Merge branch 'main' into release
This commit is contained in:
@@ -2,12 +2,12 @@
|
||||
{
|
||||
"name": "kube-prometheus-stack",
|
||||
"repo": "https://prometheus-community.github.io/helm-charts",
|
||||
"version": "45.26.0"
|
||||
"version": "45.29.0"
|
||||
},
|
||||
{
|
||||
"name": "cert-manager",
|
||||
"repo": "https://charts.jetstack.io",
|
||||
"version": "v1.11.1"
|
||||
"version": "v1.12.0"
|
||||
},
|
||||
{
|
||||
"name": "ingress-nginx",
|
||||
@@ -17,11 +17,11 @@
|
||||
{
|
||||
"name": "mysql",
|
||||
"repo": "https://charts.bitnami.com/bitnami",
|
||||
"version": "9.7.2"
|
||||
"version": "9.10.1"
|
||||
},
|
||||
{
|
||||
"name": "postgresql",
|
||||
"repo": "https://charts.bitnami.com/bitnami",
|
||||
"version": "12.2.2"
|
||||
"version": "12.5.3"
|
||||
}
|
||||
]
|
||||
|
||||
@@ -1,3 +1,23 @@
|
||||
spire-server:
|
||||
ingress:
|
||||
enabled: true
|
||||
className: "nginx"
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
|
||||
nginx.ingress.kubernetes.io/ssl-passthrough: "true"
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||
hosts:
|
||||
- host: ingress-nginx-controller.spire-oidc-insecure
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
|
||||
spire-agent:
|
||||
server:
|
||||
address: ingress-nginx-controller.spire-oidc-insecure
|
||||
port: 443
|
||||
|
||||
spiffe-oidc-discovery-provider:
|
||||
enabled: true
|
||||
|
||||
|
||||
Executable
+13
@@ -0,0 +1,13 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
set -x
|
||||
|
||||
SCRIPT=$(readlink -f "$0")
|
||||
SCRIPTPATH=$(dirname "$SCRIPT")
|
||||
|
||||
helm install \
|
||||
--namespace spire-server \
|
||||
--values "${SCRIPTPATH}/../../../examples/production/values.yaml" \
|
||||
--values "${SCRIPTPATH}/../../../examples/tornjak/values.yaml" \
|
||||
spire charts/spire --wait
|
||||
helm test spire -n spire-server
|
||||
Executable
+23
@@ -0,0 +1,23 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
set -x
|
||||
|
||||
SCRIPT="$(readlink -f "$0")"
|
||||
SCRIPTPATH="$(dirname "${SCRIPT}")"
|
||||
scenario="${scenario:-$(basename "${SCRIPTPATH}")}"
|
||||
|
||||
# shellcheck source=/dev/null
|
||||
source "${SCRIPTPATH}/../common.sh"
|
||||
|
||||
print_helm_releases
|
||||
print_spire_workload_status spire-server spire-system
|
||||
|
||||
kubectl rollout status --watch --timeout 180s --namespace spire-server deployments.apps spire-tornjak-frontend
|
||||
kubectl -n spire-server get deploy spire-tornjak-frontend
|
||||
kubectl -n spire-server get service spire-tornjak-frontend
|
||||
|
||||
|
||||
if [[ "$1" -ne 0 ]]; then
|
||||
get_namespace_details spire-server
|
||||
get_namespace_details spire-system
|
||||
fi
|
||||
Executable
+6
@@ -0,0 +1,6 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
kubectl create namespace spire-system
|
||||
kubectl label namespace spire-system pod-security.kubernetes.io/enforce=privileged
|
||||
kubectl create namespace spire-server
|
||||
kubectl label namespace spire-server pod-security.kubernetes.io/enforce=restricted
|
||||
@@ -36,6 +36,7 @@ jobs:
|
||||
id: cpr
|
||||
uses: peter-evans/[email protected]
|
||||
with:
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
title: Bump test chart dependencies
|
||||
branch: bump-test-chart-deps
|
||||
commit-message: Bump test chart dependencies
|
||||
|
||||
@@ -0,0 +1,60 @@
|
||||
name: Helm Chart CI
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [synchronize, opened, reopened]
|
||||
paths-ignore:
|
||||
- 'charts/**'
|
||||
- '.github/workflows/helm-chart-ci.yaml'
|
||||
- '.github/kind/conf/kind-config.yaml'
|
||||
- '.github/tests/**/*.yaml'
|
||||
- '.github/tests/**/*.sh'
|
||||
- '.github/tests/**/*.json'
|
||||
- 'examples/**/*.yaml'
|
||||
- 'helm-docs.sh'
|
||||
|
||||
jobs:
|
||||
lint-chart:
|
||||
runs-on: ubuntu-22.04
|
||||
steps:
|
||||
- run: 'echo "Skipping linter"'
|
||||
|
||||
checks:
|
||||
runs-on: ubuntu-22.04
|
||||
steps:
|
||||
- run: 'echo "Skipping checks"'
|
||||
|
||||
build-matrix:
|
||||
name: Build matrix
|
||||
runs-on: ubuntu-22.04
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/[email protected]
|
||||
|
||||
- id: set-matrix
|
||||
name: Collect all tests
|
||||
run: |
|
||||
tests="$(echo -e "default\n$(find .github/tests -maxdepth 1 -type d | grep -Ev 'tests$' | xargs -I % basename % | sort | uniq)")"
|
||||
tests_json="$(echo "$tests" | jq -c --slurp --raw-input 'split("\n") | map(select(. != ""))')"
|
||||
echo "tests=$tests_json" >> $GITHUB_OUTPUT
|
||||
|
||||
outputs:
|
||||
tests: ${{ steps.set-matrix.outputs.tests }}
|
||||
|
||||
test:
|
||||
runs-on: ubuntu-22.04
|
||||
needs:
|
||||
- build-matrix
|
||||
|
||||
strategy:
|
||||
matrix:
|
||||
k8s:
|
||||
- v1.27.0
|
||||
- v1.26.3
|
||||
- v1.25.8
|
||||
values:
|
||||
- ${{ fromJson(needs.build-matrix.outputs.tests) }}
|
||||
|
||||
steps:
|
||||
- run: 'echo "Skipping tests"'
|
||||
@@ -10,6 +10,7 @@ on:
|
||||
- '.github/kind/conf/kind-config.yaml'
|
||||
- '.github/tests/**/*.yaml'
|
||||
- '.github/tests/**/*.sh'
|
||||
- '.github/tests/**/*.json'
|
||||
- 'examples/**/*.yaml'
|
||||
- 'helm-docs.sh'
|
||||
|
||||
@@ -92,14 +93,6 @@ jobs:
|
||||
with:
|
||||
version: ${{ env.CHART_TESTING_VERSION }}
|
||||
|
||||
- name: Run chart-testing (list-changed)
|
||||
id: list-changed
|
||||
run: |
|
||||
changed=$(ct list-changed --target-branch ${{ github.base_ref }})
|
||||
if [[ -n "$changed" ]]; then
|
||||
echo "changed=true" >> $GITHUB_OUTPUT
|
||||
fi
|
||||
|
||||
- name: Run chart-testing (lint)
|
||||
run: |
|
||||
ct lint --debug ${{ github.base_ref != 'release' && '--check-version-increment=false' || '' }} \
|
||||
@@ -114,8 +107,6 @@ jobs:
|
||||
|
||||
needs: [lint-chart]
|
||||
|
||||
if: needs.lint-chart.outputs.changed == 'true'
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/[email protected]
|
||||
@@ -137,8 +128,6 @@ jobs:
|
||||
- lint-chart
|
||||
- build-matrix
|
||||
|
||||
if: needs.lint-chart.outputs.changed == 'true'
|
||||
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
@@ -153,7 +142,6 @@ jobs:
|
||||
- v1.24.12
|
||||
- v1.23.17
|
||||
- v1.22.17
|
||||
- v1.21.14
|
||||
values:
|
||||
- ${{ fromJson(needs.build-matrix.outputs.tests) }}
|
||||
|
||||
@@ -179,7 +167,7 @@ jobs:
|
||||
version: ${{ env.CHART_TESTING_VERSION }}
|
||||
|
||||
- name: Create kind ${{ matrix.k8s }} cluster
|
||||
uses: helm/kind-action@v1.5.0
|
||||
uses: helm/kind-action@v1.7.0
|
||||
# Only build a kind cluster if there are chart changes to test.
|
||||
with:
|
||||
version: v0.18.0
|
||||
@@ -209,6 +197,7 @@ jobs:
|
||||
"${TEST_DIR}/install.sh"
|
||||
else
|
||||
ct install --debug \
|
||||
--charts "charts/spire" \
|
||||
--namespace "${scenario}" \
|
||||
--target-branch ${{ github.base_ref }} \
|
||||
--exclude-deprecated \
|
||||
|
||||
@@ -29,7 +29,7 @@ jobs:
|
||||
git config user.email "[email protected]"
|
||||
|
||||
- name: Setup cosign
|
||||
uses: sigstore/[email protected].3
|
||||
uses: sigstore/[email protected].5
|
||||
with:
|
||||
cosign-release: v2.0.2
|
||||
|
||||
|
||||
@@ -23,9 +23,9 @@ Unless otherwise noted in an application chart README, the following dependencie
|
||||
|:-----------|:-------------------|
|
||||
| SPIRE | `1.5.3`+, `1.6.x` |
|
||||
| Helm | `3.x` |
|
||||
| Kubernetes | `1.21+` |
|
||||
| Kubernetes | `1.22+` |
|
||||
|
||||
> **Note**: For Kubernetes, we will officially support the last 3 versions as described in [k8s versioning](https://kubernetes.io/releases/version-skew-policy/#supported-versions). Any version before the last 3 we will try to support as long it doesn't bring security issues or any big maintenance burden. *The first version we tested this chart with is `1.21`.*
|
||||
> **Note**: For Kubernetes, we will officially support the last 3 versions as described in [k8s versioning](https://kubernetes.io/releases/version-skew-policy/#supported-versions). Any version before the last 3 we will try to support as long it doesn't bring security issues or any big maintenance burden. *The first version we tested this chart with is `1.22`.*
|
||||
|
||||
## Contributing
|
||||
|
||||
|
||||
@@ -3,8 +3,8 @@ name: spire
|
||||
description: >
|
||||
A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.
|
||||
type: application
|
||||
version: 0.7.0
|
||||
appVersion: "1.6.3"
|
||||
version: 0.8.0
|
||||
appVersion: "1.6.4"
|
||||
keywords: ["spiffe", "spire", "spire-server", "spire-agent", "oidc", "spire-controller-manager"]
|
||||
home: https://github.com/spiffe/helm-charts/tree/main/charts/spire
|
||||
sources:
|
||||
@@ -38,6 +38,10 @@ dependencies:
|
||||
condition: spiffe-oidc-discovery-provider.enabled
|
||||
repository: file://./charts/spiffe-oidc-discovery-provider
|
||||
version: 0.1.0
|
||||
- name: tornjak-frontend
|
||||
condition: tornjak-frontend.enabled
|
||||
repository: file://./charts/tornjak-frontend
|
||||
version: 0.1.0
|
||||
annotations:
|
||||
artifacthub.io/category: security
|
||||
artifacthub.io/license: Apache-2.0
|
||||
|
||||
+91
-23
@@ -2,7 +2,7 @@
|
||||
|
||||
<!-- This README.md is generated. Please edit README.md.gotmpl -->
|
||||
|
||||
  
|
||||
  
|
||||
[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
|
||||
|
||||
A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.
