE identifiers | `example.org` |
|
||||||
| `bundleConfigMap` | Set the Configmap name for SPIRE bundle | `spire-bundle` |
|
| `bundleConfigMap` | Set the Configmap name for SPIRE bundle | `spire-bundle` |
|
||||||
| `clusterDomain` | This is the value of your clusters `kubeadm init --service-dns-domain` flag | `cluster.local` |
|
| `clusterDomain` | This is the value of your clusters `kubeadm init --service-dns-domain` flag | `cluster.local` |
|
||||||
| `federation.enabled` | Flag to enable federation | `false` |
|
| `federation.enabled` | Flag to enable federation | `false` |
|
||||||
| `federation.bundleEndpoint.port` | Port value for trust bundle federation | `8443` |
|
| `federation.bundleEndpoint.port` | Port value for trust bundle federation | `8443` |
|
||||||
| `federation.bundleEndpoint.address` | Address for trust bundle federation | `0.0.0.0` |
|
| `federation.bundleEndpoint.address` | Address for trust bundle federation | `0.0.0.0` |
|
||||||
| `federation.bundleEndpoint.refreshHint` | Hint used by federated servers on how often to refresh the bundle. CA TTL must be 3-5x the duration of this value to ensure public keys are loaded on federated servers prior to private key rotation on remote server. | `5m` |
|
| `federation.bundleEndpoint.refreshHint` | Hint used by federated servers on how often to refresh the bundle. CA TTL must be 3-5x the duration of this value to ensure public keys are loaded on federated servers prior to private key rotation on remote server. | `5m` |
|
||||||
| `federation.bundleEndpoint.profile.httpWeb.fileSyncInterval` | Interval on which to reload the certificate/key from disk | `1h` |
|
| `federation.bundleEndpoint.profile.httpWeb.fileSyncInterval` | Interval on which to reload the certificate/key from disk | `1h` |
|
||||||
| `federation.tls.spire.enabled` | Use spire to secure the federation bundle endpoint | `true` |
|
| `federation.tls.spire.enabled` | Use spire to secure the federation bundle endpoint | `true` |
|
||||||
| `federation.tls.externalSecret.enabled` | Provide your own certificate/key via tls style Kubernetes Secret | `false` |
|
| `federation.tls.externalSecret.enabled` | Provide your own certificate/key via tls style Kubernetes Secret | `false` |
|
||||||
| `federation.tls.externalSecret.secretName` | Specify which Secret to use | `""` |
|
| `federation.tls.externalSecret.secretName` | Specify which Secret to use | `""` |
|
||||||
| `federation.tls.certManager.enabled` | Use certificateManager to create the certificate | `false` |
|
| `federation.tls.certManager.enabled` | Use certificateManager to create the certificate | `false` |
|
||||||
| `federation.tls.certManager.issuer.create` | Create an issuer to use to issue the certificate | `true` |
|
| `federation.tls.certManager.issuer.create` | Create an issuer to use to issue the certificate | `true` |
|
||||||
| `federation.tls.certManager.issuer.acme.email` | Must be set in order to register with LetsEncrypt. By setting, you agree to their Terms of Service | `""` |
|
| `federation.tls.certManager.issuer.acme.email` | Must be set in order to register with LetsEncrypt. By setting, you agree to their Terms of Service | `""` |
|
||||||
| `federation.tls.certManager.issuer.acme.server` | Server to use to get certificate. Defaults to LetsEncrypt | `https://acme-v02.api.letsencrypt.org/directory` |
|
| `federation.tls.certManager.issuer.acme.server` | Server to use to get certificate. Defaults to LetsEncrypt | `https://acme-v02.api.letsencrypt.org/directory` |
|
||||||
| `federation.tls.certManager.issuer.acme.solvers` | Configure the issuer solvers. Defaults to http01 via ingress. | `{}` |
|
| `federation.tls.certManager.issuer.acme.solvers` | Configure the issuer solvers. Defaults to http01 via ingress. | `{}` |
|
||||||
| `federation.tls.certManager.certificate.dnsNames` | Override the dnsNames on the certificate request. Defaults to the same settings as Ingress | `[]` |
|
| `federation.tls.certManager.certificate.dnsNames` | Override the dnsNames on the certificate request. Defaults to the same settings as Ingress | `[]` |
|
||||||
| `federation.tls.certManager.certificate.issuerRef.group` | If you are using an external plugin, specify the group for it here | `""` |
|
| `federation.tls.certManager.certificate.issuerRef.group` | If you are using an external plugin, specify the group for it here | `""` |
|
||||||
| `federation.tls.certManager.certificate.issuerRef.kind` | Kind of the issuer reference. Override if you want to use a ClusterIssuer | `Issuer` |
|
| `federation.tls.certManager.certificate.issuerRef.kind` | Kind of the issuer reference. Override if you want to use a ClusterIssuer | `Issuer` |
|
||||||
| `federation.tls.certManager.certificate.issuerRef.name` | Name of the issuer to use. If unset, it will use the name of the built in issuer | `""` |
|
| `federation.tls.certManager.certificate.issuerRef.name` | Name of the issuer to use. If unset, it will use the name of the built in issuer | `""` |
|
||||||
| `federation.ingress.enabled` | Flag to enable ingress for federation | `false` |
|
| `federation.ingress.enabled` | Flag to enable ingress for federation | `false` |
|
||||||
| `federation.ingress.className` | Ingress class name for federation | `""` |
|
| `federation.ingress.className` | Ingress class name for federation | `""` |
|
||||||
| `federation.ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, autodetection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` |
|
| `federation.ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, autodetection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` |
|
||||||
| `federation.ingress.annotations` | Annotations for the ingress object | `{}` |
|
| `federation.ingress.annotations` | Annotations for the ingress object | `{}` |
|
||||||
| `federation.ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `spire-server-federation` |
|
| `federation.ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `spire-server-federation` |
|
||||||
| `federation.ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` |
|
| `federation.ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` |
|
||||||
| `federation.ingress.hosts` | Host paths for ingress object. If empty, rules will be built based on the host var. | `[]` |
|
| `federation.ingress.hosts` | Host paths for ingress object. If empty, rules will be built based on the host var. | `[]` |
|
||||||
| `federation.ingress.tls` | Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. | `[]` |
|
| `federation.ingress.tls` | Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. | `[]` |
|
||||||
| `caSubject.country` | Country for Spire server CA | `ARPA` |
|
| `caSubject.country` | Country for Spire server CA | `ARPA` |
|
||||||
| `caSubject.organization` | Organization for Spire server CA | `Example` |
|
| `caSubject.organization` | Organization for Spire server CA | `Example` |
|
||||||
| `caSubject.commonName` | Common Name for Spire server CA | `example.org` |
|
| `caSubject.commonName` | Common Name for Spire server CA | `example.org` |
|
||||||
| `credentialComposer.cel.enabled` | Enable the cel based credential composer | `false` |
|
| `credentialComposer.cel.enabled` | Enable the cel based credential composer | `false` |
|
||||||
| `credentialComposer.cel.image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
| `credentialComposer.cel.image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
||||||
| `credentialComposer.cel.image.repository` | The repository within the registry | `spiffe/spire-credentialcomposer-cel` |
|
| `credentialComposer.cel.image.repository` | The repository within the registry | `spiffe/spire-credentialcomposer-cel` |
|
||||||
| `credentialComposer.cel.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
| `credentialComposer.cel.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
| `credentialComposer.cel.image.tag` | Overrides the image tag | `0.0.2` |
|
| `credentialComposer.cel.image.tag` | Overrides the image tag | `0.0.2` |
|
||||||
| `credentialComposer.cel.checksum` | The sha256 checksum of the plugin binary | `23fa1d10f15ad5d5c555930cf82289c664801d7d5609bfd8847f95a0a667e4e4` |
|
| `credentialComposer.cel.checksum` | The sha256 checksum of the plugin binary | `23fa1d10f15ad5d5c555930cf82289c664801d7d5609bfd8847f95a0a667e4e4` |
|
||||||
| `credentialComposer.cel.pluginPath` | The filename in the container of the plugin | `/ko-app/cmd` |
|
| `credentialComposer.cel.pluginPath` | The filename in the container of the plugin | `/ko-app/cmd` |
|
||||||
| `credentialComposer.cel.jwt.expression` | The expression to use for jwt token composing | `""` |
|
| `credentialComposer.cel.jwt.expression` | The expression to use for jwt token composing | `""` |
|
||||||
| `credentialComposer.uniqueID.enabled` | Add the x509UniqueIdentifier attribute to workload X509-SVIDs | `false` |
|
| `credentialComposer.uniqueID.enabled` | Add the x509UniqueIdentifier attribute to workload X509-SVIDs | `false` |
|
||||||
| `keyManager.disk.enabled` | Flag to enable keyManager on disk | `true` |
|
| `keyManager.disk.enabled` | Flag to enable keyManager on disk | `true` |
|
||||||
| `keyManager.memory.enabled` | Flag to enable keyManager in memory | `false` |
|
| `keyManager.memory.enabled` | Flag to enable keyManager in memory | `false` |
|
||||||
| `keyManager.awsKMS.enabled` | Flag to enable keyManager in memory | `false` |
|
| `keyManager.awsKMS.enabled` | Flag to enable keyManager in memory | `false` |
|
||||||
| `keyManager.awsKMS.region` | Specify the region for AWS KMS | `""` |
|
| `keyManager.awsKMS.region` | Specify the region for AWS KMS | `""` |
|
||||||
| `keyManager.awsKMS.keyIdentifierFile.enabled` | Enable key identifier data to be stored in a file in persistent storage. | `false` |
|
| `keyManager.awsKMS.keyIdentifierFile.enabled` | Enable key identifier data to be stored in a file in persistent storage. | `false` |
|
||||||
| `keyManager.awsKMS.keyIdentifierValue.enabled` | Enable specifying a key identifier value for AWS KMS | `false` |
|
| `keyManager.awsKMS.keyIdentifierValue.enabled` | Enable specifying a key identifier value for AWS KMS | `false` |
|
||||||
| `keyManager.awsKMS.keyIdentifierValue.identifier` | Static identifier for the SPIRE server instance | `""` |
|
| `keyManager.awsKMS.keyIdentifierValue.identifier` | Static identifier for the SPIRE server instance | `""` |
|
||||||
| `keyManager.awsKMS.keyPolicy` | Policy to use when creating keys. If no policy is specified, a default policy will be used. | |
|
| `keyManager.awsKMS.keyPolicy` | Policy to use when creating keys. If no policy is specified, a default policy will be used. | |
|
||||||
| `keyManager.awsKMS.keyPolicy.policy` | Key policy in JSON format. | `""` |
|
| `keyManager.awsKMS.keyPolicy.policy` | Key policy in JSON format. | `""` |
|
||||||
| `keyManager.awsKMS.keyPolicy.existingConfigMap` | Name of a ConfigMap that has a `policy.json` file with the key policy in JSON format. | `""` |
|
| `keyManager.awsKMS.keyPolicy.existingConfigMap` | Name of a ConfigMap that has a `policy.json` file with the key policy in JSON format. | `""` |
|
||||||
| `keyManager.awsKMS.keyTags` | Custom tags to apply to KMS keys created by the plugin. Tags are key-value pairs used for resource management and cost allocation. When using key tagging, you must add the `kms:TagResource` permission to your IAM policy. Constraints: keys (1-128 chars), values (0-256 chars), max 50 tags, valid chars (letters, numbers, spaces, + - = . _ : / @), keys cannot start with 'aws:' or 'spire-'. | `{}` |
|
| `keyManager.awsKMS.keyTags` | Custom tags to apply to KMS keys created by the plugin. Tags are key-value pairs used for resource management and cost allocation. When using key tagging, you must add the `kms:TagResource` permission to your IAM policy. Constraints: keys (1-128 chars), values (0-256 chars), max 50 tags, valid chars (letters, numbers, spaces, + - = . _ : / @), keys cannot start with 'aws:' or 'spire-'. | `{}` |
|
||||||
| `keyManager.awsKMS.accessKeyID` | Access key ID for the AWS account. It's recommended to use an IAM role instead. See [here](https://docs.aws.amazon.com/eks/latest/userguide/associate-service-account-role.html) to learn how to annotate your SPIRE Server Service Account to assume an IAM role. | `""` |
|
| `keyManager.awsKMS.accessKeyID` | Access key ID for the AWS account. It's recommended to use an IAM role instead. See [here](https://docs.aws.amazon.com/eks/latest/userguide/associate-service-account-role.html) to learn how to annotate your SPIRE Server Service Account to assume an IAM role. | `""` |
|
||||||
| `keyManager.awsKMS.secretAccessKey` | Secret access key for the AWS account. | `""` |
|
| `keyManager.awsKMS.secretAccessKey` | Secret access key for the AWS account. | `""` |
|
||||||
| `upstreamAuthority.disk.enabled` | Flag to enable upstream authority plugin on disk | `false` |
|
| `upstreamAuthority.disk.enabled` | Flag to enable upstream authority plugin on disk | `false` |
|
||||||
| `upstreamAuthority.disk.secret.create` | If disabled requires you to create a secret with the given keys (certificate, key and optional bundle) yourself. | `true` |
|
| `upstreamAuthority.disk.secret.create` | If disabled requires you to create a secret with the given keys (certificate, key and optional bundle) yourself. | `true` |
|
||||||
| `upstreamAuthority.disk.secret.name` | If secret creation is disabled, the secret with this name will be used. | `spiffe-upstream-ca` |
|
| `upstreamAuthority.disk.secret.name` | If secret creation is disabled, the secret with this name will be used. | `spiffe-upstream-ca` |
|
||||||
| `upstreamAuthority.disk.secret.data` | If secret creation is enabled, will create a secret with following certificate info | |
|
| `upstreamAuthority.disk.secret.data` | If secret creation is enabled, will create a secret with following certificate info | |
|
||||||
| `upstreamAuthority.disk.secret.data.certificate` | Certificate to store within disk upstreamAuthority. | `""` |
|
| `upstreamAuthority.disk.secret.data.certificate` | Certificate to store within disk upstreamAuthority. | `""` |
|
||||||
| `upstreamAuthority.disk.secret.data.key` | Key corresponding to the upstreamAuthority. | `""` |
|
| `upstreamAuthority.disk.secret.data.key` | Key corresponding to the upstreamAuthority. | `""` |
|
||||||
| `upstreamAuthority.disk.secret.data.bundle` | Trust bundle for upstreamAuthority. | `""` |
|
| `upstreamAuthority.disk.secret.data.bundle` | Trust bundle for upstreamAuthority. | `""` |
|
||||||
| `upstreamAuthority.awsPCA.enabled` | Flag to enable upstream authority plugin with AWS PCA | `false` |
|
| `upstreamAuthority.awsPCA.enabled` | Flag to enable upstream authority plugin with AWS PCA | `false` |
|
||||||
| `upstreamAuthority.awsPCA.region` | AWS Region to use | `""` |
|
| `upstreamAuthority.awsPCA.region` | AWS Region to use | `""` |
|
||||||
| `upstreamAuthority.awsPCA.certificateAuthorityARN` | ARN of the "upstream" CA certificate | `""` |
|
| `upstreamAuthority.awsPCA.certificateAuthorityARN` | ARN of the "upstream" CA certificate | `""` |
|
||||||
| `upstreamAuthority.awsPCA.assumeRoleARN` | (Optional) ARN of an IAM role to assume | `""` |
|
| `upstreamAuthority.awsPCA.assumeRoleARN` | (Optional) ARN of an IAM role to assume | `""` |
|
||||||
| `upstreamAuthority.awsPCA.caSigningTemplateARN` | (Optional) ARN of the signing template to use for the server's CA. Defaults to a signing template for end-entity certificates only. See Using Templates (https://docs.aws.amazon.com/acm-pca/latest/userguide/UsingTemplates.html) for possible values. | `""` |
|
| `upstreamAuthority.awsPCA.caSigningTemplateARN` | (Optional) ARN of the signing template to use for the server's CA. Defaults to a signing template for end-entity certificates only. See Using Templates (https://docs.aws.amazon.com/acm-pca/latest/userguide/UsingTemplates.html) for possible values. | `""` |
|
||||||
| `upstreamAuthority.awsPCA.signingAlgorithm` | (Optional) Signing algorithm to use for the server's CA. Defaults to the CA's default. See Issue Certificate (https://docs.aws.amazon.com/cli/latest/reference/acm-pca/issue-certificate.html) for possible values. | `""` |
|
| `upstreamAuthority.awsPCA.signingAlgorithm` | (Optional) Signing algorithm to use for the server's CA. Defaults to the CA's default. See Issue Certificate (https://docs.aws.amazon.com/cli/latest/reference/acm-pca/issue-certificate.html) for possible values. | `""` |
|
||||||
| `upstreamAuthority.awsPCA.endpoint` | (Optional) Endpoint as hostname or fully-qualified URI that overrides the default endpoint. See AWS SDK Config docs (https://docs.aws.amazon.com/sdk-for-go/api/aws/#Config) for more information. | `""` |
|
| `upstreamAuthority.awsPCA.endpoint` | (Optional) Endpoint as hostname or fully-qualified URI that overrides the default endpoint. See AWS SDK Config docs (https://docs.aws.amazon.com/sdk-for-go/api/aws/#Config) for more information. | `""` |
|
||||||
| `upstreamAuthority.awsPCA.supplementalBundlePath` | (Optional) Path to a file containing PEM-encoded CA certificates that should be additionally included in the bundle. | `""` |
|
| `upstreamAuthority.awsPCA.supplementalBundlePath` | (Optional) Path to a file containing PEM-encoded CA certificates that should be additionally included in the bundle. | `""` |
|
||||||
| `upstreamAuthority.awsSecret.enabled` | Flag to enable upstream authority plugin with AWS Secrets Manager | `false` |
|
| `upstreamAuthority.awsSecret.enabled` | Flag to enable upstream authority plugin with AWS Secrets Manager | `false` |
|
||||||
| `upstreamAuthority.awsSecret.region` | AWS Region to use | `""` |
|
| `upstreamAuthority.awsSecret.region` | AWS Region to use | `""` |
|
||||||
| `upstreamAuthority.awsSecret.certFileArn` | ARN or name of the secret containing the intermediate CA certificate | `""` |
|
| `upstreamAuthority.awsSecret.certFileArn` | ARN or name of the secret containing the intermediate CA certificate | `""` |
|
||||||
| `upstreamAuthority.awsSecret.keyFileArn` | ARN or name of the secret containing the intermediate CA private key | `""` |
|
| `upstreamAuthority.awsSecret.keyFileArn` | ARN or name of the secret containing the intermediate CA private key | `""` |
|
||||||
| `upstreamAuthority.awsSecret.bundleFileArn` | (Optional) ARN or name of the secret containing the root CA bundle | `""` |
|
| `upstreamAuthority.awsSecret.bundleFileArn` | (Optional) ARN or name of the secret containing the root CA bundle | `""` |
|
||||||
| `upstreamAuthority.awsSecret.assumeRoleArn` | (Optional) ARN of an IAM role to assume | `""` |
|
| `upstreamAuthority.awsSecret.assumeRoleArn` | (Optional) ARN of an IAM role to assume | `""` |
|
||||||
| `upstreamAuthority.certManager.enabled` | Flag to enable upstream authority plugin with cert manager | `false` |
|
| `upstreamAuthority.certManager.enabled` | Flag to enable upstream authority plugin with cert manager | `false` |
|
||||||
| `upstreamAuthority.certManager.rbac.create` | Flag to create RBAC roles | `true` |
|
| `upstreamAuthority.certManager.rbac.create` | Flag to create RBAC roles | `true` |
|
||||||
| `upstreamAuthority.certManager.issuerName` | Defaults to the release name, override if CA is provided outside of the chart | `""` |
|
| `upstreamAuthority.certManager.issuerName` | Defaults to the release name, override if CA is provided outside of the chart | `""` |
|
||||||
| `upstreamAuthority.certManager.issuerKind` | Defaults to "Issuer", override if CA is provided outside of the chart | `Issuer` |
|
| `upstreamAuthority.certManager.issuerKind` | Defaults to "Issuer", override if CA is provided outside of the chart | `Issuer` |
|
||||||
| `upstreamAuthority.certManager.issuerGroup` | Defaults to "cert-manager.io", override if CA is provided outside of the chart | `cert-manager.io` |
|
| `upstreamAuthority.certManager.issuerGroup` | Defaults to "cert-manager.io", override if CA is provided outside of the chart | `cert-manager.io` |
|
||||||
| `upstreamAuthority.certManager.namespace` | Specify to use a namespace other then the one the chart is installed into | `""` |
|
| `upstreamAuthority.certManager.namespace` | Specify to use a namespace other then the one the chart is installed into | `""` |
|
||||||
| `upstreamAuthority.certManager.kubeConfigFile` | Path to kube config file on node to setup cert manager | `""` |
|
| `upstreamAuthority.certManager.kubeConfigFile` | Path to kube config file on node to setup cert manager | `""` |
|
||||||
| `upstreamAuthority.certManager.ca.create` | Creates a Cert-Manager CA | `false` |
|
| `upstreamAuthority.certManager.ca.create` | Creates a Cert-Manager CA | `false` |
|
||||||
| `upstreamAuthority.certManager.ca.duration` | Duration of the CA. Defaults to 10 years | `87600h` |
|
| `upstreamAuthority.certManager.ca.duration` | Duration of the CA. Defaults to 10 years | `87600h` |
