From ffe439013642723e62a856cccff4a2f442b3e3fe Mon Sep 17 00:00:00 2001 From: Pratik Lotia Date: Fri, 23 May 2025 13:50:07 -0400 Subject: [PATCH 01/16] Nit: Fix typo in param guide (#595) * nit: fix typo in param guide Signed-off-by: pratik-lotia * Update charts/spire/charts/spire-server/values.yaml Co-authored-by: Faisal Memon Signed-off-by: Pratik Lotia * Update docs Signed-off-by: Faisal Memon --------- Signed-off-by: pratik-lotia Signed-off-by: Pratik Lotia Signed-off-by: Faisal Memon Co-authored-by: Faisal Memon --- charts/spire/charts/spire-server/README.md | 2 +- charts/spire/charts/spire-server/values.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index 298cab5..875a585 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -159,7 +159,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `jwtIssuer` | The JWT issuer domain. Defaults to oidc-discovery.$trustDomain if unset | `""` | | `clusterName` | Set the name of the Kubernetes cluster. (`kubeadm init --service-dns-domain`) | `example-cluster` | | `trustDomain` | Set the trust domain to be used for the SPIFFE identifiers | `example.org` | -| `bundleConfigMap` | Set the trust domain to be used for the SPIFFE identifiers | `spire-bundle` | +| `bundleConfigMap` | Set the Configmap name for SPIRE bundle | `spire-bundle` | | `clusterDomain` | This is the value of your clusters `kubeadm init --service-dns-domain` flag | `cluster.local` | | `federation.enabled` | Flag to enable federation | `false` | | `federation.bundleEndpoint.port` | Port value for trust bundle federation | `8443` | diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index 73b914d..c00581f 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -236,7 +236,7 @@ clusterName: example-cluster ## @param trustDomain Set the trust domain to be used for the SPIFFE identifiers trustDomain: example.org -## @param bundleConfigMap Set the trust domain to be used for the SPIFFE identifiers +## @param bundleConfigMap Set the Configmap name for SPIRE bundle bundleConfigMap: spire-bundle ## @param clusterDomain This is the value of your clusters `kubeadm init --service-dns-domain` flag From c8bb71bef7a09cb069f53ed7bbf89382b5ef0791 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 28 May 2025 21:49:29 -0700 Subject: [PATCH 02/16] Bump helm.sh/helm/v3 from 3.18.0 to 3.18.1 in /tests (#599) Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.18.0 to 3.18.1. - [Release notes](https://github.com/helm/helm/releases) - [Commits](https://github.com/helm/helm/compare/v3.18.0...v3.18.1) --- updated-dependencies: - dependency-name: helm.sh/helm/v3 dependency-version: 3.18.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- tests/go.mod | 2 +- tests/go.sum | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/tests/go.mod b/tests/go.mod index 9683918..1ed7d9a 100644 --- a/tests/go.mod +++ b/tests/go.mod @@ -7,7 +7,7 @@ toolchain go1.24.1 require ( github.com/onsi/ginkgo/v2 v2.23.4 github.com/onsi/gomega v1.37.0 - helm.sh/helm/v3 v3.18.0 + helm.sh/helm/v3 v3.18.1 ) require ( diff --git a/tests/go.sum b/tests/go.sum index 33f1b92..b403d25 100644 --- a/tests/go.sum +++ b/tests/go.sum @@ -173,8 +173,8 @@ gopkg.in/inf.v0 v0.9.1/go.mod h1:cWUDdTG/fYaXco+Dcufb5Vnc6Gp2YChqWtbxRZE0mXw= gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= -helm.sh/helm/v3 v3.18.0 h1:ItOAm3Quo0dus3NUHjs+lluqWWEIO7xrSW+zKWCrvlw= -helm.sh/helm/v3 v3.18.0/go.mod h1:43QHS1W97RcoFJRk36ZBhHdTfykqBlJdsWp3yhzdq8w= +helm.sh/helm/v3 v3.18.1 h1:qLhXmtqXOHQb0Xv9HJolOLlah8RWbgyzt50xrtTWAlg= +helm.sh/helm/v3 v3.18.1/go.mod h1:43QHS1W97RcoFJRk36ZBhHdTfykqBlJdsWp3yhzdq8w= k8s.io/api v0.33.0 h1:yTgZVn1XEe6opVpP1FylmNrIFWuDqe2H0V8CT5gxfIU= k8s.io/api v0.33.0/go.mod h1:CTO61ECK/KU7haa3qq8sarQ0biLq2ju405IZAd9zsiM= k8s.io/apiextensions-apiserver v0.33.0 h1:d2qpYL7Mngbsc1taA4IjJPRJ9ilnsXIrndH+r9IimOs= From ce9b3737ff714f061592d8455f1ecec294631373 Mon Sep 17 00:00:00 2001 From: Faisal Memon Date: Thu, 29 May 2025 08:15:34 -0700 Subject: [PATCH 03/16] Update tests to go 1.24.3 (#600) Signed-off-by: Faisal Memon --- tests/go.mod | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/tests/go.mod b/tests/go.mod index 1ed7d9a..d0a874d 100644 --- a/tests/go.mod +++ b/tests/go.mod @@ -1,8 +1,6 @@ module github.com/spiffe/helm-charts/tests -go 1.24.0 - -toolchain go1.24.1 +go 1.24.3 require ( github.com/onsi/ginkgo/v2 v2.23.4 From 858eb2e4f672ad4aea5343a8815643d89847d652 Mon Sep 17 00:00:00 2001 From: kfox1111 Date: Mon, 2 Jun 2025 12:21:09 -0700 Subject: [PATCH 04/16] Fix update pattern (#603) Signed-off-by: Kevin Fox --- .github/tests/images.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/tests/images.json b/.github/tests/images.json index db8cfe9..2c05c82 100644 --- a/.github/tests/images.json +++ b/.github/tests/images.json @@ -11,9 +11,9 @@ "sort-flags": [] }, { - "query": "tools.bash.image", - "filter": "LATESTSHA", - "sort-flags": [] + "query": "tools.busybox.image", + "filter": "^[0-9]\\+\\.[0-9]\\+\\.[0-9]\\+-uclibc$", + "sort-flags": ["-t", ".", "-k1,1n", "-k2,2n", "-k3,3n"] } ], "spire-agent/values.yaml": [ From c19c7d51d9cd445b51cddb7c14a6ec6c73c6b3f1 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sun, 8 Jun 2025 05:30:11 -0700 Subject: [PATCH 05/16] Bump helm.sh/helm/v3 from 3.18.1 to 3.18.2 in /tests (#604) Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.18.1 to 3.18.2. - [Release notes](https://github.com/helm/helm/releases) - [Commits](https://github.com/helm/helm/compare/v3.18.1...v3.18.2) --- updated-dependencies: - dependency-name: helm.sh/helm/v3 dependency-version: 3.18.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- tests/go.mod | 2 +- tests/go.sum | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/tests/go.mod b/tests/go.mod index d0a874d..2503fbf 100644 --- a/tests/go.mod +++ b/tests/go.mod @@ -5,7 +5,7 @@ go 1.24.3 require ( github.com/onsi/ginkgo/v2 v2.23.4 github.com/onsi/gomega v1.37.0 - helm.sh/helm/v3 v3.18.1 + helm.sh/helm/v3 v3.18.2 ) require ( diff --git a/tests/go.sum b/tests/go.sum index b403d25..d1fc158 100644 --- a/tests/go.sum +++ b/tests/go.sum @@ -173,8 +173,8 @@ gopkg.in/inf.v0 v0.9.1/go.mod h1:cWUDdTG/fYaXco+Dcufb5Vnc6Gp2YChqWtbxRZE0mXw= gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= -helm.sh/helm/v3 v3.18.1 h1:qLhXmtqXOHQb0Xv9HJolOLlah8RWbgyzt50xrtTWAlg= -helm.sh/helm/v3 v3.18.1/go.mod h1:43QHS1W97RcoFJRk36ZBhHdTfykqBlJdsWp3yhzdq8w= +helm.sh/helm/v3 v3.18.2 h1:mPQP/HHYjNEDAztAK50dD6uxTCNV1zSVU38WwSVdw9M= +helm.sh/helm/v3 v3.18.2/go.mod h1:43QHS1W97RcoFJRk36ZBhHdTfykqBlJdsWp3yhzdq8w= k8s.io/api v0.33.0 h1:yTgZVn1XEe6opVpP1FylmNrIFWuDqe2H0V8CT5gxfIU= k8s.io/api v0.33.0/go.mod h1:CTO61ECK/KU7haa3qq8sarQ0biLq2ju405IZAd9zsiM= k8s.io/apiextensions-apiserver v0.33.0 h1:d2qpYL7Mngbsc1taA4IjJPRJ9ilnsXIrndH+r9IimOs= From 971e4be7d34f054fe468bce2a0622dc28313190b Mon Sep 17 00:00:00 2001 From: "spire-helm-version-checker[bot]" <161522935+spire-helm-version-checker[bot]@users.noreply.github.com> Date: Mon, 9 Jun 2025 06:30:15 -0700 Subject: [PATCH 06/16] Bump test chart dependencies (#606) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com> --- .github/tests/charts.json | 4 ++-- .github/tests/oci-charts.json | 6 +++--- .../spire/charts/spiffe-oidc-discovery-provider/README.md | 4 ++-- .../spire/charts/spiffe-oidc-discovery-provider/values.yaml | 4 ++-- charts/spire/charts/spire-agent/README.md | 6 +++--- charts/spire/charts/spire-agent/values.yaml | 6 +++--- charts/spire/charts/spire-server/README.md | 4 ++-- charts/spire/charts/spire-server/values.yaml | 4 ++-- charts/spire/charts/tornjak-frontend/README.md | 2 +- charts/spire/charts/tornjak-frontend/values.yaml | 2 +- 10 files changed, 21 insertions(+), 21 deletions(-) diff --git a/.github/tests/charts.json b/.github/tests/charts.json index 2bb93cc..a645269 100644 --- a/.github/tests/charts.json +++ b/.github/tests/charts.json @@ -2,7 +2,7 @@ { "name": "kube-prometheus-stack", "repo": "https://prometheus-community.github.io/helm-charts", - "version": "72.5.0" + "version": "73.2.0" }, { "name": "cert-manager", @@ -12,6 +12,6 @@ { "name": "ingress-nginx", "repo": "https://kubernetes.github.io/ingress-nginx", - "version": "4.12.2" + "version": "4.12.3" } ] diff --git a/.github/tests/oci-charts.json b/.github/tests/oci-charts.json index db33fa0..c203d38 100644 --- a/.github/tests/oci-charts.json +++ b/.github/tests/oci-charts.json @@ -2,16 +2,16 @@ { "name": "mysql", "registry": "docker.io/bitnamicharts/mysql", - "version": "13.0.0" + "version": "13.0.1" }, { "name": "postgresql", "registry": "docker.io/bitnamicharts/postgresql", - "version": "16.7.4" + "version": "16.7.9" }, { "name": "envoy-gateway", "registry": "docker.io/envoyproxy/gateway-helm", - "version": "v1.4.0" + "version": "v1.4.1" } ] diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md index 14d2532..e7c4c73 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md @@ -120,11 +120,11 @@ A Helm chart to install the SPIFFE OIDC discovery provider. | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e` | | `tests.toolkit.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.toolkit.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` | | `tests.toolkit.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.toolkit.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:3e5ee5ed41e764999f8e499b48d2e62d1f8ffd526aad5b4c3aa7a0759e0139db` | +| `tests.toolkit.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:d63f4689c6c67b8fb67a05b2f58df969e35e6bf4c35a107c93bb7a7986d0a51f` | | `tests.step.image.registry` | The OCI registry to pull the image from | `docker.io` | | `tests.step.image.repository` | The repository within the registry | `smallstep/step-cli` | | `tests.step.image.pullPolicy` | The image pull policy | `IfNotPresent` | diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml index 9c5edcd..ab14cd1 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml @@ -340,7 +340,7 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4 + tag: latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e toolkit: ## @param tests.toolkit.image.registry The OCI registry to pull the image from @@ -352,7 +352,7 @@ tests: registry: cgr.dev repository: chainguard/min-toolkit-debug pullPolicy: IfNotPresent - tag: latest@sha256:3e5ee5ed41e764999f8e499b48d2e62d1f8ffd526aad5b4c3aa7a0759e0139db + tag: latest@sha256:d63f4689c6c67b8fb67a05b2f58df969e35e6bf4c35a107c93bb7a7986d0a51f step: ## @param tests.step.image.registry The OCI registry to pull the image from diff --git a/charts/spire/charts/spire-agent/README.md b/charts/spire/charts/spire-agent/README.md index 7294bc8..335e977 100644 --- a/charts/spire/charts/spire-agent/README.md +++ b/charts/spire/charts/spire-agent/README.md @@ -70,7 +70,7 @@ A Helm chart to install the SPIRE agent. | `fsGroupFix.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `fsGroupFix.image.repository` | The repository within the registry | `chainguard/bash` | | `fsGroupFix.image.pullPolicy` | The image pull policy | `Always` | -| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4` | +| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e` | | `fsGroupFix.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `keyManager.memory.enabled` | Enable the memory based Key Manager | `true` | | `nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s Node Attestor | `true` | @@ -114,12 +114,12 @@ A Helm chart to install the SPIRE agent. | `socketAlternate.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `socketAlternate.image.repository` | The repository within the registry | `chainguard/bash` | | `socketAlternate.image.pullPolicy` | The image pull policy | `Always` | -| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4` | +| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e` | | `socketAlternate.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `hostCert.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `hostCert.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` | | `hostCert.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `hostCert.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:3e5ee5ed41e764999f8e499b48d2e62d1f8ffd526aad5b4c3aa7a0759e0139db` | +| `hostCert.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:d63f4689c6c67b8fb67a05b2f58df969e35e6bf4c35a107c93bb7a7986d0a51f` | | `hostCert.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `priorityClassName` | Priority class assigned to daemonset pods. Can be auto set with global.recommendations.priorityClassName. | `""` | | `extraEnvVars` | Extra environment variables to be added to the Spire Agent container | `[]` | diff --git a/charts/spire/charts/spire-agent/values.yaml b/charts/spire/charts/spire-agent/values.yaml index 3e2e164..273c2b5 100644 --- a/charts/spire/charts/spire-agent/values.yaml +++ b/charts/spire/charts/spire-agent/values.yaml @@ -153,7 +153,7 @@ fsGroupFix: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4 + tag: latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e ## @param fsGroupFix.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -280,7 +280,7 @@ socketAlternate: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4 + tag: latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e ## @param socketAlternate.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -295,7 +295,7 @@ hostCert: registry: cgr.dev repository: chainguard/min-toolkit-debug pullPolicy: IfNotPresent - tag: latest@sha256:3e5ee5ed41e764999f8e499b48d2e62d1f8ffd526aad5b4c3aa7a0759e0139db + tag: latest@sha256:d63f4689c6c67b8fb67a05b2f58df969e35e6bf4c35a107c93bb7a7986d0a51f ## @param hostCert.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index 875a585..9911061 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -451,7 +451,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `chown.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `chown.image.repository` | The repository within the registry | `chainguard/bash` | | `chown.image.pullPolicy` | The image pull policy | `Always` | -| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4` | +| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e` | | `chown.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `experimental.enabled` | Allow configuration of experimental features | `false` | | `experimental.cacheReloadInterval` | The amount of time between two reloads of the in-memory entry cache. | `5s` | @@ -464,5 +464,5 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e` | | `kubeConfigs` | Manage additional kubeconfig files to talk to external Kubernetes clusters | `{}` | diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index c00581f..e050282 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -1148,7 +1148,7 @@ chown: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4 + tag: latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e ## @param chown.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -1183,7 +1183,7 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4 + tag: latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e ## @param kubeConfigs [object] Manage additional kubeconfig files to talk to external Kubernetes clusters kubeConfigs: {} diff --git a/charts/spire/charts/tornjak-frontend/README.md b/charts/spire/charts/tornjak-frontend/README.md index 11b31c3..9763dad 100644 --- a/charts/spire/charts/tornjak-frontend/README.md +++ b/charts/spire/charts/tornjak-frontend/README.md @@ -101,4 +101,4 @@ port forwarding. See the chart NOTES output for more details. | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e` | diff --git a/charts/spire/charts/tornjak-frontend/values.yaml b/charts/spire/charts/tornjak-frontend/values.yaml index a54098f..b0ab11d 100644 --- a/charts/spire/charts/tornjak-frontend/values.yaml +++ b/charts/spire/charts/tornjak-frontend/values.yaml @@ -162,4 +162,4 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:57ed0cb7b67f52ea7678128da5c4cf99c1a71d269db92a6a40c179fa57f00ce4 + tag: latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e From bfd08bcfd13c37bcbe9e5e06bcc0d55182a4dbaf Mon Sep 17 00:00:00 2001 From: "spire-helm-version-checker[bot]" <161522935+spire-helm-version-checker[bot]@users.noreply.github.com> Date: Mon, 16 Jun 2025 12:15:39 -0700 Subject: [PATCH 07/16] Bump test chart dependencies (#608) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com> --- .github/tests/charts.json | 4 ++-- .github/tests/oci-charts.json | 2 +- .../spire/charts/spiffe-oidc-discovery-provider/README.md | 4 ++-- .../spire/charts/spiffe-oidc-discovery-provider/values.yaml | 4 ++-- charts/spire/charts/spire-agent/README.md | 6 +++--- charts/spire/charts/spire-agent/values.yaml | 6 +++--- charts/spire/charts/spire-server/README.md | 4 ++-- charts/spire/charts/spire-server/values.yaml | 4 ++-- charts/spire/charts/tornjak-frontend/README.md | 2 +- charts/spire/charts/tornjak-frontend/values.yaml | 2 +- 10 files changed, 19 insertions(+), 19 deletions(-) diff --git a/.github/tests/charts.json b/.github/tests/charts.json index a645269..7707cee 100644 --- a/.github/tests/charts.json +++ b/.github/tests/charts.json @@ -2,12 +2,12 @@ { "name": "kube-prometheus-stack", "repo": "https://prometheus-community.github.io/helm-charts", - "version": "73.2.0" + "version": "74.2.1" }, { "name": "cert-manager", "repo": "https://charts.jetstack.io", - "version": "v1.17.2" + "version": "v1.18.0" }, { "name": "ingress-nginx", diff --git a/.github/tests/oci-charts.json b/.github/tests/oci-charts.json index c203d38..44307cc 100644 --- a/.github/tests/oci-charts.json +++ b/.github/tests/oci-charts.json @@ -2,7 +2,7 @@ { "name": "mysql", "registry": "docker.io/bitnamicharts/mysql", - "version": "13.0.1" + "version": "13.0.2" }, { "name": "postgresql", diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md index e7c4c73..00e07c8 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md @@ -120,11 +120,11 @@ A Helm chart to install the SPIFFE OIDC discovery provider. | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa` | | `tests.toolkit.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.toolkit.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` | | `tests.toolkit.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.toolkit.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:d63f4689c6c67b8fb67a05b2f58df969e35e6bf4c35a107c93bb7a7986d0a51f` | +| `tests.toolkit.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:ab50aff497472bf2c218859eff90b8a11c8095767ea99fec0064026b3c2696f2` | | `tests.step.image.registry` | The OCI registry to pull the image from | `docker.io` | | `tests.step.image.repository` | The repository within the registry | `smallstep/step-cli` | | `tests.step.image.pullPolicy` | The image pull policy | `IfNotPresent` | diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml index ab14cd1..ab86829 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml @@ -340,7 +340,7 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e + tag: latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa toolkit: ## @param tests.toolkit.image.registry The OCI registry to pull the image from @@ -352,7 +352,7 @@ tests: registry: cgr.dev repository: chainguard/min-toolkit-debug pullPolicy: IfNotPresent - tag: latest@sha256:d63f4689c6c67b8fb67a05b2f58df969e35e6bf4c35a107c93bb7a7986d0a51f + tag: latest@sha256:ab50aff497472bf2c218859eff90b8a11c8095767ea99fec0064026b3c2696f2 step: ## @param tests.step.image.registry The OCI registry to pull the image from diff --git a/charts/spire/charts/spire-agent/README.md b/charts/spire/charts/spire-agent/README.md index 335e977..9e491e7 100644 --- a/charts/spire/charts/spire-agent/README.md +++ b/charts/spire/charts/spire-agent/README.md @@ -70,7 +70,7 @@ A Helm chart to install the SPIRE agent. | `fsGroupFix.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `fsGroupFix.image.repository` | The repository within the registry | `chainguard/bash` | | `fsGroupFix.image.pullPolicy` | The image pull policy | `Always` | -| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e` | +| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa` | | `fsGroupFix.