|
||||
@@ -19,9 +19,9 @@ A Helm chart for deploying the complete Spire stack including: spire-server, spi
|
||||
|:-----------|:-------------------|
|
||||
| SPIRE | `1.5.3+`, `1.6.3+` |
|
||||
| Helm | `3.x` |
|
||||
| Kubernetes | `1.21+` |
|
||||
| Kubernetes | `1.22+` |
|
||||
|
||||
> **Note**: For Kubernetes, we will officially support the last 3 versions as described in [k8s versioning](https://kubernetes.io/releases/version-skew-policy/#supported-versions). Any version before the last 3 we will try to support as long it doesn't bring security issues or any big maintenance burden. *The first version we tested this chart with is `1.21`.*
|
||||
> **Note**: For Kubernetes, we will officially support the last 3 versions as described in [k8s versioning](https://kubernetes.io/releases/version-skew-policy/#supported-versions). Any version before the last 3 we will try to support as long it doesn't bring security issues or any big maintenance burden.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
@@ -96,14 +96,13 @@ Now you can interact with the Spire agent socket from your own application. The
|
||||
|
||||
## Requirements
|
||||
|
||||
Kubernetes: `>=1.21.0-0`
|
||||
|
||||
| Repository | Name | Version |
|
||||
|------------|------|---------|
|
||||
| file://./charts/spiffe-csi-driver | spiffe-csi-driver | 0.1.0 |
|
||||
| file://./charts/spiffe-oidc-discovery-provider | spiffe-oidc-discovery-provider | 0.1.0 |
|
||||
| file://./charts/spire-agent | spire-agent | 0.1.0 |
|
||||
| file://./charts/spire-server | spire-server | 0.1.0 |
|
||||
| file://./charts/tornjak-frontend | tornjak-frontend | 0.1.0 |
|
||||
|
||||
## Values
|
||||
|
||||
@@ -114,20 +113,22 @@ Kubernetes: `>=1.21.0-0`
|
||||
| global.spire.clusterName | string | `"example-cluster"` | |
|
||||
| global.spire.image.registry | string | `""` | Override all Spire image registries at once |
|
||||
| global.spire.trustDomain | string | `"example.org"` | The trust domain to be used for the SPIFFE identifiers |
|
||||
| spiffe-csi-driver.enabled | bool | `true` | |
|
||||
| spiffe-oidc-discovery-provider.enabled | bool | `false` | |
|
||||
| spire-agent.enabled | bool | `true` | |
|
||||
| spiffe-csi-driver.enabled | bool | `true` | Enables deployment of CSI driver |
|
||||
| spiffe-oidc-discovery-provider.enabled | bool | `false` | Enables deployment of OIDC discovery provider |
|
||||
| spire-agent.enabled | bool | `true` | Enables deployment of SPIRE Agent(s) |
|
||||
| spire-agent.nameOverride | string | `"agent"` | |
|
||||
| spire-server.controllerManager.enabled | bool | `true` | |
|
||||
| spire-server.enabled | bool | `true` | |
|
||||
| spire-server.controllerManager.enabled | bool | `true` | Enables deployment of Controller Manager |
|
||||
| spire-server.enabled | bool | `true` | Enables deployment of SPIRE Server |
|
||||
| spire-server.nameOverride | string | `"server"` | |
|
||||
| tornjak-frontend.enabled | bool | `false` | Enables deployment of Tornjak frontend/UI (Not for production) |
|
||||
| spiffe-csi-driver.agentSocketPath | string | `"/run/spire/agent-sockets/spire-agent.sock"` | The unix socket path to the spire-agent |
|
||||
| spiffe-csi-driver.fullnameOverride | string | `""` | |
|
||||
| spiffe-csi-driver.healthChecks.port | int | `9809` | |
|
||||
| spiffe-csi-driver.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| spiffe-csi-driver.image.registry | string | `"ghcr.io"` | The OCI registry to pull the image from |
|
||||
| spiffe-csi-driver.image.repository | string | `"spiffe/spiffe-csi-driver"` | The repository within the registry |
|
||||
| spiffe-csi-driver.image.version | string | `""` | Overrides the image tag whose default is the chart appVersion |
|
||||
| spiffe-csi-driver.image.tag | string | `""` | Overrides the image tag whose default is the chart appVersion |
|
||||
| spiffe-csi-driver.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| spiffe-csi-driver.imagePullSecrets | list | `[]` | |
|
||||
| spiffe-csi-driver.kubeletPath | string | `"/var/lib/kubelet"` | |
|
||||
| spiffe-csi-driver.nameOverride | string | `""` | |
|
||||
@@ -135,7 +136,8 @@ Kubernetes: `>=1.21.0-0`
|
||||
| spiffe-csi-driver.nodeDriverRegistrar.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| spiffe-csi-driver.nodeDriverRegistrar.image.registry | string | `"registry.k8s.io"` | The OCI registry to pull the image from |
|
||||
| spiffe-csi-driver.nodeDriverRegistrar.image.repository | string | `"sig-storage/csi-node-driver-registrar"` | The repository within the registry |
|
||||
| spiffe-csi-driver.nodeDriverRegistrar.image.version | string | `"v2.6.2"` | |
|
||||
| spiffe-csi-driver.nodeDriverRegistrar.image.tag | string | `"v2.8.0"` | Overrides the image tag |
|
||||
| spiffe-csi-driver.nodeDriverRegistrar.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| spiffe-csi-driver.nodeDriverRegistrar.resources | object | `{}` | |
|
||||
| spiffe-csi-driver.nodeSelector | object | `{}` | |
|
||||
| spiffe-csi-driver.pluginName | string | `"csi.spiffe.io"` | Set the csi driver name deployed to Kubernetes. |
|
||||
@@ -168,7 +170,8 @@ Kubernetes: `>=1.21.0-0`
|
||||
| spiffe-oidc-discovery-provider.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| spiffe-oidc-discovery-provider.image.registry | string | `"ghcr.io"` | The OCI registry to pull the image from |
|
||||
| spiffe-oidc-discovery-provider.image.repository | string | `"spiffe/oidc-discovery-provider"` | The repository within the registry |
|
||||
| spiffe-oidc-discovery-provider.image.version | string | `""` | Overrides the image tag whose default is the chart appVersion |
|
||||
| spiffe-oidc-discovery-provider.image.tag | string | `""` | Overrides the image tag whose default is the chart appVersion |
|
||||
| spiffe-oidc-discovery-provider.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| spiffe-oidc-discovery-provider.imagePullSecrets | list | `[]` | |
|
||||
| spiffe-oidc-discovery-provider.ingress.annotations | object | `{}` | |
|
||||
| spiffe-oidc-discovery-provider.ingress.className | string | `""` | |
|
||||
@@ -181,7 +184,8 @@ Kubernetes: `>=1.21.0-0`
|
||||
| spiffe-oidc-discovery-provider.insecureScheme.nginx.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| spiffe-oidc-discovery-provider.insecureScheme.nginx.image.registry | string | `"docker.io"` | The OCI registry to pull the image from |
|
||||
| spiffe-oidc-discovery-provider.insecureScheme.nginx.image.repository | string | `"nginxinc/nginx-unprivileged"` | The repository within the registry |
|
||||
| spiffe-oidc-discovery-provider.insecureScheme.nginx.image.version | string | `"1.23.2-alpine"` | |
|
||||
| spiffe-oidc-discovery-provider.insecureScheme.nginx.image.tag | string | `"1.24.0-alpine"` | Overrides the image tag |
|
||||
| spiffe-oidc-discovery-provider.insecureScheme.nginx.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| spiffe-oidc-discovery-provider.insecureScheme.nginx.resources | object | `{}` | |
|
||||
| spiffe-oidc-discovery-provider.nameOverride | string | `""` | |
|
||||
| spiffe-oidc-discovery-provider.namespaceOverride | string | `""` | |
|
||||
@@ -201,7 +205,8 @@ Kubernetes: `>=1.21.0-0`
|
||||
| spiffe-oidc-discovery-provider.telemetry.prometheus.nginxExporter.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| spiffe-oidc-discovery-provider.telemetry.prometheus.nginxExporter.image.registry | string | `"docker.io"` | The OCI registry to pull the image from |
|
||||
| spiffe-oidc-discovery-provider.telemetry.prometheus.nginxExporter.image.repository | string | `"nginx/nginx-prometheus-exporter"` | The repository within the registry |
|
||||
| spiffe-oidc-discovery-provider.telemetry.prometheus.nginxExporter.image.version | string | `"0.11.0"` | |
|
||||
| spiffe-oidc-discovery-provider.telemetry.prometheus.nginxExporter.image.tag | string | `"0.11.0"` | Overrides the image tag |
|
||||
| spiffe-oidc-discovery-provider.telemetry.prometheus.nginxExporter.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| spiffe-oidc-discovery-provider.telemetry.prometheus.nginxExporter.resources | object | `{}` | |
|
||||
| spiffe-oidc-discovery-provider.telemetry.prometheus.podMonitor.enabled | bool | `false` | |
|
||||
| spiffe-oidc-discovery-provider.telemetry.prometheus.podMonitor.labels | object | `{}` | |
|
||||
@@ -220,7 +225,8 @@ Kubernetes: `>=1.21.0-0`
|
||||
| spire-agent.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| spire-agent.image.registry | string | `"ghcr.io"` | The OCI registry to pull the image from |
|
||||
| spire-agent.image.repository | string | `"spiffe/spire-agent"` | The repository within the registry |
|
||||
| spire-agent.image.version | string | `""` | |
|
||||
| spire-agent.image.tag | string | `""` | Overrides the image tag whose default is the chart appVersion. |
|
||||
| spire-agent.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| spire-agent.imagePullSecrets | list | `[]` | |
|
||||
| spire-agent.initContainers | list | `[]` | |
|
||||
| spire-agent.logLevel | string | `"info"` | The log level, valid values are "debug", "info", "warn", and "error" |
|
||||
@@ -250,7 +256,8 @@ Kubernetes: `>=1.21.0-0`
|
||||
| spire-agent.waitForIt.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| spire-agent.waitForIt.image.registry | string | `"cgr.dev"` | The OCI registry to pull the image from |
|
||||
| spire-agent.waitForIt.image.repository | string | `"chainguard/wait-for-it"` | The repository within the registry |
|
||||
| spire-agent.waitForIt.image.version | string | `"latest-20230113"` | |
|
||||
| spire-agent.waitForIt.image.tag | string | `"latest-20230517"` | Overrides the image tag |
|
||||
| spire-agent.waitForIt.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| spire-agent.waitForIt.resources | object | `{}` | |
|
||||
| spire-agent.workloadAttestors.k8s.skipKubeletVerification | bool | `true` | If true, kubelet certificate verification is skipped |
|
||||
| spire-agent.workloadAttestors.unix.enabled | bool | `false` | enables the Unix workload attestor |
|
||||
@@ -281,7 +288,8 @@ Kubernetes: `>=1.21.0-0`
|
||||
| spire-server.controllerManager.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| spire-server.controllerManager.image.registry | string | `"ghcr.io"` | The OCI registry to pull the image from |
|
||||
| spire-server.controllerManager.image.repository | string | `"spiffe/spire-controller-manager"` | The repository within the registry |
|
||||
| spire-server.controllerManager.image.version | string | `"0.2.2"` | |
|
||||
| spire-server.controllerManager.image.tag | string | `"0.2.2"` | Overrides the image tag |
|
||||
| spire-server.controllerManager.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| spire-server.controllerManager.resources | object | `{}` | |
|
||||
| spire-server.controllerManager.securityContext | object | `{}` | |
|
||||
| spire-server.controllerManager.service.annotations | object | `{}` | |
|
||||
@@ -289,9 +297,10 @@ Kubernetes: `>=1.21.0-0`
|
||||
| spire-server.controllerManager.service.type | string | `"ClusterIP"` | |
|
||||
| spire-server.controllerManager.validatingWebhookConfiguration.failurePolicy | string | `"Fail"` | |
|
||||
| spire-server.controllerManager.validatingWebhookConfiguration.upgradeHook.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| spire-server.controllerManager.validatingWebhookConfiguration.upgradeHook.image.registry | string | `"cgr.dev"` | The OCI registry to pull the image from |
|
||||
| spire-server.controllerManager.validatingWebhookConfiguration.upgradeHook.image.repository | string | `"chainguard/kubectl"` | The repository within the registry |
|
||||
| spire-server.controllerManager.validatingWebhookConfiguration.upgradeHook.image.version | string | `"latest"` | |
|
||||
| spire-server.controllerManager.validatingWebhookConfiguration.upgradeHook.image.registry | string | `"docker.io"` | The OCI registry to pull the image from |
|
||||
| spire-server.controllerManager.validatingWebhookConfiguration.upgradeHook.image.repository | string | `"rancher/kubectl"` | The repository within the registry |
|
||||
| spire-server.controllerManager.validatingWebhookConfiguration.upgradeHook.image.tag | string | `""` | Overrides the image tag |
|
||||
| spire-server.controllerManager.validatingWebhookConfiguration.upgradeHook.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| spire-server.dataStore.sql.databaseName | string | `"spire"` | Only used by "postgres" or "mysql" |
|
||||
| spire-server.dataStore.sql.databaseType | string | `"sqlite3"` | Other supported databases are "postgres" and "mysql" |
|
||||
| spire-server.dataStore.sql.host | string | `""` | Only used by "postgres" or "mysql" |
|
||||
@@ -308,12 +317,27 @@ Kubernetes: `>=1.21.0-0`
|
||||
| spire-server.federation.bundleEndpoint.address | string | `"0.0.0.0"` | |
|
||||
| spire-server.federation.bundleEndpoint.port | int | `8443` | |
|
||||
| spire-server.federation.enabled | bool | `false` | |
|
||||
| spire-server.federation.ingress.annotations | object | `{}` | |
|
||||
| spire-server.federation.ingress.className | string | `""` | |
|
||||
| spire-server.federation.ingress.enabled | bool | `false` | |
|
||||
| spire-server.federation.ingress.hosts[0].host | string | `"spire-server-federation.example.org"` | |
|
||||
| spire-server.federation.ingress.hosts[0].paths[0].path | string | `"/"` | |
|
||||
| spire-server.federation.ingress.hosts[0].paths[0].pathType | string | `"Prefix"` | |
|
||||
| spire-server.federation.ingress.tls | list | `[]` | |
|
||||
| spire-server.fullnameOverride | string | `""` | |
|
||||
| spire-server.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| spire-server.image.registry | string | `"ghcr.io"` | The OCI registry to pull the image from |
|
||||
| spire-server.image.repository | string | `"spiffe/spire-server"` | The repository within the registry |
|
||||
| spire-server.image.version | string | `""` | |
|
||||
| spire-server.image.tag | string | `""` | Overrides the image tag whose default is the chart appVersion. |
|
||||
| spire-server.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| spire-server.imagePullSecrets | list | `[]` | |
|
||||
| spire-server.ingress.annotations | object | `{}` | |
|
||||
| spire-server.ingress.className | string | `""` | |
|
||||
| spire-server.ingress.enabled | bool | `false` | |
|
||||
| spire-server.ingress.hosts[0].host | string | `"spire-server.example.org"` | |
|
||||
| spire-server.ingress.hosts[0].paths[0].path | string | `"/"` | |
|
||||
| spire-server.ingress.hosts[0].paths[0].pathType | string | `"Prefix"` | |
|
||||
| spire-server.ingress.tls | list | `[]` | |
|
||||
| spire-server.initContainers | list | `[]` | |
|
||||
| spire-server.jwtIssuer | string | `"oidc-discovery.example.org"` | The JWT issuer domain |
|
||||
| spire-server.logLevel | string | `"info"` | The log level, valid values are "debug", "info", "warn", and "error" |
|
||||
@@ -321,7 +345,7 @@ Kubernetes: `>=1.21.0-0`
|
||||
| spire-server.namespaceOverride | string | `""` | |
|
||||
| spire-server.nodeAttestor.k8sPsat.enabled | bool | `true` | |
|
||||
| spire-server.nodeAttestor.k8sPsat.serviceAccountAllowList | list | `[]` | |
|
||||
| spire-server.nodeSelector | object | `{}` | |
|
||||
| spire-server.nodeSelector | object | `{}` | Select specific nodes to run on (currently only amd64 is supported by Tornjak) |
|
||||
| spire-server.notifier.k8sbundle.namespace | string | `""` | Namespace to push the bundle into, if blank will default to SPIRE Server namespace |
|
||||
| spire-server.persistence.accessMode | string | `"ReadWriteOnce"` | |
|
||||
| spire-server.persistence.size | string | `"1Gi"` | |
|
||||