|
||||||
| `upstreamAuthority.certManager.ca.privateKey.algorithm` | Algorithm to generate private key for CA | `ECDSA` |
|
| `upstreamAuthority.certManager.ca.privateKey.algorithm` | Algorithm to generate private key for CA | `ECDSA` |
|
||||||
| `upstreamAuthority.certManager.ca.privateKey.size` | Size of generated private key for CA | `256` |
|
| `upstreamAuthority.certManager.ca.privateKey.size` | Size of generated private key for CA | `256` |
|
||||||
| `upstreamAuthority.certManager.ca.privateKey.rotationPolicy` | Rotation policy for generated private key | `""` |
|
| `upstreamAuthority.certManager.ca.privateKey.rotationPolicy` | Rotation policy for generated private key | `""` |
|
||||||
| `upstreamAuthority.certManager.ca.renewBefore` | How long to wait before renewing the CA | `""` |
|
| `upstreamAuthority.certManager.ca.renewBefore` | How long to wait before renewing the CA | `""` |
|
||||||
| `upstreamAuthority.spire.enabled` | Flag to use another Spire install as upstream CA | `false` |
|
| `upstreamAuthority.spire.enabled` | Flag to use another Spire install as upstream CA | `false` |
|
||||||
| `upstreamAuthority.spire.upstreamDriver` | Driver for Spire as upstream CA | `""` |
|
| `upstreamAuthority.spire.upstreamDriver` | Driver for Spire as upstream CA | `""` |
|
||||||
| `upstreamAuthority.spire.server` | Server details for the Spire instance use as upstream CA | |
|
| `upstreamAuthority.spire.server` | Server details for the Spire instance use as upstream CA | |
|
||||||
| `upstreamAuthority.spire.server.nameOverride` | Override the name for upstream Spire server. Should only be changed when building your own nested chart to ensure names align. | `""` |
|
| `upstreamAuthority.spire.server.nameOverride` | Override the name for upstream Spire server. Should only be changed when building your own nested chart to ensure names align. | `""` |
|
||||||
| `upstreamAuthority.spire.server.address` | Address for upstream Spire server | `""` |
|
| `upstreamAuthority.spire.server.address` | Address for upstream Spire server | `""` |
|
||||||
| `upstreamAuthority.spire.server.port` | Port for upstream Spire server | `443` |
|
| `upstreamAuthority.spire.server.port` | Port for upstream Spire server | `443` |
|
||||||
| `upstreamAuthority.vault.enabled` | Enable Hashicorp Vault as upstream CA | `false` |
|
| `upstreamAuthority.vault.enabled` | Enable Hashicorp Vault as upstream CA | `false` |
|
||||||
| `upstreamAuthority.vault.vaultAddr` | The URL of the Vault server. (e.g., https://vault.example.com:8443/) | `""` |
|
| `upstreamAuthority.vault.vaultAddr` | The URL of the Vault server. (e.g., https://vault.example.com:8443/) | `""` |
|
||||||
| `upstreamAuthority.vault.namespace` | Name of the Vault namespace. This is only available in the Vault Enterprise. | `""` |
|
| `upstreamAuthority.vault.namespace` | Name of the Vault namespace. This is only available in the Vault Enterprise. | `""` |
|
||||||
| `upstreamAuthority.vault.pkiMountPoint` | Name of the mount point where PKI secret engine is mounted | `pki` |
|
| `upstreamAuthority.vault.pkiMountPoint` | Name of the mount point where PKI secret engine is mounted | `pki` |
|
||||||
| `upstreamAuthority.vault.insecureSkipVerify` | If true, caCert options are ignored and Spire accepts any server certificates claiming to be Vault | `false` |
|
| `upstreamAuthority.vault.insecureSkipVerify` | If true, caCert options are ignored and Spire accepts any server certificates claiming to be Vault | `false` |
|
||||||
| `upstreamAuthority.vault.caCert.type` | Type of resource representing the Vault server certificate, options are 'Secret' or 'Configmap', the item must be named `ca.crt` | `Secret` |
|
| `upstreamAuthority.vault.caCert.type` | Type of resource representing the Vault server certificate, options are 'Secret' or 'Configmap', the item must be named `ca.crt` | `Secret` |
|
||||||
| `upstreamAuthority.vault.caCert.name` | Name of the Kubernetes resource containing the Vault server certificate | `vault-ca` |
|
| `upstreamAuthority.vault.caCert.name` | Name of the Kubernetes resource containing the Vault server certificate | `vault-ca` |
|
||||||
| `upstreamAuthority.vault.k8sAuth.enabled` | Enable k8s authentication to Hashicorp Vault | `false` |
|
| `upstreamAuthority.vault.k8sAuth.enabled` | Enable k8s authentication to Hashicorp Vault | `false` |
|
||||||
| `upstreamAuthority.vault.k8sAuth.k8sAuthMountPoint` | Name of the mount point where the Kubernetes auth method is mounted | `kubernetes` |
|
| `upstreamAuthority.vault.k8sAuth.k8sAuthMountPoint` | Name of the mount point where the Kubernetes auth method is mounted | `kubernetes` |
|
||||||
| `upstreamAuthority.vault.k8sAuth.k8sAuthRoleName` | Required - Name of the Vault role. The plugin authenticates against the named role | `""` |
|
| `upstreamAuthority.vault.k8sAuth.k8sAuthRoleName` | Required - Name of the Vault role. The plugin authenticates against the named role | `""` |
|
||||||
| `upstreamAuthority.vault.k8sAuth.token.audience` | Intended audience of the PSAT, it must match one of the audiences supported by the Kubernetes API server. If no audience is specified, it defaults to the identifier of API Server. See ['Service Account Documentation'](https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/#serviceaccount-token-volume-projection) for more info. | `vault` |
|
| `upstreamAuthority.vault.k8sAuth.token.audience` | Intended audience of the PSAT, it must match one of the audiences supported by the Kubernetes API server. If no audience is specified, it defaults to the identifier of API Server. See ['Service Account Documentation'](https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/#serviceaccount-token-volume-projection) for more info. | `vault` |
|
||||||
| `upstreamAuthority.vault.k8sAuth.token.expiry` | Expiry time in seconds for the token | `7200` |
|
| `upstreamAuthority.vault.k8sAuth.token.expiry` | Expiry time in seconds for the token | `7200` |
|
||||||
| `notifier.k8sBundle.enabled` | Enable local k8s bundle uploader | `false` |
|
| `notifier.k8sBundle.enabled` | Enable local k8s bundle uploader | `false` |
|
||||||
| `notifier.k8sBundle.namespace` | Namespace to push the bundle into, if blank will default to SPIRE Server namespace | `""` |
|
| `notifier.k8sBundle.namespace` | Namespace to push the bundle into, if blank will default to SPIRE Server namespace | `""` |
|
||||||
| `notifier.k8sBundle.apiServiceLabel` | If set, rotate the CA Bundle in API services with this label set to true. | `""` |
|
| `notifier.k8sBundle.apiServiceLabel` | If set, rotate the CA Bundle in API services with this label set to true. | `""` |
|
||||||
| `notifier.k8sBundle.webhookLabel` | If set, rotate the CA Bundle in validating and mutating webhooks with this label set to true. | `""` |
|
| `notifier.k8sBundle.webhookLabel` | If set, rotate the CA Bundle in validating and mutating webhooks with this label set to true. | `""` |
|
||||||
| `notifier.externalK8sBundle.enabled` | Enable external k8s bundle uploader | `false` |
|
| `notifier.externalK8sBundle.enabled` | Enable external k8s bundle uploader | `false` |
|
||||||
| `notifier.externalK8sBundle.defaults.namespace` | Namespace to push the bundle into on clusters | `spire-system` |
|
| `notifier.externalK8sBundle.defaults.namespace` | Namespace to push the bundle into on clusters | `spire-system` |
|
||||||
| `notifier.externalK8sBundle.defaults.configMap` | ConfigMap name to push the bundle into on external clusters | `spire-bundle-upstream` |
|
| `notifier.externalK8sBundle.defaults.configMap` | ConfigMap name to push the bundle into on external clusters | `spire-bundle-upstream` |
|
||||||
| `notifier.externalK8sBundle.defaults.configMapKey` | ConfigMap key to push the bundle into on external clusters | `bundle.crt` |
|
| `notifier.externalK8sBundle.defaults.configMapKey` | ConfigMap key to push the bundle into on external clusters | `bundle.crt` |
|
||||||
| `notifier.externalK8sBundle.clusters` | A dictionary of clusters to add with optional overrides. If empty, all clusters defined in kubeConfigs will be used. | `{}` |
|
| `notifier.externalK8sBundle.clusters` | A dictionary of clusters to add with optional overrides. If empty, all clusters defined in kubeConfigs will be used. | `{}` |
|
||||||
| `controllerManager.enabled` | Flag to enable controller manager | `false` |
|
| `controllerManager.enabled` | Flag to enable controller manager | `false` |
|
||||||
| `controllerManager.staticManifestMode` | Flag to configure static mode. Valid options off, internal, and external. If internal, the identities config options will be rendered to an included configmap | `off` |
|
| `controllerManager.staticManifestMode` | Flag to configure static mode. Valid options off, internal, and external. If internal, the identities config options will be rendered to an included configmap | `off` |
|
||||||
| `controllerManager.className` | specify to use an explicit class name. If empty, it will be automatically set to Release.Namespace-Release.Name to not conflict with other installs, enabling parallel installs. | `""` |
|
| `controllerManager.className` | specify to use an explicit class name. If empty, it will be automatically set to Release.Namespace-Release.Name to not conflict with other installs, enabling parallel installs. | `""` |
|
||||||
| `controllerManager.watchClassless` | specify to process custom resources without class name specified. Useful to slowly migrate to class names from classless installs. Do not have two installs on the same k8s cluster both set to true. | `false` |
|
| `controllerManager.watchClassless` | specify to process custom resources without class name specified. Useful to slowly migrate to class names from classless installs. Do not have two installs on the same k8s cluster both set to true. | `false` |
|
||||||
| `controllerManager.entryIDPrefixCleanup` | Sets which entry prefixes to remove for migrations. Consult the spiffe.io docs about this option before changing. Its unlikely you will need to ever change it. | `false` |
|
| `controllerManager.entryIDPrefixCleanup` | Sets which entry prefixes to remove for migrations. Consult the spiffe.io docs about this option before changing. Its unlikely you will need to ever change it. | `false` |
|
||||||
| `controllerManager.addEntryIDPrefix` | If true, prepends the clusterName to the entryID of each entry the controller manager registers. | `true` |
|
| `controllerManager.addEntryIDPrefix` | If true, prepends the clusterName to the entryID of each entry the controller manager registers. | `true` |
|
||||||
| `controllerManager.gcInterval` | How often the SPIRE state is reconciled when the controller is otherwise idle. This impacts how quickly SPIRE state will converge after CRDs are removed or SPIRE state is mutated underneath the controller. Values are in nanoseconds. | `10000000000` |
|
| `controllerManager.gcInterval` | How often the SPIRE state is reconciled when the controller is otherwise idle. This impacts how quickly SPIRE state will converge after CRDs are removed or SPIRE state is mutated underneath the controller. Values are in nanoseconds. | `10000000000` |
|
||||||
| `controllerManager.logLevel` | The log level for the controller manager. Supported values are info, error, warn and debug. | `info` |
|
| `controllerManager.logLevel` | The log level for the controller manager. Supported values are info, error, warn and debug. | `info` |
|
||||||
| `controllerManager.logEncoding` | The log encoding for the controller manager. Supported values are console and json. | `console` |
|
| `controllerManager.logEncoding` | The log encoding for the controller manager. Supported values are console and json. | `console` |
|
||||||
| `controllerManager.leaderElection.leaseDuration` | Duration that non-leader candidates will wait to force acquire leadership. Increase this in high-load clusters to reduce API server pressure. | `15s` |
|
| `controllerManager.leaderElection.leaseDuration` | Duration that non-leader candidates will wait to force acquire leadership. Increase this in high-load clusters to reduce API server pressure. | `15s` |
|
||||||
| `controllerManager.leaderElection.renewDeadline` | Duration the acting leader will retry refreshing leadership before giving up. Must be less than leaseDuration. | `10s` |
|
| `controllerManager.leaderElection.renewDeadline` | Duration the acting leader will retry refreshing leadership before giving up. Must be less than leaseDuration. | `10s` |
|
||||||
| `controllerManager.leaderElection.retryPeriod` | Duration the LeaderElector clients should wait between tries of actions. Must be less than renewDeadline. | `2s` |
|
| `controllerManager.leaderElection.retryPeriod` | Duration the LeaderElector clients should wait between tries of actions. Must be less than renewDeadline. | `2s` |
|
||||||
| `controllerManager.livenessProbe.initialDelaySeconds` | Initial delay seconds for livenessProbe | `5` |
|
| `controllerManager.livenessProbe.initialDelaySeconds` | Initial delay seconds for livenessProbe | `5` |
|
||||||
| `controllerManager.livenessProbe.periodSeconds` | Period seconds for livenessProbe | `10` |
|
| `controllerManager.livenessProbe.periodSeconds` | Period seconds for livenessProbe | `10` |
|
||||||
| `controllerManager.livenessProbe.timeoutSeconds` | Timeout seconds for livenessProbe | `5` |
|
| `controllerManager.livenessProbe.timeoutSeconds` | Timeout seconds for livenessProbe | `5` |
|
||||||
| `controllerManager.livenessProbe.failureThreshold` | Failure threshold for livenessProbe | `3` |
|
| `controllerManager.livenessProbe.failureThreshold` | Failure threshold for livenessProbe | `3` |
|
||||||
| `controllerManager.readinessProbe.initialDelaySeconds` | Initial delay seconds for readinessProbe | `5` |
|
| `controllerManager.readinessProbe.initialDelaySeconds` | Initial delay seconds for readinessProbe | `5` |
|
||||||
| `controllerManager.readinessProbe.periodSeconds` | Period seconds for readinessProbe | `10` |
|
| `controllerManager.readinessProbe.periodSeconds` | Period seconds for readinessProbe | `10` |
|
||||||
| `controllerManager.readinessProbe.timeoutSeconds` | Timeout seconds for readinessProbe | `5` |
|
| `controllerManager.readinessProbe.timeoutSeconds` | Timeout seconds for readinessProbe | `5` |
|
||||||
| `controllerManager.readinessProbe.failureThreshold` | Failure threshold for readinessProbe | `3` |
|
| `controllerManager.readinessProbe.failureThreshold` | Failure threshold for readinessProbe | `3` |
|
||||||
| `controllerManager.parentIDTemplate` | The template that is used to register workloads. | `spiffe://{{ .TrustDomain }}/spire/agent/k8s_psat/{{ .ClusterName }}/{{ .NodeMeta.UID }}` |
|
| `controllerManager.parentIDTemplate` | The template that is used to register workloads. | `spiffe://{{ .TrustDomain }}/spire/agent/k8s_psat/{{ .ClusterName }}/{{ .NodeMeta.UID }}` |
|
||||||
| `controllerManager.expandEnv` | Set to true to enable environment variable substitution of config file options | `false` |
|
| `controllerManager.expandEnv` | Set to true to enable environment variable substitution of config file options | `false` |
|
||||||
| `controllerManager.extraEnv` | Extra environment variables to add to the controller manager | `[]` |
|
| `controllerManager.extraEnv` | Extra environment variables to add to the controller manager | `[]` |
|
||||||
| `controllerManager.installAndUpgradeHook.enabled` | Enable Helm hook to autofix common install/upgrade issues (should be disabled when using `helm template`) | `true` |
|
| `controllerManager.installAndUpgradeHook.enabled` | Enable Helm hook to autofix common install/upgrade issues (should be disabled when using `helm template`) | `true` |
|
||||||
| `controllerManager.deleteHook.enabled` | Enable Helm hook to autofix common delete issues (should be disabled when using `helm template`) | `true` |
|
| `controllerManager.deleteHook.enabled` | Enable Helm hook to autofix common delete issues (should be disabled when using `helm template`) | `true` |
|
||||||
| `controllerManager.image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
| `controllerManager.image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
||||||
| `controllerManager.image.repository` | The repository within the registry | `spiffe/spire-controller-manager` |
|
| `controllerManager.image.repository` | The repository within the registry | `spiffe/spire-controller-manager` |
|
||||||
| `controllerManager.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
| `controllerManager.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
| `controllerManager.image.tag` | Overrides the image tag whose default is the chart appVersion | `0.6.4` |
|
| `controllerManager.image.tag` | Overrides the image tag whose default is the chart appVersion | `0.6.4` |
|
||||||
| `controllerManager.resources` | Resource requests and limits for controller manager | `{}` |
|
| `controllerManager.resources` | Resource requests and limits for controller manager | `{}` |
|
||||||
| `controllerManager.securityContext` | Security context | `{}` |
|
| `controllerManager.securityContext` | Security context | `{}` |
|
||||||
| `controllerManager.service.type` | Service type for controller manager | `ClusterIP` |
|
| `controllerManager.service.type` | Service type for controller manager | `ClusterIP` |
|
||||||
| `controllerManager.service.port` | Service port for controller manager | `443` |
|
| `controllerManager.service.port` | Service port for controller manager | `443` |
|
||||||
| `controllerManager.service.annotations` | Annotations for service resource | `{}` |
|
| `controllerManager.service.annotations` | Annotations for service resource | `{}` |
|
||||||
| `controllerManager.configMap.annotations` | Annotations to add to the Controller Manager ConfigMap | `{}` |
|
| `controllerManager.configMap.annotations` | Annotations to add to the Controller Manager ConfigMap | `{}` |
|
||||||
| `controllerManager.ignoreNamespaces` | These namespaces are ignored by controller manager | `[]` |
|
| `controllerManager.ignoreNamespaces` | These namespaces are ignored by controller manager | `[]` |
|
||||||
| `controllerManager.reconcile.clusterSPIFFEIDs` | Enable reconciliation of clusterSPIFFEIDs from K8s to the SPIRE server | `true` |
|
| `controllerManager.reconcile.clusterSPIFFEIDs` | Enable reconciliation of clusterSPIFFEIDs from K8s to the SPIRE server | `true` |
|
||||||
| `controllerManager.reconcile.clusterStaticEntries` | Enable reconciliation of clusterStaticEntries from K8s to the SPIRE server | `true` |
|
| `controllerManager.reconcile.clusterStaticEntries` | Enable reconciliation of clusterStaticEntries from K8s to the SPIRE server | `true` |
|
||||||
| `controllerManager.reconcile.clusterFederatedTrustDomains` | Enable reconciliation of clusterFederatedTrustDomains from K8s to the SPIRE server | `true` |
|
| `controllerManager.reconcile.clusterFederatedTrustDomains` | Enable reconciliation of clusterFederatedTrustDomains from K8s to the SPIRE server | `true` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.default.enabled` | Enable this identity for controller manager | `true` |
|
| `controllerManager.identities.clusterSPIFFEIDs.default.enabled` | Enable this identity for controller manager | `true` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.default.spiffeIDTemplate` | Spiffe ID template for identities | `spiffe://{{ .TrustDomain }}/ns/{{ .PodMeta.Namespace }}/sa/{{ .PodSpec.ServiceAccountName }}` |
|
| `controllerManager.identities.clusterSPIFFEIDs.default.spiffeIDTemplate` | Spiffe ID template for identities | `spiffe://{{ .TrustDomain }}/ns/{{ .PodMeta.Namespace }}/sa/{{ .PodSpec.ServiceAccountName }}` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.default.podSelector` | Selector for pods to issue identity | `{}` |
|
| `controllerManager.identities.clusterSPIFFEIDs.default.podSelector` | Selector for pods to issue identity | `{}` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.default.namespaceSelector` | Selector for namespaces to issue identity | `{}` |
|
| `controllerManager.identities.clusterSPIFFEIDs.default.namespaceSelector` | Selector for namespaces to issue identity | `{}` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.default.dnsNameTemplates` | DNS name template for issued identities | `[]` |
|
| `controllerManager.identities.clusterSPIFFEIDs.default.dnsNameTemplates` | DNS name template for issued identities | `[]` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.default.federatesWith` | Other Spire server URLs for identity federation | `[]` |
|
| `controllerManager.identities.clusterSPIFFEIDs.default.federatesWith` | Other Spire server URLs for identity federation | `[]` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.default.workloadSelectorTemplates` | Templates to produce selectors that apply to a given workload before it will receive an ID | `[]` |
