Fix spire-server configmap UpstreamAuthority/aws_pca and KeyManager/a… (#489)

Current configmap template renders to a wrong KeyManager and
UpstreamAuthority configurarion when aws_kms and aws_pca are enabled and
container is crashing. The proposed changes will fix the issue.

---------

Signed-off-by: unufree <[email protected]>
Signed-off-by: unufr33 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
This commit is contained in:
unufr33
2023-10-12 15:21:59 -07:00
committed by Faisal Memon
co-authored by Faisal Memon
parent ff0b0683e3
commit 1c98c618b1
2 changed files with 63 additions and 31 deletions
@@ -89,19 +89,19 @@ plugins:
{{- if eq (.enabled | toString) "true" }} {{- if eq (.enabled | toString) "true" }}
{{- $keyManagerUsed = add1 $keyManagerUsed }} {{- $keyManagerUsed = add1 $keyManagerUsed }}
KeyManager: KeyManager:
- aws_kms: aws_kms:
plugin_data: plugin_data:
region: {{ .region | quote }} region: {{ .region | quote }}
key_metadata_file: "/run/spire/data/aws-kms-key-metadata" key_metadata_file: "/run/spire/data/aws-kms-key-metadata"
{{- if ne .accessKeyID "" }} {{- if ne .accessKeyID "" }}
access_key_id: "${AWS_KMS_ACCESS_KEY_ID}" access_key_id: "${AWS_KMS_ACCESS_KEY_ID}"
{{- end }} {{- end }}
{{- if ne .secretAccessKey "" }} {{- if ne .secretAccessKey "" }}
secret_access_key: "${AWS_KMS_SECRET_ACCESS_KEY}" secret_access_key: "${AWS_KMS_SECRET_ACCESS_KEY}"
{{- end }} {{- end }}
{{- if or (ne .keyPolicy.policy "") (ne .keyPolicy.existingConfigMap "") }} {{- if or (ne .keyPolicy.policy "") (ne .keyPolicy.existingConfigMap "") }}
key_policy_file: "/run/spire/data/aws-kms-key-policy.json" key_policy_file: "/run/spire/data/aws-kms-key-policy.json"
{{- end }} {{- end }}
{{- end }} {{- end }}
{{- end }} {{- end }}
@@ -193,23 +193,23 @@ plugins:
{{- if eq (.enabled | toString) "true" }} {{- if eq (.enabled | toString) "true" }}
{{- $upstreamAuthorityUsed = add1 $upstreamAuthorityUsed }} {{- $upstreamAuthorityUsed = add1 $upstreamAuthorityUsed }}
UpstreamAuthority: UpstreamAuthority:
- aws_pca: aws_pca:
plugin_data: plugin_data:
region: {{ .region | quote }} region: {{ .region | quote }}
certificate_authority_arn: {{ .certificateAuthorityARN | quote }} certificate_authority_arn: {{ .certificateAuthorityARN | quote }}
ca_signing_template_arn: {{ .caSigningTemplateARN | default "arn:aws:acm-pca:::template/SubordinateCACertificate_PathLen0/V1" | quote }} ca_signing_template_arn: {{ .caSigningTemplateARN | default "arn:aws:acm-pca:::template/SubordinateCACertificate_PathLen0/V1" | quote }}
{{- if ne .signingAlgorithm "" }} {{- if ne .signingAlgorithm "" }}
signing_algorithm: {{ .signingAlgorithm | quote }} signing_algorithm: {{ .signingAlgorithm | quote }}
{{- end }} {{- end }}
{{- if ne .assumeRoleARN "" }} {{- if ne .assumeRoleARN "" }}
assume_role_arn: {{ .assumeRoleARN | quote }} assume_role_arn: {{ .assumeRoleARN | quote }}
{{- end }} {{- end }}
{{- if ne .endpoint "" }} {{- if ne .endpoint "" }}
endpoint: {{ .endpoint | quote }} endpoint: {{ .endpoint | quote }}
{{- end }} {{- end }}
{{- if ne .supplementalBundlePath "" }} {{- if ne .supplementalBundlePath "" }}
supplemental_bundle_path: {{ .supplementalBundlePath | quote }} supplemental_bundle_path: {{ .supplementalBundlePath | quote }}
{{- end }} {{- end }}
{{- end }} {{- end }}
{{- end }} {{- end }}
{{- if gt $upstreamAuthorityUsed 1 }} {{- if gt $upstreamAuthorityUsed 1 }}
+33 -1
View File
@@ -16,7 +16,7 @@ func ValueStringRender(chart *helmchart.Chart, values string) (map[string]string
return nil, err return nil, err
} }
ro := helmutil.ReleaseOptions{Name: "spire", Namespace: "spire-server", Revision: 1, IsUpgrade: false, IsInstall: true} ro := helmutil.ReleaseOptions{Name: "spire", Namespace: "spire-server", Revision: 1, IsUpgrade: false, IsInstall: true}
v, err = helmutil.ToRenderValues(chart, v, ro, helmutil.DefaultCapabilities); v, err = helmutil.ToRenderValues(chart, v, ro, helmutil.DefaultCapabilities)
if err != nil { if err != nil {
return nil, err return nil, err
} }
@@ -71,4 +71,36 @@ spire-server:
Expect(notes).Should(ContainSubstring("join_token")) Expect(notes).Should(ContainSubstring("join_token"))
}) })
}) })
Describe("spire-server.keyManager.aws_kms", func() {
It("plugin set ok", func() {
objs, err := ValueStringRender(chart, `
spire-server:
keyManager:
awsKMS:
enabled: true
region: us-west-2
plugin_data: {}
disk:
enabled: false
`)
Expect(err).Should(Succeed())
notes := objs["spire/charts/spire-server/templates/configmap.yaml"]
Expect(notes).Should(ContainSubstring("\"aws_kms\": {"))
})
})
Describe("spire-server.UpstreamAuthority.aws_pca", func() {
It("plugin set ok", func() {
objs, err := ValueStringRender(chart, `
spire-server:
upstreamAuthority:
awsPCA:
enabled: true
region: us-west-2
plugin_data: {}
`)
Expect(err).Should(Succeed())
notes := objs["spire/charts/spire-server/templates/configmap.yaml"]
Expect(notes).Should(ContainSubstring("\"aws_pca\": {"))
})
})
}) })