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `keyManager.memory.enabled` | Enable the memory based Key Manager | `true` | | `nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s Node Attestor | `true` | @@ -114,12 +114,12 @@ A Helm chart to install the SPIRE agent. | `socketAlternate.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `socketAlternate.image.repository` | The repository within the registry | `chainguard/bash` | | `socketAlternate.image.pullPolicy` | The image pull policy | `Always` | -| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e` | +| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa` | | `socketAlternate.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `hostCert.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `hostCert.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` | | `hostCert.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `hostCert.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:d63f4689c6c67b8fb67a05b2f58df969e35e6bf4c35a107c93bb7a7986d0a51f` | +| `hostCert.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:ab50aff497472bf2c218859eff90b8a11c8095767ea99fec0064026b3c2696f2` | | `hostCert.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `priorityClassName` | Priority class assigned to daemonset pods. Can be auto set with global.recommendations.priorityClassName. | `""` | | `extraEnvVars` | Extra environment variables to be added to the Spire Agent container | `[]` | diff --git a/charts/spire/charts/spire-agent/values.yaml b/charts/spire/charts/spire-agent/values.yaml index 273c2b5..ad6540b 100644 --- a/charts/spire/charts/spire-agent/values.yaml +++ b/charts/spire/charts/spire-agent/values.yaml @@ -153,7 +153,7 @@ fsGroupFix: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e + tag: latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa ## @param fsGroupFix.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -280,7 +280,7 @@ socketAlternate: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e + tag: latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa ## @param socketAlternate.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -295,7 +295,7 @@ hostCert: registry: cgr.dev repository: chainguard/min-toolkit-debug pullPolicy: IfNotPresent - tag: latest@sha256:d63f4689c6c67b8fb67a05b2f58df969e35e6bf4c35a107c93bb7a7986d0a51f + tag: latest@sha256:ab50aff497472bf2c218859eff90b8a11c8095767ea99fec0064026b3c2696f2 ## @param hostCert.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index 9911061..aed97e9 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -451,7 +451,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `chown.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `chown.image.repository` | The repository within the registry | `chainguard/bash` | | `chown.image.pullPolicy` | The image pull policy | `Always` | -| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e` | +| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa` | | `chown.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `experimental.enabled` | Allow configuration of experimental features | `false` | | `experimental.cacheReloadInterval` | The amount of time between two reloads of the in-memory entry cache. | `5s` | @@ -464,5 +464,5 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa` | | `kubeConfigs` | Manage additional kubeconfig files to talk to external Kubernetes clusters | `{}` | diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index e050282..d81a1ea 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -1148,7 +1148,7 @@ chown: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e + tag: latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa ## @param chown.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -1183,7 +1183,7 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e + tag: latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa ## @param kubeConfigs [object] Manage additional kubeconfig files to talk to external Kubernetes clusters kubeConfigs: {} diff --git a/charts/spire/charts/tornjak-frontend/README.md b/charts/spire/charts/tornjak-frontend/README.md index 9763dad..b076303 100644 --- a/charts/spire/charts/tornjak-frontend/README.md +++ b/charts/spire/charts/tornjak-frontend/README.md @@ -101,4 +101,4 @@ port forwarding. See the chart NOTES output for more details. | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa` | diff --git a/charts/spire/charts/tornjak-frontend/values.yaml b/charts/spire/charts/tornjak-frontend/values.yaml index b0ab11d..6d28c4c 100644 --- a/charts/spire/charts/tornjak-frontend/values.yaml +++ b/charts/spire/charts/tornjak-frontend/values.yaml @@ -162,4 +162,4 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:dcd67ed564ff8f70914157a1b15526cd66196d84a0f968f05c6aaf09056cb70e + tag: latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa From fccc154b22dca26c3ac244f3cbd3942e8e12839f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 19 Jun 2025 08:14:48 -0700 Subject: [PATCH 08/16] Bump helm.sh/helm/v3 from 3.18.2 to 3.18.3 in /tests (#609) Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.18.2 to 3.18.3. - [Release notes](https://github.com/helm/helm/releases) - [Commits](https://github.com/helm/helm/compare/v3.18.2...v3.18.3) --- updated-dependencies: - dependency-name: helm.sh/helm/v3 dependency-version: 3.18.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- tests/go.mod | 20 ++++++++++---------- tests/go.sum | 40 ++++++++++++++++++++-------------------- 2 files changed, 30 insertions(+), 30 deletions(-) diff --git a/tests/go.mod b/tests/go.mod index 2503fbf..6ff4a11 100644 --- a/tests/go.mod +++ b/tests/go.mod @@ -5,7 +5,7 @@ go 1.24.3 require ( github.com/onsi/ginkgo/v2 v2.23.4 github.com/onsi/gomega v1.37.0 - helm.sh/helm/v3 v3.18.2 + helm.sh/helm/v3 v3.18.3 ) require ( @@ -46,21 +46,21 @@ require ( github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect github.com/xeipuuv/gojsonschema v1.2.0 // indirect go.uber.org/automaxprocs v1.6.0 // indirect - golang.org/x/crypto v0.37.0 // indirect - golang.org/x/net v0.38.0 // indirect + golang.org/x/crypto v0.39.0 // indirect + golang.org/x/net v0.40.0 // indirect golang.org/x/oauth2 v0.28.0 // indirect golang.org/x/sys v0.33.0 // indirect - golang.org/x/term v0.31.0 // indirect - golang.org/x/text v0.24.0 // indirect + golang.org/x/term v0.32.0 // indirect + golang.org/x/text v0.26.0 // indirect golang.org/x/time v0.9.0 // indirect - golang.org/x/tools v0.31.0 // indirect + golang.org/x/tools v0.33.0 // indirect google.golang.org/protobuf v1.36.5 // indirect gopkg.in/inf.v0 v0.9.1 // indirect gopkg.in/yaml.v3 v3.0.1 // indirect - k8s.io/api v0.33.0 // indirect - k8s.io/apiextensions-apiserver v0.33.0 // indirect - k8s.io/apimachinery v0.33.0 // indirect - k8s.io/client-go v0.33.0 // indirect + k8s.io/api v0.33.1 // indirect + k8s.io/apiextensions-apiserver v0.33.1 // indirect + k8s.io/apimachinery v0.33.1 // indirect + k8s.io/client-go v0.33.1 // indirect k8s.io/klog/v2 v2.130.1 // indirect k8s.io/kube-openapi v0.0.0-20250318190949-c8a335a9a2ff // indirect k8s.io/utils v0.0.0-20241104100929-3ea5e8cea738 // indirect diff --git a/tests/go.sum b/tests/go.sum index d1fc158..c54cbe4 100644 --- a/tests/go.sum +++ b/tests/go.sum @@ -123,16 +123,16 @@ go.uber.org/automaxprocs v1.6.0/go.mod h1:ifeIMSnPZuznNm6jmdzmU3/bfk01Fe2fotchwE golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w= golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI= golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto= -golang.org/x/crypto v0.37.0 h1:kJNSjF/Xp7kU0iB2Z+9viTPMW4EqqsrywMXLJOOsXSE= -golang.org/x/crypto v0.37.0/go.mod h1:vg+k43peMZ0pUMhYmVAWysMK35e6ioLh3wB8ZCAfbVc= +golang.org/x/crypto v0.39.0 h1:SHs+kF4LP+f+p14esP5jAoDpHU8Gu/v9lFRK6IT5imM= +golang.org/x/crypto v0.39.0/go.mod h1:L+Xg3Wf6HoL4Bn4238Z6ft6KfEpN0tJGo53AAPC632U= golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg= golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU= -golang.org/x/net v0.38.0 h1:vRMAPTMaeGqVhG5QyLJHqNDwecKTomGeqbnfZyKlBI8= -golang.org/x/net v0.38.0/go.mod h1:ivrbrMbzFq5J41QOQh0siUuly180yBYtLp+CKbEaFx8= +golang.org/x/net v0.40.0 h1:79Xs7wF06Gbdcg4kdCCIQArK11Z1hr5POQ6+fIYHNuY= +golang.org/x/net v0.40.0/go.mod h1:y0hY0exeL2Pku80/zKK7tpntoX23cqL3Oa6njdgRtds= golang.org/x/oauth2 v0.28.0 h1:CrgCKl8PPAVtLnU3c+EDw6x11699EWlsDeWNWKdIOkc= golang.org/x/oauth2 v0.28.0/go.mod h1:onh5ek6nERTohokkhCD/y2cV4Do3fxFHFuAejCkRWT8= golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= @@ -143,20 +143,20 @@ golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7w golang.org/x/sys v0.0.0-20200930185726-fdedc70b468f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= golang.org/x/sys v0.33.0 h1:q3i8TbbEz+JRD9ywIRlyRAQbM0qF7hu24q3teo2hbuw= golang.org/x/sys v0.33.0/go.mod h1:BJP2sWEmIv4KK5OTEluFJCKSidICx8ciO85XgH3Ak8k= -golang.org/x/term v0.31.0 h1:erwDkOK1Msy6offm1mOgvspSkslFnIGsFnxOKoufg3o= -golang.org/x/term v0.31.0/go.mod h1:R4BeIy7D95HzImkxGkTW1UQTtP54tio2RyHz7PwK0aw= +golang.org/x/term v0.32.0 h1:DR4lr0TjUs3epypdhTOkMmuF5CDFJ/8pOnbzMZPQ7bg= +golang.org/x/term v0.32.0/go.mod h1:uZG1FhGx848Sqfsq4/DlJr3xGGsYMu/L5GW4abiaEPQ= golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ= golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= -golang.org/x/text v0.24.0 h1:dd5Bzh4yt5KYA8f9CJHCP4FB4D51c2c6JvN37xJJkJ0= -golang.org/x/text v0.24.0/go.mod h1:L8rBsPeo2pSS+xqN0d5u2ikmjtmoJbDBT1b7nHvFCdU= +golang.org/x/text v0.26.0 h1:P42AVeLghgTYr4+xUnTRKDMqpar+PtX7KWuNQL21L8M= +golang.org/x/text v0.26.0/go.mod h1:QK15LZJUUQVJxhz7wXgxSy/CJaTFjd0G+YLonydOVQA= golang.org/x/time v0.9.0 h1:EsRrnYcQiGH+5FfbgvV4AP7qEZstoyrHB0DzarOQ4ZY= golang.org/x/time v0.9.0/go.mod h1:3BpzKBy/shNhVucY/MWOyx10tF3SFh9QdLuxbVysPQM= golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= golang.org/x/tools v0.0.0-20200619180055-7c47624df98f/go.mod h1:EkVYQZoAsY45+roYkvgYkIh4xh/qjgUK9TdY2XT94GE= golang.org/x/tools v0.0.0-20210106214847-113979e3529a/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA= -golang.org/x/tools v0.31.0 h1:0EedkvKDbh+qistFTd0Bcwe/YLh4vHwWEkiI0toFIBU= -golang.org/x/tools v0.31.0/go.mod h1:naFTU+Cev749tSJRXJlna0T3WxKvb1kWEx15xA4SdmQ= +golang.org/x/tools v0.33.0 h1:4qz2S3zmRxbGIhDIAgjxvFutSvH5EfnsYrRBj0UI0bc= +golang.org/x/tools v0.33.0/go.mod h1:CIJMaWEY88juyUfo7UbgPqbC8rU2OqfAV1h2Qp0oMYI= golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= @@ -173,16 +173,16 @@ gopkg.in/inf.v0 v0.9.1/go.mod h1:cWUDdTG/fYaXco+Dcufb5Vnc6Gp2YChqWtbxRZE0mXw= gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= -helm.sh/helm/v3 v3.18.2 h1:mPQP/HHYjNEDAztAK50dD6uxTCNV1zSVU38WwSVdw9M= -helm.sh/helm/v3 v3.18.2/go.mod h1:43QHS1W97RcoFJRk36ZBhHdTfykqBlJdsWp3yhzdq8w= -k8s.io/api v0.33.0 h1:yTgZVn1XEe6opVpP1FylmNrIFWuDqe2H0V8CT5gxfIU= -k8s.io/api v0.33.0/go.mod h1:CTO61ECK/KU7haa3qq8sarQ0biLq2ju405IZAd9zsiM= -k8s.io/apiextensions-apiserver v0.33.0 h1:d2qpYL7Mngbsc1taA4IjJPRJ9ilnsXIrndH+r9IimOs= -k8s.io/apiextensions-apiserver v0.33.0/go.mod h1:VeJ8u9dEEN+tbETo+lFkwaaZPg6uFKLGj5vyNEwwSzc= -k8s.io/apimachinery v0.33.0 h1:1a6kHrJxb2hs4t8EE5wuR/WxKDwGN1FKH3JvDtA0CIQ= -k8s.io/apimachinery v0.33.0/go.mod h1:BHW0YOu7n22fFv/JkYOEfkUYNRN0fj0BlvMFWA7b+SM= -k8s.io/client-go v0.33.0 h1:UASR0sAYVUzs2kYuKn/ZakZlcs2bEHaizrrHUZg0G98= -k8s.io/client-go v0.33.0/go.mod h1:kGkd+l/gNGg8GYWAPr0xF1rRKvVWvzh9vmZAMXtaKOg= +helm.sh/helm/v3 v3.18.3 h1:+cvyGKgs7Jt7BN3Klmb4SsG4IkVpA7GAZVGvMz6VO4I= +helm.sh/helm/v3 v3.18.3/go.mod h1:wUc4n3txYBocM7S9RjTeZBN9T/b5MjffpcSsWEjSIpw= +k8s.io/api v0.33.1 h1:tA6Cf3bHnLIrUK4IqEgb2v++/GYUtqiu9sRVk3iBXyw= +k8s.io/api v0.33.1/go.mod h1:87esjTn9DRSRTD4fWMXamiXxJhpOIREjWOSjsW1kEHw= +k8s.io/apiextensions-apiserver v0.33.1 h1:N7ccbSlRN6I2QBcXevB73PixX2dQNIW0ZRuguEE91zI= +k8s.io/apiextensions-apiserver v0.33.1/go.mod h1:uNQ52z1A1Gu75QSa+pFK5bcXc4hq7lpOXbweZgi4dqA= +k8s.io/apimachinery v0.33.1 h1:mzqXWV8tW9Rw4VeW9rEkqvnxj59k1ezDUl20tFK/oM4= +k8s.io/apimachinery v0.33.1/go.mod h1:BHW0YOu7n22fFv/JkYOEfkUYNRN0fj0BlvMFWA7b+SM= +k8s.io/client-go v0.33.1 h1:ZZV/Ks2g92cyxWkRRnfUDsnhNn28eFpt26aGc8KbXF4= +k8s.io/client-go v0.33.1/go.mod h1:JAsUrl1ArO7uRVFWfcj6kOomSlCv+JpvIsp6usAGefA= k8s.io/klog/v2 v2.130.1 h1:n9Xl7H1Xvksem4KFG4PYbdQCQxqc/tTUyrgXaOhHSzk= k8s.io/klog/v2 v2.130.1/go.mod h1:3Jpz1GvMt720eyJH1ckRHK1EDfpxISzJ7I9OYgaDtPE= k8s.io/kube-openapi v0.0.0-20250318190949-c8a335a9a2ff h1:/usPimJzUKKu+m+TE36gUyGcf03XZEP0ZIKgKj35LS4= From 38314ed6de4ff10a475399e92672f52fdfb53d8e Mon Sep 17 00:00:00 2001 From: "spire-helm-version-checker[bot]" <161522935+spire-helm-version-checker[bot]@users.noreply.github.com> Date: Mon, 23 Jun 2025 05:51:32 -0700 Subject: [PATCH 09/16] Bump test chart dependencies (#611) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com> --- .github/tests/charts.json | 4 ++-- .../spire/charts/spiffe-oidc-discovery-provider/README.md | 4 ++-- .../spire/charts/spiffe-oidc-discovery-provider/values.yaml | 4 ++-- charts/spire/charts/spire-agent/README.md | 6 +++--- charts/spire/charts/spire-agent/values.yaml | 6 +++--- charts/spire/charts/spire-server/README.md | 4 ++-- charts/spire/charts/spire-server/values.yaml | 4 ++-- charts/spire/charts/tornjak-frontend/README.md | 2 +- charts/spire/charts/tornjak-frontend/values.yaml | 2 +- 9 files changed, 18 insertions(+), 18 deletions(-) diff --git a/.github/tests/charts.json b/.github/tests/charts.json index 7707cee..879cdd0 100644 --- a/.github/tests/charts.json +++ b/.github/tests/charts.json @@ -2,12 +2,12 @@ { "name": "kube-prometheus-stack", "repo": "https://prometheus-community.github.io/helm-charts", - "version": "74.2.1" + "version": "75.4.0" }, { "name": "cert-manager", "repo": "https://charts.jetstack.io", - "version": "v1.18.0" + "version": "v1.18.1" }, { "name": "ingress-nginx", diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md index 00e07c8..7e5727e 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md @@ -120,11 +120,11 @@ A Helm chart to install the SPIFFE OIDC discovery provider. | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a` | | `tests.toolkit.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.toolkit.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` | | `tests.toolkit.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.toolkit.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:ab50aff497472bf2c218859eff90b8a11c8095767ea99fec0064026b3c2696f2` | +| `tests.toolkit.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9e3e978258955e1e6a4d855f83a1ce66146ca5de6a9e52bf75d3918fafe3e5a4` | | `tests.step.image.registry` | The OCI registry to pull the image from | `docker.io` | | `tests.step.image.repository` | The repository within the registry | `smallstep/step-cli` | | `tests.step.image.pullPolicy` | The image pull policy | `IfNotPresent` | diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml index ab86829..f2d7a77 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml @@ -340,7 +340,7 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa + tag: latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a toolkit: ## @param tests.toolkit.image.registry The OCI registry to pull the image from @@ -352,7 +352,7 @@ tests: registry: cgr.dev repository: chainguard/min-toolkit-debug pullPolicy: IfNotPresent - tag: latest@sha256:ab50aff497472bf2c218859eff90b8a11c8095767ea99fec0064026b3c2696f2 + tag: latest@sha256:9e3e978258955e1e6a4d855f83a1ce66146ca5de6a9e52bf75d3918fafe3e5a4 step: ## @param tests.step.image.registry The OCI registry to pull the image from diff --git a/charts/spire/charts/spire-agent/README.md b/charts/spire/charts/spire-agent/README.md index 9e491e7..ed41cba 100644 --- a/charts/spire/charts/spire-agent/README.md +++ b/charts/spire/charts/spire-agent/README.md @@ -70,7 +70,7 @@ A Helm chart to install the SPIRE agent. | `fsGroupFix.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `fsGroupFix.image.repository` | The repository within the registry | `chainguard/bash` | | `fsGroupFix.image.pullPolicy` | The image pull policy | `Always` | -| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa` | +| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a` | | `fsGroupFix.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `keyManager.memory.enabled` | Enable the memory based Key Manager | `true` | | `nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s Node Attestor | `true` | @@ -114,12 +114,12 @@ A Helm chart to install the SPIRE agent. | `socketAlternate.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `socketAlternate.image.repository` | The repository within the registry | `chainguard/bash` | | `socketAlternate.image.pullPolicy` | The image pull policy | `Always` | -| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa` | +| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a` | | `socketAlternate.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `hostCert.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `hostCert.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` | | `hostCert.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `hostCert.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:ab50aff497472bf2c218859eff90b8a11c8095767ea99fec0064026b3c2696f2` | +| `hostCert.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9e3e978258955e1e6a4d855f83a1ce66146ca5de6a9e52bf75d3918fafe3e5a4` | | `hostCert.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `priorityClassName` | Priority class assigned to daemonset pods. Can be auto set with global.recommendations.priorityClassName. | `""` | | `extraEnvVars` | Extra environment variables to be added to the Spire Agent container | `[]` | diff --git a/charts/spire/charts/spire-agent/values.yaml b/charts/spire/charts/spire-agent/values.yaml index ad6540b..af4fb81 100644 --- a/charts/spire/charts/spire-agent/values.yaml +++ b/charts/spire/charts/spire-agent/values.yaml @@ -153,7 +153,7 @@ fsGroupFix: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa + tag: latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a ## @param fsGroupFix.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -280,7 +280,7 @@ socketAlternate: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa + tag: latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a ## @param socketAlternate.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -295,7 +295,7 @@ hostCert: registry: cgr.dev repository: chainguard/min-toolkit-debug pullPolicy: IfNotPresent - tag: latest@sha256:ab50aff497472bf2c218859eff90b8a11c8095767ea99fec0064026b3c2696f2 + tag: latest@sha256:9e3e978258955e1e6a4d855f83a1ce66146ca5de6a9e52bf75d3918fafe3e5a4 ## @param hostCert.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index aed97e9..172716a 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -451,7 +451,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `chown.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `chown.image.repository` | The repository within the registry | `chainguard/bash` | | `chown.image.pullPolicy` | The image pull policy | `Always` | -| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa` | +| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a` | | `chown.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `experimental.enabled` | Allow configuration of experimental features | `false` | | `experimental.cacheReloadInterval` | The amount of time between two reloads of the in-memory entry cache. | `5s` | @@ -464,5 +464,5 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a` | | `kubeConfigs` | Manage additional kubeconfig files to talk to external Kubernetes clusters | `{}` | diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index d81a1ea..fb24a49 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -1148,7 +1148,7 @@ chown: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa + tag: latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a ## @param chown.