Support for Cloud SQL Proxy in GCP (#646)

* allow IAM auth for non-password methods

Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* add example, patch charts' versions and values

Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* updates

Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Bump test chart dependencies (#647)

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Bump github.com/onsi/ginkgo/v2 from 2.23.4 to 2.24.0 in /tests (#648)

Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.23.4 to 2.24.0.
- [Release notes](https://github.com/onsi/ginkgo/releases)
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/ginkgo/compare/v2.23.4...v2.24.0)

---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
  dependency-version: 2.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Bump helm.sh/helm/v3 from 3.18.4 to 3.18.6 in /tests (#650)

Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.18.4 to 3.18.6.
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](https://github.com/helm/helm/compare/v3.18.4...v3.18.6)

---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.18.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Bump github.com/onsi/ginkgo/v2 from 2.24.0 to 2.25.1 in /tests (#651)

Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.24.0 to 2.25.1.
- [Release notes](https://github.com/onsi/ginkgo/releases)
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/ginkgo/compare/v2.24.0...v2.25.1)

---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
  dependency-version: 2.25.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Bump test chart dependencies (#653)

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Bump github.com/onsi/gomega from 1.38.0 to 1.38.1 in /tests (#652)

Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.38.0 to 1.38.1.
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/gomega/compare/v1.38.0...v1.38.1)

---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.38.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Bump github.com/onsi/gomega from 1.38.1 to 1.38.2 in /tests (#654)

Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.38.1 to 1.38.2.
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/gomega/compare/v1.38.1...v1.38.2)

---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Bump test chart dependencies (#658)

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Bump github.com/onsi/ginkgo/v2 from 2.25.1 to 2.25.3 in /tests (#659)

Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.25.1 to 2.25.3.
- [Release notes](https://github.com/onsi/ginkgo/releases)
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/ginkgo/compare/v2.25.1...v2.25.3)

---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
  dependency-version: 2.25.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Bump test chart dependencies (#660)

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Add labels to the spiffe-oidc-discovery-provider values.yaml (#656)

* add labels to the spiffe-oidc-discovery-provider values.yaml

Signed-off-by: tuxotron <[email protected]>

* add labels to readme

Signed-off-by: tuxotron <[email protected]>

* Bump github.com/onsi/gomega from 1.38.1 to 1.38.2 in /tests (#654)

Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.38.1 to 1.38.2.
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/gomega/compare/v1.38.1...v1.38.2)

---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: tuxotron <[email protected]>

* Bump test chart dependencies (#658)

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Signed-off-by: tuxotron <[email protected]>

---------

Signed-off-by: tuxotron <[email protected]>
Signed-off-by: dependabot[bot] <[email protected]>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: spire-helm-version-checker[bot] <161522935+spire-helm-version-checker[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Bump helm.sh/helm/v3 from 3.18.6 to 3.19.0 in /tests (#664)

Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.18.6 to 3.19.0.
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](https://github.com/helm/helm/compare/v3.18.6...v3.19.0)

---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* blend into same logic in the chart for the new auth method, add the ability to add loadbalancer ip

Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* remove whitespaces

Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* update README and values file

Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Spire agent helm chart: allow configuring logFormat (#661)

* Spire agent helm chart: allow configuring logFormat

Signed-off-by: Nikolai Tihhomirov <[email protected]>

* Fixup: wrong doc parameter

Signed-off-by: Nikolai Tihhomirov <[email protected]>

---------

Signed-off-by: Nikolai Tihhomirov <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Add controller manager configs gcInterval, logLevel, and make entryIDPrefix configurable (#662)

* Make controller manager gcInterval configurable in spire-server helm chart

Signed-off-by: Daniel Schlatter <[email protected]>

* Make controller manager logLevel configurable in spire-server helm chart

Signed-off-by: Daniel Schlatter <[email protected]>

* Make controller manager entryIDPrefix configurable in spire-server helm chart

Signed-off-by: Daniel Schlatter <[email protected]>

* change configurable entryIDPrefix to a binary option of add the cluster name or not

Signed-off-by: Daniel Schlatter <[email protected]>

---------

Signed-off-by: Daniel Schlatter <[email protected]>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Bump test chart dependencies (#666)

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* make spire server's auth_opa_policy_engine configurable in the helm chart (#663)

Signed-off-by: Hamdan Al-Radaideh <[email protected]>

* Update spire to 1.13.0 (#667)

Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: Hamdan Al-Radaideh <[email protected]>

---------

Signed-off-by: Hamdan Al-Radaideh <[email protected]>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <[email protected]>
Signed-off-by: tuxotron <[email protected]>
Signed-off-by: Nikolai Tihhomirov <[email protected]>
Signed-off-by: Daniel Schlatter <[email protected]>
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: spire-helm-version-checker[bot] <161522935+spire-helm-version-checker[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: tuxotron <[email protected]>
Co-authored-by: Nikolai <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
Co-authored-by: Daniel Schlatter <[email protected]>
This commit is contained in:
Hamdan Al-Radaideh
2025-09-23 02:46:18 +00:00
committed by GitHub
co-authored by dependabot[bot] kfox1111 marcofranssen spire-helm-version-checker[bot] tuxotron Nikolai Daniel Schlatter
parent 3c3718c904
commit 1ab06a1b11
12 changed files with 212 additions and 12 deletions
@@ -51,6 +51,7 @@ A Helm chart to install the SPIFFE OIDC discovery provider.
| `service.ports.http` | Insecure port for the service | `80` | | `service.ports.http` | Insecure port for the service | `80` |
| `service.ports.https` | Secure port for the service | `443` | | `service.ports.https` | Secure port for the service | `443` |
| `service.annotations` | Annotations for service resource | `{}` | | `service.annotations` | Annotations for service resource | `{}` |
| `service.loadBalancerIP` | IP address to assign to load balancer (if supported) | `""` |
| `configMap.annotations` | Annotations to add to the SPIFFE OIDC Discovery Provider ConfigMap | `{}` | | `configMap.annotations` | Annotations to add to the SPIFFE OIDC Discovery Provider ConfigMap | `{}` |
| `podSecurityContext` | Pod security context for OIDC discovery provider pods | `{}` | | `podSecurityContext` | Pod security context for OIDC discovery provider pods | `{}` |
| `securityContext` | Security context for OIDC discovery provider deployment | `{}` | | `securityContext` | Security context for OIDC discovery provider deployment | `{}` |
@@ -9,6 +9,9 @@ metadata:
{{- end }} {{- end }}
spec: spec:
type: {{ .Values.service.type }} type: {{ .Values.service.type }}
{{- if and (eq .Values.service.type "LoadBalancer") .Values.service.loadBalancerIP }}
loadBalancerIP: {{ .Values.service.loadBalancerIP }}
{{- end }}
ports: ports:
{{- if eq (include "spiffe-oidc-discovery-provider.tls-enabled" .) "false" }} {{- if eq (include "spiffe-oidc-discovery-provider.tls-enabled" .) "false" }}
- name: http - name: http
@@ -88,6 +88,8 @@ service:
https: 443 https: 443
annotations: {} annotations: {}
# external-dns.alpha.kubernetes.io/hostname: oidc-discovery.example.org # external-dns.alpha.kubernetes.io/hostname: oidc-discovery.example.org
## @param service.loadBalancerIP IP address to assign to load balancer (if supported)
loadBalancerIP: ""
configMap: configMap:
## @param configMap.annotations [object] Annotations to add to the SPIFFE OIDC Discovery Provider ConfigMap ## @param configMap.annotations [object] Annotations to add to the SPIFFE OIDC Discovery Provider ConfigMap
+2 -1
View File
@@ -104,6 +104,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr
| `service.type` | Type of the Spire server service created | `ClusterIP` | | `service.type` | Type of the Spire server service created | `ClusterIP` |
| `service.port` | Port for the created service | `443` | | `service.port` | Port for the created service | `443` |
| `service.annotations` | Annotations to add to the service object | `{}` | | `service.annotations` | Annotations to add to the service object | `{}` |
| `service.loadBalancerIP` | IP address to assign to load balancer (if supported) | `""` |
