Allow to configure spire-server CA key type

Resolves #18

Signed-off-by: Marco Franssen <[email protected]>
This commit is contained in:
Marco Franssen
2023-03-07 22:07:54 +01:00
parent eb186ca346
commit 3b7b3564da
3 changed files with 4 additions and 2 deletions
@@ -23,6 +23,7 @@ A Helm chart to install the SPIRE server.
| autoscaling.minReplicas | int | `1` | | | autoscaling.minReplicas | int | `1` | |
| autoscaling.targetCPUUtilizationPercentage | int | `80` | | | autoscaling.targetCPUUtilizationPercentage | int | `80` | |
| bundleConfigMap | string | `"spire-server"` | | | bundleConfigMap | string | `"spire-server"` | |
| caKeyType | string | `"rsa-2048"` | The CA key type to use, possible values are rsa-2048, rsa-4096, ec-p256, ec-p384 (AWS requires the use of RSA. EC cryptography is not supported) |
| caTTL | string | `"24h"` | | | caTTL | string | `"24h"` | |
| ca_subject.common_name | string | `"example.org"` | | | ca_subject.common_name | string | `"example.org"` | |
| ca_subject.country | string | `"NL"` | | | ca_subject.country | string | `"NL"` | |
@@ -15,8 +15,7 @@ data:
jwt_issuer = {{ .Values.jwtIssuer | quote }} jwt_issuer = {{ .Values.jwtIssuer | quote }}
# AWS requires the use of RSA. EC cryptography is not supported ca_key_type = {{ .Values.caKeyType | quote }}
ca_key_type = "rsa-2048"
ca_ttl = {{ .Values.caTTL | quote }} ca_ttl = {{ .Values.caTTL | quote }}
default_x509_svid_ttl = {{ .Values.defaultX509SvidTTL | quote }} default_x509_svid_ttl = {{ .Values.defaultX509SvidTTL | quote }}
@@ -178,6 +178,8 @@ extraContainers: []
initContainers: [] initContainers: []
# -- The CA key type to use, possible values are rsa-2048, rsa-4096, ec-p256, ec-p384 (AWS requires the use of RSA. EC cryptography is not supported)
caKeyType: rsa-2048
caTTL: 24h caTTL: 24h
defaultX509SvidTTL: 4h defaultX509SvidTTL: 4h
defaultJwtSvidTTL: 1h defaultJwtSvidTTL: 1h