|
| `controllerManager.identities.clusterSPIFFEIDs.default.workloadSelectorTemplates` | Templates to produce selectors that apply to a given workload before it will receive an ID | `[]` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.default.ttl` | Indicates an upper-bound time-to-live for X509 SVIDs. If unset, the cluster default will be chosen. | `""` |
|
| `controllerManager.identities.clusterSPIFFEIDs.default.ttl` | Indicates an upper-bound time-to-live for X509 SVIDs. If unset, the cluster default will be chosen. | `""` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.default.jwtTTL` | Indicates an upper-bound time-to-live for JWT SVIDs. If unset, the cluster default will be chosen. | `""` |
|
| `controllerManager.identities.clusterSPIFFEIDs.default.jwtTTL` | Indicates an upper-bound time-to-live for JWT SVIDs. If unset, the cluster default will be chosen. | `""` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.default.admin` | Indicates any pod matched by this identity will be an admin. Use this with extreme care. | `false` |
|
| `controllerManager.identities.clusterSPIFFEIDs.default.admin` | Indicates any pod matched by this identity will be an admin. Use this with extreme care. | `false` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.default.downstream` | Set if this spire instance is a root server and the workloads are downstream servers. | `false` |
|
| `controllerManager.identities.clusterSPIFFEIDs.default.downstream` | Set if this spire instance is a root server and the workloads are downstream servers. | `false` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.default.autoPopulateDNSNames` | Auto populate DNS names from services attached to pods | `false` |
|
| `controllerManager.identities.clusterSPIFFEIDs.default.autoPopulateDNSNames` | Auto populate DNS names from services attached to pods | `false` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.default.fallback` | Apply this ID only if there are no other matching non fallback ClusterSPIFFEIDs | `true` |
|
| `controllerManager.identities.clusterSPIFFEIDs.default.fallback` | Apply this ID only if there are no other matching non fallback ClusterSPIFFEIDs | `true` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.child-servers.enabled` | Enable this identity for controller manager | `false` |
|
| `controllerManager.identities.clusterSPIFFEIDs.child-servers.enabled` | Enable this identity for controller manager | `false` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.child-servers.type` | The type of rule this is. | `child-servers` |
|
| `controllerManager.identities.clusterSPIFFEIDs.child-servers.type` | The type of rule this is. | `child-servers` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.child-servers.downstream` | Set if this spire instance is a root server and the workloads are downstream servers. | `true` |
|
| `controllerManager.identities.clusterSPIFFEIDs.child-servers.downstream` | Set if this spire instance is a root server and the workloads are downstream servers. | `true` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.enabled` | Enable this identity for controller manager | `true` |
|
| `controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.enabled` | Enable this identity for controller manager | `true` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.type` | The type of rule this is. | `oidc-discovery-provider` |
|
| `controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.type` | The type of rule this is. | `oidc-discovery-provider` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.autoPopulateDNSNames` | Auto populate DNS names to the discovery provider | `true` |
|
| `controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.autoPopulateDNSNames` | Auto populate DNS names to the discovery provider | `true` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.dnsNameTemplates` | DNS name template for issued identities | `[]` |
|
| `controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.dnsNameTemplates` | DNS name template for issued identities | `[]` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.test-keys.enabled` | Enable this identity for controller manager | `true` |
|
| `controllerManager.identities.clusterSPIFFEIDs.test-keys.enabled` | Enable this identity for controller manager | `true` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.test-keys.type` | The type of rule this is. | `test-keys` |
|
| `controllerManager.identities.clusterSPIFFEIDs.test-keys.type` | The type of rule this is. | `test-keys` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.enabled` | Enable this identity for controller manager | `true` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.enabled` | Enable this identity for controller manager | `true` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.type` | The type of rule this is. | `spike-keeper` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.type` | The type of rule this is. | `spike-keeper` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/keeper/{{ .PodMeta.Name }}` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/keeper/{{ .PodMeta.Name }}` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.enabled` | Enable this identity for controller manager | `true` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.enabled` | Enable this identity for controller manager | `true` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.type` | The type of rule this is. | `spike-nexus` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.type` | The type of rule this is. | `spike-nexus` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/nexus/{{ .PodMeta.Name }}` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/nexus/{{ .PodMeta.Name }}` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.spike-bootstrap.enabled` | Enable this identity for controller manager | `true` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-bootstrap.enabled` | Enable this identity for controller manager | `true` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.spike-bootstrap.type` | The type of rule this is. | `spike-bootstrap` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-bootstrap.type` | The type of rule this is. | `spike-bootstrap` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.spike-bootstrap.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/bootstrap/{{ .PodMeta.Name }}` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-bootstrap.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/bootstrap/{{ .PodMeta.Name }}` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.enabled` | Enable this identity for controller manager | `true` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.enabled` | Enable this identity for controller manager | `true` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.type` | The type of rule this is. | `spike-pilot` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.type` | The type of rule this is. | `spike-pilot` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/pilot/role/superuser` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/pilot/role/superuser` |
|
||||||
| `controllerManager.identities.clusterStaticEntries` | Specify ClusterStaticEntry objects. | `{}` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.enabled` | Enable this identity for controller manager | `false` |
|
||||||
| `controllerManager.identities.clusterFederatedTrustDomains` | Specify ClusterFederatedTrustDomain objects. | `{}` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.type` | The type of rule this is. | `spire-ha-agent` |
|
||||||
| `controllerManager.validatingWebhookConfiguration.enabled` | Disable only when you have another chart instance on the k8s cluster with webhooks enabled. | `true` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spire-ha-agent` |
|
||||||
| `controllerManager.validatingWebhookConfiguration.failurePolicy` | Action when identity is not issued | `Fail` |
|
| `controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.federatesWith` | Federated trust domains to pass to the workload | `["spire-ha"]` |
|
||||||
| `controllerManager.cacheNamespaces` | If specified restricts the manager's cache to watch objects in the desired namespaces. Defaults to all namespaces. | `{}` |
|
| `controllerManager.identities.clusterStaticEntries` | Specify ClusterStaticEntry objects. | `{}` |
|
||||||
| `externalControllerManagers.enabled` | Flag to enable external controller managers | `false` |
|
| `controllerManager.identities.clusterFederatedTrustDomains` | Specify ClusterFederatedTrustDomain objects. | `{}` |
|
||||||
| `externalControllerManagers.defaults.reconcile.clusterSPIFFEIDs` | Enable reconciliation of clusterSPIFFEIDs from K8s to the SPIRE server | `true` |
|
| `controllerManager.validatingWebhookConfiguration.enabled` | Disable only when you have another chart instance on the k8s cluster with webhooks enabled. | `true` |
|
||||||
| `externalControllerManagers.defaults.reconcile.clusterStaticEntries` | Enable reconciliation of clusterStaticEntries from K8s to the SPIRE server | `false` |
|
| `controllerManager.validatingWebhookConfiguration.failurePolicy` | Action when identity is not issued | `Fail` |
|
||||||
| `externalControllerManagers.defaults.reconcile.clusterFederatedTrustDomains` | Enable reconciliation of clusterFederatedTrustDomains from K8s to the SPIRE server | `false` |
|
| `controllerManager.cacheNamespaces` | If specified restricts the manager's cache to watch objects in the desired namespaces. Defaults to all namespaces. | `{}` |
|
||||||
| `externalControllerManagers.defaults.className` | specify to use an explicit class name. If empty, it will be automatically set to Release.Namespace-Release.Name to not conflict with other installs, enabling parallel installs. | `""` |
|
| `externalControllerManagers.enabled` | Flag to enable external controller managers | `false` |
|
||||||
| `externalControllerManagers.defaults.watchClassless` | specify to process custom resources without class name specified. Useful to slowly migrate to class names from classless installs. Do not have two installs on the same k8s cluster both set to true. | `false` |
|
| `externalControllerManagers.defaults.reconcile.clusterSPIFFEIDs` | Enable reconciliation of clusterSPIFFEIDs from K8s to the SPIRE server | `true` |
|
||||||
| `externalControllerManagers.defaults.entryIDPrefixCleanup` | consult the spiffe.io docs about this option before changing. Its unlikely you will need to ever change it. | `false` |
|
| `externalControllerManagers.defaults.reconcile.clusterStaticEntries` | Enable reconciliation of clusterStaticEntries from K8s to the SPIRE server | `false` |
|
||||||
| `externalControllerManagers.defaults.parentIDTemplate` | The template that is used to register workloads. | `spiffe://{{ .TrustDomain }}/spire/agent/k8s_psat/{{ .ClusterName }}/{{ .NodeMeta.UID }}` |
|
| `externalControllerManagers.defaults.reconcile.clusterFederatedTrustDomains` | Enable reconciliation of clusterFederatedTrustDomains from K8s to the SPIRE server | `false` |
|
||||||
| `externalControllerManagers.defaults.leaderElection.leaseDuration` | Duration that non-leader candidates will wait to force acquire leadership. Increase this in high-load clusters to reduce API server pressure. | `15s` |
|
| `externalControllerManagers.defaults.className` | specify to use an explicit class name. If empty, it will be automatically set to Release.Namespace-Release.Name to not conflict with other installs, enabling parallel installs. | `""` |
|
||||||
| `externalControllerManagers.defaults.leaderElection.renewDeadline` | Duration the acting leader will retry refreshing leadership before giving up. Must be less than leaseDuration. | `10s` |
|
| `externalControllerManagers.defaults.watchClassless` | specify to process custom resources without class name specified. Useful to slowly migrate to class names from classless installs. Do not have two installs on the same k8s cluster both set to true. | `false` |
|
||||||
| `externalControllerManagers.defaults.leaderElection.retryPeriod` | Duration the LeaderElector clients should wait between tries of actions. Must be less than renewDeadline. | `2s` |
|
| `externalControllerManagers.defaults.entryIDPrefixCleanup` | consult the spiffe.io docs about this option before changing. Its unlikely you will need to ever change it. | `false` |
|
||||||
| `externalControllerManagers.defaults.expandEnv` | Set to true to enable environment variable substitution of config file options | `false` |
|
| `externalControllerManagers.defaults.parentIDTemplate` | The template that is used to register workloads. | `spiffe://{{ .TrustDomain }}/spire/agent/k8s_psat/{{ .ClusterName }}/{{ .NodeMeta.UID }}` |
|
||||||
| `externalControllerManagers.defaults.extraEnv` | Extra environment variables to add to the controller manager | `[]` |
|
| `externalControllerManagers.defaults.leaderElection.leaseDuration` | Duration that non-leader candidates will wait to force acquire leadership. Increase this in high-load clusters to reduce API server pressure. | `15s` |
|
||||||
| `externalControllerManagers.defaults.resources` | Resource requests and limits for controller manager | `{}` |
|
| `externalControllerManagers.defaults.leaderElection.renewDeadline` | Duration the acting leader will retry refreshing leadership before giving up. Must be less than leaseDuration. | `10s` |
|
||||||
| `externalControllerManagers.defaults.securityContext` | Security context | `{}` |
|
| `externalControllerManagers.defaults.leaderElection.retryPeriod` | Duration the LeaderElector clients should wait between tries of actions. Must be less than renewDeadline. | `2s` |
|
||||||
| `externalControllerManagers.defaults.configMap.annotations` | Annotations to add to the Controller Manager ConfigMap | `{}` |
|
| `externalControllerManagers.defaults.expandEnv` | Set to true to enable environment variable substitution of config file options | `false` |
|
||||||
| `externalControllerManagers.defaults.ignoreNamespaces` | These namespaces are ignored by controller manager | `[]` |
|
| `externalControllerManagers.defaults.extraEnv` | Extra environment variables to add to the controller manager | `[]` |
|
||||||
| `externalControllerManagers.defaults.cacheNamespaces` | If specified restricts the manager's cache to watch objects in the desired namespaces. Defaults to all namespaces. | `{}` |
|
| `externalControllerManagers.defaults.resources` | Resource requests and limits for controller manager | `{}` |
|
||||||
| `externalControllerManagers.clusters` | A dictionary of clusters to add with optional overrides (kubeConfigName, reconcile, healthPortName, prometheusPortName). If empty, all clusters defined in kubeConfigs will be used. | `{}` |
|
| `externalControllerManagers.defaults.securityContext` | Security context | `{}` |
|
||||||
| `tools.kubectl.image.registry` | The OCI registry to pull the image from | `registry.k8s.io` |
|
| `externalControllerManagers.defaults.configMap.annotations` | Annotations to add to the Controller Manager ConfigMap | `{}` |
|
||||||
| `tools.kubectl.image.repository` | The repository within the registry | `kubectl` |
|
| `externalControllerManagers.defaults.ignoreNamespaces` | These namespaces are ignored by controller manager | `[]` |
|
||||||
| `tools.kubectl.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
| `externalControllerManagers.defaults.cacheNamespaces` | If specified restricts the manager's cache to watch objects in the desired namespaces. Defaults to all namespaces. | `{}` |
|
||||||
| `tools.kubectl.image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
|
| `externalControllerManagers.clusters` | A dictionary of clusters to add with optional overrides (kubeConfigName, reconcile, healthPortName, prometheusPortName). If empty, all clusters defined in kubeConfigs will be used. | `{}` |
|
||||||
| `tools.busybox.image.registry` | The OCI registry to pull the image from | `""` |
|
| `tools.kubectl.image.registry` | The OCI registry to pull the image from | `registry.k8s.io` |
|
||||||
| `tools.busybox.image.repository` | The repository within the registry | `busybox` |
|
| `tools.kubectl.image.repository` | The repository within the registry | `kubectl` |
|
||||||
| `tools.busybox.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
| `tools.kubectl.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
| `tools.busybox.image.tag` | Overrides the image tag whose default is the chart appVersion | `1.37.0-uclibc` |
|
| `tools.kubectl.image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
|
||||||
| `telemetry.prometheus.enabled` | Flag to enable prometheus monitoring | `false` |
|
| `tools.busybox.image.registry` | The OCI registry to pull the image from | `""` |
|
||||||
| `telemetry.prometheus.podMonitor.enabled` | Enable podMonitor for prometheus | `false` |
|
| `tools.busybox.image.repository` | The repository within the registry | `busybox` |
|
||||||
| `telemetry.prometheus.podMonitor.namespace` | Override where to install the podMonitor, if not set will use the same namespace as the spire-agent | `""` |
|
| `tools.busybox.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
| `telemetry.prometheus.podMonitor.labels` | Pod labels to filter for prometheus monitoring | `{}` |
|
| `tools.busybox.image.tag` | Overrides the image tag whose default is the chart appVersion | `1.37.0-uclibc` |
|
||||||
| `telemetry.datadog.enabled` | Flag to enable datadog monitoring | `false` |
|
| `telemetry.prometheus.enabled` | Flag to enable prometheus monitoring | `false` |
|
||||||
| `telemetry.datadog.address` | The address of the datadog service to send metrics to. The default URL for services are `<service-name>.<namespace>.svc` | `datadog.kube-system.svc` |
|
| `telemetry.prometheus.podMonitor.enabled` | Enable podMonitor for prometheus | `false` |
|
||||||
| `telemetry.datadog.port` | The port of the datadog service to send metrics to | `8125` |
|
| `telemetry.prometheus.podMonitor.namespace` | Override where to install the podMonitor, if not set will use the same namespace as the spire-agent | `""` |
|
||||||
| `ingress.enabled` | Flag to enable ingress | `false` |
|
| `telemetry.prometheus.podMonitor.labels` | Pod labels to filter for prometheus monitoring | `{}` |
|
||||||
| `ingress.className` | Ingress class name | `""` |
|
| `telemetry.datadog.enabled` | Flag to enable datadog monitoring | `false` |
|
||||||
| `ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, autodetection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` |
|
| `telemetry.datadog.address` | The address of the datadog service to send metrics to. The default URL for services are `<service-name>.<namespace>.svc` | `datadog.kube-system.svc` |
|
||||||
| `ingress.annotations` | Annotations for the ingress object | `{}` |
|
| `telemetry.datadog.port` | The port of the datadog service to send metrics to | `8125` |
|
||||||
| `ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `spire-server` |
|
| `ingress.enabled` | Flag to enable ingress | `false` |
|
||||||
| `ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` |
|
| `ingress.className` | Ingress class name | `""` |
|
||||||
| `ingress.hosts` | Host paths for ingress object. If empty, rules will be built based on the host var. | `[]` |
|
| `ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, autodetection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` |
|
||||||
| `ingress.tls` | Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. | `[]` |
|
| `ingress.annotations` | Annotations for the ingress object | `{}` |
|
||||||
| `extraEnv` | Extra environment variables to add to the spire server | `[]` |
|
| `ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `spire-server` |
|
||||||
| `extraVolumes` | Extra volumes to be mounted | `[]` |
|
| `ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` |
|
||||||
| `extraVolumeMounts` | Extra volume mounts | `[]` |
|
| `ingress.hosts` | Host paths for ingress object. If empty, rules will be built based on the host var. | `[]` |
|
||||||
| `extraContainers` | Additional containers to create | `[]` |
|
| `ingress.tls` | Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. | `[]` |
|
||||||
| `initContainers` | Additional init containers to create | `[]` |
|
| `extraEnv` | Extra environment variables to add to the spire server | `[]` |
|
||||||
| `caKeyType` | The CA key type to use, possible values are rsa-2048, rsa-4096, ec-p256, ec-p384 (AWS requires the use of RSA. EC cryptography is not supported) | `rsa-2048` |
|
| `extraVolumes` | Extra volumes to be mounted | `[]` |
|
||||||
| `caTTL` | TTL for CA | `24h` |
|
| `extraVolumeMounts` | Extra volume mounts | `[]` |
|
||||||
| `agentTTL` | The TTL to use for agent SVIDs. If unset, the defaultX509SvidTTL will be used. | `""` |
