diff --git a/.github/tests/charts.json b/.github/tests/charts.json
index 2bb93cc..007acf2 100644
--- a/.github/tests/charts.json
+++ b/.github/tests/charts.json
@@ -2,16 +2,16 @@
{
"name": "kube-prometheus-stack",
"repo": "https://prometheus-community.github.io/helm-charts",
- "version": "72.5.0"
+ "version": "75.6.1"
},
{
"name": "cert-manager",
"repo": "https://charts.jetstack.io",
- "version": "v1.17.2"
+ "version": "v1.18.1"
},
{
"name": "ingress-nginx",
"repo": "https://kubernetes.github.io/ingress-nginx",
- "version": "4.12.2"
+ "version": "4.12.3"
}
]
diff --git a/.github/tests/images.json b/.github/tests/images.json
index db8cfe9..2c05c82 100644
--- a/.github/tests/images.json
+++ b/.github/tests/images.json
@@ -11,9 +11,9 @@
"sort-flags": []
},
{
- "query": "tools.bash.image",
- "filter": "LATESTSHA",
- "sort-flags": []
+ "query": "tools.busybox.image",
+ "filter": "^[0-9]\\+\\.[0-9]\\+\\.[0-9]\\+-uclibc$",
+ "sort-flags": ["-t", ".", "-k1,1n", "-k2,2n", "-k3,3n"]
}
],
"spire-agent/values.yaml": [
diff --git a/.github/tests/oci-charts.json b/.github/tests/oci-charts.json
index db33fa0..44307cc 100644
--- a/.github/tests/oci-charts.json
+++ b/.github/tests/oci-charts.json
@@ -2,16 +2,16 @@
{
"name": "mysql",
"registry": "docker.io/bitnamicharts/mysql",
- "version": "13.0.0"
+ "version": "13.0.2"
},
{
"name": "postgresql",
"registry": "docker.io/bitnamicharts/postgresql",
- "version": "16.7.4"
+ "version": "16.7.9"
},
{
"name": "envoy-gateway",
"registry": "docker.io/envoyproxy/gateway-helm",
- "version": "v1.4.0"
+ "version": "v1.4.1"
}
]
diff --git a/charts/spire-nested/Chart.yaml b/charts/spire-nested/Chart.yaml
index ac14087..4653ec0 100644
--- a/charts/spire-nested/Chart.yaml
+++ b/charts/spire-nested/Chart.yaml
@@ -3,8 +3,8 @@ name: spire-nested
description: >
A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.
type: application
-version: 0.25.0
-appVersion: "1.12.2"
+version: 0.26.0
+appVersion: "1.12.4"
keywords: ["spiffe", "spire", "spire-server", "spire-agent", "oidc", "spire-controller-manager"]
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
sources:
diff --git a/charts/spire-nested/README.md b/charts/spire-nested/README.md
index 2dd751e..4685867 100644
--- a/charts/spire-nested/README.md
+++ b/charts/spire-nested/README.md
@@ -1,6 +1,6 @@
# spire
-  
+  
[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.
@@ -350,6 +350,6 @@ Now you can interact with the Spire agent socket from your own application. The
| `external-spire-server.upstreamAuthority.spire.enabled` | Enable upstream SPIRE server | `true` |
| `external-spire-server.upstreamAuthority.spire.upstreamDriver` | Use an upstream driver for authentication | `upstream.csi.spiffe.io` |
| `external-spire-server.upstreamAuthority.spire.server.nameOverride` | The name override setting of the root SPIRE server | `root-server` |
-| `external-spire-server.notifier.k8sBundle.enabled` | Enable local k8s bundle uploader | `false` |
+| `external-spire-server.bundlePublisher.k8sConfigMap.enabled` | Enable local k8s bundle uploader | `false` |
| `external-spire-server.nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s nodeattestor | `false` |
| `external-spire-server.nodeAttestor.joinToken.enabled` | Enable the join_token nodeattestor | `true` |
diff --git a/charts/spire-nested/values.yaml b/charts/spire-nested/values.yaml
index 4465ade..3ef0315 100644
--- a/charts/spire-nested/values.yaml
+++ b/charts/spire-nested/values.yaml
@@ -384,9 +384,9 @@ external-spire-server:
server:
## @param external-spire-server.upstreamAuthority.spire.server.nameOverride The name override setting of the root SPIRE server
nameOverride: root-server
- notifier:
- k8sBundle:
- ## @param external-spire-server.notifier.k8sBundle.enabled Enable local k8s bundle uploader
+ bundlePublisher:
+ k8sConfigMap:
+ ## @param external-spire-server.bundlePublisher.k8sConfigMap.enabled Enable local k8s bundle uploader
enabled: false
nodeAttestor:
k8sPSAT:
diff --git a/charts/spire/Chart.yaml b/charts/spire/Chart.yaml
index b9c3528..8c1cf55 100644
--- a/charts/spire/Chart.yaml
+++ b/charts/spire/Chart.yaml
@@ -3,8 +3,8 @@ name: spire
description: >
A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.
type: application
-version: 0.25.0
-appVersion: "1.12.2"
+version: 0.26.0
+appVersion: "1.12.4"
keywords: ["spiffe", "spire", "spire-server", "spire-agent", "oidc", "spire-controller-manager"]
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
sources:
@@ -55,6 +55,18 @@ dependencies:
condition: tornjak-frontend.enabled
repository: file://./charts/tornjak-frontend
version: 0.1.0
+ - name: spike-keeper
+ condition: spike-keeper.enabled
+ repository: file://./charts/spike-keeper
+ version: 0.1.0
+ - name: spike-nexus
+ condition: spike-nexus.enabled
+ repository: file://./charts/spike-nexus
+ version: 0.1.0
+ - name: spike-pilot
+ condition: spike-pilot.enabled
+ repository: file://./charts/spike-pilot
+ version: 0.1.0
annotations:
artifacthub.io/category: security
artifacthub.io/license: Apache-2.0
diff --git a/charts/spire/README.md b/charts/spire/README.md
index 69d6857..60c27c2 100644
--- a/charts/spire/README.md
+++ b/charts/spire/README.md
@@ -1,6 +1,6 @@
# spire
-  
+  
[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.
@@ -88,6 +88,11 @@ kubectl delete crds clusterfederatedtrustdomains.spire.spiffe.io clusterspiffeid
We only support upgrading one major/minor version at a time. Version skipping isn't supported. Please see for details.
+### 0.26.X
+
+- The notifier.k8sBundle plugin has been deprecated in favor of bundlePublisher.k8sConfigMap. The only features it does not provide are the settings `apiServiceLabel` and `webhookLabel`. If you are using either of these two features, set the chart to use the notifier.k8sBundle plugin again, and let us know. We don't think anyone is using these features.
+- The default trust bundle format has been changed to `spiffe`. This switch should be transparent unless you ware fetching the bundle from the configmap manually, or have a nested setup and dont upgrade the root, then child clusters in short order.
+
### 0.24.X
- You must upgrade [spire-crds](https://artifacthub.io/packages/helm/spiffe/spire-crds) to 0.5.0+ before performing this upgrade.
@@ -373,3 +378,21 @@ Now you can interact with the Spire agent socket from your own application. The
| Name | Description | Value |
| -------------------------- | -------------------------------------------------------------- | ------- |
| `tornjak-frontend.enabled` | Enables deployment of Tornjak frontend/UI (Not for production) | `false` |
+
+### SPIKE Keeper parameters
+
+| Name | Description | Value |
+| ---------------------- | ------------------------------------------------------- | ------- |
+| `spike-keeper.enabled` | Enables deployment of SPIKE Keeper (Not for production) | `false` |
+
+### SPIKE Nexus parameters
+
+| Name | Description | Value |
+| --------------------- | ------------------------------------------------------ | ------- |
+| `spike-nexus.enabled` | Enables deployment of SPIKE Nexus (Not for production) | `false` |
+
+### SPIKE Pilot parameters
+
+| Name | Description | Value |
+| --------------------- | ------------------------------------------------------ | ------- |
+| `spike-pilot.enabled` | Enables deployment of SPIKE Pilot (Not for production) | `false` |
diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml
index 5fa67b0..81cec52 100644
--- a/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml
+++ b/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml
@@ -3,7 +3,7 @@ name: spiffe-oidc-discovery-provider
description: A Helm chart to install the SPIFFE OIDC discovery provider.
type: application
version: 0.1.0
-appVersion: "1.12.2"
+appVersion: "1.12.4"
keywords: ["spiffe", "oidc"]
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
sources:
diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md
index 14d2532..88d9d79 100644
--- a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md
+++ b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md
@@ -29,6 +29,8 @@ A Helm chart to install the SPIFFE OIDC discovery provider.
| ----------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- |
| `agentSocketName` | The name of the spire-agent unix socket | `spire-agent.sock` |
| `csiDriverName` | The csi driver to use | `csi.spiffe.io` |
+| `bundleSource` | Configure where to fetch the trust bundle from. Must be CSI or ConfigMap. | `CSI` |
+| `bundleConfigMap` | ConfigMap name for SPIRE bundle when bundleSource is ConfigMap | `spire-bundle` |
| `replicaCount` | Replica count | `1` |
| `namespaceOverride` | Namespace override | `""` |
| `annotations` | Annotations for the deployment | `{}` |
@@ -71,7 +73,7 @@ A Helm chart to install the SPIFFE OIDC discovery provider.
| `insecureScheme.nginx.image.registry` | The OCI registry to pull the image from. Only used when TLS is disabled. | `docker.io` |
| `insecureScheme.nginx.image.repository` | The repository within the registry. Only used when TLS is disabled. | `nginxinc/nginx-unprivileged` |
| `insecureScheme.nginx.image.pullPolicy` | The image pull policy. Only used when TLS is disabled. | `IfNotPresent` |
-| `insecureScheme.nginx.image.tag` | Overrides the image tag whose default is the chart appVersion. Only used when TLS is disabled. | `1.28.0-alpine` |
+| `insecureScheme.nginx.image.tag` | Overrides the image tag whose default is the chart appVersion. Only used when TLS is disabled. | `1.29.0-alpine` |
| `insecureScheme.nginx.ipMode` | IP modes supported by the cluster. Must be one of [ipv4, ipv6, both] | `both` |
| `insecureScheme.nginx.resources` | Resource requests and limits | `{}` |
| `jwtIssuer` | Path to JWT issuer. Defaults to oidc-discovery.$trustDomain if unset | `""` |
@@ -120,11 +122,11 @@ A Helm chart to install the SPIFFE OIDC discovery provider.
| `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
| `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` |
| `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` |
-| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4` |
+| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea` |
| `tests.toolkit.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
| `tests.toolkit.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` |
| `tests.toolkit.image.pullPolicy` | The image pull policy | `IfNotPresent` |
-| `tests.toolkit.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:3e5ee5ed41e764999f8e499b48d2e62d1f8ffd526aad5b4c3aa7a0759e0139db` |
+| `tests.toolkit.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:3dd03ca4056a6c8024ed1e5dc0999aa836c0c28777dcc3b85bd1d9d853e1ed38` |
| `tests.step.image.registry` | The OCI registry to pull the image from | `docker.io` |
| `tests.step.image.repository` | The repository within the registry | `smallstep/step-cli` |
| `tests.step.image.pullPolicy` | The image pull policy | `IfNotPresent` |
diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/templates/configmap.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/templates/configmap.yaml
index 06a52f3..30e970e 100644
--- a/charts/spire/charts/spiffe-oidc-discovery-provider/templates/configmap.yaml
+++ b/charts/spire/charts/spiffe-oidc-discovery-provider/templates/configmap.yaml
@@ -1,3 +1,6 @@
+{{- if and (ne .Values.bundleSource "ConfigMap") (ne .Values.bundleSource "CSI") }}
+{{- fail "Bundle source must be CSI or ConfigmMap" }}
+{{- end }}
{{- $tlsCount := 0 }}
{{- if and .Values.enabled .Values.tls.spire.enabled }}
{{- $tlsCount = add $tlsCount 1 }}
@@ -44,9 +47,14 @@ serving_cert_file:
jwks_uri: {{ .Values.config.jwksUri | quote }}
{{- end }}
+{{- if eq .Values.bundleSource "ConfigMap" }}
+file:
+ path: /bundle/bundle.spiffe
+{{- else }}
workload_api:
socket_path: {{ include "spiffe-oidc-discovery-provider.workload-api-socket-path" . | quote }}
trust_domain: {{ include "spire-lib.trust-domain" . | quote }}
+{{- end }}
health_checks:
bind_port: "8008"
diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/templates/deployment.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/templates/deployment.yaml
index 8b02c5b..07420bf 100644
--- a/charts/spire/charts/spiffe-oidc-discovery-provider/templates/deployment.yaml
+++ b/charts/spire/charts/spiffe-oidc-discovery-provider/templates/deployment.yaml
@@ -86,9 +86,15 @@ spec:
name: https
{{- end }}
volumeMounts:
+ {{- if eq .Values.bundleSource "ConfigMap" }}
+ - name: spiffe-bundle
+ mountPath: /bundle
+ readOnly: true
+ {{- else }}
- name: spiffe-workload-api
mountPath: {{ include "spiffe-oidc-discovery-provider.workload-api-socket-path" . | dir }}
readOnly: true
+ {{- end }}
- name: spire-oidc-sockets
mountPath: /run/spire/oidc-sockets
readOnly: false
@@ -171,10 +177,17 @@ spec:
{{- end }}
{{- end }}
volumes:
+ {{- if or .Values.tls.spire.enabled (eq .Values.bundleSource "CSI") }}
- name: spiffe-workload-api
csi:
driver: "{{ .Values.csiDriverName }}"
readOnly: true
+ {{- end }}
+ {{- if eq .Values.bundleSource "ConfigMap" }}
+ - name: spiffe-bundle
+ configMap:
+ name: {{ include "spire-lib.bundle-configmap" . }}
+ {{- end }}
- name: spire-oidc-sockets
emptyDir: {}
- name: spire-oidc-config
diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml
index 9c5edcd..43ef469 100644
--- a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml
+++ b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml
@@ -11,6 +11,12 @@ agentSocketName: spire-agent.sock
## @param csiDriverName The csi driver to use
csiDriverName: csi.spiffe.io
+## @param bundleSource Configure where to fetch the trust bundle from. Must be CSI or ConfigMap.
+bundleSource: CSI
+
+## @param bundleConfigMap ConfigMap name for SPIRE bundle when bundleSource is ConfigMap
+bundleConfigMap: spire-bundle
+
## @param replicaCount Replica count
replicaCount: 1
@@ -170,7 +176,7 @@ insecureScheme:
registry: docker.io
repository: nginxinc/nginx-unprivileged
pullPolicy: IfNotPresent
- tag: 1.28.0-alpine
+ tag: 1.29.0-alpine
## @param insecureScheme.nginx.ipMode IP modes supported by the cluster. Must be one of [ipv4, ipv6, both]
ipMode: both
## @param insecureScheme.nginx.resources Resource requests and limits
@@ -340,7 +346,7 @@ tests:
registry: cgr.dev
repository: chainguard/bash
pullPolicy: IfNotPresent
- tag: latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4
+ tag: latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea
toolkit:
## @param tests.toolkit.image.registry The OCI registry to pull the image from
@@ -352,7 +358,7 @@ tests:
registry: cgr.dev
repository: chainguard/min-toolkit-debug
pullPolicy: IfNotPresent
- tag: latest@sha256:3e5ee5ed41e764999f8e499b48d2e62d1f8ffd526aad5b4c3aa7a0759e0139db
+ tag: latest@sha256:3dd03ca4056a6c8024ed1e5dc0999aa836c0c28777dcc3b85bd1d9d853e1ed38
step:
## @param tests.step.image.registry The OCI registry to pull the image from
diff --git a/charts/spire/charts/spike-keeper/Chart.yaml b/charts/spire/charts/spike-keeper/Chart.yaml
new file mode 100644
index 0000000..9cb2683
--- /dev/null
+++ b/charts/spire/charts/spike-keeper/Chart.yaml
@@ -0,0 +1,13 @@
+apiVersion: v2
+name: spike-keeper
+description: A Helm chart to deploy SPIKE Keeper
+type: application
+version: 0.1.0
+appVersion: "0.4.1"
+home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
+sources:
+ - https://github.com/spiffe/spike
+icon: https://spike.ist/assets/spike-banner.png
+maintainers:
+ - name: kfox1111
+ email: Kevin.Fox@pnnl.gov
diff --git a/charts/spire/charts/spike-keeper/README.md b/charts/spire/charts/spike-keeper/README.md
new file mode 100644
index 0000000..2552edf
--- /dev/null
+++ b/charts/spire/charts/spike-keeper/README.md
@@ -0,0 +1,72 @@
+# spike-keeper
+
+  
+[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
+
+A Helm chart to deploy spike keepers
+
+**Homepage:**
+
+## Version support
+
+> [!Note]
+> This Chart is still in development and still subject to change the API (`values.yaml`).
+> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although
+> we do aim for as much stability as possible.
+
+| Dependency | Supported Versions |
+|:-----------|:-------------------|
+| Helm | `3.x` |
+
+## Source Code
+
+*
+
+
+
+## Parameters
+
+### Chart parameters
+
+| Name | Description | Value |
+| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------- |
+| `image.registry` | The OCI registry to pull the image from | `ghcr.io` |
+| `image.repository` | The repository within the registry | `spiffe/spike-keeper` |
+| `image.pullPolicy` | The image pull policy | `IfNotPresent` |
+| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
+| `replicas` | The number of keepers to launch | `3` |
+| `trustRoot.nexus` | Override which trustRoot Nexus is in | `""` |
+| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `debug` |
+| `agentSocketName` | The name of the spire-agent unix socket | `spire-agent.sock` |
+| `csiDriverName` | The csi driver to use | `csi.spiffe.io` |
+| `imagePullSecrets` | Pull secrets for images | `[]` |
+| `nameOverride` | Name override | `""` |
+| `namespaceOverride` | Namespace override | `""` |
+| `fullnameOverride` | Fullname override | `""` |
+| `serviceAccount.create` | Specifies whether a service account should be created | `true` |
+| `serviceAccount.annotations` | Annotations to add to the service account | `{}` |
+| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` |
+| `labels` | Labels for pods | `{}` |
+| `podSecurityContext` | Pod security context | `{}` |
+| `securityContext` | Security context | `{}` |
+| `service.type` | Service type | `ClusterIP` |
+| `service.port` | Service port | `443` |
+| `service.annotations` | Annotations for service resource | `{}` |
+| `nodeSelector` | (Optional) Select specific nodes to run on. | `{}` |
+| `affinity` | Affinity rules | `{}` |
+| `tolerations` | List of tolerations | `[]` |
+| `topologySpreadConstraints` | List of topology spread constraints for resilience | `[]` |
+| `startupProbe.enabled` | Enable startupProbe | `true` |
+| `startupProbe.initialDelaySeconds` | Initial delay seconds for startupProbe | `5` |
+| `startupProbe.periodSeconds` | Period seconds for startupProbe | `10` |
+| `startupProbe.timeoutSeconds` | Timeout seconds for startupProbe | `5` |
+| `startupProbe.failureThreshold` | Failure threshold count for startupProbe | `6` |
+| `startupProbe.successThreshold` | Success threshold count for startupProbe | `1` |
+| `ingress.enabled` | Flag to enable ingress | `false` |
+| `ingress.className` | Ingress class name | `""` |
+| `ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` |
+| `ingress.annotations` | Annotations | `{}` |
+| `ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `keeper` |
+| `ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` |
+| `ingress.hosts` | Host paths for ingress object. If empty, rules will be built based on the host var. | `[]` |
+| `ingress.tls` | Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. | `[]` |
diff --git a/charts/spire/charts/spike-keeper/templates/NOTES.txt b/charts/spire/charts/spike-keeper/templates/NOTES.txt
new file mode 100644
index 0000000..dfe3e24
--- /dev/null
+++ b/charts/spire/charts/spike-keeper/templates/NOTES.txt
@@ -0,0 +1 @@
+Installed {{ .Chart.Name }}…
diff --git a/charts/spire/charts/spike-keeper/templates/_helpers.tpl b/charts/spire/charts/spike-keeper/templates/_helpers.tpl
new file mode 100644
index 0000000..66c9019
--- /dev/null
+++ b/charts/spire/charts/spike-keeper/templates/_helpers.tpl
@@ -0,0 +1,83 @@
+{{/*
+Expand the name of the chart.
+*/}}
+{{- define "spike-keeper.name" -}}
+{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
+{{- end }}
+
+{{/*
+Create a default fully qualified app name.
+We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
+If release name contains chart name it will be used as a full name.
+*/}}
+{{- define "spike-keeper.fullname" -}}
+{{- if .Values.fullnameOverride }}
+{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
+{{- else }}
+{{- $name := default .Chart.Name .Values.nameOverride }}
+{{- if contains $name .Release.Name }}
+{{- .Release.Name | trunc 63 | trimSuffix "-" }}
+{{- else }}
+{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
+{{- end }}
+{{- end }}
+{{- end }}
+
+{{/*
+Allow the release namespace to be overridden for multi-namespace deployments in combined charts
+*/}}
+{{- define "spike-keeper.namespace" -}}
+ {{- if .Values.namespaceOverride -}}
+ {{- .Values.namespaceOverride -}}
+ {{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }}
+ {{- if ne (len (dig "spire" "namespaces" "server" "name" "" .Values.global)) 0 }}
+ {{- .Values.global.spire.namespaces.server.name }}
+ {{- else }}
+ {{- printf "spire-server" }}
+ {{- end }}
+ {{- else -}}
+ {{- .Release.Namespace -}}
+ {{- end -}}
+{{- end -}}
+
+{{/*
+Create chart name and version as used by the chart label.
+*/}}
+{{- define "spike-keeper.chart" -}}
+{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
+{{- end }}
+
+{{/*
+Common labels
+*/}}
+{{- define "spike-keeper.labels" -}}
+helm.sh/chart: {{ include "spike-keeper.chart" . }}
+{{ include "spike-keeper.selectorLabels" . }}
+{{- if .Chart.AppVersion }}
+app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
+{{- end }}
+app.kubernetes.io/managed-by: {{ .Release.Service }}
+{{- end }}
+
+{{/*
+Selector labels
+*/}}
+{{- define "spike-keeper.selectorLabels" -}}
+app.kubernetes.io/name: {{ include "spike-keeper.name" . }}
+app.kubernetes.io/instance: {{ .Release.Name }}
+{{- end }}
+
+{{/*
+Create the name of the service account to use
+*/}}
+{{- define "spike-keeper.serviceAccountName" -}}
+{{- if .Values.serviceAccount.create }}
+{{- default (include "spike-keeper.fullname" .) .Values.serviceAccount.name }}
+{{- else }}
+{{- default "default" .Values.serviceAccount.name }}
+{{- end }}
+{{- end }}
+
+{{- define "spike-keeper.workload-api-socket-path" -}}
+{{- printf "/spiffe-workload-api/%s" .Values.agentSocketName }}
+{{- end }}
diff --git a/charts/spire/charts/spike-keeper/templates/ingress.yaml b/charts/spire/charts/spike-keeper/templates/ingress.yaml
new file mode 100644
index 0000000..af2ff0c
--- /dev/null
+++ b/charts/spire/charts/spike-keeper/templates/ingress.yaml
@@ -0,0 +1,44 @@
+{{- if .Values.ingress.enabled -}}
+{{ $root := . }}
+{{- $ingressControllerType := include "spire-lib.ingress-controller-type" (dict "global" .Values.global "ingress" .Values.ingress) }}
+{{- $fullName := include "spike-keeper.fullname" . -}}
+{{- $tlsSection := true }}
+{{- $annotations := deepCopy .Values.ingress.annotations }}
+{{- if eq $ingressControllerType "ingress-nginx" }}
+{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-redirect" "true" }}
+{{- $_ := set $annotations "nginx.ingress.kubernetes.io/force-ssl-redirect" "true" }}
+{{- $_ := set $annotations "nginx.ingress.kubernetes.io/backend-protocol" "HTTPS" }}
+{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-passthrough" "true" }}
+{{- else if eq $ingressControllerType "openshift" }}
+{{- $path = "" }}
+{{- $_ := set $annotations "route.openshift.io/termination" "passthrough" }}
+{{- $tlsSection = false }}
+{{- end }}
+{{ $last := sub (.Values.replicas | int) 1 | int }}
+{{ range (seq 0 ($last) | toString | split " ") }}
+{{ $i := . }}
+---
+apiVersion: networking.k8s.io/v1
+kind: Ingress
+metadata:
+ name: {{ $fullName }}-{{ $i }}
+ namespace: {{ include "spike-keeper.namespace" $root }}
+ labels:
+ {{ include "spike-keeper.labels" $root | nindent 4}}
+ {{- with $annotations }}
+ annotations:
+ {{- toYaml . | nindent 4 }}
+ {{- end }}
+spec:
+ {{- $host := $root.Values.ingress.host }}
+ {{- if contains "." $host }}
+ {{- $hostParts := regexSplit "[.]" $host 2 }}
+ {{- $host = printf "%s-%s.%s" (index $hostParts 0) $i (index $hostParts 1) }}
+ {{- else }}
+ {{- $host = printf "%s-%s" $host $i }}
+ {{- end }}
+ {{ $ingress := deepCopy $root.Values.ingress }}
+ {{ $_ := set $ingress "host" $host }}
+ {{ include "spire-lib.ingress-spec" (dict "ingress" $ingress "svcName" (printf "%s-%s" $fullName $i) "port" $root.Values.service.port "path" "/" "pathType" "Prefix" "tlsSection" $tlsSection "Values" $root.Values) | nindent 2 }}
+{{- end }}
+{{- end }}
diff --git a/charts/spire/charts/spike-keeper/templates/service.yaml b/charts/spire/charts/spike-keeper/templates/service.yaml
new file mode 100644
index 0000000..1d86355
--- /dev/null
+++ b/charts/spire/charts/spike-keeper/templates/service.yaml
@@ -0,0 +1,48 @@
+{{ $root := . }}
+{{ $last := sub (.Values.replicas | int) 1 | int }}
+{{ range (seq 0 ($last) | toString | split " ") }}
+{{ $i := . }}
+---
+apiVersion: v1
+kind: Service
+metadata:
+ namespace: {{ include "spike-keeper.namespace" $root }}
+ name: {{ include "spike-keeper.fullname" $root }}-{{ $i }}
+ {{- with $root.Values.service.annotations }}
+ annotations:
+ {{- toYaml . | nindent 4 }}
+ {{- end }}
+ labels:
+ apps.kubernetes.io/pod-index: {{ $i | quote }}
+ {{- include "spike-keeper.labels" $root | nindent 4 }}
+spec:
+ type: {{ $root.Values.service.type }}
+ selector:
+ apps.kubernetes.io/pod-index: {{ $i | quote }}
+ {{- include "spike-keeper.selectorLabels" $root | nindent 4 }}
+ ports:
+ - name: {{ include "spike-keeper.fullname" $root }}
+ port: {{ $root.Values.service.port }}
+ targetPort: http
+{{ end }}
+---
+apiVersion: v1
+kind: Service
+metadata:
+ namespace: {{ include "spike-keeper.namespace" $root }}
+ name: {{ include "spike-keeper.fullname" $root }}-headless
+ {{- with $root.Values.service.annotations }}
+ annotations:
+ {{- toYaml . | nindent 4 }}
+ {{- end }}
+ labels:
+ {{- include "spike-keeper.labels" $root | nindent 4 }}
+spec:
+ type: {{ $root.Values.service.type }}
+ clusterIP: None
+ selector:
+ {{- include "spike-keeper.selectorLabels" $root | nindent 4 }}
+ ports:
+ - name: {{ include "spike-keeper.fullname" $root }}
+ port: {{ $root.Values.service.port }}
+ targetPort: http
diff --git a/charts/spire/charts/spike-keeper/templates/serviceaccount.yaml b/charts/spire/charts/spike-keeper/templates/serviceaccount.yaml
new file mode 100644
index 0000000..7f13cb3
--- /dev/null
+++ b/charts/spire/charts/spike-keeper/templates/serviceaccount.yaml
@@ -0,0 +1,13 @@
+{{- if .Values.serviceAccount.create -}}
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ name: {{ include "spike-keeper.serviceAccountName" . }}
+ namespace: {{ include "spike-keeper.namespace" . }}
+ labels:
+ {{- include "spike-keeper.labels" . | nindent 4 }}
+ {{- with .Values.serviceAccount.annotations }}
+ annotations:
+ {{- toYaml . | nindent 4 }}
+ {{- end }}
+{{- end }}
diff --git a/charts/spire/charts/spike-keeper/templates/statefulset.yaml b/charts/spire/charts/spike-keeper/templates/statefulset.yaml
new file mode 100644
index 0000000..baf33f8
--- /dev/null
+++ b/charts/spire/charts/spike-keeper/templates/statefulset.yaml
@@ -0,0 +1,84 @@
+apiVersion: apps/v1
+kind: StatefulSet
+metadata:
+ name: {{ include "spike-keeper.fullname" . }}
+ namespace: {{ include "spike-keeper.namespace" . }}
+ labels:
+ {{- include "spike-keeper.labels" . | nindent 4 }}
+spec:
+ serviceName: {{ include "spike-keeper.fullname" . }}-headless
+ replicas: {{ .Values.replicas }}
+ selector:
+ matchLabels:
+ {{- include "spike-keeper.selectorLabels" . | nindent 6 }}
+ template:
+ metadata:
+ labels:
+ {{- include "spike-keeper.selectorLabels" . | nindent 8 }}
+ release: {{ .Release.Name }}
+ release-namespace: {{ .Release.Namespace }}
+ component: spike-keeper
+ spec:
+ {{- with .Values.imagePullSecrets }}
+ imagePullSecrets:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ serviceAccountName: {{ include "spike-keeper.serviceAccountName" . }}
+ securityContext:
+ {{- include "spire-lib.podsecuritycontext" . | nindent 8 }}
+ containers:
+ - name: {{ include "spike-keeper.fullname" . }}
+ image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image "global" .Values.global "ubi" true) }}
+ imagePullPolicy: {{ .Values.image.pullPolicy }}
+ securityContext:
+ {{- include "spire-lib.securitycontext" . | nindent 12 }}
+ ports:
+ - name: http
+ containerPort: 8443
+ protocol: TCP
+ env:
+ - name: SPIFFE_ENDPOINT_SOCKET
+ value: unix://{{ include "spike-keeper.workload-api-socket-path" . }}
+ - name: SPIKE_SYSTEM_LOG_LEVEL
+ value: {{ .Values.logLevel | upper }}
+ - name: SPIKE_TRUST_ROOT
+ value: {{ include "spire-lib.trust-domain" . }}
+ - name: SPIKE_TRUST_ROOT_NEXUS
+ value: {{if eq .Values.trustRoot.nexus "" }}{{ include "spire-lib.trust-domain" . }}{{ else }}{{.Values.trustRoot.nexus }}{{ end }}
+ - name: SPIKE_KEEPER_TLS_PORT
+ value: ":8443"
+ {{- if .Values.startupProbe.enabled }}
+ startupProbe:
+ tcpSocket:
+ port: 8443
+ failureThreshold: {{ .Values.startupProbe.failureThreshold }}
+ initialDelaySeconds: {{ .Values.startupProbe.initialDelaySeconds }}
+ periodSeconds: {{ .Values.startupProbe.periodSeconds }}
+ successThreshold: {{ .Values.startupProbe.successThreshold }}
+ timeoutSeconds: {{ .Values.startupProbe.timeoutSeconds }}
+ {{- end }}
+ volumeMounts:
+ - name: spiffe-workload-api
+ mountPath: {{ include "spike-keeper.workload-api-socket-path" . | dir }}
+ readOnly: true
+ {{- with .Values.nodeSelector }}
+ nodeSelector:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ {{- with .Values.affinity }}
+ affinity:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ {{- with .Values.tolerations }}
+ tolerations:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ {{- with .Values.topologySpreadConstraints }}
+ topologySpreadConstraints:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ volumes:
+ - name: spiffe-workload-api
+ csi:
+ driver: "{{ .Values.csiDriverName }}"
+ readOnly: true
diff --git a/charts/spire/charts/spike-keeper/values.yaml b/charts/spire/charts/spike-keeper/values.yaml
new file mode 100644
index 0000000..312280d
--- /dev/null
+++ b/charts/spire/charts/spike-keeper/values.yaml
@@ -0,0 +1,139 @@
+# Default configuration for SPIKE Keeper
+# SPDX-License-Identifier: APACHE-2.0
+
+## @skip global
+global: {}
+
+## @section Chart parameters
+##
+## @param image.registry The OCI registry to pull the image from
+## @param image.repository The repository within the registry
+## @param image.pullPolicy The image pull policy
+## @param image.tag Overrides the image tag whose default is the chart appVersion
+##
+image:
+ registry: ghcr.io
+ repository: spiffe/spike-keeper
+ pullPolicy: IfNotPresent
+ tag: ""
+
+## @param replicas The number of keepers to launch
+replicas: 3
+
+trustRoot:
+ ## @param trustRoot.nexus Override which trustRoot Nexus is in
+ nexus: ""
+
+## @param logLevel The log level, valid values are "debug", "info", "warn", and "error"
+logLevel: debug
+
+## @param agentSocketName The name of the spire-agent unix socket
+agentSocketName: spire-agent.sock
+## @param csiDriverName The csi driver to use
+csiDriverName: csi.spiffe.io
+
+## @param imagePullSecrets [array] Pull secrets for images
+imagePullSecrets: []
+
+## @param nameOverride Name override
+nameOverride: ""
+
+## @param namespaceOverride Namespace override
+namespaceOverride: ""
+
+## @param fullnameOverride Fullname override
+fullnameOverride: ""
+
+## @param serviceAccount.create Specifies whether a service account should be created
+## @param serviceAccount.annotations [object] Annotations to add to the service account
+## @param serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated.
