From 0fc00cbbe6d52e41a6820857362fbb4e6418f3af Mon Sep 17 00:00:00 2001 From: "spire-helm-version-checker[bot]" <161522935+spire-helm-version-checker[bot]@users.noreply.github.com> Date: Mon, 14 Apr 2025 05:50:09 -0700 Subject: [PATCH 1/8] Bump test chart dependencies (#561) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com> --- .github/tests/charts.json | 2 +- .github/tests/oci-charts.json | 4 ++-- charts/spire/charts/spiffe-oidc-discovery-provider/README.md | 2 +- .../spire/charts/spiffe-oidc-discovery-provider/values.yaml | 2 +- charts/spire/charts/spire-agent/README.md | 4 ++-- charts/spire/charts/spire-agent/values.yaml | 4 ++-- charts/spire/charts/spire-server/README.md | 4 ++-- charts/spire/charts/spire-server/values.yaml | 4 ++-- charts/spire/charts/tornjak-frontend/README.md | 2 +- charts/spire/charts/tornjak-frontend/values.yaml | 2 +- 10 files changed, 15 insertions(+), 15 deletions(-) diff --git a/.github/tests/charts.json b/.github/tests/charts.json index 6623d66..08f0d5e 100644 --- a/.github/tests/charts.json +++ b/.github/tests/charts.json @@ -2,7 +2,7 @@ { "name": "kube-prometheus-stack", "repo": "https://prometheus-community.github.io/helm-charts", - "version": "70.4.1" + "version": "70.4.2" }, { "name": "cert-manager", diff --git a/.github/tests/oci-charts.json b/.github/tests/oci-charts.json index 076f056..cd74aff 100644 --- a/.github/tests/oci-charts.json +++ b/.github/tests/oci-charts.json @@ -2,12 +2,12 @@ { "name": "mysql", "registry": "docker.io/bitnamicharts/mysql", - "version": "12.3.2" + "version": "12.3.3" }, { "name": "postgresql", "registry": "docker.io/bitnamicharts/postgresql", - "version": "16.6.1" + "version": "16.6.3" }, { "name": "envoy-gateway", diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md index d922c20..ba3f0c5 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md @@ -120,7 +120,7 @@ A Helm chart to install the SPIFFE OIDC discovery provider. | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:ce272ee5a3739a3c45784c317b2fb1e93a4cc4ea1f4d3feabb702b278e5bf514` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2` | | `tests.toolkit.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.toolkit.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` | | `tests.toolkit.image.pullPolicy` | The image pull policy | `IfNotPresent` | diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml index 58e8850..91c4051 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml @@ -340,7 +340,7 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:ce272ee5a3739a3c45784c317b2fb1e93a4cc4ea1f4d3feabb702b278e5bf514 + tag: latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2 toolkit: ## @param tests.toolkit.image.registry The OCI registry to pull the image from diff --git a/charts/spire/charts/spire-agent/README.md b/charts/spire/charts/spire-agent/README.md index 3959b0a..99ab1c8 100644 --- a/charts/spire/charts/spire-agent/README.md +++ b/charts/spire/charts/spire-agent/README.md @@ -70,7 +70,7 @@ A Helm chart to install the SPIRE agent. | `fsGroupFix.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `fsGroupFix.image.repository` | The repository within the registry | `chainguard/bash` | | `fsGroupFix.image.pullPolicy` | The image pull policy | `Always` | -| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:ce272ee5a3739a3c45784c317b2fb1e93a4cc4ea1f4d3feabb702b278e5bf514` | +| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2` | | `fsGroupFix.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `keyManager.memory.enabled` | Enable the memory based Key Manager | `true` | | `nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s Node Attestor | `true` | @@ -114,7 +114,7 @@ A Helm chart to install the SPIRE agent. | `socketAlternate.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `socketAlternate.image.repository` | The repository within the registry | `chainguard/bash` | | `socketAlternate.image.pullPolicy` | The image pull policy | `Always` | -| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:ce272ee5a3739a3c45784c317b2fb1e93a4cc4ea1f4d3feabb702b278e5bf514` | +| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2` | | `socketAlternate.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `hostCert.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `hostCert.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` | diff --git a/charts/spire/charts/spire-agent/values.yaml b/charts/spire/charts/spire-agent/values.yaml index cc0a9ba..a357d79 100644 --- a/charts/spire/charts/spire-agent/values.yaml +++ b/charts/spire/charts/spire-agent/values.yaml @@ -153,7 +153,7 @@ fsGroupFix: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:ce272ee5a3739a3c45784c317b2fb1e93a4cc4ea1f4d3feabb702b278e5bf514 + tag: latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2 ## @param fsGroupFix.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -280,7 +280,7 @@ socketAlternate: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:ce272ee5a3739a3c45784c317b2fb1e93a4cc4ea1f4d3feabb702b278e5bf514 + tag: latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2 ## @param socketAlternate.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index acab8e7..101fc0e 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -437,7 +437,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `chown.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `chown.image.repository` | The repository within the registry | `chainguard/bash` | | `chown.image.pullPolicy` | The image pull policy | `Always` | -| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:ce272ee5a3739a3c45784c317b2fb1e93a4cc4ea1f4d3feabb702b278e5bf514` | +| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2` | | `chown.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `experimental.enabled` | Allow configuration of experimental features | `false` | | `experimental.cacheReloadInterval` | The amount of time between two reloads of the in-memory entry cache. | `5s` | @@ -450,5 +450,5 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:ce272ee5a3739a3c45784c317b2fb1e93a4cc4ea1f4d3feabb702b278e5bf514` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2` | | `kubeConfigs` | Manage additional kubeconfig files to talk to external Kubernetes clusters | `{}` | diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index 37790fa..7a6a10b 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -1104,7 +1104,7 @@ chown: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:ce272ee5a3739a3c45784c317b2fb1e93a4cc4ea1f4d3feabb702b278e5bf514 + tag: latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2 ## @param chown.