|
| `extraContainers` | Additional containers to create | `[]` |
|
||||||
| `defaultX509SvidTTL` | TTL for X509 Svids | `4h` |
|
| `initContainers` | Additional init containers to create | `[]` |
|
||||||
| `defaultJwtSvidTTL` | TTL for JWT Svids | `1h` |
|
| `caKeyType` | The CA key type to use, possible values are rsa-2048, rsa-4096, ec-p256, ec-p384 (AWS requires the use of RSA. EC cryptography is not supported) | `rsa-2048` |
|
||||||
| `rateLimit.attestation` | Enable rate limiting for node attestation. When true, rate limits node attestation to 1 per second globally. Set to false to disable. | `true` |
|
| `caTTL` | TTL for CA | `24h` |
|
||||||
| `rateLimit.signing` | Enable rate limiting for SVID signing (BatchNewX509SVID, BatchNewJWTSVID). When true, rate limits signing to 500 requests per second per server pod. Set to false to disable. Disabling is appropriate when running many replicas or during thundering-herd recovery. | `true` |
|
| `agentTTL` | The TTL to use for agent SVIDs. If unset, the defaultX509SvidTTL will be used. | `""` |
|
||||||
| `pruneAttestedNodesExpiredFor` | Enables periodic pruning of attested node entries with expired SVIDs. Set to a duration (e.g. "168h" for 7 days) to prune nodes that expired longer ago than the specified duration. Set to "" (empty) to disable pruning. When enabled, expired nodes are pruned at a regular interval. | `""` |
|
| `defaultX509SvidTTL` | TTL for X509 Svids | `4h` |
|
||||||
| `pruneTOFUNodes` | If true, includes non-reattestable (TOFU) nodes in the pruning process when pruneAttestedNodesExpiredFor is set. Banned nodes are never pruned. | `false` |
|
| `defaultJwtSvidTTL` | TTL for JWT Svids | `1h` |
|
||||||
| `maxAttestedNodeInfoStaleness` | How long to trust stale cache information about attested nodes. Set to "" to use the SPIRE default (0s). Increasing this can improve performance under high load by reducing datastore reads, at the cost of acting on slightly stale node state. Accepts Go duration strings (e.g. "10s", "1m"). | `""` |
|
| `rateLimit.attestation` | Enable rate limiting for node attestation. When true, rate limits node attestation to 1 per second globally. Set to false to disable. | `true` |
|
||||||
| `nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s nodeattestor | `true` |
|
| `rateLimit.signing` | Enable rate limiting for SVID signing (BatchNewX509SVID, BatchNewJWTSVID). When true, rate limits signing to 500 requests per second per server pod. Set to false to disable. Disabling is appropriate when running many replicas or during thundering-herd recovery. | `true` |
|
||||||
| `nodeAttestor.k8sPSAT.serviceAccountAllowList` | Allowed service accounts for PSAT nodeattestor. If namespace isn't specified, release namespace will be used. | `[]` |
|
| `pruneAttestedNodesExpiredFor` | Enables periodic pruning of attested node entries with expired SVIDs. Set to a duration (e.g. "168h" for 7 days) to prune nodes that expired longer ago than the specified duration. Set to "" (empty) to disable pruning. When enabled, expired nodes are pruned at a regular interval. | `""` |
|
||||||
| `nodeAttestor.k8sPSAT.audience` | Audience for token validation. If set to [] (empty array), Kubernetes API server audience is used | `[]` |
|
| `pruneTOFUNodes` | If true, includes non-reattestable (TOFU) nodes in the pruning process when pruneAttestedNodesExpiredFor is set. Banned nodes are never pruned. | `false` |
|
||||||
| `nodeAttestor.k8sPSAT.allowedNodeLabelKeys` | Node label keys considered for selectors | `[]` |
|
| `maxAttestedNodeInfoStaleness` | How long to trust stale cache information about attested nodes. Set to "" to use the SPIRE default (0s). Increasing this can improve performance under high load by reducing datastore reads, at the cost of acting on slightly stale node state. Accepts Go duration strings (e.g. "10s", "1m"). | `""` |
|
||||||
| `nodeAttestor.k8sPSAT.allowedPodLabelKeys` | Pod label keys considered for selectors | `[]` |
|
| `nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s nodeattestor | `true` |
|
||||||
| `nodeAttestor.externalK8sPSAT.enabled` | Enable PSAT k8s nodeattestor for external Kubernetes clusters | `true` |
|
| `nodeAttestor.k8sPSAT.serviceAccountAllowList` | Allowed service accounts for PSAT nodeattestor. If namespace isn't specified, release namespace will be used. | `[]` |
|
||||||
| `nodeAttestor.externalK8sPSAT.defaults.serviceAccountAllowList` | Allowed service accounts for PSAT node attestor | `[]` |
|
| `nodeAttestor.k8sPSAT.audience` | Audience for token validation. If set to [] (empty array), Kubernetes API server audience is used | `[]` |
|
||||||
| `nodeAttestor.externalK8sPSAT.defaults.audience` | Audience for token validation. If it is set to an empty array ([]), Kubernetes API server audience is used | `[]` |
|
| `nodeAttestor.k8sPSAT.allowedNodeLabelKeys` | Node label keys considered for selectors | `[]` |
|
||||||
| `nodeAttestor.externalK8sPSAT.defaults.allowedNodeLabelKeys` | Node label keys considered for selectors | `[]` |
|
| `nodeAttestor.k8sPSAT.allowedPodLabelKeys` | Pod label keys considered for selectors | `[]` |
|
||||||
| `nodeAttestor.externalK8sPSAT.defaults.allowedPodLabelKeys` | Pod label keys considered for selectors | `[]` |
|
| `nodeAttestor.externalK8sPSAT.enabled` | Enable PSAT k8s nodeattestor for external Kubernetes clusters | `true` |
|
||||||
| `nodeAttestor.externalK8sPSAT.clusters` | A dictionary of clusters to add with optional overrides. If empty, all clusters defined in kubeConfigs will be used. | `{}` |
|
| `nodeAttestor.externalK8sPSAT.defaults.serviceAccountAllowList` | Allowed service accounts for PSAT node attestor | `[]` |
|
||||||
| `nodeAttestor.joinToken.enabled` | Enable the join_token nodeattestor | `false` |
|
| `nodeAttestor.externalK8sPSAT.defaults.audience` | Audience for token validation. If it is set to an empty array ([]), Kubernetes API server audience is used | `[]` |
|
||||||
| `nodeAttestor.httpChallenge.enabled` | Enable the http_challenge nodeattesto | `false` |
|
| `nodeAttestor.externalK8sPSAT.defaults.allowedNodeLabelKeys` | Node label keys considered for selectors | `[]` |
|
||||||
| `nodeAttestor.httpChallenge.allowedDNSPatterns` | A list of regular expressions to match to the hostname being attested. If none match, attestation will fail. If a blank list, all hostnames are allowed. | `[]` |
|
| `nodeAttestor.externalK8sPSAT.defaults.allowedPodLabelKeys` | Pod label keys considered for selectors | `[]` |
|
||||||
| `nodeAttestor.httpChallenge.requiredPort` | Set to a port number to require clients to listen only on that port. If 0, all port numbers are allowed | `0` |
|
| `nodeAttestor.externalK8sPSAT.clusters` | A dictionary of clusters to add with optional overrides. If empty, all clusters defined in kubeConfigs will be used. | `{}` |
|
||||||
| `nodeAttestor.httpChallenge.allowNonRootPorts` | Allow using ports >= 1024 from clients for attestation | `true` |
|
| `nodeAttestor.joinToken.enabled` | Enable the join_token nodeattestor | `false` |
|
||||||
| `nodeAttestor.httpChallenge.tofu` | Trust on first use of the successful challenge. Can only be disabled if allowNonRootPorts=false or requiredPort < 1024 | `true` |
|
| `nodeAttestor.httpChallenge.enabled` | Enable the http_challenge nodeattesto | `false` |
|
||||||
| `nodeAttestor.tpmDirect.enabled` | Enable the direct TPM node attestor, a 3rd party plugin by Boxboat. This plugin is experimental. | `false` |
|
| `nodeAttestor.httpChallenge.allowedDNSPatterns` | A list of regular expressions to match to the hostname being attested. If none match, attestation will fail. If a blank list, all hostnames are allowed. | `[]` |
|
||||||
| `nodeAttestor.tpmDirect.image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
| `nodeAttestor.httpChallenge.requiredPort` | Set to a port number to require clients to listen only on that port. If 0, all port numbers are allowed | `0` |
|
||||||
| `nodeAttestor.tpmDirect.image.repository` | The repository within the registry | `spiffe/spire-tpm-plugin-tpm-attestor-server` |
|
| `nodeAttestor.httpChallenge.allowNonRootPorts` | Allow using ports >= 1024 from clients for attestation | `true` |
|
||||||
| `nodeAttestor.tpmDirect.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
| `nodeAttestor.httpChallenge.tofu` | Trust on first use of the successful challenge. Can only be disabled if allowNonRootPorts=false or requiredPort < 1024 | `true` |
|
||||||
| `nodeAttestor.tpmDirect.image.tag` | Overrides the image tag | `v1.9.0` |
|
| `nodeAttestor.tpmDirect.enabled` | Enable the direct TPM node attestor, a 3rd party plugin by Boxboat. This plugin is experimental. | `false` |
|
||||||
| `nodeAttestor.tpmDirect.checksum` | The sha256 checksum of the plugin binary | `46d0caad8c25a027dd11c93e18b58a8bc6fbd9f1fe2e36fa2a0dd440986de4dc` |
|
| `nodeAttestor.tpmDirect.image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
||||||
| `nodeAttestor.tpmDirect.pluginPath` | The filename in the container of the plugin | `/app/tpm_attestor_server` |
|
| `nodeAttestor.tpmDirect.image.repository` | The repository within the registry | `spiffe/spire-tpm-plugin-tpm-attestor-server` |
|
||||||
| `nodeAttestor.tpmDirect.cas` | A dictionary of TPM CA PEM or DER files that are allowed to connect. | `{}` |
|
| `nodeAttestor.tpmDirect.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
| `nodeAttestor.tpmDirect.hashes` | A list of TPM hashes that are allowed to connect. | `[]` |
|
| `nodeAttestor.tpmDirect.image.tag` | Overrides the image tag | `v1.9.0` |
|
||||||
| `nodeAttestor.awsIID.enabled` | Enable the aws_iid node attestor | `false` |
|
| `nodeAttestor.tpmDirect.checksum` | The sha256 checksum of the plugin binary | `46d0caad8c25a027dd11c93e18b58a8bc6fbd9f1fe2e36fa2a0dd440986de4dc` |
|
||||||
| `nodeAttestor.awsIID.assumeRole` | AWS IAM Role NAME to use for the attestation | `""` |
|
| `nodeAttestor.tpmDirect.pluginPath` | The filename in the container of the plugin | `/app/tpm_attestor_server` |
|
||||||
| `nodeAttestor.awsIID.verifyOrganization` | When enabled, SPIRE verifies the attesting node's AWS account is a member of your AWS Organization ([SPIRE aws_iid server plugin](https://github.com/spiffe/spire/blob/main/doc/plugin_server_nodeattestor_aws_iid.md)). | |
|
| `nodeAttestor.tpmDirect.cas` | A dictionary of TPM CA PEM or DER files that are allowed to connect. | `{}` |
|
||||||
| `nodeAttestor.awsIID.verifyOrganization.enabled` | Enable AWS Organizations membership validation (`verify_organization` in plugin config) | `false` |
|
| `nodeAttestor.tpmDirect.hashes` | A list of TPM hashes that are allowed to connect. | `[]` |
|
||||||
| `nodeAttestor.awsIID.verifyOrganization.managementAccountId` | AWS Organizations management/root account ID (12 digits); SPIRE assumes `arn:aws:iam::<managementAccountId>:role/<assumeOrgRole>` for listing org accounts. | `""` |
|
| `nodeAttestor.awsIID.enabled` | Enable the aws_iid node attestor | `false` |
|
||||||
| `nodeAttestor.awsIID.verifyOrganization.assumeOrgRole` | IAM role **name** in the management account; must allow `organizations:ListAccounts` and trust the IAM identity used by the SPIRE server. | `""` |
|
| `nodeAttestor.awsIID.assumeRole` | AWS IAM Role NAME to use for the attestation | `""` |
|
||||||
| `nodeAttestor.awsIID.verifyOrganization.managementAccountRegion` | Optional region SPIRE uses for org validation/cache keying (defaults in SPIRE if unset). | `""` |
|
| `nodeAttestor.awsIID.verifyOrganization` | When enabled, SPIRE verifies the attesting node's AWS account is a member of your AWS Organization ([SPIRE aws_iid server plugin](https://github.com/spiffe/spire/blob/main/doc/plugin_server_nodeattestor_aws_iid.md)). | |
|
||||||
| `nodeAttestor.awsIID.verifyOrganization.orgAccountMapTTL` | Optional cache TTL for the org account map (SPIRE expects a duration ≥ 1m when set; e.g. `3m`, `5m`). Defaults to 3 minutes. | `3m` |
|
| `nodeAttestor.awsIID.verifyOrganization.enabled` | Enable AWS Organizations membership validation (`verify_organization` in plugin config) | `false` |
|
||||||
| `nodeAttestor.gcpIIT.enabled` | Enable the gcp_iit node attestor | `false` |
|
| `nodeAttestor.awsIID.verifyOrganization.managementAccountId` | AWS Organizations management/root account ID (12 digits); SPIRE assumes `arn:aws:iam::<managementAccountId>:role/<assumeOrgRole>` for listing org accounts. | `""` |
|
||||||
| `nodeAttestor.gcpIIT.projectIDAllowList` | List of ProjectIDs from which nodes can be attested | `[]` |
|
| `nodeAttestor.awsIID.verifyOrganization.assumeOrgRole` | IAM role **name** in the management account; must allow `organizations:ListAccounts` and trust the IAM identity used by the SPIRE server. | `""` |
|
||||||
| `nodeAttestor.gcpIIT.useInstanceMetadata` | If true, instance metadata is fetched from the Google Compute Engine API and used to augment the node selectors produced by the plugin | `false` |
|
| `nodeAttestor.awsIID.verifyOrganization.managementAccountRegion` | Optional region SPIRE uses for org validation/cache keying (defaults in SPIRE if unset). | `""` |
|
||||||
| `nodeAttestor.gcpIIT.allowedLabelKeys` | Instance label keys considered for selectors | `[]` |
|
| `nodeAttestor.awsIID.verifyOrganization.orgAccountMapTTL` | Optional cache TTL for the org account map (SPIRE expects a duration ≥ 1m when set; e.g. `3m`, `5m`). Defaults to 3 minutes. | `3m` |
|
||||||
| `nodeAttestor.gcpIIT.allowedMetadataKeys` | Instance metadata keys considered for selectors | `[]` |
|
| `nodeAttestor.gcpIIT.enabled` | Enable the gcp_iit node attestor | `false` |
|
||||||
| `nodeAttestor.gcpIIT.metadataValueMaxSize` | Sets the maximum metadata value size considered by the plugin for selectors | `0` |
|
| `nodeAttestor.gcpIIT.projectIDAllowList` | List of ProjectIDs from which nodes can be attested | `[]` |
|
||||||
| `nodeAttestor.gcpIIT.agentPathTemplate` | A URL path portion format of Agent's SPIFFE ID. Describe in text/template format. | `""` |
|
| `nodeAttestor.gcpIIT.useInstanceMetadata` | If true, instance metadata is fetched from the Google Compute Engine API and used to augment the node selectors produced by the plugin | `false` |
|
||||||
| `bundlePublisher.k8sConfigMap.enabled` | Enable local k8s bundle uploader | `true` |
|
| `nodeAttestor.gcpIIT.allowedLabelKeys` | Instance label keys considered for selectors | `[]` |
|
||||||
| `bundlePublisher.k8sConfigMap.namespace` | Namespace to push the bundle into, if blank will default to SPIRE Server namespace | `""` |
|
| `nodeAttestor.gcpIIT.allowedMetadataKeys` | Instance metadata keys considered for selectors | `[]` |
|
||||||
| `bundlePublisher.k8sConfigMap.format` | Format of the trust bundle. Can be pem or spiffe | `spiffe` |
|
| `nodeAttestor.gcpIIT.metadataValueMaxSize` | Sets the maximum metadata value size considered by the plugin for selectors | `0` |
|
||||||
| `bundlePublisher.externalK8sConfigMap.enabled` | Enable external k8s bundle uploader | `true` |
|
| `nodeAttestor.gcpIIT.agentPathTemplate` | A URL path portion format of Agent's SPIFFE ID. Describe in text/template format. | `""` |
|
||||||
| `bundlePublisher.externalK8sConfigMap.defaults.namespace` | Namespace to push the bundle into on clusters | `spire-system` |
|
| `nodeAttestor.x509POP.enabled` | Enable the x509_popg node attestor | `false` |
|
||||||
| `bundlePublisher.externalK8sConfigMap.defaults.configMapName` | ConfigMap name to push the bundle into on external clusters | `spire-bundle-upstream` |
|
| `nodeAttestor.x509POP.mode` | What mode to set the plugin to. Currently only spiffe mode is supported | `spiffe` |
|
||||||
| `bundlePublisher.externalK8sConfigMap.defaults.configMapKey` | ConfigMap key to push the bundle into on external clusters | `""` |
|
| `nodeAttestor.x509POP.svidPrefix` | What prefix to use when mode is spiffe | `/spire-exchange` |
|
||||||
| `bundlePublisher.externalK8sConfigMap.defaults.format` | Format of the trust bundle. Can be pem or spiffe | `spiffe` |
|
| `nodeAttestor.x509POP.agentPathTemplate` | Override the default agent path template | `""` |
|
||||||
| `bundlePublisher.externalK8sConfigMap.clusters` | A dictionary of clusters to add with optional overrides. If empty, all clusters defined in kubeConfigs will be used. | `{}` |
|
| `nodeAttestor.x509POP.maxIntermediates` | Maximum number of intermediate certificates allowed in the certificate chain | `4` |
|
||||||
| `bundlePublisher.awsRolesAnywhereTrustAnchor.enabled` | Enable the AWS S3 bundle publisher | `false` |
|
| `nodeAttestor.x509POP.maxRSAKeySize` | Maximum RSA key size in bits allowed in certificates | `8192` |
|
||||||
| `bundlePublisher.awsRolesAnywhereTrustAnchor.region` | AWS region to store the trust bundle | `""` |
|
| `nodeAttestor.x509POP.addClusterName.svidPrefix` | Suffix the cluster name onto the svidPrefix | `false` |
|
||||||
| `bundlePublisher.awsRolesAnywhereTrustAnchor.trustAnchorID` | AWS trust anchor ID to publish to | `""` |
|
| `nodeAttestor.x509POP.addClusterName.agentPathTemplate` | Suffix the cluster name onto the agentPathTemplate | `false` |
|
||||||
| `bundlePublisher.awsS3.enabled` | Enable the AWS S3 bundle publisher | `false` |
|
| `bundlePublisher.k8sConfigMap.enabled` | Enable local k8s bundle uploader | `true` |
|
||||||
| `bundlePublisher.awsS3.endpoint` | A custom S3 endpoint should be set when using third-party object storage providers, such as Minio. | `""` |
|
| `bundlePublisher.k8sConfigMap.namespace` | Namespace to push the bundle into, if blank will default to SPIRE Server namespace | `""` |
|
||||||
| `bundlePublisher.awsS3.region` | AWS region to store the trust bundle | `""` |
|
| `bundlePublisher.k8sConfigMap.format` | Format of the trust bundle. Can be pem or spiffe | `spiffe` |
|
||||||
| `bundlePublisher.awsS3.bucket` | AWS S3 bucket name to which the trust bundle is uploaded | `""` |
|
| `bundlePublisher.externalK8sConfigMap.enabled` | Enable external k8s bundle uploader | `true` |
|
||||||
| `bundlePublisher.awsS3.objectKey` | AWS S3 object key inside the bucket | `""` |
|
| `bundlePublisher.externalK8sConfigMap.defaults.namespace` | Namespace to push the bundle into on clusters | `spire-system` |
|
||||||
| `bundlePublisher.awsS3.format` | Format in which the trust bundle is stored. Valid options [spiffe, jwks, pem] | `""` |
|
| `bundlePublisher.externalK8sConfigMap.defaults.configMapName` | ConfigMap name to push the bundle into on external clusters | `spire-bundle-upstream` |
|
||||||
| `bundlePublisher.gcpCloudStorage.enabled` | Enable the Google Cloud Storage bundle publisher | `false` |
|
| `bundlePublisher.externalK8sConfigMap.defaults.configMapKey` | ConfigMap key to push the bundle into on external clusters | `""` |
|
||||||
| `bundlePublisher.gcpCloudStorage.bucketName` | Google Cloud Storage bucket name to which the trust bundle is uploaded | `""` |
|
| `bundlePublisher.externalK8sConfigMap.defaults.format` | Format of the trust bundle. Can be pem or spiffe | `spiffe` |
|
||||||
| `bundlePublisher.gcpCloudStorage.objectName` | Google Cloud Storage object name | `""` |
|
| `bundlePublisher.externalK8sConfigMap.clusters` | A dictionary of clusters to add with optional overrides. If empty, all clusters defined in kubeConfigs will be used. | `{}` |
|
||||||
| `bundlePublisher.gcpCloudStorage.format` | Format in which the trust bundle is stored. Valid options [spiffe, jwks, pem] | `""` |
|
| `bundlePublisher.awsRolesAnywhereTrustAnchor.enabled` | Enable the AWS S3 bundle publisher | `false` |
|
||||||
|
| `bundlePublisher.awsRolesAnywhereTrustAnchor.region` | AWS region to store the trust bundle | `""` |
|
||||||
|
| `bundlePublisher.awsRolesAnywhereTrustAnchor.trustAnchorID` | AWS trust anchor ID to publish to | `""` |
|
||||||
|
| `bundlePublisher.awsS3.enabled` | Enable the AWS S3 bundle publisher | `false` |
|
||||||
|
| `bundlePublisher.awsS3.endpoint` | A custom S3 endpoint should be set when using third-party object storage providers, such as Minio. | `""` |
|
||||||
|
| `bundlePublisher.awsS3.region` | AWS region to store the trust bundle | `""` |
|
||||||
|
| `bundlePublisher.awsS3.bucket` | AWS S3 bucket name to which the trust bundle is uploaded | `""` |
|
||||||
|
| `bundlePublisher.awsS3.objectKey` | AWS S3 object key inside the bucket | `""` |
|
||||||
|
| `bundlePublisher.awsS3.format` | Format in which the trust bundle is stored. Valid options [spiffe, jwks, pem] | `""` |
|
||||||
|
| `bundlePublisher.gcpCloudStorage.enabled` | Enable the Google Cloud Storage bundle publisher | `false` |
|
||||||
|
| `bundlePublisher.gcpCloudStorage.bucketName` | Google Cloud Storage bucket name to which the trust bundle is uploaded | `""` |
|
||||||
|
| `bundlePublisher.gcpCloudStorage.objectName` | Google Cloud Storage object name | `""` |
|
||||||
|
| `bundlePublisher.gcpCloudStorage.format` | Format in which the trust bundle is stored. Valid options [spiffe, jwks, pem] | `""` |
