Move oidc-discovery-provider to sub chart
Signed-off-by: Marco Franssen <[email protected]> Co-authored-by: Gert Jan Kamstra <[email protected]> Signed-off-by: Marco Franssen <[email protected]> Signed-off-by: Marco Franssen <[email protected]>
This commit is contained in:
co-authored by
Gert Jan Kamstra
parent
35b8ad3c00
commit
99da500c1c
@@ -42,3 +42,7 @@ dependencies:
|
|||||||
- name: spiffe-csi-driver
|
- name: spiffe-csi-driver
|
||||||
repository: file://./charts/spiffe-csi-driver
|
repository: file://./charts/spiffe-csi-driver
|
||||||
version: 0.1.0
|
version: 0.1.0
|
||||||
|
- name: spiffe-oidc-discovery-provider
|
||||||
|
condition: spiffe-oidc-discovery-provider.enabled
|
||||||
|
repository: file://./charts/spiffe-oidc-discovery-provider
|
||||||
|
version: 0.1.0
|
||||||
|
|||||||
+2
-29
@@ -47,6 +47,7 @@ Kubernetes: `>=1.21.0-0`
|
|||||||
| Repository | Name | Version |
|
| Repository | Name | Version |
|
||||||
|------------|------|---------|
|
|------------|------|---------|
|
||||||
| file://./charts/spiffe-csi-driver | spiffe-csi-driver | 0.1.0 |
|
| file://./charts/spiffe-csi-driver | spiffe-csi-driver | 0.1.0 |
|
||||||
|
| file://./charts/spiffe-oidc-discovery-provider | spiffe-oidc-discovery-provider | 0.1.0 |
|
||||||
|
|
||||||
## Values
|
## Values
|
||||||
|
|
||||||
@@ -64,35 +65,6 @@ Kubernetes: `>=1.21.0-0`
|
|||||||
| fullnameOverride | string | `""` | |
|
| fullnameOverride | string | `""` | |
|
||||||
| imagePullSecrets | list | `[]` | |
|
| imagePullSecrets | list | `[]` | |
|
||||||
| nameOverride | string | `""` | |
|
| nameOverride | string | `""` | |
|
||||||
| oidc.affinity | object | `{}` | |
|
|
||||||
| oidc.config.acme.cacheDir | string | `"/run/spire"` | |
|
|
||||||
| oidc.config.acme.directoryUrl | string | `"https://acme-v02.api.letsencrypt.org/directory"` | |
|
|
||||||
| oidc.config.acme.emailAddress | string | `"[email protected]"` | |
|
|
||||||
| oidc.config.acme.tosAccepted | bool | `false` | |
|
|
||||||
| oidc.config.domains[0] | string | `"localhost"` | |
|
|
||||||
| oidc.config.domains[1] | string | `"oidc-discovery.example.org"` | |
|
|
||||||
| oidc.config.logLevel | string | `"info"` | |
|
|
||||||
| oidc.enabled | bool | `false` | |
|
|
||||||
| oidc.image.pullPolicy | string | `"IfNotPresent"` | |
|
|
||||||
| oidc.image.registry | string | `"ghcr.io"` | |
|
|
||||||
| oidc.image.repository | string | `"spiffe/oidc-discovery-provider"` | |
|
|
||||||
| oidc.image.version | string | `""` | |
|
|
||||||
| oidc.insecureScheme.enabled | bool | `false` | |
|
|
||||||
| oidc.insecureScheme.nginx.image.pullPolicy | string | `"IfNotPresent"` | |
|
|
||||||
| oidc.insecureScheme.nginx.image.registry | string | `"docker.io"` | |
|
|
||||||
| oidc.insecureScheme.nginx.image.repository | string | `"nginx"` | |
|
|
||||||
| oidc.insecureScheme.nginx.image.version | string | `"1.23.2-alpine"` | |
|
|
||||||
| oidc.insecureScheme.nginx.resources | object | `{}` | |
|
|
||||||
| oidc.nodeSelector."kubernetes.io/arch" | string | `"amd64"` | |
|
|
||||||
| oidc.podAnnotations | object | `{}` | |
|
|
||||||
| oidc.podSecurityContext | object | `{}` | |
|
|
||||||
| oidc.replicaCount | int | `1` | |
|
|
||||||
| oidc.resources | object | `{}` | |
|
|
||||||
| oidc.securityContext | object | `{}` | |
|
|
||||||
| oidc.service.annotations | object | `{}` | |
|
|
||||||
| oidc.service.port | int | `80` | |
|
|
||||||
| oidc.service.type | string | `"NodePort"` | |
|
|
||||||
| oidc.tolerations | list | `[]` | |
|
|
||||||
| server.config.ca_subject.common_name | string | `"example.org"` | |
|
| server.config.ca_subject.common_name | string | `"example.org"` | |