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -1139,7 +1139,7 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:ce272ee5a3739a3c45784c317b2fb1e93a4cc4ea1f4d3feabb702b278e5bf514 + tag: latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2 ## @param kubeConfigs [object] Manage additional kubeconfig files to talk to external Kubernetes clusters kubeConfigs: {} diff --git a/charts/spire/charts/tornjak-frontend/README.md b/charts/spire/charts/tornjak-frontend/README.md index 73eb5e8..4823017 100644 --- a/charts/spire/charts/tornjak-frontend/README.md +++ b/charts/spire/charts/tornjak-frontend/README.md @@ -101,4 +101,4 @@ port forwarding. See the chart NOTES output for more details. | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:ce272ee5a3739a3c45784c317b2fb1e93a4cc4ea1f4d3feabb702b278e5bf514` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2` | diff --git a/charts/spire/charts/tornjak-frontend/values.yaml b/charts/spire/charts/tornjak-frontend/values.yaml index fe9a728..3d3541f 100644 --- a/charts/spire/charts/tornjak-frontend/values.yaml +++ b/charts/spire/charts/tornjak-frontend/values.yaml @@ -162,4 +162,4 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:ce272ee5a3739a3c45784c317b2fb1e93a4cc4ea1f4d3feabb702b278e5bf514 + tag: latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2 From 33edad1952d38b511c960b8c92bda57a212dbf1f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 19 Apr 2025 06:12:07 -0700 Subject: [PATCH 2/8] Bump golang.org/x/net from 0.37.0 to 0.38.0 in /tests (#565) Bumps [golang.org/x/net](https://github.com/golang/net) from 0.37.0 to 0.38.0. - [Commits](https://github.com/golang/net/compare/v0.37.0...v0.38.0) --- updated-dependencies: - dependency-name: golang.org/x/net dependency-version: 0.38.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- tests/go.mod | 2 +- tests/go.sum | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/tests/go.mod b/tests/go.mod index 450d6af..dab0d75 100644 --- a/tests/go.mod +++ b/tests/go.mod @@ -50,7 +50,7 @@ require ( github.com/xeipuuv/gojsonschema v1.2.0 // indirect go.uber.org/automaxprocs v1.6.0 // indirect golang.org/x/crypto v0.36.0 // indirect - golang.org/x/net v0.37.0 // indirect + golang.org/x/net v0.38.0 // indirect golang.org/x/oauth2 v0.23.0 // indirect golang.org/x/sys v0.32.0 // indirect golang.org/x/term v0.30.0 // indirect diff --git a/tests/go.sum b/tests/go.sum index 5eefdd1..150e3da 100644 --- a/tests/go.sum +++ b/tests/go.sum @@ -133,8 +133,8 @@ golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU= -golang.org/x/net v0.37.0 h1:1zLorHbz+LYj7MQlSf1+2tPIIgibq2eL5xkrGk6f+2c= -golang.org/x/net v0.37.0/go.mod h1:ivrbrMbzFq5J41QOQh0siUuly180yBYtLp+CKbEaFx8= +golang.org/x/net v0.38.0 h1:vRMAPTMaeGqVhG5QyLJHqNDwecKTomGeqbnfZyKlBI8= +golang.org/x/net v0.38.0/go.mod h1:ivrbrMbzFq5J41QOQh0siUuly180yBYtLp+CKbEaFx8= golang.org/x/oauth2 v0.23.0 h1:PbgcYx2W7i4LvjJWEbf0ngHV6qJYr86PkAV3bXdLEbs= golang.org/x/oauth2 v0.23.0/go.mod h1:XYTD2NtWslqkgxebSiOHnXEap4TF09sJSc7H1sXbhtI= golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= From 912f4127ab22067bbb993e691e695b81c91c4f03 Mon Sep 17 00:00:00 2001 From: kfox1111 Date: Sat, 19 Apr 2025 21:06:41 -0700 Subject: [PATCH 3/8] Update tpm plugin version (#564) Signed-off-by: Kevin Fox --- charts/spire/charts/spire-agent/README.md | 14 +++++++------- charts/spire/charts/spire-agent/values.yaml | 14 +++++++------- charts/spire/charts/spire-server/README.md | 8 ++++---- charts/spire/charts/spire-server/values.yaml | 8 ++++---- 4 files changed, 22 insertions(+), 22 deletions(-) diff --git a/charts/spire/charts/spire-agent/README.md b/charts/spire/charts/spire-agent/README.md index 99ab1c8..5535af2 100644 --- a/charts/spire/charts/spire-agent/README.md +++ b/charts/spire/charts/spire-agent/README.md @@ -79,17 +79,17 @@ A Helm chart to install the SPIRE agent. | `nodeAttestor.httpChallenge.port` | The port to listen on. If 0, a random value will be used. | `0` | | `nodeAttestor.httpChallenge.advertisedPort` | The port to tell the server to call back on. Set only if your using an http proxy on the hosts. If 0, will use the port setting. | `0` | | `nodeAttestor.tpmDirect.enabled` | Enable the direct TPM node attestor, a 3rd party plugin by Boxboat. This plugin is experimental. | `false` | -| `nodeAttestor.tpmDirect.plugin.image.registry` | The OCI registry to pull the image from | `docker.io` | -| `nodeAttestor.tpmDirect.plugin.image.repository` | The repository within the registry | `boxboat/spire-tpm-plugin-tpm-attestor-agent` | +| `nodeAttestor.tpmDirect.plugin.image.registry` | The OCI registry to pull the image from | `ghcr.io` | +| `nodeAttestor.tpmDirect.plugin.image.repository` | The repository within the registry | `spiffe/spire-tpm-plugin-tpm-attestor-agent` | | `nodeAttestor.tpmDirect.plugin.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `nodeAttestor.tpmDirect.plugin.image.tag` | Overrides the image tag | `v1.8.7` | -| `nodeAttestor.tpmDirect.plugin.checksum` | The sha256 checksum of the plugin binary | `1d7c73ccac948ee86cbd78ddde2d30128a1838b403f7bb2100d38d916a252244` | +| `nodeAttestor.tpmDirect.plugin.image.tag` | Overrides the image tag | `v1.9.0` | +| `nodeAttestor.tpmDirect.plugin.checksum` | The sha256 checksum of the plugin binary | `22f67063f1699330e70cdedc9b923e517688f5ae71085a26bd9b83b3060ee86e` | | `nodeAttestor.tpmDirect.plugin.path` | The filename in the container of the plugin | `/app/tpm_attestor_agent` | | `nodeAttestor.tpmDirect.pubHash.enabled` | Display pubhash in logs | `true` | -| `nodeAttestor.tpmDirect.pubHash.image.registry` | The OCI registry to pull the image from | `docker.io` | -| `nodeAttestor.tpmDirect.pubHash.image.repository` | The repository within the registry | `boxboat/spire-tpm-plugin-get-tpm-pubhash` | +| `nodeAttestor.tpmDirect.pubHash.image.registry` | The OCI registry to pull the image from | `ghcr.io` | +| `nodeAttestor.tpmDirect.pubHash.image.repository` | The repository within the registry | `spiffe/spire-tpm-plugin-get-tpm-pubhash` | | `nodeAttestor.tpmDirect.pubHash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `nodeAttestor.tpmDirect.pubHash.image.tag` | Overrides the image tag | `v1.8.7` | +| `nodeAttestor.tpmDirect.pubHash.image.tag` | Overrides the image tag | `v1.9.0` | | `workloadAttestors.unix.enabled` | Enables the Unix workload attestor | `false` | | `workloadAttestors.k8s.enabled` | Enables the Kubernetes workload attestor | `true` | | `workloadAttestors.k8s.verification.type` | What kind of verification to do against kubelet. auto will first attempt to use hostCert, and then fall back to apiServerCA. Valid options are [auto, hostCert, apiServerCA, skip] | `skip` | diff --git