diff --git a/charts/spire-nested/Chart.yaml b/charts/spire-nested/Chart.yaml index ac14087..6c20050 100644 --- a/charts/spire-nested/Chart.yaml +++ b/charts/spire-nested/Chart.yaml @@ -4,7 +4,7 @@ description: > A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. type: application version: 0.25.0 -appVersion: "1.12.2" +appVersion: "1.12.4" keywords: ["spiffe", "spire", "spire-server", "spire-agent", "oidc", "spire-controller-manager"] home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire sources: diff --git a/charts/spire-nested/README.md b/charts/spire-nested/README.md index 2dd751e..78d9edd 100644 --- a/charts/spire-nested/README.md +++ b/charts/spire-nested/README.md @@ -1,6 +1,6 @@ # spire -![Version: 0.25.0](https://img.shields.io/badge/Version-0.25.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.2](https://img.shields.io/badge/AppVersion-1.12.2-informational?style=flat-square) +![Version: 0.25.0](https://img.shields.io/badge/Version-0.25.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.4](https://img.shields.io/badge/AppVersion-1.12.4-informational?style=flat-square) [![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. @@ -350,6 +350,6 @@ Now you can interact with the Spire agent socket from your own application. The | `external-spire-server.upstreamAuthority.spire.enabled` | Enable upstream SPIRE server | `true` | | `external-spire-server.upstreamAuthority.spire.upstreamDriver` | Use an upstream driver for authentication | `upstream.csi.spiffe.io` | | `external-spire-server.upstreamAuthority.spire.server.nameOverride` | The name override setting of the root SPIRE server | `root-server` | -| `external-spire-server.notifier.k8sBundle.enabled` | Enable local k8s bundle uploader | `false` | +| `external-spire-server.bundlePublisher.k8sConfigMap.enabled` | Enable local k8s bundle uploader | `false` | | `external-spire-server.nodeAttestor.k8sPSAT.enabled` | Enable PSAT k8s nodeattestor | `false` | | `external-spire-server.nodeAttestor.joinToken.enabled` | Enable the join_token nodeattestor | `true` | diff --git a/charts/spire-nested/values.yaml b/charts/spire-nested/values.yaml index 4465ade..3ef0315 100644 --- a/charts/spire-nested/values.yaml +++ b/charts/spire-nested/values.yaml @@ -384,9 +384,9 @@ external-spire-server: server: ## @param external-spire-server.upstreamAuthority.spire.server.nameOverride The name override setting of the root SPIRE server nameOverride: root-server - notifier: - k8sBundle: - ## @param external-spire-server.notifier.k8sBundle.enabled Enable local k8s bundle uploader + bundlePublisher: + k8sConfigMap: + ## @param external-spire-server.bundlePublisher.k8sConfigMap.enabled Enable local k8s bundle uploader enabled: false nodeAttestor: k8sPSAT: diff --git a/charts/spire/Chart.yaml b/charts/spire/Chart.yaml index 3ef2cad..4e00f7a 100644 --- a/charts/spire/Chart.yaml +++ b/charts/spire/Chart.yaml @@ -4,7 +4,7 @@ description: > A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. type: application version: 0.25.0 -appVersion: "1.12.2" +appVersion: "1.12.4" keywords: ["spiffe", "spire", "spire-server", "spire-agent", "oidc", "spire-controller-manager"] home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire sources: diff --git a/charts/spire/README.md b/charts/spire/README.md index 0fb63c3..7df685c 100644 --- a/charts/spire/README.md +++ b/charts/spire/README.md @@ -1,6 +1,6 @@ # spire -![Version: 0.25.0](https://img.shields.io/badge/Version-0.25.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.2](https://img.shields.io/badge/AppVersion-1.12.2-informational?style=flat-square) +![Version: 0.25.0](https://img.shields.io/badge/Version-0.25.