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -1183,7 +1183,7 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa + tag: latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a ## @param kubeConfigs [object] Manage additional kubeconfig files to talk to external Kubernetes clusters kubeConfigs: {} diff --git a/charts/spire/charts/tornjak-frontend/README.md b/charts/spire/charts/tornjak-frontend/README.md index b076303..b8fd86c 100644 --- a/charts/spire/charts/tornjak-frontend/README.md +++ b/charts/spire/charts/tornjak-frontend/README.md @@ -101,4 +101,4 @@ port forwarding. See the chart NOTES output for more details. | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a` | diff --git a/charts/spire/charts/tornjak-frontend/values.yaml b/charts/spire/charts/tornjak-frontend/values.yaml index 6d28c4c..69a3b41 100644 --- a/charts/spire/charts/tornjak-frontend/values.yaml +++ b/charts/spire/charts/tornjak-frontend/values.yaml @@ -162,4 +162,4 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:5a1b374162dc37e9d78f52ca64ed1922817fea6c67e1b3433c444cc3d44d18aa + tag: latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a From e78400ebcd0a0b353c1f33c710ae4eecc65ed487 Mon Sep 17 00:00:00 2001 From: kfox1111 Date: Mon, 23 Jun 2025 23:07:40 -0700 Subject: [PATCH 10/16] Initial spike support (#591) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * Initial spike support Signed-off-by: Kevin Fox * Fix lint and docs Signed-off-by: Kevin Fox * Update spike to 0.4.1 Signed-off-by: Kevin Fox * Update for multiarch Signed-off-by: Kevin Fox * Update Signed-off-by: Kevin Fox * Fix values and docs Signed-off-by: Kevin Fox * Pull in changes from Volkan Signed-off-by: Kevin Fox * Fix service Signed-off-by: Kevin Fox * Typo fix Signed-off-by: Volkan Özçelik * Apply suggestions from code review Co-authored-by: Faisal Memon Signed-off-by: kfox1111 * Update docs Signed-off-by: Kevin Fox --------- Signed-off-by: Kevin Fox Signed-off-by: Volkan Özçelik Signed-off-by: kfox1111 Co-authored-by: Volkan Özçelik Co-authored-by: Faisal Memon --- charts/spire/Chart.yaml | 12 ++ charts/spire/README.md | 18 ++ charts/spire/charts/spike-keeper/Chart.yaml | 13 ++ charts/spire/charts/spike-keeper/README.md | 72 ++++++++ .../charts/spike-keeper/templates/NOTES.txt | 1 + .../spike-keeper/templates/_helpers.tpl | 83 +++++++++ .../spike-keeper/templates/ingress.yaml | 44 +++++ .../spike-keeper/templates/service.yaml | 48 +++++ .../templates/serviceaccount.yaml | 13 ++ .../spike-keeper/templates/statefulset.yaml | 84 +++++++++ charts/spire/charts/spike-keeper/values.yaml | 139 ++++++++++++++ charts/spire/charts/spike-nexus/Chart.yaml | 13 ++ charts/spire/charts/spike-nexus/README.md | 82 +++++++++ .../charts/spike-nexus/templates/NOTES.txt | 1 + .../charts/spike-nexus/templates/_helpers.tpl | 83 +++++++++ .../charts/spike-nexus/templates/ingress.yaml | 31 ++++ .../charts/spike-nexus/templates/service.yaml | 20 ++ .../spike-nexus/templates/serviceaccount.yaml | 13 ++ .../spike-nexus/templates/statefulset.yaml | 112 ++++++++++++ charts/spire/charts/spike-nexus/values.yaml | 172 ++++++++++++++++++ charts/spire/charts/spike-pilot/Chart.yaml | 13 ++ charts/spire/charts/spike-pilot/README.md | 63 +++++++ .../charts/spike-pilot/templates/NOTES.txt | 1 + .../charts/spike-pilot/templates/_helpers.tpl | 83 +++++++++ .../spike-pilot/templates/deployment.yaml | 96 ++++++++++ .../spike-pilot/templates/serviceaccount.yaml | 13 ++ charts/spire/charts/spike-pilot/values.yaml | 116 ++++++++++++ charts/spire/charts/spire-server/README.md | 9 + .../controller-manager-cluster-ids.yaml | 19 +- charts/spire/charts/spire-server/values.yaml | 22 +++ charts/spire/values.yaml | 21 +++ examples/spike/values.yaml | 15 ++ 32 files changed, 1523 insertions(+), 2 deletions(-) create mode 100644 charts/spire/charts/spike-keeper/Chart.yaml create mode 100644 charts/spire/charts/spike-keeper/README.md create mode 100644 charts/spire/charts/spike-keeper/templates/NOTES.txt create mode 100644 charts/spire/charts/spike-keeper/templates/_helpers.tpl create mode 100644 charts/spire/charts/spike-keeper/templates/ingress.yaml create mode 100644 charts/spire/charts/spike-keeper/templates/service.yaml create mode 100644 charts/spire/charts/spike-keeper/templates/serviceaccount.yaml create mode 100644 charts/spire/charts/spike-keeper/templates/statefulset.yaml create mode 100644 charts/spire/charts/spike-keeper/values.yaml create mode 100644 charts/spire/charts/spike-nexus/Chart.yaml create mode 100644 charts/spire/charts/spike-nexus/README.md create mode 100644 charts/spire/charts/spike-nexus/templates/NOTES.txt create mode 100644 charts/spire/charts/spike-nexus/templates/_helpers.tpl create mode 100644 charts/spire/charts/spike-nexus/templates/ingress.yaml create mode 100644 charts/spire/charts/spike-nexus/templates/service.yaml create mode 100644 charts/spire/charts/spike-nexus/templates/serviceaccount.yaml create mode 100644 charts/spire/charts/spike-nexus/templates/statefulset.yaml create mode 100644 charts/spire/charts/spike-nexus/values.yaml create mode 100644 charts/spire/charts/spike-pilot/Chart.yaml create mode 100644 charts/spire/charts/spike-pilot/README.md create mode 100644 charts/spire/charts/spike-pilot/templates/NOTES.txt create mode 100644 charts/spire/charts/spike-pilot/templates/_helpers.tpl create mode 100644 charts/spire/charts/spike-pilot/templates/deployment.yaml create mode 100644 charts/spire/charts/spike-pilot/templates/serviceaccount.yaml create mode 100644 charts/spire/charts/spike-pilot/values.yaml create mode 100644 examples/spike/values.yaml diff --git a/charts/spire/Chart.yaml b/charts/spire/Chart.yaml index b9c3528..3ef2cad 100644 --- a/charts/spire/Chart.yaml +++ b/charts/spire/Chart.yaml @@ -55,6 +55,18 @@ dependencies: condition: tornjak-frontend.enabled repository: file://./charts/tornjak-frontend version: 0.1.0 + - name: spike-keeper + condition: spike-keeper.enabled + repository: file://./charts/spike-keeper + version: 0.1.0 + - name: spike-nexus + condition: spike-nexus.enabled + repository: file://./charts/spike-nexus + version: 0.1.0 + - name: spike-pilot + condition: spike-pilot.enabled + repository: file://./charts/spike-pilot + version: 0.1.0 annotations: artifacthub.io/category: security artifacthub.io/license: Apache-2.0 diff --git a/charts/spire/README.md b/charts/spire/README.md index 69d6857..0fb63c3 100644 --- a/charts/spire/README.md +++ b/charts/spire/README.md @@ -373,3 +373,21 @@ Now you can interact with the Spire agent socket from your own application. The | Name | Description | Value | | -------------------------- | -------------------------------------------------------------- | ------- | | `tornjak-frontend.enabled` | Enables deployment of Tornjak frontend/UI (Not for production) | `false` | + +### SPIKE Keeper parameters + +| Name | Description | Value | +| ---------------------- | ------------------------------------------------------- | ------- | +| `spike-keeper.enabled` | Enables deployment of SPIKE Keeper (Not for production) | `false` | + +### SPIKE Nexus parameters + +| Name | Description | Value | +| --------------------- | ------------------------------------------------------ | ------- | +| `spike-nexus.enabled` | Enables deployment of SPIKE Nexus (Not for production) | `false` | + +### SPIKE Pilot parameters + +| Name | Description | Value | +| --------------------- | ------------------------------------------------------ | ------- | +| `spike-pilot.enabled` | Enables deployment of SPIKE Pilot (Not for production) | `false` | diff --git a/charts/spire/charts/spike-keeper/Chart.yaml b/charts/spire/charts/spike-keeper/Chart.yaml new file mode 100644 index 0000000..9cb2683 --- /dev/null +++ b/charts/spire/charts/spike-keeper/Chart.yaml @@ -0,0 +1,13 @@ +apiVersion: v2 +name: spike-keeper +description: A Helm chart to deploy SPIKE Keeper +type: application +version: 0.1.0 +appVersion: "0.4.1" +home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire +sources: + - https://github.com/spiffe/spike +icon: https://spike.ist/assets/spike-banner.png +maintainers: + - name: kfox1111 + email: Kevin.Fox@pnnl.gov diff --git a/charts/spire/charts/spike-keeper/README.md b/charts/spire/charts/spike-keeper/README.md new file mode 100644 index 0000000..2552edf --- /dev/null +++ b/charts/spire/charts/spike-keeper/README.md @@ -0,0 +1,72 @@ +# spike-keeper + +![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v0.4.1](https://img.shields.io/badge/AppVersion-v0.4.1-informational?style=flat-square) +[![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) + +A Helm chart to deploy spike keepers + +**Homepage:** + +## Version support + +> [!Note] +> This Chart is still in development and still subject to change the API (`values.yaml`). +> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although +> we do aim for as much stability as possible. + +| Dependency | Supported Versions | +|:-----------|:-------------------| +| Helm | `3.x` | + +## Source Code + +* + + + +## Parameters + +### Chart parameters + +| Name | Description | Value | +| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------- | +| `image.registry` | The OCI registry to pull the image from | `ghcr.io` | +| `image.repository` | The repository within the registry | `spiffe/spike-keeper` | +| `image.pullPolicy` | The image pull policy | `IfNotPresent` | +| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` | +| `replicas` | The number of keepers to launch | `3` | +| `trustRoot.nexus` | Override which trustRoot Nexus is in | `""` | +| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `debug` | +| `agentSocketName` | The name of the spire-agent unix socket | `spire-agent.sock` | +| `csiDriverName` | The csi driver to use | `csi.spiffe.io` | +| `imagePullSecrets` | Pull secrets for images | `[]` | +| `nameOverride` | Name override | `""` | +| `namespaceOverride` | Namespace override | `""` | +| `fullnameOverride` | Fullname override | `""` | +| `serviceAccount.create` | Specifies whether a service account should be created | `true` | +| `serviceAccount.annotations` | Annotations to add to the service account | `{}` | +| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` | +| `labels` | Labels for pods | `{}` | +| `podSecurityContext` | Pod security context | `{}` | +| `securityContext` | Security context | `{}` | +| `service.type` | Service type | `ClusterIP` | +| `service.port` | Service port | `443` | +| `service.annotations` | Annotations for service resource | `{}` | +| `nodeSelector` | (Optional) Select specific nodes to run on. | `{}` | +| `affinity` | Affinity rules | `{}` | +| `tolerations` | List of tolerations | `[]` | +| `topologySpreadConstraints` | List of topology spread constraints for resilience | `[]` | +| `startupProbe.enabled` | Enable startupProbe | `true` | +| `startupProbe.initialDelaySeconds` | Initial delay seconds for startupProbe | `5` | +| `startupProbe.periodSeconds` | Period seconds for startupProbe | `10` | +| `startupProbe.timeoutSeconds` | Timeout seconds for startupProbe | `5` | +| `startupProbe.failureThreshold` | Failure threshold count for startupProbe | `6` | +| `startupProbe.successThreshold` | Success threshold count for startupProbe | `1` | +| `ingress.enabled` | Flag to enable ingress | `false` | +| `ingress.className` | Ingress class name | `""` | +| `ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` | +| `ingress.annotations` | Annotations | `{}` | +| `ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `keeper` | +| `ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` | +| `ingress.hosts` | Host paths for ingress object. If empty, rules will be built based on the host var. | `[]` | +| `ingress.tls` | Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. | `[]` | diff --git a/charts/spire/charts/spike-keeper/templates/NOTES.txt b/charts/spire/charts/spike-keeper/templates/NOTES.txt new file mode 100644 index 0000000..dfe3e24 --- /dev/null +++ b/charts/spire/charts/spike-keeper/templates/NOTES.txt @@ -0,0 +1 @@ +Installed {{ .Chart.Name }}… diff --git a/charts/spire/charts/spike-keeper/templates/_helpers.tpl b/charts/spire/charts/spike-keeper/templates/_helpers.tpl new file mode 100644 index 0000000..66c9019 --- /dev/null +++ b/charts/spire/charts/spike-keeper/templates/_helpers.tpl @@ -0,0 +1,83 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "spike-keeper.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "spike-keeper.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Allow the release namespace to be overridden for multi-namespace deployments in combined charts +*/}} +{{- define "spike-keeper.namespace" -}} + {{- if .Values.namespaceOverride -}} + {{- .Values.namespaceOverride -}} + {{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }} + {{- if ne (len (dig "spire" "namespaces" "server" "name" "" .Values.global)) 0 }} + {{- .Values.global.spire.namespaces.server.name }} + {{- else }} + {{- printf "spire-server" }} + {{- end }} + {{- else -}} + {{- .Release.Namespace -}} + {{- end -}} +{{- end -}} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "spike-keeper.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "spike-keeper.labels" -}} +helm.sh/chart: {{ include "spike-keeper.chart" . }} +{{ include "spike-keeper.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "spike-keeper.selectorLabels" -}} +app.kubernetes.io/name: {{ include "spike-keeper.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} + +{{/* +Create the name of the service account to use +*/}} +{{- define "spike-keeper.serviceAccountName" -}} +{{- if .Values.serviceAccount.create }} +{{- default (include "spike-keeper.fullname" .) .Values.serviceAccount.name }} +{{- else }} +{{- default "default" .Values.serviceAccount.name }} +{{- end }} +{{- end }} + +{{- define "spike-keeper.workload-api-socket-path" -}} +{{- printf "/spiffe-workload-api/%s" .Values.agentSocketName }} +{{- end }} diff --git a/charts/spire/charts/spike-keeper/templates/ingress.yaml b/charts/spire/charts/spike-keeper/templates/ingress.yaml new file mode 100644 index 0000000..af2ff0c --- /dev/null +++ b/charts/spire/charts/spike-keeper/templates/ingress.yaml @@ -0,0 +1,44 @@ +{{- if .Values.ingress.enabled -}} +{{ $root := . }} +{{- $ingressControllerType := include "spire-lib.ingress-controller-type" (dict "global" .Values.global "ingress" .Values.ingress) }} +{{- $fullName := include "spike-keeper.fullname" . -}} +{{- $tlsSection := true }} +{{- $annotations := deepCopy .Values.ingress.annotations }} +{{- if eq $ingressControllerType "ingress-nginx" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-redirect" "true" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/force-ssl-redirect" "true" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/backend-protocol" "HTTPS" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-passthrough" "true" }} +{{- else if eq $ingressControllerType "openshift" }} +{{- $path = "" }} +{{- $_ := set $annotations "route.openshift.io/termination" "passthrough" }} +{{- $tlsSection = false }} +{{- end }} +{{ $last := sub (.Values.replicas | int) 1 | int }} +{{ range (seq 0 ($last) | toString | split " ") }} +{{ $i := . }} +--- +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: {{ $fullName }}-{{ $i }} + namespace: {{ include "spike-keeper.namespace" $root }} + labels: + {{ include "spike-keeper.labels" $root | nindent 4}} + {{- with $annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + {{- $host := $root.Values.ingress.host }} + {{- if contains "." $host }} + {{- $hostParts := regexSplit "[.]" $host 2 }} + {{- $host = printf "%s-%s.%s" (index $hostParts 0) $i (index $hostParts 1) }} + {{- else }} + {{- $host = printf "%s-%s" $host $i }} + {{- end }} + {{ $ingress := deepCopy $root.Values.ingress }} + {{ $_ := set $ingress "host" $host }} + {{ include "spire-lib.ingress-spec" (dict "ingress" $ingress "svcName" (printf "%s-%s" $fullName $i) "port" $root.Values.service.port "path" "/" "pathType" "Prefix" "tlsSection" $tlsSection "Values" $root.Values) | nindent 2 }} +{{- end }} +{{- end }} diff --git a/charts/spire/charts/spike-keeper/templates/service.yaml b/charts/spire/charts/spike-keeper/templates/service.yaml new file mode 100644 index 0000000..1d86355 --- /dev/null +++ b/charts/spire/charts/spike-keeper/templates/service.yaml @@ -0,0 +1,48 @@ +{{ $root := . }} +{{ $last := sub (.Values.replicas | int) 1 | int }} +{{ range (seq 0 ($last) | toString | split " ") }} +{{ $i := . }} +--- +apiVersion: v1 +kind: Service +metadata: + namespace: {{ include "spike-keeper.namespace" $root }} + name: {{ include "spike-keeper.fullname" $root }}-{{ $i }} + {{- with $root.Values.service.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + labels: + apps.kubernetes.io/pod-index: {{ $i | quote }} + {{- include "spike-keeper.labels" $root | nindent 4 }} +spec: + type: {{ $root.Values.service.type }} + selector: + apps.kubernetes.io/pod-index: {{ $i | quote }} + {{- include "spike-keeper.selectorLabels" $root | nindent 4 }} + ports: + - name: {{ include "spike-keeper.fullname" $root }} + port: {{ $root.Values.service.port }} + targetPort: http +{{ end }} +--- +apiVersion: v1 +kind: Service +metadata: + namespace: {{ include "spike-keeper.namespace" $root }} + name: {{ include "spike-keeper.fullname" $root }}-headless + {{- with $root.Values.service.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + labels: + {{- include "spike-keeper.labels" $root | nindent 4 }} +spec: + type: {{ $root.Values.service.type }} + clusterIP: None + selector: + {{- include "spike-keeper.selectorLabels" $root | nindent 4 }} + ports: + - name: {{ include "spike-keeper.fullname" $root }} + port: {{ $root.Values.service.port }} + targetPort: http diff --git a/charts/spire/charts/spike-keeper/templates/serviceaccount.yaml b/charts/spire/charts/spike-keeper/templates/serviceaccount.yaml new file mode 100644 index 0000000..7f13cb3 --- /dev/null +++ b/charts/spire/charts/spike-keeper/templates/serviceaccount.yaml @@ -0,0 +1,13 @@ +{{- if .Values.serviceAccount.create -}} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ include "spike-keeper.serviceAccountName" . }} + namespace: {{ include "spike-keeper.namespace" . }} + labels: + {{- include "spike-keeper.