+##
+serviceAccount:
+ create: true
+ annotations: {}
+ name: ""
+
+## @param labels [object] Labels for pods
+labels: {}
+
+## @param podSecurityContext [object] Pod security context
+podSecurityContext: {}
+ # fsGroup: 2000
+
+## @param securityContext [object] Security context
+securityContext: {}
+ # capabilities:
+ # drop:
+ # - ALL
+ # readOnlyRootFilesystem: true
+ # runAsNonRoot: true
+ # runAsUser: 1000
+
+## @param service.type Service type
+## @param service.port Service port
+## @param service.annotations Annotations for service resource
+##
+service:
+ type: ClusterIP
+ port: 443
+ annotations: {}
+
+## @param nodeSelector (Optional) Select specific nodes to run on.
+nodeSelector: {}
+
+## @param affinity [object] Affinity rules
+affinity: {}
+
+## @param tolerations [array] List of tolerations
+tolerations: []
+
+## @param topologySpreadConstraints [array] List of topology spread constraints for resilience
+topologySpreadConstraints: []
+
+## Provide minimal resources to prevent accidental crashes due to resource exhaustion
+# resources:
+# requests:
+# cpu: 50m
+# memory: 128Mi
+# limits:
+# cpu: 100m
+# memory: 512Mi
+
+## Configure extra options for startup probe
+## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-startup-probes
+## @param startupProbe.enabled Enable startupProbe
+## @param startupProbe.initialDelaySeconds Initial delay seconds for startupProbe
+## @param startupProbe.periodSeconds Period seconds for startupProbe
+## @param startupProbe.timeoutSeconds Timeout seconds for startupProbe
+## @param startupProbe.failureThreshold Failure threshold count for startupProbe
+## @param startupProbe.successThreshold Success threshold count for startupProbe
+##
+startupProbe:
+ enabled: true
+ initialDelaySeconds: 5
+ periodSeconds: 10
+ timeoutSeconds: 5
+ failureThreshold: 6
+ successThreshold: 1
+
+## @param ingress.enabled Flag to enable ingress
+## @param ingress.className Ingress class name
+## @param ingress.controllerType Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""].
+## @param ingress.annotations [object] Annotations
+ingress:
+ enabled: false
+ className: ""
+ controllerType: ""
+ annotations: {}
+
+ ## @param ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead.
+ host: "keeper"
+
+ ## @param ingress.tlsSecret Secret that has the certs. If blank will use default certs. Used with host var.
+ tlsSecret: ""
+
+ ## @param ingress.hosts [array] Host paths for ingress object. If empty, rules will be built based on the host var.
+ hosts: []
+
+ ## @param ingress.tls [array] Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars.
+ tls: []
diff --git a/charts/spire/charts/spike-nexus/Chart.yaml b/charts/spire/charts/spike-nexus/Chart.yaml
new file mode 100644
index 0000000..c125986
--- /dev/null
+++ b/charts/spire/charts/spike-nexus/Chart.yaml
@@ -0,0 +1,13 @@
+apiVersion: v2
+name: spike-nexus
+description: A Helm chart to deploy SPIKE Nexus
+type: application
+version: 0.1.0
+appVersion: "0.4.1"
+home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
+sources:
+ - https://github.com/spiffe/spike
+icon: https://spike.ist/assets/spike-banner.png
+maintainers:
+ - name: kfox1111
+ email: Kevin.Fox@pnnl.gov
diff --git a/charts/spire/charts/spike-nexus/README.md b/charts/spire/charts/spike-nexus/README.md
new file mode 100644
index 0000000..9d20a00
--- /dev/null
+++ b/charts/spire/charts/spike-nexus/README.md
@@ -0,0 +1,82 @@
+# spike-nexus
+
+  
+[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
+
+A Helm chart to deploy spike nexus
+
+**Homepage:**
+
+## Version support
+
+> [!Note]
+> This Chart is still in development and still subject to change the API (`values.yaml`).
+> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although
+> we do aim for as much stability as possible.
+
+| Dependency | Supported Versions |
+|:-----------|:-------------------|
+| Helm | `3.x` |
+
+## Source Code
+
+*
+
+
+
+## Parameters
+
+### Chart parameters
+
+| Name | Description | Value |
+| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------- |
+| `image.registry` | The OCI registry to pull the image from | `ghcr.io` |
+| `image.repository` | The repository within the registry | `spiffe/spike-nexus` |
+| `image.pullPolicy` | The image pull policy | `IfNotPresent` |
+| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
+| `replicas` | The number of keepers to launch | `1` |
+| `shamir.shares` | How many shares to configure for shamir secrets | `3` |
+| `shamir.threshold` | How many shares needed to recover | `2` |
+| `keeperPeers` | Keeper peer configuration. If blank, it will be autodetected | `[]` |
+| `trustRoot.nexus` | Override which trustRoot Nexus is in | `""` |
+| `trustRoot.keepers` | Override which trustRoot Keepers are in | `[]` |
+| `trustRoot.pilot` | Override which trustRoot Pilot is in | `""` |
+| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `debug` |
+| `agentSocketName` | The name of the spire-agent unix socket | `spire-agent.sock` |
+| `csiDriverName` | The csi driver to use | `csi.spiffe.io` |
+| `imagePullSecrets` | Pull secrets for images | `[]` |
+| `nameOverride` | Name override | `""` |
+| `namespaceOverride` | Namespace override | `""` |
+| `fullnameOverride` | Fullname override | `""` |
+| `serviceAccount.create` | Specifies whether a service account should be created | `true` |
+| `serviceAccount.annotations` | Annotations to add to the service account | `{}` |
+| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` |
+| `labels` | Labels for pods | `{}` |
+| `podSecurityContext` | Pod security context | `{}` |
+| `securityContext` | Security context | `{}` |
+| `service.type` | Service type | `ClusterIP` |
+| `service.port` | Service port | `443` |
+| `service.annotations` | Annotations for service resource | `{}` |
+| `nodeSelector` | (Optional) Select specific nodes to run on. | `{}` |
+| `affinity` | Affinity rules | `{}` |
+| `tolerations` | List of tolerations | `[]` |
+| `topologySpreadConstraints` | List of topology spread constraints for resilience | `[]` |
+| `startupProbe.enabled` | Enable startupProbe | `true` |
+| `startupProbe.initialDelaySeconds` | Initial delay seconds for startupProbe | `5` |
+| `startupProbe.periodSeconds` | Period seconds for startupProbe | `10` |
+| `startupProbe.timeoutSeconds` | Timeout seconds for startupProbe | `5` |
+| `startupProbe.failureThreshold` | Failure threshold count for startupProbe | `6` |
+| `startupProbe.successThreshold` | Success threshold count for startupProbe | `1` |
+| `ingress.enabled` | Flag to enable ingress | `false` |
+| `ingress.className` | Ingress class name | `""` |
+| `ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` |
+| `ingress.annotations` | Annotations | `{}` |
+| `ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `nexus` |
+| `ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` |
+| `ingress.hosts` | Host paths for ingress object. If empty, rules will be built based on the host var. | `[]` |
+| `ingress.tls` | Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. | `[]` |
+| `persistence.type` | What type of volume to use for persistence. Valid options pvc (recommended), hostPath, emptyDir (testing only) | `pvc` |
+| `persistence.size` | What size volume to use for persistence | `1Gi` |
+| `persistence.accessMode` | What access mode to use for persistence. Valid options are ReadWriteOnce (recommended), ReadWriteOncePod, ReadWriteMany (not recommended) | `ReadWriteOnce` |
+| `persistence.storageClass` | What storage class to use for persistence | `nil` |
+| `persistence.hostPath` | Which path to use on the host when persistence.type = hostPath | `""` |
diff --git a/charts/spire/charts/spike-nexus/templates/NOTES.txt b/charts/spire/charts/spike-nexus/templates/NOTES.txt
new file mode 100644
index 0000000..dfe3e24
--- /dev/null
+++ b/charts/spire/charts/spike-nexus/templates/NOTES.txt
@@ -0,0 +1 @@
+Installed {{ .Chart.Name }}…
diff --git a/charts/spire/charts/spike-nexus/templates/_helpers.tpl b/charts/spire/charts/spike-nexus/templates/_helpers.tpl
new file mode 100644
index 0000000..22df59e
--- /dev/null
+++ b/charts/spire/charts/spike-nexus/templates/_helpers.tpl
@@ -0,0 +1,83 @@
+{{/*
+Expand the name of the chart.
+*/}}
+{{- define "spike-nexus.name" -}}
+{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
+{{- end }}
+
+{{/*
+Create a default fully qualified app name.
+We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
+If release name contains chart name it will be used as a full name.
+*/}}
+{{- define "spike-nexus.fullname" -}}
+{{- if .Values.fullnameOverride }}
+{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
+{{- else }}
+{{- $name := default .Chart.Name .Values.nameOverride }}
+{{- if contains $name .Release.Name }}
+{{- .Release.Name | trunc 63 | trimSuffix "-" }}
+{{- else }}
+{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
+{{- end }}
+{{- end }}
+{{- end }}
+
+{{/*
+Allow the release namespace to be overridden for multi-namespace deployments in combined charts
+*/}}
+{{- define "spike-nexus.namespace" -}}
+ {{- if .Values.namespaceOverride -}}
+ {{- .Values.namespaceOverride -}}
+ {{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }}
+ {{- if ne (len (dig "spire" "namespaces" "server" "name" "" .Values.global)) 0 }}
+ {{- .Values.global.spire.namespaces.server.name }}
+ {{- else }}
+ {{- printf "spire-server" }}
+ {{- end }}
+ {{- else -}}
+ {{- .Release.Namespace -}}
+ {{- end -}}
+{{- end -}}
+
+{{/*
+Create chart name and version as used by the chart label.
+*/}}
+{{- define "spike-nexus.chart" -}}
+{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
+{{- end }}
+
+{{/*
+Common labels
+*/}}
+{{- define "spike-nexus.labels" -}}
+helm.sh/chart: {{ include "spike-nexus.chart" . }}
+{{ include "spike-nexus.selectorLabels" . }}
+{{- if .Chart.AppVersion }}
+app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
+{{- end }}
+app.kubernetes.io/managed-by: {{ .Release.Service }}
+{{- end }}
+
+{{/*
+Selector labels
+*/}}
+{{- define "spike-nexus.selectorLabels" -}}
+app.kubernetes.io/name: {{ include "spike-nexus.name" . }}
+app.kubernetes.io/instance: {{ .Release.Name }}
+{{- end }}
+
+{{/*
+Create the name of the service account to use
+*/}}
+{{- define "spike-nexus.serviceAccountName" -}}
+{{- if .Values.serviceAccount.create }}
+{{- default (include "spike-nexus.fullname" .) .Values.serviceAccount.name }}
+{{- else }}
+{{- default "default" .Values.serviceAccount.name }}
+{{- end }}
+{{- end }}
+
+{{- define "spike-nexus.workload-api-socket-path" -}}
+{{- printf "/spiffe-workload-api/%s" .Values.agentSocketName }}
+{{- end }}
diff --git a/charts/spire/charts/spike-nexus/templates/ingress.yaml b/charts/spire/charts/spike-nexus/templates/ingress.yaml
new file mode 100644
index 0000000..82c1b8a
--- /dev/null
+++ b/charts/spire/charts/spike-nexus/templates/ingress.yaml
@@ -0,0 +1,31 @@
+{{- if .Values.ingress.enabled -}}
+{{ $root := . }}
+{{- $ingressControllerType := include "spire-lib.ingress-controller-type" (dict "global" .Values.global "ingress" .Values.ingress) }}
+{{- $fullName := include "spike-nexus.fullname" . -}}
+{{- $tlsSection := true }}
+{{- $annotations := deepCopy .Values.ingress.annotations }}
+{{- if eq $ingressControllerType "ingress-nginx" }}
+{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-redirect" "true" }}
+{{- $_ := set $annotations "nginx.ingress.kubernetes.io/force-ssl-redirect" "true" }}
+{{- $_ := set $annotations "nginx.ingress.kubernetes.io/backend-protocol" "HTTPS" }}
+{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-passthrough" "true" }}
+{{- else if eq $ingressControllerType "openshift" }}
+{{- $path = "" }}
+{{- $_ := set $annotations "route.openshift.io/termination" "passthrough" }}
+{{- $tlsSection = false }}
+{{- end }}
+{{ $last := sub (.Values.replicas | int) 1 | int }}
+apiVersion: networking.k8s.io/v1
+kind: Ingress
+metadata:
+ name: {{ $fullName }}
+ namespace: {{ include "spike-nexus.namespace" $root }}
+ labels:
+ {{ include "spike-nexus.labels" $root | nindent 4}}
+ {{- with $annotations }}
+ annotations:
+ {{- toYaml . | nindent 4 }}
+ {{- end }}
+spec:
+ {{ include "spire-lib.ingress-spec" (dict "ingress" .Values.ingress "svcName" $fullName "port" $root.Values.service.port "path" "/" "pathType" "Prefix" "tlsSection" $tlsSection "Values" $root.Values) | nindent 2 }}
+{{- end }}
diff --git a/charts/spire/charts/spike-nexus/templates/service.yaml b/charts/spire/charts/spike-nexus/templates/service.yaml
new file mode 100644
index 0000000..40d2733
--- /dev/null
+++ b/charts/spire/charts/spike-nexus/templates/service.yaml
@@ -0,0 +1,20 @@
+{{ $root := . }}
+apiVersion: v1
+kind: Service
+metadata:
+ namespace: {{ include "spike-nexus.namespace" $root }}
+ name: {{ include "spike-nexus.fullname" $root }}
+ {{- with $root.Values.service.annotations }}
+ annotations:
+ {{- toYaml . | nindent 4 }}
+ {{- end }}
+ labels:
+ {{- include "spike-nexus.labels" $root | nindent 4 }}
+spec:
+ type: {{ $root.Values.service.type }}
+ selector:
+ {{- include "spike-nexus.selectorLabels" $root | nindent 4 }}
+ ports:
+ - name: {{ include "spike-nexus.fullname" $root }}
+ port: {{ $root.Values.service.port }}
+ targetPort: http
diff --git a/charts/spire/charts/spike-nexus/templates/serviceaccount.yaml b/charts/spire/charts/spike-nexus/templates/serviceaccount.yaml
new file mode 100644
index 0000000..01380df
--- /dev/null
+++ b/charts/spire/charts/spike-nexus/templates/serviceaccount.yaml
@@ -0,0 +1,13 @@
+{{- if .Values.serviceAccount.create -}}
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ name: {{ include "spike-nexus.serviceAccountName" . }}
+ namespace: {{ include "spike-nexus.namespace" . }}
+ labels:
+ {{- include "spike-nexus.labels" . | nindent 4 }}
+ {{- with .Values.serviceAccount.annotations }}
+ annotations:
+ {{- toYaml . | nindent 4 }}
+ {{- end }}
+{{- end }}
diff --git a/charts/spire/charts/spike-nexus/templates/statefulset.yaml b/charts/spire/charts/spike-nexus/templates/statefulset.yaml
new file mode 100644
index 0000000..1dfeb6b
--- /dev/null
+++ b/charts/spire/charts/spike-nexus/templates/statefulset.yaml
@@ -0,0 +1,112 @@
+apiVersion: apps/v1
+kind: StatefulSet
+metadata:
+ name: {{ include "spike-nexus.fullname" . }}
+ namespace: {{ include "spike-nexus.namespace" . }}
+ labels:
+ {{- include "spike-nexus.labels" . | nindent 4 }}
+spec:
+ replicas: {{ .Values.replicas }}
+ selector:
+ matchLabels:
+ {{- include "spike-nexus.selectorLabels" . | nindent 6 }}
+ template:
+ metadata:
+ labels:
+ {{- include "spike-nexus.selectorLabels" . | nindent 8 }}
+ release: {{ .Release.Name }}
+ release-namespace: {{ .Release.Namespace }}
+ component: spike-nexus
+ spec:
+ {{- with .Values.imagePullSecrets }}
+ imagePullSecrets:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ serviceAccountName: {{ include "spike-nexus.serviceAccountName" . }}
+ securityContext:
+ {{- include "spire-lib.podsecuritycontext" . | nindent 8 }}
+ containers:
+ - name: {{ include "spike-nexus.fullname" . }}
+ image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image "global" .Values.global "ubi" true) }}
+ imagePullPolicy: {{ .Values.image.pullPolicy }}
+ securityContext:
+ {{- include "spire-lib.securitycontext" . | nindent 12 }}
+ ports:
+ - name: http
+ containerPort: 8443
+ protocol: TCP
+ env:
+ - name: SPIKE_NEXUS_SHAMIR_SHARES
+ value: {{ .Values.shamir.shares | quote }}
+ - name: SPIKE_NEXUS_SHAMIR_THRESHOLD
+ value: {{ .Values.shamir.threshold | quote }}
+ # Note: IP will depend on the testbed.