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.12.4](https://img.shields.io/badge/AppVersion-1.12.4-informational?style=flat-square) [![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. @@ -88,6 +88,11 @@ kubectl delete crds clusterfederatedtrustdomains.spire.spiffe.io clusterspiffeid We only support upgrading one major/minor version at a time. Version skipping isn't supported. Please see for details. +### 0.26.X + +- The notifier.k8sBundle plugin has been deprecated in favor of bundlePublisher.k8sConfigMap. The only features it does not provide are the settings `apiServiceLabel` and `webhookLabel`. If you are using either of these two features, set the chart to use the notifier.k8sBundle plugin again, and let us know. We don't think anyone is using these features. +- The default trust bundle format has been changed to `spiffe`. This switch should be transparent unless you ware fetching the bundle from the configmap manually, or have a nested setup and dont upgrade the root, then child clusters in short order. + ### 0.24.X - You must upgrade [spire-crds](https://artifacthub.io/packages/helm/spiffe/spire-crds) to 0.5.0+ before performing this upgrade. diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml index 5fa67b0..81cec52 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml @@ -3,7 +3,7 @@ name: spiffe-oidc-discovery-provider description: A Helm chart to install the SPIFFE OIDC discovery provider. type: application version: 0.1.0 -appVersion: "1.12.2" +appVersion: "1.12.4" keywords: ["spiffe", "oidc"] home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire sources: diff --git a/charts/spire/charts/spire-agent/Chart.yaml b/charts/spire/charts/spire-agent/Chart.yaml index 4f121f7..816bb11 100644 --- a/charts/spire/charts/spire-agent/Chart.yaml +++ b/charts/spire/charts/spire-agent/Chart.yaml @@ -3,7 +3,7 @@ name: spire-agent description: A Helm chart to install the SPIRE agent. type: application version: 0.1.0 -appVersion: "1.12.2" +appVersion: "1.12.4" keywords: ["spiffe", "spire-agent"] home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire sources: diff --git a/charts/spire/charts/spire-agent/README.md b/charts/spire/charts/spire-agent/README.md index 92ea859..43fc74f 100644 --- a/charts/spire/charts/spire-agent/README.md +++ b/charts/spire/charts/spire-agent/README.md @@ -52,7 +52,7 @@ A Helm chart to install the SPIRE agent. | `clusterName` | The name of the Kubernetes cluster (`kubeadm init --service-dns-domain`) | `example-cluster` | | `trustDomain` | The trust domain to be used for the SPIFFE identifiers | `example.org` | | `trustBundleURL` | If set, obtain trust bundle from url instead of Kubernetes ConfigMap | `""` | -| `trustBundleFormat` | If using trustBundleURL, what format is the url. Choices are "pem" and "spiffe" | `pem` | +| `trustBundleFormat` | If using trustBundleURL, what format is the url. Choices are "pem" and "spiffe" | `spiffe` | | `trustBundleHostPath` | If set, obtain trust bundle from a file on the host instead of from the ConfigMap | `""` | | `bundleConfigMap` | Configmap name for Spire bundle | `spire-bundle` | | `availabilityTarget` | The minimum amount of time desired to gracefully handle SPIRE Server or Agent downtime. This configurable influences how aggressively X509 SVIDs should be rotated. If set, must be at least 24h. | `""` | diff --git a/charts/spire/charts/spire-agent/templates/configmap.yaml b/charts/spire/charts/spire-agent/templates/configmap.yaml