|
||||||
| server.config.ca_subject.country | string | `"NL"` | |
|
| server.config.ca_subject.country | string | `"NL"` | |
|
||||||
| server.config.ca_subject.organization | string | `"Example"` | |
|
| server.config.ca_subject.organization | string | `"Example"` | |
|
||||||
@@ -124,6 +96,7 @@ Kubernetes: `>=1.21.0-0`
|
|||||||
| serviceAccount.annotations | object | `{}` | |
|
| serviceAccount.annotations | object | `{}` | |
|
||||||
| serviceAccount.create | bool | `true` | |
|
| serviceAccount.create | bool | `true` | |
|
||||||
| serviceAccount.name | string | `""` | |
|
| serviceAccount.name | string | `""` | |
|
||||||
|
| spiffe-oidc-discovery-provider.enabled | bool | `false` | |
|
||||||
| spire.clusterName | string | `"example-cluster"` | |
|
| spire.clusterName | string | `"example-cluster"` | |
|
||||||
| spire.trustDomain | string | `"example.org"` | |
|
| spire.trustDomain | string | `"example.org"` | |
|
||||||
| waitForIt.image.pullPolicy | string | `"IfNotPresent"` | |
|
| waitForIt.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
|
|||||||
@@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: spiffe-oidc-discovery-provider
|
||||||
|
description: A Helm chart to install the SPIFFE OIDC discovery provider.
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.5.3"
|
||||||
@@ -0,0 +1,53 @@
|
|||||||
|
# spiffe-oidc-discovery-provider
|
||||||
|
|
||||||
|
<!-- This README.md is generated. -->
|
||||||
|
|
||||||
|
  
|
||||||
|
|
||||||
|
A Helm chart to install the SPIFFE OIDC discovery provider.
|
||||||
|
|
||||||
|
## Values
|
||||||
|
|
||||||
|
| Key | Type | Default | Description |
|
||||||
|
|-----|------|---------|-------------|
|
||||||
|
| affinity | object | `{}` | |
|
||||||
|
| agentSocketPath | string | `"/run/spire/agent-sockets/spire-agent.sock"` | |
|
||||||
|
| autoscaling.enabled | bool | `false` | |
|
||||||
|
| autoscaling.maxReplicas | int | `5` | |
|
||||||
|
| autoscaling.minReplicas | int | `1` | |
|
||||||
|
| autoscaling.targetCPUUtilizationPercentage | int | `80` | |
|
||||||
|
| autoscaling.targetMemoryUtilizationPercentage | int | `80` | |
|
||||||
|
| config.acme.cacheDir | string | `"/run/spire"` | |
|
||||||
|
| config.acme.directoryUrl | string | `"https://acme-v02.api.letsencrypt.org/directory"` | |
|
||||||
|
| config.acme.emailAddress | string | `"[email protected]"` | |
|
||||||
|
| config.acme.tosAccepted | bool | `false` | |
|
||||||
|
| config.domains[0] | string | `"localhost"` | |
|
||||||
|
| config.domains[1] | string | `"oidc-discovery.example.org"` | |
|
||||||
|
| config.logLevel | string | `"info"` | |
|
||||||
|
| fullnameOverride | string | `""` | |
|
||||||
|
| image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
|
| image.registry | string | `"ghcr.io"` | |
|
||||||
|
| image.repository | string | `"spiffe/oidc-discovery-provider"` | |
|
||||||
|
| image.version | string | `""` | |
|
||||||
|
| imagePullSecrets | list | `[]` | |
|
||||||
|
| insecureScheme.enabled | bool | `false` | |
|
||||||
|
| insecureScheme.nginx.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
|
| insecureScheme.nginx.image.registry | string | `"docker.io"` | |
|
||||||
|
| insecureScheme.nginx.image.repository | string | `"nginx"` | |
|
||||||
|
| insecureScheme.nginx.image.version | string | `"1.23.2-alpine"` | |
|
||||||
|
| insecureScheme.nginx.resources | object | `{}` | |
|
||||||
|
| nameOverride | string | `""` | |
|
||||||
|
| nodeSelector."kubernetes.io/arch" | string | `"amd64"` | |
|
||||||
|
| podAnnotations | object | `{}` | |
|
||||||
|
| podSecurityContext | object | `{}` | |
|
||||||
|
| replicaCount | int | `1` | |