+ - name: SPIKE_NEXUS_KEEPER_PEERS
+ {{- if gt (len .Values.keeperPeers) 0 }}
+ value: {{ .Values.keeperPeers | join "," | quote }}
+ {{- else }}
+ value: https://{{ .Release.Name }}-spike-keeper-0.{{ .Release.Name }}-spike-keeper-headless:8443,https://{{ .Release.Name }}-spike-keeper-1.{{ .Release.Name }}-spike-keeper-headless:8443,https://{{ .Release.Name }}-spike-keeper-2.{{ .Release.Name }}-spike-keeper-headless:8443
+ {{- end }}
+ - name: SPIFFE_ENDPOINT_SOCKET
+ value: unix://{{ include "spike-nexus.workload-api-socket-path" . }}
+ - name: SPIKE_SYSTEM_LOG_LEVEL
+ value: {{ .Values.logLevel | upper }}
+ - name: SPIKE_TRUST_ROOT
+ value: {{ include "spire-lib.trust-domain" . }}
+ - name: SPIKE_TRUST_ROOT_KEEPER
+ value: {{ if gt (len .Values.trustRoot.keepers) 0 }}{{ .Values.trustRoot.keepers | join "," | quote}}{{ else }}{{ include "spire-lib.trust-domain" . }}{{ end }}
+ - name: SPIKE_TRUST_ROOT_PILOT
+ value: {{if eq .Values.trustRoot.pilot "" }}{{ include "spire-lib.trust-domain" . }}{{ else }}{{.Values.trustRoot.pilot }}{{ end }}
+ - name: SPIKE_NEXUS_TLS_PORT
+ value: ":8443"
+ {{- if .Values.startupProbe.enabled }}
+ startupProbe:
+ tcpSocket:
+ port: 8443
+ failureThreshold: {{ .Values.startupProbe.failureThreshold }}
+ initialDelaySeconds: {{ .Values.startupProbe.initialDelaySeconds }}
+ periodSeconds: {{ .Values.startupProbe.periodSeconds }}
+ successThreshold: {{ .Values.startupProbe.successThreshold }}
+ timeoutSeconds: {{ .Values.startupProbe.timeoutSeconds }}
+ {{- end }}
+ volumeMounts:
+ - name: spiffe-workload-api
+ mountPath: {{ include "spike-nexus.workload-api-socket-path" . | dir }}
+ readOnly: true
+ - name: nexus-data
+ mountPath: /.spike
+ {{- with .Values.nodeSelector }}
+
+ nodeSelector:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ {{- with .Values.affinity }}
+ affinity:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ {{- with .Values.tolerations }}
+ tolerations:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ {{- with .Values.topologySpreadConstraints }}
+ topologySpreadConstraints:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ volumes:
+ - name: spiffe-workload-api
+ csi:
+ driver: "{{ .Values.csiDriverName }}"
+ readOnly: true
+ volumeClaimTemplates:
+ - metadata:
+ name: nexus-data
+ spec:
+ accessModes:
+ - {{ .Values.persistence.accessMode | default "ReadWriteOnce" }}
+ resources:
+ requests:
+ storage: {{ .Values.persistence.size }}
+ {{- $storageClass := (dig "spire" "persistence" "storageClass" nil .Values.global) | default .Values.persistence.storageClass }}
+ {{- if $storageClass }}
+ storageClassName: {{ $storageClass }}
+ {{- end }}
diff --git a/charts/spire/charts/spike-nexus/values.yaml b/charts/spire/charts/spike-nexus/values.yaml
new file mode 100644
index 0000000..4d51f78
--- /dev/null
+++ b/charts/spire/charts/spike-nexus/values.yaml
@@ -0,0 +1,172 @@
+# Default configuration for SPIKE Keeper
+# SPDX-License-Identifier: APACHE-2.0
+
+## @skip global
+global: {}
+
+## @section Chart parameters
+##
+## @param image.registry The OCI registry to pull the image from
+## @param image.repository The repository within the registry
+## @param image.pullPolicy The image pull policy
+## @param image.tag Overrides the image tag whose default is the chart appVersion
+##
+image:
+ registry: ghcr.io
+ repository: spiffe/spike-nexus
+ pullPolicy: IfNotPresent
+ tag: ""
+
+## @param replicas The number of keepers to launch
+replicas: 1
+
+shamir:
+ ## @param shamir.shares How many shares to configure for shamir secrets
+ shares: 3
+ ## @param shamir.threshold How many shares needed to recover
+ threshold: 2
+
+## @param keeperPeers Keeper peer configuration. If blank, it will be autodetected
+keeperPeers: []
+
+trustRoot:
+ ## @param trustRoot.nexus Override which trustRoot Nexus is in
+ nexus: ""
+ ## @param trustRoot.keepers Override which trustRoot Keepers are in
+ keepers: []
+ ## @param trustRoot.pilot Override which trustRoot Pilot is in
+ pilot: ""
+
+## @param logLevel The log level, valid values are "debug", "info", "warn", and "error"
+logLevel: debug
+
+## @param agentSocketName The name of the spire-agent unix socket
+agentSocketName: spire-agent.sock
+## @param csiDriverName The csi driver to use
+csiDriverName: csi.spiffe.io
+
+## @param imagePullSecrets [array] Pull secrets for images
+imagePullSecrets: []
+
+## @param nameOverride Name override
+nameOverride: ""
+
+## @param namespaceOverride Namespace override
+namespaceOverride: ""
+
+## @param fullnameOverride Fullname override
+fullnameOverride: ""
+
+## @param serviceAccount.create Specifies whether a service account should be created
+## @param serviceAccount.annotations [object] Annotations to add to the service account
+## @param serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated.
+##
+serviceAccount:
+ create: true
+ annotations: {}
+ name: ""
+
+## @param labels [object] Labels for pods
+labels: {}
+
+## @param podSecurityContext [object] Pod security context
+podSecurityContext: {}
+ # fsGroup: 2000
+
+## @param securityContext [object] Security context
+securityContext:
+ # capabilities:
+ # drop:
+ # - ALL
+ # readOnlyRootFilesystem: true
+ runAsNonRoot: true
+ runAsUser: 1000
+
+## @param service.type Service type
+## @param service.port Service port
+## @param service.annotations Annotations for service resource
+##
+service:
+ type: ClusterIP
+ port: 443
+ annotations: {}
+
+## @param nodeSelector (Optional) Select specific nodes to run on.
+nodeSelector: {}
+
+## @param affinity [object] Affinity rules
+affinity: {}
+
+## @param tolerations [array] List of tolerations
+tolerations: []
+
+## @param topologySpreadConstraints [array] List of topology spread constraints for resilience
+topologySpreadConstraints: []
+
+## Provide minimal resources to prevent accidental crashes due to resource exhaustion
+# resources:
+# requests:
+# cpu: 50m
+# memory: 128Mi
+# limits:
+# cpu: 100m
+# memory: 512Mi
+
+## Configure extra options for startup probe
+## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-startup-probes
+## @param startupProbe.enabled Enable startupProbe
+## @param startupProbe.initialDelaySeconds Initial delay seconds for startupProbe
+## @param startupProbe.periodSeconds Period seconds for startupProbe
+## @param startupProbe.timeoutSeconds Timeout seconds for startupProbe
+## @param startupProbe.failureThreshold Failure threshold count for startupProbe
+## @param startupProbe.successThreshold Success threshold count for startupProbe
+##
+startupProbe:
+ enabled: true
+ initialDelaySeconds: 5
+ periodSeconds: 10
+ timeoutSeconds: 5
+ failureThreshold: 6
+ successThreshold: 1
+
+## @param ingress.enabled Flag to enable ingress
+## @param ingress.className Ingress class name
+## @param ingress.controllerType Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""].
+## @param ingress.annotations [object] Annotations
+ingress:
+ enabled: false
+ className: ""
+ controllerType: ""
+ annotations: {}
+
+ ## @param ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead.
+ host: "nexus"
+
+ ## @param ingress.tlsSecret Secret that has the certs. If blank will use default certs. Used with host var.
+ tlsSecret: ""
+
+ ## @param ingress.hosts [array] Host paths for ingress object. If empty, rules will be built based on the host var.
+ hosts: []
+ # - host: nexus.example.org
+ # paths:
+ # - path: /
+ # pathType: Prefix
+
+ ## @param ingress.tls [array] Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars.
+ tls: []
+ # - secretName: chart-example-tls
+ # hosts:
+ # - nexus.example.org
+
+## @param persistence.type What type of volume to use for persistence. Valid options pvc (recommended), hostPath, emptyDir (testing only)
+## @param persistence.size What size volume to use for persistence
+## @param persistence.accessMode What access mode to use for persistence. Valid options are ReadWriteOnce (recommended), ReadWriteOncePod, ReadWriteMany (not recommended)
+## @param persistence.storageClass What storage class to use for persistence
+## @param persistence.hostPath Which path to use on the host when persistence.type = hostPath
+##
+persistence:
+ type: pvc
+ size: 1Gi
+ accessMode: ReadWriteOnce
+ storageClass: null
+ hostPath: ""
diff --git a/charts/spire/charts/spike-pilot/Chart.yaml b/charts/spire/charts/spike-pilot/Chart.yaml
new file mode 100644
index 0000000..34c265a
--- /dev/null
+++ b/charts/spire/charts/spike-pilot/Chart.yaml
@@ -0,0 +1,13 @@
+apiVersion: v2
+name: spike-pilot
+description: A Helm chart to deploy SPIKE Pilot
+type: application
+version: 0.1.0
+appVersion: "0.4.1"
+home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
+sources:
+ - https://github.com/spiffe/spike
+icon: https://spike.ist/assets/spike-banner.png
+maintainers:
+ - name: kfox1111
+ email: Kevin.Fox@pnnl.gov
diff --git a/charts/spire/charts/spike-pilot/README.md b/charts/spire/charts/spike-pilot/README.md
new file mode 100644
index 0000000..0bc3b31
--- /dev/null
+++ b/charts/spire/charts/spike-pilot/README.md
@@ -0,0 +1,63 @@
+# spike-pilot
+
+  
+[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
+
+A Helm chart to deploy spike pilot
+
+**Homepage:**
+
+## Version support
+
+> [!Note]
+> This Chart is still in development and still subject to change the API (`values.yaml`).
+> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although
+> we do aim for as much stability as possible.
+
+| Dependency | Supported Versions |
+|:-----------|:-------------------|
+| Helm | `3.x` |
+
+## Source Code
+
+*
+
+
+
+## Parameters
+
+### Chart parameters
+
+| Name | Description | Value |
+| -------------------------------- | ------------------------------------------------------------------------------------------- | -------------------- |
+| `image.registry` | The OCI registry to pull the image from | `ghcr.io` |
+| `image.repository` | The repository within the registry | `spiffe/spike-pilot` |
+| `image.pullPolicy` | The image pull policy | `IfNotPresent` |
+| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
+| `shell.image.registry` | The OCI registry to pull the image from | `""` |
+| `shell.image.repository` | The repository within the registry | `busybox` |
+| `shell.image.pullPolicy` | The image pull policy | `IfNotPresent` |
+| `shell.image.tag` | Overrides the image tag whose default is the chart appVersion | `1.37.0-uclibc` |
+| `tools.busybox.image.registry` | The OCI registry to pull the image from | `""` |
+| `tools.busybox.image.repository` | The repository within the registry | `busybox` |
+| `tools.busybox.image.pullPolicy` | The image pull policy | `IfNotPresent` |
+| `tools.busybox.image.tag` | Overrides the image tag whose default is the chart appVersion | `1.37.0-uclibc` |
+| `replicas` | The number of keepers to launch | `1` |
+| `trustRoot.nexus` | Override which trustRoot Nexus is in | `""` |
+| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `debug` |
+| `agentSocketName` | The name of the spire-agent unix socket | `spire-agent.sock` |
+| `csiDriverName` | The csi driver to use | `csi.spiffe.io` |
+| `imagePullSecrets` | Pull secrets for images | `[]` |
+| `nameOverride` | Name override | `""` |
+| `namespaceOverride` | Namespace override | `""` |
+| `fullnameOverride` | Fullname override | `""` |
+| `serviceAccount.create` | Specifies whether a service account should be created | `true` |
+| `serviceAccount.annotations` | Annotations to add to the service account | `{}` |
+| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` |
+| `labels` | Labels for pods | `{}` |
+| `podSecurityContext` | Pod security context | `{}` |
+| `securityContext` | Security context | `{}` |
+| `nodeSelector` | (Optional) Select specific nodes to run on. | `{}` |
+| `affinity` | Affinity rules | `{}` |
+| `tolerations` | List of tolerations | `[]` |
+| `topologySpreadConstraints` | List of topology spread constraints for resilience | `[]` |
diff --git a/charts/spire/charts/spike-pilot/templates/NOTES.txt b/charts/spire/charts/spike-pilot/templates/NOTES.txt
new file mode 100644
index 0000000..dfe3e24
--- /dev/null
+++ b/charts/spire/charts/spike-pilot/templates/NOTES.txt
@@ -0,0 +1 @@
+Installed {{ .Chart.Name }}…
diff --git a/charts/spire/charts/spike-pilot/templates/_helpers.tpl b/charts/spire/charts/spike-pilot/templates/_helpers.tpl
new file mode 100644
index 0000000..899776d
--- /dev/null
+++ b/charts/spire/charts/spike-pilot/templates/_helpers.tpl
@@ -0,0 +1,83 @@
+{{/*
+Expand the name of the chart.
+*/}}
+{{- define "spike-pilot.name" -}}
+{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
+{{- end }}
+
+{{/*
+Create a default fully qualified app name.
+We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
+If release name contains chart name it will be used as a full name.