@@ -343,6 +367,17 @@ Kubernetes: `>=1.21.0-0`
|
||||
| spire-server.telemetry.prometheus.podMonitor.namespace | string | `""` | Override where to install the podMonitor, if not set will use the same namespace as the spire-server |
|
||||
| spire-server.tolerations | list | `[]` | |
|
||||
| spire-server.topologySpreadConstraints | list | `[]` | |
|
||||
| spire-server.tornjak.config.dataStore | object | `{"driver":"sqlite3","file":"/run/spire/data/tornjak.sqlite3"}` | persistent DB for storing Tornjak specific information |
|
||||
| spire-server.tornjak.enabled | bool | `false` | Deploys Tornjak API (backend) (Not for production) |
|
||||
| spire-server.tornjak.image.pullPolicy | string | `"IfNotPresent"` | The Tornjak image pull policy |
|
||||
| spire-server.tornjak.image.registry | string | `"ghcr.io"` | The OCI registry to pull the Tornjak image from |
|
||||
| spire-server.tornjak.image.repository | string | `"spiffe/tornjak-backend"` | The repository within the registry |
|
||||
| spire-server.tornjak.image.tag | string | `"v1.2.1"` | Overrides the image tag |
|
||||
| spire-server.tornjak.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| spire-server.tornjak.resources | object | `{}` | |
|
||||
| spire-server.tornjak.service.annotations | object | `{}` | |
|
||||
| spire-server.tornjak.service.port | int | `10000` | |
|
||||
| spire-server.tornjak.service.type | string | `"ClusterIP"` | |
|
||||
| spire-server.trustDomain | string | `"example.org"` | Set the trust domain to be used for the SPIFFE identifiers |
|
||||
| spire-server.upstreamAuthority.certManager.enabled | bool | `false` | |
|
||||
| spire-server.upstreamAuthority.certManager.issuer_group | string | `"cert-manager.io"` | |
|
||||
@@ -355,5 +390,38 @@ Kubernetes: `>=1.21.0-0`
|
||||
| spire-server.upstreamAuthority.disk.secret.create | bool | `true` | If disabled requires you to create a secret with the given keys (certificate, key and optional bundle) yourself. |
|
||||
| spire-server.upstreamAuthority.disk.secret.data | object | `{"bundle":"","certificate":"","key":""}` | If secret creation is enabled, will create a secret with following certificate info |
|
||||
| spire-server.upstreamAuthority.disk.secret.name | string | `"spiffe-upstream-ca"` | If secret creation is disabled, the secret with this name will be used. |
|
||||
| spire-server.upstreamAuthority.spire.enabled | bool | `false` | |
|
||||
| spire-server.upstreamAuthority.spire.server.address | string | `""` | |
|
||||
| spire-server.upstreamAuthority.spire.server.port | int | `8081` | |
|
||||
| tornjak-frontend.affinity | object | `{}` | |
|
||||
| tornjak-frontend.apiServerURL | string | `"http://localhost:10000/"` | URL of the Tornjak APIs (backend) Since Tornjak Frontend runs in the browser, this URL must be accessible from the machine running a browser. |
|
||||
| tornjak-frontend.fullnameOverride | string | `""` | |
|
||||
| tornjak-frontend.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||
| tornjak-frontend.image.registry | string | `"ghcr.io"` | |
|
||||
| tornjak-frontend.image.repository | string | `"spiffe/tornjak-frontend"` | |
|
||||
| tornjak-frontend.image.tag | string | `""` | Overrides the image tag whose default is the chart appVersion. |
|
||||
| tornjak-frontend.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| tornjak-frontend.imagePullSecrets | list | `[]` | |
|
||||
| tornjak-frontend.labels | object | `{}` | |
|
||||
| tornjak-frontend.nameOverride | string | `""` | |
|
||||
| tornjak-frontend.namespaceOverride | string | `""` | |
|
||||
| tornjak-frontend.nodeSelector | object | `{"kubernetes.io/arch":"amd64"}` | Select specific nodes to run on (currently only amd64 is supported by Tornjak) |
|
||||
| tornjak-frontend.podSecurityContext | object | `{}` | |
|
||||
| tornjak-frontend.securityContext | object | `{}` | |
|
||||
| tornjak-frontend.service.annotations | object | `{}` | |
|
||||
| tornjak-frontend.service.port | int | `3000` | |
|
||||
| tornjak-frontend.service.type | string | `"ClusterIP"` | |
|
||||
| tornjak-frontend.serviceAccount.annotations | object | `{}` | Annotations to add to the service account |
|
||||
| tornjak-frontend.serviceAccount.create | bool | `true` | Specifies whether a service account should be created |
|
||||
| tornjak-frontend.serviceAccount.name | string | `""` | The name of the service account to use. If not set and create is true, a name is generated using the fullname template |
|
||||
| tornjak-frontend.spireHealthCheck.enabled | bool | `true` | Enables the SPIRE Healthchecker indicator |
|
||||
| tornjak-frontend.startupProbe.enabled | bool | `true` | Enable startupProbe on Tornjak frontend container |
|
||||
| tornjak-frontend.startupProbe.failureThreshold | int | `6` | Failure threshold for startupProbe |
|
||||
| tornjak-frontend.startupProbe.initialDelaySeconds | int | `5` | Initial delay seconds for startupProbe |
|
||||
| tornjak-frontend.startupProbe.periodSeconds | int | `10` | Period seconds for startupProbe |
|
||||
| tornjak-frontend.startupProbe.successThreshold | int | `1` | Success threshold for startupProbe |
|
||||
| tornjak-frontend.startupProbe.timeoutSeconds | int | `5` | Timeout seconds for startupProbe |
|
||||
| tornjak-frontend.tolerations | list | `[]` | |
|
||||
| tornjak-frontend.topologySpreadConstraints | list | `[]` | |
|
||||
|
||||
----------------------------------------------
|
||||
|
||||
@@ -21,9 +21,9 @@
|
||||
|:-----------|:-------------------|
|
||||
| SPIRE | `1.5.3+`, `1.6.3+` |
|
||||
| Helm | `3.x` |
|
||||
| Kubernetes | `1.21+` |
|
||||
| Kubernetes | `1.22+` |
|
||||
|
||||
> **Note**: For Kubernetes, we will officially support the last 3 versions as described in [k8s versioning](https://kubernetes.io/releases/version-skew-policy/#supported-versions). Any version before the last 3 we will try to support as long it doesn't bring security issues or any big maintenance burden. *The first version we tested this chart with is `1.21`.*
|
||||
> **Note**: For Kubernetes, we will officially support the last 3 versions as described in [k8s versioning](https://kubernetes.io/releases/version-skew-policy/#supported-versions). Any version before the last 3 we will try to support as long it doesn't bring security issues or any big maintenance burden.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
@@ -87,7 +87,9 @@ Now you can interact with the Spire agent socket from your own application. The
|
||||
|
||||
{{ template "chart.sourcesSection" . }}
|
||||
|
||||
{{ template "chart.requirementsSection" . }}
|
||||
{{ template "chart.requirementsHeader" . }}
|
||||
|
||||
{{ template "chart.requirementsTable" . }}
|
||||
|
||||
{{ template "chart.valuesSection" . }}
|
||||
|
||||
|
||||
@@ -19,7 +19,8 @@ A Helm chart to install the SPIFFE CSI driver.
|
||||
| image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| image.registry | string | `"ghcr.io"` | The OCI registry to pull the image from |
|
||||
| image.repository | string | `"spiffe/spiffe-csi-driver"` | The repository within the registry |
|
||||
| image.version | string | `""` | Overrides the image tag whose default is the chart appVersion |
|
||||
| image.tag | string | `""` | Overrides the image tag whose default is the chart appVersion |
|
||||
| image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| imagePullSecrets | list | `[]` | |
|
||||
| kubeletPath | string | `"/var/lib/kubelet"` | |
|
||||
| nameOverride | string | `""` | |
|
||||
@@ -27,7 +28,8 @@ A Helm chart to install the SPIFFE CSI driver.
|
||||
| nodeDriverRegistrar.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| nodeDriverRegistrar.image.registry | string | `"registry.k8s.io"` | The OCI registry to pull the image from |
|
||||
| nodeDriverRegistrar.image.repository | string | `"sig-storage/csi-node-driver-registrar"` | The repository within the registry |
|
||||
| nodeDriverRegistrar.image.version | string | `"v2.6.2"` | |
|
||||
| nodeDriverRegistrar.image.tag | string | `"v2.8.0"` | Overrides the image tag |
|
||||
| nodeDriverRegistrar.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| nodeDriverRegistrar.resources | object | `{}` | |
|
||||
| nodeSelector | object | `{}` | |
|
||||
| pluginName | string | `"csi.spiffe.io"` | Set the csi driver name deployed to Kubernetes. |
|
||||
|
||||
@@ -8,8 +8,10 @@ image:
|
||||
repository: spiffe/spiffe-csi-driver
|
||||
# -- The image pull policy
|
||||
pullPolicy: IfNotPresent
|
||||
# -- Overrides the image tag whose default is the chart appVersion
|
||||
# -- This value is deprecated in favor of tag. (Will be removed in a future release)
|
||||
version: ""
|
||||
# -- Overrides the image tag whose default is the chart appVersion
|
||||
tag: ""
|
||||
resources: {}
|
||||
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||
# choice for the user. This also increases chances charts run on environments with little
|
||||
@@ -63,7 +65,10 @@ nodeDriverRegistrar:
|
||||
repository: sig-storage/csi-node-driver-registrar
|
||||
# -- The image pull policy
|
||||
pullPolicy: IfNotPresent
|
||||
version: v2.6.2
|
||||
# -- This value is deprecated in favor of tag. (Will be removed in a future release)
|
||||
version: ""
|
||||
# -- Overrides the image tag
|
||||
tag: v2.8.0
|
||||
resources: {}
|
||||
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||
# choice for the user. This also increases chances charts run on environments with little
|
||||
|
||||
@@ -3,4 +3,4 @@ name: spiffe-oidc-discovery-provider
|
||||
description: A Helm chart to install the SPIFFE OIDC discovery provider.
|
||||
type: application
|
||||
version: 0.1.0
|
||||
appVersion: "1.6.3"
|
||||
appVersion: "1.6.4"
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
|
||||
<!-- This README.md is generated. Please edit README.md.gotmpl -->
|
||||
|
||||
  
|
||||
  
|
||||
|
||||
A Helm chart to install the SPIFFE OIDC discovery provider.
|
||||
|
||||
@@ -34,7 +34,8 @@ A Helm chart to install the SPIFFE OIDC discovery provider.
|
||||
| image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| image.registry | string | `"ghcr.io"` | The OCI registry to pull the image from |
|
||||
| image.repository | string | `"spiffe/oidc-discovery-provider"` | The repository within the registry |
|
||||
| image.version | string | `""` | Overrides the image tag whose default is the chart appVersion |
|
||||
| image.tag | string | `""` | Overrides the image tag whose default is the chart appVersion |
|
||||
| image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| imagePullSecrets | list | `[]` | |
|
||||
| ingress.annotations | object | `{}` | |
|
||||
| ingress.className | string | `""` | |
|
||||
@@ -47,7 +48,8 @@ A Helm chart to install the SPIFFE OIDC discovery provider.
|
||||
| insecureScheme.nginx.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| insecureScheme.nginx.image.registry | string | `"docker.io"` | The OCI registry to pull the image from |
|
||||
| insecureScheme.nginx.image.repository | string | `"nginxinc/nginx-unprivileged"` | The repository within the registry |
|
||||
| insecureScheme.nginx.image.version | string | `"1.23.2-alpine"` | |
|
||||
| insecureScheme.nginx.image.tag | string | `"1.24.0-alpine"` | Overrides the image tag |
|
||||
| insecureScheme.nginx.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| insecureScheme.nginx.resources | object | `{}` | |
|
||||
| nameOverride | string | `""` | |
|
||||
| namespaceOverride | string | `""` | |
|
||||
@@ -67,7 +69,8 @@ A Helm chart to install the SPIFFE OIDC discovery provider.
|
||||
| telemetry.prometheus.nginxExporter.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| telemetry.prometheus.nginxExporter.image.registry | string | `"docker.io"` | The OCI registry to pull the image from |
|
||||
| telemetry.prometheus.nginxExporter.image.repository | string | `"nginx/nginx-prometheus-exporter"` | The repository within the registry |
|
||||
| telemetry.prometheus.nginxExporter.image.version | string | `"0.11.0"` | |
|
||||
| telemetry.prometheus.nginxExporter.image.tag | string | `"0.11.0"` | Overrides the image tag |
|
||||
| telemetry.prometheus.nginxExporter.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| telemetry.prometheus.nginxExporter.resources | object | `{}` | |
|
||||
| telemetry.prometheus.podMonitor.enabled | bool | `false` | |
|
||||
| telemetry.prometheus.podMonitor.labels | object | `{}` | |
|
||||
|
||||
@@ -1,42 +1,16 @@
|
||||
{{- if .Values.ingress.enabled -}}
|
||||
{{- $fullName := include "spiffe-oidc-discovery-provider.fullname" . }}
|
||||
{{- $port := .Values.service.port }}
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: {{ $fullName }}
|
||||
namespace: {{ include "spiffe-oidc-discovery-provider.namespace" . }}
|
||||
labels:
|
||||
{{- include "spiffe-oidc-discovery-provider.labels" . | nindent 4 }}
|
||||
{{ include "spiffe-oidc-discovery-provider.labels" . | nindent 4 }}
|
||||
{{- with .Values.ingress.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
ingressClassName: {{ .Values.ingress.className }}
|
||||
{{- if .Values.ingress.tls }}
|
||||
tls:
|
||||
{{- range .Values.ingress.tls }}
|
||||
- hosts:
|
||||
{{- range .hosts }}
|
||||
- {{ . | quote }}
|
||||
{{- end }}
|
||||
secretName: {{ .secretName }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
rules:
|
||||
{{- range .Values.ingress.hosts }}
|
||||
- host: {{ .host | quote }}
|
||||
http:
|
||||
paths:
|
||||
{{- range .paths }}
|
||||
- path: {{ .path }}
|
||||
pathType: {{ .pathType }}
|
||||
backend:
|
||||
service:
|
||||
name: {{ $fullName }}
|
||||
port:
|
||||
number: {{ $port }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{ include "spire-lib.ingress-spec" (dict "ingress" .Values.ingress "svcName" $fullName "port" .Values.service.port "global" .Values.global) | nindent 2 }}
|
||||
{{- end }}
|
||||
|
||||
@@ -16,8 +16,10 @@ image:
|
||||
repository: spiffe/oidc-discovery-provider
|
||||
# -- The image pull policy
|
||||
pullPolicy: IfNotPresent
|
||||
# -- Overrides the image tag whose default is the chart appVersion
|
||||
# -- This value is deprecated in favor of tag. (Will be removed in a future release)
|
||||
version: ""
|
||||
# -- Overrides the image tag whose default is the chart appVersion
|
||||
tag: ""
|
||||
|
||||
resources: {}
|
||||
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||
@@ -65,13 +67,16 @@ insecureScheme:
|
||||
repository: nginxinc/nginx-unprivileged
|
||||
# -- The image pull policy
|
||||
pullPolicy: IfNotPresent
|
||||
version: 1.23.2-alpine
|
||||
# -- This value is deprecated in favor of tag. (Will be removed in a future release)
|
||||
version: ""
|
||||
# -- Overrides the image tag
|
||||
tag: 1.24.0-alpine
|
||||
# chainguard image does not support the templates feature
|
||||
# https://github.com/chainguard-images/nginx/issues/43
|
||||
# registry: cgr.dev
|
||||
# repository: chainguard/nginx
|
||||
# pullPolicy: IfNotPresent
|
||||
# version: "1.23.2"
|
||||
# tag: "1.23.2"
|
||||
resources: {}
|
||||
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||
# choice for the user. This also increases chances charts run on environments with little
|
||||
@@ -146,7 +151,10 @@ telemetry:
|
||||
repository: nginx/nginx-prometheus-exporter
|
||||
# -- The image pull policy
|
||||
pullPolicy: IfNotPresent
|
||||
version: "0.11.0"
|
||||
# -- This value is deprecated in favor of tag. (Will be removed in a future release)
|
||||
version: ""
|
||||
# -- Overrides the image tag
|
||||
tag: "0.11.0"
|
||||
|
||||
resources: {}
|
||||
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||
|
||||
@@ -3,4 +3,4 @@ name: spire-agent
|
||||
description: A Helm chart to install the SPIRE agent.