| `configMap.annotations` | Annotations to add to the SPIRE Server ConfigMap | `{}` | | `configMap.annotations` | Annotations to add to the SPIRE Server ConfigMap | `{}` |
| `resources` | Resource requests and limits | `{}` | | `resources` | Resource requests and limits | `{}` |
| `autoscaling.enabled` | Flag to enable autoscaling | `false` | | `autoscaling.enabled` | Flag to enable autoscaling | `false` |
@@ -125,7 +126,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr
| `persistence.accessMode` | What access mode to use for persistence. Valid options are ReadWriteOnce (recommended), ReadWriteOncePod, ReadWriteMany (not recommended) | `ReadWriteOnce` | | `persistence.accessMode` | What access mode to use for persistence. Valid options are ReadWriteOnce (recommended), ReadWriteOncePod, ReadWriteMany (not recommended) | `ReadWriteOnce` |
| `persistence.storageClass` | What storage class to use for persistence | `nil` | | `persistence.storageClass` | What storage class to use for persistence | `nil` |
| `persistence.hostPath` | Which path to use on the host when persistence.type = hostPath | `""` | | `persistence.hostPath` | Which path to use on the host when persistence.type = hostPath | `""` |
| `dataStore.sql.databaseType` | Other supported databases are ["postgres", "mysql", "aws_postgresql", "aws_mysql"]. Note: aws type databases are still experimental | `sqlite3` | | `dataStore.sql.databaseType` | Other supported databases are ["postgres", "mysql", "aws_postgresql", "aws_mysql", "gcp_mysql_sa_iam"]. Note: aws type databases are still experimental. gcp_mysql_sa_iam uses IAM authentication by default. | `sqlite3` |
| `dataStore.sql.databaseName` | Only used when type != "sqlite3" | `spire` | | `dataStore.sql.databaseName` | Only used when type != "sqlite3" | `spire` |
| `dataStore.sql.host` | Only used when type != "sqlite3" | `""` | | `dataStore.sql.host` | Only used when type != "sqlite3" | `""` |
| `dataStore.sql.port` | If 0 (default), it will auto set to 5432 for postgres and 3306 for mysql. Only used by those databases. | `0` | | `dataStore.sql.port` | If 0 (default), it will auto set to 5432 for postgres and 3306 for mysql. Only used by those databases. | `0` |
@@ -234,21 +234,35 @@ Create the name of the service account to use
{{- $_ := set $config "database_type" "sqlite3" }} {{- $_ := set $config "database_type" "sqlite3" }}
{{- $query := include "spire-server.config-sqlite-query" .Values.dataStore.sql.options }} {{- $query := include "spire-server.config-sqlite-query" .Values.dataStore.sql.options }}
{{- $_ := set $config "connection_string" (printf "%s%s" .Values.dataStore.sql.file $query) }} {{- $_ := set $config "connection_string" (printf "%s%s" .Values.dataStore.sql.file $query) }}
{{- else if or (eq .Values.dataStore.sql.databaseType "mysql") (eq .Values.dataStore.sql.databaseType "aws_mysql") }} {{- else if or (eq .Values.dataStore.sql.databaseType "mysql") (eq .Values.dataStore.sql.databaseType "aws_mysql") (eq .Values.dataStore.sql.databaseType "gcp_mysql_sa_iam") }}
{{- if eq .Values.dataStore.sql.databaseType "mysql" }} {{- if eq .Values.dataStore.sql.databaseType "mysql" }}
{{- $_ := set $config "database_type" "mysql" }} {{- $_ := set $config "database_type" "mysql" }}
{{- $pw = "${DBPW}" }} {{- $pw = "${DBPW}" }}
{{- $ropw = "${RODBPW}" }} {{- $ropw = "${RODBPW}" }}
{{- else if eq .Values.dataStore.sql.databaseType "gcp_mysql_sa_iam" }}
{{- $_ := set $config "database_type" "mysql" }}
{{- $pw = "" }}
{{- $ropw = "" }}
{{- else }} {{- else }}
{{- $_ := set $config "database_type" (list (dict "aws_mysql" (dict "region" .Values.dataStore.sql.region))) }} {{- $_ := set $config "database_type" (list (dict "aws_mysql" (dict "region" .Values.dataStore.sql.region))) }}