+*/}}
+{{- define "spike-pilot.fullname" -}}
+{{- if .Values.fullnameOverride }}
+{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
+{{- else }}
+{{- $name := default .Chart.Name .Values.nameOverride }}
+{{- if contains $name .Release.Name }}
+{{- .Release.Name | trunc 63 | trimSuffix "-" }}
+{{- else }}
+{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
+{{- end }}
+{{- end }}
+{{- end }}
+
+{{/*
+Allow the release namespace to be overridden for multi-namespace deployments in combined charts
+*/}}
+{{- define "spike-pilot.namespace" -}}
+ {{- if .Values.namespaceOverride -}}
+ {{- .Values.namespaceOverride -}}
+ {{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }}
+ {{- if ne (len (dig "spire" "namespaces" "server" "name" "" .Values.global)) 0 }}
+ {{- .Values.global.spire.namespaces.server.name }}
+ {{- else }}
+ {{- printf "spire-server" }}
+ {{- end }}
+ {{- else -}}
+ {{- .Release.Namespace -}}
+ {{- end -}}
+{{- end -}}
+
+{{/*
+Create chart name and version as used by the chart label.
+*/}}
+{{- define "spike-pilot.chart" -}}
+{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
+{{- end }}
+
+{{/*
+Common labels
+*/}}
+{{- define "spike-pilot.labels" -}}
+helm.sh/chart: {{ include "spike-pilot.chart" . }}
+{{ include "spike-pilot.selectorLabels" . }}
+{{- if .Chart.AppVersion }}
+app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
+{{- end }}
+app.kubernetes.io/managed-by: {{ .Release.Service }}
+{{- end }}
+
+{{/*
+Selector labels
+*/}}
+{{- define "spike-pilot.selectorLabels" -}}
+app.kubernetes.io/name: {{ include "spike-pilot.name" . }}
+app.kubernetes.io/instance: {{ .Release.Name }}
+{{- end }}
+
+{{/*
+Create the name of the service account to use
+*/}}
+{{- define "spike-pilot.serviceAccountName" -}}
+{{- if .Values.serviceAccount.create }}
+{{- default (include "spike-pilot.fullname" .) .Values.serviceAccount.name }}
+{{- else }}
+{{- default "default" .Values.serviceAccount.name }}
+{{- end }}
+{{- end }}
+
+{{- define "spike-pilot.workload-api-socket-path" -}}
+{{- printf "/spiffe-workload-api/%s" .Values.agentSocketName }}
+{{- end }}
diff --git a/charts/spire/charts/spike-pilot/templates/deployment.yaml b/charts/spire/charts/spike-pilot/templates/deployment.yaml
new file mode 100644
index 0000000..0c0958a
--- /dev/null
+++ b/charts/spire/charts/spike-pilot/templates/deployment.yaml
@@ -0,0 +1,96 @@
+apiVersion: apps/v1
+kind: Deployment
+metadata:
+ name: {{ include "spike-pilot.fullname" . }}
+ namespace: {{ include "spike-pilot.namespace" . }}
+ labels:
+ {{- include "spike-pilot.labels" . | nindent 4 }}
+spec:
+ replicas: {{ .Values.replicas }}
+ selector:
+ matchLabels:
+ {{- include "spike-pilot.selectorLabels" . | nindent 6 }}
+ template:
+ metadata:
+ labels:
+ {{- include "spike-pilot.selectorLabels" . | nindent 8 }}
+ release: {{ .Release.Name }}
+ release-namespace: {{ .Release.Namespace }}
+ component: spike-pilot
+ spec:
+ {{- with .Values.imagePullSecrets }}
+ imagePullSecrets:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ serviceAccountName: {{ include "spike-pilot.serviceAccountName" . }}
+ securityContext:
+ {{- include "spire-lib.podsecuritycontext" . | nindent 8 }}
+ initContainers:
+ - name: init
+ image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.tools.busybox.image "global" .Values.global "ubi" true) }}
+ imagePullPolicy: {{ .Values.tools.busybox.image.pullPolicy }}
+ command: ["/bin/sh", "-c", "cp -a /bin/busybox /data"]
+ securityContext:
+ {{- include "spire-lib.securitycontext" . | nindent 12 }}
+ volumeMounts:
+ - name: pilot
+ mountPath: /data
+ - name: init2
+ image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image "global" .Values.global "ubi" true) }}
+ imagePullPolicy: {{ .Values.image.pullPolicy }}
+ command: ["/data/busybox", "sh", "-c", "/data/busybox cp -a /usr/local/bin/spike /data && /data/busybox rm -f /data/busybox"]
+ securityContext:
+ {{- include "spire-lib.securitycontext" . | nindent 12 }}
+ volumeMounts:
+ - name: pilot
+ mountPath: /data
+ containers:
+ - name: {{ include "spike-pilot.fullname" . }}
+ image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.shell.image "global" .Values.global "ubi" true) }}
+ imagePullPolicy: {{ .Values.shell.image.pullPolicy }}
+ command: ["/bin/sh", "-c", "echo I live; while true; do sleep 1000; done"]
+ securityContext:
+ {{- include "spire-lib.securitycontext" . | nindent 12 }}
+ env:
+ #FIXME make this configurable
+ - name: SPIKE_NEXUS_API_URL
+ value: https://{{ .Release.Name }}-spike-nexus:443
+ - name: SPIFFE_ENDPOINT_SOCKET
+ value: unix://{{ include "spike-pilot.workload-api-socket-path" . }}
+ - name: SPIKE_SYSTEM_LOG_LEVEL
+ value: {{ .Values.logLevel | upper }}
+ - name: SPIKE_TRUST_ROOT
+ value: {{ include "spire-lib.trust-domain" . }}
+ - name: SPIKE_TRUST_ROOT_NEXUS
+ value: {{if eq .Values.trustRoot.Nexus "" }}{{ include "spire-lib.trust-domain" . }}{{ else }}{{.Values.trustRoot.Nexus }}{{ end }}
+ volumeMounts:
+ - name: spiffe-workload-api
+ mountPath: {{ include "spike-pilot.workload-api-socket-path" . | dir }}
+ readOnly: true
+ - name: pilot
+ mountPath: /bin/spike
+ subPath: spike
+ readOnly: true
+ {{- with .Values.nodeSelector }}
+ nodeSelector:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ {{- with .Values.affinity }}
+ affinity:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ {{- with .Values.tolerations }}
+ tolerations:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ {{- with .Values.topologySpreadConstraints }}
+ topologySpreadConstraints:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ volumes:
+ - name: pilot
+ emptyDir: {}
+ - name: spiffe-workload-api
+ csi:
+ driver: "{{ .Values.csiDriverName }}"
+ readOnly: true
diff --git a/charts/spire/charts/spike-pilot/templates/serviceaccount.yaml b/charts/spire/charts/spike-pilot/templates/serviceaccount.yaml
new file mode 100644
index 0000000..47daf93
--- /dev/null
+++ b/charts/spire/charts/spike-pilot/templates/serviceaccount.yaml
@@ -0,0 +1,13 @@
+{{- if .Values.serviceAccount.create -}}
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ name: {{ include "spike-pilot.serviceAccountName" . }}
+ namespace: {{ include "spike-pilot.namespace" . }}
+ labels:
+ {{- include "spike-pilot.labels" . | nindent 4 }}
+ {{- with .Values.serviceAccount.annotations }}
+ annotations:
+ {{- toYaml . | nindent 4 }}
+ {{- end }}
+{{- end }}
diff --git a/charts/spire/charts/spike-pilot/values.yaml b/charts/spire/charts/spike-pilot/values.yaml
new file mode 100644
index 0000000..6bf2310
--- /dev/null
+++ b/charts/spire/charts/spike-pilot/values.yaml
@@ -0,0 +1,116 @@
+# Default configuration for SPIKE Keeper
+# SPDX-License-Identifier: APACHE-2.0
+
+## @skip global
+global: {}
+
+## @section Chart parameters
+##
+## @param image.registry The OCI registry to pull the image from
+## @param image.repository The repository within the registry
+## @param image.pullPolicy The image pull policy
+## @param image.tag Overrides the image tag whose default is the chart appVersion
+##
+image:
+ registry: ghcr.io
+ repository: spiffe/spike-pilot
+ pullPolicy: IfNotPresent
+ tag: ""
+
+shell:
+ ## @param shell.image.registry The OCI registry to pull the image from
+ ## @param shell.image.repository The repository within the registry
+ ## @param shell.image.pullPolicy The image pull policy
+ ## @param shell.image.tag Overrides the image tag whose default is the chart appVersion
+ ##
+ image:
+ registry: ""
+ repository: busybox
+ pullPolicy: IfNotPresent
+ tag: 1.37.0-uclibc
+
+tools:
+ busybox:
+ ## @param tools.busybox.image.registry The OCI registry to pull the image from
+ ## @param tools.busybox.image.repository The repository within the registry
+ ## @param tools.busybox.image.pullPolicy The image pull policy
+ ## @param tools.busybox.image.tag Overrides the image tag whose default is the chart appVersion
+ ##
+ image:
+ registry: ""
+ repository: busybox
+ pullPolicy: IfNotPresent
+ tag: 1.37.0-uclibc
+
+## @param replicas The number of keepers to launch
+replicas: 1
+
+trustRoot:
+ ## @param trustRoot.nexus Override which trustRoot Nexus is in
+ nexus: ""
+
+## @param logLevel The log level, valid values are "debug", "info", "warn", and "error"
+logLevel: debug
+
+## @param agentSocketName The name of the spire-agent unix socket
+agentSocketName: spire-agent.sock
+## @param csiDriverName The csi driver to use
+csiDriverName: csi.spiffe.io
+
+## @param imagePullSecrets [array] Pull secrets for images
+imagePullSecrets: []
+
+## @param nameOverride Name override
+nameOverride: ""
+
+## @param namespaceOverride Namespace override
+namespaceOverride: ""
+
+## @param fullnameOverride Fullname override
+fullnameOverride: ""
+
+## @param serviceAccount.create Specifies whether a service account should be created
+## @param serviceAccount.annotations [object] Annotations to add to the service account
+## @param serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated.
+##
+serviceAccount:
+ create: true
+ annotations: {}
+ name: ""
+
+## @param labels [object] Labels for pods
+labels: {}
+
+## @param podSecurityContext [object] Pod security context
+podSecurityContext: {}
+ # fsGroup: 2000
+
+## @param securityContext [object] Security context
+securityContext: {}
+ # capabilities:
+ # drop:
+ # - ALL
+ # readOnlyRootFilesystem: true
+ # runAsNonRoot: true
+ # runAsUser: 1000
+
+## @param nodeSelector (Optional) Select specific nodes to run on.
+nodeSelector: {}
+
+## @param affinity [object] Affinity rules
+affinity: {}
+
+## @param tolerations [array] List of tolerations
+tolerations: []
+
+## @param topologySpreadConstraints [array] List of topology spread constraints for resilience
+topologySpreadConstraints: []
+
+## Provide minimal resources to prevent accidental crashes due to resource exhaustion
+# resources:
+# requests:
+# cpu: 50m
+# memory: 128Mi
+# limits:
+# cpu: 100m
+# memory: 512Mi
diff --git a/charts/spire/charts/spire-agent/Chart.yaml b/charts/spire/charts/spire-agent/Chart.yaml
index 4f121f7..816bb11 100644
--- a/charts/spire/charts/spire-agent/Chart.yaml
+++ b/charts/spire/charts/spire-agent/Chart.yaml
@@ -3,7 +3,7 @@ name: spire-agent
description: A Helm chart to install the SPIRE agent.
type: application
version: 0.1.0
-appVersion: "1.12.2"
+appVersion: "1.12.4"
keywords: ["spiffe", "spire-agent"]
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
sources:
diff --git a/charts/spire/charts/spire-agent/README.md b/charts/spire/charts/spire-agent/README.md
index 7294bc8..43fc74f 100644
--- a/charts/spire/charts/spire-agent/README.md
+++ b/charts/spire/charts/spire-agent/README.md
@@ -52,7 +52,7 @@ A Helm chart to install the SPIRE agent.
| `clusterName` | The name of the Kubernetes cluster (`kubeadm init --service-dns-domain`) | `example-cluster` |
| `trustDomain` | The trust domain to be used for the SPIFFE identifiers | `example.org` |
| `trustBundleURL` | If set, obtain trust bundle from url instead of Kubernetes ConfigMap | `""` |
-| `trustBundleFormat` | If using trustBundleURL, what format is the url. Choices are "pem" and "spiffe" | `pem` |
+| `trustBundleFormat` | If using trustBundleURL, what format is the url. Choices are "pem" and "spiffe" | `spiffe` |
| `trustBundleHostPath` | If set, obtain trust bundle from a file on the host instead of from the ConfigMap | `""` |
| `bundleConfigMap` | Configmap name for Spire bundle | `spire-bundle` |
| `availabilityTarget` | The minimum amount of time desired to gracefully handle SPIRE Server or Agent downtime. This configurable influences how aggressively X509 SVIDs should be rotated. If set, must be at least 24h. | `""` |
@@ -70,7 +70,7 @@ A Helm chart to install the SPIRE agent.
| `fsGroupFix.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
| `fsGroupFix.image.repository` | The repository within the registry | `chainguard/bash` |
| `fsGroupFix.image.pullPolicy` | The image pull policy | `Always` |
-| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4` |
+| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea` |
| `fsGroupFix.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` |
| `keyManager.memory.enabled` | Enable the memory based Key Manager | `true` |
| `nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s Node Attestor | `true` |
@@ -114,12 +114,12 @@ A Helm chart to install the SPIRE agent.
| `socketAlternate.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
| `socketAlternate.image.repository` | The repository within the registry | `chainguard/bash` |
| `socketAlternate.image.pullPolicy` | The image pull policy | `Always` |
-| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4` |
+| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea` |
| `socketAlternate.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` |
| `hostCert.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
| `hostCert.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` |
| `hostCert.image.pullPolicy` | The image pull policy | `IfNotPresent` |
-| `hostCert.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:3e5ee5ed41e764999f8e499b48d2e62d1f8ffd526aad5b4c3aa7a0759e0139db` |
+| `hostCert.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:3dd03ca4056a6c8024ed1e5dc0999aa836c0c28777dcc3b85bd1d9d853e1ed38` |
| `hostCert.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` |
| `priorityClassName` | Priority class assigned to daemonset pods. Can be auto set with global.recommendations.priorityClassName. | `""` |
| `extraEnvVars` | Extra environment variables to be added to the Spire Agent container | `[]` |
diff --git a/charts/spire/charts/spire-agent/templates/configmap.yaml b/charts/spire/charts/spire-agent/templates/configmap.yaml
index 1c62fb8..eb4253a 100644
--- a/charts/spire/charts/spire-agent/templates/configmap.yaml
+++ b/charts/spire/charts/spire-agent/templates/configmap.yaml
@@ -38,13 +38,13 @@ agent:
server_address: {{ include "spire-agent.server-address" . | trim | quote }}
server_port: {{ .Values.server.port | quote }}
socket_path: /tmp/spire-agent/public/{{ include "spire-agent.socket-path" . | base }}
+ trust_bundle_format: {{ .Values.trustBundleFormat | quote }}
{{- if ne (len .Values.trustBundleURL) 0 }}
trust_bundle_url: {{ .Values.trustBundleURL | quote }}
- trust_bundle_format: {{ .Values.trustBundleFormat | quote }}
{{- else if ne (len .Values.trustBundleHostPath) 0 }}
trust_bundle_path: {{ .Values.trustBundleHostPath | quote }}
{{- else }}
- trust_bundle_path: "/run/spire/bundle/bundle.crt"
+ trust_bundle_path: {{ printf "/run/spire/bundle/bundle.%s" (include "spire-lib.trust-bundle-ext" (dict "trustBundleFormat" .Values.trustBundleFormat)) | quote }}
{{- end }}
trust_domain: {{ include "spire-lib.trust-domain" . | quote }}
{{- with .Values.availabilityTarget }}
diff --git a/charts/spire/charts/spire-agent/values.yaml b/charts/spire/charts/spire-agent/values.yaml
index 3e2e164..a7dd78a 100644
--- a/charts/spire/charts/spire-agent/values.yaml
+++ b/charts/spire/charts/spire-agent/values.yaml
@@ -94,7 +94,7 @@ trustDomain: example.org
## @param trustBundleURL If set, obtain trust bundle from url instead of Kubernetes ConfigMap
trustBundleURL: ""
## @param trustBundleFormat If using trustBundleURL, what format is the url. Choices are "pem" and "spiffe"
-trustBundleFormat: pem
+trustBundleFormat: spiffe
## @param trustBundleHostPath If set, obtain trust bundle from a file on the host instead of from the ConfigMap
trustBundleHostPath: ""
## @param bundleConfigMap Configmap name for Spire bundle
@@ -153,7 +153,7 @@ fsGroupFix:
registry: cgr.dev
repository: chainguard/bash
pullPolicy: Always
- tag: latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4
+ tag: latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea
## @param fsGroupFix.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
resources: {}
@@ -280,7 +280,7 @@ socketAlternate:
registry: cgr.dev
repository: chainguard/bash
pullPolicy: Always
- tag: latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4
+ tag: latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea
## @param socketAlternate.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
resources: {}
@@ -295,7 +295,7 @@ hostCert:
registry: cgr.dev
repository: chainguard/min-toolkit-debug
pullPolicy: IfNotPresent
- tag: latest@sha256:3e5ee5ed41e764999f8e499b48d2e62d1f8ffd526aad5b4c3aa7a0759e0139db
+ tag: latest@sha256:3dd03ca4056a6c8024ed1e5dc0999aa836c0c28777dcc3b85bd1d9d853e1ed38
## @param hostCert.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
resources: {}
diff --git a/charts/spire/charts/spire-lib/templates/_helpers.tpl b/charts/spire/charts/spire-lib/templates/_helpers.tpl
index fab4700..7185d77 100644
--- a/charts/spire/charts/spire-lib/templates/_helpers.tpl
+++ b/charts/spire/charts/spire-lib/templates/_helpers.tpl
@@ -336,3 +336,11 @@ Anything lower has an incompatible API.