|
||||||
|
| `dynamicRegistration.enabled` | Deploys the sidecar helper for dynamic registration | `false` |
|
||||||
|
| `dynamicRegistration.image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
||||||
|
| `dynamicRegistration.image.repository` | The repository within the registry | `spiffe/spire-controller-manager-dynamic-registration/spire-controller-manager-dynamic-registration-server` |
|
||||||
|
| `dynamicRegistration.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
|
| `dynamicRegistration.image.tag` | Overrides the image tag to be whatever you need it to be. It will always be the flag you set without modifications | `0.1.0` |
|
||||||
|
| `dynamicRegistration.serviceAccount` | Which service account to allow to register | `spire-agent` |
|
||||||
|
| `dynamicRegistration.audience` | The expected audience | `spire-controller-manager-dynamic-registration` |
|
||||||
|
| `dynamicRegistration.entryPrefix` | Unique prefix to bind nodes aliases to the server | `scmnr` |
|
||||||
|
| `dynamicRegistration.allowedIDPrefix` | Prefix of agents that are allowed to register | `spire/agent/k8s_psat` |
|
||||||
|
| `dynamicRegistration.registrationPrefix` | prefix to use on all new registration entries | `k8s_psat` |
|
||||||
|
| `dynamicRegistration.addClusterName.registrationPrefix` | suffix the cluster name onto the registrationPrefix | `true` |
|
||||||
|
| `dynamicRegistration.addClusterName.allowedIDPrefix` | suffix the cluster name onto the allowedIDPrefix | `true` |
|
||||||
|
| `dynamicRegistration.securityContext` | Security Context to use | `{}` |
|
||||||
|
|
||||||
### Tornjak
|
### Tornjak
|
||||||
|
|
||||||
@@ -515,6 +540,13 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr
|
|||||||
| `secrets.aws.accessKeyID` | AWS Access Key ID | `""` |
|
| `secrets.aws.accessKeyID` | AWS Access Key ID | `""` |
|
||||||
| `secrets.aws.secretAccessKey` | AWS Secret Access Key | `""` |
|
| `secrets.aws.secretAccessKey` | AWS Secret Access Key | `""` |
|
||||||
| `secrets.gcp.applicationCredentials` | Google Application Credentials | `""` |
|
| `secrets.gcp.applicationCredentials` | Google Application Credentials | `""` |
|
||||||
|
| `trustSync.enabled` | Allow configuration of trust syncing | `false` |
|
||||||
|
| `trustSync.domains` | List of trust domains to sync from parent to child servers | `[]` |
|
||||||
|
| `trustSync.image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
||||||
|
| `trustSync.image.repository` | The repository within the registry | `spiffe/spire-ha-agent/spire-trust-sync` |
|
||||||
|
| `trustSync.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
|
| `trustSync.image.tag` | Overrides the image tag to be whatever you need it to be. It will always be the flag you set without modifications | `0.0.21` |
|
||||||
|
| `trustSync.resources` | Resource requests and limits | `{}` |
|
||||||
| `customPlugins.bundlePublisher` | Custom plugins of type BundlePublisher are configured here | `{}` |
|
| `customPlugins.bundlePublisher` | Custom plugins of type BundlePublisher are configured here | `{}` |
|
||||||
| `customPlugins.credentialComposer` | Custom plugins of type CredentialComposer are configured here | `{}` |
|
| `customPlugins.credentialComposer` | Custom plugins of type CredentialComposer are configured here | `{}` |
|
||||||
| `customPlugins.keyManager` | Custom plugins of type KeyManager are configured here | `{}` |
|
| `customPlugins.keyManager` | Custom plugins of type KeyManager are configured here | `{}` |
|
||||||
@@ -527,6 +559,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr
|
|||||||
| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `1.37.0-uclibc` |
|
| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `1.37.0-uclibc` |
|
||||||
| `chown.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` |
|
| `chown.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` |
|
||||||
| `experimental.enabled` | Allow configuration of experimental features | `false` |
|
| `experimental.enabled` | Allow configuration of experimental features | `false` |
|
||||||
|
| `experimental.agentSPIFFEIDAsSelector` | enable adding spiffe_id selectors to all agents | `false` |
|
||||||
| `experimental.cacheReloadInterval` | The amount of time between two reloads of the in-memory entry cache. | `5s` |
|
| `experimental.cacheReloadInterval` | The amount of time between two reloads of the in-memory entry cache. | `5s` |
|
||||||
| `experimental.eventsBasedCache` | Use events to update the cache with what's changed since the last update. | `false` |
|
| `experimental.eventsBasedCache` | Use events to update the cache with what's changed since the last update. | `false` |
|
||||||
| `experimental.pruneEventsOlderThan` | How old an event can be before being deleted. Used with events based cache. | `12h` |
|
| `experimental.pruneEventsOlderThan` | How old an event can be before being deleted. Used with events based cache. | `12h` |
|
||||||
|
|||||||
@@ -289,6 +289,12 @@ Create the name of the service account to use
|
|||||||
{{- define "spire-server.upstream-spire-address" }}
|
{{- define "spire-server.upstream-spire-address" }}
|
||||||
{{- if ne (len (dig "spire" "upstreamSpireAddress" "" .Values.global)) 0 }}
|
{{- if ne (len (dig "spire" "upstreamSpireAddress" "" .Values.global)) 0 }}
|
||||||
{{- print .Values.global.spire.upstreamSpireAddress }}
|
{{- print .Values.global.spire.upstreamSpireAddress }}
|
||||||
|
{{- else if .Values.upstreamAuthority.spire.server.address }}
|
||||||
|
{{- if contains "." .Values.upstreamAuthority.spire.server.address }}
|
||||||
|
{{- print .Values.upstreamAuthority.spire.server.address }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s.%s" .Values.upstreamAuthority.spire.server.address (include "spire-lib.trust-domain" .) }}
|
||||||
|
{{- end }}
|
||||||
{{- else if .Values.upstreamAuthority.spire.server.nameOverride }}
|
{{- else if .Values.upstreamAuthority.spire.server.nameOverride }}
|
||||||
{{- printf "%s-%s" .Release.Name .Values.upstreamAuthority.spire.server.nameOverride }}
|
{{- printf "%s-%s" .Release.Name .Values.upstreamAuthority.spire.server.nameOverride }}
|
||||||
{{- else }}
|
{{- else }}
|
||||||
|
|||||||
@@ -105,6 +105,7 @@ server:
|
|||||||
{{- with .Values.experimental }}
|
{{- with .Values.experimental }}
|
||||||
{{- if eq (.enabled | toString) "true" }}
|
{{- if eq (.enabled | toString) "true" }}
|
||||||
experimental:
|
experimental:
|
||||||
|
agent_spiffe_id_as_selector: {{ .agentSPIFFEIDAsSelector }}
|
||||||
cache_reload_interval: {{ .cacheReloadInterval | quote }}
|
cache_reload_interval: {{ .cacheReloadInterval | quote }}
|
||||||
events_based_cache: {{ .eventsBasedCache }}
|
events_based_cache: {{ .eventsBasedCache }}
|
||||||
prune_events_older_than: {{ .pruneEventsOlderThan | quote }}
|
prune_events_older_than: {{ .pruneEventsOlderThan | quote }}
|
||||||
@@ -175,7 +176,7 @@ plugins:
|
|||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|
||||||
{{- if or .Values.nodeAttestor.k8sPSAT.enabled .Values.nodeAttestor.externalK8sPSAT.enabled .Values.nodeAttestor.joinToken.enabled .Values.nodeAttestor.httpChallenge.enabled .Values.nodeAttestor.tpmDirect.enabled .Values.nodeAttestor.awsIID.enabled .Values.nodeAttestor.gcpIIT.enabled }}
|
{{- if or .Values.nodeAttestor.k8sPSAT.enabled .Values.nodeAttestor.externalK8sPSAT.enabled .Values.nodeAttestor.joinToken.enabled .Values.nodeAttestor.httpChallenge.enabled .Values.nodeAttestor.tpmDirect.enabled .Values.nodeAttestor.awsIID.enabled .Values.nodeAttestor.gcpIIT.enabled .Values.nodeAttestor.x509POP.enabled }}
|
||||||
NodeAttestor:
|
NodeAttestor:
|
||||||
{{- $clusters := default .Values.kubeConfigs .Values.nodeAttestor.externalK8sPSAT.clusters }}
|
{{- $clusters := default .Values.kubeConfigs .Values.nodeAttestor.externalK8sPSAT.clusters }}
|
||||||
{{- if or (eq (.Values.nodeAttestor.k8sPSAT.enabled | toString) "true") (and (eq (.Values.nodeAttestor.externalK8sPSAT.enabled | toString) "true") (gt (len $clusters) 0)) }}
|
{{- if or (eq (.Values.nodeAttestor.k8sPSAT.enabled | toString) "true") (and (eq (.Values.nodeAttestor.externalK8sPSAT.enabled | toString) "true") (gt (len $clusters) 0)) }}
|
||||||
@@ -255,6 +256,27 @@ plugins:
|
|||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
{{- with .Values.nodeAttestor.x509POP }}
|
||||||
|
{{- if eq (.enabled | toString) "true" }}
|
||||||
|
x509pop:
|
||||||
|
plugin_data:
|
||||||
|
mode: {{ .mode }}
|
||||||
|
{{- if .addClusterName.svidPrefix }}
|
||||||
|
svid_prefix: {{ printf "%s/%s" .svidPrefix (include "spire-lib.cluster-name" $root) | quote }}
|
||||||
|
{{- else }}
|
||||||
|
svid_prefix: {{ .svidPrefix | quote }}
|
||||||
|
{{- end }}
|
||||||
|
max_intermediates: {{ .maxIntermediates }}
|
||||||
|
max_rsa_key_size: {{ .maxRSAKeySize }}
|
||||||
|
{{- if ne .agentPathTemplate "" }}
|
||||||
|
{{- if .addClusterName.agentPathTemplate }}
|
||||||
|
agent_path_template: {{ printf "%s/%s" .agentPathTemplate (include "spire-lib.cluster-name" $root) | quote }}
|
||||||
|
{{- else }}
|
||||||
|
agent_path_template: {{ .agentPathTemplate | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
{{- with .Values.nodeAttestor.awsIID }}
|
{{- with .Values.nodeAttestor.awsIID }}
|
||||||
{{- if eq (.enabled | toString) "true" }}
|
{{- if eq (.enabled | toString) "true" }}
|
||||||
aws_iid:
|
aws_iid:
|
||||||
|
|||||||
@@ -12,6 +12,9 @@ values:
|
|||||||
{{- if eq .type "child-servers" }}
|
{{- if eq .type "child-servers" }}
|
||||||
matchLabels:
|
matchLabels:
|
||||||
component: server
|
component: server
|
||||||
|
{{- else if eq .type "oidc-discovery-provider-common" }}
|
||||||
|
matchLabels:
|
||||||
|
component: oidc-discovery-provider
|
||||||
{{- else if eq .type "oidc-discovery-provider" }}
|
{{- else if eq .type "oidc-discovery-provider" }}
|
||||||
matchLabels:
|
matchLabels:
|
||||||
release: {{ .Release.Name }}
|
release: {{ .Release.Name }}
|
||||||
@@ -42,6 +45,9 @@ matchLabels:
|
|||||||
release: {{ .Release.Name }}
|
release: {{ .Release.Name }}
|
||||||
release-namespace: {{ .Release.Namespace }}
|
release-namespace: {{ .Release.Namespace }}
|
||||||
component: test-keys
|
component: test-keys
|
||||||
|
{{- else if eq .type "spire-ha-agent" }}
|
||||||
|
matchLabels:
|
||||||
|
"app.kubernetes.io/name": spire-ha-agent
|
||||||
{{- else }}
|
{{- else }}
|
||||||
{}
|
{}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
@@ -58,8 +64,8 @@ matchLabels:
|
|||||||
{{- if eq ($root.Values.controllerManager.enabled | toString) "true" }}
|
{{- if eq ($root.Values.controllerManager.enabled | toString) "true" }}
|
||||||
{{- if or (not (hasKey $value "enabled")) (eq ($value.enabled | toString) "true") }}
|
{{- if or (not (hasKey $value "enabled")) (eq ($value.enabled | toString) "true") }}
|
||||||
{{- $type := dig "type" "base" $value }}
|
{{- $type := dig "type" "base" $value }}
|
||||||
{{- if not (has $type (list "base" "raw" "child-servers" "oidc-discovery-provider" "spike-keeper" "spike-nexus" "spike-bootstrap" "spike-pilot" "test-keys")) }}
|
{{- if not (has $type (list "base" "raw" "spire-ha-agent" "child-servers" "oidc-discovery-provider" "oidc-discovery-provider-common" "spike-keeper" "spike-nexus" "spike-bootstrap" "spike-pilot" "test-keys")) }}
|
||||||
{{- fail (printf "Type given: %s, must be one of [base, raw, child-servers, oidc-discovery-provider, spike-keeper, spike-nexus, spike-bootstrap, spike-pilot, test-keys]" $type) }}
|
{{- fail (printf "Type given: %s, must be one of [base, raw, spire-ha-agent, child-servers, oidc-discovery-provider, oidc-discovery-provider-common, spike-keeper, spike-nexus, spike-bootstrap, spike-pilot, test-keys]" $type) }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- $namespaceSelector := deepCopy (dig "namespaceSelector" (dict) $value) }}
|
{{- $namespaceSelector := deepCopy (dig "namespaceSelector" (dict) $value) }}
|
||||||
{{- if ne $type "raw" }}
|
{{- if ne $type "raw" }}
|
||||||
|
|||||||
@@ -64,7 +64,7 @@ roleRef:
|
|||||||
name: {{ include "spire-lib.bundle-configmap" . }}
|
name: {{ include "spire-lib.bundle-configmap" . }}
|
||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if and .Values.nodeAttestor.k8sPSAT.enabled }}
|
{{- if or .Values.nodeAttestor.k8sPSAT.enabled .Values.dynamicRegistration.enabled }}
|
||||||
---
|
---
|
||||||
# ClusterRole to allow spire-server node attestor to query Token Review API
|
# ClusterRole to allow spire-server node attestor to query Token Review API
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
@@ -79,11 +79,13 @@ rules:
|
|||||||
- watch
|
- watch
|
||||||
- list
|
- list
|
||||||
- create
|
- create
|
||||||
|
{{- if .Values.nodeAttestor.k8sPSAT.enabled }}
|
||||||
- apiGroups: [""]
|
- apiGroups: [""]
|
||||||
resources: [nodes, pods]
|
resources: [nodes, pods]
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
|
{{- end }}
|
||||||
---
|
---
|
||||||
# Binds above cluster role to spire-server service account
|
# Binds above cluster role to spire-server service account
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
|
|||||||
@@ -396,6 +396,46 @@ spec:
|
|||||||
mountPath: /tmp
|
mountPath: /tmp
|
||||||
readOnly: false
|
readOnly: false
|
||||||
{{- include "spire-controller-manager.containers" . | nindent 8 }}
|
{{- include "spire-controller-manager.containers" . | nindent 8 }}
|
||||||
|
{{- if eq (.Values.dynamicRegistration.enabled | toString) "true" }}
|
||||||
|
- name: dynamic-registration
|
||||||
|
securityContext:
|
||||||
|
{{- include "spire-lib.securitycontext-extended" (dict "root" . "securityContext" .Values.tornjak.securityContext) | nindent 12 }}
|
||||||
|
image: {{ template "spire-lib.image" (dict "appVersion" .Values.dynamicRegistration.image.tag "image" .Values.dynamicRegistration.image "global" .Values.global "ubi" false) }}
|
||||||
|
imagePullPolicy: {{ .Values.dynamicRegistration.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
- name: SPIFFE_TRUST_DOMAIN
|
||||||
|
value: {{ include "spire-lib.trust-domain" . | quote }}
|
||||||
|
- name: EXPECTED_AUDIENCE
|
||||||
|
value: {{ .Values.dynamicRegistration.audience | quote }}
|
||||||
|
- name: EXPECTED_SERVICE_ACCOUNT
|
||||||
|
{{- if contains ":" .Values.dynamicRegistration.serviceAccount }}
|
||||||
|
value: {{ .Values.dynamicRegistration.serviceAccount | quote }}
|
||||||
|
{{- else }}
|
||||||
|
value: {{ printf "%s:%s" (include "spire-server.agent-namespace" .) .Values.dynamicRegistration.serviceAccount | quote }}
|
||||||
|
{{- end }}
|
||||||
|
- name: ALLOWEDID_PREFIX
|
||||||
|
{{- if .Values.dynamicRegistration.addClusterName.allowedIDPrefix }}
|
||||||
|
value: {{ printf "%s/%s" .Values.dynamicRegistration.allowedIDPrefix (include "spire-lib.cluster-name" .) | quote }}
|
||||||
|
{{- else }}
|
||||||
|
value: {{ .Values.dynamicRegistration.allowedIDPrefix | quote }}
|
||||||
|
{{- end }}
|
||||||
|
- name: ENTRY_PREFIX
|
||||||
|
value: {{ .Values.dynamicRegistration.entryPrefix | quote }}
|
||||||
|
- name: REGISTRATION_PREFIX
|
||||||
|
{{- if .Values.dynamicRegistration.addClusterName.registrationPrefix }}
|
||||||
|
value: {{ printf "%s/%s" .Values.dynamicRegistration.registrationPrefix (include "spire-lib.cluster-name" .) | quote }}
|
||||||
|
{{- else }}
|
||||||
|
value: {{ .Values.dynamicRegistration.registrationPrefix | quote }}
|
||||||
|
{{- end }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: spire-server-socket
|
||||||
|
mountPath: /tmp/spire-server/private
|
||||||
|
readOnly: true
|
||||||
|
ports:
|
||||||
|
- name: dynamic-https
|
||||||
|
containerPort: 8931
|
||||||
|
protocol: TCP
|
||||||
|
{{- end }}
|
||||||
{{- if eq (.Values.tornjak.enabled | toString) "true" }}
|
{{- if eq (.Values.tornjak.enabled | toString) "true" }}
|
||||||
- name: tornjak
|
- name: tornjak
|
||||||
securityContext:
|
securityContext:
|
||||||
@@ -445,6 +485,29 @@ spec:
|
|||||||
mountPath: /opt/spire/user
|
mountPath: /opt/spire/user
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
{{- if eq (.Values.trustSync.enabled | toString) "true" }}
|
||||||
|
- name: spire-trust-sync
|
||||||
|
image: {{ template "spire-lib.image" (dict "appVersion" .Values.trustSync.image.defaultTag "image" .Values.trustSync.image "global" .Values.global "ubi" false) }}
|
||||||
|
imagePullPolicy: {{ .Values.trustSync.image.pullPolicy }}
|
||||||
|
args:
|
||||||
|
- -trust-domains={{ join "," .Values.trustSync.domains }}
|
||||||
|
env:
|
||||||
|
- name: SPIFFE_TRUST_DOMAIN
|
||||||
|
value: {{ include "spire-lib.trust-domain" . | quote }}
|
||||||
|
- name: SPIRE_SERVER_SOCKET
|
||||||
|
value: unix:///tmp/spire-server/private/api.sock
|
||||||
|
- name: SPIFFE_ENDPOINT_SOCKET
|
||||||
|
value: unix:///run/spire/upstream_agent/spire-agent.sock
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /run/spire/upstream_agent
|
||||||
|
name: upstream-agent
|
||||||
|
readOnly: true
|
||||||
|
- mountPath: /tmp/spire-server/private
|
||||||
|
name: spire-server-socket
|
||||||
|
readOnly: true
|
||||||
|
securityContext:
|
||||||
|
{{- include "spire-lib.securitycontext" . | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
{{- if gt (len .Values.extraContainers) 0 }}
|
{{- if gt (len .Values.extraContainers) 0 }}
|
||||||
{{- toYaml .Values.extraContainers | nindent 8 }}
|
{{- toYaml .Values.extraContainers | nindent 8 }}
|
||||||
|
|||||||
@@ -28,6 +28,14 @@ spec:
|
|||||||
protocol: TCP
|
protocol: TCP
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
{{- with .Values.dynamicRegistration }}
|
||||||
|
{{- if eq (.enabled | toString) "true" }}
|
||||||
|
- name: dynamic-registration
|
||||||
|
port: 8931
|
||||||
|
targetPort: dynamic-https
|
||||||
|
protocol: TCP
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
selector:
|
selector:
|
||||||
{{- include "spire-server.selectorLabels" . | nindent 4 }}
|
{{- include "spire-server.selectorLabels" . | nindent 4 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -144,7 +144,7 @@ readinessProbe:
|
|||||||
initialDelaySeconds: 5
|
initialDelaySeconds: 5
|
||||||
periodSeconds: 5
|
periodSeconds: 5
|
||||||
|
|
||||||
## @param persistence.type What type of volume to use for persistence. Valid options pvc (recommended), hostPath, emptyDir (testing only)
|
## @param persistence.type What type of volume to use for persistence. Valid options pvc (recommended), hostPath, emptyDir (testing or nested child only)
|
||||||
## @param persistence.size What size volume to use for persistence
|
## @param persistence.size What size volume to use for persistence
|
||||||
## @param persistence.accessMode What access mode to use for persistence. Valid options are ReadWriteOnce (recommended), ReadWriteOncePod, ReadWriteMany (not recommended)
|
## @param persistence.accessMode What access mode to use for persistence. Valid options are ReadWriteOnce (recommended), ReadWriteOncePod, ReadWriteMany (not recommended)
|
||||||
## @param persistence.storageClass What storage class to use for persistence
|
## @param persistence.storageClass What storage class to use for persistence
|
||||||
@@ -788,6 +788,17 @@ controllerManager:
|
|||||||
## @param controllerManager.identities.clusterSPIFFEIDs.spike-pilot.spiffeIDTemplate The template to use for this rule.
|
## @param controllerManager.identities.clusterSPIFFEIDs.spike-pilot.spiffeIDTemplate The template to use for this rule.
|
||||||
spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spike/pilot/role/superuser
|
spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spike/pilot/role/superuser
|
||||||
|
|
||||||
|
spire-ha-agent:
|
||||||
|
## @param controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.enabled Enable this identity for controller manager
|
||||||
|
enabled: false
|
||||||
|
## @param controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.type The type of rule this is.
|
||||||
|
type: spire-ha-agent
|
||||||
|
## @param controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.spiffeIDTemplate The template to use for this rule.
|
||||||
|
spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spire-ha-agent
|
||||||
|
## @param controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.federatesWith Federated trust domains to pass to the workload
|
||||||
|
federatesWith:
|
||||||
|
- spire-ha
|
||||||
|
|
||||||
# You can specify additional ClusterSPIFFEIDs following this example:
|
# You can specify additional ClusterSPIFFEIDs following this example:
|
||||||
# foo:
|
# foo:
|
||||||
# labels:
|
# labels:
|
||||||
@@ -1109,6 +1120,24 @@ nodeAttestor:
|
|||||||
metadataValueMaxSize: 0
|
metadataValueMaxSize: 0
|
||||||
## @param nodeAttestor.gcpIIT.agentPathTemplate A URL path portion format of Agent's SPIFFE ID. Describe in text/template format.
|
## @param nodeAttestor.gcpIIT.agentPathTemplate A URL path portion format of Agent's SPIFFE ID. Describe in text/template format.