a/charts/spire/charts/spire-agent/values.yaml b/charts/spire/charts/spire-agent/values.yaml index a357d79..cdbeb2a 100644 --- a/charts/spire/charts/spire-agent/values.yaml +++ b/charts/spire/charts/spire-agent/values.yaml @@ -186,12 +186,12 @@ nodeAttestor: ## @param nodeAttestor.tpmDirect.plugin.image.tag Overrides the image tag ## image: - registry: docker.io - repository: boxboat/spire-tpm-plugin-tpm-attestor-agent + registry: ghcr.io + repository: spiffe/spire-tpm-plugin-tpm-attestor-agent pullPolicy: IfNotPresent - tag: "v1.8.7" + tag: "v1.9.0" ## @param nodeAttestor.tpmDirect.plugin.checksum The sha256 checksum of the plugin binary - checksum: 1d7c73ccac948ee86cbd78ddde2d30128a1838b403f7bb2100d38d916a252244 + checksum: 22f67063f1699330e70cdedc9b923e517688f5ae71085a26bd9b83b3060ee86e ## @param nodeAttestor.tpmDirect.plugin.path The filename in the container of the plugin path: /app/tpm_attestor_agent pubHash: @@ -203,10 +203,10 @@ nodeAttestor: ## @param nodeAttestor.tpmDirect.pubHash.image.tag Overrides the image tag ## image: - registry: docker.io - repository: boxboat/spire-tpm-plugin-get-tpm-pubhash + registry: ghcr.io + repository: spiffe/spire-tpm-plugin-get-tpm-pubhash pullPolicy: IfNotPresent - tag: "v1.8.7" + tag: "v1.9.0" # workloadAttestors determine a workload's properties and then generate a set of selectors associated with it. workloadAttestors: diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index 101fc0e..cd24ab1 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -365,11 +365,11 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `nodeAttestor.httpChallenge.allowNonRootPorts` | Allow using ports >= 1024 from clients for attestation | `true` | | `nodeAttestor.httpChallenge.tofu` | Trust on first use of the successful challenge. Can only be disabled if allowNonRootPorts=false or requiredPort < 1024 | `true` | | `nodeAttestor.tpmDirect.enabled` | Enable the direct TPM node attestor, a 3rd party plugin by Boxboat. This plugin is experimental. | `false` | -| `nodeAttestor.tpmDirect.image.registry` | The OCI registry to pull the image from | `docker.io` | -| `nodeAttestor.tpmDirect.image.repository` | The repository within the registry | `boxboat/spire-tpm-plugin-tpm-attestor-server` | +| `nodeAttestor.tpmDirect.image.registry` | The OCI registry to pull the image from | `ghcr.io` | +| `nodeAttestor.tpmDirect.image.repository` | The repository within the registry | `spiffe/spire-tpm-plugin-tpm-attestor-server` | | `nodeAttestor.tpmDirect.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `nodeAttestor.tpmDirect.image.tag` | Overrides the image tag | `v1.8.7` | -| `nodeAttestor.tpmDirect.checksum` | The sha256 checksum of the plugin binary | `f39ef9cdd2b3dd74112bfe827b79d6721c59215d0d5f4c2e34fa09bbc60d36d2` | +| `nodeAttestor.tpmDirect.image.tag` | Overrides the image tag | `v1.9.0` | +| `nodeAttestor.tpmDirect.checksum` | The sha256 checksum of the plugin binary | `46d0caad8c25a027dd11c93e18b58a8bc6fbd9f1fe2e36fa2a0dd440986de4dc` | | `nodeAttestor.tpmDirect.pluginPath` | The filename in the container of the plugin | `/app/tpm_attestor_server` | | `nodeAttestor.tpmDirect.cas` | A dictionary of TPM CA PEM or DER files that are allowed to connect. | `{}` | | `nodeAttestor.tpmDirect.hashes` | A list of TPM hashes that are allowed to connect. | `[]` | diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index 7a6a10b..fef4d24 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -897,12 +897,12 @@ nodeAttestor: ## @param nodeAttestor.tpmDirect.image.tag Overrides the image tag ## image: - registry: docker.io - repository: boxboat/spire-tpm-plugin-tpm-attestor-server + registry: ghcr.io + repository: spiffe/spire-tpm-plugin-tpm-attestor-server pullPolicy: IfNotPresent - tag: "v1.8.7" + tag: "v1.9.0" ## @param nodeAttestor.tpmDirect.checksum The sha256 checksum of the plugin binary - checksum: f39ef9cdd2b3dd74112bfe827b79d6721c59215d0d5f4c2e34fa09bbc60d36d2 + checksum: 46d0caad8c25a027dd11c93e18b58a8bc6fbd9f1fe2e36fa2a0dd440986de4dc ## @param nodeAttestor.tpmDirect.pluginPath The filename in the container of the plugin pluginPath: /app/tpm_attestor_server ## @param nodeAttestor.tpmDirect.cas A dictionary of TPM CA PEM or DER files that are allowed to connect. From ed9fb6a121bbf03728692bc436fb6059ab37332d Mon Sep 17 00:00:00 2001 From: "spire-helm-version-checker[bot]" <161522935+spire-helm-version-checker[bot]@users.noreply.github.com> Date: Mon, 21 Apr 2025 06:06:45 -0700 Subject: [PATCH 4/8] Bump test chart dependencies (#566) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com> --- .github/tests/charts.json | 2 +- .github/tests/oci-charts.json | 2 +- charts/spire/charts/spiffe-oidc-discovery-provider/README.md | 2 +- .../spire/charts/spiffe-oidc-discovery-provider/values.yaml | 2 +- charts/spire/charts/spire-agent/README.md | 4 ++-- charts/spire/charts/spire-agent/values.yaml | 4 ++-- charts/spire/charts/spire-server/README.md | 4 ++-- charts/spire/charts/spire-server/values.yaml | 4 ++-- charts/spire/charts/tornjak-frontend/README.md | 2 +- charts/spire/charts/tornjak-frontend/values.yaml | 2 +- 10 files changed, 14 insertions(+), 14 deletions(-) diff --git a/.github/tests/charts.json b/.github/tests/charts.json index 08f0d5e..2e15527 100644 --- a/.github/tests/charts.json +++ b/.github/tests/charts.json @@ -2,7 +2,7 @@ { "name": "kube-prometheus-stack", "repo": "https://prometheus-community.github.io/helm-charts", - "version": "70.4.2" + "version": "70.7.0" }, { "name": "cert-manager", diff --git a/.github/tests/oci-charts.json b/.github/tests/oci-charts.json index cd74aff..2b5aefd 100644 --- a/.github/tests/oci-charts.json +++ b/.github/tests/oci-charts.json @@ -2,7 +2,7 @@ { "name": "mysql", "registry": "docker.io/bitnamicharts/mysql", - "version": "12.3.3" + "version": "12.3.4" }, { "name": "postgresql", diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md index ba3f0c5..ebc8506 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md @@ -120,7 +120,7 @@ A Helm chart to install the SPIFFE OIDC discovery provider. | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:0cc351822c8e066b93d28344713d1a6cbad83e3ee4906d137d7a4e85d9a06f73` | | `tests.toolkit.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.toolkit.