{{- fail "Unsupported autoscaling API version" }}
{{- end }}
{{- end }}
+
+{{- define "spire-lib.trust-bundle-ext" -}}
+{{- if eq .trustBundleFormat "spiffe" }}
+{{- print "spiffe" }}
+{{- else }}
+{{- print "crt" }}
+{{- end }}
+{{- end }}
diff --git a/charts/spire/charts/spire-server/Chart.yaml b/charts/spire/charts/spire-server/Chart.yaml
index 17672ea..26dc991 100644
--- a/charts/spire/charts/spire-server/Chart.yaml
+++ b/charts/spire/charts/spire-server/Chart.yaml
@@ -3,7 +3,7 @@ name: spire-server
description: A Helm chart to install the SPIRE server.
type: application
version: 0.1.0
-appVersion: "1.12.2"
+appVersion: "1.12.4"
keywords: ["spiffe", "spire-server", "spire-controller-manager"]
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
sources:
diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md
index 298cab5..fc2f6c3 100644
--- a/charts/spire/charts/spire-server/README.md
+++ b/charts/spire/charts/spire-server/README.md
@@ -159,7 +159,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr
| `jwtIssuer` | The JWT issuer domain. Defaults to oidc-discovery.$trustDomain if unset | `""` |
| `clusterName` | Set the name of the Kubernetes cluster. (`kubeadm init --service-dns-domain`) | `example-cluster` |
| `trustDomain` | Set the trust domain to be used for the SPIFFE identifiers | `example.org` |
-| `bundleConfigMap` | Set the trust domain to be used for the SPIFFE identifiers | `spire-bundle` |
+| `bundleConfigMap` | Set the Configmap name for SPIRE bundle | `spire-bundle` |
| `clusterDomain` | This is the value of your clusters `kubeadm init --service-dns-domain` flag | `cluster.local` |
| `federation.enabled` | Flag to enable federation | `false` |
| `federation.bundleEndpoint.port` | Port value for trust bundle federation | `8443` |
@@ -256,11 +256,11 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr
| `upstreamAuthority.vault.k8sAuth.k8sAuthRoleName` | Required - Name of the Vault role. The plugin authenticates against the named role | `""` |
| `upstreamAuthority.vault.k8sAuth.token.audience` | Intended audience of the PSAT, it must match one of the audiences supported by the Kubernetes API server. If no audience is specified, it defaults to the identifier of API Server. See ['Service Account Documentation'](https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/#serviceaccount-token-volume-projection) for more info. | `vault` |
| `upstreamAuthority.vault.k8sAuth.token.expiry` | Expiry time in seconds for the token | `7200` |
-| `notifier.k8sBundle.enabled` | Enable local k8s bundle uploader | `true` |
+| `notifier.k8sBundle.enabled` | Enable local k8s bundle uploader | `false` |
| `notifier.k8sBundle.namespace` | Namespace to push the bundle into, if blank will default to SPIRE Server namespace | `""` |
| `notifier.k8sBundle.apiServiceLabel` | If set, rotate the CA Bundle in API services with this label set to true. | `""` |
| `notifier.k8sBundle.webhookLabel` | If set, rotate the CA Bundle in validating and mutating webhooks with this label set to true. | `""` |
-| `notifier.externalK8sBundle.enabled` | Enable external k8s bundle uploader | `true` |
+| `notifier.externalK8sBundle.enabled` | Enable external k8s bundle uploader | `false` |
| `notifier.externalK8sBundle.defaults.namespace` | Namespace to push the bundle into on clusters | `spire-system` |
| `notifier.externalK8sBundle.defaults.configMap` | ConfigMap name to push the bundle into on external clusters | `spire-bundle-upstream` |
| `notifier.externalK8sBundle.defaults.configMapKey` | ConfigMap key to push the bundle into on external clusters | `bundle.crt` |
@@ -311,6 +311,15 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr
| `controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.dnsNameTemplates` | DNS name template for issued identities | `[]` |
| `controllerManager.identities.clusterSPIFFEIDs.test-keys.enabled` | Enable this identity for controller manager | `true` |
| `controllerManager.identities.clusterSPIFFEIDs.test-keys.type` | The type of rule this is. | `test-keys` |
+| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.enabled` | Enable this identity for controller manager | `true` |
+| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.type` | The type of rule this is. | `spike-keeper` |
+| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/keeper` |
+| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.enabled` | Enable this identity for controller manager | `true` |
+| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.type` | The type of rule this is. | `spike-nexus` |
+| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/nexus` |
+| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.enabled` | Enable this identity for controller manager | `true` |
+| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.type` | The type of rule this is. | `spike-pilot` |
+| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/pilot/role/superuser` |
| `controllerManager.identities.clusterStaticEntries` | Specify ClusterStaticEntry objects. | `{}` |
| `controllerManager.identities.clusterFederatedTrustDomains` | Specify ClusterFederatedTrustDomain objects. | `{}` |
| `controllerManager.validatingWebhookConfiguration.enabled` | Disable only when you have another chart instance on the k8s cluster with webhooks enabled. | `true` |
@@ -387,6 +396,15 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr
| `nodeAttestor.tpmDirect.pluginPath` | The filename in the container of the plugin | `/app/tpm_attestor_server` |
| `nodeAttestor.tpmDirect.cas` | A dictionary of TPM CA PEM or DER files that are allowed to connect. | `{}` |
| `nodeAttestor.tpmDirect.hashes` | A list of TPM hashes that are allowed to connect. | `[]` |
+| `bundlePublisher.k8sConfigMap.enabled` | Enable local k8s bundle uploader | `true` |
+| `bundlePublisher.k8sConfigMap.namespace` | Namespace to push the bundle into, if blank will default to SPIRE Server namespace | `""` |
+| `bundlePublisher.k8sConfigMap.format` | Format of the trust bundle. Can be pem or spiffe | `spiffe` |
+| `bundlePublisher.externalK8sConfigMap.enabled` | Enable external k8s bundle uploader | `true` |
+| `bundlePublisher.externalK8sConfigMap.defaults.namespace` | Namespace to push the bundle into on clusters | `spire-system` |
+| `bundlePublisher.externalK8sConfigMap.defaults.configMapName` | ConfigMap name to push the bundle into on external clusters | `spire-bundle-upstream` |
+| `bundlePublisher.externalK8sConfigMap.defaults.configMapKey` | ConfigMap key to push the bundle into on external clusters | `""` |
+| `bundlePublisher.externalK8sConfigMap.defaults.format` | Format of the trust bundle. Can be pem or spiffe | `spiffe` |
+| `bundlePublisher.externalK8sConfigMap.clusters` | A dictionary of clusters to add with optional overrides. If empty, all clusters defined in kubeConfigs will be used. | `{}` |
| `bundlePublisher.awsRolesAnywhereTrustAnchor.enabled` | Enable the AWS S3 bundle publisher | `false` |
| `bundlePublisher.awsRolesAnywhereTrustAnchor.region` | AWS region to store the trust bundle | `""` |
| `bundlePublisher.awsRolesAnywhereTrustAnchor.trustAnchorID` | AWS trust anchor ID to publish to | `""` |
@@ -410,7 +428,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr
| `tornjak.image.repository` | The repository within the registry | `spiffe/tornjak-backend` |
| `tornjak.image.pullPolicy` | The image pull policy | `IfNotPresent` |
| `tornjak.image.tag` | Overrides the image tag to be whatever you need it to be. It will always be the flag you set without modifications | `""` |
-| `tornjak.image.defaultTag` | Sets the default image to use when image.tag is not set. It will automatically be updated with a ubi- prefix if on OpenShift. | `v1.6.0` |
+| `tornjak.image.defaultTag` | Sets the default image to use when image.tag is not set. It will automatically be updated with a ubi- prefix if on OpenShift. | `v2.1.0` |
| `tornjak.service.type` | Type of service resource | `ClusterIP` |
| `tornjak.service.ports.http` | Insecure port for tornjak service | `10000` |
| `tornjak.service.ports.https` | Secure port for tornjak service | `10443` |
@@ -451,7 +469,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr
| `chown.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
| `chown.image.repository` | The repository within the registry | `chainguard/bash` |
| `chown.image.pullPolicy` | The image pull policy | `Always` |
-| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4` |
+| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea` |
| `chown.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` |
| `experimental.enabled` | Allow configuration of experimental features | `false` |
| `experimental.cacheReloadInterval` | The amount of time between two reloads of the in-memory entry cache. | `5s` |
@@ -464,5 +482,5 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr
| `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
| `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` |
| `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` |
-| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4` |
+| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea` |
| `kubeConfigs` | Manage additional kubeconfig files to talk to external Kubernetes clusters | `{}` |
diff --git a/charts/spire/charts/spire-server/templates/_helpers.tpl b/charts/spire/charts/spire-server/templates/_helpers.tpl
index 49c8e6e..c2c755e 100644
--- a/charts/spire/charts/spire-server/templates/_helpers.tpl
+++ b/charts/spire/charts/spire-server/templates/_helpers.tpl
@@ -65,7 +65,23 @@ Allow the release namespace to be overridden for multi-namespace deployments in
{{- end -}}
{{- end -}}
-{{- define "spire-server.bundle-namespace" -}}
+{{- define "spire-server.bundle-namespace-bundlepublisher" -}}
+ {{- if .Values.bundlePublisher.k8sConfigMap.namespace }}
+ {{- .Values.bundlePublisher.k8sConfigMap.namespace }}
+ {{- else if .Values.namespaceOverride -}}
+ {{- .Values.namespaceOverride -}}
+ {{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }}
+ {{- if ne (len (dig "spire" "namespaces" "system" "name" "" .Values.global)) 0 }}
+ {{- .Values.global.spire.namespaces.system.name }}
+ {{- else }}
+ {{- printf "spire-system" }}
+ {{- end }}
+ {{- else -}}
+ {{- .Release.Namespace -}}
+ {{- end -}}
+{{- end -}}
+
+{{- define "spire-server.bundle-namespace-notifier" -}}
{{- if .Values.notifier.k8sBundle.namespace }}
{{- .Values.notifier.k8sBundle.namespace }}
{{- else if .Values.namespaceOverride -}}
@@ -81,6 +97,14 @@ Allow the release namespace to be overridden for multi-namespace deployments in
{{- end -}}
{{- end -}}
+{{- define "spire-server.bundle-namespace" -}}
+ {{- if .Values.notifier.k8sBundle.namespace }}
+ {{- .Values.notifier.k8sBundle.namespace }}
+ {{- else }}
+ {{- include "spire-server.bundle-namespace-bundlepublisher" . -}}
+ {{- end }}
+{{- end }}
+
{{- define "spire-server.podMonitor.namespace" -}}
{{- if ne (len .Values.telemetry.prometheus.podMonitor.namespace) 0 }}
{{- .Values.telemetry.prometheus.podMonitor.namespace }}
diff --git a/charts/spire/charts/spire-server/templates/bundle-configmap.yaml b/charts/spire/charts/spire-server/templates/bundle-configmap.yaml
index 4217322..505d66b 100644
--- a/charts/spire/charts/spire-server/templates/bundle-configmap.yaml
+++ b/charts/spire/charts/spire-server/templates/bundle-configmap.yaml
@@ -1,3 +1,7 @@
+{{- if and .Values.notifier.k8sBundle.enabled .Values.bundlePublisher.k8sConfigMap.enabled }}
+{{- fail "You can only enable either notifier.k8sBundle or bundlePublisher.k8sConfigMap." }}
+{{- end }}
+{{- if .Values.notifier.k8sBundle.enabled }}
{{- $namespace := include "spire-server.bundle-namespace" . }}
apiVersion: v1
kind: ConfigMap
@@ -8,3 +12,4 @@ metadata:
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
+{{- end }}
diff --git a/charts/spire/charts/spire-server/templates/configmap.yaml b/charts/spire/charts/spire-server/templates/configmap.yaml
index ed30e50..8b0b923 100644
--- a/charts/spire/charts/spire-server/templates/configmap.yaml
+++ b/charts/spire/charts/spire-server/templates/configmap.yaml
@@ -274,7 +274,7 @@ plugins:
k8sbundle:
plugin_data:
{{- if eq (.Values.notifier.k8sBundle.enabled | toString) "true" }}
- namespace: {{ include "spire-server.bundle-namespace" . | quote }}
+ namespace: {{ include "spire-server.bundle-namespace-notifier" . | quote }}
config_map: {{ include "spire-lib.bundle-configmap" . | quote }}
{{- with .Values.notifier.k8sBundle.apiServiceLabel }}
api_service_label: {{ . | quote }}
@@ -304,8 +304,51 @@ plugins:
{{- end }}
{{- end }}
- {{- if or .Values.bundlePublisher.awsRolesAnywhereTrustAnchor.enabled .Values.bundlePublisher.awsS3.enabled .Values.bundlePublisher.gcpCloudStorage.enabled }}
+ {{- $externalK8sConfigMapClusters := default .Values.kubeConfigs .Values.bundlePublisher.externalK8sConfigMap.clusters }}
+ {{- if or .Values.bundlePublisher.awsRolesAnywhereTrustAnchor.enabled .Values.bundlePublisher.awsS3.enabled .Values.bundlePublisher.gcpCloudStorage.enabled .Values.bundlePublisher.k8sConfigMap.enabled (and .Values.bundlePublisher.externalK8sConfigMap.enabled (ne (len $externalK8sConfigMapClusters) 0)) }}
BundlePublisher:
+ {{- if or .Values.bundlePublisher.k8sConfigMap.enabled (and .Values.bundlePublisher.externalK8sConfigMap.enabled (ne (len $externalK8sConfigMapClusters) 0)) }}