|
||||||
agentPathTemplate: ""
|
agentPathTemplate: ""
|
||||||
|
x509POP:
|
||||||
|
## @param nodeAttestor.x509POP.enabled Enable the x509_popg node attestor
|
||||||
|
enabled: false
|
||||||
|
## @param nodeAttestor.x509POP.mode What mode to set the plugin to. Currently only spiffe mode is supported
|
||||||
|
mode: spiffe
|
||||||
|
## @param nodeAttestor.x509POP.svidPrefix What prefix to use when mode is spiffe
|
||||||
|
svidPrefix: /spire-exchange
|
||||||
|
## @param nodeAttestor.x509POP.agentPathTemplate Override the default agent path template
|
||||||
|
agentPathTemplate: ""
|
||||||
|
## @param nodeAttestor.x509POP.maxIntermediates Maximum number of intermediate certificates allowed in the certificate chain
|
||||||
|
maxIntermediates: 4
|
||||||
|
## @param nodeAttestor.x509POP.maxRSAKeySize Maximum RSA key size in bits allowed in certificates
|
||||||
|
maxRSAKeySize: 8192
|
||||||
|
addClusterName:
|
||||||
|
## @param nodeAttestor.x509POP.addClusterName.svidPrefix Suffix the cluster name onto the svidPrefix
|
||||||
|
svidPrefix: false
|
||||||
|
## @param nodeAttestor.x509POP.addClusterName.agentPathTemplate Suffix the cluster name onto the agentPathTemplate
|
||||||
|
agentPathTemplate: false
|
||||||
|
|
||||||
# The secrets needed for this plugin are configured in the secrets: section
|
# The secrets needed for this plugin are configured in the secrets: section
|
||||||
bundlePublisher:
|
bundlePublisher:
|
||||||
@@ -1166,6 +1195,40 @@ bundlePublisher:
|
|||||||
## @param bundlePublisher.gcpCloudStorage.format Format in which the trust bundle is stored. Valid options [spiffe, jwks, pem]
|
## @param bundlePublisher.gcpCloudStorage.format Format in which the trust bundle is stored. Valid options [spiffe, jwks, pem]
|
||||||
format: ""
|
format: ""
|
||||||
|
|
||||||
|
dynamicRegistration:
|
||||||
|
## @param dynamicRegistration.enabled Deploys the sidecar helper for dynamic registration
|
||||||
|
enabled: false
|
||||||
|
## @param dynamicRegistration.image.registry The OCI registry to pull the image from
|
||||||
|
## @param dynamicRegistration.image.repository The repository within the registry
|
||||||
|
## @param dynamicRegistration.image.pullPolicy The image pull policy
|
||||||
|
## @param dynamicRegistration.image.tag Overrides the image tag to be whatever you need it to be. It will always be the flag you set without modifications
|
||||||
|
##
|
||||||
|
image:
|
||||||
|
registry: ghcr.io
|
||||||
|
repository: spiffe/spire-controller-manager-dynamic-registration/spire-controller-manager-dynamic-registration-server
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
tag: "0.1.0"
|
||||||
|
|
||||||
|
## @param dynamicRegistration.serviceAccount Which service account to allow to register
|
||||||
|
serviceAccount: "spire-agent"
|
||||||
|
|
||||||
|
## @param dynamicRegistration.audience The expected audience
|
||||||
|
audience: spire-controller-manager-dynamic-registration
|
||||||
|
## @param dynamicRegistration.entryPrefix Unique prefix to bind nodes aliases to the server
|
||||||
|
entryPrefix: "scmnr"
|
||||||
|
## @param dynamicRegistration.allowedIDPrefix Prefix of agents that are allowed to register
|
||||||
|
allowedIDPrefix: "spire/agent/k8s_psat"
|
||||||
|
## @param dynamicRegistration.registrationPrefix prefix to use on all new registration entries
|
||||||
|
registrationPrefix: "k8s_psat"
|
||||||
|
addClusterName:
|
||||||
|
## @param dynamicRegistration.addClusterName.registrationPrefix suffix the cluster name onto the registrationPrefix
|
||||||
|
registrationPrefix: true
|
||||||
|
## @param dynamicRegistration.addClusterName.allowedIDPrefix suffix the cluster name onto the allowedIDPrefix
|
||||||
|
allowedIDPrefix: true
|
||||||
|
|
||||||
|
## @param dynamicRegistration.securityContext [object] Security Context to use
|
||||||
|
securityContext: {}
|
||||||
|
|
||||||
## @section Tornjak
|
## @section Tornjak
|
||||||
tornjak:
|
tornjak:
|
||||||
## @param tornjak.enabled Deploys Tornjak API (backend) (Not for production)
|
## @param tornjak.enabled Deploys Tornjak API (backend) (Not for production)
|
||||||
@@ -1291,6 +1354,38 @@ secrets:
|
|||||||
## @param secrets.gcp.applicationCredentials Google Application Credentials
|
## @param secrets.gcp.applicationCredentials Google Application Credentials
|
||||||
applicationCredentials: ""
|
applicationCredentials: ""
|
||||||
|
|
||||||
|
trustSync:
|
||||||
|
## @param trustSync.enabled Allow configuration of trust syncing
|
||||||
|
enabled: false
|
||||||
|
## @param trustSync.domains List of trust domains to sync from parent to child servers
|
||||||
|
domains: []
|
||||||
|
#- spire-ha
|
||||||
|
#- foo.org
|
||||||
|
|
||||||
|
## @param trustSync.image.registry The OCI registry to pull the image from
|
||||||
|
## @param trustSync.image.repository The repository within the registry
|
||||||
|
## @param trustSync.image.pullPolicy The image pull policy
|
||||||
|
## @param trustSync.image.tag Overrides the image tag to be whatever you need it to be. It will always be the flag you set without modifications
|
||||||
|
##
|
||||||
|
image:
|
||||||
|
registry: ghcr.io
|
||||||
|
repository: spiffe/spire-ha-agent/spire-trust-sync
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
tag: "0.0.21"
|
||||||
|
|
||||||
|
## @param trustSync.resources [object] Resource requests and limits
|
||||||
|
resources: {}
|
||||||
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||||
|
# choice for the user. This also increases chances charts run on environments with little
|
||||||
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||||
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||||
|
# limits:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 128Mi
|
||||||
|
# requests:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 128Mi
|
||||||
|
|
||||||
# NOTE: This is unsupported and only to configure currently supported spire built in plugins but plugins unsupported by the chart.
|
# NOTE: This is unsupported and only to configure currently supported spire built in plugins but plugins unsupported by the chart.
|
||||||
# Upgrades wont be tested for anything under this config. If you need this, please let the chart developers know your needs so we
|
# Upgrades wont be tested for anything under this config. If you need this, please let the chart developers know your needs so we
|
||||||
# can prioritize proper support.
|
# can prioritize proper support.
|
||||||
@@ -1336,6 +1431,8 @@ chown:
|
|||||||
experimental:
|
experimental:
|
||||||
## @param experimental.enabled Allow configuration of experimental features
|
## @param experimental.enabled Allow configuration of experimental features
|
||||||
enabled: false
|
enabled: false
|
||||||
|
## @param experimental.agentSPIFFEIDAsSelector enable adding spiffe_id selectors to all agents
|
||||||
|
agentSPIFFEIDAsSelector: false
|
||||||
## @param experimental.cacheReloadInterval The amount of time between two reloads of the in-memory entry cache.
|
## @param experimental.cacheReloadInterval The amount of time between two reloads of the in-memory entry cache.
|
||||||
cacheReloadInterval: 5s
|
cacheReloadInterval: 5s
|
||||||
## @param experimental.eventsBasedCache Use events to update the cache with what's changed since the last update.
|
## @param experimental.eventsBasedCache Use events to update the cache with what's changed since the last update.
|
||||||
|
|||||||
@@ -0,0 +1,138 @@
|
|||||||
|
## Kubernetes Bottom Turtle HA Setup
|
||||||
|
|
||||||
|
In this setup, a bottom turtle HA setup based on spire-ha-agent and then Kubernetes based access is built from the ground up.
|
||||||
|
|
||||||
|
What does this mean?
|
||||||
|
|
||||||
|
The bottom turtle:
|
||||||
|
There is a pair of spire servers deployed. Trust is established between the two servers creating an HA Trust Domain without needing any 3rd party
|
||||||
|
trust sources.
|
||||||
|
|
||||||
|
A spire-ha-agent, a spire-agent@a and a spire-agent@b is run on the k8s hosts. This provides a bottom turtle trust source between the services on the os Kubernetes
|
||||||
|
runs on.
|
||||||
|
|
||||||
|
Host services can then use this trust chain to secure communications such as:
|
||||||
|
* kubelet -> kube-apiserver
|
||||||
|
* sshd
|
||||||
|
* log shipper -> centeralized log processor
|
||||||
|
* os level metrics
|
||||||
|
* etc
|
||||||
|
|
||||||
|
We will not discuss how to do that here, but need to utilize this base to establish trust inside of Kubernetes.
|
||||||
|
|
||||||
|
We will bridge os to Kubernetes cluster with some configuration on the host, and deploying the helm charts to utilize and export new services on top.
|
||||||
|
|
||||||
|
What do we need to do?
|
||||||
|
|
||||||
|
There are two different kinds of services that need permission bridging.
|
||||||
|
|
||||||
|
* SPIRE Servers
|
||||||
|
* Downstream agents
|
||||||
|
|
||||||
|
### Root Servers
|
||||||
|
|
||||||
|
Setup a pair of HA root servers as described here:
|
||||||
|
https://github.com/spiffe/bootc/tree/main/demo
|
||||||
|
|
||||||
|
Root Servers, A and B:
|
||||||
|

|
||||||
|

|
||||||
|
|
||||||
|
### K8s SPIRE Servers
|
||||||
|
|
||||||
|
In the following diagram, we see all the parts involved from getting the K8s SPIRE Servers running on the control plane nodes.
|
||||||
|

|
||||||
|
|
||||||
|
We need to be able to use the hosts workload attestors to attest the SPIRE Servers running inside Kubernetes.
|
||||||
|
|
||||||
|
To do so, we will define a workload on the root spire servers, and inject it into the spire servers inside Kubernetes.
|
||||||
|
|
||||||
|
Example workload definition:
|
||||||
|
```
|
||||||
|
apiVersion: spire.spiffe.io/v1alpha1
|
||||||
|
kind: ClusterStaticEntry
|
||||||
|
metadata:
|
||||||
|
name: node1-k8s-spire-server
|
||||||
|
spec:
|
||||||
|
parentID: spiffe://${SPIFFE_TRUST_DOMAIN}/node/node1.${SPIFFE_TRUST_DOMAIN}
|
||||||
|
spiffeID: spiffe://${SPIFFE_TRUST_DOMAIN}/k8s-spire-server/server-${SUBINSTANCE}
|
||||||
|
downstream: true
|
||||||
|
selectors:
|
||||||
|
- systemd:id:spiffe-socat-unix@k8s-spire-server-${SUBINSTANCE}.service
|
||||||
|
federatesWith:
|
||||||
|
- spire-ha
|
||||||
|
```
|
||||||
|
|
||||||
|
And on the host, we install spiffe-socat-unix via packages, and then enable the bridges:
|
||||||
|
```
|
||||||
|
spiffe-socat-unix@k8s-spire-server-a.service
|
||||||
|
spiffe-socat-unix@k8s-spire-server-b.service
|
||||||
|
```
|
||||||
|
|
||||||
|
Any process that can access the unix socket will be able to become a spire downstream server. Treat this socket with great care.
|
||||||
|
|
||||||
|
Consider only doing this on your control plane nodes, and restricting the spire-server to only run on the control plane nodes for extra isolation.
|
||||||
|
|
||||||
|
### Downstream agents
|
||||||
|
|
||||||
|
In the following diagram we show how a worker node is aranged.
|
||||||
|

|
||||||
|
|
||||||
|
We need to be able to use the hosts workload attestors to attest the SPIRE Agents running inside Kubernetes.
|
||||||
|
|
||||||
|
To do so, we will define a workload on the root spire servers, and inject it into the spire agents inside Kubernetes.
|
||||||
|
|
||||||
|
Example workload definition:
|
||||||
|
```
|
||||||
|
apiVersion: spire.spiffe.io/v1alpha1
|
||||||
|
kind: ClusterStaticEntry
|
||||||
|
metadata:
|
||||||
|
name: node1-k8s-spire-agent
|
||||||
|
spec:
|
||||||
|
parentID: spiffe://${SPIFFE_TRUST_DOMAIN}/node/node1.${SPIFFE_TRUST_DOMAIN}
|
||||||
|
spiffeID: spiffe://${SPIFFE_TRUST_DOMAIN}/spire-exchange/node1.${SPIFFE_TRUST_DOMAIN}
|
||||||
|
selectors:
|
||||||
|
- systemd:id:spiffe-socat-unix@k8s-spire-agent-${SUBINSTANCE}.service
|
||||||
|
```
|
||||||
|
|
||||||
|
And on the host, we install spiffe-socat-unix via packages, and then enable the bridges:
|
||||||
|
```
|
||||||
|
spiffe-socat-unix@k8s-spire-agent-a.service
|
||||||
|
spiffe-socat-unix@k8s-spire-agent-b.service
|
||||||
|
```
|
||||||
|
|
||||||
|
## Install the charts:
|
||||||
|
|
||||||
|
We need to install 4 charts.
|
||||||
|
|
||||||
|
* spire crds
|
||||||
|
* side A
|
||||||
|
* side B
|
||||||
|
* the common infrasctructure
|
||||||
|
|
||||||
|
This allows upgrading Side A or Side B completely independencly from each other, ensuring if there is a problem it will not affect production.
|
||||||
|
|
||||||
|
Setup the spire-values.yaml as needed.
|
||||||
|
|
||||||
|
```
|
||||||
|
# Install the common components
|
||||||
|
helm upgrade --install --create-namespace --namespace spire-mgmt --values "spire-values.yaml" \
|
||||||
|
spire oci://ghcr.io/spiffe/helm-charts/spire-nested \
|
||||||
|
--set tags.haAgentCommon=true \
|
||||||
|
--set "global.spire.namespaces.create=true" \
|
||||||
|
--set "global.spire.ingressControllerType=ingress-nginx" \
|
||||||
|
--set "spiffe-oidc-discovery-provider.ingress.enabled=true"
|
||||||
|
|
||||||
|
# Install server side a
|
||||||
|
helm upgrade --install --namespace spire-mgmt --values "spire-values.yaml" \
|
||||||
|
--wait spire-a oci://ghcr.io/spiffe/helm-charts/spire-nested \
|
||||||
|
--set tags.bottomTurtleHAA=true \
|
||||||
|
--set "global.spire.ingressControllerType=ingress-nginx"
|
||||||
|
|
||||||
|
|
||||||
|
# Install server side b
|
||||||
|
helm upgrade --install --namespace spire-mgmt --values "spire-values.yaml" \
|
||||||
|
--wait spire-b oci://ghcr.io/spiffe/helm-charts/spire-nested \
|
||||||
|
--set tags.bottomTurtleHAB=true \
|
||||||
|
--set "global.spire.ingressControllerType=ingress-nginx"
|
||||||
|
```
|
||||||
@@ -0,0 +1,136 @@
|
|||||||
|
digraph G {
|
||||||
|
compound=true;
|
||||||
|
|
||||||
|
# --- ROOT SERVERS ---
|
||||||
|
subgraph cluster_server1 {
|
||||||
|
label = "node name: n1"
|
||||||
|
style="filled,solid,bold";
|
||||||
|
color="#b3b3b3";
|
||||||
|
fillcolor="#f5f5f5";
|
||||||
|
labeljust="l";
|
||||||
|
|
||||||
|
spire_server_1[label=<<table border="0"><tr><td><b>SPIRE Server A</b></td></tr><tr><td align="left"><font point-size="9">NodeAttestors: tpm,x509pop</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#6c8ebf",fillcolor="#dae8fc"]
|
||||||
|
}
|
||||||
|
|
||||||
|
subgraph cluster_server2 {
|
||||||
|
label = "node name: n2"
|
||||||
|
style="filled,solid,bold";
|
||||||
|
color="#b3b3b3";
|
||||||
|
fillcolor="#f5f5f5";
|
||||||
|
labeljust="l";
|
||||||
|
spire_server_2[label=<<table border="0"><tr><td><b>SPIRE Server B</b></td></tr><tr><td align="left"><font point-size="9">NodeAttestors: tpm,x509pop</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#6c8ebf",fillcolor="#dae8fc"]
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- NODE N3 (SPIRE SERVER A PIPELINE) ---
|
||||||
|
subgraph cluster_node3 {
|
||||||
|
label = "node name: n3"
|
||||||
|
style="filled,solid,bold";
|
||||||
|
color="#b3b3b3";
|
||||||
|
fillcolor="#f5f5f5";
|
||||||
|
labeljust="l";
|
||||||
|
|
||||||
|
subgraph cluster_node3_systemd {
|
||||||
|
label = "systemd managed"
|
||||||
|
style = "dashed,filled"
|
||||||
|
color="#939393";
|
||||||
|
fillcolor="#d5d5d5";
|
||||||
|
labeljust="l";
|
||||||
|
|
||||||
|
spire_agent1[label=<<table border="0"><tr><td><b>SPIRE Agent A</b></td></tr><tr><td align="left"><font point-size="9">NodeAttestor: tpm</font></td></tr><tr><td align="left"><font point-size="9">WorkloadAttestor: systemd</font></td></tr><tr><td align="left"><font point-size="9">systemd: [email protected]</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#82b366",fillcolor="#d5e8d4"]
|
||||||
|
spire_agent2_n3[label=<<table border="0"><tr><td><b>SPIRE Agent B</b></td></tr><tr><td align="left"><font point-size="9">NodeAttestor: tpm</font></td></tr><tr><td align="left"><font point-size="9">WorkloadAttestor: systemd</font></td></tr><tr><td align="left"><font point-size="9">systemd: [email protected]</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#82b366",fillcolor="#d5e8d4"]
|
||||||
|
|
||||||
|
subgraph cluster_tb_n3 {
|
||||||
|
label=""
|
||||||
|
style="invis"
|
||||||
|
spire_ha_agent_n3[label=<<table border="0"><tr><td><b>SPIRE HA Agent</b></td></tr><tr><td align="left"><font point-size="9">systemd: [email protected]</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#82b366",fillcolor="#d5e8d4"]
|
||||||
|
}
|
||||||
|
|
||||||
|
sshd1_n3[label="sshd",shape="box",style="rounded,solid,filled,bold",color="#d6b656",fillcolor="#fff2cc"]
|
||||||
|
kubelet1_n3[label="kubelet",shape="box",style="rounded,solid,filled,bold",color="#d6b656",fillcolor="#fff2cc"]
|
||||||
|
k8s_spire_server_a[label=<<table border="0"><tr><td><b>K8s SPIRE Server A Identity</b></td></tr><tr><td align="left"><font point-size="9">systemd: spiffe-socat-unix@k8s-spire-server-a</font></td></tr><tr><td align="left"><font point-size="9">tool: socat</font></td></tr></table>>,shape="box",style="rounded,solid,filled,bold",color="#d79b00",fillcolor="#ffe6cc"]
|
||||||
|
}
|
||||||
|
|
||||||
|
subgraph cluster_node3_k8s {
|
||||||
|
label = "k8s managed"
|
||||||
|
style = "dashed,filled"
|
||||||
|
color="#939393";
|
||||||
|
fillcolor="#d5d5d5";
|
||||||
|
labeljust="l";
|
||||||
|
|
||||||
|
k8s_upstream_csi_a[label=<<table border="0"><tr><td><b>Upstream CSI A</b></td></tr><tr><td align="left"><font point-size="9">path: /var/run/spiffe/socat/unix/k8s-spire-server-a/public/agent.sock</font></td></tr></table>>,shape="box",style="rounded,solid,filled,bold",color="#d79b00",fillcolor="#ffe6cc"]
|
||||||
|
spire_server_n1[label=<<table border="0"><tr><td><b>K8s SPIRE Server A</b></td></tr><tr><td align="left"><font point-size="9">NodeAttestors: x509pop</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#6c8ebf",fillcolor="#dae8fc"]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- NODE N4 (SPIRE SERVER B PIPELINE) ---
|
||||||
|
subgraph cluster_node4 {
|
||||||
|
label = "node name: n4"
|
||||||
|
style="filled,solid,bold";
|
||||||
|
color="#b3b3b3";
|
||||||
|
fillcolor="#f5f5f5";
|
||||||
|
labeljust="l";
|
||||||
|
|
||||||
|
subgraph cluster_node4_systemd {
|
||||||
|
label = "systemd managed"
|
||||||
|
style = "dashed,filled"
|
||||||
|
color="#939393";
|
||||||
|
fillcolor="#d5d5d5";
|
||||||
|
labeljust="l";
|
||||||
|
|
||||||
|
spire_agent1_n4[label=<<table border="0"><tr><td><b>SPIRE Agent A</b></td></tr><tr><td align="left"><font point-size="9">NodeAttestor: tpm</font></td></tr><tr><td align="left"><font point-size="9">WorkloadAttestor: systemd</font></td></tr><tr><td align="left"><font point-size="9">systemd: [email protected]</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#82b366",fillcolor="#d5e8d4"]
|
||||||
|
spire_agent2[label=<<table border="0"><tr><td><b>SPIRE Agent B</b></td></tr><tr><td align="left"><font point-size="9">NodeAttestor: tpm</font></td></tr><tr><td align="left"><font point-size="9">WorkloadAttestor: systemd</font></td></tr><tr><td align="left"><font point-size="9">systemd: [email protected]</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#82b366",fillcolor="#d5e8d4"]
|
||||||
|
|
||||||
|
subgraph cluster_tb_n4 {
|
||||||
|
label=""
|
||||||
|
style="invis"
|
||||||
|
spire_ha_agent_n4[label=<<table border="0"><tr><td><b>SPIRE HA Agent</b></td></tr><tr><td align="left"><font point-size="9">systemd: [email protected]</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#82b366",fillcolor="#d5e8d4"]
|
||||||
|
}
|
||||||
|
|
||||||
|
sshd1_n4[label="sshd",shape="box",style="rounded,solid,filled,bold",color="#d6b656",fillcolor="#fff2cc"]
|
||||||
|
kubelet1_n4[label="kubelet",shape="box",style="rounded,solid,filled,bold",color="#d6b656",fillcolor="#fff2cc"]
|
||||||
|
k8s_spire_server_b[label=<<table border="0"><tr><td><b>K8s SPIRE Server B Identity</b></td></tr><tr><td align="left"><font point-size="9">systemd: spiffe-socat-unix@k8s-spire-server-b</font></td></tr><tr><td align="left"><font point-size="9">tool: socat</font></td></tr></table>>,shape="box",style="rounded,solid,filled,bold",color="#d79b00",fillcolor="#ffe6cc"]
|
||||||
|
}
|
||||||
|
|
||||||
|
subgraph cluster_node4_k8s {
|
||||||
|
label = "k8s managed"
|
||||||
|
style = "dashed,filled"
|
||||||
|
color="#939393";
|
||||||
|
fillcolor="#d5d5d5";
|
||||||
|
labeljust="l";
|
||||||
|
|
||||||
|
k8s_upstream_csi_b[label=<<table border="0"><tr><td><b>Upstream CSI B</b></td></tr><tr><td align="left"><font point-size="9">path: /var/run/spiffe/socat/unix/k8s-spire-server-b/public/agent.sock</font></td></tr></table>>,shape="box",style="rounded,solid,filled,bold",color="#d79b00",fillcolor="#ffe6cc"]
|
||||||
|
spire_server_n2[label=<<table border="0"><tr><td><b>K8s SPIRE Server B</b></td></tr><tr><td align="left"><font point-size="9">NodeAttestors: x509pop</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#6c8ebf",fillcolor="#dae8fc"]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- NETWORKING & LINKS ---
|
||||||
|
|
||||||
|
# Upstream Core Cross-Links
|
||||||
|
spire_server_1 -> spire_agent1[dir=back]
|
||||||
|
spire_server_1 -> spire_agent1_n4[dir=back]
|
||||||
|
spire_server_2 -> spire_agent2_n3[dir=back]
|
||||||
|
spire_server_2 -> spire_agent2[dir=back]
|
||||||
|
|
||||||
|
# Node 3 Pipelines
|
||||||
|
spire_agent1 -> spire_ha_agent_n3[dir=back]
|
||||||
|
spire_agent2_n3 -> spire_ha_agent_n3[dir=back]
|
||||||
|
spire_ha_agent_n3 -> sshd1_n3[dir=back]
|
||||||
|
spire_ha_agent_n3 -> kubelet1_n3[dir=back]
|
||||||
|
spire_agent1 -> k8s_spire_server_a[dir=back]
|
||||||
|
k8s_spire_server_a -> k8s_upstream_csi_a[dir=back]
|
||||||
|
k8s_upstream_csi_a -> spire_server_n1[dir=back]
|
||||||
|
kubelet1_n3 -> k8s_upstream_csi_a [lhead=cluster_node3_k8s, style=dotted]
|
||||||
|
spire_server_1 -> spire_server_n1 [dir=back]
|
||||||
|
|
||||||
|
# Node 4 Pipelines
|
||||||
|
spire_agent1_n4 -> spire_ha_agent_n4[dir=back]
|
||||||
|
spire_agent2 -> spire_ha_agent_n4[dir=back]
|
||||||
|
spire_ha_agent_n4 -> sshd1_n4[dir=back]
|
||||||
|
spire_ha_agent_n4 -> kubelet1_n4[dir=back]
|
||||||
|
spire_agent2 -> k8s_spire_server_b[dir=back]
|
||||||
|
k8s_spire_server_b -> k8s_upstream_csi_b[dir=back]
|
||||||
|
k8s_upstream_csi_b -> spire_server_n2[dir=back]
|
||||||
|
kubelet1_n4 -> k8s_upstream_csi_b [lhead=cluster_node4_k8s, style=dotted]
|
||||||
|
spire_server_2 -> spire_server_n2 [dir=back]
|
||||||
|
}
|
||||||
|
|
||||||
Binary file not shown.