|
||||
type: application
|
||||
version: 0.1.0
|
||||
appVersion: "1.6.3"
|
||||
appVersion: "1.6.4"
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
|
||||
<!-- This README.md is generated. Please edit README.md.gotmpl -->
|
||||
|
||||
  
|
||||
  
|
||||
|
||||
A Helm chart to install the SPIRE agent.
|
||||
|
||||
@@ -25,7 +25,8 @@ A Helm chart to install the SPIRE agent.
|
||||
| image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| image.registry | string | `"ghcr.io"` | The OCI registry to pull the image from |
|
||||
| image.repository | string | `"spiffe/spire-agent"` | The repository within the registry |
|
||||
| image.version | string | `""` | |
|
||||
| image.tag | string | `""` | Overrides the image tag whose default is the chart appVersion. |
|
||||
| image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| imagePullSecrets | list | `[]` | |
|
||||
| initContainers | list | `[]` | |
|
||||
| logLevel | string | `"info"` | The log level, valid values are "debug", "info", "warn", and "error" |
|
||||
@@ -55,7 +56,8 @@ A Helm chart to install the SPIRE agent.
|
||||
| waitForIt.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| waitForIt.image.registry | string | `"cgr.dev"` | The OCI registry to pull the image from |
|
||||
| waitForIt.image.repository | string | `"chainguard/wait-for-it"` | The repository within the registry |
|
||||
| waitForIt.image.version | string | `"latest-20230113"` | |
|
||||
| waitForIt.image.tag | string | `"latest-20230517"` | Overrides the image tag |
|
||||
| waitForIt.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| waitForIt.resources | object | `{}` | |
|
||||
| workloadAttestors.k8s.skipKubeletVerification | bool | `true` | If true, kubelet certificate verification is skipped |
|
||||
| workloadAttestors.unix.enabled | bool | `false` | enables the Unix workload attestor |
|
||||
|
||||
@@ -9,8 +9,10 @@ image:
|
||||
repository: spiffe/spire-agent
|
||||
# -- The image pull policy
|
||||
pullPolicy: IfNotPresent
|
||||
# Overrides the image tag whose default is the chart appVersion.
|
||||
# -- This value is deprecated in favor of tag. (Will be removed in a future release)
|
||||
version: ""
|
||||
# -- Overrides the image tag whose default is the chart appVersion.
|
||||
tag: ""
|
||||
|
||||
imagePullSecrets: []
|
||||
nameOverride: ""
|
||||
@@ -86,7 +88,10 @@ waitForIt:
|
||||
repository: chainguard/wait-for-it
|
||||
# -- The image pull policy
|
||||
pullPolicy: IfNotPresent
|
||||
version: latest-20230113
|
||||
# -- This value is deprecated in favor of tag. (Will be removed in a future release)
|
||||
version: ""
|
||||
# -- Overrides the image tag
|
||||
tag: latest-20230517
|
||||
resources: {}
|
||||
|
||||
# workloadAttestors determine a workload's properties and then generate a set of selectors associated with it.
|
||||
|
||||
@@ -3,4 +3,4 @@ name: spire-server
|
||||
description: A Helm chart to install the SPIRE server.
|
||||
type: application
|
||||
version: 0.1.0
|
||||
appVersion: "1.6.3"
|
||||
appVersion: "1.6.4"
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
|
||||
<!-- This README.md is generated. Please edit README.md.gotmpl -->
|
||||
|
||||
  
|
||||
  
|
||||
|
||||
A Helm chart to install the SPIRE server.
|
||||
|
||||
@@ -44,7 +44,8 @@ A Helm chart to install the SPIRE server.
|
||||
| controllerManager.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| controllerManager.image.registry | string | `"ghcr.io"` | The OCI registry to pull the image from |
|
||||
| controllerManager.image.repository | string | `"spiffe/spire-controller-manager"` | The repository within the registry |
|
||||
| controllerManager.image.version | string | `"0.2.2"` | |
|
||||
| controllerManager.image.tag | string | `"0.2.2"` | Overrides the image tag |
|
||||
| controllerManager.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| controllerManager.resources | object | `{}` | |
|
||||
| controllerManager.securityContext | object | `{}` | |
|
||||
| controllerManager.service.annotations | object | `{}` | |
|
||||
@@ -52,9 +53,10 @@ A Helm chart to install the SPIRE server.
|
||||
| controllerManager.service.type | string | `"ClusterIP"` | |
|
||||
| controllerManager.validatingWebhookConfiguration.failurePolicy | string | `"Fail"` | |
|
||||
| controllerManager.validatingWebhookConfiguration.upgradeHook.image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| controllerManager.validatingWebhookConfiguration.upgradeHook.image.registry | string | `"cgr.dev"` | The OCI registry to pull the image from |
|
||||
| controllerManager.validatingWebhookConfiguration.upgradeHook.image.repository | string | `"chainguard/kubectl"` | The repository within the registry |
|
||||
| controllerManager.validatingWebhookConfiguration.upgradeHook.image.version | string | `"latest"` | |
|
||||
| controllerManager.validatingWebhookConfiguration.upgradeHook.image.registry | string | `"docker.io"` | The OCI registry to pull the image from |
|
||||
| controllerManager.validatingWebhookConfiguration.upgradeHook.image.repository | string | `"rancher/kubectl"` | The repository within the registry |
|
||||
| controllerManager.validatingWebhookConfiguration.upgradeHook.image.tag | string | `""` | Overrides the image tag |
|
||||
| controllerManager.validatingWebhookConfiguration.upgradeHook.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| dataStore.sql.databaseName | string | `"spire"` | Only used by "postgres" or "mysql" |
|
||||
| dataStore.sql.databaseType | string | `"sqlite3"` | Other supported databases are "postgres" and "mysql" |
|
||||
| dataStore.sql.host | string | `""` | Only used by "postgres" or "mysql" |
|
||||
@@ -71,12 +73,27 @@ A Helm chart to install the SPIRE server.
|
||||
| federation.bundleEndpoint.address | string | `"0.0.0.0"` | |
|
||||
| federation.bundleEndpoint.port | int | `8443` | |
|
||||
| federation.enabled | bool | `false` | |
|
||||
| federation.ingress.annotations | object | `{}` | |
|
||||
| federation.ingress.className | string | `""` | |
|
||||
| federation.ingress.enabled | bool | `false` | |
|
||||
| federation.ingress.hosts[0].host | string | `"spire-server-federation.example.org"` | |
|
||||
| federation.ingress.hosts[0].paths[0].path | string | `"/"` | |
|
||||
| federation.ingress.hosts[0].paths[0].pathType | string | `"Prefix"` | |
|
||||
| federation.ingress.tls | list | `[]` | |
|
||||
| fullnameOverride | string | `""` | |
|
||||
| image.pullPolicy | string | `"IfNotPresent"` | The image pull policy |
|
||||
| image.registry | string | `"ghcr.io"` | The OCI registry to pull the image from |
|
||||
| image.repository | string | `"spiffe/spire-server"` | The repository within the registry |
|
||||
| image.version | string | `""` | |
|
||||
| image.tag | string | `""` | Overrides the image tag whose default is the chart appVersion. |
|
||||
| image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| imagePullSecrets | list | `[]` | |
|
||||
| ingress.annotations | object | `{}` | |
|
||||
| ingress.className | string | `""` | |
|
||||
| ingress.enabled | bool | `false` | |
|
||||
| ingress.hosts[0].host | string | `"spire-server.example.org"` | |
|
||||
| ingress.hosts[0].paths[0].path | string | `"/"` | |
|
||||
| ingress.hosts[0].paths[0].pathType | string | `"Prefix"` | |
|
||||
| ingress.tls | list | `[]` | |
|
||||
| initContainers | list | `[]` | |
|
||||
| jwtIssuer | string | `"oidc-discovery.example.org"` | The JWT issuer domain |
|
||||
| logLevel | string | `"info"` | The log level, valid values are "debug", "info", "warn", and "error" |
|
||||
@@ -84,7 +101,7 @@ A Helm chart to install the SPIRE server.
|
||||
| namespaceOverride | string | `""` | |
|
||||
| nodeAttestor.k8sPsat.enabled | bool | `true` | |
|
||||
| nodeAttestor.k8sPsat.serviceAccountAllowList | list | `[]` | |
|
||||
| nodeSelector | object | `{}` | |
|
||||
| nodeSelector | object | `{}` | Select specific nodes to run on (currently only amd64 is supported by Tornjak) |
|
||||
| notifier.k8sbundle.namespace | string | `""` | Namespace to push the bundle into, if blank will default to SPIRE Server namespace |
|
||||
| persistence.accessMode | string | `"ReadWriteOnce"` | |
|
||||
| persistence.size | string | `"1Gi"` | |
|
||||
@@ -106,6 +123,17 @@ A Helm chart to install the SPIRE server.
|
||||
| telemetry.prometheus.podMonitor.namespace | string | `""` | Override where to install the podMonitor, if not set will use the same namespace as the spire-server |
|
||||
| tolerations | list | `[]` | |
|
||||
| topologySpreadConstraints | list | `[]` | |
|
||||
| tornjak.config.dataStore | object | `{"driver":"sqlite3","file":"/run/spire/data/tornjak.sqlite3"}` | persistent DB for storing Tornjak specific information |
|
||||
| tornjak.enabled | bool | `false` | Deploys Tornjak API (backend) (Not for production) |
|
||||
| tornjak.image.pullPolicy | string | `"IfNotPresent"` | The Tornjak image pull policy |
|
||||
| tornjak.image.registry | string | `"ghcr.io"` | The OCI registry to pull the Tornjak image from |
|
||||
| tornjak.image.repository | string | `"spiffe/tornjak-backend"` | The repository within the registry |
|
||||
| tornjak.image.tag | string | `"v1.2.1"` | Overrides the image tag |
|
||||
| tornjak.image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| tornjak.resources | object | `{}` | |
|
||||
| tornjak.service.annotations | object | `{}` | |
|
||||
| tornjak.service.port | int | `10000` | |
|
||||
| tornjak.service.type | string | `"ClusterIP"` | |
|
||||
| trustDomain | string | `"example.org"` | Set the trust domain to be used for the SPIFFE identifiers |
|
||||
| upstreamAuthority.certManager.enabled | bool | `false` | |
|
||||
| upstreamAuthority.certManager.issuer_group | string | `"cert-manager.io"` | |
|
||||
@@ -118,5 +146,8 @@ A Helm chart to install the SPIRE server.
|
||||
| upstreamAuthority.disk.secret.create | bool | `true` | If disabled requires you to create a secret with the given keys (certificate, key and optional bundle) yourself. |
|
||||
| upstreamAuthority.disk.secret.data | object | `{"bundle":"","certificate":"","key":""}` | If secret creation is enabled, will create a secret with following certificate info |
|
||||
| upstreamAuthority.disk.secret.name | string | `"spiffe-upstream-ca"` | If secret creation is disabled, the secret with this name will be used. |
|
||||
| upstreamAuthority.spire.enabled | bool | `false` | |
|
||||
| upstreamAuthority.spire.server.address | string | `""` | |
|
||||
| upstreamAuthority.spire.server.port | int | `8081` | |
|
||||
|
||||
----------------------------------------------
|
||||
|
||||
@@ -4,3 +4,20 @@ Installed {{ .Chart.Name }}…
|
||||
|
||||
kubectl exec -n {{ .Release.Namespace }} {{ include "spire-server.fullname" . }}-0 -c spire-server -- \
|
||||
spire-server entry show
|
||||
|
||||
{{- if eq (.Values.tornjak.enabled | toString) "true" }}
|
||||
|
||||
Installed {{ include "spire-tornjak.fullname" . }}…
|
||||
|
||||
### WARNING ###
|
||||
|
||||
Tornjak runs without authentication and is therefore NOT suitable to run in production environments.
|
||||
Only use in test environments!
