Remove option to choose different agent socket path
Resolves #19 Signed-off-by: Marco Franssen <[email protected]>
This commit is contained in:
@@ -59,13 +59,12 @@ Kubernetes: `>=1.21.0-0`
|
|||||||
|-----|------|---------|-------------|
|
|-----|------|---------|-------------|
|
||||||
| fullnameOverride | string | `""` | |
|
| fullnameOverride | string | `""` | |
|
||||||
| nameOverride | string | `""` | |
|
| nameOverride | string | `""` | |
|
||||||
| spiffe-csi-driver.agentSocketPath | string | `"/run/spire/agent-sockets/spire-agent.sock"` | |
|
| spiffe-csi-driver | object | `{}` | |
|
||||||
| spiffe-oidc-discovery-provider.enabled | bool | `false` | |
|
| spiffe-oidc-discovery-provider.enabled | bool | `false` | |
|
||||||
| spiffe-oidc-discovery-provider.trustDomain | string | `"example.org"` | |
|
| spiffe-oidc-discovery-provider.trustDomain | string | `"example.org"` | |
|
||||||
| spire-agent.bundleConfigMap | string | `"spire-bundle"` | |
|
| spire-agent.bundleConfigMap | string | `"spire-bundle"` | |
|
||||||
| spire-agent.clusterName | string | `"example-cluster"` | |
|
| spire-agent.clusterName | string | `"example-cluster"` | |
|
||||||
| spire-agent.nameOverride | string | `"agent"` | |
|
| spire-agent.nameOverride | string | `"agent"` | |
|
||||||
| spire-agent.socketPath | string | `"/run/spire/agent-sockets/spire-agent.sock"` | |
|
|
||||||
| spire-agent.trustDomain | string | `"example.org"` | |
|
| spire-agent.trustDomain | string | `"example.org"` | |
|
||||||
| spire-server.bundleConfigMap | string | `"spire-bundle"` | |
|
| spire-server.bundleConfigMap | string | `"spire-bundle"` | |
|
||||||
| spire-server.clusterName | string | `"example-cluster"` | |
|
| spire-server.clusterName | string | `"example-cluster"` | |
|
||||||
|
|||||||
@@ -10,7 +10,6 @@ A Helm chart to install the SPIFFE CSI driver.
|
|||||||
|
|
||||||
| Key | Type | Default | Description |
|
| Key | Type | Default | Description |
|
||||||
|-----|------|---------|-------------|
|
|-----|------|---------|-------------|
|
||||||
| agentSocketPath | string | `"/run/spire/agent-sockets/spire-agent.sock"` | |
|
|
||||||
| fullnameOverride | string | `""` | |
|
| fullnameOverride | string | `""` | |
|
||||||
| image.pullPolicy | string | `"IfNotPresent"` | |
|
| image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
| image.registry | string | `"ghcr.io"` | |
|
| image.registry | string | `"ghcr.io"` | |
|
||||||
|
|||||||
@@ -96,11 +96,11 @@ spec:
|
|||||||
volumes:
|
volumes:
|
||||||
- name: spire-agent-sockets
|
- name: spire-agent-sockets
|
||||||
hostPath:
|
hostPath:
|
||||||
path: {{ dir .Values.agentSocketPath }}
|
path: {{ include "spire.agent-socket-path" . | dir }}
|
||||||
type: DirectoryOrCreate
|
type: DirectoryOrCreate
|
||||||
- name: spire-agent-socket-dir
|
- name: spire-agent-socket-dir
|
||||||
hostPath:
|
hostPath:
|
||||||
path: {{ dir .Values.agentSocketPath }}
|
path: {{ include "spire.agent-socket-path" . | dir }}
|
||||||
type: DirectoryOrCreate
|
type: DirectoryOrCreate
|
||||||
# This volume is where the socket for kubelet->driver communication lives
|
# This volume is where the socket for kubelet->driver communication lives
|
||||||
- name: spiffe-csi-socket-dir
|
- name: spiffe-csi-socket-dir
|
||||||
|
|||||||
@@ -63,5 +63,3 @@ nodeDriverRegistrar:
|
|||||||
# limits:
|
# limits:
|
||||||
# cpu: 100m
|
# cpu: 100m
|
||||||
# memory: 64Mi
|
# memory: 64Mi
|
||||||
|
|
||||||
agentSocketPath: /run/spire/agent-sockets/spire-agent.sock
|
|
||||||
|
|||||||
@@ -11,7 +11,6 @@ A Helm chart to install the SPIFFE OIDC discovery provider.
|
|||||||
| Key | Type | Default | Description |
|
| Key | Type | Default | Description |
|
||||||
|-----|------|---------|-------------|
|
|-----|------|---------|-------------|
|
||||||
| affinity | object | `{}` | |
|
| affinity | object | `{}` | |
|
||||||
| agentSocketPath | string | `"/run/spire/agent-sockets/spire-agent.sock"` | |
|
|
||||||
| autoscaling.enabled | bool | `false` | |
|
| autoscaling.enabled | bool | `false` | |
|
||||||
| autoscaling.maxReplicas | int | `5` | |
|
| autoscaling.maxReplicas | int | `5` | |
|
||||||
| autoscaling.minReplicas | int | `1` | |
|
| autoscaling.minReplicas | int | `1` | |
|
||||||
|
|||||||
@@ -30,7 +30,7 @@ data:
|
|||||||
{{- end }}
|
{{- end }}
|
||||||
|
|
||||||
workload_api {
|
workload_api {
|
||||||
socket_path = "/spiffe-workload-api/{{ splitList "/" .Values.agentSocketPath | last }}"
|
socket_path = "/spiffe-workload-api/{{ include "spire.agent-socket-path" . | splitList "/" | last }}"
|
||||||
trust_domain = "{{ .Values.trustDomain }}"
|
trust_domain = "{{ .Values.trustDomain }}"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -109,5 +109,4 @@ tolerations: []
|
|||||||
|
|
||||||
affinity: {}
|
affinity: {}
|
||||||
|
|
||||||
agentSocketPath: /run/spire/agent-sockets/spire-agent.sock
|
|
||||||
trustDomain: "example.org"
|
trustDomain: "example.org"
|
||||||
|
|||||||
@@ -29,7 +29,6 @@ A Helm chart to install the SPIRE agent.