|
After Width: | Height: | Size: 168 KiB |
@@ -0,0 +1,150 @@
|
|||||||
|
digraph G {
|
||||||
|
compound=true;
|
||||||
|
subgraph cluster_server1 {
|
||||||
|
label = "node name: n1"
|
||||||
|
#style = dashed
|
||||||
|
style="filled,solid,bold";
|
||||||
|
color="#b3b3b3";
|
||||||
|
fillcolor="#f5f5f5";
|
||||||
|
labeljust="l";
|
||||||
|
|
||||||
|
spire_server_1[label=<<table border="0"><tr><td><b>SPIRE Server A</b></td></tr><tr><td align="left"><font point-size="9">NodeAttestors: tpm</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#6c8ebf",fillcolor="#dae8fc"]
|
||||||
|
}
|
||||||
|
|
||||||
|
subgraph cluster_ps1 {
|
||||||
|
label = "Control Plane Node: X"
|
||||||
|
#style = dashed
|
||||||
|
style="filled,solid,bold";
|
||||||
|
color="#b3b3b3";
|
||||||
|
fillcolor="#f5f5f5";
|
||||||
|
labeljust="l";
|
||||||
|
|
||||||
|
pod_spire_server_1[label=<<table border="0"><tr><td><b>K8s SPIRE Server A</b></td></tr><tr><td align="left"><font point-size="9">NodeAttestors: x509pop</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#6c8ebf",fillcolor="#dae8fc"]
|
||||||
|
}
|
||||||
|
|
||||||
|
subgraph cluster_ps2 {
|
||||||
|
label = "Control Plane Node: Y"
|
||||||
|
#style = dashed
|
||||||
|
style="filled,solid,bold";
|
||||||
|
color="#b3b3b3";
|
||||||
|
fillcolor="#f5f5f5";
|
||||||
|
labeljust="l";
|
||||||
|
|
||||||
|
pod_spire_server_2[label=<<table border="0"><tr><td><b>K8s SPIRE Server B</b></td></tr><tr><td align="left"><font point-size="9">NodeAttestors: x509pop</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#6c8ebf",fillcolor="#dae8fc"]
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
subgraph cluster_server2 {
|
||||||
|
|
||||||
|
label = "node name: n2"
|
||||||
|
#style = dashed
|
||||||
|
style="filled,solid,bold";
|
||||||
|
color="#b3b3b3";
|
||||||
|
fillcolor="#f5f5f5";
|
||||||
|
labeljust="l";
|
||||||
|
spire_server_2[label=<<table border="0"><tr><td><b>SPIRE Server B</b></td></tr><tr><td align="left"><font point-size="9">NodeAttestors: tpm</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#6c8ebf",fillcolor="#dae8fc"]
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
subgraph cluster_node3 {
|
||||||
|
label = "node name: n3"
|
||||||
|
#style = dashed
|
||||||
|
style="filled,solid,bold";
|
||||||
|
color="#b3b3b3";
|
||||||
|
fillcolor="#f5f5f5";
|
||||||
|
labeljust="l";
|
||||||
|
|
||||||
|
subgraph cluster_node1_systemd {
|
||||||
|
#label = "Systemd"
|
||||||
|
label = "systemd managed"
|
||||||
|
style = "dashed,filled"
|
||||||
|
color="#939393";
|
||||||
|
fillcolor="#d5d5d5";
|
||||||
|
|
||||||
|
labeljust="l";
|
||||||
|
|
||||||
|
spire_agent1[label=<<table border="0"><tr><td><b>SPIRE Agent A</b></td></tr><tr><td align="left"><font point-size="9">NodeAttestor: tpm</font></td></tr><tr><td align="left"><font point-size="9">WorkloadAttestor: systemd</font></td></tr><tr><td align="left"><font point-size="9">systemd: [email protected]</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#82b366",fillcolor="#d5e8d4"]
|
||||||
|
spire_agent2[label=<<table border="0"><tr><td><b>SPIRE Agent B</b></td></tr><tr><td align="left"><font point-size="9">NodeAttestor: tpm</font></td></tr><tr><td align="left"><font point-size="9">WorkloadAttestor: systemd</font></td></tr><tr><td align="left"><font point-size="9">systemd: [email protected]</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#82b366",fillcolor="#d5e8d4"]
|
||||||
|
subgraph cluster_tb {
|
||||||
|
label=""
|
||||||
|
style="invis"
|
||||||
|
spire_ha_agent[label=<<table border="0"><tr><td><b>SPIRE HA Agent</b></td></tr><tr><td align="left"><font point-size="9">systemd: [email protected]</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#82b366",fillcolor="#d5e8d4"]
|
||||||
|
subgraph cluster_storage {
|
||||||
|
#spire_ha_agent_state_a[label="Trust Bundle A", shape=note,style="rounded,solid,filled,bold",fillcolor="#ffffff"]
|
||||||
|
#spire_ha_agent_state_b[label="Trust Bundle B", shape=note,style="rounded,solid,filled,bold",fillcolor="#ffffff"]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
sshd1[label="sshd",shape="box",style="rounded,solid,filled,bold",color="#d6b656",fillcolor="#fff2cc"]
|
||||||
|
kubelet1[label="kubelet",shape="box",style="rounded,solid,filled,bold",color="#d6b656",fillcolor="#fff2cc"]
|
||||||
|
k8s_spire_server_a[label=<<table border="0"><tr><td><b>K8s SPIRE Agent A Identity</b></td></tr><tr><td align="left"><font point-size="9">systemd: spiffe-socat-unix@k8s-spire-agent-a</font></td></tr><tr><td align="left"><font point-size="9">tool: socat</font></td></tr></table>>,shape="box",style="rounded,solid,filled,bold",color="#d79b00",fillcolor="#ffe6cc"]
|
||||||
|
k8s_spire_server_b[label=<<table border="0"><tr><td><b>K8s SPIRE Agent B Identity</b></td></tr><tr><td align="left"><font point-size="9">systemd: spiffe-socat-unix@k8s-spire-agent-b</font></td></tr><tr><td align="left"><font point-size="9">tool: socat</font></td></tr></table>>,shape="box",style="rounded,solid,filled,bold",color="#d79b00",fillcolor="#ffe6cc"]
|
||||||
|
}
|
||||||
|
|
||||||
|
subgraph cluster_node1_k8s {
|
||||||
|
#label = "Systemd"
|
||||||
|
label = "k8s managed"
|
||||||
|
style = "dashed,filled"
|
||||||
|
color="#939393";
|
||||||
|
fillcolor="#d5d5d5";
|
||||||
|
|
||||||
|
labeljust="l";
|
||||||
|
|
||||||
|
// k8s_upstream_csi_a[label=<<table border="0"><tr><td><b>Downstream CSI A</b></td></tr><tr><td align="left"><font point-size="9">path: /var/run/spiffe/socat/unix/k8s-spire-server-a/public/agent.sock</font></td></tr></table>>,shape="box",style="rounded,solid,filled,bold",color="#d79b00",fillcolor="#ffe6cc"]
|
||||||
|
// k8s_upstream_csi_b[label=<<table border="0"><tr><td><b>Downstream CSI B</b></td></tr><tr><td align="left"><font point-size="9">path: /var/run/spiffe/socat/unix/k8s-spire-server-b/public/agent.sock</font></td></tr></table>>,shape="box",style="rounded,solid,filled,bold",color="#d79b00",fillcolor="#ffe6cc"]
|
||||||
|
|
||||||
|
k8s_downstream_csi[label=<<table border="0"><tr><td><b>Downstream CSI</b></td></tr><tr><td align="left"><font point-size="9">path: /var/run/spire/agent-sockets/spire-agent.sock</font></td></tr></table>>,shape="box",style="rounded,solid,filled,bold",color="#d79b00",fillcolor="#ffe6cc"]
|
||||||
|
|
||||||
|
spire_server_n1[label=<<table border="0"><tr><td><b>K8s SPIRE Agent A</b></td></tr><tr><td align="left"><font point-size="9">systemd: [email protected]</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#82b366",fillcolor="#d5e8d4"]
|
||||||
|
|
||||||
|
spire_server_n2[label=<<table border="0"><tr><td><b>K8s SPIRE Agent B</b></td></tr><tr><td align="left"><font point-size="9">systemd: [email protected]</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#82b366",fillcolor="#d5e8d4"]
|
||||||
|
|
||||||
|
|
||||||
|
spire_ha_agent_pod[label=<<table border="0"><tr><td><b>SPIRE HA Agent</b></td></tr><tr><td align="left"><font point-size="9">systemd: [email protected]</font></td></tr></table>>,shape="record",style="rounded,solid,filled,bold",color="#82b366",fillcolor="#d5e8d4"]
|
||||||
|
pod1[label="pod",shape="box",style="rounded,solid,filled,bold",color="#d6b656",fillcolor="#fff2cc"]
|
||||||
|
pod2[label="pod",shape="box",style="rounded,solid,filled,bold",color="#d6b656",fillcolor="#fff2cc"]
|
||||||
|
pod3[label="pod",shape="box",style="rounded,solid,filled,bold",color="#d6b656",fillcolor="#fff2cc"]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
spire_server_1 -> spire_agent1[dir=back]
|
||||||
|
spire_server_2 -> spire_agent2[dir=back]
|
||||||
|
spire_agent1 -> spire_ha_agent[dir=back]
|
||||||
|
spire_agent2 -> spire_ha_agent[dir=back]
|
||||||
|
spire_ha_agent -> sshd1[dir=back]
|
||||||
|
spire_ha_agent -> kubelet1[dir=back]
|
||||||
|
spire_agent1 -> k8s_spire_server_a[dir=back]
|
||||||
|
spire_agent2 -> k8s_spire_server_b[dir=back]
|
||||||
|
|
||||||
|
spire_server_1 -> pod_spire_server_1[dir=back]
|
||||||
|
spire_server_2 -> pod_spire_server_2[dir=back]
|
||||||
|
|
||||||
|
//k8s_spire_server_a -> k8s_upstream_csi_a[dir=back]
|
||||||
|
k8s_spire_server_a -> spire_server_n1[dir=back]
|
||||||
|
k8s_spire_server_b -> spire_server_n2[dir=back]
|
||||||
|
// k8s_upstream_csi_b -> k8s_spire_server_b
|
||||||
|
|
||||||
|
// k8s_upstream_csi_a -> spire_server_n1[dir=back]
|
||||||
|
// k8s_upstream_csi_b -> spire_server_n2[dir=back]
|
||||||
|
// k8s_spire_server_b -> spire_server_n2[dir=back]
|
||||||
|
|
||||||
|
//kubelet1 -> cluster_node1_k8s
|
||||||
|
kubelet1 -> spire_server_n1 [lhead=cluster_node1_k8s, style=dotted]
|
||||||
|
pod_spire_server_1 -> spire_server_n1 [dir=back]
|
||||||
|
pod_spire_server_2 -> spire_server_n2 [dir=back]
|
||||||
|
//kubelet1 -> spire_server_n1
|
||||||
|
//kubelet1 -> spire_server_n2
|
||||||
|
spire_server_n1 -> spire_ha_agent_pod [dir=back]
|
||||||
|
spire_server_n2 -> spire_ha_agent_pod [dir=back]
|
||||||
|
|
||||||
|
spire_ha_agent_pod -> k8s_downstream_csi [dir=back]
|
||||||
|
k8s_downstream_csi -> pod1 [dir=back]
|
||||||
|
k8s_downstream_csi -> pod2 [dir=back]
|
||||||
|
k8s_downstream_csi -> pod3 [dir=back]
|
||||||
|
// spire_ha_agent -> spire_ha_agent_state[dir=both, constraint=false]
|
||||||
|
// spire_ha_agent_state_a -> spire_ha_agent_state_b
|
||||||
|
//spire_agent1 -> spire_ha_agent_state_a
|
||||||
|
//spire_agent2 -> spire_ha_agent_state_b
|
||||||
|
//spire_ha_agent_state_a -> spire_ha_agent
|
||||||
|
//spire_ha_agent_state_b -> spire_ha_agent
|
||||||
|
}
|
||||||
|
|
||||||
Binary file not shown.
|
After Width: | Height: | Size: 177 KiB |
@@ -0,0 +1,12 @@
|
|||||||
|
apiVersion: spire.spiffe.io/v1alpha1
|
||||||
|
kind: ClusterStaticEntry
|
||||||
|
metadata:
|
||||||
|
name: node1-k8s-spire-server
|
||||||
|
spec:
|
||||||
|
parentID: spiffe://${SPIFFE_TRUST_DOMAIN}/agent/node1
|
||||||
|
spiffeID: spiffe://${SPIFFE_TRUST_DOMAIN}/k8s-spire-server/node1
|
||||||
|
selectors:
|
||||||
|
- systemd:id:spiffe-socat-unix@k8s-spire-server-${SUBINSTANCE}.service
|
||||||
|
downstream: true
|
||||||
|
federatesWith:
|
||||||
|
- spire-ha
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
apiVersion: spire.spiffe.io/v1alpha1
|
||||||
|
kind: ClusterStaticEntry
|
||||||
|
metadata:
|
||||||
|
name: node1-spire-trust-sync-a
|
||||||
|
spec:
|
||||||
|
parentID: spiffe://${SPIFFE_TRUST_DOMAIN}/agent/node1
|
||||||
|
spiffeID: spiffe://${SPIFFE_TRUST_DOMAIN}/spire-trust-sync-a
|
||||||
|
selectors:
|
||||||
|
- systemd:id:[email protected]
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
apiVersion: spire.spiffe.io/v1alpha1
|
||||||
|
kind: ClusterStaticEntry
|
||||||
|
metadata:
|
||||||
|
name: node1-spire-trust-sync-b
|
||||||
|
spec:
|
||||||
|
parentID: spiffe://${SPIFFE_TRUST_DOMAIN}/agent/node1
|
||||||
|
spiffeID: spiffe://${SPIFFE_TRUST_DOMAIN}/spire-trust-sync-b
|
||||||
|
selectors:
|
||||||
|
- systemd:id:[email protected]
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
apiVersion: spire.spiffe.io/v1alpha1
|
||||||
|
kind: ClusterStaticEntry
|
||||||
|
metadata:
|
||||||
|
name: node2-k8s-spire-server
|
||||||
|
spec:
|
||||||
|
parentID: spiffe://${SPIFFE_TRUST_DOMAIN}/agent/node1
|
||||||
|
spiffeID: spiffe://${SPIFFE_TRUST_DOMAIN}/spire-exchange/k8s/production/node2.${SPIFFE_TRUST_DOMAIN}
|
||||||
|
selectors:
|
||||||
|
- systemd:id:spiffe-socat-unix@k8s-spire-agent-2-${SUBINSTANCE}.service
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
apiVersion: spire.spiffe.io/v1alpha1
|
||||||
|
kind: ClusterStaticEntry
|
||||||
|
metadata:
|
||||||
|
name: node3-k8s-spire-server
|
||||||
|
spec:
|
||||||
|
parentID: spiffe://${SPIFFE_TRUST_DOMAIN}/agent/node1
|
||||||
|
spiffeID: spiffe://${SPIFFE_TRUST_DOMAIN}/spire-exchange/k8s/production/node3.${SPIFFE_TRUST_DOMAIN}
|
||||||
|
selectors:
|
||||||
|
- systemd:id:spiffe-socat-unix@k8s-spire-agent-3-${SUBINSTANCE}.service
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
apiVersion: spire.spiffe.io/v1alpha1
|
||||||
|
kind: ClusterStaticEntry
|
||||||
|
metadata:
|
||||||
|
name: node4-k8s-spire-server
|
||||||
|
spec:
|
||||||
|
parentID: spiffe://${SPIFFE_TRUST_DOMAIN}/agent/node1
|
||||||
|
spiffeID: spiffe://${SPIFFE_TRUST_DOMAIN}/spire-exchange/k8s/production/node4.${SPIFFE_TRUST_DOMAIN}
|
||||||
|
selectors:
|
||||||
|
- systemd:id:spiffe-socat-unix@k8s-spire-agent-4-${SUBINSTANCE}.service
|
||||||
Binary file not shown.
|
After Width: | Height: | Size: 332 KiB |
Executable
+293
@@ -0,0 +1,293 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# shellcheck disable=SC2317
|
||||||
|
|
||||||
|
set -xe
|
||||||
|
|
||||||
|
SCRIPT="$(readlink -f "$0")"
|
||||||
|
SCRIPTPATH="$(dirname "${SCRIPT}")"
|
||||||
|
TESTDIR="${SCRIPTPATH}/../../.github/tests"
|
||||||
|
#DEPS="${TESTDIR}/dependencies"
|
||||||
|
|
||||||
|
# shellcheck source=/dev/null
|
||||||
|
source "${SCRIPTPATH}/../../.github/scripts/parse-versions.sh"
|
||||||
|
# shellcheck source=/dev/null
|
||||||
|
source "${TESTDIR}/common.sh"
|
||||||
|
|
||||||
|
CLEANUP=1
|
||||||
|
|
||||||
|
for i in "$@"; do
|
||||||
|
case $i in
|
||||||
|
-c)
|
||||||
|
CLEANUP=0
|
||||||
|
shift # past argument=value
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ "x${GITHUB_JOB}" != "x" ]; then
|
||||||
|
echo "Running in GitHub"
|
||||||
|
else
|
||||||
|
echo "Do not run this script on your own box. For testing, it deploys a testing local spire ha setup using sudo. This is likely not what you want. Only use this script as a reference."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
teardown() {
|
||||||
|
echo ---------------------------
|
||||||
|
docker exec -i chart-testing-worker /bin/bash -c "more /var/lib/kubelet/pods/*/volumes/kubernetes.io~empty-dir/disk-keymanager/keys.json /var/lib/kubelet/pods/*/volumes/kubernetes.io~empty-dir/spire-agent-persistence/agent-data.json | cat"
|
||||||
|
sudo systemctl status spire-server@a || true
|
||||||
|
sudo systemctl status spire-server@b || true
|
||||||
|
sudo spire-server entry show -instance a || true
|
||||||
|
sudo spire-server entry show -instance b || true
|
||||||
|
sudo systemctl status spire-controller-manager@a || true
|
||||||
|
sudo systemctl status spire-controller-manager@b || true
|
||||||
|
sudo systemctl status spire-agent@a || true
|
||||||
|
sudo systemctl status spire-agent@b || true
|
||||||
|
sudo systemctl status spire-trust-sync@a || true
|
||||||
|
sudo systemctl status spire-trust-sync@b || true
|
||||||
|
sudo systemctl status spiffe-socat-unix@k8s-spire-server-a || true
|
||||||
|
sudo systemctl status spiffe-socat-unix@k8s-spire-server-b || true
|
||||||
|
sudo systemctl status spiffe-socat-unix@k8s-spire-agent-2-a || true
|
||||||
|
sudo systemctl status spiffe-socat-unix@k8s-spire-agent-2-b || true
|
||||||
|
sudo systemctl status spiffe-socat-unix@k8s-spire-agent-3-a || true
|
||||||
|
sudo systemctl status spiffe-socat-unix@k8s-spire-agent-3-b || true
|
||||||
|
sudo systemctl status spiffe-socat-unix@k8s-spire-agent-4-a || true
|
||||||
|
sudo systemctl status spiffe-socat-unix@k8s-spire-agent-4-b || true
|
||||||
|
sudo spire-server bundle list -socketPath /var/run/spire/server/sockets/a/private/api.sock || true
|
||||||
|
sudo spire-server bundle list -socketPath /var/run/spire/server/sockets/b/private/api.sock || true
|
||||||
|
kubectl exec -i -n spire-server spire-a-internal-server-0 -- spire-server entry show || true
|
||||||
|
kubectl exec -i -n spire-server spire-b-internal-server-0 -- spire-server entry show || true
|
||||||
|
kubectl exec -i -n spire-server spire-a-internal-server-0 -- spire-server agent list -output json | yq e . - -P || true
|
||||||
|
kubectl exec -i -n spire-server spire-b-internal-server-0 -- spire-server agent list -output json | yq e . - -P || true
|
||||||
|
|
||||||
|
print_helm_releases
|
||||||
|
|
||||||
|
if [[ "$1" -ne 0 ]]; then
|
||||||
|
get_namespace_details spire-server spire-system
|
||||||
|
kubectl describe pod -n spire-system
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ "${CLEANUP}" -eq 1 ]; then
|
||||||
|
helm uninstall --namespace spire-mgmt spire-b 2>/dev/null || true
|
||||||
|
helm uninstall --namespace spire-mgmt spire-a 2>/dev/null || true
|
||||||
|
helm uninstall --namespace spire-mgmt spire 2>/dev/null || true
|
||||||
|
kubectl delete ns spire-server 2>/dev/null || true
|
||||||
|
kubectl delete ns spire-system 2>/dev/null || true
|
||||||
|
kubectl delete ns spire-mgmt 2>/dev/null || true
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
trap 'EC=$? && trap - SIGTERM && teardown $EC' SIGINT SIGTERM EXIT
|
||||||
|
|
||||||
|
wait_for_healthcheck() {
|
||||||
|
local app="$1"
|
||||||
|
local socket="$2"
|
||||||
|
local timeout=30
|
||||||
|
local count=0
|
||||||
|
while [ "$count" -lt "$timeout" ]; do
|
||||||
|
rc=0
|
||||||
|
sudo "$app" healthcheck -socketPath "$socket" || rc=$?