|
||||
|
||||
Access Tornjak:
|
||||
|
||||
kubectl -n {{ include "spire-server.namespace" . }} port-forward service/{{ include "spire-tornjak.backend" . }} {{ .Values.tornjak.service.port }}:10000
|
||||
|
||||
Open browser to: http://localhost:{{ .Values.tornjak.service.port }}
|
||||
|
||||
{{- end }}
|
||||
|
||||
@@ -105,6 +105,15 @@ Create the name of the service account to use
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "spire-server.kubectl-image" }}
|
||||
{{- $root := deepCopy . }}
|
||||
{{- $tag := (default $root.image.tag $root.image.version) | toString }}
|
||||
{{- if eq (len $tag) 0 }}
|
||||
{{- $_ := set $root.image "tag" (regexReplaceAll "^(v?\\d+\\.\\d+\\.\\d+).*" $root.KubeVersion "${1}") }}
|
||||
{{- end }}
|
||||
{{- include "spire-lib.image" $root }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "spire-server.config-mysql-query" }}
|
||||
{{- $lst := list }}
|
||||
{{- range . }}
|
||||
@@ -153,3 +162,19 @@ Create the name of the service account to use
|
||||
{{- end }}
|
||||
{{- $config | toYaml }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Tornjak specific section
|
||||
*/}}
|
||||
|
||||
{{- define "spire-tornjak.fullname" -}}
|
||||
{{ include "spire-server.fullname" . | trimSuffix "-server" }}-tornjak
|
||||
{{- end }}
|
||||
|
||||
{{- define "spire-tornjak.config" -}}
|
||||
{{ include "spire-tornjak.fullname" . }}-config
|
||||
{{- end }}
|
||||
|
||||
{{- define "spire-tornjak.backend" -}}
|
||||
{{ include "spire-tornjak.fullname" . }}-backend
|
||||
{{- end }}
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
{{- define "spire-server.yaml-config" -}}
|
||||
{{- $upstreamAuthorityUsed := 0 }}
|
||||
{{- $root := . }}
|
||||
server:
|
||||
bind_address: "0.0.0.0"
|
||||
@@ -59,6 +60,7 @@ plugins:
|
||||
|
||||
{{- with .Values.upstreamAuthority.disk }}
|
||||
{{- if eq (.enabled | toString) "true" }}
|
||||
{{- $upstreamAuthorityUsed = add1 $upstreamAuthorityUsed }}
|
||||
UpstreamAuthority:
|
||||
- disk:
|
||||
plugin_data:
|
||||
@@ -72,6 +74,7 @@ plugins:
|
||||
|
||||
{{- with .Values.upstreamAuthority.certManager }}
|
||||
{{- if eq (.enabled | toString) "true" }}
|
||||
{{- $upstreamAuthorityUsed = add1 $upstreamAuthorityUsed }}
|
||||
UpstreamAuthority:
|
||||
- cert-manager:
|
||||
plugin_data:
|
||||
@@ -85,6 +88,21 @@ plugins:
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- with .Values.upstreamAuthority.spire }}
|
||||
{{- if eq (.enabled | toString) "true" }}
|
||||
{{- $upstreamAuthorityUsed = add1 $upstreamAuthorityUsed }}
|
||||
UpstreamAuthority:
|
||||
- spire:
|
||||
plugin_data:
|
||||
server_address: {{ .server.address | quote }}
|
||||
server_port: {{ .server.port }}
|
||||
workload_api_socket: "/run/spire/upstream_agent/spire-agent.sock"
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if gt $upstreamAuthorityUsed 1 }}
|
||||
{{- fail "You can only enable a single Upstream Authority." }}
|
||||
{{- end }}
|
||||
|
||||
health_checks:
|
||||
listener_enabled: true
|
||||
bind_address: "0.0.0.0"
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
{{- if .Values.federation.enabled }}
|
||||
{{- if .Values.federation.ingress.enabled -}}
|
||||
{{- $svcName := include "spire-server.fullname" . }}
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: {{ printf "%s-federation" $svcName }}
|
||||
namespace: {{ include "spire-server.namespace" . }}
|
||||
labels:
|
||||
{{ include "spire-server.labels" . | nindent 4 }}
|
||||
{{- with .Values.ingress.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
{{ include "spire-lib.ingress-spec" (dict "ingress" .Values.federation.ingress "svcName" $svcName "port" .Values.federation.bundleEndpoint.port "global" .Values.global) | nindent 2 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,16 @@
|
||||
{{- if .Values.ingress.enabled -}}
|
||||
{{- $fullName := include "spire-server.fullname" . -}}
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: {{ $fullName }}
|
||||
namespace: {{ include "spire-server.namespace" . }}
|
||||
labels:
|
||||
{{ include "spire-server.labels" . | nindent 4}}
|
||||
{{- with .Values.ingress.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
{{ include "spire-lib.ingress-spec" (dict "ingress" .Values.ingress "svcName" $fullName "port" .Values.service.port "global" .Values.global) | nindent 2 }}
|
||||
{{- end }}
|
||||
@@ -63,23 +63,25 @@ spec:
|
||||
- name: post-install-job
|
||||
securityContext:
|
||||
{{- toYaml .Values.securityContext | nindent 10 }}
|
||||
image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.controllerManager.validatingWebhookConfiguration.upgradeHook.image "global" .Values.global) }}
|
||||
command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- |-
|
||||
kubectl patch validatingwebhookconfiguration {{ include "spire-controller-manager.fullname" . }}-webhook --type='strategic' -p '
|
||||
{
|
||||
"webhooks":[
|
||||
{
|
||||
"name":"vclusterspiffeid.kb.io",
|
||||
"failurePolicy":"{{ .Values.controllerManager.validatingWebhookConfiguration.failurePolicy }}"
|
||||
},
|
||||
{
|
||||
"name":"vclusterfederatedtrustdomain.kb.io",
|
||||
"failurePolicy":"{{ .Values.controllerManager.validatingWebhookConfiguration.failurePolicy }}"
|
||||
}
|
||||
]
|
||||
}'
|
||||
image: {{ template "spire-server.kubectl-image" (dict "appVersion" $.Chart.AppVersion "image" .Values.controllerManager.validatingWebhookConfiguration.upgradeHook.image "global" .Values.global "KubeVersion" .Capabilities.KubeVersion.Version) }}
|
||||
args:
|
||||
- patch
|
||||
- validatingwebhookconfiguration
|
||||
- {{ include "spire-controller-manager.fullname" . }}-webhook
|
||||
- --type=strategic
|
||||
- -p
|
||||
- |
|
||||
{
|
||||
"webhooks":[
|
||||
{
|
||||
"name":"vclusterspiffeid.kb.io",
|
||||
"failurePolicy":"{{ .Values.controllerManager.validatingWebhookConfiguration.failurePolicy }}"
|
||||
},
|
||||
{
|
||||
"name":"vclusterfederatedtrustdomain.kb.io",
|
||||
"failurePolicy":"{{ .Values.controllerManager.validatingWebhookConfiguration.failurePolicy }}"
|
||||
}
|
||||
]
|
||||
}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
@@ -63,23 +63,25 @@ spec:
|
||||
- name: post-upgrade-job
|
||||
securityContext:
|
||||
{{- toYaml .Values.securityContext | nindent 10 }}
|
||||
image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.controllerManager.validatingWebhookConfiguration.upgradeHook.image "global" .Values.global) }}
|
||||
command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- |-
|
||||
kubectl patch validatingwebhookconfiguration {{ include "spire-controller-manager.fullname" . }}-webhook --type='strategic' -p '
|
||||
{
|
||||
"webhooks":[
|
||||
{
|
||||
"name":"vclusterspiffeid.kb.io",
|
||||
"failurePolicy":"{{ .Values.controllerManager.validatingWebhookConfiguration.failurePolicy }}"
|
||||
},
|
||||
{
|
||||
"name":"vclusterfederatedtrustdomain.kb.io",
|
||||
"failurePolicy":"{{ .Values.controllerManager.validatingWebhookConfiguration.failurePolicy }}"
|
||||
}
|
||||
]
|
||||
}'
|
||||
image: {{ template "spire-server.kubectl-image" (dict "appVersion" $.Chart.AppVersion "image" .Values.controllerManager.validatingWebhookConfiguration.upgradeHook.image "global" .Values.global "KubeVersion" .Capabilities.KubeVersion.Version) }}
|
||||
args:
|
||||
- patch
|
||||
- validatingwebhookconfiguration
|
||||
- {{ include "spire-controller-manager.fullname" . }}-webhook
|
||||
- --type=strategic
|
||||
- -p
|
||||
- |
|
||||
{
|
||||
"webhooks":[
|
||||
{
|
||||
"name":"vclusterspiffeid.kb.io",
|
||||
"failurePolicy":"{{ .Values.controllerManager.validatingWebhookConfiguration.failurePolicy }}"
|
||||
},
|
||||
{
|
||||
"name":"vclusterfederatedtrustdomain.kb.io",
|
||||
"failurePolicy":"{{ .Values.controllerManager.validatingWebhookConfiguration.failurePolicy }}"
|
||||
}
|
||||
]
|
||||
}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
@@ -63,23 +63,25 @@ spec:
|
||||
- name: post-install-job
|
||||
securityContext:
|
||||
{{- toYaml .Values.securityContext | nindent 10 }}
|
||||
image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.controllerManager.validatingWebhookConfiguration.upgradeHook.image "global" .Values.global) }}
|
||||
command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- |-
|
||||
kubectl patch validatingwebhookconfiguration {{ include "spire-controller-manager.fullname" . }}-webhook --type='strategic' -p '
|
||||
{
|
||||
"webhooks":[
|
||||
{
|
||||
"name":"vclusterspiffeid.kb.io",
|
||||
"failurePolicy":"Ignore"
|
||||
},
|
||||
{
|
||||
"name":"vclusterfederatedtrustdomain.kb.io",
|
||||
"failurePolicy":"Ignore"
|
||||
}
|
||||
]
|
||||
}'
|
||||
image: {{ template "spire-server.kubectl-image" (dict "appVersion" $.Chart.AppVersion "image" .Values.controllerManager.validatingWebhookConfiguration.upgradeHook.image "global" .Values.global "KubeVersion" .Capabilities.KubeVersion.Version) }}
|
||||
args:
|
||||
- patch
|
||||
- validatingwebhookconfiguration
|
||||
- {{ include "spire-controller-manager.fullname" . }}-webhook
|
||||
- --type=strategic
|
||||
- -p
|
||||
- |
|
||||
{
|
||||
"webhooks":[
|
||||
{
|
||||
"name":"vclusterspiffeid.kb.io",
|
||||
"failurePolicy":"Ignore"
|
||||
},
|
||||
{
|
||||
"name":"vclusterfederatedtrustdomain.kb.io",
|
||||
"failurePolicy":"Ignore"
|
||||
}
|
||||
]
|
||||
}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
{{- $configSum := (include (print $.Template.BasePath "/configmap.yaml") . | sha256sum) }}
|
||||
{{- $configSum2 := (include (print $.Template.BasePath "/secret.yaml") . | sha256sum) }}
|
||||
{{- $configSum3 := (include (print $.Template.BasePath "/controller-manager-configmap.yaml") . | sha256sum) }}
|
||||
{{- $configSumTornjak := (include (print $.Template.BasePath "/tornjak-config.yaml") . | sha256sum) }}
|
||||
{{- $fullname := include "spire-server.fullname" . }}
|
||||
apiVersion: apps/v1
|
||||
kind: StatefulSet
|
||||
@@ -26,6 +27,7 @@ spec:
|
||||
checksum/config: {{ $configSum }}
|
||||
checksum/config2: {{ $configSum2 }}
|
||||
checksum/config3: {{ $configSum3 }}
|
||||
checksum/configTornjak: {{ $configSumTornjak }}
|
||||
{{- with .Values.podAnnotations }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
@@ -155,6 +157,47 @@ spec:
|
||||
mountPath: /tmp
|
||||
readOnly: false
|
||||
{{- end }}
|
||||
|
||||
{{- if eq (.Values.tornjak.enabled | toString) "true" }}
|
||||
- name: tornjak
|
||||
securityContext:
|
||||
{{- toYaml .Values.controllerManager.securityContext | nindent 12 }}
|
||||
image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.tornjak.image "global" .Values.global) }}
|
||||
imagePullPolicy: {{ .Values.tornjak.image.pullPolicy }}
|
||||
startupProbe:
|
||||
httpGet:
|
||||
scheme: HTTP
|
||||
port: 10000
|
||||
failureThreshold: 3
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 10
|
||||
successThreshold: 1
|
||||
timeoutSeconds: 5
|
||||
args:
|
||||
- --spire-config
|
||||
- /run/spire/config/server.conf
|
||||
- --tornjak-config
|
||||
- /run/spire/tornjak-config/server.conf
|
||||
ports:
|
||||
- name: tornjak
|
||||
containerPort: 10000
|
||||
protocol: TCP
|
||||
resources:
|
||||
{{- toYaml .Values.tornjak.resources | nindent 12 }}
|
||||
volumeMounts:
|
||||
- name: {{ include "spire-tornjak.config" . }}
|
||||
mountPath: /run/spire/tornjak-config
|
||||
- name: spire-server-socket
|
||||
mountPath: /tmp/spire-server/private
|
||||
readOnly: true
|
||||
- name: spire-config
|
||||
mountPath: /run/spire/config
|
||||
readOnly: true
|
||||
- name: spire-data
|
||||
mountPath: /run/spire/data
|
||||
readOnly: false
|
||||
{{- end }}
|
||||
|
||||
{{- if gt (len .Values.extraContainers) 0 }}
|
||||
{{- toYaml .Values.extraContainers | nindent 8 }}
|
||||
{{- end }}
|
||||
@@ -192,6 +235,14 @@ spec:
|
||||
configMap:
|
||||
name: {{ include "spire-controller-manager.fullname" . }}
|
||||
{{- end }}
|
||||
{{- if eq (.Values.tornjak.enabled | toString) "true" }}
|
||||
{{- if .Values.tornjak.config }}
|
||||
- name: {{ include "spire-tornjak.config" . }}
|
||||
configMap:
|
||||
defaultMode: 420
|
||||
name: {{ include "spire-tornjak.config" . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if gt (len .Values.extraVolumes) 0 }}
|
||||
{{- toYaml .Values.extraVolumes | nindent 8 }}
|
||||
{{- end }}
|
||||
|
||||
@@ -0,0 +1,22 @@
|
||||
{{- if eq (.Values.tornjak.enabled | toString) "true" }}
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: "{{ include "spire-tornjak.fullname" . }}-test-connection"
|
||||
namespace: {{ include "spire-server.namespace" . }}
|
||||
labels:
|
||||
{{- include "spire-server.labels" . | nindent 4 }}
|
||||
annotations:
|
||||
"helm.sh/hook": test
|
||||
spec:
|
||||
securityContext:
|
||||
{{- toYaml .Values.podSecurityContext | nindent 4 }}
|
||||
containers:
|
||||
- name: curl-tornjak-backend
|
||||
image: cgr.dev/chainguard/bash:latest
|
||||
command: ['curl']
|
||||
args: ['-k', '-s', '-f', 'http://{{ include "spire-tornjak.backend" . }}.{{ include "spire-server.namespace" . }}.svc.{{ include "spire-lib.cluster-domain" . }}:{{ .Values.tornjak.service.port }}']
|
||||
securityContext:
|
||||
{{- toYaml .Values.securityContext | nindent 8 }}
|
||||
restartPolicy: Never
|
||||
{{- end }}
|
||||
@@ -0,0 +1,28 @@
|
||||
{{- if eq (.Values.tornjak.enabled | toString) "true" }}
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: {{ include "spire-tornjak.config" . }}
|
||||
namespace: {{ include "spire-server.namespace" . }}
|
||||
data:
|
||||
server.conf: |
|
||||
server {
|
||||
spire_socket_path = "unix:///tmp/spire-server/private/api.sock" # socket to communicate with SPIRE server
|
||||
|
||||
http {
|
||||
enabled = true # if true, opens HTTP server
|
||||
port = "10000" # if HTTP enabled, opens HTTP listen port at container port 10000
|
||||
}
|
||||
}
|
||||
|
||||
plugins {
|
||||
{{- if .Values.tornjak.config.dataStore }}
|
||||
DataStore "sql" {
|
||||
plugin_data {
|
||||
drivername = "{{ .Values.tornjak.config.dataStore.driver }}"
|
||||
filename = "{{ .Values.tornjak.config.dataStore.file }}"
|
||||
}
|
||||
}
|
||||
{{- end }}
|
||||
}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,22 @@
|
||||
{{- if eq (.Values.tornjak.enabled | toString) "true" }}
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
namespace: {{ include "spire-server.namespace" . }}
|
||||
name: {{ include "spire-tornjak.backend" . }}
|
||||
{{- with .Values.tornjak.service.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "spire-server.labels" . | nindent 4 }}
|
||||
spec:
|
||||
type: {{ .Values.tornjak.service.type }}
|
||||
selector:
|
||||
{{- include "spire-server.selectorLabels" . | nindent 4 }}
|
||||
ports:
|
||||
- name: {{ include "spire-tornjak.backend" . }}
|
||||
port: {{ .Values.tornjak.service.port }}
|
||||
targetPort: tornjak
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
@@ -12,8 +12,10 @@ image:
