Add by default k8s workload registrar compatible SPIFFEIDs to controller-manager setup
Signed-off-by: Marco Franssen <[email protected]> Signed-off-by: Marco Franssen <[email protected]>
This commit is contained in:
@@ -19,6 +19,11 @@ A Helm chart to install the SPIRE server.
|
|||||||
| ca_subject.organization | string | `"Example"` | |
|
| ca_subject.organization | string | `"Example"` | |
|
||||||
| clusterName | string | `"example-cluster"` | |
|
| clusterName | string | `"example-cluster"` | |
|
||||||
| controllerManager.enabled | bool | `false` | |
|
| controllerManager.enabled | bool | `false` | |
|
||||||
|
| controllerManager.identities.dnsNameTemplates | list | `[]` | |
|
||||||
|
| controllerManager.identities.enabled | bool | `true` | |
|
||||||
|
| controllerManager.identities.podSelector | object | `{}` | |
|
||||||
|
| controllerManager.identities.spiffeIDTemplate | string | `"spiffe://{{ .TrustDomain }}/ns/{{ .PodMeta.Namespace }}/sa/{{ .PodSpec.ServiceAccountName }}"` | |
|
||||||
|
| controllerManager.ignoreNamespaces | list | `[]` | |
|
||||||
| controllerManager.image.pullPolicy | string | `"IfNotPresent"` | |
|
| controllerManager.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
| controllerManager.image.registry | string | `"ghcr.io"` | |
|
| controllerManager.image.registry | string | `"ghcr.io"` | |
|
||||||
| controllerManager.image.repository | string | `"spiffe/spire-controller-manager"` | |
|
| controllerManager.image.repository | string | `"spiffe/spire-controller-manager"` | |
|
||||||
|
|||||||
@@ -0,0 +1,19 @@
|
|||||||
|
{{- $root := . }}
|
||||||
|
{{- with .Values.controllerManager }}
|
||||||
|
{{- if and (eq (.enabled | toString) "true") (eq (.identities.enabled | toString) "true") }}
|
||||||
|
apiVersion: spire.spiffe.io/v1alpha1
|
||||||
|
kind: ClusterSPIFFEID
|
||||||
|
metadata:
|
||||||
|
name: {{ include "spire-controller-manager.fullname" $root }}-service-account-based
|
||||||
|
spec:
|
||||||
|
spiffeIDTemplate: {{ .identities.spiffeIDTemplate | quote }}
|
||||||
|
{{- with .identities.podSelector }}
|
||||||
|
podSelector:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .identities.dnsNameTemplates }}
|
||||||
|
dnsNameTemplates:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -28,5 +28,8 @@ data:
|
|||||||
- kube-public
|
- kube-public
|
||||||
- {{ .Release.Namespace }}
|
- {{ .Release.Namespace }}
|
||||||
- local-path-storage
|
- local-path-storage
|
||||||
|
{{- with .Values.controllerManager.ignoreNamespaces }}
|
||||||
|
{{- toYaml . | nindent 6 }}
|
||||||
|
{{- end }}
|
||||||
spireServerSocketPath: {{ .Values.socketPath | quote }}
|
spireServerSocketPath: {{ .Values.socketPath | quote }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -142,6 +142,18 @@ controllerManager:
|
|||||||
port: 443
|
port: 443
|
||||||
annotations: {}
|
annotations: {}
|
||||||
|
|
||||||
|
ignoreNamespaces: []
|
||||||
|
|
||||||
|
identities:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
spiffeIDTemplate: spiffe://{{ .TrustDomain }}/ns/{{ .PodMeta.Namespace }}/sa/{{ .PodSpec.ServiceAccountName }}
|
||||||
|
podSelector: {}
|
||||||
|
# matchLabels:
|
||||||
|
# spiffe.io/spiffe-id: "true"
|
||||||
|
dnsNameTemplates: []
|
||||||
|
# - '{{ index .PodMeta.Labels "app.kubernetes.io/name" }}.{{ .PodMeta.Namespace }}.svc.cluster.local'
|
||||||
|
|
||||||
k8sWorkloadRegistrar:
|
k8sWorkloadRegistrar:
|
||||||
# -- The `k8s-workload-registrar` is deprecated in favor of the `spire-controller-manager`
|
# -- The `k8s-workload-registrar` is deprecated in favor of the `spire-controller-manager`
|
||||||
# A next release will switch to use the `spire-controller-manager` by default.
|
# A next release will switch to use the `spire-controller-manager` by default.
|
||||||
|
|||||||
Reference in New Issue
Block a user