index 1c62fb8..eb4253a 100644 --- a/charts/spire/charts/spire-agent/templates/configmap.yaml +++ b/charts/spire/charts/spire-agent/templates/configmap.yaml @@ -38,13 +38,13 @@ agent: server_address: {{ include "spire-agent.server-address" . | trim | quote }} server_port: {{ .Values.server.port | quote }} socket_path: /tmp/spire-agent/public/{{ include "spire-agent.socket-path" . | base }} + trust_bundle_format: {{ .Values.trustBundleFormat | quote }} {{- if ne (len .Values.trustBundleURL) 0 }} trust_bundle_url: {{ .Values.trustBundleURL | quote }} - trust_bundle_format: {{ .Values.trustBundleFormat | quote }} {{- else if ne (len .Values.trustBundleHostPath) 0 }} trust_bundle_path: {{ .Values.trustBundleHostPath | quote }} {{- else }} - trust_bundle_path: "/run/spire/bundle/bundle.crt" + trust_bundle_path: {{ printf "/run/spire/bundle/bundle.%s" (include "spire-lib.trust-bundle-ext" (dict "trustBundleFormat" .Values.trustBundleFormat)) | quote }} {{- end }} trust_domain: {{ include "spire-lib.trust-domain" . | quote }} {{- with .Values.availabilityTarget }} diff --git a/charts/spire/charts/spire-agent/values.yaml b/charts/spire/charts/spire-agent/values.yaml index 22a3be7..a7dd78a 100644 --- a/charts/spire/charts/spire-agent/values.yaml +++ b/charts/spire/charts/spire-agent/values.yaml @@ -94,7 +94,7 @@ trustDomain: example.org ## @param trustBundleURL If set, obtain trust bundle from url instead of Kubernetes ConfigMap trustBundleURL: "" ## @param trustBundleFormat If using trustBundleURL, what format is the url. Choices are "pem" and "spiffe" -trustBundleFormat: pem +trustBundleFormat: spiffe ## @param trustBundleHostPath If set, obtain trust bundle from a file on the host instead of from the ConfigMap trustBundleHostPath: "" ## @param bundleConfigMap Configmap name for Spire bundle diff --git a/charts/spire/charts/spire-lib/templates/_helpers.tpl b/charts/spire/charts/spire-lib/templates/_helpers.tpl index fab4700..7185d77 100644 --- a/charts/spire/charts/spire-lib/templates/_helpers.tpl +++ b/charts/spire/charts/spire-lib/templates/_helpers.tpl @@ -336,3 +336,11 @@ Anything lower has an incompatible API. {{- fail "Unsupported autoscaling API version" }} {{- end }} {{- end }} + +{{- define "spire-lib.trust-bundle-ext" -}} +{{- if eq .trustBundleFormat "spiffe" }} +{{- print "spiffe" }} +{{- else }} +{{- print "crt" }} +{{- end }} +{{- end }} diff --git a/charts/spire/charts/spire-server/Chart.yaml b/charts/spire/charts/spire-server/Chart.yaml index 17672ea..26dc991 100644 --- a/charts/spire/charts/spire-server/Chart.yaml +++ b/charts/spire/charts/spire-server/Chart.yaml @@ -3,7 +3,7 @@ name: spire-server description: A Helm chart to install the SPIRE server. type: application version: 0.1.0 -appVersion: "1.12.2" +appVersion: "1.12.4" keywords: ["spiffe", "spire-server", "spire-controller-manager"] home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire sources: diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index 1673cc2..e2ddab5 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -256,11 +256,11 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `upstreamAuthority.vault.k8sAuth.k8sAuthRoleName` | Required - Name of the Vault role. The plugin authenticates against the named role | `""` | | `upstreamAuthority.vault.k8sAuth.token.audience` | Intended audience of the PSAT, it must match one of the audiences supported by the Kubernetes API server. If no audience is specified, it defaults to the identifier of API Server. See ['Service Account