|
||||
repository: spiffe/spire-server
|
||||
# -- The image pull policy
|
||||
pullPolicy: IfNotPresent
|
||||
# Overrides the image tag whose default is the chart appVersion.
|
||||
# -- This value is deprecated in favor of tag. (Will be removed in a future release)
|
||||
version: ""
|
||||
# -- Overrides the image tag whose default is the chart appVersion.
|
||||
tag: ""
|
||||
|
||||
imagePullSecrets: []
|
||||
nameOverride: ""
|
||||
@@ -70,6 +72,7 @@ autoscaling:
|
||||
targetCPUUtilizationPercentage: 80
|
||||
# targetMemoryUtilizationPercentage: 80
|
||||
|
||||
# -- Select specific nodes to run on (currently only amd64 is supported by Tornjak)
|
||||
nodeSelector: {}
|
||||
|
||||
tolerations: []
|
||||
@@ -124,6 +127,26 @@ federation:
|
||||
port: 8443
|
||||
address: "0.0.0.0"
|
||||
|
||||
ingress:
|
||||
enabled: false
|
||||
className: ""
|
||||
annotations: {}
|
||||
# kubernetes.io/ingress.class: nginx
|
||||
# kubernetes.io/tls-acme: "true"
|
||||
# nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
|
||||
# If Profile Type == https_spiffe:
|
||||
# nginx.ingress.kubernetes.io/ssl-passthrough: "true"
|
||||
hosts:
|
||||
- host: spire-server-federation.example.org
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
tls: []
|
||||
# - hosts:
|
||||
# - spire-server-federation.example.org
|
||||
# If Profile Type == https_web:
|
||||
# secretName: spire-server-federation-tls
|
||||
|
||||
ca_subject:
|
||||
country: NL
|
||||
organization: Example
|
||||
@@ -152,6 +175,11 @@ upstreamAuthority:
|
||||
# -- Specify to use a namespace other then the one the chart is installed into
|
||||
namespace: ""
|
||||
kube_config_file: ""
|
||||
spire:
|
||||
enabled: false
|
||||
server:
|
||||
address: ""
|
||||
port: 8081
|
||||
|
||||
notifier:
|
||||
k8sbundle:
|
||||
@@ -168,8 +196,10 @@ controllerManager:
|
||||
repository: spiffe/spire-controller-manager
|
||||
# -- The image pull policy
|
||||
pullPolicy: IfNotPresent
|
||||
# Overrides the image tag whose default is the chart appVersion.
|
||||
version: "0.2.2"
|
||||
# -- This value is deprecated in favor of tag. (Will be removed in a future release)
|
||||
version: ""
|
||||
# -- Overrides the image tag
|
||||
tag: "0.2.2"
|
||||
|
||||
resources: {}
|
||||
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||
@@ -223,12 +253,15 @@ controllerManager:
|
||||
upgradeHook:
|
||||
image:
|
||||
# -- The OCI registry to pull the image from
|
||||
registry: cgr.dev
|
||||
registry: docker.io
|
||||
# -- The repository within the registry
|
||||
repository: chainguard/kubectl
|
||||
repository: rancher/kubectl
|
||||
# -- The image pull policy
|
||||
pullPolicy: IfNotPresent
|
||||
version: latest
|
||||
# -- This value is deprecated in favor of tag. (Will be removed in a future release)
|
||||
version: ""
|
||||
# -- Overrides the image tag
|
||||
tag: ""
|
||||
|
||||
telemetry:
|
||||
prometheus:
|
||||
@@ -239,6 +272,24 @@ telemetry:
|
||||
namespace: ""
|
||||
labels: {}
|
||||
|
||||
ingress:
|
||||
enabled: false
|
||||
className: ""
|
||||
annotations: {}
|
||||
# kubernetes.io/ingress.class: nginx
|
||||
# kubernetes.io/tls-acme: "true"
|
||||
# nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
|
||||
# nginx.ingress.kubernetes.io/ssl-passthrough: "true"
|
||||
hosts:
|
||||
- host: spire-server.example.org
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
tls: []
|
||||
# - secretName: spire-server-tls
|
||||
# hosts:
|
||||
# - spire-server.example.org
|
||||
|
||||
extraVolumes: []
|
||||
extraVolumeMounts: []
|
||||
extraContainers: []
|
||||
@@ -255,3 +306,39 @@ nodeAttestor:
|
||||
k8sPsat:
|
||||
enabled: true
|
||||
serviceAccountAllowList: []
|
||||
|
||||
# tornjak - Tornjak specific configuration
|
||||
tornjak:
|
||||
# -- Deploys Tornjak API (backend) (Not for production)
|
||||
enabled: false
|
||||
image:
|
||||
# -- The OCI registry to pull the Tornjak image from
|
||||
registry: ghcr.io
|
||||
# -- The repository within the registry
|
||||
repository: spiffe/tornjak-backend
|
||||
# -- The Tornjak image pull policy
|
||||
pullPolicy: IfNotPresent
|
||||
# -- This value is deprecated in favor of tag. (Will be removed in a future release)
|
||||
version: ""
|
||||
# -- Overrides the image tag
|
||||
tag: "v1.2.1"
|
||||
service:
|
||||
type: ClusterIP
|
||||
port: 10000
|
||||
annotations: {}
|
||||
config:
|
||||
# -- persistent DB for storing Tornjak specific information
|
||||
dataStore:
|
||||
driver: "sqlite3"
|
||||
file: "/run/spire/data/tornjak.sqlite3"
|
||||
resources: {}
|
||||
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||
# choice for the user. This also increases chances charts run on environments with little
|
||||
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||
# limits:
|
||||
# cpu: 100m
|
||||
# memory: 128Mi
|
||||
# requests:
|
||||
# cpu: 100m
|
||||
# memory: 128Mi
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: v2
|
||||
name: tornjak-frontend
|
||||
description: A Helm chart to deploy Tornjak frontend
|
||||
type: application
|
||||
version: 0.1.0
|
||||
appVersion: "v1.2.1"
|
||||
home: https://github.com/spiffe/helm-charts/tree/main/charts/spire
|
||||
sources:
|
||||
- https://github.com/spiffe/tornjak
|
||||
icon: https://raw.githubusercontent.com/spiffe/tornjak/main/logos/logo%2Btornjak.2132x1291.png
|
||||
maintainers:
|
||||
- name: mrsabath
|
||||
email: [email protected]
|
||||
url: https://mrsabath.github.io
|
||||
@@ -0,0 +1,82 @@
|
||||
# tornjak-frontend
|
||||
|
||||
<!-- This README.md is generated. Please edit README.md.gotmpl -->
|
||||
|
||||
  
|
||||
[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
|
||||
|
||||
A Helm chart to deploy Tornjak frontend
|
||||
|
||||
**Homepage:** <https://github.com/spiffe/helm-charts/tree/main/charts/spire>
|
||||
|
||||
## Version support
|
||||
|
||||
> **Note**: This Chart is still in development and still subject to change the API (`values.yaml`).
|
||||
> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although
|
||||
> we do aim for as much stability as possible.
|
||||
|
||||
| Dependency | Supported Versions |
|
||||
|:-----------|:-------------------|
|
||||
| SPIRE | `1.5.3+`, `1.6.x` |
|
||||
| Tornjak | `1.0.x` |
|
||||
| Helm | `3.x` |
|
||||
|
||||
## Prerequisites
|
||||
|
||||
This chart requires access to Tornjak Backend (`tornjakFrontend.apiServerURL`).
|
||||
This URL needs to be reachable from your web browser and can therefore not be a cluster internal URL.
|
||||
|
||||
Obtain the URL for Tornjak APIs. If deployed in the same cluster, locally,
|
||||
Tornjak APIs are typically available at `http://localhost:10000`.
|
||||
Review Tornjak documentation for more details.
|
||||
|
||||
## Usage
|
||||
|
||||
Since this is just a demo version, to access Tornjak APIs you can use
|
||||
port forwarding. See the chart NOTES output for more details.
|
||||
|
||||
## Maintainers
|
||||
|
||||
| Name | Email | Url |
|
||||
| ---- | ------ | --- |
|
||||
| mrsabath | <mrsabath@gmail.com> | <https://mrsabath.github.io> |
|
||||
|
||||
## Source Code
|
||||
|
||||
* <https://github.com/spiffe/tornjak>
|
||||
|
||||
## Values
|
||||
|
||||
| Key | Type | Default | Description |
|
||||
|-----|------|---------|-------------|
|
||||
| affinity | object | `{}` | |
|
||||
| apiServerURL | string | `"http://localhost:10000/"` | URL of the Tornjak APIs (backend) Since Tornjak Frontend runs in the browser, this URL must be accessible from the machine running a browser. |
|
||||
| fullnameOverride | string | `""` | |
|
||||
| image.pullPolicy | string | `"IfNotPresent"` | |
|
||||
| image.registry | string | `"ghcr.io"` | |
|
||||
| image.repository | string | `"spiffe/tornjak-frontend"` | |
|
||||
| image.tag | string | `""` | Overrides the image tag whose default is the chart appVersion. |
|
||||
| image.version | string | `""` | This value is deprecated in favor of tag. (Will be removed in a future release) |
|
||||
| imagePullSecrets | list | `[]` | |
|
||||
| labels | object | `{}` | |
|
||||
| nameOverride | string | `""` | |
|
||||
| namespaceOverride | string | `""` | |
|
||||
| nodeSelector | object | `{"kubernetes.io/arch":"amd64"}` | Select specific nodes to run on (currently only amd64 is supported by Tornjak) |
|
||||
| podSecurityContext | object | `{}` | |
|
||||
| securityContext | object | `{}` | |
|
||||
| service.annotations | object | `{}` | |
|
||||
| service.port | int | `3000` | |
|
||||
| service.type | string | `"ClusterIP"` | |
|
||||
| serviceAccount.annotations | object | `{}` | Annotations to add to the service account |
|
||||
| serviceAccount.create | bool | `true` | Specifies whether a service account should be created |
|
||||
| serviceAccount.name | string | `""` | The name of the service account to use. If not set and create is true, a name is generated using the fullname template |
|
||||
| spireHealthCheck.enabled | bool | `true` | Enables the SPIRE Healthchecker indicator |
|
||||
| startupProbe.enabled | bool | `true` | Enable startupProbe on Tornjak frontend container |
|
||||
| startupProbe.failureThreshold | int | `6` | Failure threshold for startupProbe |
|
||||
| startupProbe.initialDelaySeconds | int | `5` | Initial delay seconds for startupProbe |
|
||||
| startupProbe.periodSeconds | int | `10` | Period seconds for startupProbe |
|
||||
| startupProbe.successThreshold | int | `1` | Success threshold for startupProbe |
|
||||
| startupProbe.timeoutSeconds | int | `5` | Timeout seconds for startupProbe |
|
||||
| tolerations | list | `[]` | |
|
||||
| topologySpreadConstraints | list | `[]` | |
|
||||
----------------------------------------------
|
||||
@@ -0,0 +1,47 @@
|
||||
{{ template "chart.header" . }}
|
||||
|
||||
<!-- This README.md is generated. Please edit README.md.gotmpl -->
|
||||
|
||||
{{ template "chart.deprecationWarning" . }}
|
||||
|
||||
{{ template "chart.badgesSection" . }}
|
||||
[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
|
||||
|
||||
{{ template "chart.description" . }}
|
||||
|
||||
{{ template "chart.homepageLine" . }}
|
||||
|
||||
## Version support
|
||||
|
||||
> **Note**: This Chart is still in development and still subject to change the API (`values.yaml`).
|
||||
> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although
|
||||
> we do aim for as much stability as possible.
|
||||
|
||||
| Dependency | Supported Versions |
|
||||
|:-----------|:-------------------|
|
||||
| SPIRE | `1.5.3+`, `1.6.x` |
|
||||
| Tornjak | `1.0.x` |
|
||||
| Helm | `3.x` |
|
||||
|
||||
## Prerequisites
|
||||
|
||||
This chart requires access to Tornjak Backend (`tornjakFrontend.apiServerURL`).
|
||||
This URL needs to be reachable from your web browser and can therefore not be a cluster internal URL.
|
||||
|
||||
Obtain the URL for Tornjak APIs. If deployed in the same cluster, locally,
|
||||
Tornjak APIs are typically available at `http://localhost:10000`.
|
||||
Review Tornjak documentation for more details.
|
||||
|
||||
## Usage
|
||||
|
||||
Since this is just a demo version, to access Tornjak APIs you can use
|
||||
port forwarding. See the chart NOTES output for more details.
|
||||
|
||||
{{ template "chart.maintainersSection" . }}
|
||||
|
||||
{{ template "chart.sourcesSection" . }}
|
||||
|
||||
{{ template "chart.requirementsSection" . }}
|
||||
|
||||
{{ template "chart.valuesSection" . }}
|
||||
----------------------------------------------
|
||||
@@ -0,0 +1,30 @@
|
||||
Installed {{ .Chart.Name }}…
|
||||
|
||||
Name: {{ include "tornjak-frontend.name" . }}
|
||||
Fullname: {{ include "tornjak-frontend.fullname" . }}
|
||||
Your release is named: {{ .Release.Name }}
|
||||
Namespace: {{ include "tornjak-frontend.namespace" . }}
|
||||
|
||||
Tornjak UI (Frontend)
|
||||
image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image "global" .Values.global) }}
|
||||
pull policy: {{ .Values.image.pullPolicy }}
|
||||
Tornjak API (Backend): {{ include "tornjak-frontend.apiURL" . }}
|
||||
SPIRE health check enabled: "{{ .Values.spireHealthCheck.enabled }}"
|
||||
|
||||
### WARNING ###
|
||||
|
||||
Tornjak runs without authentication and is therefore NOT suitable to run in production environments.
|
||||
Only use in test environments!
|
||||
|
||||
Access Tornjak:
|
||||
|
||||
kubectl -n {{ include "tornjak-frontend.namespace" . }} port-forward service/{{ include "tornjak-frontend.fullname" . }} {{ .Values.service.port }}:3000
|
||||
|
||||
Ensure you have port-forwarding for tornjak-backend as well.
|
||||
|
||||
Open browser to: http://localhost:{{ .Values.service.port }}
|
||||
|
||||
To learn more about the release, try:
|
||||
|
||||
$ helm status {{ .Release.Name }}
|
||||
$ helm get all {{ .Release.Name }}
|
||||
@@ -0,0 +1,85 @@
|
||||
{{/*
|
||||
Expand the name of the chart.
|
||||
*/}}
|
||||
{{- define "tornjak-frontend.name" -}}
|
||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Create a default fully qualified app name.
|
||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||
If release name contains chart name it will be used as a full name.
|
||||
*/}}
|
||||
{{- define "tornjak-frontend.fullname" -}}
|
||||
{{- if .Values.fullnameOverride }}
|
||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||
{{- else }}
|
||||
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||
{{- if contains $name .Release.Name }}
|
||||
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||
{{- else }}
|
||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Allow the release namespace to be overridden for multi-namespace deployments in combined charts
|
||||
*/}}
|
||||
{{- define "tornjak-frontend.namespace" -}}
|
||||
{{- if .Values.namespaceOverride -}}
|
||||
{{- .Values.namespaceOverride -}}
|
||||
{{- else -}}
|
||||
{{- .Release.Namespace -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create chart name and version as used by the chart label.