{{- end }} {{- $pw = "${DBPW}" }}
{{- $ropw = "${RODBPW}" }}
{{- end }}
{{- $port := int .Values.dataStore.sql.port | default 3306 }} {{- $port := int .Values.dataStore.sql.port | default 3306 }}
{{- $query := include "spire-server.config-mysql-query" .Values.dataStore.sql.options }} {{- $query := include "spire-server.config-mysql-query" .Values.dataStore.sql.options }}
{{- $_ := set $config "connection_string" (printf "%s:%s@tcp(%s:%d)/%s%s" .Values.dataStore.sql.username $pw .Values.dataStore.sql.host $port .Values.dataStore.sql.databaseName $query) }} {{- if eq $pw "" }}
{{- $_ := set $config "connection_string" (printf "%s@tcp(%s:%d)/%s%s" .Values.dataStore.sql.username .Values.dataStore.sql.host $port .Values.dataStore.sql.databaseName $query) }}
{{- else }}
{{- $_ := set $config "connection_string" (printf "%s:%s@tcp(%s:%d)/%s%s" .Values.dataStore.sql.username $pw .Values.dataStore.sql.host $port .Values.dataStore.sql.databaseName $query) }}
{{- end }}
{{- if .Values.dataStore.sql.readOnly.enabled }} {{- if .Values.dataStore.sql.readOnly.enabled }}
{{- $roPort := int .Values.dataStore.sql.readOnly.port | default 3306 }} {{- $roPort := int .Values.dataStore.sql.readOnly.port | default 3306 }}
{{- $roQuery := include "spire-server.config-mysql-query" .Values.dataStore.sql.readOnly.options }} {{- $roQuery := include "spire-server.config-mysql-query" .Values.dataStore.sql.readOnly.options }}
{{- $_ := set $config "ro_connection_string" (printf "%s:%s@tcp(%s:%d)/%s%s" .Values.dataStore.sql.readOnly.username $ropw .Values.dataStore.sql.readOnly.host $roPort .Values.dataStore.sql.readOnly.databaseName $roQuery) }} {{- if eq $ropw "" }}
{{- $_ := set $config "ro_connection_string" (printf "%s@tcp(%s:%d)/%s%s" .Values.dataStore.sql.readOnly.username .Values.dataStore.sql.readOnly.host $roPort .Values.dataStore.sql.readOnly.databaseName $roQuery) }}
{{- else }}
{{- $_ := set $config "ro_connection_string" (printf "%s:%s@tcp(%s:%d)/%s%s" .Values.dataStore.sql.readOnly.username $ropw .Values.dataStore.sql.readOnly.host $roPort .Values.dataStore.sql.readOnly.databaseName $roQuery) }}
{{- end }}
{{- end }} {{- end }}
{{- else if or (eq .Values.dataStore.sql.databaseType "postgres") (eq .Values.dataStore.sql.databaseType "aws_postgres") }} {{- else if or (eq .Values.dataStore.sql.databaseType "postgres") (eq .Values.dataStore.sql.databaseType "aws_postgres") }}
{{- if eq .Values.dataStore.sql.databaseType "postgres" }} {{- if eq .Values.dataStore.sql.databaseType "postgres" }}
@@ -7,8 +7,7 @@
{{- if and (.Values.dataStore.sql.externalSecret.enabled) (eq .Values.dataStore.sql.externalSecret.key "") }} {{- if and (.Values.dataStore.sql.externalSecret.enabled) (eq .Values.dataStore.sql.externalSecret.key "") }}
{{- fail "dataStore.sql.externalSecret.key cannot be empty string when dataStore.sql.externalSecret is enabled" }} {{- fail "dataStore.sql.externalSecret.key cannot be empty string when dataStore.sql.externalSecret is enabled" }}
{{- end }} {{- end }}
{{- if ne .Values.dataStore.sql.databaseType "sqlite3" }} {{- if and (ne .Values.dataStore.sql.databaseType "sqlite3") (not .Values.dataStore.sql.externalSecret.enabled) (ne .Values.dataStore.sql.databaseType "gcp_mysql_sa_iam") }}
{{- if not .Values.dataStore.sql.externalSecret.enabled }}
apiVersion: v1 apiVersion: v1
kind: Secret kind: Secret
metadata: metadata:
@@ -20,4 +19,3 @@ data:
RODBPW: {{ .Values.dataStore.sql.readOnly.password | b64enc }} RODBPW: {{ .Values.dataStore.sql.readOnly.password | b64enc }}
{{- end }} {{- end }}
{{- end }} {{- end }}
{{- end }}
@@ -228,7 +228,7 @@ spec:
{{- with .Values.extraEnv }} {{- with .Values.extraEnv }}
{{- . | toYaml | nindent 10 }} {{- . | toYaml | nindent 10 }}