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` | | `tests.toolkit.image.pullPolicy` | The image pull policy | `IfNotPresent` | diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml index 91c4051..eeec0b9 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml @@ -340,7 +340,7 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2 + tag: latest@sha256:0cc351822c8e066b93d28344713d1a6cbad83e3ee4906d137d7a4e85d9a06f73 toolkit: ## @param tests.toolkit.image.registry The OCI registry to pull the image from diff --git a/charts/spire/charts/spire-agent/README.md b/charts/spire/charts/spire-agent/README.md index 5535af2..9786d70 100644 --- a/charts/spire/charts/spire-agent/README.md +++ b/charts/spire/charts/spire-agent/README.md @@ -70,7 +70,7 @@ A Helm chart to install the SPIRE agent. | `fsGroupFix.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `fsGroupFix.image.repository` | The repository within the registry | `chainguard/bash` | | `fsGroupFix.image.pullPolicy` | The image pull policy | `Always` | -| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2` | +| `fsGroupFix.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:0cc351822c8e066b93d28344713d1a6cbad83e3ee4906d137d7a4e85d9a06f73` | | `fsGroupFix.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `keyManager.memory.enabled` | Enable the memory based Key Manager | `true` | | `nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s Node Attestor | `true` | @@ -114,7 +114,7 @@ A Helm chart to install the SPIRE agent. | `socketAlternate.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `socketAlternate.image.repository` | The repository within the registry | `chainguard/bash` | | `socketAlternate.image.pullPolicy` | The image pull policy | `Always` | -| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2` | +| `socketAlternate.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:0cc351822c8e066b93d28344713d1a6cbad83e3ee4906d137d7a4e85d9a06f73` | | `socketAlternate.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `hostCert.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `hostCert.image.repository` | The repository within the registry | `chainguard/min-toolkit-debug` | diff --git a/charts/spire/charts/spire-agent/values.yaml b/charts/spire/charts/spire-agent/values.yaml index cdbeb2a..6f6ce56 100644 --- a/charts/spire/charts/spire-agent/values.yaml +++ b/charts/spire/charts/spire-agent/values.yaml @@ -153,7 +153,7 @@ fsGroupFix: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2 + tag: latest@sha256:0cc351822c8e066b93d28344713d1a6cbad83e3ee4906d137d7a4e85d9a06f73 ## @param fsGroupFix.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -280,7 +280,7 @@ socketAlternate: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2 + tag: latest@sha256:0cc351822c8e066b93d28344713d1a6cbad83e3ee4906d137d7a4e85d9a06f73 ## @param socketAlternate.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index cd24ab1..7882326 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -437,7 +437,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `chown.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `chown.image.repository` | The repository within the registry | `chainguard/bash` | | `chown.image.pullPolicy` | The image pull policy | `Always` | -| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2` | +| `chown.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:0cc351822c8e066b93d28344713d1a6cbad83e3ee4906d137d7a4e85d9a06f73` | | `chown.resources` | Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ | `{}` | | `experimental.enabled` | Allow configuration of experimental features | `false` | | `experimental.cacheReloadInterval` | The amount of time between two reloads of the in-memory entry cache. | `5s` | @@ -450,5 +450,5 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:0cc351822c8e066b93d28344713d1a6cbad83e3ee4906d137d7a4e85d9a06f73` | | `kubeConfigs` | Manage additional kubeconfig files to talk to external Kubernetes clusters | `{}` | diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index fef4d24..26faea2 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -1104,7 +1104,7 @@ chown: registry: cgr.dev repository: chainguard/bash pullPolicy: Always - tag: latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2 + tag: latest@sha256:0cc351822c8e066b93d28344713d1a6cbad83e3ee4906d137d7a4e85d9a06f73 ## @param chown.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} @@ -1139,7 +1139,7 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2 + tag: latest@sha256:0cc351822c8e066b93d28344713d1a6cbad83e3ee4906d137d7a4e85d9a06f73 ## @param kubeConfigs [object] Manage additional kubeconfig files to talk to external Kubernetes clusters kubeConfigs: {} diff --git a/charts/spire/charts/tornjak-frontend/README.md b/charts/spire/charts/tornjak-frontend/README.md index 4823017..87548cc 100644 --- a/charts/spire/charts/tornjak-frontend/README.md +++ b/charts/spire/charts/tornjak-frontend/README.md @@ -101,4 +101,4 @@ port forwarding. See the chart NOTES output for more details. | `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | | `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | | `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:0cc351822c8e066b93d28344713d1a6cbad83e3ee4906d137d7a4e85d9a06f73` | diff --git a/charts/spire/charts/tornjak-frontend/values.yaml b/charts/spire/charts/tornjak-frontend/values.yaml index 3d3541f..1e9bcb8 100644 --- a/charts/spire/charts/tornjak-frontend/values.yaml +++ b/charts/spire/charts/tornjak-frontend/values.yaml @@ -162,4 +162,4 @@ tests: registry: cgr.dev repository: chainguard/bash pullPolicy: IfNotPresent - tag: latest@sha256:9c5b741595b1f3ac67945be0046790afa63dad1b450d7e2ca9911a3d2b116ed2 + tag: latest@sha256:0cc351822c8e066b93d28344713d1a6cbad83e3ee4906d137d7a4e85d9a06f73 From 4dee6ca72ec0fceadc4616b35a313b6723e7fea8 Mon Sep 17 00:00:00 2001 From: Roman Willi Date: Wed, 23 Apr 2025 16:14:03 +0200 Subject: [PATCH 5/8] Fix invalid image name for digest in template function of `spire-lib` (#569) Signed-off-by: Roman Willi --- charts/spire/charts/spire-lib/templates/_helpers.tpl | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/charts/spire/charts/spire-lib/templates/_helpers.tpl b/charts/spire/charts/spire-lib/templates/_helpers.tpl index 8e3684a..fab4700 100644 --- a/charts/spire/charts/spire-lib/templates/_helpers.tpl +++ b/charts/spire/charts/spire-lib/templates/_helpers.tpl @@ -53,7 +53,7 @@ {{- $repo := .image.repository }} {{- $tag := .image.tag | toString }} {{- if eq (substr 0 7 $tag) "sha256:" }} -{{- printf "%s/%s@%s" $registry $repo $tag | quote }} +{{- printf "%s%s@%s" $registry $repo $tag | quote }} {{- else if .appVersion }} {{- $appVersion := .appVersion }} {{- if and (hasKey . "ubi") (dig "openshift" false .global) }} From 1169dd5692ffbd7b704df0587450cb33dbaae5e0 Mon Sep 17 00:00:00 2001 From: kfox1111 Date: Wed, 23 Apr 2025 10:56:55 -0700 Subject: [PATCH 6/8] Update spire-controller-manager to 0.6.2 and add its staticManifest support (#563) * Update spire-controller-manager to 0.6.2 and add its