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +{{- end }} diff --git a/charts/spire/charts/spike-keeper/templates/statefulset.yaml b/charts/spire/charts/spike-keeper/templates/statefulset.yaml new file mode 100644 index 0000000..baf33f8 --- /dev/null +++ b/charts/spire/charts/spike-keeper/templates/statefulset.yaml @@ -0,0 +1,84 @@ +apiVersion: apps/v1 +kind: StatefulSet +metadata: + name: {{ include "spike-keeper.fullname" . }} + namespace: {{ include "spike-keeper.namespace" . }} + labels: + {{- include "spike-keeper.labels" . | nindent 4 }} +spec: + serviceName: {{ include "spike-keeper.fullname" . }}-headless + replicas: {{ .Values.replicas }} + selector: + matchLabels: + {{- include "spike-keeper.selectorLabels" . | nindent 6 }} + template: + metadata: + labels: + {{- include "spike-keeper.selectorLabels" . | nindent 8 }} + release: {{ .Release.Name }} + release-namespace: {{ .Release.Namespace }} + component: spike-keeper + spec: + {{- with .Values.imagePullSecrets }} + imagePullSecrets: + {{- toYaml . | nindent 8 }} + {{- end }} + serviceAccountName: {{ include "spike-keeper.serviceAccountName" . }} + securityContext: + {{- include "spire-lib.podsecuritycontext" . | nindent 8 }} + containers: + - name: {{ include "spike-keeper.fullname" . }} + image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image "global" .Values.global "ubi" true) }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + securityContext: + {{- include "spire-lib.securitycontext" . | nindent 12 }} + ports: + - name: http + containerPort: 8443 + protocol: TCP + env: + - name: SPIFFE_ENDPOINT_SOCKET + value: unix://{{ include "spike-keeper.workload-api-socket-path" . }} + - name: SPIKE_SYSTEM_LOG_LEVEL + value: {{ .Values.logLevel | upper }} + - name: SPIKE_TRUST_ROOT + value: {{ include "spire-lib.trust-domain" . }} + - name: SPIKE_TRUST_ROOT_NEXUS + value: {{if eq .Values.trustRoot.nexus "" }}{{ include "spire-lib.trust-domain" . }}{{ else }}{{.Values.trustRoot.nexus }}{{ end }} + - name: SPIKE_KEEPER_TLS_PORT + value: ":8443" + {{- if .Values.startupProbe.enabled }} + startupProbe: + tcpSocket: + port: 8443 + failureThreshold: {{ .Values.startupProbe.failureThreshold }} + initialDelaySeconds: {{ .Values.startupProbe.initialDelaySeconds }} + periodSeconds: {{ .Values.startupProbe.periodSeconds }} + successThreshold: {{ .Values.startupProbe.successThreshold }} + timeoutSeconds: {{ .Values.startupProbe.timeoutSeconds }} + {{- end }} + volumeMounts: + - name: spiffe-workload-api + mountPath: {{ include "spike-keeper.workload-api-socket-path" . | dir }} + readOnly: true + {{- with .Values.nodeSelector }} + nodeSelector: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.tolerations }} + tolerations: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.topologySpreadConstraints }} + topologySpreadConstraints: + {{- toYaml . | nindent 8 }} + {{- end }} + volumes: + - name: spiffe-workload-api + csi: + driver: "{{ .Values.csiDriverName }}" + readOnly: true diff --git a/charts/spire/charts/spike-keeper/values.yaml b/charts/spire/charts/spike-keeper/values.yaml new file mode 100644 index 0000000..312280d --- /dev/null +++ b/charts/spire/charts/spike-keeper/values.yaml @@ -0,0 +1,139 @@ +# Default configuration for SPIKE Keeper +# SPDX-License-Identifier: APACHE-2.0 + +## @skip global +global: {} + +## @section Chart parameters +## +## @param image.registry The OCI registry to pull the image from +## @param image.repository The repository within the registry +## @param image.pullPolicy The image pull policy +## @param image.tag Overrides the image tag whose default is the chart appVersion +## +image: + registry: ghcr.io + repository: spiffe/spike-keeper + pullPolicy: IfNotPresent + tag: "" + +## @param replicas The number of keepers to launch +replicas: 3 + +trustRoot: + ## @param trustRoot.nexus Override which trustRoot Nexus is in + nexus: "" + +## @param logLevel The log level, valid values are "debug", "info", "warn", and "error" +logLevel: debug + +## @param agentSocketName The name of the spire-agent unix socket +agentSocketName: spire-agent.sock +## @param csiDriverName The csi driver to use +csiDriverName: csi.spiffe.io + +## @param imagePullSecrets [array] Pull secrets for images +imagePullSecrets: [] + +## @param nameOverride Name override +nameOverride: "" + +## @param namespaceOverride Namespace override +namespaceOverride: "" + +## @param fullnameOverride Fullname override +fullnameOverride: "" + +## @param serviceAccount.create Specifies whether a service account should be created +## @param serviceAccount.annotations [object] Annotations to add to the service account +## @param serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated. +## +serviceAccount: + create: true + annotations: {} + name: "" + +## @param labels [object] Labels for pods +labels: {} + +## @param podSecurityContext [object] Pod security context +podSecurityContext: {} + # fsGroup: 2000 + +## @param securityContext [object] Security context +securityContext: {} + # capabilities: + # drop: + # - ALL + # readOnlyRootFilesystem: true + # runAsNonRoot: true + # runAsUser: 1000 + +## @param service.type Service type +## @param service.port Service port +## @param service.annotations Annotations for service resource +## +service: + type: ClusterIP + port: 443 + annotations: {} + +## @param nodeSelector (Optional) Select specific nodes to run on. +nodeSelector: {} + +## @param affinity [object] Affinity rules +affinity: {} + +## @param tolerations [array] List of tolerations +tolerations: [] + +## @param topologySpreadConstraints [array] List of topology spread constraints for resilience +topologySpreadConstraints: [] + +## Provide minimal resources to prevent accidental crashes due to resource exhaustion +# resources: +# requests: +# cpu: 50m +# memory: 128Mi +# limits: +# cpu: 100m +# memory: 512Mi + +## Configure extra options for startup probe +## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-startup-probes +## @param startupProbe.enabled Enable startupProbe +## @param startupProbe.initialDelaySeconds Initial delay seconds for startupProbe +## @param startupProbe.periodSeconds Period seconds for startupProbe +## @param startupProbe.timeoutSeconds Timeout seconds for startupProbe +## @param startupProbe.failureThreshold Failure threshold count for startupProbe +## @param startupProbe.successThreshold Success threshold count for startupProbe +## +startupProbe: + enabled: true + initialDelaySeconds: 5 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 6 + successThreshold: 1 + +## @param ingress.enabled Flag to enable ingress +## @param ingress.className Ingress class name +## @param ingress.controllerType Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. +## @param ingress.annotations [object] Annotations +ingress: + enabled: false + className: "" + controllerType: "" + annotations: {} + + ## @param ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. + host: "keeper" + + ## @param ingress.tlsSecret Secret that has the certs. If blank will use default certs. Used with host var. + tlsSecret: "" + + ## @param ingress.hosts [array] Host paths for ingress object. If empty, rules will be built based on the host var. + hosts: [] + + ## @param ingress.tls [array] Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. + tls: [] diff --git a/charts/spire/charts/spike-nexus/Chart.yaml b/charts/spire/charts/spike-nexus/Chart.yaml new file mode 100644 index 0000000..c125986 --- /dev/null +++ b/charts/spire/charts/spike-nexus/Chart.yaml @@ -0,0 +1,13 @@ +apiVersion: v2 +name: spike-nexus +description: A Helm chart to deploy SPIKE Nexus +type: application +version: 0.1.0 +appVersion: "0.4.1" +home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire +sources: + - https://github.com/spiffe/spike +icon: https://spike.ist/assets/spike-banner.png +maintainers: + - name: kfox1111 + email: Kevin.Fox@pnnl.gov diff --git a/charts/spire/charts/spike-nexus/README.md b/charts/spire/charts/spike-nexus/README.md new file mode 100644 index 0000000..9d20a00 --- /dev/null +++ b/charts/spire/charts/spike-nexus/README.md @@ -0,0 +1,82 @@ +# spike-nexus + +![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v0.4.1](https://img.shields.io/badge/AppVersion-v0.4.1-informational?style=flat-square) +[![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) + +A Helm chart to deploy spike nexus + +**Homepage:** + +## Version support + +> [!Note] +> This Chart is still in development and still subject to change the API (`values.yaml`). +> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although +> we do aim for as much stability as possible. + +| Dependency | Supported Versions | +|:-----------|:-------------------| +| Helm | `3.x` | + +## Source Code + +* + + + +## Parameters + +### Chart parameters + +| Name | Description | Value | +| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------- | +| `image.registry` | The OCI registry to pull the image from | `ghcr.io` | +| `image.repository` | The repository within the registry | `spiffe/spike-nexus` | +| `image.pullPolicy` | The image pull policy | `IfNotPresent` | +| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` | +| `replicas` | The number of keepers to launch | `1` | +| `shamir.shares` | How many shares to configure for shamir secrets | `3` | +| `shamir.threshold` | How many shares needed to recover | `2` | +| `keeperPeers` | Keeper peer configuration. If blank, it will be autodetected | `[]` | +| `trustRoot.nexus` | Override which trustRoot Nexus is in | `""` | +| `trustRoot.keepers` | Override which trustRoot Keepers are in | `[]` | +| `trustRoot.pilot` | Override which trustRoot Pilot is in | `""` | +| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `debug` | +| `agentSocketName` | The name of the spire-agent unix socket | `spire-agent.sock` | +| `csiDriverName` | The csi driver to use | `csi.spiffe.io` | +| `imagePullSecrets` | Pull secrets for images | `[]` | +| `nameOverride` | Name override | `""` | +| `namespaceOverride` | Namespace override | `""` | +| `fullnameOverride` | Fullname override | `""` | +| `serviceAccount.create` | Specifies whether a service account should be created | `true` | +| `serviceAccount.annotations` | Annotations to add to the service account | `{}` | +| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` | +| `labels` | Labels for pods | `{}` | +| `podSecurityContext` | Pod security context | `{}` | +| `securityContext` | Security context | `{}` | +| `service.type` | Service type | `ClusterIP` | +| `service.port` | Service port | `443` | +| `service.annotations` | Annotations for service resource | `{}` | +| `nodeSelector` | (Optional) Select specific nodes to run on. | `{}` | +| `affinity` | Affinity rules | `{}` | +| `tolerations` | List of tolerations | `[]` | +| `topologySpreadConstraints` | List of topology spread constraints for resilience | `[]` | +| `startupProbe.enabled` | Enable startupProbe | `true` | +| `startupProbe.initialDelaySeconds` | Initial delay seconds for startupProbe | `5` | +| `startupProbe.periodSeconds` | Period seconds for startupProbe | `10` | +| `startupProbe.timeoutSeconds` | Timeout seconds for startupProbe | `5` | +| `startupProbe.failureThreshold` | Failure threshold count for startupProbe | `6` | +| `startupProbe.successThreshold` | Success threshold count for startupProbe | `1` | +| `ingress.enabled` | Flag to enable ingress | `false` | +| `ingress.className` | Ingress class name | `""` | +| `ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` | +| `ingress.annotations` | Annotations | `{}` | +| `ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `nexus` | +| `ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` | +| `ingress.hosts` | Host paths for ingress object. If empty, rules will be built based on the host var. | `[]` | +| `ingress.tls` | Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. | `[]` | +| `persistence.type` | What type of volume to use for persistence. Valid options pvc (recommended), hostPath, emptyDir (testing only) | `pvc` | +| `persistence.size` | What size volume to use for persistence | `1Gi` | +| `persistence.accessMode` | What access mode to use for persistence. Valid options are ReadWriteOnce (recommended), ReadWriteOncePod, ReadWriteMany (not recommended) | `ReadWriteOnce` | +| `persistence.storageClass` | What storage class to use for persistence | `nil` | +| `persistence.hostPath` | Which path to use on the host when persistence.type = hostPath | `""` | diff --git a/charts/spire/charts/spike-nexus/templates/NOTES.txt b/charts/spire/charts/spike-nexus/templates/NOTES.txt new file mode 100644 index 0000000..dfe3e24 --- /dev/null +++ b/charts/spire/charts/spike-nexus/templates/NOTES.txt @@ -0,0 +1 @@ +Installed {{ .Chart.Name }}… diff --git a/charts/spire/charts/spike-nexus/templates/_helpers.tpl b/charts/spire/charts/spike-nexus/templates/_helpers.tpl new file mode 100644 index 0000000..22df59e --- /dev/null +++ b/charts/spire/charts/spike-nexus/templates/_helpers.tpl @@ -0,0 +1,83 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "spike-nexus.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "spike-nexus.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Allow the release namespace to be overridden for multi-namespace deployments in combined charts +*/}} +{{- define "spike-nexus.namespace" -}} + {{- if .Values.namespaceOverride -}} + {{- .Values.namespaceOverride -}} + {{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }} + {{- if ne (len (dig "spire" "namespaces" "server" "name" "" .Values.global)) 0 }} + {{- .Values.global.spire.namespaces.server.name }} + {{- else }} + {{- printf "spire-server" }} + {{- end }} + {{- else -}} + {{- .Release.Namespace -}} + {{- end -}} +{{- end -}} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "spike-nexus.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "spike-nexus.labels" -}} +helm.sh/chart: {{ include "spike-nexus.chart" . }} +{{ include "spike-nexus.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "spike-nexus.selectorLabels" -}} +app.kubernetes.io/name: {{ include "spike-nexus.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} + +{{/* +Create the name of the service account to use +*/}} +{{- define "spike-nexus.serviceAccountName" -}} +{{- if .Values.serviceAccount.create }} +{{- default (include "spike-nexus.fullname" .) .Values.serviceAccount.name }} +{{- else }} +{{- default "default" .Values.serviceAccount.name }} +{{- end }} +{{- end }} + +{{- define "spike-nexus.workload-api-socket-path" -}} +{{- printf "/spiffe-workload-api/%s" .Values.agentSocketName }} +{{- end }} diff --git a/charts/spire/charts/spike-nexus/templates/ingress.yaml b/charts/spire/charts/spike-nexus/templates/ingress.yaml new file mode 100644 index 0000000..82c1b8a --- /dev/null +++ b/charts/spire/charts/spike-nexus/templates/ingress.yaml @@ -0,0 +1,31 @@ +{{- if .Values.ingress.enabled -}} +{{ $root := . }} +{{- $ingressControllerType := include "spire-lib.ingress-controller-type" (dict "global" .Values.global "ingress" .Values.ingress) }} +{{- $fullName := include "spike-nexus.fullname" . -}} +{{- $tlsSection := true }} +{{- $annotations := deepCopy .Values.ingress.annotations }} +{{- if eq $ingressControllerType "ingress-nginx" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-redirect" "true" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/force-ssl-redirect" "true" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/backend-protocol" "HTTPS" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-passthrough" "true" }} +{{- else if eq $ingressControllerType "openshift" }} +{{- $path = "" }} +{{- $_ := set $annotations "route.openshift.io/termination" "passthrough" }} +{{- $tlsSection = false }} +{{- end }} +{{ $last := sub (.Values.replicas | int) 1 | int }} +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: {{ $fullName }} + namespace: {{ include "spike-nexus.namespace" $root }} + labels: + {{ include "spike-nexus.labels" $root | nindent 4}} + {{- with $annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + {{ include "spire-lib.ingress-spec" (dict "ingress" .Values.ingress "svcName" $fullName "port" $root.Values.service.port "path" "/" "pathType" "Prefix" "tlsSection" $tlsSection "Values" $root.Values) | nindent 2 }} +{{- end }} diff --git a/charts/spire/charts/spike-nexus/templates/service.yaml b/charts/spire/charts/spike-nexus/templates/service.yaml new file mode 100644 index 0000000..40d2733 --- /dev/null +++ b/charts/spire/charts/spike-nexus/templates/service.yaml @@ -0,0 +1,20 @@ +{{ $root := . }} +apiVersion: v1 +kind: Service +metadata: + namespace: {{ include "spike-nexus.namespace" $root }} + name: {{ include "spike-nexus.fullname" $root }} + {{- with $root.Values.service.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + labels: + {{- include "spike-nexus.labels" $root | nindent 4 }} +spec: + type: {{ $root.Values.service.type }} + selector: + {{- include "spike-nexus.selectorLabels" $root | nindent 4 }} + ports: + - name: {{ include "spike-nexus.fullname" $root }} + port: {{ $root.Values.service.port }} + targetPort: http diff --git a/charts/spire/charts/spike-nexus/templates/serviceaccount.yaml b/charts/spire/charts/spike-nexus/templates/serviceaccount.yaml new file mode 100644 index 0000000..01380df --- /dev/null +++ b/charts/spire/charts/spike-nexus/templates/serviceaccount.yaml @@ -0,0 +1,13 @@ +{{- if .Values.serviceAccount.create -}} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ include "spike-nexus.serviceAccountName" . }} + namespace: {{ include "spike-nexus.namespace" . }} + labels: + {{- include "spike-nexus.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +{{- end }} diff --git a/charts/spire/charts/spike-nexus/templates/statefulset.yaml b/charts/spire/charts/spike-nexus/templates/statefulset.yaml new file mode 100644 index 0000000..1dfeb6b --- /dev/null +++ b/charts/spire/charts/spike-nexus/templates/statefulset.yaml @@ -0,0 +1,112 @@ +apiVersion: apps/v1 +kind: StatefulSet +metadata: + name: {{ include "spike-nexus.fullname" . }} + namespace: {{ include "spike-nexus.namespace" . }} + labels: + {{- include "spike-nexus.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicas }} + selector: + matchLabels: + {{- include "spike-nexus.selectorLabels" . | nindent 6 }} + template: + metadata: + labels: + {{- include "spike-nexus.selectorLabels" . | nindent 8 }} + release: {{ .Release.Name }} + release-namespace: {{ .Release.Namespace }} + component: spike-nexus + spec: + {{- with .Values.imagePullSecrets }} + imagePullSecrets: + {{- toYaml . | nindent 8 }} + {{- end }} + serviceAccountName: {{ include "spike-nexus.serviceAccountName" . }} + securityContext: + {{- include "spire-lib.podsecuritycontext" . | nindent 8 }} + containers: + - name: {{ include "spike-nexus.fullname" . }} + image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image "global" .Values.global "ubi" true) }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + securityContext: + {{- include "spire-lib.securitycontext" . | nindent 12 }} + ports: + - name: http + containerPort: 8443 + protocol: TCP + env: + - name: SPIKE_NEXUS_SHAMIR_SHARES + value: {{ .Values.shamir.shares | quote }} + - name: SPIKE_NEXUS_SHAMIR_THRESHOLD + value: {{ .Values.shamir.threshold | quote }} + # Note: IP will depend on the testbed. + - name: SPIKE_NEXUS_KEEPER_PEERS + {{- if gt (len .Values.keeperPeers) 0 }} + value: {{ .Values.keeperPeers | join "," | quote }} + {{- else }} + value: https://{{ .Release.Name }}-spike-keeper-0.{{ .Release.Name }}-spike-keeper-headless:8443,https://{{ .Release.Name }}-spike-keeper-1.{{ .Release.Name }}-spike-keeper-headless:8443,https://{{ .Release.Name }}-spike-keeper-2.