Documentation'](https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/#serviceaccount-token-volume-projection) for more info. | `vault` | | `upstreamAuthority.vault.k8sAuth.token.expiry` | Expiry time in seconds for the token | `7200` | -| `notifier.k8sBundle.enabled` | Enable local k8s bundle uploader | `true` | +| `notifier.k8sBundle.enabled` | Enable local k8s bundle uploader | `false` | | `notifier.k8sBundle.namespace` | Namespace to push the bundle into, if blank will default to SPIRE Server namespace | `""` | | `notifier.k8sBundle.apiServiceLabel` | If set, rotate the CA Bundle in API services with this label set to true. | `""` | | `notifier.k8sBundle.webhookLabel` | If set, rotate the CA Bundle in validating and mutating webhooks with this label set to true. | `""` | -| `notifier.externalK8sBundle.enabled` | Enable external k8s bundle uploader | `true` | +| `notifier.externalK8sBundle.enabled` | Enable external k8s bundle uploader | `false` | | `notifier.externalK8sBundle.defaults.namespace` | Namespace to push the bundle into on clusters | `spire-system` | | `notifier.externalK8sBundle.defaults.configMap` | ConfigMap name to push the bundle into on external clusters | `spire-bundle-upstream` | | `notifier.externalK8sBundle.defaults.configMapKey` | ConfigMap key to push the bundle into on external clusters | `bundle.crt` | @@ -396,6 +396,15 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `nodeAttestor.tpmDirect.pluginPath` | The filename in the container of the plugin | `/app/tpm_attestor_server` | | `nodeAttestor.tpmDirect.cas` | A dictionary of TPM CA PEM or DER files that are allowed to connect. | `{}` | | `nodeAttestor.tpmDirect.hashes` | A list of TPM hashes that are allowed to connect. | `[]` | +| `bundlePublisher.k8sConfigMap.enabled` | Enable local k8s bundle uploader | `true` | +| `bundlePublisher.k8sConfigMap.namespace` | Namespace to push the bundle into, if blank will default to SPIRE Server namespace | `""` | +| `bundlePublisher.k8sConfigMap.format` | Format of the trust bundle. Can be pem or spiffe | `spiffe` | +| `bundlePublisher.externalK8sConfigMap.enabled` | Enable external k8s bundle uploader | `true` | +| `bundlePublisher.externalK8sConfigMap.defaults.namespace` | Namespace to push the bundle into on clusters | `spire-system` | +| `bundlePublisher.externalK8sConfigMap.defaults.configMapName` | ConfigMap name to push the bundle into on external clusters | `spire-bundle-upstream` | +| `bundlePublisher.externalK8sConfigMap.defaults.configMapKey` | ConfigMap key to push the bundle into on external clusters | `""` | +| `bundlePublisher.externalK8sConfigMap.defaults.format` | Format of the trust bundle. Can be pem or spiffe | `spiffe` | +| `bundlePublisher.externalK8sConfigMap.clusters` | A dictionary of clusters to add with optional overrides. If empty, all clusters defined in kubeConfigs will be used. | `{}` | | `bundlePublisher.awsRolesAnywhereTrustAnchor.enabled` | Enable the AWS S3 bundle publisher | `false` | | `bundlePublisher.awsRolesAnywhereTrustAnchor.region` | AWS region to store the trust bundle | `""` | | `bundlePublisher.awsRolesAnywhereTrustAnchor.trustAnchorID` | AWS trust anchor ID to publish to | `""` | diff --git a/charts/spire/charts/spire-server/templates/_helpers.tpl b/charts/spire/charts/spire-server/templates/_helpers.tpl index 49c8e6e..c2c755e 100644 --- a/charts/spire/charts/spire-server/templates/_helpers.tpl +++ b/charts/spire/charts/spire-server/templates/_helpers.tpl @@ -65,7 +65,23 @@ Allow the release namespace to be overridden for multi-namespace deployments in {{- end -}} {{- end -}} -{{- define "spire-server.bundle-namespace" -}} +{{- define "spire-server.bundle-namespace-bundlepublisher" -}} + {{- if .Values.bundlePublisher.k8sConfigMap.namespace }} + {{- .Values.bundlePublisher.k8sConfigMap.namespace }} + {{- else if .Values.namespaceOverride -}} + {{- .Values.namespaceOverride -}} + {{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }} + {{- if ne (len (dig "spire" "namespaces" "system" "name" "" .Values.global)) 0 }} + {{- .Values.global.spire.namespaces.system.name }} + {{- else }} + {{- printf "spire-system" }} + {{- end }} + {{- else -}} + {{- .Release.Namespace -}} + {{- end -}} +{{- end -}} + +{{- define "spire-server.bundle-namespace-notifier" -}} {{- if .Values.notifier.k8sBundle.namespace }} {{- .Values.notifier.k8sBundle.namespace }} {{- else if .Values.namespaceOverride -}} @@ -81,6 +97,14 @@ Allow the release namespace to be overridden for multi-namespace deployments in {{- end -}} {{- end -}} +{{- define "spire-server.bundle-namespace" -}} + {{- if .Values.notifier.k8sBundle.namespace }} + {{- .Values.notifier.k8sBundle.namespace }} + {{- else }} + {{- include "spire-server.bundle-namespace-bundlepublisher" . -}} + {{- end }} +{{- end }} + {{- define "spire-server.podMonitor.namespace" -}} {{- if ne (len .Values.telemetry.prometheus.podMonitor.namespace) 0 }} {{- .Values.telemetry.prometheus.podMonitor.namespace }} diff --git a/charts/spire/charts/spire-server/templates/bundle-configmap.yaml b/charts/spire/charts/spire-server/templates/bundle-configmap.yaml index 4217322..505d66b 100644 --- a/charts/spire/charts/spire-server/templates/bundle-configmap.yaml +++ b/charts/spire/charts/spire-server/templates/bundle-configmap.yaml @@ -1,3 +1,7 @@ +{{- if and .Values.notifier.k8sBundle.enabled .Values.bundlePublisher.k8sConfigMap.enabled }} +{{- fail "You can only enable either notifier.k8sBundle or bundlePublisher.k8sConfigMap." }} +{{- end }} +{{- if .Values.notifier.k8sBundle.enabled }} {{- $namespace := include "spire-server.bundle-namespace" . }} apiVersion: v1 kind: ConfigMap @@ -8,3 +12,4 @@ metadata: annotations: {{- toYaml . | nindent 4 }} {{- end }} +{{- end }} diff --git a/charts/spire/charts/spire-server/templates/configmap.yaml b/charts/spire/charts/spire-server/templates/configmap.yaml index ed30e50..8b0b923 100644 --- a/charts/spire/charts/spire-server/templates/configmap.yaml +++ b/charts/spire/charts/spire-server/templates/configmap.yaml @@ -274,7 +274,7 @@ plugins: k8sbundle: plugin_data: {{- if eq (.Values.notifier.k8sBundle.enabled | toString) "true" }} - namespace: {{ include "spire-server.bundle-namespace" . | quote }} + namespace: {{ include "spire-server.bundle-namespace-notifier" . | quote }} config_map: {{ include "spire-lib.bundle-configmap" . | quote }} {{- with .Values.notifier.k8sBundle.apiServiceLabel }} api_service_label: {{ . | quote }} @@ -304,8 +304,51 @@ plugins: {{- end }} {{- end }} - {{- if or .Values.bundlePublisher.awsRolesAnywhereTrustAnchor.enabled .Values.bundlePublisher.awsS3.enabled .Values.bundlePublisher.gcpCloudStorage.enabled }} + {{- $externalK8sConfigMapClusters := default .Values.kubeConfigs .Values.bundlePublisher.externalK8sConfigMap.clusters }} + {{- if or .Values.bundlePublisher.awsRolesAnywhereTrustAnchor.enabled .Values.bundlePublisher.awsS3.enabled .Values.bundlePublisher.gcpCloudStorage.enabled .Values.bundlePublisher.k8sConfigMap.enabled (and .Values.bundlePublisher.externalK8sConfigMap.enabled (ne (len $externalK8sConfigMapClusters) 0)) }} BundlePublisher: + {{- if or .Values.bundlePublisher.k8sConfigMap.enabled (and .Values.bundlePublisher.externalK8sConfigMap.enabled (ne (len $externalK8sConfigMapClusters) 0)) }} + k8s_configmap: + plugin_data: + clusters: + {{- $prefix := "-" }} + {{- if eq (.Values.bundlePublisher.k8sConfigMap.enabled | toString) "true" }} + {{ $prefix }} chart-internal: + format: {{ .Values.bundlePublisher.k8sConfigMap.format | quote }} + namespace: {{ include "spire-server.bundle-namespace-bundlepublisher" . | quote }} + configmap_name: {{ include "spire-lib.bundle-configmap" . | quote }} + configmap_key: {{ printf "bundle.%s" (include "spire-lib.trust-bundle-ext" (dict "trustBundleFormat" .Values.bundlePublisher.k8sConfigMap.format)) | quote }} + {{- $prefix := " " }} + {{- end }} + {{- if and (eq (.Values.bundlePublisher.externalK8sConfigMap.enabled | toString) "true") (ne (len $externalK8sConfigMapClusters) 0) }} + {{- $clusterDefaults := .Values.bundlePublisher.externalK8sConfigMap.defaults }} + {{- range $name, $_ := $externalK8sConfigMapClusters }} + {{ $prefix }} {{ $name | quote }}: + {{- $clusterSettings := dict }} + {{- if hasKey $root.Values.bundlePublisher.externalK8sConfigMap.clusters $name }} + {{- $clusterSettings = index $root.Values.bundlePublisher.externalK8sConfigMap.clusters $name }} + {{- end }} + {{- if hasKey $clusterSettings "kubeConfigName" }} + kubeconfig_path: /kubeconfigs/{{ $clusterSettings.kubeConfigName }} + {{- else }} + kubeconfig_path: /kubeconfigs/{{ $name }} + {{- end }} + {{- $format := $clusterDefaults.format }} + {{- if hasKey $clusterSettings "format" }}{{- $format = $clusterSettings.format }}{{- end }} + format: {{ $format | quote }} + namespace: {{ if hasKey $clusterSettings "namespace" }}{{ $clusterSettings.namespace }}{{ else }}{{ $clusterDefaults.namespace }}{{ end }} + configmap_name: {{ if hasKey $clusterSettings "configMapName" }}{{ $clusterSettings.configMapName }}{{ else }}{{ $clusterDefaults.configMapName }}{{ end }} + {{- if hasKey $clusterSettings "configMapKey" }} + configmap_key: {{ $clusterSettings.configMapKey | quote }} + {{- else if ne $clusterDefaults.configMapKey "" }} + configmap_key: {{ $clusterDefaults.configMapKey | quote }} + {{- else }} + configmap_key: {{ printf "bundle.%s" (include "spire-lib.trust-bundle-ext" (dict "trustBundleFormat" $format)) | quote }} + {{- end }} + {{- $prefix := " " }} + {{- end }} + {{- end }} + {{- end }} {{- if .Values.bundlePublisher.awsRolesAnywhereTrustAnchor.enabled }} aws_rolesanywhere_trustanchor: plugin_data: diff --git a/charts/spire/charts/spire-server/templates/roles.yaml b/charts/spire/charts/spire-server/templates/roles.yaml index 197dc02..47ef87b 100644 --- a/charts/spire/charts/spire-server/templates/roles.yaml +++ b/charts/spire/charts/spire-server/templates/roles.yaml @@ -1,7 +1,7 @@ {{- $subject := include "spire-server.subject" . }} {{- $namespace := include "spire-server.namespace" . }} {{- $bundleNamespace := include "spire-server.bundle-namespace" . }} -{{- if .Values.notifier.k8sBundle.enabled }} +{{- if or .Values.notifier.k8sBundle.enabled .Values.bundlePublisher.k8sConfigMap.enabled }} # Role to be able to push certificate bundles to a configmap kind: Role apiVersion: rbac.authorization.k8s.io/v1 @@ -15,6 +15,9 @@ rules: verbs: - get - patch +{{- if .Values.bundlePublisher.k8sConfigMap.enabled }} + - create +{{- end }} {{- end }} {{- if and .Values.upstreamAuthority.certManager.enabled .Values.upstreamAuthority.certManager.rbac.create }} --- @@ -48,7 +51,7 @@ roleRef: name: {{ include "spire-server.fullname" . }}-cm apiGroup: rbac.authorization.k8s.io {{- end }} -{{- if .Values.notifier.k8sBundle.enabled }} +{{- if or .Values.notifier.k8sBundle.enabled .Values.bundlePublisher.k8sConfigMap.enabled }} --- kind: RoleBinding apiVersion: rbac.authorization.k8s.io/v1 diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index 816fb8f..79dceec 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -514,7 +514,7 @@ upstreamAuthority: notifier: k8sBundle: ## @param notifier.k8sBundle.enabled Enable local k8s bundle uploader - enabled: true + enabled: false ## @param notifier.k8sBundle.namespace Namespace to push the bundle into, if blank will default to SPIRE Server namespace namespace: "" ## @param notifier.k8sBundle.apiServiceLabel If set, rotate the CA Bundle in API services with this label set to true. @@ -523,7 +523,7 @@ notifier: webhookLabel: "" externalK8sBundle: ## @param notifier.externalK8sBundle.enabled Enable external k8s bundle uploader - enabled: true + enabled: false defaults: ## @param notifier.externalK8sBundle.defaults.namespace Namespace to push the bundle into on clusters namespace: "spire-system" @@ -978,6 +978,30 @@ nodeAttestor: # The secrets needed for this plugin are configured in the secrets: section bundlePublisher: + k8sConfigMap: + ## @param bundlePublisher.k8sConfigMap.enabled Enable local k8s bundle uploader + enabled: true + ## @param bundlePublisher.k8sConfigMap.namespace Namespace to push the bundle into, if blank will default to SPIRE Server namespace + namespace: "" + ## @param bundlePublisher.k8sConfigMap.format Format of the trust bundle. Can be pem or spiffe + format: spiffe + externalK8sConfigMap: + ## @param bundlePublisher.externalK8sConfigMap.enabled Enable external k8s bundle uploader + enabled: true + defaults: + ## @param bundlePublisher.externalK8sConfigMap.defaults.namespace Namespace to push the bundle into on clusters + namespace: "spire-system" + ## @param bundlePublisher.externalK8sConfigMap.defaults.configMapName ConfigMap name to push the bundle into on external clusters + configMapName: "spire-bundle-upstream" + ## @param bundlePublisher.externalK8sConfigMap.defaults.configMapKey ConfigMap key to push the bundle into on external clusters + configMapKey: "" + ## @param bundlePublisher.externalK8sConfigMap.defaults.format Format of the trust bundle. Can be pem or spiffe + format: spiffe + ## @param bundlePublisher.externalK8sConfigMap.clusters [object] A dictionary of clusters to add with optional overrides. If empty, all clusters defined in kubeConfigs will be used. + clusters: {} + # clustera: + # namespace: foo + # clusterb: {} awsRolesAnywhereTrustAnchor: ## @param bundlePublisher.awsRolesAnywhereTrustAnchor.enabled Enable the AWS S3 bundle publisher enabled: false diff --git a/tests/integration/spiffe-step-ssh/run-tests.sh b/tests/integration/spiffe-step-ssh/run-tests.sh index 109792d..772b241 100755 --- a/tests/integration/spiffe-step-ssh/run-tests.sh +++ b/tests/integration/spiffe-step-ssh/run-tests.sh @@ -152,7 +152,7 @@ popd helm upgrade --install spiffe-step-ssh charts/spiffe-step-ssh --set caPassword="$(cat spiffe-step-ssh-password.txt)" -f spiffe-step-ssh-values.yaml -f "${SCRIPTPATH}/ingress-values.yaml" --set trustDomain=production.other --wait --timeout 10m # Is fetchca responding. -kubectl get configmap -n spire-system spire-bundle-downstream -o go-template='{{ index .data "bundle.crt" }}' > /tmp/ca.pem +kubectl exec -it -n spire-server spire-internal-server-0 -- spire-server bundle show > /tmp/ca.pem cat /tmp/ca.pem curl https://spiffe-step-ssh-fetchca.production.other -s --cacert /tmp/ca.pem