{{- end }} {{- end }}
{{- if ne .Values.dataStore.sql.databaseType "sqlite3" }} {{- if and (ne .Values.dataStore.sql.databaseType "sqlite3") (ne .Values.dataStore.sql.databaseType "gcp_mysql_sa_iam") }}
{{- if .Values.dataStore.sql.externalSecret.enabled }} {{- if .Values.dataStore.sql.externalSecret.enabled }}
- name: DBPW - name: DBPW
valueFrom: valueFrom:
@@ -242,13 +242,14 @@ spec:
name: {{ $fullname }}-dbpw name: {{ $fullname }}-dbpw
key: DBPW key: DBPW
{{- end }} {{- end }}
{{- if and .Values.dataStore.sql.readOnly.enabled .Values.dataStore.sql.readOnly.externalSecret.enabled }} {{- if and .Values.dataStore.sql.readOnly.enabled (ne .Values.dataStore.sql.databaseType "gcp_mysql_sa_iam") }}
{{- if .Values.dataStore.sql.readOnly.externalSecret.enabled }}
- name: RODBPW - name: RODBPW
valueFrom: valueFrom:
secretKeyRef: secretKeyRef:
name: {{ .Values.dataStore.sql.readOnly.externalSecret.name }} name: {{ .Values.dataStore.sql.readOnly.externalSecret.name }}
key: {{ .Values.dataStore.sql.readOnly.externalSecret.key }} key: {{ .Values.dataStore.sql.readOnly.externalSecret.key }}
{{- else if .Values.dataStore.sql.readOnly.enabled }} {{- else }}
- name: RODBPW - name: RODBPW
valueFrom: valueFrom:
secretKeyRef: secretKeyRef:
@@ -256,6 +257,7 @@ spec:
key: RODBPW key: RODBPW
{{- end }} {{- end }}
{{- end }} {{- end }}
{{- end }}
{{- if ne .Values.keyManager.awsKMS.accessKeyID "" }} {{- if ne .Values.keyManager.awsKMS.accessKeyID "" }}
- name: AWS_KMS_ACCESS_KEY_ID - name: AWS_KMS_ACCESS_KEY_ID
valueFrom: valueFrom:
@@ -12,6 +12,9 @@ metadata:
{{- include "spire-server.labels" . | nindent 4 }} {{- include "spire-server.labels" . | nindent 4 }}
spec: spec:
type: {{ .Values.service.type }} type: {{ .Values.service.type }}
{{- if and (eq .Values.service.type "LoadBalancer") .Values.service.loadBalancerIP }}
loadBalancerIP: {{ .Values.service.loadBalancerIP }}
{{- end }}
ports: ports:
- name: grpc - name: grpc
port: {{ .Values.service.port }} port: {{ .Values.service.port }}
+3 -1
View File
@@ -80,6 +80,8 @@ service:
type: ClusterIP type: ClusterIP
port: 443 port: 443
annotations: {} annotations: {}
## @param service.loadBalancerIP IP address to assign to load balancer (if supported)
loadBalancerIP: ""
configMap: configMap:
## @param configMap.annotations [object] Annotations to add to the SPIRE Server ConfigMap ## @param configMap.annotations [object] Annotations to add to the SPIRE Server ConfigMap
@@ -155,7 +157,7 @@ persistence:
dataStore: dataStore:
sql: sql:
## @param dataStore.sql.databaseType Other supported databases are ["postgres", "mysql", "aws_postgresql", "aws_mysql"]. Note: aws type databases are still experimental ## @param dataStore.sql.databaseType Other supported databases are ["postgres", "mysql", "aws_postgresql", "aws_mysql", "gcp_mysql_sa_iam"]. Note: aws type databases are still experimental. gcp_mysql_sa_iam uses IAM authentication by default.
databaseType: sqlite3 databaseType: sqlite3
## @param dataStore.sql.databaseName Only used when type != "sqlite3" ## @param dataStore.sql.databaseName Only used when type != "sqlite3"
databaseName: spire databaseName: spire
+46
View File
@@ -0,0 +1,46 @@
# Cloud SQL Proxy with GCP IAM Authentication
Use SPIRE Server with Google Cloud SQL using IAM authentication instead of passwords.
## Setup
### 1. Create Infrastructure
**Prerequisites:**
- GKE cluster with Workload Identity enabled
- Terraform configured with GCP provider
Use Terraform to create the database, service account, and Workload Identity:
```bash
# Edit main.tf and replace placeholders:
# - YOUR_PROJECT_ID with your GCP project ID
# - YOUR_REGION with your preferred region (e.g., us-central1)
terraform init
terraform apply
```