{{ .Release.Name }}-spike-keeper-headless:8443 + {{- end }} + - name: SPIFFE_ENDPOINT_SOCKET + value: unix://{{ include "spike-nexus.workload-api-socket-path" . }} + - name: SPIKE_SYSTEM_LOG_LEVEL + value: {{ .Values.logLevel | upper }} + - name: SPIKE_TRUST_ROOT + value: {{ include "spire-lib.trust-domain" . }} + - name: SPIKE_TRUST_ROOT_KEEPER + value: {{ if gt (len .Values.trustRoot.keepers) 0 }}{{ .Values.trustRoot.keepers | join "," | quote}}{{ else }}{{ include "spire-lib.trust-domain" . }}{{ end }} + - name: SPIKE_TRUST_ROOT_PILOT + value: {{if eq .Values.trustRoot.pilot "" }}{{ include "spire-lib.trust-domain" . }}{{ else }}{{.Values.trustRoot.pilot }}{{ end }} + - name: SPIKE_NEXUS_TLS_PORT + value: ":8443" + {{- if .Values.startupProbe.enabled }} + startupProbe: + tcpSocket: + port: 8443 + failureThreshold: {{ .Values.startupProbe.failureThreshold }} + initialDelaySeconds: {{ .Values.startupProbe.initialDelaySeconds }} + periodSeconds: {{ .Values.startupProbe.periodSeconds }} + successThreshold: {{ .Values.startupProbe.successThreshold }} + timeoutSeconds: {{ .Values.startupProbe.timeoutSeconds }} + {{- end }} + volumeMounts: + - name: spiffe-workload-api + mountPath: {{ include "spike-nexus.workload-api-socket-path" . | dir }} + readOnly: true + - name: nexus-data + mountPath: /.spike + {{- with .Values.nodeSelector }} + + nodeSelector: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.tolerations }} + tolerations: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.topologySpreadConstraints }} + topologySpreadConstraints: + {{- toYaml . | nindent 8 }} + {{- end }} + volumes: + - name: spiffe-workload-api + csi: + driver: "{{ .Values.csiDriverName }}" + readOnly: true + volumeClaimTemplates: + - metadata: + name: nexus-data + spec: + accessModes: + - {{ .Values.persistence.accessMode | default "ReadWriteOnce" }} + resources: + requests: + storage: {{ .Values.persistence.size }} + {{- $storageClass := (dig "spire" "persistence" "storageClass" nil .Values.global) | default .Values.persistence.storageClass }} + {{- if $storageClass }} + storageClassName: {{ $storageClass }} + {{- end }} diff --git a/charts/spire/charts/spike-nexus/values.yaml b/charts/spire/charts/spike-nexus/values.yaml new file mode 100644 index 0000000..4d51f78 --- /dev/null +++ b/charts/spire/charts/spike-nexus/values.yaml @@ -0,0 +1,172 @@ +# Default configuration for SPIKE Keeper +# SPDX-License-Identifier: APACHE-2.0 + +## @skip global +global: {} + +## @section Chart parameters +## +## @param image.registry The OCI registry to pull the image from +## @param image.repository The repository within the registry +## @param image.pullPolicy The image pull policy +## @param image.tag Overrides the image tag whose default is the chart appVersion +## +image: + registry: ghcr.io + repository: spiffe/spike-nexus + pullPolicy: IfNotPresent + tag: "" + +## @param replicas The number of keepers to launch +replicas: 1 + +shamir: + ## @param shamir.shares How many shares to configure for shamir secrets + shares: 3 + ## @param shamir.threshold How many shares needed to recover + threshold: 2 + +## @param keeperPeers Keeper peer configuration. If blank, it will be autodetected +keeperPeers: [] + +trustRoot: + ## @param trustRoot.nexus Override which trustRoot Nexus is in + nexus: "" + ## @param trustRoot.keepers Override which trustRoot Keepers are in + keepers: [] + ## @param trustRoot.pilot Override which trustRoot Pilot is in + pilot: "" + +## @param logLevel The log level, valid values are "debug", "info", "warn", and "error" +logLevel: debug + +## @param agentSocketName The name of the spire-agent unix socket +agentSocketName: spire-agent.sock +## @param csiDriverName The csi driver to use +csiDriverName: csi.spiffe.io + +## @param imagePullSecrets [array] Pull secrets for images +imagePullSecrets: [] + +## @param nameOverride Name override +nameOverride: "" + +## @param namespaceOverride Namespace override +namespaceOverride: "" + +## @param fullnameOverride Fullname override +fullnameOverride: "" + +## @param serviceAccount.create Specifies whether a service account should be created +## @param serviceAccount.annotations [object] Annotations to add to the service account +## @param serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated. +## +serviceAccount: + create: true + annotations: {} + name: "" + +## @param labels [object] Labels for pods +labels: {} + +## @param podSecurityContext [object] Pod security context +podSecurityContext: {} + # fsGroup: 2000 + +## @param securityContext [object] Security context +securityContext: + # capabilities: + # drop: + # - ALL + # readOnlyRootFilesystem: true + runAsNonRoot: true + runAsUser: 1000 + +## @param service.type Service type +## @param service.port Service port +## @param service.annotations Annotations for service resource +## +service: + type: ClusterIP + port: 443 + annotations: {} + +## @param nodeSelector (Optional) Select specific nodes to run on. +nodeSelector: {} + +## @param affinity [object] Affinity rules +affinity: {} + +## @param tolerations [array] List of tolerations +tolerations: [] + +## @param topologySpreadConstraints [array] List of topology spread constraints for resilience +topologySpreadConstraints: [] + +## Provide minimal resources to prevent accidental crashes due to resource exhaustion +# resources: +# requests: +# cpu: 50m +# memory: 128Mi +# limits: +# cpu: 100m +# memory: 512Mi + +## Configure extra options for startup probe +## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-startup-probes +## @param startupProbe.enabled Enable startupProbe +## @param startupProbe.initialDelaySeconds Initial delay seconds for startupProbe +## @param startupProbe.periodSeconds Period seconds for startupProbe +## @param startupProbe.timeoutSeconds Timeout seconds for startupProbe +## @param startupProbe.failureThreshold Failure threshold count for startupProbe +## @param startupProbe.successThreshold Success threshold count for startupProbe +## +startupProbe: + enabled: true + initialDelaySeconds: 5 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 6 + successThreshold: 1 + +## @param ingress.enabled Flag to enable ingress +## @param ingress.className Ingress class name +## @param ingress.controllerType Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. +## @param ingress.annotations [object] Annotations +ingress: + enabled: false + className: "" + controllerType: "" + annotations: {} + + ## @param ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. + host: "nexus" + + ## @param ingress.tlsSecret Secret that has the certs. If blank will use default certs. Used with host var. + tlsSecret: "" + + ## @param ingress.hosts [array] Host paths for ingress object. If empty, rules will be built based on the host var. + hosts: [] + # - host: nexus.example.org + # paths: + # - path: / + # pathType: Prefix + + ## @param ingress.tls [array] Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. + tls: [] + # - secretName: chart-example-tls + # hosts: + # - nexus.example.org + +## @param persistence.type What type of volume to use for persistence. Valid options pvc (recommended), hostPath, emptyDir (testing only) +## @param persistence.size What size volume to use for persistence +## @param persistence.accessMode What access mode to use for persistence. Valid options are ReadWriteOnce (recommended), ReadWriteOncePod, ReadWriteMany (not recommended) +## @param persistence.storageClass What storage class to use for persistence +## @param persistence.hostPath Which path to use on the host when persistence.type = hostPath +## +persistence: + type: pvc + size: 1Gi + accessMode: ReadWriteOnce + storageClass: null + hostPath: "" diff --git a/charts/spire/charts/spike-pilot/Chart.yaml b/charts/spire/charts/spike-pilot/Chart.yaml new file mode 100644 index 0000000..34c265a --- /dev/null +++ b/charts/spire/charts/spike-pilot/Chart.yaml @@ -0,0 +1,13 @@ +apiVersion: v2 +name: spike-pilot +description: A Helm chart to deploy SPIKE Pilot +type: application +version: 0.1.0 +appVersion: "0.4.1" +home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire +sources: + - https://github.com/spiffe/spike +icon: https://spike.ist/assets/spike-banner.png +maintainers: + - name: kfox1111 + email: Kevin.Fox@pnnl.gov diff --git a/charts/spire/charts/spike-pilot/README.md b/charts/spire/charts/spike-pilot/README.md new file mode 100644 index 0000000..0bc3b31 --- /dev/null +++ b/charts/spire/charts/spike-pilot/README.md @@ -0,0 +1,63 @@ +# spike-pilot + +![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v0.4.1](https://img.shields.io/badge/AppVersion-v0.4.1-informational?style=flat-square) +[![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) + +A Helm chart to deploy spike pilot + +**Homepage:** + +## Version support + +> [!Note] +> This Chart is still in development and still subject to change the API (`values.yaml`). +> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although +> we do aim for as much stability as possible. + +| Dependency | Supported Versions | +|:-----------|:-------------------| +| Helm | `3.x` | + +## Source Code + +* + + + +## Parameters + +### Chart parameters + +| Name | Description | Value | +| -------------------------------- | ------------------------------------------------------------------------------------------- | -------------------- | +| `image.registry` | The OCI registry to pull the image from | `ghcr.io` | +| `image.repository` | The repository within the registry | `spiffe/spike-pilot` | +| `image.pullPolicy` | The image pull policy | `IfNotPresent` | +| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` | +| `shell.image.registry` | The OCI registry to pull the image from | `""` | +| `shell.image.repository` | The repository within the registry | `busybox` | +| `shell.image.pullPolicy` | The image pull policy | `IfNotPresent` | +| `shell.image.tag` | Overrides the image tag whose default is the chart appVersion | `1.37.0-uclibc` | +| `tools.busybox.image.registry` | The OCI registry to pull the image from | `""` | +| `tools.busybox.image.repository` | The repository within the registry | `busybox` | +| `tools.busybox.image.pullPolicy` | The image pull policy | `IfNotPresent` | +| `tools.busybox.image.tag` | Overrides the image tag whose default is the chart appVersion | `1.37.0-uclibc` | +| `replicas` | The number of keepers to launch | `1` | +| `trustRoot.nexus` | Override which trustRoot Nexus is in | `""` | +| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `debug` | +| `agentSocketName` | The name of the spire-agent unix socket | `spire-agent.sock` | +| `csiDriverName` | The csi driver to use | `csi.spiffe.io` | +| `imagePullSecrets` | Pull secrets for images | `[]` | +| `nameOverride` | Name override | `""` | +| `namespaceOverride` | Namespace override | `""` | +| `fullnameOverride` | Fullname override | `""` | +| `serviceAccount.create` | Specifies whether a service account should be created | `true` | +| `serviceAccount.annotations` | Annotations to add to the service account | `{}` | +| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` | +| `labels` | Labels for pods | `{}` | +| `podSecurityContext` | Pod security context | `{}` | +| `securityContext` | Security context | `{}` | +| `nodeSelector` | (Optional) Select specific nodes to run on. | `{}` | +| `affinity` | Affinity rules | `{}` | +| `tolerations` | List of tolerations | `[]` | +| `topologySpreadConstraints` | List of topology spread constraints for resilience | `[]` | diff --git a/charts/spire/charts/spike-pilot/templates/NOTES.txt b/charts/spire/charts/spike-pilot/templates/NOTES.txt new file mode 100644 index 0000000..dfe3e24 --- /dev/null +++ b/charts/spire/charts/spike-pilot/templates/NOTES.txt @@ -0,0 +1 @@ +Installed {{ .Chart.Name }}… diff --git a/charts/spire/charts/spike-pilot/templates/_helpers.tpl b/charts/spire/charts/spike-pilot/templates/_helpers.tpl new file mode 100644 index 0000000..899776d --- /dev/null +++ b/charts/spire/charts/spike-pilot/templates/_helpers.tpl @@ -0,0 +1,83 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "spike-pilot.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "spike-pilot.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Allow the release namespace to be overridden for multi-namespace deployments in combined charts +*/}} +{{- define "spike-pilot.namespace" -}} + {{- if .Values.namespaceOverride -}} + {{- .Values.namespaceOverride -}} + {{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }} + {{- if ne (len (dig "spire" "namespaces" "server" "name" "" .Values.global)) 0 }} + {{- .Values.global.spire.namespaces.server.name }} + {{- else }} + {{- printf "spire-server" }} + {{- end }} + {{- else -}} + {{- .Release.Namespace -}} + {{- end -}} +{{- end -}} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "spike-pilot.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "spike-pilot.labels" -}} +helm.sh/chart: {{ include "spike-pilot.chart" . }} +{{ include "spike-pilot.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "spike-pilot.selectorLabels" -}} +app.kubernetes.io/name: {{ include "spike-pilot.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} + +{{/* +Create the name of the service account to use +*/}} +{{- define "spike-pilot.serviceAccountName" -}} +{{- if .Values.serviceAccount.create }} +{{- default (include "spike-pilot.fullname" .) .Values.serviceAccount.name }} +{{- else }} +{{- default "default" .Values.serviceAccount.name }} +{{- end }} +{{- end }} + +{{- define "spike-pilot.workload-api-socket-path" -}} +{{- printf "/spiffe-workload-api/%s" .Values.agentSocketName }} +{{- end }} diff --git a/charts/spire/charts/spike-pilot/templates/deployment.yaml b/charts/spire/charts/spike-pilot/templates/deployment.yaml new file mode 100644 index 0000000..0c0958a --- /dev/null +++ b/charts/spire/charts/spike-pilot/templates/deployment.yaml @@ -0,0 +1,96 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "spike-pilot.fullname" . }} + namespace: {{ include "spike-pilot.namespace" . }} + labels: + {{- include "spike-pilot.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicas }} + selector: + matchLabels: + {{- include "spike-pilot.selectorLabels" . | nindent 6 }} + template: + metadata: + labels: + {{- include "spike-pilot.selectorLabels" . | nindent 8 }} + release: {{ .Release.Name }} + release-namespace: {{ .Release.Namespace }} + component: spike-pilot + spec: + {{- with .Values.imagePullSecrets }} + imagePullSecrets: + {{- toYaml . | nindent 8 }} + {{- end }} + serviceAccountName: {{ include "spike-pilot.serviceAccountName" . }} + securityContext: + {{- include "spire-lib.podsecuritycontext" . | nindent 8 }} + initContainers: + - name: init + image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.tools.busybox.image "global" .Values.global "ubi" true) }} + imagePullPolicy: {{ .Values.tools.busybox.image.pullPolicy }} + command: ["/bin/sh", "-c", "cp -a /bin/busybox /data"] + securityContext: + {{- include "spire-lib.securitycontext" . | nindent 12 }} + volumeMounts: + - name: pilot + mountPath: /data + - name: init2 + image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image "global" .Values.global "ubi" true) }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: ["/data/busybox", "sh", "-c", "/data/busybox cp -a /usr/local/bin/spike /data && /data/busybox rm -f /data/busybox"] + securityContext: + {{- include "spire-lib.securitycontext" . | nindent 12 }} + volumeMounts: + - name: pilot + mountPath: /data + containers: + - name: {{ include "spike-pilot.fullname" . }} + image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.shell.image "global" .Values.global "ubi" true) }} + imagePullPolicy: {{ .Values.shell.image.pullPolicy }} + command: ["/bin/sh", "-c", "echo I live; while true; do sleep 1000; done"] + securityContext: + {{- include "spire-lib.securitycontext" . | nindent 12 }} + env: + #FIXME make this configurable + - name: SPIKE_NEXUS_API_URL + value: https://{{ .Release.Name }}-spike-nexus:443 + - name: SPIFFE_ENDPOINT_SOCKET + value: unix://{{ include "spike-pilot.workload-api-socket-path" . }} + - name: SPIKE_SYSTEM_LOG_LEVEL + value: {{ .Values.logLevel | upper }} + - name: SPIKE_TRUST_ROOT + value: {{ include "spire-lib.trust-domain" . }} + - name: SPIKE_TRUST_ROOT_NEXUS + value: {{if eq .Values.trustRoot.Nexus "" }}{{ include "spire-lib.trust-domain" . }}{{ else }}{{.Values.trustRoot.Nexus }}{{ end }} + volumeMounts: + - name: spiffe-workload-api + mountPath: {{ include "spike-pilot.workload-api-socket-path" . | dir }} + readOnly: true + - name: pilot + mountPath: /bin/spike + subPath: spike + readOnly: true + {{- with .Values.nodeSelector }} + nodeSelector: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.tolerations }} + tolerations: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.topologySpreadConstraints }} + topologySpreadConstraints: + {{- toYaml . | nindent 8 }} + {{- end }} + volumes: + - name: pilot + emptyDir: {} + - name: spiffe-workload-api + csi: + driver: "{{ .Values.csiDriverName }}" + readOnly: true diff --git a/charts/spire/charts/spike-pilot/templates/serviceaccount.yaml b/charts/spire/charts/spike-pilot/templates/serviceaccount.yaml new file mode 100644 index 0000000..47daf93 --- /dev/null +++ b/charts/spire/charts/spike-pilot/templates/serviceaccount.yaml @@ -0,0 +1,13 @@ +{{- if .Values.serviceAccount.create -}} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ include "spike-pilot.serviceAccountName" . }} + namespace: {{ include "spike-pilot.namespace" . }} + labels: + {{- include "spike-pilot.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +{{- end }} diff --git a/charts/spire/charts/spike-pilot/values.yaml b/charts/spire/charts/spike-pilot/values.yaml new file mode 100644 index 0000000..6bf2310 --- /dev/null +++ b/charts/spire/charts/spike-pilot/values.yaml @@ -0,0 +1,116 @@ +# Default configuration for SPIKE Keeper +# SPDX-License-Identifier: APACHE-2.0 + +## @skip global +global: {} + +## @section Chart parameters +## +## @param image.registry The OCI registry to pull the image from +## @param image.repository The repository within the registry +## @param image.pullPolicy The image pull policy +## @param image.tag Overrides the image tag whose default is the chart appVersion +## +image: + registry: ghcr.io + repository: spiffe/spike-pilot + pullPolicy: IfNotPresent + tag: "" + +shell: + ## @param shell.image.registry The OCI registry to pull the image from + ## @param shell.image.repository The repository within the registry + ## @param shell.image.pullPolicy The image pull policy + ## @param shell.image.tag Overrides the image tag whose default is the chart appVersion + ## + image: + registry: "" + repository: busybox + pullPolicy: IfNotPresent + tag: 1.37.0-uclibc + +tools: + busybox: + ## @param tools.busybox.image.registry The OCI registry to pull the image from + ## @param tools.busybox.image.repository The repository within the registry + ## @param tools.busybox.image.pullPolicy The image pull policy + ## @param tools.busybox.image.tag Overrides the image tag whose default is the chart appVersion + ## + image: + registry: "" + repository: busybox + pullPolicy: IfNotPresent + tag: 1.37.0-uclibc + +## @param replicas The number of keepers to launch +replicas: 1 + +trustRoot: + ## @param trustRoot.nexus Override which trustRoot Nexus is in + nexus: "" + +## @param logLevel The log level, valid values are "debug", "info", "warn", and "error" +logLevel: debug + +## @param agentSocketName The name of the spire-agent unix socket +agentSocketName: spire-agent.sock +## @param csiDriverName The csi driver to use +csiDriverName: csi.spiffe.io + +## @param imagePullSecrets [array] Pull secrets for images +imagePullSecrets: [] + +## @param nameOverride Name override +nameOverride: "" + +## @param namespaceOverride Namespace override +namespaceOverride: "" + +## @param fullnameOverride Fullname override +fullnameOverride: "" + +## @param serviceAccount.create Specifies whether a service account should be created +## @param serviceAccount.annotations [object] Annotations to add to the service account +## @param serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated. +## +serviceAccount: + create: true + annotations: {} + name: "" + +## @param labels [object] Labels for pods +labels: {} + +## @param podSecurityContext [object] Pod security context +podSecurityContext: {} + # fsGroup: 2000 + +## @param securityContext [object] Security context +securityContext: {} + # capabilities: + # drop: + # - ALL + # readOnlyRootFilesystem: true + # runAsNonRoot: true + # runAsUser: 1000 + +## @param nodeSelector (Optional) Select specific nodes to run on. +nodeSelector: {} + +## @param affinity [object] Affinity rules +affinity: {} + +## @param tolerations [array] List of tolerations +tolerations: [] + +## @param topologySpreadConstraints [array] List of topology spread constraints for resilience +topologySpreadConstraints: [] + +## Provide minimal resources to prevent accidental crashes due to resource exhaustion +# resources: +# requests: +# cpu: 50m +# memory: 128Mi +# limits: +# cpu: 100m +# memory: 512Mi diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index 172716a..717b1ae 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -311,6 +311,15 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.dnsNameTemplates` | DNS name template for issued identities | `[]` | | `controllerManager.identities.clusterSPIFFEIDs.test-keys.enabled` | Enable this identity for controller manager | `true` | | `controllerManager.identities.clusterSPIFFEIDs.test-keys.type` | The type of rule this is. | `test-keys` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.enabled` | Enable this identity for controller manager | `true` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.type` | The type of rule this is. | `spike-keeper` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/keeper` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.enabled` | Enable this identity for controller manager | `true` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.type` | The type of rule this is. | `spike-nexus` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/nexus` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.enabled` | Enable this identity for controller manager | `true` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.type` | The type of rule this is. | `spike-pilot` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/pilot/role/superuser` | | `controllerManager.identities.clusterStaticEntries` | Specify ClusterStaticEntry objects. | `{}` | | `controllerManager.identities.clusterFederatedTrustDomains` | Specify ClusterFederatedTrustDomain objects. | `{}` | | `controllerManager.validatingWebhookConfiguration.enabled` | Disable only when you have another chart instance on the k8s cluster with webhooks enabled. | `true` | diff --git a/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml b/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml index f16c4de..26027a8 100644 --- a/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml +++ b/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml @@ -17,6 +17,21 @@ matchLabels: release: {{ .Release.Name }} release-namespace: {{ .Release.Namespace }} component: oidc-discovery-provider +{{- else if eq .type "spike-keeper" }} +matchLabels: + release: {{ .Release.Name }} + release-namespace: {{ .Release.Namespace }} + component: spike-keeper +{{- else if eq .type "spike-nexus" }} +matchLabels: + release: {{ .Release.Name }} + release-namespace: {{ .Release.Namespace }} + component: spike-nexus +{{- else if eq .type "spike-pilot" }} +matchLabels: + release: {{ .Release.Name }} + release-namespace: {{ .Release.Namespace }} + component: spike-pilot {{- else if eq .type "test-keys" }} matchLabels: release: {{ .Release.Name }} @@ -38,8 +53,8 @@ matchLabels: {{- if eq ($root.Values.controllerManager.enabled | toString) "true" }} {{- if or (not (hasKey $value "enabled")) (eq ($value.enabled | toString) "true") }} {{- $type := dig "type" "base" $value }} -{{- if not (has $type (list "base" "raw" "child-servers" "oidc-discovery-provider" "test-keys")) }} -{{- fail (printf "Type given: %s, must be one of [base, raw, child-servers, oidc-discovery-provider, test-keys]" $type) }} +{{- if not (has $type (list "base" "raw" "child-servers" "oidc-discovery-provider" "spike-keeper" "spike-nexus" "spike-pilot" "test-keys")) }} +{{- fail (printf "Type given: %s, must be one of [base, raw, child-servers, oidc-discovery-provider, spike-keeper, spike-nexus, spike-pilot, test-keys]" $type) }} {{- end }} {{- $namespaceSelector := deepCopy (dig "namespaceSelector" (dict) $value) }} {{- if ne $type "raw" }} diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index fb24a49..710e2d0 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -695,6 +695,28 @@ controllerManager: ## @param controllerManager.identities.clusterSPIFFEIDs.test-keys.type The type of rule this is. type: test-keys + spike-keeper: + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-keeper.enabled Enable this identity for controller manager + enabled: true + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-keeper.type The type of rule this is. + type: spike-keeper + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-keeper.spiffeIDTemplate The template to use for this rule. + spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spike/keeper + spike-nexus: + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-nexus.enabled Enable this identity for controller manager + enabled: true + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-nexus.type The type of rule this is. + type: spike-nexus + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-nexus.spiffeIDTemplate The template to use for this rule. + spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spike/nexus + spike-pilot: + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-pilot.enabled Enable this identity for controller manager + enabled: true + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-pilot.type The type of rule this is. + type: spike-pilot + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-pilot.spiffeIDTemplate The template to use for this rule. + spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spike/pilot/role/superuser + # You can specify additional ClusterSPIFFEIDs following this example: # foo: # labels: diff --git a/charts/spire/values.yaml b/charts/spire/values.yaml index bb76fee..1cff2cf 100644 --- a/charts/spire/values.yaml +++ b/charts/spire/values.yaml @@ -219,3 +219,24 @@ spiffe-oidc-discovery-provider: tornjak-frontend: ## @param tornjak-frontend.enabled Enables deployment of Tornjak frontend/UI (Not for production) enabled: false + +## @section SPIKE Keeper parameters +## Parameter values for SPIKE Keeper +## +spike-keeper: + ## @param spike-keeper.enabled Enables deployment of SPIKE Keeper (Not for production) + enabled: false + +## @section SPIKE Nexus parameters +## Parameter values for SPIKE Nexus +## +spike-nexus: + ## @param spike-nexus.enabled Enables deployment of SPIKE Nexus (Not for production) + enabled: false + +## @section SPIKE Pilot parameters +## Parameter values for SPIKE Pilot +## +spike-pilot: + ## @param spike-pilot.enabled Enables deployment of SPIKE Pilot (Not for production) + enabled: false diff --git a/examples/spike/values.yaml b/examples/spike/values.yaml new file mode 100644 index 0000000..bda38ae --- /dev/null +++ b/examples/spike/values.yaml @@ -0,0 +1,15 @@ +global: + spire: + ingressControllerType: ingress-nginx +spike-keeper: + enabled: true + #ingress: + # enabled: true + # className: nginx +spike-nexus: + enabled: true + ingress: + enabled: true + className: nginx +spike-pilot: + enabled: true From b74b10a0f6035e5f9112eafec926ce13ed65eb64 Mon Sep 17 00:00:00 2001 From: "spire-helm-version-checker[bot]" <161522935+spire-helm-version-checker[bot]@users.noreply.github.com> Date: Mon, 30 Jun 2025 06:08:14 -0700 Subject: [PATCH 11/16] Bump test chart dependencies (#615) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com> --- .github/tests/charts.json | 2 +- .../spire/charts/spiffe-oidc-discovery-provider/README.md | 6 +++--- .../spire/charts/spiffe-oidc-discovery-provider/values.yaml | 6 +++--- charts/spire/charts/spire-agent/README.md | 6 +++--- charts/spire/charts/spire-agent/values.yaml | 6 +++--- charts/spire/charts/spire-server/README.md | 4 ++-- charts/spire/charts/spire-server/values.yaml | 4 ++-- charts/spire/charts/tornjak-frontend/README.md | 2 +- charts/spire/charts/tornjak-frontend/values.yaml | 2 +- 9 files changed, 19 insertions(+), 19 deletions(-) diff --git a/.github/tests/charts.json b/.github/tests/charts.json index 879cdd0..007acf2 100644 --- a/.github/tests/charts.json +++ b/.github/tests/charts.json @@ -2,7 +2,7 @@ { "name": "kube-prometheus-stack", "repo": "https://prometheus-community.github.io/helm-charts", - "version": "75.4.0" + "version": "75.6.1" }, { "name": "cert-manager", diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md index 7e5727e..8fab9b8 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md @@ -71,7 +71,7 @@ A Helm chart to install the SPIFFE OIDC discovery provider. | `insecureScheme.nginx.image.registry` | The OCI registry to pull the image from. Only used when TLS is disabled. | `docker.io` | | `insecureScheme.nginx.image.repository` | The repository within the registry. Only used when TLS is disabled. | `nginxinc/nginx-unprivileged` | | `insecureScheme.nginx.image.pullPolicy` | The image pull policy. Only used when TLS is disabled. | `IfNotPresent` | -| `insecureScheme.nginx.image.tag` | Overrides the image tag whose default is the chart appVersion. Only used when TLS is disabled. | `1.28.0-alpine` | +| `insecureScheme.nginx.image.tag` | Overrides the image tag whose default is the chart appVersion. Only used when TLS is disabled. | `1.29.0-alpine` | | `insecureScheme.nginx.ipMode` | IP modes supported by the cluster. Must be one of [ipv4, ipv6, both] | `both` | | `insecureScheme.nginx.resources` | Resource requests and limits | `{}` | | `jwtIssuer` | Path to JWT issuer. Defaults to oidc-discovery.$trustDomain if unset | `""` | @@ -120,11 +120,11 @@ A Helm chart to install the SPIFFE OIDC discovery provider. | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea` | | `tests.toolkit.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.toolkit.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` | | `tests.toolkit.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.toolkit.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9e3e978258955e1e6a4d855f83a1ce66146ca5de6a9e52bf75d3918fafe3e5a4` | +| `tests.toolkit.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:3dd03ca4056a6c8024ed1e5dc0999aa836c0c28777dcc3b85bd1d9d853e1ed38` | | `tests.step.image.registry` | The OCI registry to pull the image from | `docker.io` | | `tests.step.image.repository` | The repository within the registry | `smallstep/step-cli` | | `tests.step.image.pullPolicy` | The image pull policy | `IfNotPresent` | diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml index f2d7a77..613b131 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml @@ -170,7 +170,7 @@ insecureScheme: registry: docker.io repository: nginxinc/nginx-unprivileged pullPolicy: IfNotPresent - tag: 1.28.0-alpine + tag: 1.29.0-alpine ## @param insecureScheme.nginx.ipMode IP modes supported by the cluster. Must be one of [ipv4, ipv6, both] ipMode: both ## @param insecureScheme.nginx.resources Resource requests and limits @@ -340,7 +340,7 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a + tag: latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea toolkit: ## @param tests.toolkit.image.registry The OCI registry to pull the image from @@ -352,7 +352,7 @@ tests: registry: cgr.dev repository: chainguard/min-toolkit-debug pullPolicy: IfNotPresent - tag: latest@sha256:9e3e978258955e1e6a4d855f83a1ce66146ca5de6a9e52bf75d3918fafe3e5a4 + tag: latest@sha256:3dd03ca4056a6c8024ed1e5dc0999aa836c0c28777dcc3b85bd1d9d853e1ed38 step: ## @param tests.step.image.registry The OCI registry to pull the image from diff --git a/charts/spire/charts/spire-agent/README.md b/charts/spire/charts/spire-agent/README.md index ed41cba..92ea859 100644 --- a/charts/spire/charts/spire-agent/README.md +++ b/charts/spire/charts/spire-agent/README.md @@ -70,7 +70,7 @@ A Helm chart to install the SPIRE agent. | `fsGroupFix.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `fsGroupFix.image.repository` | The repository within the registry | `chainguard/bash` | | `fsGroupFix.image.pullPolicy` | The image pull policy | `Always` | -| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a` | +| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea` | | `fsGroupFix.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `keyManager.memory.enabled` | Enable the memory based Key Manager | `true` | | `nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s Node Attestor | `true` | @@ -114,12 +114,12 @@ A Helm chart to install the SPIRE agent. | `socketAlternate.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `socketAlternate.image.repository` | The repository within the registry | `chainguard/bash` | | `socketAlternate.image.pullPolicy` | The image pull policy | `Always` | -| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a` | +| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea` | | `socketAlternate.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `hostCert.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `hostCert.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` | | `hostCert.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `hostCert.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9e3e978258955e1e6a4d855f83a1ce66146ca5de6a9e52bf75d3918fafe3e5a4` | +| `hostCert.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:3dd03ca4056a6c8024ed1e5dc0999aa836c0c28777dcc3b85bd1d9d853e1ed38` | | `hostCert.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `priorityClassName` | Priority class assigned to daemonset pods. Can be auto set with global.recommendations.priorityClassName. | `""` | | `extraEnvVars` | Extra environment variables to be added to the Spire Agent container | `[]` | diff --git a/charts/spire/charts/spire-agent/values.yaml b/charts/spire/charts/spire-agent/values.yaml index af4fb81..22a3be7 100644 --- a/charts/spire/charts/spire-agent/values.yaml +++ b/charts/spire/charts/spire-agent/values.yaml @@ -153,7 +153,7 @@ fsGroupFix: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a + tag: latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea ## @param fsGroupFix.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -280,7 +280,7 @@ socketAlternate: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a + tag: latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea ## @param socketAlternate.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -295,7 +295,7 @@ hostCert: registry: cgr.dev repository: chainguard/min-toolkit-debug pullPolicy: IfNotPresent - tag: latest@sha256:9e3e978258955e1e6a4d855f83a1ce66146ca5de6a9e52bf75d3918fafe3e5a4 + tag: latest@sha256:3dd03ca4056a6c8024ed1e5dc0999aa836c0c28777dcc3b85bd1d9d853e1ed38 ## @param hostCert.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index 717b1ae..1673cc2 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -460,7 +460,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `chown.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `chown.image.repository` | The repository within the registry | `chainguard/bash` | | `chown.image.pullPolicy` | The image pull policy | `Always` | -| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a` | +| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea` | | `chown.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `experimental.enabled` | Allow configuration of experimental features | `false` | | `experimental.cacheReloadInterval` | The amount of time between two reloads of the in-memory entry cache. | `5s` | @@ -473,5 +473,5 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea` | | `kubeConfigs` | Manage additional kubeconfig files to talk to external Kubernetes clusters | `{}` | diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index 710e2d0..816fb8f 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -1170,7 +1170,7 @@ chown: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a + tag: latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea ## @param chown.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -1205,7 +1205,7 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a + tag: latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea ## @param kubeConfigs [object] Manage additional kubeconfig files to talk to external Kubernetes clusters kubeConfigs: {} diff --git a/charts/spire/charts/tornjak-frontend/README.md b/charts/spire/charts/tornjak-frontend/README.md index b8fd86c..2dd860c 100644 --- a/charts/spire/charts/tornjak-frontend/README.md +++ b/charts/spire/charts/tornjak-frontend/README.md @@ -101,4 +101,4 @@ port forwarding. See the chart NOTES output for more details. | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea` | diff --git a/charts/spire/charts/tornjak-frontend/values.yaml b/charts/spire/charts/tornjak-frontend/values.yaml index 69a3b41..6719a5e 100644 --- a/charts/spire/charts/tornjak-frontend/values.yaml +++ b/charts/spire/charts/tornjak-frontend/values.yaml @@ -162,4 +162,4 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:642933df66209814502599053ca3dfa97cccf847badc4219d2b1fd6565f6559a + tag: latest@sha256:eefb26b2a87b897e4dad65909dad8a7896fe3ed97aa76ac874fa3594011256ea From 892051c466eea40684b16570349ca1564f3e3100 Mon Sep 17 00:00:00 2001 From: kfox1111 Date: Tue, 1 Jul 2025 16:28:57 -0700 Subject: [PATCH 12/16] Update for 1.12.4 (#605) * Update for 1.12.3 Signed-off-by: Kevin Fox * Fix typo. Use test image Signed-off-by: Kevin Fox * Fix lint Signed-off-by: Kevin Fox * Fix format flag. Update config location for k8s configmap bp Signed-off-by: Kevin Fox * Fix role Signed-off-by: Kevin Fox * Update rbac Signed-off-by: Kevin Fox * Fix key Signed-off-by: Kevin Fox * Fix format Signed-off-by: Kevin Fox * Fix the bundle format for the fetchca bits Signed-off-by: Kevin Fox * Update key Signed-off-by: Kevin Fox * Fix test rather then reconfigure Signed-off-by: Kevin Fox * Add namespace Signed-off-by: Kevin Fox * Update to follow the new patch Signed-off-by: Kevin Fox * Fix formatting Signed-off-by: Kevin Fox * Fix formatting Signed-off-by: Kevin Fox * Update filename based on format Signed-off-by: Kevin Fox * Add upgrade notes Signed-off-by: Kevin Fox * Switch to testing nightly. Dont manage bundle configmap. Signed-off-by: Kevin Fox * Update permissions Signed-off-by: Kevin Fox * Update permissions Signed-off-by: Kevin Fox * Update permissions Signed-off-by: Kevin Fox * Update for final release Signed-off-by: Kevin Fox --------- Signed-off-by: Kevin Fox --- charts/spire-nested/Chart.yaml | 2 +- charts/spire-nested/README.md | 4 +- charts/spire-nested/values.yaml | 6 +-- charts/spire/Chart.yaml | 2 +- charts/spire/README.md | 7 ++- .../spiffe-oidc-discovery-provider/Chart.yaml | 2 +- charts/spire/charts/spire-agent/Chart.yaml | 2 +- charts/spire/charts/spire-agent/README.md | 2 +- .../spire-agent/templates/configmap.yaml | 4 +- charts/spire/charts/spire-agent/values.yaml | 2 +- .../charts/spire-lib/templates/_helpers.tpl | 8 ++++ charts/spire/charts/spire-server/Chart.yaml | 2 +- charts/spire/charts/spire-server/README.md | 13 ++++- .../spire-server/templates/_helpers.tpl | 26 +++++++++- .../templates/bundle-configmap.yaml | 5 ++ .../spire-server/templates/configmap.yaml | 47 ++++++++++++++++++- .../charts/spire-server/templates/roles.yaml | 7 ++- charts/spire/charts/spire-server/values.yaml | 28 ++++++++++- .../integration/spiffe-step-ssh/run-tests.sh | 2 +- 19 files changed, 146 insertions(+), 25 deletions(-) diff --git a/charts/spire-nested/Chart.yaml b/charts/spire-nested/Chart.yaml index ac14087..6c20050 100644 --- a/charts/spire-nested/Chart.yaml +++ b/charts/spire-nested/Chart.yaml @@ -4,7 +4,7 @@ description: > A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. type: application version: 0.25.0 -appVersion: "1.12.2" +appVersion: "1.12.4" keywords: ["spiffe", "spire", "spire-server", "spire-agent", "oidc", "spire-controller-manager"] home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire sources: diff --git a/charts/spire-nested/README.md b/charts/spire-nested/README.md index 2dd751e..78d9edd 100644 --- a/charts/spire-nested/README.md +++ b/charts/spire-nested/README.md @@ -1,6 +1,6 @@ # spire -![Version: 0.25.0](https://img.shields.io/badge/Version-0.25.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.2](https://img.shields.io/badge/AppVersion-1.12.2-informational?style=flat-square) +![Version: 0.25.0](https://img.shields.io/badge/Version-0.25.