|
||||
*/}}
|
||||
{{- define "tornjak-frontend.chart" -}}
|
||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Common labels
|
||||
*/}}
|
||||
{{- define "tornjak-frontend.labels" -}}
|
||||
helm.sh/chart: {{ include "tornjak-frontend.chart" . }}
|
||||
{{ include "tornjak-frontend.selectorLabels" . }}
|
||||
{{- if .Chart.AppVersion }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||
{{- end }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Selector labels
|
||||
*/}}
|
||||
{{- define "tornjak-frontend.selectorLabels" -}}
|
||||
app.kubernetes.io/name: {{ include "tornjak-frontend.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Create the name of the service account to use
|
||||
*/}}
|
||||
{{- define "tornjak-frontend.serviceAccountName" -}}
|
||||
{{- if .Values.serviceAccount.create }}
|
||||
{{- default (include "tornjak-frontend.fullname" .) .Values.serviceAccount.name }}
|
||||
{{- else }}
|
||||
{{- default "default" .Values.serviceAccount.name }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Create URL for accessing Tornjak APIs
|
||||
*/}}
|
||||
{{- define "tornjak-frontend.apiURL" -}}
|
||||
{{- if .Values.apiServerURL -}}
|
||||
{{- .Values.apiServerURL -}}
|
||||
{{- else }}
|
||||
{{- $feurl := print "http://localhost:" .Values.service.port }}
|
||||
{{- $feurl }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,74 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "tornjak-frontend.fullname" . }}
|
||||
namespace: {{ include "tornjak-frontend.namespace" . }}
|
||||
labels:
|
||||
{{- include "tornjak-frontend.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "tornjak-frontend.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
{{- include "tornjak-frontend.selectorLabels" . | nindent 8 }}
|
||||
spec:
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
serviceAccountName: {{ include "tornjak-frontend.serviceAccountName" . }}
|
||||
securityContext:
|
||||
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||
containers:
|
||||
- name: {{ include "tornjak-frontend.fullname" . }}
|
||||
image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image "global" .Values.global) }}
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
securityContext:
|
||||
{{- toYaml .Values.securityContext | nindent 12 }}
|
||||
ports:
|
||||
- name: http
|
||||
containerPort: 3000
|
||||
protocol: TCP
|
||||
env:
|
||||
- name: REACT_APP_API_SERVER_URI
|
||||
value: {{ include "tornjak-frontend.apiURL" . }}
|
||||
{{- if eq (.Values.spireHealthCheck.enabled | toString) "true" }}
|
||||
- name: REACT_APP_SPIRE_HEALTH_CHECK_ENABLE
|
||||
value: "{{ .Values.spireHealthCheck.enabled }}"
|
||||
{{- end }}
|
||||
{{- if .Values.startupProbe.enabled }}
|
||||
startupProbe:
|
||||
httpGet:
|
||||
scheme: HTTP
|
||||
port: {{ .Values.service.port }}
|
||||
failureThreshold: {{ .Values.startupProbe.failureThreshold }}
|
||||
initialDelaySeconds: {{ .Values.startupProbe.initialDelaySeconds }}
|
||||
periodSeconds: {{ .Values.startupProbe.periodSeconds }}
|
||||
successThreshold: {{ .Values.startupProbe.successThreshold }}
|
||||
timeoutSeconds: {{ .Values.startupProbe.timeoutSeconds }}
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: cache
|
||||
mountPath: /usr/src/app/
|
||||
{{- with .Values.nodeSelector }}
|
||||
nodeSelector:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.affinity }}
|
||||
affinity:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.tolerations }}
|
||||
tolerations:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
volumes:
|
||||
- name: cache
|
||||
emptyDir: {}
|
||||
@@ -0,0 +1,19 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
namespace: {{ include "tornjak-frontend.namespace" . }}
|
||||
name: {{ include "tornjak-frontend.fullname" . }}
|
||||
{{- with .Values.service.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "tornjak-frontend.labels" . | nindent 4 }}
|
||||
spec:
|
||||
type: {{ .Values.service.type }}
|
||||
selector:
|
||||
{{- include "tornjak-frontend.selectorLabels" . | nindent 4 }}
|
||||
ports:
|
||||
- name: {{ include "tornjak-frontend.fullname" . }}
|
||||
port: {{ .Values.service.port }}
|
||||
targetPort: http
|
||||
@@ -0,0 +1,13 @@
|
||||
{{- if .Values.serviceAccount.create -}}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ include "tornjak-frontend.serviceAccountName" . }}
|
||||
namespace: {{ include "tornjak-frontend.namespace" . }}
|
||||
labels:
|
||||
{{- include "tornjak-frontend.labels" . | nindent 4 }}
|
||||
{{- with .Values.serviceAccount.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,21 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: "{{ include "tornjak-frontend.fullname" . }}-test-connection"
|
||||
namespace: {{ include "tornjak-frontend.namespace" . }}
|
||||
labels:
|
||||
{{- include "tornjak-frontend.labels" . | nindent 4 }}
|
||||
annotations:
|
||||
"helm.sh/hook": test
|
||||
spec:
|
||||
securityContext:
|
||||
{{- toYaml .Values.podSecurityContext | nindent 4 }}
|
||||
containers:
|
||||
- name: curl-tornjak-frontend
|
||||
image: cgr.dev/chainguard/bash:latest
|
||||
command: ['curl']
|
||||
args: ['-k', '-s', '-f', 'http://{{ include "tornjak-frontend.fullname" . }}.{{ include "tornjak-frontend.namespace" . }}.svc.{{ include "spire-lib.cluster-domain" . }}:{{ .Values.service.port }}']
|
||||
securityContext:
|
||||
{{- toYaml .Values.securityContext | nindent 8 }}
|
||||
restartPolicy: Never
|
||||
|
||||
@@ -0,0 +1,90 @@
|
||||
# Default values for Tornjak UI (Frontend).
|
||||
# This is a YAML-formatted file.
|
||||
# Declare variables to be passed into your templates.
|
||||
|
||||
image:
|
||||
registry: ghcr.io
|
||||
repository: spiffe/tornjak-frontend
|
||||
pullPolicy: IfNotPresent
|
||||
# -- This value is deprecated in favor of tag. (Will be removed in a future release)
|
||||
version: ""
|
||||
# -- Overrides the image tag whose default is the chart appVersion.
|
||||
tag: ""
|
||||
|
||||
imagePullSecrets: []
|
||||
nameOverride: ""
|
||||
namespaceOverride: ""
|
||||
fullnameOverride: ""
|
||||
|
||||
serviceAccount:
|
||||
# -- Specifies whether a service account should be created
|
||||
create: true
|
||||
# -- Annotations to add to the service account
|
||||
annotations: {}
|
||||
# -- The name of the service account to use.
|
||||
# If not set and create is true, a name is generated using the fullname template
|
||||
name: ""
|
||||
|
||||
labels: {}
|
||||
|
||||
podSecurityContext: {}
|
||||
# fsGroup: 2000
|
||||
|
||||
securityContext: {}
|
||||
# capabilities:
|
||||
# drop:
|
||||
# - ALL
|
||||
# readOnlyRootFilesystem: true
|
||||
# runAsNonRoot: true
|
||||
# runAsUser: 1000
|
||||
|
||||
service:
|
||||
type: ClusterIP
|
||||
port: 3000
|
||||
annotations: {}
|
||||
|
||||
# -- Select specific nodes to run on (currently only amd64 is supported by Tornjak)
|
||||
nodeSelector:
|
||||
kubernetes.io/arch: amd64
|
||||
|
||||
affinity: {}
|
||||
|
||||
tolerations: []
|
||||
|
||||
topologySpreadConstraints: []
|
||||
|
||||
# -- Provide minimal resources to prevent accidental crashes due to resource exhaustion
|
||||
# resources:
|
||||
# requests:
|
||||
# cpu: 50m
|
||||
# memory: 128Mi
|
||||
# limits:
|
||||
# cpu: 100m
|
||||
# memory: 512Mi
|
||||
|
||||
# -- URL of the Tornjak APIs (backend)
|
||||
# Since Tornjak Frontend runs in the browser, this URL must be accessible from
|
||||
# the machine running a browser.
|
||||
apiServerURL: "http://localhost:10000/" # 👈 Use it for minikube or kind
|
||||
|
||||
# SPIRE Healthchecker indicator
|
||||
spireHealthCheck:
|
||||
# -- Enables the SPIRE Healthchecker indicator
|
||||
enabled: true
|
||||
|
||||
## Configure extra options for Tornjak frontend container's startup probe
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-startup-probes
|
||||
##
|
||||
startupProbe:
|
||||
# -- Enable startupProbe on Tornjak frontend container
|
||||
enabled: true
|
||||
# -- Initial delay seconds for startupProbe
|
||||
initialDelaySeconds: 5
|
||||
# -- Period seconds for startupProbe
|
||||
periodSeconds: 10
|
||||
# -- Timeout seconds for startupProbe
|
||||
timeoutSeconds: 5
|
||||
# -- Failure threshold for startupProbe
|
||||
failureThreshold: 6
|
||||
# -- Success threshold for startupProbe
|
||||
successThreshold: 1
|
||||
@@ -40,13 +40,53 @@
|
||||
|
||||
{{- define "spire-lib.image" -}}
|
||||
{{- $registry := include "spire-lib.registry" . }}
|
||||
{{- if eq (substr 0 7 .image.version) "sha256:" -}}
|
||||
{{- printf "%s/%s@%s" $registry .image.repository .image.version -}}
|
||||
{{- else if .appVersion -}}
|
||||
{{- printf "%s/%s:%s" $registry .image.repository (default .appVersion .image.version) -}}
|
||||
{{- else if .image.version -}}
|
||||
{{- printf "%s/%s:%s" $registry .image.repository .image.version -}}
|
||||
{{- else -}}
|
||||
{{- printf "%s/%s" $registry .image.repository -}}
|
||||
{{- end -}}
|
||||
{{- $repo := .image.repository }}
|
||||
{{- $tag := (default .image.tag .image.version) | toString }}
|
||||
{{- if eq (substr 0 7 $tag) "sha256:" }}
|
||||
{{- printf "%s/%s@%s" $registry $repo $tag }}
|
||||
{{- else if .appVersion }}
|
||||
{{- printf "%s/%s:%s" $registry $repo (default .appVersion $tag) }}
|
||||
{{- else if $tag }}
|
||||
{{- printf "%s/%s:%s" $registry $repo $tag }}
|
||||
{{- else }}
|
||||
{{- printf "%s/%s" $registry $repo }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* Takes in a dictionary with keys:
|
||||
* ingress - the standardized ingress object
|
||||
* svcName - The service to route to
|
||||
* port - which port on the service to use
|
||||
*/}}
|
||||
{{ define "spire-lib.ingress-spec" }}
|
||||
{{- $svcName := .svcName }}
|
||||
{{- $port := .port }}
|
||||
{{- with .ingress.className }}
|
||||
ingressClassName: {{ . | quote }}
|
||||
{{- end }}
|
||||
{{- if .ingress.tls }}
|
||||
tls:
|
||||
{{- range .ingress.tls }}
|
||||
- hosts:
|
||||
{{- range .hosts }}
|
||||
- {{ . | quote }}
|
||||
{{- end }}
|
||||
secretName: {{ .secretName | quote }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
rules:
|
||||
{{- range .ingress.hosts }}
|
||||
- host: {{ .host | quote }}
|
||||
http:
|
||||
paths:
|
||||
{{- range .paths }}
|
||||
- path: {{ .path }}
|
||||
pathType: {{ .pathType }}
|
||||
backend:
|
||||
service:
|
||||
name: {{ $svcName | quote }}
|
||||
port:
|
||||
number: {{ $port }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
@@ -26,18 +26,27 @@ global:
|
||||
|
||||
# subcharts
|
||||
spire-server:
|
||||
# -- Enables deployment of SPIRE Server
|
||||
enabled: true
|
||||
nameOverride: server
|
||||
|
||||
controllerManager:
|
||||
# -- Enables deployment of Controller Manager
|
||||
enabled: true
|
||||
|
||||
spire-agent:
|
||||
# -- Enables deployment of SPIRE Agent(s)
|
||||
enabled: true
|
||||
nameOverride: agent
|
||||
|
||||
spiffe-csi-driver:
|
||||
# -- Enables deployment of CSI driver
|
||||
enabled: true
|
||||
|
||||
spiffe-oidc-discovery-provider:
|
||||
# -- Enables deployment of OIDC discovery provider
|
||||
enabled: false
|
||||
|
||||
tornjak-frontend:
|
||||
# -- Enables deployment of Tornjak frontend/UI (Not for production)
|
||||
enabled: false
|
||||
|
||||
@@ -12,3 +12,25 @@ helm upgrade --install --namespace spire-server spire charts/spire -f values.yam
|
||||
```
|
||||
|
||||
See [values.yaml](./values.yaml) for more details on the chart configurations to achieve this setup.
|
||||
|
||||
If you want to expose your spire-server outside of Kubernetes and are using ingress-nginx, add following values file when running `helm template/install/upgrade`.