staticManifest support Signed-off-by: Kevin Fox * Update docs Signed-off-by: Kevin Fox * Fix indent Signed-off-by: Kevin Fox --------- Signed-off-by: Kevin Fox --- charts/spire/charts/spire-server/README.md | 3 +- .../_controller-manager-container.tpl | 10 ++ .../controller-manager-cluster-ids.yaml | 2 + .../controller-manager-configmap.yaml | 7 ++ .../templates/controller-manager-ftd.yaml | 73 +++++++----- .../templates/controller-manager-roles.yaml | 2 +- .../templates/controller-manager-service.yaml | 2 + .../controller-manager-static-configmap.yaml | 21 ++++ .../controller-manager-static-entries.yaml | 109 ++++++++++-------- .../templates/controller-manager-webhook.yaml | 2 + .../templates/post-install-hook.yaml | 2 + .../templates/post-upgrade-hook.yaml | 2 + .../templates/pre-upgrade-hook.yaml | 2 + .../templates/server-resource.yaml | 5 + charts/spire/charts/spire-server/values.yaml | 5 +- examples/static-manifest-server/values.yaml | 31 +++++ 16 files changed, 197 insertions(+), 81 deletions(-) create mode 100644 charts/spire/charts/spire-server/templates/controller-manager-static-configmap.yaml create mode 100644 examples/static-manifest-server/values.yaml diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index 7882326..df2c2c6 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -257,6 +257,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `notifier.externalK8sBundle.defaults.configMapKey` | ConfigMap key to push the bundle into on external clusters | `bundle.crt` | | `notifier.externalK8sBundle.clusters` | A dictionary of clusters to add with optional overrides. If empty, all clusters defined in kubeConfigs will be used. | `{}` | | `controllerManager.enabled` | Flag to enable controller manager | `false` | +| `controllerManager.staticManifestMode` | Flag to configure static mode. Valid options off, internal, and external. If internal, the identities config options will be rendered to an included configmap | `off` | | `controllerManager.className` | specify to use an explicit class name. If empty, it will be automatically set to Release.Namespace-Release.Name to not conflict with other installs, enabling parallel installs. | `""` | | `controllerManager.watchClassless` | specify to process custom resources without class name specified. Useful to slowly migrate to class names from classless installs. Do not have two installs on the same k8s cluster both set to true. | `false` | | `controllerManager.entryIDPrefixCleanup` | Sets which entry prefixes to remove for migrations. Consult the spiffe.io docs about this option before changing. Its unlikely you will need to ever change it. | `false` | @@ -268,7 +269,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `controllerManager.image.registry` | The OCI registry to pull the image from | `ghcr.io` | | `controllerManager.image.repository` | The repository within the registry | `spiffe/spire-controller-manager` | | `controllerManager.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `controllerManager.image.tag` | Overrides the image tag whose default is the chart appVersion | `0.6.0` | +| `controllerManager.image.tag` | Overrides the image tag whose default is the chart appVersion | `0.6.2` | | `controllerManager.resources` | Resource requests and limits for controller manager | `{}` | | `controllerManager.securityContext` | Security context | `{}` | | `controllerManager.service.type` | Service type for controller manager | `ClusterIP` | diff --git a/charts/spire/charts/spire-server/templates/_controller-manager-container.tpl b/charts/spire/charts/spire-server/templates/_controller-manager-container.tpl index 4c0b4e9..5ce76c3 100644 --- a/charts/spire/charts/spire-server/templates/_controller-manager-container.tpl +++ b/charts/spire/charts/spire-server/templates/_controller-manager-container.tpl @@ -75,7 +75,11 @@ {{- end }} env: - name: ENABLE_WEBHOOKS + {{- if eq .Values.controllerManager.staticManifestMode "off" }} value: {{ .webhooksEnabled | toString | quote }} + {{- else }} + value: "false" + {{- end }} {{- if gt (len $extraEnv) 0 }} {{- $extraEnv | toYaml | nindent 4 }} {{- end }} @@ -91,6 +95,7 @@ - containerPort: {{ $promPort }} name: prom-cm{{ .suffix }} {{- end }} +{{- if eq .Values.controllerManager.staticManifestMode "off" }} livenessProbe: httpGet: path: /healthz @@ -99,12 +104,17 @@ httpGet: path: /readyz port: healthz +{{- end }} resources: {{- toYaml .Values.controllerManager.resources | nindent 4 }} volumeMounts: - name: spire-server-socket mountPath: /tmp/spire-server/private readOnly: true + {{- if ne .Values.controllerManager.staticManifestMode "off" }} + - name: controller-manager-static-config + mountPath: /manifests + {{- end }} - name: controller-manager-config mountPath: /controller-manager-config{{ .suffix }}.yaml subPath: controller-manager-config{{ .suffix }}.yaml diff --git a/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml b/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml index 1973bda..f16c4de 100644 --- a/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml +++ b/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml @@ -26,6 +26,7 @@ matchLabels: {} {{- end }} {{- end }} +{{- if eq .Values.controllerManager.staticManifestMode "off" }} {{- $root := . }} {{ $namespaces := list .Release.Namespace .Values.namespaceOverride (dig "spire" "namespaces" "server" "name" "" .Values.global) (dig "spire" "namespaces" "system" "name" "" .Values.global) | compact | uniq }} {{- range $key, $value := .Values.controllerManager.identities.clusterSPIFFEIDs }} @@ -116,3 +117,4 @@ spec: {{- end }} {{- end }} {{- end }} +{{- end }} diff --git a/charts/spire/charts/spire-server/templates/controller-manager-configmap.yaml b/charts/spire/charts/spire-server/templates/controller-manager-configmap.yaml index f5bad18..57a2f9e 100644 --- a/charts/spire/charts/spire-server/templates/controller-manager-configmap.yaml +++ b/charts/spire/charts/spire-server/templates/controller-manager-configmap.yaml @@ -47,10 +47,12 @@ metrics: bindAddress: 0.0.0.0:{{ $promPort }} health: healthProbeBindAddress: 0.0.0.0:{{ $healthPort }} +{{- if eq .Values.controllerManager.staticManifestMode "off" }} leaderElection: leaderElect: true resourceName: {{ printf "%s-%s%s" .Release.Namespace (default .Release.Name .Values.crNameOverride) .suffix | sha256sum | trunc 8 }}.spiffe.io resourceNamespace: {{ include "spire-server.namespace" . }} +{{- end }} {{- with .settings.cacheNamespaces }} cacheNamespaces: {{- toYaml . | nindent 2 }} @@ -85,7 +87,12 @@ parentIDTemplate: {{ if hasKey .settings "parentIDTemplate" }}{{ .settings.paren {{- $reconcile = .settings.reconcile }} {{- end }} reconcile: + {{- if eq .Values.controllerManager.staticManifestMode "off" }} clusterSPIFFEIDs: {{ if hasKey $reconcile "clusterSPIFFEIDs" }}{{ toYaml $reconcile.clusterSPIFFEIDs }}{{ else }}{{ toYaml .defaults.reconcile.clusterSPIFFEIDs }}{{ end }} + {{- end }} clusterStaticEntries: {{ if hasKey $reconcile "clusterStaticEntries" }}{{ toYaml $reconcile.clusterStaticEntries }}{{ else }}{{ toYaml .defaults.reconcile.clusterStaticEntries }}{{ end }} clusterFederatedTrustDomains: {{ if hasKey $reconcile "clusterFederatedTrustDomains" }}{{ toYaml $reconcile.clusterFederatedTrustDomains }}{{ else }}{{ toYaml .defaults.reconcile.clusterFederatedTrustDomains }}{{ end }} +{{- if ne .Values.controllerManager.staticManifestMode "off" }} +staticManifestPath: /manifests +{{- end }} {{- end }} diff --git a/charts/spire/charts/spire-server/templates/controller-manager-ftd.yaml b/charts/spire/charts/spire-server/templates/controller-manager-ftd.yaml index d41c0b7..dcf0f05 100644 --- a/charts/spire/charts/spire-server/templates/controller-manager-ftd.yaml +++ b/charts/spire/charts/spire-server/templates/controller-manager-ftd.yaml @@ -1,5 +1,7 @@ -{{- $root := . }} -{{- range $key, $value := .Values.controllerManager.identities.clusterFederatedTrustDomains }} +{{- define "spire-server.cluster-federated-trust-domains" -}} +{{- $root := .root }} +{{- $useShortName := .useShortName }} +{{- range $key, $value := $root.Values.controllerManager.identities.clusterFederatedTrustDomains }} {{- range $skey, $svalue := $value }} {{- if not (has $skey (list "name" "annotations" "labels" "enabled" "bundleEndpointProfile" "bundleEndpointURL" "trustDomain" "trustDomainBundle")) }} {{- fail (printf "Unsupported property specified: %s" $skey) }} @@ -12,34 +14,45 @@ {{- end }} {{- if eq ($root.Values.controllerManager.enabled | toString) "true" }} {{- if or (not (hasKey $value "enabled")) (eq ($value.enabled | toString) "true") }} ---- -apiVersion: spire.spiffe.io/v1alpha1 -kind: ClusterFederatedTrustDomain -metadata: - name: {{ $root.Release.Namespace }}-{{ default $root.Release.Name $root.Values.crNameOverride }}-{{ $key }} - {{- with $value.annotations }} - annotations: - {{- toYaml . | nindent 4 }} - {{- end }} - {{- with $value.labels }} - labels: - {{- toYaml . | nindent 4 }} - {{- end }} -spec: - className: {{ include "spire-server.controller-manager-class-name" $root | quote }} - {{- with $value.bundleEndpointProfile }} - bundleEndpointProfile: - {{- toYaml . | nindent 4 }} - {{- end }} - {{- with $value.bundleEndpointURL }} - bundleEndpointURL: {{ . | quote }} - {{- end }} - {{- with $value.trustDomain }} - trustDomain: {{ . | quote }} - {{- end }} - {{- with $value.trustDomainBundle }} - trustDomainBundle: {{ . | quote }} - {{- end }} +- apiVersion: spire.spiffe.io/v1alpha1 + kind: ClusterFederatedTrustDomain + metadata: + {{- if $useShortName }} + name: {{ $key }} + {{- else }} + name: {{ $root.Release.Namespace }}-{{ default $root.Release.Name $root.Values.crNameOverride }}-{{ $key }} + {{- end }} + {{- with $value.annotations }} + annotations: + {{- toYaml . | nindent 6 }} + {{- end }} + {{- with $value.labels }} + labels: + {{- toYaml . | nindent 6 }} + {{- end }} + spec: + className: {{ include "spire-server.controller-manager-class-name" $root | quote }} + {{- with $value.bundleEndpointProfile }} + bundleEndpointProfile: + {{- toYaml . | nindent 6 }} + {{- end }} + {{- with $value.bundleEndpointURL }} + bundleEndpointURL: {{ . | quote }} + {{- end }} + {{- with $value.trustDomain }} + trustDomain: {{ . | quote }} + {{- end }} + {{- with $value.trustDomainBundle }} + trustDomainBundle: {{ . | quote }} + {{- end }} {{- end }} {{- end }} {{- end }} +{{- end }} +{{- if eq .Values.controllerManager.staticManifestMode "off" }} +{{- $t := include "spire-server.cluster-federated-trust-domains" (dict "root" . "useShortName" false) | fromYamlArray }} +{{- range $_, $v := $t }} +--- +{{- $v | toYaml }} +{{- end }} +{{- end }} diff --git a/charts/spire/charts/spire-server/templates/controller-manager-roles.yaml b/charts/spire/charts/spire-server/templates/controller-manager-roles.yaml index 8b18b3d..eee0a00 100644 --- a/charts/spire/charts/spire-server/templates/controller-manager-roles.yaml +++ b/charts/spire/charts/spire-server/templates/controller-manager-roles.yaml @@ -1,4 +1,4 @@ -{{- if eq (.Values.controllerManager.enabled | toString) "true" }} +{{- if and (eq (.Values.controllerManager.enabled | toString) "true") (eq .Values.controllerManager.staticManifestMode "off") }} apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: diff --git a/charts/spire/charts/spire-server/templates/controller-manager-service.yaml b/charts/spire/charts/spire-server/templates/controller-manager-service.yaml index 864c204..e9f547c 100644 --- a/charts/spire/charts/spire-server/templates/controller-manager-service.yaml +++ b/charts/spire/charts/spire-server/templates/controller-manager-service.yaml @@ -1,4 +1,5 @@ {{- if not .Values.externalServer }} +{{- if eq .Values.controllerManager.staticManifestMode "off" }} {{- if eq (.Values.controllerManager.enabled | toString) "true" }} apiVersion: v1 kind: Service @@ -22,3 +23,4 @@ spec: {{- include "spire-server.selectorLabels" . | nindent 4 }} {{- end }} {{- end }} +{{- end }} diff --git a/charts/spire/charts/spire-server/templates/controller-manager-static-configmap.yaml b/charts/spire/charts/spire-server/templates/controller-manager-static-configmap.yaml new file mode 100644 index 0000000..0a40ef8 --- /dev/null +++ b/charts/spire/charts/spire-server/templates/controller-manager-static-configmap.yaml @@ -0,0 +1,21 @@ +{{- if not (has .Values.controllerManager.staticManifestMode (list "off" "internal" "external" )) }} +{{- fail "Unsupported option specified for controllerManager.staticManifestMode" }} +{{- end }} +{{- if eq .Values.controllerManager.staticManifestMode "internal" }} +apiVersion: v1 +kind: ConfigMap +metadata: + name: {{ include "spire-controller-manager.fullname" . }}-static + namespace: {{ include "spire-server.namespace" . }} +data: + {{- $t := include "spire-server.cluster-static-entries" (dict "root" . "useShortName" true) | fromYamlArray }} + {{- range $_, $v := $t }} + "e-{{ $v.metadata.name }}.yaml": | + {{- $v | toYaml | nindent 4 }} + {{- end }} + {{- $t := include "spire-server.cluster-federated-trust-domains" (dict "root" . "useShortName" true) | fromYamlArray }} + {{- range $_, $v := $t }} + "f-{{ $v.metadata.name }}.yaml": | + {{- $v | toYaml | nindent 4 }} + {{- end }} +{{- end }} diff --git a/charts/spire/charts/spire-server/templates/controller-manager-static-entries.yaml b/charts/spire/charts/spire-server/templates/controller-manager-static-entries.yaml