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.4](https://img.shields.io/badge/AppVersion-1.12.4-informational?style=flat-square) [![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. @@ -350,6 +350,6 @@ Now you can interact with the Spire agent socket from your own application. The | `external-spire-server.upstreamAuthority.spire.enabled` | Enable upstream SPIRE server | `true` | | `external-spire-server.upstreamAuthority.spire.upstreamDriver` | Use an upstream driver for authentication | `upstream.csi.spiffe.io` | | `external-spire-server.upstreamAuthority.spire.server.nameOverride` | The name override setting of the root SPIRE server | `root-server` | -| `external-spire-server.notifier.k8sBundle.enabled` | Enable local k8s bundle uploader | `false` | +| `external-spire-server.bundlePublisher.k8sConfigMap.enabled` | Enable local k8s bundle uploader | `false` | | `external-spire-server.nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s nodeattestor | `false` | | `external-spire-server.nodeAttestor.joinToken.enabled` | Enable the join_token nodeattestor | `true` | diff --git a/charts/spire-nested/values.yaml b/charts/spire-nested/values.yaml index 4465ade..3ef0315 100644 --- a/charts/spire-nested/values.yaml +++ b/charts/spire-nested/values.yaml @@ -384,9 +384,9 @@ external-spire-server: server: ## @param external-spire-server.upstreamAuthority.spire.server.nameOverride The name override setting of the root SPIRE server nameOverride: root-server - notifier: - k8sBundle: - ## @param external-spire-server.notifier.k8sBundle.enabled Enable local k8s bundle uploader + bundlePublisher: + k8sConfigMap: + ## @param external-spire-server.bundlePublisher.k8sConfigMap.enabled Enable local k8s bundle uploader enabled: false nodeAttestor: k8sPSAT: diff --git a/charts/spire/Chart.yaml b/charts/spire/Chart.yaml index 3ef2cad..4e00f7a 100644 --- a/charts/spire/Chart.yaml +++ b/charts/spire/Chart.yaml @@ -4,7 +4,7 @@ description: > A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. type: application version: 0.25.0 -appVersion: "1.12.2" +appVersion: "1.12.4" keywords: ["spiffe", "spire", "spire-server", "spire-agent", "oidc", "spire-controller-manager"] home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire sources: diff --git a/charts/spire/README.md b/charts/spire/README.md index 0fb63c3..7df685c 100644 --- a/charts/spire/README.md +++ b/charts/spire/README.md @@ -1,6 +1,6 @@ # spire -![Version: 0.25.0](https://img.shields.io/badge/Version-0.25.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.2](https://img.shields.io/badge/AppVersion-1.12.2-informational?style=flat-square) +![Version: 0.25.0](https://img.shields.io/badge/Version-0.25.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.4](https://img.shields.io/badge/AppVersion-1.12.4-informational?style=flat-square) [![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. @@ -88,6 +88,11 @@ kubectl delete crds clusterfederatedtrustdomains.spire.spiffe.io clusterspiffeid We only support upgrading one major/minor version at a time. Version skipping isn't supported. Please see for details. +### 0.26.X + +- The notifier.k8sBundle plugin has been deprecated in favor of bundlePublisher.k8sConfigMap. The only features it does not provide are the settings `apiServiceLabel` and `webhookLabel`. If you are using either of these two features, set the chart to use the notifier.k8sBundle plugin again, and let us know. We don't think anyone is using these features. +- The default trust bundle format has been changed to `spiffe`. This switch should be transparent unless you ware fetching the bundle from the configmap manually, or have a nested setup and dont upgrade the root, then child clusters in short order. + ### 0.24.X - You must upgrade [spire-crds](https://artifacthub.io/packages/helm/spiffe/spire-crds) to 0.5.0+ before performing this upgrade. diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml index 5fa67b0..81cec52 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml @@ -3,7 +3,7 @@ name: spiffe-oidc-discovery-provider description: A Helm chart to install the SPIFFE OIDC discovery provider. type: application version: 0.1.0 -appVersion: "1.12.2" +appVersion: "1.12.4" keywords: ["spiffe", "oidc"] home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire sources: diff --git a/charts/spire/charts/spire-agent/Chart.yaml b/charts/spire/charts/spire-agent/Chart.yaml index 4f121f7..816bb11 100644 --- a/charts/spire/charts/spire-agent/Chart.yaml +++ b/charts/spire/charts/spire-agent/Chart.yaml @@ -3,7 +3,7 @@ name: spire-agent description: A Helm chart to install the SPIRE agent. type: application version: 0.1.0 -appVersion: "1.12.2" +appVersion: "1.12.4" keywords: ["spiffe", "spire-agent"] home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire sources: diff --git a/charts/spire/charts/spire-agent/README.md b/charts/spire/charts/spire-agent/README.md index 92ea859..43fc74f 100644 --- a/charts/spire/charts/spire-agent/README.md +++ b/charts/spire/charts/spire-agent/README.md @@ -52,7 +52,7 @@ A Helm chart to install the SPIRE agent. | `clusterName` | The name of the Kubernetes cluster (`kubeadm init --service-dns-domain`) | `example-cluster` | | `trustDomain` | The trust domain to be used for the SPIFFE identifiers | `example.org` | | `trustBundleURL` | If set, obtain trust bundle from url instead of Kubernetes ConfigMap | `""` | -| `trustBundleFormat` | If using trustBundleURL, what format is the url. Choices are "pem" and "spiffe" | `pem` | +| `trustBundleFormat` | If using trustBundleURL, what format is the url. Choices are "pem" and "spiffe" | `spiffe` | | `trustBundleHostPath` | If set, obtain trust bundle from a file on the host instead of from the ConfigMap | `""` | | `bundleConfigMap` | Configmap name for Spire bundle | `spire-bundle` | | `availabilityTarget` | The minimum amount of time desired to gracefully handle SPIRE Server or Agent downtime. This configurable influences how aggressively X509 SVIDs should be rotated. If set, must be at least 24h. | `""` | diff --git a/charts/spire/charts/spire-agent/templates/configmap.yaml b/charts/spire/charts/spire-agent/templates/configmap.yaml index 1c62fb8..eb4253a 100644 --- a/charts/spire/charts/spire-agent/templates/configmap.yaml +++ b/charts/spire/charts/spire-agent/templates/configmap.yaml @@ -38,13 +38,13 @@ agent: server_address: {{ include "spire-agent.server-address" . | trim | quote }} server_port: {{ .Values.server.port | quote }} socket_path: /tmp/spire-agent/public/{{ include "spire-agent.socket-path" . | base }} + trust_bundle_format: {{ .Values.trustBundleFormat | quote }} {{- if ne (len .Values.trustBundleURL) 0 }} trust_bundle_url: {{ .Values.trustBundleURL | quote }} - trust_bundle_format: {{ .Values.trustBundleFormat | quote }} {{- else if ne (len .Values.trustBundleHostPath) 0 }} trust_bundle_path: {{ .Values.trustBundleHostPath | quote }} {{- else }} - trust_bundle_path: "/run/spire/bundle/bundle.crt" + trust_bundle_path: {{ printf "/run/spire/bundle/bundle.%s" (include "spire-lib.trust-bundle-ext" (dict "trustBundleFormat" .Values.trustBundleFormat)) | quote }} {{- end }} trust_domain: {{ include "spire-lib.trust-domain" . | quote }} {{- with .Values.availabilityTarget }} diff --git a/charts/spire/charts/spire-agent/values.yaml b/charts/spire/charts/spire-agent/values.yaml index 22a3be7..a7dd78a 100644 --- a/charts/spire/charts/spire-agent/values.yaml +++ b/charts/spire/charts/spire-agent/values.yaml @@ -94,7 +94,7 @@ trustDomain: example.org ## @param trustBundleURL If set, obtain trust bundle from url instead of Kubernetes ConfigMap trustBundleURL: "" ## @param trustBundleFormat If using trustBundleURL, what format is the url. Choices are "pem" and "spiffe" -trustBundleFormat: pem +trustBundleFormat: spiffe ## @param trustBundleHostPath If set, obtain trust bundle from a file on the host instead of from the ConfigMap trustBundleHostPath: "" ## @param bundleConfigMap Configmap name for Spire bundle diff --git a/charts/spire/charts/spire-lib/templates/_helpers.tpl b/charts/spire/charts/spire-lib/templates/_helpers.tpl index fab4700..7185d77 100644 --- a/charts/spire/charts/spire-lib/templates/_helpers.tpl +++ b/charts/spire/charts/spire-lib/templates/_helpers.tpl @@ -336,3 +336,11 @@ Anything lower has an incompatible API. {{- fail "Unsupported autoscaling API version" }} {{- end }} {{- end }} + +{{- define "spire-lib.trust-bundle-ext" -}} +{{- if eq .trustBundleFormat "spiffe" }} +{{- print "spiffe" }} +{{- else }} +{{- print "crt" }} +{{- end }} +{{- end }} diff --git a/charts/spire/charts/spire-server/Chart.yaml b/charts/spire/charts/spire-server/Chart.yaml index 17672ea..26dc991 100644 --- a/charts/spire/charts/spire-server/Chart.yaml +++ b/charts/spire/charts/spire-server/Chart.yaml @@ -3,7 +3,7 @@ name: spire-server description: A Helm chart to install the SPIRE server. type: application version: 0.1.0 -appVersion: "1.12.2" +appVersion: "1.12.4" keywords: ["spiffe", "spire-server", "spire-controller-manager"] home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire sources: diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index 1673cc2..e2ddab5 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -256,11 +256,11 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `upstreamAuthority.vault.k8sAuth.k8sAuthRoleName` | Required - Name of the Vault role. The plugin authenticates against the named role | `""` | | `upstreamAuthority.vault.k8sAuth.token.audience` | Intended audience of the PSAT, it must match one of the audiences supported by the Kubernetes API server. If no audience is specified, it defaults to the identifier of API Server. See ['Service Account Documentation'](https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/#serviceaccount-token-volume-projection) for more info. | `vault` | | `upstreamAuthority.vault.k8sAuth.token.expiry` | Expiry time in seconds for the token | `7200` | -| `notifier.k8sBundle.enabled` | Enable local k8s bundle uploader | `true` | +| `notifier.k8sBundle.enabled` | Enable local k8s bundle uploader | `false` | | `notifier.k8sBundle.namespace` | Namespace to push the bundle into, if blank will default to SPIRE Server namespace | `""` | | `notifier.k8sBundle.apiServiceLabel` | If set, rotate the CA Bundle in API services with this label set to true. | `""` | | `notifier.k8sBundle.webhookLabel` | If set, rotate the CA Bundle in validating and mutating webhooks with this label set to true. | `""` | -| `notifier.externalK8sBundle.enabled` | Enable external k8s bundle uploader | `true` | +| `notifier.externalK8sBundle.enabled` | Enable external k8s bundle uploader | `false` | | `notifier.externalK8sBundle.defaults.namespace` | Namespace to push the bundle into on clusters | `spire-system` | | `notifier.externalK8sBundle.defaults.configMap` | ConfigMap name to push the bundle into on external clusters | `spire-bundle-upstream` | | `notifier.externalK8sBundle.defaults.configMapKey` | ConfigMap key to push the bundle into on external clusters | `bundle.crt` | @@ -396,6 +396,15 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `nodeAttestor.tpmDirect.pluginPath` | The filename in the container of the plugin | `/app/tpm_attestor_server` | | `nodeAttestor.tpmDirect.cas` | A dictionary of TPM CA PEM or DER files that are allowed to connect. | `{}` | | `nodeAttestor.tpmDirect.hashes` | A list of TPM hashes that are allowed to connect. | `[]` | +| `bundlePublisher.k8sConfigMap.enabled` | Enable local k8s bundle uploader | `true` | +| `bundlePublisher.k8sConfigMap.namespace` | Namespace to push the bundle into, if blank will default to SPIRE Server namespace | `""` | +| `bundlePublisher.k8sConfigMap.format` | Format of the trust bundle. Can be pem or spiffe | `spiffe` | +| `bundlePublisher.externalK8sConfigMap.enabled` | Enable external k8s bundle uploader | `true` | +| `bundlePublisher.externalK8sConfigMap.defaults.namespace` | Namespace to push the bundle into on clusters | `spire-system` | +| `bundlePublisher.externalK8sConfigMap.defaults.configMapName` | ConfigMap name to push the bundle into on external clusters | `spire-bundle-upstream` | +| `bundlePublisher.externalK8sConfigMap.defaults.configMapKey` | ConfigMap key to push the bundle into on external clusters | `""` | +| `bundlePublisher.externalK8sConfigMap.defaults.format` | Format of the trust bundle. Can be pem or spiffe | `spiffe` | +| `bundlePublisher.externalK8sConfigMap.clusters` | A dictionary of clusters to add with optional overrides. If empty, all clusters defined in kubeConfigs will be used. | `{}` | | `bundlePublisher.awsRolesAnywhereTrustAnchor.enabled` | Enable the AWS S3 bundle publisher | `false` | | `bundlePublisher.awsRolesAnywhereTrustAnchor.region` | AWS region to store the trust bundle | `""` | | `bundlePublisher.awsRolesAnywhereTrustAnchor.trustAnchorID` | AWS trust anchor ID to publish to | `""` | diff --git a/charts/spire/charts/spire-server/templates/_helpers.tpl b/charts/spire/charts/spire-server/templates/_helpers.tpl index 49c8e6e..c2c755e 100644 --- a/charts/spire/charts/spire-server/templates/_helpers.tpl +++ b/charts/spire/charts/spire-server/templates/_helpers.tpl @@ -65,7 +65,23 @@ Allow the release namespace to be overridden for multi-namespace deployments in {{- end -}} {{- end -}} -{{- define "spire-server.bundle-namespace" -}} +{{- define "spire-server.bundle-namespace-bundlepublisher" -}} + {{- if .Values.bundlePublisher.k8sConfigMap.namespace }} + {{- .Values.bundlePublisher.k8sConfigMap.namespace }} + {{- else if .Values.namespaceOverride -}} + {{- .Values.namespaceOverride -}} + {{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }} + {{- if ne (len (dig "spire" "namespaces" "system" "name" "" .Values.global)) 0 }} + {{- .Values.global.spire.namespaces.system.name }} + {{- else }} + {{- printf "spire-system" }} + {{- end }} + {{- else -}} + {{- .Release.Namespace -}} + {{- end -}} +{{- end -}} + +{{- define "spire-server.bundle-namespace-notifier" -}} {{- if .Values.notifier.k8sBundle.namespace }} {{- .Values.notifier.k8sBundle.namespace }} {{- else if .Values.namespaceOverride -}} @@ -81,6 +97,14 @@ Allow the release namespace to be overridden for multi-namespace deployments in {{- end -}} {{- end -}} +{{- define "spire-server.bundle-namespace" -}} + {{- if .Values.notifier.k8sBundle.namespace }} + {{- .Values.notifier.k8sBundle.namespace }} + {{- else }} + {{- include "spire-server.bundle-namespace-bundlepublisher" . -}} + {{- end }} +{{- end }} + {{- define "spire-server.podMonitor.namespace" -}} {{- if ne (len .Values.telemetry.prometheus.podMonitor.namespace) 0 }} {{- .Values.telemetry.prometheus.podMonitor.namespace }} diff --git a/charts/spire/charts/spire-server/templates/bundle-configmap.yaml b/charts/spire/charts/spire-server/templates/bundle-configmap.yaml index 4217322..505d66b 100644 --- a/charts/spire/charts/spire-server/templates/bundle-configmap.yaml +++ b/charts/spire/charts/spire-server/templates/bundle-configmap.yaml @@ -1,3 +1,7 @@ +{{- if and .Values.notifier.k8sBundle.enabled .Values.bundlePublisher.k8sConfigMap.enabled }} +{{- fail "You can only enable either notifier.k8sBundle or bundlePublisher.k8sConfigMap." }} +{{- end }} +{{- if .Values.notifier.k8sBundle.enabled }} {{- $namespace := include "spire-server.bundle-namespace" . }} apiVersion: v1 kind: ConfigMap @@ -8,3 +12,4 @@ metadata: annotations: {{- toYaml . | nindent 4 }} {{- end }} +{{- end }} diff --git a/charts/spire/charts/spire-server/templates/configmap.yaml b/charts/spire/charts/spire-server/templates/configmap.yaml index ed30e50..8b0b923 100644 --- a/charts/spire/charts/spire-server/templates/configmap.yaml +++ b/charts/spire/charts/spire-server/templates/configmap.yaml @@ -274,7 +274,7 @@ plugins: k8sbundle: plugin_data: {{- if eq (.Values.notifier.k8sBundle.enabled | toString) "true" }} - namespace: {{ include "spire-server.bundle-namespace" . | quote }} + namespace: {{ include "spire-server.bundle-namespace-notifier" . | quote }} config_map: {{ include "spire-lib.bundle-configmap" . | quote }} {{- with .Values.notifier.k8sBundle.apiServiceLabel }} api_service_label: {{ . | quote }} @@ -304,8 +304,51 @@ plugins: {{- end }} {{- end }} - {{- if or .Values.bundlePublisher.awsRolesAnywhereTrustAnchor.enabled .Values.bundlePublisher.awsS3.enabled .Values.bundlePublisher.gcpCloudStorage.enabled }} + {{- $externalK8sConfigMapClusters := default .Values.kubeConfigs .Values.bundlePublisher.externalK8sConfigMap.clusters }} + {{- if or .Values.bundlePublisher.awsRolesAnywhereTrustAnchor.enabled .Values.bundlePublisher.awsS3.enabled .Values.bundlePublisher.gcpCloudStorage.enabled .Values.bundlePublisher.k8sConfigMap.enabled (and .Values.bundlePublisher.externalK8sConfigMap.enabled (ne (len $externalK8sConfigMapClusters) 0)) }} BundlePublisher: + {{- if or .Values.bundlePublisher.k8sConfigMap.enabled (and .Values.bundlePublisher.externalK8sConfigMap.enabled (ne (len $externalK8sConfigMapClusters) 0)) }} + k8s_configmap: + plugin_data: + clusters: + {{- $prefix := "-" }} + {{- if eq (.Values.bundlePublisher.k8sConfigMap.enabled | toString) "true" }} + {{ $prefix }} chart-internal: + format: {{ .Values.bundlePublisher.k8sConfigMap.format | quote }} + namespace: {{ include "spire-server.bundle-namespace-bundlepublisher" . | quote }} + configmap_name: {{ include "spire-lib.bundle-configmap" . | quote }} + configmap_key: {{ printf "bundle.%s" (include "spire-lib.trust-bundle-ext" (dict "trustBundleFormat" .Values.bundlePublisher.k8sConfigMap.format)) | quote }} + {{- $prefix := " " }} + {{- end }} + {{- if and (eq (.Values.bundlePublisher.externalK8sConfigMap.enabled | toString) "true") (ne (len $externalK8sConfigMapClusters) 0) }} + {{- $clusterDefaults := .Values.bundlePublisher.externalK8sConfigMap.defaults }} + {{- range $name, $_ := $externalK8sConfigMapClusters }} + {{ $prefix }} {{ $name | quote }}: + {{- $clusterSettings := dict }} + {{- if hasKey $root.Values.bundlePublisher.externalK8sConfigMap.clusters $name }} + {{- $clusterSettings = index $root.Values.bundlePublisher.externalK8sConfigMap.clusters $name }} + {{- end }} + {{- if hasKey $clusterSettings "kubeConfigName" }} + kubeconfig_path: /kubeconfigs/{{ $clusterSettings.kubeConfigName }} + {{- else }} + kubeconfig_path: /kubeconfigs/{{ $name }} + {{- end }} + {{- $format := $clusterDefaults.format }} + {{- if hasKey $clusterSettings "format" }}{{- $format = $clusterSettings.format }}{{- end }} + format: {{ $format | quote }} + namespace: {{ if hasKey $clusterSettings "namespace" }}{{ $clusterSettings.namespace }}{{ else }}{{ $clusterDefaults.namespace }}{{ end }} + configmap_name: {{ if hasKey $clusterSettings "configMapName" }}{{ $clusterSettings.configMapName }}{{ else }}{{ $clusterDefaults.configMapName }}{{ end }} + {{- if hasKey $clusterSettings "configMapKey" }} + configmap_key: {{ $clusterSettings.configMapKey | quote }} + {{- else if ne $clusterDefaults.configMapKey "" }} + configmap_key: {{ $clusterDefaults.configMapKey | quote }} + {{- else }} + configmap_key: {{ printf "bundle.