+ k8s_configmap:
+ plugin_data:
+ clusters:
+ {{- $prefix := "-" }}
+ {{- if eq (.Values.bundlePublisher.k8sConfigMap.enabled | toString) "true" }}
+ {{ $prefix }} chart-internal:
+ format: {{ .Values.bundlePublisher.k8sConfigMap.format | quote }}
+ namespace: {{ include "spire-server.bundle-namespace-bundlepublisher" . | quote }}
+ configmap_name: {{ include "spire-lib.bundle-configmap" . | quote }}
+ configmap_key: {{ printf "bundle.%s" (include "spire-lib.trust-bundle-ext" (dict "trustBundleFormat" .Values.bundlePublisher.k8sConfigMap.format)) | quote }}
+ {{- $prefix := " " }}
+ {{- end }}
+ {{- if and (eq (.Values.bundlePublisher.externalK8sConfigMap.enabled | toString) "true") (ne (len $externalK8sConfigMapClusters) 0) }}
+ {{- $clusterDefaults := .Values.bundlePublisher.externalK8sConfigMap.defaults }}
+ {{- range $name, $_ := $externalK8sConfigMapClusters }}
+ {{ $prefix }} {{ $name | quote }}:
+ {{- $clusterSettings := dict }}
+ {{- if hasKey $root.Values.bundlePublisher.externalK8sConfigMap.clusters $name }}
+ {{- $clusterSettings = index $root.Values.bundlePublisher.externalK8sConfigMap.clusters $name }}
+ {{- end }}
+ {{- if hasKey $clusterSettings "kubeConfigName" }}
+ kubeconfig_path: /kubeconfigs/{{ $clusterSettings.kubeConfigName }}
+ {{- else }}
+ kubeconfig_path: /kubeconfigs/{{ $name }}
+ {{- end }}
+ {{- $format := $clusterDefaults.format }}
+ {{- if hasKey $clusterSettings "format" }}{{- $format = $clusterSettings.format }}{{- end }}
+ format: {{ $format | quote }}
+ namespace: {{ if hasKey $clusterSettings "namespace" }}{{ $clusterSettings.namespace }}{{ else }}{{ $clusterDefaults.namespace }}{{ end }}
+ configmap_name: {{ if hasKey $clusterSettings "configMapName" }}{{ $clusterSettings.configMapName }}{{ else }}{{ $clusterDefaults.configMapName }}{{ end }}
+ {{- if hasKey $clusterSettings "configMapKey" }}
+ configmap_key: {{ $clusterSettings.configMapKey | quote }}
+ {{- else if ne $clusterDefaults.configMapKey "" }}
+ configmap_key: {{ $clusterDefaults.configMapKey | quote }}
+ {{- else }}
+ configmap_key: {{ printf "bundle.%s" (include "spire-lib.trust-bundle-ext" (dict "trustBundleFormat" $format)) | quote }}
+ {{- end }}
+ {{- $prefix := " " }}
+ {{- end }}
+ {{- end }}
+ {{- end }}
{{- if .Values.bundlePublisher.awsRolesAnywhereTrustAnchor.enabled }}
aws_rolesanywhere_trustanchor:
plugin_data:
diff --git a/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml b/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml
index f16c4de..26027a8 100644
--- a/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml
+++ b/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml
@@ -17,6 +17,21 @@ matchLabels:
release: {{ .Release.Name }}
release-namespace: {{ .Release.Namespace }}
component: oidc-discovery-provider
+{{- else if eq .type "spike-keeper" }}
+matchLabels:
+ release: {{ .Release.Name }}
+ release-namespace: {{ .Release.Namespace }}
+ component: spike-keeper
+{{- else if eq .type "spike-nexus" }}
+matchLabels:
+ release: {{ .Release.Name }}
+ release-namespace: {{ .Release.Namespace }}
+ component: spike-nexus
+{{- else if eq .type "spike-pilot" }}
+matchLabels:
+ release: {{ .Release.Name }}
+ release-namespace: {{ .Release.Namespace }}
+ component: spike-pilot
{{- else if eq .type "test-keys" }}
matchLabels:
release: {{ .Release.Name }}
@@ -38,8 +53,8 @@ matchLabels:
{{- if eq ($root.Values.controllerManager.enabled | toString) "true" }}
{{- if or (not (hasKey $value "enabled")) (eq ($value.enabled | toString) "true") }}
{{- $type := dig "type" "base" $value }}
-{{- if not (has $type (list "base" "raw" "child-servers" "oidc-discovery-provider" "test-keys")) }}
-{{- fail (printf "Type given: %s, must be one of [base, raw, child-servers, oidc-discovery-provider, test-keys]" $type) }}
+{{- if not (has $type (list "base" "raw" "child-servers" "oidc-discovery-provider" "spike-keeper" "spike-nexus" "spike-pilot" "test-keys")) }}
+{{- fail (printf "Type given: %s, must be one of [base, raw, child-servers, oidc-discovery-provider, spike-keeper, spike-nexus, spike-pilot, test-keys]" $type) }}
{{- end }}
{{- $namespaceSelector := deepCopy (dig "namespaceSelector" (dict) $value) }}
{{- if ne $type "raw" }}
diff --git a/charts/spire/charts/spire-server/templates/roles.yaml b/charts/spire/charts/spire-server/templates/roles.yaml
index 197dc02..47ef87b 100644
--- a/charts/spire/charts/spire-server/templates/roles.yaml
+++ b/charts/spire/charts/spire-server/templates/roles.yaml
@@ -1,7 +1,7 @@
{{- $subject := include "spire-server.subject" . }}
{{- $namespace := include "spire-server.namespace" . }}
{{- $bundleNamespace := include "spire-server.bundle-namespace" . }}
-{{- if .Values.notifier.k8sBundle.enabled }}
+{{- if or .Values.notifier.k8sBundle.enabled .Values.bundlePublisher.k8sConfigMap.enabled }}
# Role to be able to push certificate bundles to a configmap
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
@@ -15,6 +15,9 @@ rules:
verbs:
- get
- patch
+{{- if .Values.bundlePublisher.k8sConfigMap.enabled }}
+ - create
+{{- end }}
{{- end }}
{{- if and .Values.upstreamAuthority.certManager.enabled .Values.upstreamAuthority.certManager.rbac.create }}
---
@@ -48,7 +51,7 @@ roleRef:
name: {{ include "spire-server.fullname" . }}-cm
apiGroup: rbac.authorization.k8s.io
{{- end }}
-{{- if .Values.notifier.k8sBundle.enabled }}
+{{- if or .Values.notifier.k8sBundle.enabled .Values.bundlePublisher.k8sConfigMap.enabled }}
---
kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
diff --git a/charts/spire/charts/spire-server/templates/tests/test-tornjak-connection.yaml b/charts/spire/charts/spire-server/templates/tests/test-tornjak-connection.yaml
index c259f12..946a64e 100644
--- a/charts/spire/charts/spire-server/templates/tests/test-tornjak-connection.yaml
+++ b/charts/spire/charts/spire-server/templates/tests/test-tornjak-connection.yaml
@@ -17,13 +17,13 @@ spec:
- name: curl-tornjak-backend
image: {{ template "spire-lib.image" (dict "image" .Values.tests.bash.image "global" .Values.global) }}
command: ['curl']
- args: ['-k', '-s', '-f', 'http://{{ include "spire-tornjak.servicename" . }}.{{ include "spire-server.namespace" . }}.svc.{{ include "spire-lib.cluster-domain" . }}:{{ .Values.tornjak.service.ports.http }}/api/tornjak/serverinfo']
+ args: ['-k', '-s', '-f', 'http://{{ include "spire-tornjak.servicename" . }}.{{ include "spire-server.namespace" . }}.svc.{{ include "spire-lib.cluster-domain" . }}:{{ .Values.tornjak.service.ports.http }}/api/v1/tornjak/serverinfo']
securityContext:
{{- include "spire-lib.securitycontext" . | nindent 8 }}
- name: curl-tornjak-backend-and-spire
image: {{ template "spire-lib.image" (dict "image" .Values.tests.bash.image "global" .Values.global) }}
command: ['curl']
- args: ['-k', '-s', '-f', 'http://{{ include "spire-tornjak.servicename" . }}.{{ include "spire-server.namespace" . }}.svc.{{ include "spire-lib.cluster-domain" . }}:{{ .Values.tornjak.service.ports.http }}/api/healthcheck']
+ args: ['-k', '-s', '-f', 'http://{{ include "spire-tornjak.servicename" . }}.{{ include "spire-server.namespace" . }}.svc.{{ include "spire-lib.cluster-domain" . }}:{{ .Values.tornjak.service.ports.http }}/api/v1/spire/healthcheck']
securityContext:
{{- include "spire-lib.securitycontext" . | nindent 8 }}
restartPolicy: Never
diff --git a/charts/spire/charts/spire-server/templates/tornjak-config.yaml b/charts/spire/charts/spire-server/templates/tornjak-config.yaml
index ec7b2e6..203e8d3 100644
--- a/charts/spire/charts/spire-server/templates/tornjak-config.yaml
+++ b/charts/spire/charts/spire-server/templates/tornjak-config.yaml
@@ -10,25 +10,22 @@ data:
spire_socket_path = "unix:///tmp/spire-server/private/api.sock" # socket to communicate with SPIRE server
{{- if eq (include "spire-tornjak.connectionType" .) "http" }}
http {
- enabled = true # if true, opens HTTP server
port = "10000" # if HTTP enabled, opens HTTP listen port at specified container port
}
{{- end }}
{{- if eq (include "spire-tornjak.connectionType" .) "tls" }}
- tls {
- enabled = true
+ https {
port = "10443" # container port for TLS connection
cert = "/opt/spire/server/tls.crt" # TLS server cert
key = "/opt/spire/server/tls.key" # TLS server key
}
{{- end }}
{{- if eq (include "spire-tornjak.connectionType" .) "mtls" }}
- mtls {
- enabled = true
+ https {
port = "10443" # container port for mTLS connection
cert = "/opt/spire/server/tls.crt" # mTLS server cert
key = "/opt/spire/server/tls.key" # mTLS server key
- ca = "/opt/spire/user/ca.crt" # mTLS user CA
+ client_ca = "/opt/spire/user/ca.crt" # mTLS user CA
}
{{- end }}
}
@@ -43,7 +40,7 @@ data:
}
{{- end }}
{{- if ne .Values.tornjak.config.userManagement.issuer "" }}
- UserManagement "KeycloakAuth" {
+ Authenticator "Keycloak" {
plugin_data {
issuer = "{{ .Values.tornjak.config.userManagement.issuer }}"
audience = "{{ .Values.tornjak.config.userManagement.audience }}"
diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml
index 73b914d..b80d2f5 100644
--- a/charts/spire/charts/spire-server/values.yaml
+++ b/charts/spire/charts/spire-server/values.yaml
@@ -236,7 +236,7 @@ clusterName: example-cluster
## @param trustDomain Set the trust domain to be used for the SPIFFE identifiers
trustDomain: example.org
-## @param bundleConfigMap Set the trust domain to be used for the SPIFFE identifiers
+## @param bundleConfigMap Set the Configmap name for SPIRE bundle
bundleConfigMap: spire-bundle
## @param clusterDomain This is the value of your clusters `kubeadm init --service-dns-domain` flag
@@ -514,7 +514,7 @@ upstreamAuthority:
notifier:
k8sBundle:
## @param notifier.k8sBundle.enabled Enable local k8s bundle uploader
- enabled: true
+ enabled: false
## @param notifier.k8sBundle.namespace Namespace to push the bundle into, if blank will default to SPIRE Server namespace
namespace: ""
## @param notifier.k8sBundle.apiServiceLabel If set, rotate the CA Bundle in API services with this label set to true.
@@ -523,7 +523,7 @@ notifier:
webhookLabel: ""
externalK8sBundle:
## @param notifier.externalK8sBundle.enabled Enable external k8s bundle uploader
- enabled: true
+ enabled: false
defaults:
## @param notifier.externalK8sBundle.defaults.namespace Namespace to push the bundle into on clusters
namespace: "spire-system"
@@ -695,6 +695,28 @@ controllerManager:
## @param controllerManager.identities.clusterSPIFFEIDs.test-keys.type The type of rule this is.
type: test-keys
+ spike-keeper:
+ ## @param controllerManager.identities.clusterSPIFFEIDs.spike-keeper.enabled Enable this identity for controller manager
+ enabled: true
+ ## @param controllerManager.identities.clusterSPIFFEIDs.spike-keeper.type The type of rule this is.
+ type: spike-keeper
+ ## @param controllerManager.identities.clusterSPIFFEIDs.spike-keeper.spiffeIDTemplate The template to use for this rule.
+ spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spike/keeper
+ spike-nexus:
+ ## @param controllerManager.identities.clusterSPIFFEIDs.spike-nexus.enabled Enable this identity for controller manager
+ enabled: true
+ ## @param controllerManager.identities.clusterSPIFFEIDs.spike-nexus.type The type of rule this is.
+ type: spike-nexus
+ ## @param controllerManager.identities.clusterSPIFFEIDs.spike-nexus.spiffeIDTemplate The template to use for this rule.
+ spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spike/nexus
+ spike-pilot:
+ ## @param controllerManager.identities.clusterSPIFFEIDs.spike-pilot.enabled Enable this identity for controller manager
+ enabled: true
+ ## @param controllerManager.identities.clusterSPIFFEIDs.spike-pilot.type The type of rule this is.
+ type: spike-pilot
+ ## @param controllerManager.identities.clusterSPIFFEIDs.spike-pilot.spiffeIDTemplate The template to use for this rule.
+ spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spike/pilot/role/superuser
+
# You can specify additional ClusterSPIFFEIDs following this example:
# foo:
# labels:
@@ -956,6 +978,30 @@ nodeAttestor:
# The secrets needed for this plugin are configured in the secrets: section
bundlePublisher:
+ k8sConfigMap:
+ ## @param bundlePublisher.k8sConfigMap.enabled Enable local k8s bundle uploader
+ enabled: true
+ ## @param bundlePublisher.k8sConfigMap.namespace Namespace to push the bundle into, if blank will default to SPIRE Server namespace
+ namespace: ""
+ ## @param bundlePublisher.k8sConfigMap.format Format of the trust bundle. Can be pem or spiffe
+ format: spiffe
+ externalK8sConfigMap:
+ ## @param bundlePublisher.externalK8sConfigMap.enabled Enable external k8s bundle uploader
+ enabled: true
+ defaults:
+ ## @param bundlePublisher.externalK8sConfigMap.defaults.namespace Namespace to push the bundle into on clusters
+ namespace: "spire-system"
+ ## @param bundlePublisher.externalK8sConfigMap.defaults.configMapName ConfigMap name to push the bundle into on external clusters
+ configMapName: "spire-bundle-upstream"
+ ## @param bundlePublisher.externalK8sConfigMap.defaults.configMapKey ConfigMap key to push the bundle into on external clusters
+ configMapKey: ""
+ ## @param bundlePublisher.externalK8sConfigMap.defaults.format Format of the trust bundle. Can be pem or spiffe
+ format: spiffe
+ ## @param bundlePublisher.externalK8sConfigMap.clusters [object] A dictionary of clusters to add with optional overrides. If empty, all clusters defined in kubeConfigs will be used.