|
||||||
|
if [ "$rc" -eq 0 ]; then
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
sleep 1
|
||||||
|
((count++)) || true
|
||||||
|
done
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
|
wait_for_trust_sync() {
|
||||||
|
local socket="$1"
|
||||||
|
local timeout=30
|
||||||
|
local count=0
|
||||||
|
while [ "$count" -lt "$timeout" ]; do
|
||||||
|
entries=$(sudo spire-server bundle list -socketPath "$socket" | wc -l)
|
||||||
|
if [ "$entries" -ne 0 ]; then
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
sleep 1
|
||||||
|
((count++)) || true
|
||||||
|
done
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
|
wait_for_jwt() {
|
||||||
|
local socket="$1"
|
||||||
|
local timeout=30
|
||||||
|
local count=0
|
||||||
|
while [ "$count" -lt "$timeout" ]; do
|
||||||
|
rc=0
|
||||||
|
sudo spire-agent api fetch jwt -audience test -socketPath "$socket" || rc=$?
|
||||||
|
if [ "$rc" -eq 0 ]; then
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
sleep 1
|
||||||
|
((count++)) || true
|
||||||
|
done
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
|
"${SCRIPTPATH}/../../.github/scripts/prepare-local-chart-deps.sh"
|
||||||
|
|
||||||
|
# Get the package repo and install the packages
|
||||||
|
sudo curl -s -o /etc/apt/sources.list.d/spire-examples.list https://raw.githubusercontent.com/spiffe/spire-examples/refs/heads/main/examples/debs/amd64/spire-examples.list
|
||||||
|
sudo apt-get update
|
||||||
|
sudo apt-get install -y spire-common spire-agent spire-server spire-controller-manager spiffe-socat-unix socat spire-trust-sync spiffe-helper
|
||||||
|
|
||||||
|
# Set our testing trust domain
|
||||||
|
sudo sed -i 's/example.org/production.other/' /etc/spiffe/default-trust-domain.env
|
||||||
|
|
||||||
|
# register some workloads with the spire server using manifests
|
||||||
|
sudo mkdir -p /etc/spire/server/a/manifests/ /etc/spire/server/b/manifests/
|
||||||
|
sudo cp "${SCRIPTPATH}/example-manifests"/* /etc/spire/server/a/manifests/
|
||||||
|
sudo cp "${SCRIPTPATH}/example-manifests"/* /etc/spire/server/b/manifests/
|
||||||
|
|
||||||
|
# For testing, help speed up the sync
|
||||||
|
sudo rm -f /etc/spire/server/a/manifests/node1-k8s-spire-server.yaml
|
||||||
|
sudo rm -f /etc/spire/server/b/manifests/node1-k8s-spire-server.yaml
|
||||||
|
|
||||||
|
# Since we are running the two root spire servers on the same machine, we need to ensure ports do not conflict for server b
|
||||||
|
sudo /bin/bash -c 'echo SPIRE_BIND_PORT=8082 > /etc/spire/server/b.env'
|
||||||
|
sudo /bin/bash -c '(echo METRICS_BIND_ADDRESS="0.0.0.0:9125"; echo HEALTH_PROBE_BIND_ADDRESS="0.0.0.0:9126") > /etc/spire/controller-manager/b.env'
|
||||||
|
|
||||||
|
# Startup servers and make sure they are ready
|
||||||
|
sudo systemctl start spire-server@a spire-server@b spire-controller-manager@a spire-controller-manager@b
|
||||||
|
wait_for_healthcheck spire-server /run/spire/server/sockets/a/private/api.sock
|
||||||
|
wait_for_healthcheck spire-server /run/spire/server/sockets/b/private/api.sock
|
||||||
|
|
||||||
|
# Configure our agents. For the test, create join tokens for both agents. You should really use a node attestor other then join tokens such as tpm-direct, http_challenge, or a cloud provider one
|
||||||
|
JOIN_TOKEN_A=$(sudo spire-server token generate -spiffeID spiffe://production.other/agent/node1 -socketPath /run/spire/server/sockets/a/private/api.sock | awk '{print "\""$2"\""}')
|
||||||
|
JOIN_TOKEN_B=$(sudo spire-server token generate -spiffeID spiffe://production.other/agent/node1 -socketPath /run/spire/server/sockets/b/private/api.sock | awk '{print "\""$2"\""}')
|
||||||
|
export JOIN_TOKEN_A
|
||||||
|
export JOIN_TOKEN_B
|
||||||
|
sudo /bin/bash -c "echo JOIN_TOKEN=${JOIN_TOKEN_A} > /etc/spire/agent/a.env"
|
||||||
|
sudo /bin/bash -c "echo JOIN_TOKEN=${JOIN_TOKEN_B} > /etc/spire/agent/b.env"
|
||||||
|
sudo /bin/bash -c "echo SPIRE_SERVER_PORT=8082 >> /etc/spire/agent/b.env"
|
||||||
|
|
||||||
|
# Since we are running the two root spire servers on the same machine, we need to configure the trust sync instances to point to the opposite server
|
||||||
|
sudo /bin/bash -c 'echo "SPIRE_SERVER_SOCKET=/var/run/spire/server/sockets/b/private/api.sock" > /etc/spire/trust-sync/a.conf'
|
||||||
|
sudo /bin/bash -c 'echo "SPIRE_SERVER_SOCKET=/var/run/spire/server/sockets/a/private/api.sock" > /etc/spire/trust-sync/b.conf'
|
||||||
|
|
||||||
|
# Startup the agent
|
||||||
|
sudo systemctl start spire-agent@a spire-agent@b
|
||||||
|
sudo systemctl start spire-trust-sync@a spire-trust-sync@b
|
||||||
|
wait_for_healthcheck spire-agent /var/run/spire/agent/sockets/a/public/api.sock
|
||||||
|
wait_for_healthcheck spire-agent /var/run/spire/agent/sockets/b/public/api.sock
|
||||||
|
wait_for_trust_sync /var/run/spire/server/sockets/a/private/api.sock
|
||||||
|
wait_for_trust_sync /var/run/spire/server/sockets/b/private/api.sock
|
||||||
|
|
||||||
|
sudo cp "${SCRIPTPATH}/example-manifests"/node1-k8s-spire-server.yaml /etc/spire/server/a/manifests/
|
||||||
|
sudo cp "${SCRIPTPATH}/example-manifests"/node1-k8s-spire-server.yaml /etc/spire/server/b/manifests/
|
||||||
|
|
||||||
|
# Startup the socat bridge to allow the k8s spire servers to get an identity/trust bundles from the host
|
||||||
|
sudo systemctl start spiffe-socat-unix@k8s-spire-server-a spiffe-socat-unix@k8s-spire-server-b
|
||||||
|
wait_for_healthcheck spire-agent /var/run/spiffe/socat/unix/k8s-spire-server-a/public/spire-agent.sock
|
||||||
|
wait_for_healthcheck spire-agent /var/run/spiffe/socat/unix/k8s-spire-server-b/public/spire-agent.sock
|
||||||
|
wait_for_jwt /var/run/spiffe/socat/unix/k8s-spire-server-a/public/spire-agent.sock
|
||||||
|
wait_for_jwt /var/run/spiffe/socat/unix/k8s-spire-server-b/public/spire-agent.sock
|
||||||
|
|
||||||
|
# Configure and start up the socat bridges to allow the k8s spire-agents to get an identity/trust bundles from the host.
|
||||||
|
# We only have one vm mapped to multiple k8s virtual nodes in kind, so we run a pair per k8s virtual node. Normally you would only run one pair per host/vm.
|
||||||
|
sudo /bin/bash -c "echo SPIFFE_INSTANCE=a > /etc/spiffe/socat/unix/k8s-spire-agent-2-a.conf"
|
||||||
|
sudo /bin/bash -c "echo SPIFFE_INSTANCE=a > /etc/spiffe/socat/unix/k8s-spire-agent-3-a.conf"
|
||||||
|
sudo /bin/bash -c "echo SPIFFE_INSTANCE=a > /etc/spiffe/socat/unix/k8s-spire-agent-4-a.conf"
|
||||||
|
sudo /bin/bash -c "echo SPIFFE_INSTANCE=b > /etc/spiffe/socat/unix/k8s-spire-agent-2-b.conf"
|
||||||
|
sudo /bin/bash -c "echo SPIFFE_INSTANCE=b > /etc/spiffe/socat/unix/k8s-spire-agent-3-b.conf"
|
||||||
|
sudo /bin/bash -c "echo SPIFFE_INSTANCE=b > /etc/spiffe/socat/unix/k8s-spire-agent-4-b.conf"
|
||||||
|
sudo systemctl start spiffe-socat-unix@k8s-spire-agent-2-a spiffe-socat-unix@k8s-spire-agent-2-b
|
||||||
|
sudo systemctl start spiffe-socat-unix@k8s-spire-agent-3-a spiffe-socat-unix@k8s-spire-agent-3-b
|
||||||
|
sudo systemctl start spiffe-socat-unix@k8s-spire-agent-4-a spiffe-socat-unix@k8s-spire-agent-4-b
|
||||||
|
wait_for_healthcheck spire-agent /var/run/spiffe/socat/unix/k8s-spire-agent-2-a/public/api.sock
|
||||||
|
wait_for_healthcheck spire-agent /var/run/spiffe/socat/unix/k8s-spire-agent-2-b/public/api.sock
|
||||||
|
wait_for_healthcheck spire-agent /var/run/spiffe/socat/unix/k8s-spire-agent-3-a/public/api.sock
|
||||||
|
wait_for_healthcheck spire-agent /var/run/spiffe/socat/unix/k8s-spire-agent-3-b/public/api.sock
|
||||||
|
wait_for_healthcheck spire-agent /var/run/spiffe/socat/unix/k8s-spire-agent-4-a/public/api.sock
|
||||||
|
wait_for_healthcheck spire-agent /var/run/spiffe/socat/unix/k8s-spire-agent-4-b/public/api.sock
|
||||||
|
wait_for_jwt /var/run/spiffe/socat/unix/k8s-spire-agent-2-a/public/api.sock
|
||||||
|
wait_for_jwt /var/run/spiffe/socat/unix/k8s-spire-agent-2-b/public/api.sock
|
||||||
|
wait_for_jwt /var/run/spiffe/socat/unix/k8s-spire-agent-3-a/public/api.sock
|
||||||
|
wait_for_jwt /var/run/spiffe/socat/unix/k8s-spire-agent-3-b/public/api.sock
|
||||||
|
wait_for_jwt /var/run/spiffe/socat/unix/k8s-spire-agent-4-a/public/api.sock
|
||||||
|
wait_for_jwt /var/run/spiffe/socat/unix/k8s-spire-agent-4-b/public/api.sock
|
||||||
|
|
||||||
|
# Deploy an ingress controller
|
||||||
|
IP=$(kubectl get nodes chart-testing-control-plane -o go-template='{{ range .status.addresses }}{{ if eq .type "InternalIP" }}{{ .address }}{{ end }}{{ end }}')
|
||||||
|
helm upgrade --install ingress-nginx ingress-nginx --version "$VERSION_INGRESS_NGINX" --repo "$HELM_REPO_INGRESS_NGINX" \
|
||||||
|
--namespace ingress-nginx \
|
||||||
|
--create-namespace \
|
||||||
|
--set "controller.extraArgs.enable-ssl-passthrough=,controller.admissionWebhooks.enabled=false,controller.service.type=ClusterIP,controller.service.externalIPs[0]=$IP" \
|
||||||
|
--set controller.ingressClassResource.default=true \
|
||||||
|
--wait
|
||||||
|
|
||||||
|
# Test the ingress controller. Should 404 as there is no services yet.
|
||||||
|
common_test_url "$IP"
|
||||||
|
|
||||||
|
# Get the host IP And add spire-server-[ab].${trust_domain} records to it so the spire-servers can talk back to root servers running on the host
|
||||||
|
HOSTIP=$(ip addr show docker0 | grep 'inet ' | awk '{print $2}' | cut -d/ -f1)
|
||||||
|
kubectl get configmap -n kube-system coredns -o yaml | grep hosts || kubectl get configmap -n kube-system coredns -o yaml | sed "/ready/a\ hosts {\n fallthrough\n }" | kubectl apply -f -
|
||||||
|
kubectl get configmap -n kube-system coredns -o yaml | grep production.other || kubectl get configmap -n kube-system coredns -o yaml | sed "/hosts/a\ $HOSTIP spire-server-a.production.other\n $HOSTIP oidc-discovery.production.other\n $HOSTIP spire-server-b.production.other\n" | kubectl apply -f -
|
||||||
|
kubectl rollout restart -n kube-system deployment/coredns
|
||||||
|
kubectl rollout status -n kube-system -w --timeout=1m deploy/coredns
|
||||||
|
|
||||||
|
# Install the common components
|
||||||
|
helm upgrade --install --create-namespace --namespace spire-mgmt --values "${COMMON_TEST_YOUR_VALUES},${SCRIPTPATH}/spire-values.yaml" \
|
||||||
|
spire charts/spire-nested \
|
||||||
|
--set tags.haAgentCommon=true \
|
||||||
|
--set "global.spire.namespaces.create=true" \
|
||||||
|
--set "global.spire.ingressControllerType=ingress-nginx" \
|
||||||
|
--set "spiffe-oidc-discovery-provider.ingress.enabled=true"
|
||||||
|
|
||||||
|
# Install server side a
|
||||||
|
helm upgrade --install --namespace spire-mgmt --values "${COMMON_TEST_YOUR_VALUES},${SCRIPTPATH}/spire-values.yaml" \
|
||||||
|
--wait spire-a charts/spire-nested \
|
||||||
|
--set tags.bottomTurtleHAA=true \
|
||||||
|
--set "global.spire.ingressControllerType=ingress-nginx"
|
||||||
|
|
||||||
|
docker exec -i chart-testing-worker /bin/bash -c "more /var/lib/kubelet/pods/*/volumes/kubernetes.io~empty-dir/disk-keymanager/keys.json /var/lib/kubelet/pods/*/volumes/kubernetes.io~empty-dir/spire-agent-persistence/agent-data.json | cat"
|
||||||
|
|
||||||
|
# Rollout just to sped up the tests
|
||||||
|
kubectl patch deployment spiffe-oidc-discovery-provider -n spire-server --type='strategic' -p '{"spec": {"strategy": {"type": "Recreate", "rollingUpdate": null}}}'
|
||||||
|
kubectl rollout restart daemonset -n spire-system spire-ha-agent
|
||||||
|
kubectl rollout status daemonset -n spire-system spire-ha-agent
|
||||||
|
kubectl rollout restart deployment -n spire-server spiffe-oidc-discovery-provider
|
||||||
|
kubectl rollout status deployment -n spire-server spiffe-oidc-discovery-provider --timeout=1m
|
||||||
|
kubectl wait -n spire-server --for=condition=ready pod -l "app.kubernetes.io/name=spiffe-oidc-discovery-provider" --field-selector=status.phase=Running --timeout=90s
|
||||||
|
curl -k --resolve "oidc-discovery.production.other:443:$IP" "https://oidc-discovery.production.other/.well-known/openid-configuration" -s --fail
|
||||||
|
|
||||||
|
# Install server side b
|
||||||
|
helm upgrade --install --namespace spire-mgmt --values "${COMMON_TEST_YOUR_VALUES},${SCRIPTPATH}/spire-values.yaml" \
|
||||||
|
--wait spire-b charts/spire-nested \
|
||||||
|
--set tags.bottomTurtleHAB=true \
|
||||||
|
--set internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.server.port=8082 \
|
||||||
|
--set "global.spire.ingressControllerType=ingress-nginx"
|
||||||
|
|
||||||
|
docker ps
|
||||||
|
docker exec -i chart-testing-worker /bin/bash -c "more /var/lib/kubelet/pods/*/volumes/kubernetes.io~empty-dir/disk-keymanager/keys.json /var/lib/kubelet/pods/*/volumes/kubernetes.io~empty-dir/spire-agent-persistence/agent-data.json | cat"
|
||||||
|
|
||||||
|
# From here on out, we sanity check that everything is working properly with both servers running.
|
||||||
|
|
||||||
|
ENTRIES="$(kubectl exec -i -n spire-server spire-b-internal-server-0 -- spire-server entry show)"
|
||||||
|
if [[ "${ENTRIES}" == "Found 0 entries" ]]; then
|
||||||
|
echo "${ENTRIES}"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
ENTRIES="$(kubectl exec -i -n spire-server spire-a-internal-server-0 -- spire-server entry show)"
|
||||||
|
if [[ "${ENTRIES}" == "Found 0 entries" ]]; then
|
||||||
|
echo "${ENTRIES}"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
kubectl get pods -A -o wide
|
||||||
|
|
||||||
|
helm test --namespace spire-mgmt spire-a
|
||||||
|
helm test --namespace spire-mgmt spire-b
|
||||||
|
curl -k --resolve "oidc-discovery.production.other:443:$IP" "https://oidc-discovery.production.other/.well-known/openid-configuration" -s --fail
|
||||||
|
|
||||||
|
#Test out running only on side b since we know already only both servers work together, and that only side a works if we made it this far.
|
||||||
|
helm delete -n spire-mgmt spire-a
|
||||||
|
kubectl rollout restart daemonset -n spire-system spire-ha-agent
|
||||||
|
kubectl rollout status daemonset -n spire-system spire-ha-agent
|
||||||
|
kubectl rollout restart deployment -n spire-server spiffe-oidc-discovery-provider
|
||||||
|
kubectl rollout status deployment -n spire-server spiffe-oidc-discovery-provider --timeout=1m
|
||||||
|
curl -k --resolve "oidc-discovery.production.other:443:$IP" "https://oidc-discovery.production.other/.well-known/openid-configuration" -s --fail
|
||||||
|
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
global:
|
||||||
|
spire:
|
||||||
|
recommendations:
|
||||||
|
enabled: true
|
||||||
|
namespaces:
|
||||||
|
create: false
|
||||||
|
#ingressControllerType: ""
|
||||||
|
#clusterName: example-cluster
|
||||||
|
#trustDomain: example.org
|
||||||
|
#caSubject:
|
||||||
|
# country: ""
|
||||||
|
# organization: ""
|
||||||
|
# commonName: ""
|
||||||
@@ -123,16 +123,13 @@ echo "${IP} spire-server.production.other spiffe-step-ssh.production.other spiff
|
|||||||
echo Hosts:
|
echo Hosts:
|
||||||
cat /etc/hosts
|
cat /etc/hosts
|
||||||
|
|
||||||
curl -L https://raw.githubusercontent.com/kfox1111/spire-examples/refs/heads/spiffe-step-ssh/examples/spiffe-step-ssh/scripts/demo.sh | sudo bash
|
# Get the package repo and install the packages
|
||||||
|
curl -o /tmp/stepcli.deb https://dl.smallstep.com/gh-release/cli/gh-release-header/v0.30.2/step-cli_0.30.2-1_amd64.deb -L
|
||||||
|
sudo dpkg -i /tmp/stepcli.deb
|
||||||
|
sudo curl -s -o /etc/apt/sources.list.d/spire-examples.list https://raw.githubusercontent.com/spiffe/spire-examples/refs/heads/main/examples/debs/amd64/spire-examples.list
|
||||||
|
sudo apt-get update
|
||||||
|
sudo apt-get install -y spire-common spire-agent spiffe-step-ssh spiffe-helper
|
||||||
|
|
||||||
sudo mkdir -p /usr/libexec/spiffe-step-ssh
|
|
||||||
sudo mkdir -p /etc/systemd/system/sshd.service.d
|
|
||||||
sudo curl -L -o /usr/libexec/spiffe-step-ssh/update.sh https://raw.githubusercontent.com/kfox1111/spire-examples/refs/heads/spiffe-step-ssh/examples/spiffe-step-ssh/scripts/update.sh
|
|
||||||
sudo curl -L -o /etc/systemd/system/[email protected] https://raw.githubusercontent.com/kfox1111/spire-examples/refs/heads/spiffe-step-ssh/examples/spiffe-step-ssh/systemd/[email protected]
|
|
||||||
sudo curl -L -o /etc/systemd/system/spiffe-step-ssh-cleanup.service https://raw.githubusercontent.com/kfox1111/spire-examples/refs/heads/spiffe-step-ssh/examples/spiffe-step-ssh/systemd/spiffe-step-ssh-cleanup.service
|
|
||||||
sudo curl -L -o /etc/systemd/system/sshd.service.d/10-spiffe-step-ssh.conf https://raw.githubusercontent.com/kfox1111/spire-examples/refs/heads/spiffe-step-ssh/examples/spiffe-step-ssh/conf/10-spiffe-step-ssh.conf
|
|
||||||
|
|
||||||
sudo mkdir -p /etc/spire/agent
|
|
||||||
sudo cp "${SCRIPTPATH}/spire-agent.conf" /etc/spire/agent/main.conf
|
sudo cp "${SCRIPTPATH}/spire-agent.conf" /etc/spire/agent/main.conf
|
||||||
|
|
||||||
PASSWORD=$(openssl rand -base64 48)
|
PASSWORD=$(openssl rand -base64 48)
|
||||||
|
|||||||
Reference in New Issue
Block a user