index df76208..b557203 100644 --- a/charts/spire/charts/spire-server/templates/controller-manager-static-entries.yaml +++ b/charts/spire/charts/spire-server/templates/controller-manager-static-entries.yaml @@ -1,5 +1,7 @@ -{{- $root := . }} -{{- range $key, $value := .Values.controllerManager.identities.clusterStaticEntries }} +{{- define "spire-server.cluster-static-entries" -}} +{{- $root := .root }} +{{- $useShortName := .useShortName }} +{{- range $key, $value := $root.Values.controllerManager.identities.clusterStaticEntries }} {{- range $skey, $svalue := $value }} {{- if not (has $skey (list "name" "annotations" "labels" "enabled" "admin" "dnsNames" "downstream" "federatesWith" "hint" "jwtSVIDTTL" "parentID" "selectors" "spiffeID" "x509SVIDTTL")) }} {{- fail (printf "Unsupported property specified: %s" $skey) }} @@ -12,52 +14,63 @@ {{- end }} {{- if eq ($root.Values.controllerManager.enabled | toString) "true" }} {{- if or (not (hasKey $value "enabled")) (eq ($value.enabled | toString) "true") }} ---- -apiVersion: spire.spiffe.io/v1alpha1 -kind: ClusterStaticEntry -metadata: - name: {{ $root.Release.Namespace }}-{{ default $root.Release.Name $root.Values.crNameOverride }}-{{ $key }} - {{- with $value.annotations }} - annotations: - {{- toYaml . | nindent 4 }} - {{- end }} - {{- with $value.labels }} - labels: - {{- toYaml . | nindent 4 }} - {{- end }} -spec: - className: {{ include "spire-server.controller-manager-class-name" $root | quote }} - spiffeID: {{ $value.spiffeID | quote }} - {{- with $value.federatesWith }} - federatesWith: - {{- toYaml . | nindent 4 }} - {{- end }} - {{- with $value.selectors }} - selectors: - {{- toYaml . | nindent 4 }} - {{- end }} - {{- with $value.parentID }} - parentID: {{ . | quote }} - {{- end }} - {{- with $value.dnsNames }} - dnsNames: - {{- toYaml . | nindent 4 }} - {{- end }} - {{- with $value.hint }} - hint: {{ . | quote }} - {{- end }} - {{- with $value.x509SVIDTTL }} - x509SVIDTTL: {{ . | quote }} - {{- end }} - {{- with $value.jwtSVIDTTL }} - jwtSVIDTTL: {{ . | quote }} - {{- end }} - {{- with $value.admin }} - admin: {{ . }} - {{- end }} - {{- with $value.downstream }} - downstream: {{ . }} - {{- end }} +- apiVersion: spire.spiffe.io/v1alpha1 + kind: ClusterStaticEntry + metadata: + {{- if $useShortName }} + name: {{ $key }} + {{- else }} + name: {{ $root.Release.Namespace }}-{{ default $root.Release.Name $root.Values.crNameOverride }}-{{ $key }} + {{- end }} + {{- with $value.annotations }} + annotations: + {{- toYaml . | nindent 6 }} + {{- end }} + {{- with $value.labels }} + labels: + {{- toYaml . | nindent 6 }} + {{- end }} + spec: + className: {{ include "spire-server.controller-manager-class-name" $root | quote }} + spiffeID: {{ $value.spiffeID | quote }} + {{- with $value.federatesWith }} + federatesWith: + {{- toYaml . | nindent 6 }} + {{- end }} + {{- with $value.selectors }} + selectors: + {{- toYaml . | nindent 6 }} + {{- end }} + {{- with $value.parentID }} + parentID: {{ . | quote }} + {{- end }} + {{- with $value.dnsNames }} + dnsNames: + {{- toYaml . | nindent 6 }} + {{- end }} + {{- with $value.hint }} + hint: {{ . | quote }} + {{- end }} + {{- with $value.x509SVIDTTL }} + x509SVIDTTL: {{ . | quote }} + {{- end }} + {{- with $value.jwtSVIDTTL }} + jwtSVIDTTL: {{ . | quote }} + {{- end }} + {{- with $value.admin }} + admin: {{ . }} + {{- end }} + {{- with $value.downstream }} + downstream: {{ . }} + {{- end }} {{- end }} {{- end }} {{- end }} +{{- end }} +{{- if eq .Values.controllerManager.staticManifestMode "off" }} +{{- $t := include "spire-server.cluster-static-entries" (dict "root" . "useShortName" false) | fromYamlArray }} +{{- range $_, $v := $t }} +--- +{{- $v | toYaml }} +{{- end }} +{{- end }} diff --git a/charts/spire/charts/spire-server/templates/controller-manager-webhook.yaml b/charts/spire/charts/spire-server/templates/controller-manager-webhook.yaml index 660c2f8..8e80679 100644 --- a/charts/spire/charts/spire-server/templates/controller-manager-webhook.yaml +++ b/charts/spire/charts/spire-server/templates/controller-manager-webhook.yaml @@ -1,4 +1,5 @@ {{- if not .Values.externalServer }} +{{- if eq .Values.controllerManager.staticManifestMode "off" }} {{- if and (eq (.Values.controllerManager.enabled | toString) "true") .Values.controllerManager.validatingWebhookConfiguration.enabled }} apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingWebhookConfiguration @@ -39,3 +40,4 @@ webhooks: sideEffects: None {{- end }} {{- end }} +{{- end }} diff --git a/charts/spire/charts/spire-server/templates/post-install-hook.yaml b/charts/spire/charts/spire-server/templates/post-install-hook.yaml index 4f43dd2..325fbef 100644 --- a/charts/spire/charts/spire-server/templates/post-install-hook.yaml +++ b/charts/spire/charts/spire-server/templates/post-install-hook.yaml @@ -1,5 +1,6 @@ {{- if not .Values.externalServer }} {{- if eq ((dig "installAndUpgradeHooks" "enabled" .Values.controllerManager.installAndUpgradeHook.enabled .Values.global) | toString) "true" }} +{{- if eq .Values.controllerManager.staticManifestMode "off" }} {{- if and (eq (.Values.controllerManager.enabled | toString) "true") .Values.controllerManager.validatingWebhookConfiguration.enabled }} {{- if eq .Values.controllerManager.validatingWebhookConfiguration.failurePolicy "Fail" }} apiVersion: v1 @@ -93,3 +94,4 @@ spec: {{- end }} {{- end }} {{- end }} +{{- end }} diff --git a/charts/spire/charts/spire-server/templates/post-upgrade-hook.yaml b/charts/spire/charts/spire-server/templates/post-upgrade-hook.yaml index 1d6f0a0..309b63c 100644 --- a/charts/spire/charts/spire-server/templates/post-upgrade-hook.yaml +++ b/charts/spire/charts/spire-server/templates/post-upgrade-hook.yaml @@ -1,5 +1,6 @@ {{- if not .Values.externalServer }} {{- if eq ((dig "installAndUpgradeHooks" "enabled" .Values.controllerManager.installAndUpgradeHook.enabled .Values.global) | toString) "true" }} +{{- if eq .Values.controllerManager.staticManifestMode "off" }} {{- if and (eq (.Values.controllerManager.enabled | toString) "true") .Values.controllerManager.validatingWebhookConfiguration.enabled }} {{- if eq .Values.controllerManager.validatingWebhookConfiguration.failurePolicy "Fail" }} apiVersion: v1 @@ -93,3 +94,4 @@ spec: {{- end }} {{- end }} {{- end }} +{{- end }} diff --git a/charts/spire/charts/spire-server/templates/pre-upgrade-hook.yaml b/charts/spire/charts/spire-server/templates/pre-upgrade-hook.yaml index a3258b0..ee92e0d 100644 --- a/charts/spire/charts/spire-server/templates/pre-upgrade-hook.yaml +++ b/charts/spire/charts/spire-server/templates/pre-upgrade-hook.yaml @@ -1,5 +1,6 @@ {{- if not .Values.externalServer }} {{- if eq ((dig "installAndUpgradeHooks" "enabled" .Values.controllerManager.installAndUpgradeHook.enabled .Values.global) | toString) "true" }} +{{- if eq .Values.controllerManager.staticManifestMode "off" }} {{- if and (eq (.Values.controllerManager.enabled | toString) "true") .Values.controllerManager.validatingWebhookConfiguration.enabled }} {{- if eq .Values.controllerManager.validatingWebhookConfiguration.failurePolicy "Fail" }} apiVersion: v1 @@ -93,3 +94,4 @@ spec: {{- end }} {{- end }} {{- end }} +{{- end }} diff --git a/charts/spire/charts/spire-server/templates/server-resource.yaml b/charts/spire/charts/spire-server/templates/server-resource.yaml index fd25438..9b6f7dc 100644 --- a/charts/spire/charts/spire-server/templates/server-resource.yaml +++ b/charts/spire/charts/spire-server/templates/server-resource.yaml @@ -505,6 +505,11 @@ spec: {{- end }} {{- end }} {{- if eq (.Values.controllerManager.enabled | toString) "true" }} + {{- if ne .Values.controllerManager.staticManifestMode "off" }} + - name: controller-manager-static-config + configMap: + name: {{ include "spire-controller-manager.fullname" . }}-static + {{- end }} - name: controller-manager-config configMap: name: {{ include "spire-controller-manager.fullname" . }} diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index 26faea2..c5e6f5c 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -511,6 +511,9 @@ controllerManager: ## @param controllerManager.enabled Flag to enable controller manager enabled: false + ## @param controllerManager.staticManifestMode Flag to configure static mode. Valid options off, internal, and external. If internal, the identities config options will be rendered to an included configmap + staticManifestMode: "off" + ## @param controllerManager.className specify to use an explicit class name. If empty, it will be automatically set to Release.Namespace-Release.Name to not conflict with other installs, enabling parallel installs. className: "" ## @param controllerManager.watchClassless specify to process custom resources without class name specified. Useful to slowly migrate to class names from classless installs. Do not have two installs on the same k8s cluster both set to true. @@ -544,7 +547,7 @@ controllerManager: registry: ghcr.io repository: spiffe/spire-controller-manager pullPolicy: IfNotPresent - tag: "0.6.0" + tag: "0.6.2" ## @param controllerManager.resources [object] Resource requests and limits for controller manager resources: {} diff --git a/examples/static-manifest-server/values.yaml b/examples/static-manifest-server/values.yaml new file mode 100644 index 0000000..99c1d1c --- /dev/null +++ b/examples/static-manifest-server/values.yaml @@ -0,0 +1,31 @@ +spire-server: + nodeAttestor: + k8sPSAT: + enabled: false + joinToken: + enabled: true + tpmDirect: + enabled: true + controllerManager: + enabled: true + staticManifestMode: internal + identities: + clusterStaticEntries: + foo-node: + parentID: spiffe://example.org/spire/server + spiffeID: spiffe://example.org/hosts/foo + selectors: + - tpm:pub_hash:12345 + foo-kubelet: + parentID: spiffe://example.org/foo + spiffeID: spiffe://example.org/k8s/one/node/foo + selectors: + - systemd:id:kubelet.service + ingress: + enabled: true +spire-agent: + enabled: false +spiffe-csi-driver: + enabled: false +spiffe-oidc-discovery-provider: + enabled: false From 8ca477a0bf0f14b5d704dfa73e409f35f70ca92e Mon Sep 17 00:00:00 2001 From: Faisal Memon Date: Thu, 24 Apr 2025 10:59:19 -0700 Subject: [PATCH 7/8] Bump spire Helm Chart version from 0.24.4 to 0.24.5 (#572) * 1169dd5 Update spire-controller-manager to 0.6.2 and add its staticManifest support (#563) * 4dee6ca Fix invalid image name for digest in template function of `spire-lib` (#569) * ed9fb6a Bump test chart dependencies (#566) * 912f412 Update tpm plugin version (#564) * 0fc00cb Bump test chart dependencies (#561) Signed-off-by: Faisal Memon --- charts/spire/Chart.yaml | 2 +- charts/spire/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/charts/spire/Chart.yaml b/charts/spire/Chart.yaml index 75a642f..95f1332 100644 --- a/charts/spire/Chart.yaml +++ b/charts/spire/Chart.yaml @@ -3,7 +3,7 @@ name: spire description: > A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. type: application -version: 0.24.4 +version: 0.24.5 appVersion: "1.12.0" keywords: ["spiffe", "spire", "spire-server", "spire-agent", "oidc", "spire-controller-manager"] home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire diff --git a/charts/spire/README.md b/charts/spire/README.md index 98919b8..3b3c25a 100644 --- a/charts/spire/README.md +++ b/charts/spire/README.md @@ -1,6 +1,6 @@ # spire -![Version: 0.24.4](https://img.shields.io/badge/Version-0.24.4-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.0](https://img.shields.io/badge/AppVersion-1.12.0-informational?style=flat-square) +![Version: 0.24.5](https://img.shields.io/badge/Version-0.24.5-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.0](https://img.shields.io/badge/AppVersion-1.12.0-informational?style=flat-square) [![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. From 27ac69503baefda3db4632d1f61a04a6e5a1cfbf Mon Sep 17 00:00:00 2001 From: Faisal Memon Date: Thu, 24 Apr 2025 10:37:01 -0700 Subject: [PATCH 8/8] Bump spire-nested Helm Chart version from 0.24.4 to 0.24.5 Signed-off-by: Faisal Memon --- charts/spire-nested/Chart.yaml | 2 +- charts/spire-nested/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/charts/spire-nested/Chart.yaml b/charts/spire-nested/Chart.yaml index 13d2a96..60addff 100644 --- a/charts/spire-nested/Chart.yaml +++ b/charts/spire-nested/Chart.yaml @@ -3,7 +3,7 @@ name: spire-nested description: > A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. type: application -version: 0.24.4 +version: 0.24.5 appVersion: "1.12.0" keywords: ["spiffe", "spire", "spire-server", "spire-agent", "oidc", "spire-controller-manager"] home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire diff --git a/charts/spire-nested/README.md b/charts/spire-nested/README.md index 0594b89..078a869 100644 --- a/charts/spire-nested/README.md +++ b/charts/spire-nested/README.md @@ -1,6 +1,6 @@ # spire -![Version: 0.24.4](https://img.shields.io/badge/Version-0.24.4-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.0](https://img.shields.io/badge/AppVersion-1.12.0-informational?style=flat-square) +![Version: 0.24.5](https://img.shields.io/badge/Version-0.24.5-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.0](https://img.shields.io/badge/AppVersion-1.12.0-informational?style=flat-square) [![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.