+ clusters: {}
+ # clustera:
+ # namespace: foo
+ # clusterb: {}
awsRolesAnywhereTrustAnchor:
## @param bundlePublisher.awsRolesAnywhereTrustAnchor.enabled Enable the AWS S3 bundle publisher
enabled: false
@@ -1001,7 +1047,7 @@ tornjak:
repository: spiffe/tornjak-backend
pullPolicy: IfNotPresent
tag: ""
- defaultTag: "v1.6.0"
+ defaultTag: "v2.1.0"
service:
## @param tornjak.service.type Type of service resource
@@ -1148,7 +1194,7 @@ chown:
registry: cgr.dev
repository: chainguard/bash
pullPolicy: Always
- tag: latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4
+ tag: latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea
## @param chown.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
resources: {}
@@ -1183,7 +1229,7 @@ tests:
registry: cgr.dev
repository: chainguard/bash
pullPolicy: IfNotPresent
- tag: latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4
+ tag: latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea
## @param kubeConfigs [object] Manage additional kubeconfig files to talk to external Kubernetes clusters
kubeConfigs: {}
diff --git a/charts/spire/charts/tornjak-frontend/Chart.yaml b/charts/spire/charts/tornjak-frontend/Chart.yaml
index 2d67db3..31dbe0e 100644
--- a/charts/spire/charts/tornjak-frontend/Chart.yaml
+++ b/charts/spire/charts/tornjak-frontend/Chart.yaml
@@ -3,7 +3,7 @@ name: tornjak-frontend
description: A Helm chart to deploy Tornjak frontend
type: application
version: 0.1.0
-appVersion: "v1.6.0"
+appVersion: "v2.1.0"
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
sources:
- https://github.com/spiffe/tornjak
diff --git a/charts/spire/charts/tornjak-frontend/README.md b/charts/spire/charts/tornjak-frontend/README.md
index 11b31c3..2dd860c 100644
--- a/charts/spire/charts/tornjak-frontend/README.md
+++ b/charts/spire/charts/tornjak-frontend/README.md
@@ -101,4 +101,4 @@ port forwarding. See the chart NOTES output for more details.
| `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
| `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` |
| `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` |
-| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4` |
+| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea` |
diff --git a/charts/spire/charts/tornjak-frontend/values.yaml b/charts/spire/charts/tornjak-frontend/values.yaml
index a54098f..6719a5e 100644
--- a/charts/spire/charts/tornjak-frontend/values.yaml
+++ b/charts/spire/charts/tornjak-frontend/values.yaml
@@ -162,4 +162,4 @@ tests:
registry: cgr.dev
repository: chainguard/bash
pullPolicy: IfNotPresent
- tag: latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4
+ tag: latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea
diff --git a/charts/spire/values.yaml b/charts/spire/values.yaml
index bb76fee..1cff2cf 100644
--- a/charts/spire/values.yaml
+++ b/charts/spire/values.yaml
@@ -219,3 +219,24 @@ spiffe-oidc-discovery-provider:
tornjak-frontend:
## @param tornjak-frontend.enabled Enables deployment of Tornjak frontend/UI (Not for production)
enabled: false
+
+## @section SPIKE Keeper parameters
+## Parameter values for SPIKE Keeper
+##
+spike-keeper:
+ ## @param spike-keeper.enabled Enables deployment of SPIKE Keeper (Not for production)
+ enabled: false
+
+## @section SPIKE Nexus parameters
+## Parameter values for SPIKE Nexus
+##
+spike-nexus:
+ ## @param spike-nexus.enabled Enables deployment of SPIKE Nexus (Not for production)
+ enabled: false
+
+## @section SPIKE Pilot parameters
+## Parameter values for SPIKE Pilot
+##
+spike-pilot:
+ ## @param spike-pilot.enabled Enables deployment of SPIKE Pilot (Not for production)
+ enabled: false
diff --git a/examples/spike/values.yaml b/examples/spike/values.yaml
new file mode 100644
index 0000000..bda38ae
--- /dev/null
+++ b/examples/spike/values.yaml
@@ -0,0 +1,15 @@
+global:
+ spire:
+ ingressControllerType: ingress-nginx
+spike-keeper:
+ enabled: true
+ #ingress:
+ # enabled: true
+ # className: nginx
+spike-nexus:
+ enabled: true
+ ingress:
+ enabled: true
+ className: nginx
+spike-pilot:
+ enabled: true
diff --git a/examples/static-manifest-server/values.yaml b/examples/static-manifest-server/values.yaml
index 99c1d1c..b005fab 100644
--- a/examples/static-manifest-server/values.yaml
+++ b/examples/static-manifest-server/values.yaml
@@ -17,7 +17,7 @@ spire-server:
selectors:
- tpm:pub_hash:12345
foo-kubelet:
- parentID: spiffe://example.org/foo
+ parentID: spiffe://example.org/hosts/foo
spiffeID: spiffe://example.org/k8s/one/node/foo
selectors:
- systemd:id:kubelet.service
@@ -28,4 +28,8 @@ spire-agent:
spiffe-csi-driver:
enabled: false
spiffe-oidc-discovery-provider:
- enabled: false
+ enabled: true
+ bundleSource: ConfigMap
+ tls:
+ spire:
+ enabled: false
diff --git a/examples/tornjak/README.md b/examples/tornjak/README.md
index 32a74e2..4f3be3f 100644
--- a/examples/tornjak/README.md
+++ b/examples/tornjak/README.md
@@ -29,7 +29,7 @@ helm upgrade --install -n spire-mgmt spire spire \
--render-subchart-notes
# test the Tornjak deployment
-helm test spire -n spire-server
+helm test spire -n spire-mgmt
```
Port forward the Tornjak backend (APIs) and Tornjak frontend (UI) services. Execute these commands in separate consoles.
diff --git a/tests/go.mod b/tests/go.mod
index 9683918..6ff4a11 100644
--- a/tests/go.mod
+++ b/tests/go.mod
@@ -1,13 +1,11 @@
module github.com/spiffe/helm-charts/tests
-go 1.24.0
-
-toolchain go1.24.1
+go 1.24.3
require (
github.com/onsi/ginkgo/v2 v2.23.4
github.com/onsi/gomega v1.37.0
- helm.sh/helm/v3 v3.18.0
+ helm.sh/helm/v3 v3.18.3
)
require (
@@ -48,21 +46,21 @@ require (
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
github.com/xeipuuv/gojsonschema v1.2.0 // indirect
go.uber.org/automaxprocs v1.6.0 // indirect
- golang.org/x/crypto v0.37.0 // indirect
- golang.org/x/net v0.38.0 // indirect
+ golang.org/x/crypto v0.39.0 // indirect
+ golang.org/x/net v0.40.0 // indirect
golang.org/x/oauth2 v0.28.0 // indirect
golang.org/x/sys v0.33.0 // indirect
- golang.org/x/term v0.31.0 // indirect
- golang.org/x/text v0.24.0 // indirect
+ golang.org/x/term v0.32.0 // indirect
+ golang.org/x/text v0.26.0 // indirect
golang.org/x/time v0.9.0 // indirect
- golang.org/x/tools v0.31.0 // indirect
+ golang.org/x/tools v0.33.0 // indirect
google.golang.org/protobuf v1.36.5 // indirect
gopkg.in/inf.v0 v0.9.1 // indirect
gopkg.in/yaml.v3 v3.0.1 // indirect
- k8s.io/api v0.33.0 // indirect
- k8s.io/apiextensions-apiserver v0.33.0 // indirect
- k8s.io/apimachinery v0.33.0 // indirect
- k8s.io/client-go v0.33.0 // indirect
+ k8s.io/api v0.33.1 // indirect
+ k8s.io/apiextensions-apiserver v0.33.1 // indirect
+ k8s.io/apimachinery v0.33.1 // indirect
+ k8s.io/client-go v0.33.1 // indirect
k8s.io/klog/v2 v2.130.1 // indirect
k8s.io/kube-openapi v0.0.0-20250318190949-c8a335a9a2ff // indirect
k8s.io/utils v0.0.0-20241104100929-3ea5e8cea738 // indirect
diff --git a/tests/go.sum b/tests/go.sum
index 33f1b92..c54cbe4 100644
--- a/tests/go.sum
+++ b/tests/go.sum
@@ -123,16 +123,16 @@ go.uber.org/automaxprocs v1.6.0/go.mod h1:ifeIMSnPZuznNm6jmdzmU3/bfk01Fe2fotchwE
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI=
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
-golang.org/x/crypto v0.37.0 h1:kJNSjF/Xp7kU0iB2Z+9viTPMW4EqqsrywMXLJOOsXSE=
-golang.org/x/crypto v0.37.0/go.mod h1:vg+k43peMZ0pUMhYmVAWysMK35e6ioLh3wB8ZCAfbVc=
+golang.org/x/crypto v0.39.0 h1:SHs+kF4LP+f+p14esP5jAoDpHU8Gu/v9lFRK6IT5imM=
+golang.org/x/crypto v0.39.0/go.mod h1:L+Xg3Wf6HoL4Bn4238Z6ft6KfEpN0tJGo53AAPC632U=
golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU=
-golang.org/x/net v0.38.0 h1:vRMAPTMaeGqVhG5QyLJHqNDwecKTomGeqbnfZyKlBI8=
-golang.org/x/net v0.38.0/go.mod h1:ivrbrMbzFq5J41QOQh0siUuly180yBYtLp+CKbEaFx8=
+golang.org/x/net v0.40.0 h1:79Xs7wF06Gbdcg4kdCCIQArK11Z1hr5POQ6+fIYHNuY=
+golang.org/x/net v0.40.0/go.mod h1:y0hY0exeL2Pku80/zKK7tpntoX23cqL3Oa6njdgRtds=
golang.org/x/oauth2 v0.28.0 h1:CrgCKl8PPAVtLnU3c+EDw6x11699EWlsDeWNWKdIOkc=
golang.org/x/oauth2 v0.28.0/go.mod h1:onh5ek6nERTohokkhCD/y2cV4Do3fxFHFuAejCkRWT8=
golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
@@ -143,20 +143,20 @@ golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7w
golang.org/x/sys v0.0.0-20200930185726-fdedc70b468f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.33.0 h1:q3i8TbbEz+JRD9ywIRlyRAQbM0qF7hu24q3teo2hbuw=
golang.org/x/sys v0.33.0/go.mod h1:BJP2sWEmIv4KK5OTEluFJCKSidICx8ciO85XgH3Ak8k=
-golang.org/x/term v0.31.0 h1:erwDkOK1Msy6offm1mOgvspSkslFnIGsFnxOKoufg3o=
-golang.org/x/term v0.31.0/go.mod h1:R4BeIy7D95HzImkxGkTW1UQTtP54tio2RyHz7PwK0aw=
+golang.org/x/term v0.32.0 h1:DR4lr0TjUs3epypdhTOkMmuF5CDFJ/8pOnbzMZPQ7bg=
+golang.org/x/term v0.32.0/go.mod h1:uZG1FhGx848Sqfsq4/DlJr3xGGsYMu/L5GW4abiaEPQ=
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
-golang.org/x/text v0.24.0 h1:dd5Bzh4yt5KYA8f9CJHCP4FB4D51c2c6JvN37xJJkJ0=
-golang.org/x/text v0.24.0/go.mod h1:L8rBsPeo2pSS+xqN0d5u2ikmjtmoJbDBT1b7nHvFCdU=
+golang.org/x/text v0.26.0 h1:P42AVeLghgTYr4+xUnTRKDMqpar+PtX7KWuNQL21L8M=
+golang.org/x/text v0.26.0/go.mod h1:QK15LZJUUQVJxhz7wXgxSy/CJaTFjd0G+YLonydOVQA=
golang.org/x/time v0.9.0 h1:EsRrnYcQiGH+5FfbgvV4AP7qEZstoyrHB0DzarOQ4ZY=
golang.org/x/time v0.9.0/go.mod h1:3BpzKBy/shNhVucY/MWOyx10tF3SFh9QdLuxbVysPQM=
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo=
golang.org/x/tools v0.0.0-20200619180055-7c47624df98f/go.mod h1:EkVYQZoAsY45+roYkvgYkIh4xh/qjgUK9TdY2XT94GE=
golang.org/x/tools v0.0.0-20210106214847-113979e3529a/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA=
-golang.org/x/tools v0.31.0 h1:0EedkvKDbh+qistFTd0Bcwe/YLh4vHwWEkiI0toFIBU=
-golang.org/x/tools v0.31.0/go.mod h1:naFTU+Cev749tSJRXJlna0T3WxKvb1kWEx15xA4SdmQ=
+golang.org/x/tools v0.33.0 h1:4qz2S3zmRxbGIhDIAgjxvFutSvH5EfnsYrRBj0UI0bc=
+golang.org/x/tools v0.33.0/go.mod h1:CIJMaWEY88juyUfo7UbgPqbC8rU2OqfAV1h2Qp0oMYI=
golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
@@ -173,16 +173,16 @@ gopkg.in/inf.v0 v0.9.1/go.mod h1:cWUDdTG/fYaXco+Dcufb5Vnc6Gp2YChqWtbxRZE0mXw=
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
-helm.sh/helm/v3 v3.18.0 h1:ItOAm3Quo0dus3NUHjs+lluqWWEIO7xrSW+zKWCrvlw=
-helm.sh/helm/v3 v3.18.0/go.mod h1:43QHS1W97RcoFJRk36ZBhHdTfykqBlJdsWp3yhzdq8w=
-k8s.io/api v0.33.0 h1:yTgZVn1XEe6opVpP1FylmNrIFWuDqe2H0V8CT5gxfIU=
-k8s.io/api v0.33.0/go.mod h1:CTO61ECK/KU7haa3qq8sarQ0biLq2ju405IZAd9zsiM=
-k8s.io/apiextensions-apiserver v0.33.0 h1:d2qpYL7Mngbsc1taA4IjJPRJ9ilnsXIrndH+r9IimOs=
-k8s.io/apiextensions-apiserver v0.33.0/go.mod h1:VeJ8u9dEEN+tbETo+lFkwaaZPg6uFKLGj5vyNEwwSzc=
-k8s.io/apimachinery v0.33.0 h1:1a6kHrJxb2hs4t8EE5wuR/WxKDwGN1FKH3JvDtA0CIQ=
-k8s.io/apimachinery v0.33.0/go.mod h1:BHW0YOu7n22fFv/JkYOEfkUYNRN0fj0BlvMFWA7b+SM=
-k8s.io/client-go v0.33.0 h1:UASR0sAYVUzs2kYuKn/ZakZlcs2bEHaizrrHUZg0G98=
-k8s.io/client-go v0.33.0/go.mod h1:kGkd+l/gNGg8GYWAPr0xF1rRKvVWvzh9vmZAMXtaKOg=
+helm.sh/helm/v3 v3.18.3 h1:+cvyGKgs7Jt7BN3Klmb4SsG4IkVpA7GAZVGvMz6VO4I=
+helm.sh/helm/v3 v3.18.3/go.mod h1:wUc4n3txYBocM7S9RjTeZBN9T/b5MjffpcSsWEjSIpw=
+k8s.io/api v0.33.1 h1:tA6Cf3bHnLIrUK4IqEgb2v++/GYUtqiu9sRVk3iBXyw=
+k8s.io/api v0.33.1/go.mod h1:87esjTn9DRSRTD4fWMXamiXxJhpOIREjWOSjsW1kEHw=
+k8s.io/apiextensions-apiserver v0.33.1 h1:N7ccbSlRN6I2QBcXevB73PixX2dQNIW0ZRuguEE91zI=
+k8s.io/apiextensions-apiserver v0.33.1/go.mod h1:uNQ52z1A1Gu75QSa+pFK5bcXc4hq7lpOXbweZgi4dqA=
+k8s.io/apimachinery v0.33.1 h1:mzqXWV8tW9Rw4VeW9rEkqvnxj59k1ezDUl20tFK/oM4=
+k8s.io/apimachinery v0.33.1/go.mod h1:BHW0YOu7n22fFv/JkYOEfkUYNRN0fj0BlvMFWA7b+SM=
+k8s.io/client-go v0.33.1 h1:ZZV/Ks2g92cyxWkRRnfUDsnhNn28eFpt26aGc8KbXF4=
+k8s.io/client-go v0.33.1/go.mod h1:JAsUrl1ArO7uRVFWfcj6kOomSlCv+JpvIsp6usAGefA=
k8s.io/klog/v2 v2.130.1 h1:n9Xl7H1Xvksem4KFG4PYbdQCQxqc/tTUyrgXaOhHSzk=
k8s.io/klog/v2 v2.130.1/go.mod h1:3Jpz1GvMt720eyJH1ckRHK1EDfpxISzJ7I9OYgaDtPE=
k8s.io/kube-openapi v0.0.0-20250318190949-c8a335a9a2ff h1:/usPimJzUKKu+m+TE36gUyGcf03XZEP0ZIKgKj35LS4=
diff --git a/tests/integration/spiffe-step-ssh/run-tests.sh b/tests/integration/spiffe-step-ssh/run-tests.sh
index 109792d..772b241 100755
--- a/tests/integration/spiffe-step-ssh/run-tests.sh
+++ b/tests/integration/spiffe-step-ssh/run-tests.sh
@@ -152,7 +152,7 @@ popd
helm upgrade --install spiffe-step-ssh charts/spiffe-step-ssh --set caPassword="$(cat spiffe-step-ssh-password.txt)" -f spiffe-step-ssh-values.yaml -f "${SCRIPTPATH}/ingress-values.yaml" --set trustDomain=production.other --wait --timeout 10m
# Is fetchca responding.
-kubectl get configmap -n spire-system spire-bundle-downstream -o go-template='{{ index .data "bundle.crt" }}' > /tmp/ca.pem
+kubectl exec -it -n spire-server spire-internal-server-0 -- spire-server bundle show > /tmp/ca.pem
cat /tmp/ca.pem
curl https://spiffe-step-ssh-fetchca.production.other -s --cacert /tmp/ca.pem