|
||||
|
||||
```shell
|
||||
-f values-expose-spire-server-ingress-nginx.yaml
|
||||
```
|
||||
|
||||
If you want to expose your federation endpoint outside of Kubernetes and are using ingress-nginx
|
||||
you have two options as described here:
|
||||
https://github.com/spiffe/spiffe/blob/main/standards/SPIFFE_Federation.md#52-endpoint-profiles
|
||||
|
||||
If you chose profile https_web, use:
|
||||
|
||||
```shell
|
||||
-f values-expose-federation-https-web-ingress-nginx.yaml
|
||||
```
|
||||
|
||||
If you chose profile https_spiffe, use:
|
||||
|
||||
```shell
|
||||
-f values-expose-federation-https-spiffe-ingress-nginx.yaml
|
||||
```
|
||||
|
||||
@@ -0,0 +1,25 @@
|
||||
spire-server:
|
||||
federation:
|
||||
enabled: true
|
||||
ingress:
|
||||
enabled: true
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
|
||||
nginx.ingress.kubernetes.io/ssl-passthrough: "true"
|
||||
|
||||
# Optional settings you may put in your own values.
|
||||
# kubernetes.io/ingress.class: nginx
|
||||
# kubernetes.io/tls-acme: "true"
|
||||
|
||||
# className: nginx
|
||||
|
||||
hosts:
|
||||
- host: spire-server-federation.example.org
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
tls:
|
||||
- hosts:
|
||||
- spire-server-federation.example.org
|
||||
@@ -0,0 +1,25 @@
|
||||
spire-server:
|
||||
federation:
|
||||
enabled: true
|
||||
ingress:
|
||||
enabled: true
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
|
||||
|
||||
# Optional settings you may put in your own values.
|
||||
# kubernetes.io/ingress.class: nginx
|
||||
# kubernetes.io/tls-acme: "true"
|
||||
|
||||
# className: nginx
|
||||
|
||||
hosts:
|
||||
- host: spire-server-federation.example.org
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
tls:
|
||||
- hosts:
|
||||
- spire-server-federation.example.org
|
||||
secretName: spire-server-federation-tls
|
||||
@@ -0,0 +1,25 @@
|
||||
spire-server:
|
||||
ingress:
|
||||
enabled: true
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
|
||||
nginx.ingress.kubernetes.io/ssl-passthrough: "true"
|
||||
|
||||
# Optional settings you may put in your own values.
|
||||
# kubernetes.io/tls-acme: "true"
|
||||
# kubernetes.io/ingress.class: nginx
|
||||
|
||||
# className: nginx
|
||||
|
||||
# You must override these in your own values file with the appropriate hostname
|
||||
# and secret or it wont start.
|
||||
hosts:
|
||||
- host: spire-server.example.org
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
tls:
|
||||
- hosts:
|
||||
- spire-server.example.org
|
||||
@@ -24,9 +24,6 @@ spire-server:
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
|
||||
dataStorage:
|
||||
enabled: true
|
||||
|
||||
logLevel: info
|
||||
|
||||
controllerManager:
|
||||
@@ -77,3 +74,18 @@ spiffe-oidc-discovery-provider:
|
||||
drop: [ALL]
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
|
||||
tornjak-frontend:
|
||||
podSecurityContext:
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
fsGroup: 1000
|
||||
fsGroupChangePolicy: OnRootMismatch
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
runAsNonRoot: true
|
||||
readOnlyRootFilesystem: false
|
||||
capabilities:
|
||||
drop: [ALL]
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
|
||||
@@ -0,0 +1,37 @@
|
||||
# Recommended setup to deploy Tornjak
|
||||
|
||||
> **Warning**: The current version of Tornjak in this chart is deployed without authentication. Therefore it is not suitable to run this version in production.
|
||||
|
||||
To install Spire with the least privileges possible we deploy spire across 2 namespaces.
|
||||
|
||||
```shell
|
||||
kubectl create namespace "spire-system"
|
||||
kubectl label namespace "spire-system" pod-security.kubernetes.io/enforce=privileged
|
||||
kubectl create namespace "spire-server"
|
||||
kubectl label namespace "spire-server" pod-security.kubernetes.io/enforce=restricted
|
||||
|
||||
# deploy SPIRE with Tornjak enabled
|
||||
helm upgrade --install --namespace spire-server \
|
||||
--values ../production/values.yaml \
|
||||
--values ./values.yaml \
|
||||
--render-subchart-notes \
|
||||
spire charts/spire
|
||||
|
||||
# test the Tornjak deployment
|
||||
helm test spire -n spire-server
|
||||
```
|
||||
|
||||
## Access tornjak
|
||||
|
||||
To access Tornjak you will have to use port-forwarding for the time being *(until we add authentication and ingress)*.
|
||||
|
||||
Run following commands from your shell, if you ran with different values your namespace might differ. Consult the install notes printed when running above `helm upgrade` command in that case.
|
||||
|
||||
```shell
|
||||
kubectl -n spire-server port-forward service/spire-tornjak-backend 10000:10000
|
||||
kubectl -n spire-server port-forward service/spire-tornjak-frontend 3000:3000
|
||||
```
|
||||
|
||||
You can now access Tornjak at [localhost:3000](http://localhost:3000).
|
||||
|
||||
See [values.yaml](./values.yaml) for more details on the chart configurations to achieve this setup.
|
||||
@@ -0,0 +1,17 @@
|
||||
spire-server:
|
||||
tornjak:
|
||||
enabled: true
|
||||
|
||||
tornjak-frontend:
|
||||
enabled: true
|
||||
service:
|
||||
type: ClusterIP
|
||||
port: 3000
|
||||
apiServerURL: "http://localhost:10000/"
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 128Mi
|
||||
limits:
|
||||
cpu: 100m
|
||||
memory: 512Mi
|
||||
@@ -0,0 +1,237 @@
|
||||
<!-- vim: filetype=markdown colorcolumn=80
|
||||
-->
|
||||
|
||||
# Maintainers handbook
|
||||
|
||||
This document is a guide for maintainers across the spire/helm-chart effort to
|
||||
provide a consistent user interface for those going through the review process.
|
||||
|
||||
## The Pull Request
|
||||
|
||||
Pull requests are submitted through GitHub. They are contributions to change
|
||||
the project. There is no difference between code and non-code submissions, in
|
||||
procedure or policy.
|
||||
|
||||
All maintainers should consider that pull requests are gifts. The project
|
||||
survives due to the effort of frequent contributors and their generosity. As
|
||||
such, to encourage future submissions, the default approach to handling a merge
|
||||
request should be gratitude, even if the request cannot be merged.
|
||||
|
||||
## Roles
|
||||
|
||||
There are two primary roles within the scope of a pull request.
|
||||
|
||||
- Committer - one who offers code to be merged.
|
||||
- Maintainer - one who merges the code.
|
||||
|
||||
To ensure that all code receives a proper review, these roles are mutually
|
||||
exclusive for each pull request. Within the scope of a pull request, a
|
||||
Committer cannot be a Maintainer, nor can a Maintainer be a Committer.
|
||||
|
||||
For abandoned pull requests still requiring work, or efforts transferred between
|
||||
people, a Maintainer may become a Committer, invalidating any of their prior
|
||||
review work.
|
||||
|
||||
### Committers
|
||||
|
||||
Committers are people contributing changes to the repository. The first
|
||||
committer is typically the one that opens the pull request. Additional people
|
||||
can become committers in the same merge request if they change the pull request
|
||||
directly.
|
||||
|
||||
Suggestions to a committer by a maintainer, such as commentary that with a
|
||||
change the merge request might be accepted, does not make a maintainer a
|
||||
committer, as the committer will choose to include the change at their discretion.
|
||||
|
||||
### Maintainers
|
||||
|
||||
Maintainers hold a dual role in the project. They are ambassadors of the
|
||||
effort as well as the gatekeepers permitting changes to the repository. As
|
||||
ambassadors, maintainers must present a fair and impartial demeanor when
|
||||
dealing with contributors.
|
||||
|
||||
Failure to be fair or impartial reflects poorly on the released product, as
|
||||
guilt by association taints the product. The process of reviewing a merge
|
||||
request often includes conflict. Contributors can become defensive about work
|
||||
they've done while maintainers can become adamant in the changes they request.
|
||||
|
||||
To prevent a breakdown in the review process, the project encourages all
|
||||
reviewers to adhere to a standard set of review best practices. Reviewers
|
||||
should familiarize themselves with these practices and suggest updates to keep
|
||||
the practices relevant over time.
|
||||
|
||||
## Review Standards
|
||||
|
||||
These standards serve to prevent problems from cropping up during a review. The
|
||||
intent is that consistent application of these standards permits a consistent
|
||||
review process, leading to repeatable, suprise free, outcomes during a review.
|
||||
|
||||
The intent of maintaining standards is to enhance productivity and improve team
|
||||
morale. In the event the standards have a negative impact on productivity or
|
||||
morale, the standard itself should be questioned. To clarify the kinds of
|
||||
productivity to be improved, the intent is to reduce the time between initial
|
||||
submission of a merge request and its resolution.
|
||||
|
||||
### Challenges to the Review Process
|
||||
|
||||
Whenever possible, a maintainer should not argue a point about the review
|
||||
standards with a contributor. Instead they should provide this document to the
|
||||
contributor, indicating that changes to the review process are to be initiated
|
||||
with a standard-altering Issue.
|
||||
|
||||
In the exceedingly rare situation that a reviewer opts to ignore a review
|
||||
standard during a merge request, the reviewer must indicate they are purposefully
|
||||
ignoring the standard and the reason why. There are valid reasons to ignore
|
||||
standards, but whenever possible a maintainer should uphold the standard or
|
||||
change it.
|
||||
|
||||
### Review Outcomes
|
||||
|
||||
From the Maintainers point of view, all merge requests require one of four
|
||||
actions:
|
||||
|
||||
- The maintainer accepts the pull request.
|
||||
- The maintainer rejects the pull request.
|
||||
- The maintainer requests the pull request be altered.
|
||||
- The maintainer rewrites some or all of the pull request, becoming a
|
||||
committer.
|
||||
|
||||
Suggestions to the committer that a merge request be altered do not constitute
|
||||
becoming an committer, even if the maintainer provides the lines of code
|
||||
being suggested.
|
||||
|
||||
### Review Tempo
|
||||
|
||||
Maintainers should set aside and appropriate amount of time when reviewing. The
|
||||
initial suggestion is one hour. Most reviews will complete well under this time,
|
||||
but a few will take longer. Longer reviews should include review breaks, so the
|
||||
reviewer remains fresh and attentive. Attempting a three hour long review often
|
||||
yields worse results than two or three shorter efforts with breaks.
|
||||
|
||||
The concept of going slow to complete items quickly is not a new one. With a
|
||||
little extra time, comments can be thoughtful instead of reactive.
|
||||
|
||||
### Review Goals
|
||||
|
||||
Each review should have a defined set of goals established prior to the main
|
||||
work of the review. The review process often challenges the committer, in the
|
||||
hopes of improving the merge request. Keeping the review scoped to goals avoids
|
||||
scenarios where the reviewer's requests seem capricious or autocratic.
|
||||
|
||||
The current list of review goals include:
|
||||
|
||||
- Keeping the code base readable
|
||||
- Keeping the code base search-able
|
||||
- Keeping the code base understandable
|
||||
- Keeping the code base maintainable
|
||||
- Keeping the code base testable
|
||||
- Keeping the code base functional
|
||||
|
||||
Note that quality, stability, and robustness are purposefully not included in
|
||||
this list:
|
||||
|
||||
- Quality is the combination of readable and testable.
|
||||
- Stability is the combination of understandable, functional, and testable.
|
||||
- Robustness is the combination of maintainable, functional, and testable.
|
||||
|
||||
Code standards are being developed to clarify specific tests to support these
|
||||
goals.
|
||||
|
||||
### Developer Testing prior to Review
|
||||
|
||||
Each submission should assume that the committer ran the unit tests and
|
||||
small-scale (not requiring an environment) integration tests prior to submission.
|
||||
The merge request CI pipeline also runs these tests automatically. Failure to
|
||||
pass them leads to an automatic call for merge request modification.
|
||||
|
||||
Attempts to pass this requirement by disabling tests or modifying them such that
|
||||
they are effectively disabled are strongly discouraged. They violate the review
|
||||
goals by reducing maintainability (no new failures will be detected) and
|
||||
possibly functionality (for scenarios outside of the current mindset).
|
||||
|
||||
At their leisure, maintainers may suggest code changes to make the test suite pass.
|
||||
Doing so is never required, nor part of the minimum duties of a maintainer.
|
||||
|
||||
### Reviewer Count
|
||||
|
||||
Two passing reviews are required for code to be merged.
|
||||
|
||||
Whenever possible, the number of reviewers should be limited, as each additional
|
||||
reviewer presents an extra set of communication channels between the review and
|
||||
themselves.
|
||||
|
||||
- One reviewer has one channel between the committer and the reviewer
|
||||
- Increasing to two, adds one channel to the the committer, and one to the
|
||||
reviewers.
|
||||
- Increasing to three, adds one channel to the committer, and two to the
|
||||
reviewers.
|
||||
- Increasing to four, adds one channel to the committer, and three to the
|
||||
reviewers.
|
||||
|
||||
The amount of possible communication grows such that
|
||||
`commChannels(reviewers) = reviewers + reviewers(reviewers-1)/2` leads to an
|
||||
`O(n^2)` number of channels. Thus, keeping reviewer count low is critical to
|
||||
velocity.
|
||||
|
||||
### Reviewer Consensus
|
||||
|
||||
Reviewers should coordinate among themselves when differences of opinion arise
|
||||
in a review. The first reviewer is likely to make a statement before being
|
||||
aware of the difference of opinion; but, once a difference of opinion is known,
|
||||
the reviewers should coordinate privately to find a unified presentation of the
|
||||
desired features to communicate back to the committer.
|
||||
|
||||
The committer has no role in the evaluation of options to determine the proper
|
||||
path forward, including them only diminishes the efficiency of the process and
|
||||
increases the stress they endure while they observe the discussion. Once a path
|
||||
is agreed upon:
|
||||
|
||||
- If the request to the committer was reversed, the reviewer making that stance
|
||||
should present the new path.
|
||||
- If the request to the committer was refined, the second reviewer should
|
||||
present the refined path.
|
||||
|
||||
If no path forward can be agreed upon, the proposed path that is closest to the
|
||||
committer submission is the accepted path. This guideline exists to promote
|
||||
cooperation among reviewers. Ideas of merit which don't become part of the
|
||||
merge request should be submitted as new issues and reviewed independently.
|
||||
|
||||
### Review Automation
|
||||
|
||||
Reviewers have a commitment to continuous improvement of the review process.
|
||||
Whenever a reviewer sees an opportunity to reduce the manpower involved in the
|
||||
review process by automating a portion of the process, the reviewer should
|
||||
create an issue and submit it as an improvement to the CI process.
|
||||
|
||||
Improvements are subject to the same review process and the same review goals
|
||||
as other committer offerings. Readability, search-ability, understanding,
|
||||
maintenance, testing, and functionality are goals of the review process just as
|
||||
they are of the product code.
|
||||
|
||||
Lack of speed in the review process is viewed as a failure to make the process
|
||||
maintainable, understandable, and functional.
|
||||
|
||||
### Review Communication
|
||||
|
||||
Reviewers are encouraged to have meaningful dialogues with contributors and
|
||||
reviewers during a merge request. For these dialogues to be effective, the
|
||||
purpose of each communication should be considered. Mixing purposes in
|
||||
communication creates problems in understanding intent, retarding progress.
|
||||
Scope your communications to move efforts forward.
|
||||
|
||||
Avoid mixing the following communication scopes:
|
||||
|
||||
- Status update
|
||||
- Decision making
|
||||
- Problem solving
|
||||
- Team building
|
||||
- Information sharing
|
||||
- Brainstorming
|
||||
|
||||
Combining these scopes reduce the effectiveness of the communication. Ideally
|
||||
they should be done in different settings. Mixing a brainstorming session with
|
||||
a decision making session disrupts the evaluation of pros and cons with new
|
||||
options. Attempting to problem solve a technical issue during a status update
|
||||
draws focus away from identifying the challenges of delivering the project,
|
||||
replacing them with the challenges of solving a single problem in the project.
|
||||
|
||||
Reference in New Issue
Block a user