%s" (include "spire-lib.trust-bundle-ext" (dict "trustBundleFormat" $format)) | quote }} + {{- end }} + {{- $prefix := " " }} + {{- end }} + {{- end }} + {{- end }} {{- if .Values.bundlePublisher.awsRolesAnywhereTrustAnchor.enabled }} aws_rolesanywhere_trustanchor: plugin_data: diff --git a/charts/spire/charts/spire-server/templates/roles.yaml b/charts/spire/charts/spire-server/templates/roles.yaml index 197dc02..47ef87b 100644 --- a/charts/spire/charts/spire-server/templates/roles.yaml +++ b/charts/spire/charts/spire-server/templates/roles.yaml @@ -1,7 +1,7 @@ {{- $subject := include "spire-server.subject" . }} {{- $namespace := include "spire-server.namespace" . }} {{- $bundleNamespace := include "spire-server.bundle-namespace" . }} -{{- if .Values.notifier.k8sBundle.enabled }} +{{- if or .Values.notifier.k8sBundle.enabled .Values.bundlePublisher.k8sConfigMap.enabled }} # Role to be able to push certificate bundles to a configmap kind: Role apiVersion: rbac.authorization.k8s.io/v1 @@ -15,6 +15,9 @@ rules: verbs: - get - patch +{{- if .Values.bundlePublisher.k8sConfigMap.enabled }} + - create +{{- end }} {{- end }} {{- if and .Values.upstreamAuthority.certManager.enabled .Values.upstreamAuthority.certManager.rbac.create }} --- @@ -48,7 +51,7 @@ roleRef: name: {{ include "spire-server.fullname" . }}-cm apiGroup: rbac.authorization.k8s.io {{- end }} -{{- if .Values.notifier.k8sBundle.enabled }} +{{- if or .Values.notifier.k8sBundle.enabled .Values.bundlePublisher.k8sConfigMap.enabled }} --- kind: RoleBinding apiVersion: rbac.authorization.k8s.io/v1 diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index 816fb8f..79dceec 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -514,7 +514,7 @@ upstreamAuthority: notifier: k8sBundle: ## @param notifier.k8sBundle.enabled Enable local k8s bundle uploader - enabled: true + enabled: false ## @param notifier.k8sBundle.namespace Namespace to push the bundle into, if blank will default to SPIRE Server namespace namespace: "" ## @param notifier.k8sBundle.apiServiceLabel If set, rotate the CA Bundle in API services with this label set to true. @@ -523,7 +523,7 @@ notifier: webhookLabel: "" externalK8sBundle: ## @param notifier.externalK8sBundle.enabled Enable external k8s bundle uploader - enabled: true + enabled: false defaults: ## @param notifier.externalK8sBundle.defaults.namespace Namespace to push the bundle into on clusters namespace: "spire-system" @@ -978,6 +978,30 @@ nodeAttestor: # The secrets needed for this plugin are configured in the secrets: section bundlePublisher: + k8sConfigMap: + ## @param bundlePublisher.k8sConfigMap.enabled Enable local k8s bundle uploader + enabled: true + ## @param bundlePublisher.k8sConfigMap.namespace Namespace to push the bundle into, if blank will default to SPIRE Server namespace + namespace: "" + ## @param bundlePublisher.k8sConfigMap.format Format of the trust bundle. Can be pem or spiffe + format: spiffe + externalK8sConfigMap: + ## @param bundlePublisher.externalK8sConfigMap.enabled Enable external k8s bundle uploader + enabled: true + defaults: + ## @param bundlePublisher.externalK8sConfigMap.defaults.namespace Namespace to push the bundle into on clusters + namespace: "spire-system" + ## @param bundlePublisher.externalK8sConfigMap.defaults.configMapName ConfigMap name to push the bundle into on external clusters + configMapName: "spire-bundle-upstream" + ## @param bundlePublisher.externalK8sConfigMap.defaults.configMapKey ConfigMap key to push the bundle into on external clusters + configMapKey: "" + ## @param bundlePublisher.externalK8sConfigMap.defaults.format Format of the trust bundle. Can be pem or spiffe + format: spiffe + ## @param bundlePublisher.externalK8sConfigMap.clusters [object] A dictionary of clusters to add with optional overrides. If empty, all clusters defined in kubeConfigs will be used. + clusters: {} + # clustera: + # namespace: foo + # clusterb: {} awsRolesAnywhereTrustAnchor: ## @param bundlePublisher.awsRolesAnywhereTrustAnchor.enabled Enable the AWS S3 bundle publisher enabled: false diff --git a/tests/integration/spiffe-step-ssh/run-tests.sh b/tests/integration/spiffe-step-ssh/run-tests.sh index 109792d..772b241 100755 --- a/tests/integration/spiffe-step-ssh/run-tests.sh +++ b/tests/integration/spiffe-step-ssh/run-tests.sh @@ -152,7 +152,7 @@ popd helm upgrade --install spiffe-step-ssh charts/spiffe-step-ssh --set caPassword="$(cat spiffe-step-ssh-password.txt)" -f spiffe-step-ssh-values.yaml -f "${SCRIPTPATH}/ingress-values.yaml" --set trustDomain=production.other --wait --timeout 10m # Is fetchca responding. -kubectl get configmap -n spire-system spire-bundle-downstream -o go-template='{{ index .data "bundle.crt" }}' > /tmp/ca.pem +kubectl exec -it -n spire-server spire-internal-server-0 -- spire-server bundle show > /tmp/ca.pem cat /tmp/ca.pem curl https://spiffe-step-ssh-fetchca.production.other -s --cacert /tmp/ca.pem From f37d681bc2669bcbba20083430b2ba621bfbcbc8 Mon Sep 17 00:00:00 2001 From: kfox1111 Date: Tue, 1 Jul 2025 17:26:58 -0700 Subject: [PATCH 13/16] Enable running the oidc discovery provider without cluster-admin/CSI (#570) * Update for 1.12.3 Signed-off-by: Kevin Fox * Fix typo. Use test image Signed-off-by: Kevin Fox * Fix lint Signed-off-by: Kevin Fox * Fix format flag. Update config location for k8s configmap bp Signed-off-by: Kevin Fox * Fix role Signed-off-by: Kevin Fox * Update rbac Signed-off-by: Kevin Fox * Fix key Signed-off-by: Kevin Fox * Fix format Signed-off-by: Kevin Fox * Fix the bundle format for the fetchca bits Signed-off-by: Kevin Fox * Update key Signed-off-by: Kevin Fox * Fix test rather then reconfigure Signed-off-by: Kevin Fox * Add namespace Signed-off-by: Kevin Fox * Update to follow the new patch Signed-off-by: Kevin Fox * Fix formatting Signed-off-by: Kevin Fox * Fix formatting Signed-off-by: Kevin Fox * Update filename based on format Signed-off-by: Kevin Fox * Add upgrade notes Signed-off-by: Kevin Fox * Enable running the oidc discovery provider without cluster-admin/CSI Signed-off-by: Kevin Fox * Calm lint Signed-off-by: Kevin Fox * Switch to testing nightly. Dont manage bundle configmap. Signed-off-by: Kevin Fox * Update permissions Signed-off-by: Kevin Fox * Update permissions Signed-off-by: Kevin Fox * Update permissions Signed-off-by: Kevin Fox * Update for final release Signed-off-by: Kevin Fox * Update for final 1.12.4 release Signed-off-by: Kevin Fox * Apply suggestions from code review Co-authored-by: Faisal Memon Signed-off-by: kfox1111 * Update docs Signed-off-by: Kevin Fox --------- Signed-off-by: Kevin Fox Signed-off-by: kfox1111 Co-authored-by: Faisal Memon --- .../charts/spiffe-oidc-discovery-provider/README.md | 2 ++ .../templates/configmap.yaml | 8 ++++++++ .../templates/deployment.yaml | 13 +++++++++++++ .../spiffe-oidc-discovery-provider/values.yaml | 6 ++++++ examples/static-manifest-server/values.yaml | 8 ++++++-- 5 files changed, 35 insertions(+), 2 deletions(-) diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md index 8fab9b8..88d9d79 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md @@ -29,6 +29,8 @@ A Helm chart to install the SPIFFE OIDC discovery provider. | ----------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | | `agentSocketName` | The name of the spire-agent unix socket | `spire-agent.sock` | | `csiDriverName` | The csi driver to use | `csi.spiffe.io` | +| `bundleSource` | Configure where to fetch the trust bundle from. Must be CSI or ConfigMap. | `CSI` | +| `bundleConfigMap` | ConfigMap name for SPIRE bundle when bundleSource is ConfigMap | `spire-bundle` | | `replicaCount` | Replica count | `1` | | `namespaceOverride` | Namespace override | `""` | | `annotations` | Annotations for the deployment | `{}` | diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/templates/configmap.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/templates/configmap.yaml index 06a52f3..30e970e 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/templates/configmap.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/templates/configmap.yaml @@ -1,3 +1,6 @@ +{{- if and (ne .Values.bundleSource "ConfigMap") (ne .Values.bundleSource "CSI") }} +{{- fail "Bundle source must be CSI or ConfigmMap" }} +{{- end }} {{- $tlsCount := 0 }} {{- if and .Values.enabled .Values.tls.spire.enabled }} {{- $tlsCount = add $tlsCount 1 }} @@ -44,9 +47,14 @@ serving_cert_file: jwks_uri: {{ .Values.config.jwksUri | quote }} {{- end }} +{{- if eq .Values.bundleSource "ConfigMap" }} +file: + path: /bundle/bundle.spiffe +{{- else }} workload_api: socket_path: {{ include "spiffe-oidc-discovery-provider.workload-api-socket-path" . | quote }} trust_domain: {{ include "spire-lib.trust-domain" . | quote }} +{{- end }} health_checks: bind_port: "8008" diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/templates/deployment.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/templates/deployment.yaml index 8b02c5b..07420bf 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/templates/deployment.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/templates/deployment.yaml @@ -86,9 +86,15 @@ spec: name: https {{- end }} volumeMounts: + {{- if eq .Values.bundleSource "ConfigMap" }} + - name: spiffe-bundle + mountPath: /bundle + readOnly: true + {{- else }} - name: spiffe-workload-api mountPath: {{ include "spiffe-oidc-discovery-provider.workload-api-socket-path" . | dir }} readOnly: true + {{- end }} - name: spire-oidc-sockets mountPath: /run/spire/oidc-sockets readOnly: false @@ -171,10 +177,17 @@ spec: {{- end }} {{- end }} volumes: + {{- if or .Values.tls.spire.enabled (eq .Values.bundleSource "CSI") }} - name: spiffe-workload-api csi: driver: "{{ .Values.csiDriverName }}" readOnly: true + {{- end }} + {{- if eq .Values.bundleSource "ConfigMap" }} + - name: spiffe-bundle + configMap: + name: {{ include "spire-lib.bundle-configmap" . }} + {{- end }} - name: spire-oidc-sockets emptyDir: {} - name: spire-oidc-config diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml index 613b131..43ef469 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml @@ -11,6 +11,12 @@ agentSocketName: spire-agent.sock ## @param csiDriverName The csi driver to use csiDriverName: csi.spiffe.io +## @param bundleSource Configure where to fetch the trust bundle from. Must be CSI or ConfigMap. +bundleSource: CSI + +## @param bundleConfigMap ConfigMap name for SPIRE bundle when bundleSource is ConfigMap +bundleConfigMap: spire-bundle + ## @param replicaCount Replica count replicaCount: 1 diff --git a/examples/static-manifest-server/values.yaml b/examples/static-manifest-server/values.yaml index 99c1d1c..b005fab 100644 --- a/examples/static-manifest-server/values.yaml +++ b/examples/static-manifest-server/values.yaml @@ -17,7 +17,7 @@ spire-server: selectors: - tpm:pub_hash:12345 foo-kubelet: - parentID: spiffe://example.org/foo + parentID: spiffe://example.org/hosts/foo spiffeID: spiffe://example.org/k8s/one/node/foo selectors: - systemd:id:kubelet.service @@ -28,4 +28,8 @@ spire-agent: spiffe-csi-driver: enabled: false spiffe-oidc-discovery-provider: - enabled: false + enabled: true + bundleSource: ConfigMap + tls: + spire: + enabled: false From 255106da84b8653aad48bb954be588501780d7ce Mon Sep 17 00:00:00 2001 From: Alan Cha Date: Wed, 2 Jul 2025 17:42:18 -0400 Subject: [PATCH 14/16] Update to Tornjak 2.1.0 (#597) * Update to Tornjak 2.1.0 Signed-off-by: Alan Cha * Address comments Signed-off-by: Alan Cha * Fix Tornjak tests Signed-off-by: Alan Cha * revert namespace change Signed-off-by: Alan Cha --------- Signed-off-by: Alan Cha --- charts/spire/charts/spire-server/README.md | 2 +- .../templates/tests/test-tornjak-connection.yaml | 4 ++-- .../charts/spire-server/templates/tornjak-config.yaml | 11 ++++------- charts/spire/charts/spire-server/values.yaml | 2 +- charts/spire/charts/tornjak-frontend/Chart.yaml | 2 +- examples/tornjak/README.md | 2 +- 6 files changed, 10 insertions(+), 13 deletions(-) diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index e2ddab5..fc2f6c3 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -428,7 +428,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `tornjak.image.repository` | The repository within the registry | `spiffe/tornjak-backend` | | `tornjak.image.pullPolicy` | The image pull policy | `IfNotPresent` | | `tornjak.image.tag` | Overrides the image tag to be whatever you need it to be. It will always be the flag you set without modifications | `""` | -| `tornjak.image.defaultTag` | Sets the default image to use when image.tag is not set. It will automatically be updated with a ubi- prefix if on OpenShift. | `v1.6.0` | +| `tornjak.image.defaultTag` | Sets the default image to use when image.tag is not set. It will automatically be updated with a ubi- prefix if on OpenShift. | `v2.1.0` | | `tornjak.service.type` | Type of service resource | `ClusterIP` | | `tornjak.service.ports.http` | Insecure port for tornjak service | `10000` | | `tornjak.service.ports.https` | Secure port for tornjak service | `10443` | diff --git a/charts/spire/charts/spire-server/templates/tests/test-tornjak-connection.yaml b/charts/spire/charts/spire-server/templates/tests/test-tornjak-connection.yaml index c259f12..946a64e 100644 --- a/charts/spire/charts/spire-server/templates/tests/test-tornjak-connection.yaml +++ b/charts/spire/charts/spire-server/templates/tests/test-tornjak-connection.yaml @@ -17,13 +17,13 @@ spec: - name: curl-tornjak-backend image: {{ template "spire-lib.image" (dict "image" .Values.tests.bash.image "global" .Values.global) }} command: ['curl'] - args: ['-k', '-s', '-f', 'http://{{ include "spire-tornjak.servicename" . }}.{{ include "spire-server.namespace" . }}.svc.{{ include "spire-lib.cluster-domain" . }}:{{ .Values.tornjak.service.ports.http }}/api/tornjak/serverinfo'] + args: ['-k', '-s', '-f', 'http://{{ include "spire-tornjak.servicename" . }}.{{ include "spire-server.namespace" . }}.svc.{{ include "spire-lib.cluster-domain" . }}:{{ .Values.tornjak.service.ports.http }}/api/v1/tornjak/serverinfo'] securityContext: {{- include "spire-lib.securitycontext" . | nindent 8 }} - name: curl-tornjak-backend-and-spire image: {{ template "spire-lib.image" (dict "image" .Values.tests.bash.image "global" .Values.global) }} command: ['curl'] - args: ['-k', '-s', '-f', 'http://{{ include "spire-tornjak.servicename" . }}.{{ include "spire-server.namespace" . }}.svc.{{ include "spire-lib.cluster-domain" . }}:{{ .Values.tornjak.service.ports.http }}/api/healthcheck'] + args: ['-k', '-s', '-f', 'http://{{ include "spire-tornjak.servicename" . }}.{{ include "spire-server.namespace" . }}.svc.{{ include "spire-lib.cluster-domain" . }}:{{ .Values.tornjak.service.ports.http }}/api/v1/spire/healthcheck'] securityContext: {{- include "spire-lib.securitycontext" . | nindent 8 }} restartPolicy: Never diff --git a/charts/spire/charts/spire-server/templates/tornjak-config.yaml b/charts/spire/charts/spire-server/templates/tornjak-config.yaml index ec7b2e6..203e8d3 100644 --- a/charts/spire/charts/spire-server/templates/tornjak-config.yaml +++ b/charts/spire/charts/spire-server/templates/tornjak-config.yaml @@ -10,25 +10,22 @@ data: spire_socket_path = "unix:///tmp/spire-server/private/api.sock" # socket to communicate with SPIRE server {{- if eq (include "spire-tornjak.connectionType" .) "http" }} http { - enabled = true # if true, opens HTTP server port = "10000" # if HTTP enabled, opens HTTP listen port at specified container port } {{- end }} {{- if eq (include "spire-tornjak.connectionType" .) "tls" }} - tls { - enabled = true + https { port = "10443" # container port for TLS connection cert = "/opt/spire/server/tls.crt" # TLS server cert key = "/opt/spire/server/tls.key" # TLS server key } {{- end }} {{- if eq (include "spire-tornjak.connectionType" .) "mtls" }} - mtls { - enabled = true + https { port = "10443" # container port for mTLS connection cert = "/opt/spire/server/tls.crt" # mTLS server cert key = "/opt/spire/server/tls.key" # mTLS server key - ca = "/opt/spire/user/ca.crt" # mTLS user CA + client_ca = "/opt/spire/user/ca.crt" # mTLS user CA } {{- end }} } @@ -43,7 +40,7 @@ data: } {{- end }} {{- if ne .Values.tornjak.config.userManagement.issuer "" }} - UserManagement "KeycloakAuth" { + Authenticator "Keycloak" { plugin_data { issuer = "{{ .Values.tornjak.config.userManagement.issuer }}" audience = "{{ .Values.tornjak.config.userManagement.audience }}" diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index 79dceec..b80d2f5 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -1047,7 +1047,7 @@ tornjak: repository: spiffe/tornjak-backend pullPolicy: IfNotPresent tag: "" - defaultTag: "v1.6.0" + defaultTag: "v2.1.0" service: ## @param tornjak.service.type Type of service resource diff --git a/charts/spire/charts/tornjak-frontend/Chart.yaml b/charts/spire/charts/tornjak-frontend/Chart.yaml index 2d67db3..31dbe0e 100644 --- a/charts/spire/charts/tornjak-frontend/Chart.yaml +++ b/charts/spire/charts/tornjak-frontend/Chart.yaml @@ -3,7 +3,7 @@ name: tornjak-frontend description: A Helm chart to deploy Tornjak frontend type: application version: 0.1.0 -appVersion: "v1.6.0" +appVersion: "v2.1.0" home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire sources: - https://github.com/spiffe/tornjak diff --git a/examples/tornjak/README.md b/examples/tornjak/README.md index 32a74e2..4f3be3f 100644 --- a/examples/tornjak/README.md +++ b/examples/tornjak/README.md @@ -29,7 +29,7 @@ helm upgrade --install -n spire-mgmt spire spire \ --render-subchart-notes # test the Tornjak deployment -helm test spire -n spire-server +helm test spire -n spire-mgmt ``` Port forward the Tornjak backend (APIs) and Tornjak frontend (UI) services. Execute these commands in separate consoles. From 88f0108e10414d80ff28a27f75398f0ca1e80965 Mon Sep 17 00:00:00 2001 From: Faisal Memon Date: Fri, 4 Jul 2025 01:30:18 -0700 Subject: [PATCH 15/16] Bump spire Helm Chart version from 0.25.0 to 0.26.0 * 255106da Update to Tornjak 2.1.0 (#597) * f37d681b Enable running the oidc discovery provider without cluster-admin/CSI (#570) * 892051c4 Update for 1.12.4 (#605) * b74b10a0 Bump test chart dependencies (#615) * e78400eb Initial spike support (#591) * 38314ed6 Bump test chart dependencies (#611) * bfd08bcf Bump test chart dependencies (#608) * 971e4be7 Bump test chart dependencies (#606) * ffe43901 Nit: Fix typo in param guide (#595) Signed-off-by: Faisal Memon --- charts/spire/Chart.yaml | 2 +- charts/spire/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/charts/spire/Chart.yaml b/charts/spire/Chart.yaml index 4e00f7a..8c1cf55 100644 --- a/charts/spire/Chart.yaml +++ b/charts/spire/Chart.yaml @@ -3,7 +3,7 @@ name: spire description: > A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. type: application -version: 0.25.0 +version: 0.26.0 appVersion: "1.12.4" keywords: ["spiffe", "spire", "spire-server", "spire-agent", "oidc", "spire-controller-manager"] home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire diff --git a/charts/spire/README.md b/charts/spire/README.md index 7df685c..60c27c2 100644 --- a/charts/spire/README.md +++ b/charts/spire/README.md @@ -1,6 +1,6 @@ # spire -![Version: 0.25.0](https://img.shields.io/badge/Version-0.25.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.4](https://img.shields.io/badge/AppVersion-1.12.4-informational?style=flat-square) +![Version: 0.26.0](https://img.shields.io/badge/Version-0.26.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.4](https://img.shields.io/badge/AppVersion-1.12.4-informational?style=flat-square) [![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. From d1f5c7e93d326530a8f1e767bedac9e0f81d2026 Mon Sep 17 00:00:00 2001 From: Faisal Memon Date: Fri, 4 Jul 2025 01:30:47 -0700 Subject: [PATCH 16/16] Bump spire-nested Helm Chart version from 0.25.0 to 0.26.0 * 892051c4 Update for 1.12.4 (#605) Signed-off-by: Faisal Memon --- charts/spire-nested/Chart.yaml | 2 +- charts/spire-nested/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/charts/spire-nested/Chart.yaml b/charts/spire-nested/Chart.yaml index 6c20050..4653ec0 100644 --- a/charts/spire-nested/Chart.yaml +++ b/charts/spire-nested/Chart.yaml @@ -3,7 +3,7 @@ name: spire-nested description: > A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. type: application -version: 0.25.0 +version: 0.26.0 appVersion: "1.12.4" keywords: ["spiffe", "spire", "spire-server", "spire-agent", "oidc", "spire-controller-manager"] home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire diff --git a/charts/spire-nested/README.md b/charts/spire-nested/README.md index 78d9edd..4685867 100644 --- a/charts/spire-nested/README.md +++ b/charts/spire-nested/README.md @@ -1,6 +1,6 @@ # spire -![Version: 0.25.0](https://img.shields.io/badge/Version-0.25.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.4](https://img.shields.io/badge/AppVersion-1.12.4-informational?style=flat-square) +![Version: 0.26.0](https://img.shields.io/badge/Version-0.26.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.4](https://img.shields.io/badge/AppVersion-1.12.4-informational?style=flat-square) [![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.