**Note:** This creates:
- Service account with Cloud SQL Client and Instance User roles
- Cloud SQL instance with IAM authentication enabled
- Kubernetes service account with Workload Identity annotation
- IAM binding for Workload Identity
### 2. Deploy
Edit `values.yaml` with your project details, then:
```bash
helm upgrade --install -n spire spire spire \
--repo https://spiffe.github.io/helm-charts-hardened/ \
-f values.yaml
```
## How It Works
1. Cloud SQL Proxy runs as an init container with `restartPolicy: Always`
2. Proxy connects to your database using IAM authentication
3. SPIRE connects to `127.0.0.1:3306` through the proxy
4. Uses `gcp_mysql_sa_iam` database type for automatic IAM authentication
5. No passwords needed - everything uses IAM authentication
+71
View File
@@ -0,0 +1,71 @@
# Create service account for SPIRE
resource "google_service_account" "spire" {
account_id = "sa-spire"
display_name = "SPIRE Server Service Account"
project = "YOUR_PROJECT_ID"
}
# Grant Cloud SQL Client role
resource "google_project_iam_member" "cloudsql_client" {
project = "YOUR_PROJECT_ID"
role = "roles/cloudsql.client"
member = "serviceAccount:${google_service_account.spire.email}"
}
# Grant Cloud SQL Instance User role for IAM authentication
resource "google_project_iam_member" "cloudsql_instance_user" {
project = "YOUR_PROJECT_ID"
role = "roles/cloudsql.instanceUser"
member = "serviceAccount:${google_service_account.spire.email}"
}
# Create Cloud SQL database instance
resource "google_sql_database_instance" "instance" {
name = "spire-db"
region = "YOUR_REGION"
database_version = "MYSQL_8_0"
project = "YOUR_PROJECT_ID"
settings {
tier = "db-f1-micro"
database_flags {
name = "cloudsql_iam_authentication"
value = "on"
}
}
deletion_protection = true
}
# Create database
resource "google_sql_database" "database" {
name = "spire"
instance = google_sql_database_instance.instance.name
project = "YOUR_PROJECT_ID"
}
# Create IAM user for the service account
resource "google_sql_user" "iam_service_account_user" {
name = google_service_account.spire.email
instance = google_sql_database_instance.instance.name
type = "CLOUD_IAM_SERVICE_ACCOUNT"
project = "YOUR_PROJECT_ID"
}
# Create Kubernetes service account
resource "kubernetes_service_account" "spire" {
metadata {
name = "sa-spire"
namespace = "spire"
annotations = {
"iam.gke.io/gcp-service-account" = google_service_account.spire.email
}
}
}
# Set up Workload Identity binding
resource "google_service_account_iam_member" "workload_identity_user" {
service_account_id = google_service_account.spire.name
role = "roles/iam.workloadIdentityUser"
member = "serviceAccount:YOUR_PROJECT_ID.svc.id.goog[spire/sa-spire]"
}
+57
View File
@@ -0,0 +1,57 @@
global:
spire:
clusterName: gke_example-cluster_us-central1-a_example-cluster
trustDomain: example.org
caSubject:
country: ARPA
organization: Example
commonName: example.org
spire-server:
serviceAccount:
create: true
annotations:
iam.gke.io/gcp-service-account: "sa-spire@PROJECT_ID.iam.gserviceaccount.com"
name: "sa-spire"
initContainers:
- name: cloud-sql-proxy
image: gcr.io/cloud-sql-connectors/cloud-sql-proxy:2.14.1
restartPolicy: Always
args:
- "--auto-iam-authn"
- "--structured-logs"
- "--port=3306"
- "PROJECT_ID:REGION:INSTANCE_NAME"
env:
- name: GOOGLE_CLOUD_PROJECT
value: "PROJECT_ID"
- name: GOOGLE_CLOUD_REGION
value: "REGION"
securityContext:
runAsNonRoot: true
runAsUser: 65532
runAsGroup: 65532
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
seccompProfile:
type: RuntimeDefault
resources:
requests:
memory: "512Mi"
cpu: "250m"
limits:
memory: "1Gi"
cpu: "500m"
dataStore:
sql:
databaseType: gcp_mysql_sa_iam
databaseName: spire
host: 127.0.0.1
port: 3306
username: "sa-spire"
password: ""
externalSecret:
enabled: false