|
|||||||
| serviceAccount.annotations | object | `{}` | |
|
| serviceAccount.annotations | object | `{}` | |
|
||||||
| serviceAccount.create | bool | `true` | |
|
| serviceAccount.create | bool | `true` | |
|
||||||
| serviceAccount.name | string | `""` | |
|
| serviceAccount.name | string | `""` | |
|
||||||
| socketPath | string | `"/run/spire/agent-sockets/spire-agent.sock"` | |
|
|
||||||
| trustDomain | string | `"example.org"` | |
|
| trustDomain | string | `"example.org"` | |
|
||||||
| waitForIt.image.pullPolicy | string | `"IfNotPresent"` | |
|
| waitForIt.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
| waitForIt.image.registry | string | `"cgr.dev"` | |
|
| waitForIt.image.registry | string | `"cgr.dev"` | |
|
||||||
|
|||||||
@@ -10,7 +10,7 @@ data:
|
|||||||
log_level = {{ .Values.logLevel | quote }}
|
log_level = {{ .Values.logLevel | quote }}
|
||||||
server_address = "{{ .Release.Name }}-server"
|
server_address = "{{ .Release.Name }}-server"
|
||||||
server_port = {{ .Values.server.port | quote }}
|
server_port = {{ .Values.server.port | quote }}
|
||||||
socket_path = {{ .Values.socketPath | quote }}
|
socket_path = {{ include "spire.agent-socket-path" . | quote }}
|
||||||
trust_bundle_path = "/run/spire/bundle/bundle.crt"
|
trust_bundle_path = "/run/spire/bundle/bundle.crt"
|
||||||
trust_domain = {{ .Values.trustDomain | quote }}
|
trust_domain = {{ .Values.trustDomain | quote }}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -51,7 +51,7 @@ spec:
|
|||||||
mountPath: /run/spire/bundle
|
mountPath: /run/spire/bundle
|
||||||
readOnly: true
|
readOnly: true
|
||||||
- name: spire-agent-socket-dir
|
- name: spire-agent-socket-dir
|
||||||
mountPath: {{ dir .Values.socketPath }}
|
mountPath: {{ include "spire.agent-socket-path" . | dir }}
|
||||||
readOnly: false
|
readOnly: false
|
||||||
- name: spire-token
|
- name: spire-token
|
||||||
mountPath: /var/run/secrets/tokens
|
mountPath: /var/run/secrets/tokens
|
||||||
@@ -89,5 +89,5 @@ spec:
|
|||||||
audience: spire-server
|
audience: spire-server
|
||||||
- name: spire-agent-socket-dir
|
- name: spire-agent-socket-dir
|
||||||
hostPath:
|
hostPath:
|
||||||
path: {{ dir .Values.socketPath }}
|
path: {{ include "spire.agent-socket-path" . | dir }}
|
||||||
type: DirectoryOrCreate
|
type: DirectoryOrCreate
|
||||||
|
|||||||
@@ -53,7 +53,6 @@ nodeSelector:
|
|||||||
kubernetes.io/arch: amd64
|
kubernetes.io/arch: amd64
|
||||||
|
|
||||||
logLevel: info
|
logLevel: info
|
||||||
socketPath: /run/spire/agent-sockets/spire-agent.sock
|
|
||||||
clusterName: example-cluster
|
clusterName: example-cluster
|
||||||
trustDomain: example.org
|
trustDomain: example.org
|
||||||
|
|
||||||
|
|||||||
@@ -29,3 +29,11 @@ Create chart name and version as used by the chart label.
|
|||||||
{{- define "spire.chart" -}}
|
{{- define "spire.chart" -}}
|
||||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|
||||||
|
{{- define "spire.agent-socket-path" -}}
|
||||||
|
{{- print "/run/spire/agent-sockets/spire-agent.sock" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- define "spire.server-socket-path" -}}
|
||||||
|
{{- print "/run/spire/server-sockets/spire-server.sock" }}
|
||||||
|
{{- end }}
|
||||||
|
|||||||
@@ -16,10 +16,7 @@ spire-agent:
|
|||||||
clusterName: *clusterName
|
clusterName: *clusterName
|
||||||
trustDomain: *trustDomain
|
trustDomain: *trustDomain
|
||||||
|
|
||||||
socketPath: &agentSocketPath /run/spire/agent-sockets/spire-agent.sock
|
spiffe-csi-driver: {}
|
||||||
|
|
||||||
spiffe-csi-driver:
|
|
||||||
agentSocketPath: *agentSocketPath
|
|
||||||
|
|
||||||
spiffe-oidc-discovery-provider:
|
spiffe-oidc-discovery-provider:
|
||||||
enabled: false
|
enabled: false
|
||||||
|
|||||||
Reference in New Issue
Block a user