|
||||||
|
| resources | object | `{}` | |
|
||||||
|
| securityContext | object | `{}` | |
|
||||||
|
| service.annotations | object | `{}` | |
|
||||||
|
| service.port | int | `80` | |
|
||||||
|
| service.type | string | `"ClusterIP"` | |
|
||||||
|
| serviceAccount.annotations | object | `{}` | |
|
||||||
|
| serviceAccount.create | bool | `true` | |
|
||||||
|
| serviceAccount.name | string | `""` | |
|
||||||
|
| tolerations | list | `[]` | |
|
||||||
|
| trustDomain | string | `"example.org"` | |
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
SPIFFE OIDC discovery provider installed…
|
||||||
@@ -0,0 +1,74 @@
|
|||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "spiffe-oidc-discovery-provider.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "spiffe-oidc-discovery-provider.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||||
|
{{- if contains $name .Release.Name }}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "spiffe-oidc-discovery-provider.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "spiffe-oidc-discovery-provider.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "spiffe-oidc-discovery-provider.chart" . }}
|
||||||
|
{{ include "spiffe-oidc-discovery-provider.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "spiffe-oidc-discovery-provider.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "spiffe-oidc-discovery-provider.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "spiffe-oidc-discovery-provider.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
{{- default (include "spiffe-oidc-discovery-provider.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- define "spiffe-oidc-discovery-provider.image" -}}
|
||||||
|
{{- if eq (substr 0 7 .image.version) "sha256:" -}}
|
||||||
|
{{- printf "%s/%s@%s" .image.registry .image.repository .image.version -}}
|
||||||
|
{{- else if .appVersion -}}
|
||||||
|
{{- printf "%s/%s:%s" .image.registry .image.repository (default .appVersion .image.version) -}}
|
||||||
|
{{- else if .image.version -}}
|
||||||
|
{{- printf "%s/%s:%s" .image.registry .image.repository .image.version -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%s/%s" .image.registry .image.repository -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,56 @@
|
|||||||
|
{{- $oidcSocket := "/run/spire/oidc-sockets/spire-oidc-server.sock" }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: {{ include "spire.fullname" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
data:
|
||||||
|
oidc-discovery-provider.conf: |
|
||||||
|
log_level = "{{ .Values.config.logLevel }}"
|
||||||
|
|
||||||
|
domains = [
|
||||||
|
"{{ include "spiffe-oidc-discovery-provider.fullname" . }}",
|
||||||
|
"{{ include "spiffe-oidc-discovery-provider.fullname" . }}.svc.cluster.local",
|
||||||
|
{{- if gt (len .Values.config.domains) 0 }}
|
||||||
|
"{{- join "\",\n \"" .Values.config.domains }}"
|
||||||
|
{{- end }}
|
||||||
|
]
|
||||||
|
|
||||||
|
{{- if .Values.insecureScheme.enabled }}
|
||||||
|
allow_insecure_scheme = {{ .Values.insecureScheme.enabled }}
|
||||||
|
listen_socket_path = {{ $oidcSocket | quote }}
|
||||||
|
{{- else }}
|
||||||
|
acme {
|
||||||
|
directory_url = "{{ .Values.config.acme.directoryUrl }}"
|
||||||
|
cache_dir = "{{ .Values.config.acme.cacheDir }}"
|
||||||
|
tos_accepted = {{ .Values.config.acme.tosAccepted }}
|
||||||
|
email = "{{ .Values.config.acme.emailAddress }}"
|
||||||
|
}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
workload_api {
|
||||||
|
socket_path = "/spiffe-workload-api/{{ splitList "/" .Values.agentSocketPath | last }}"
|
||||||
|
trust_domain = "{{ .Values.trustDomain }}"
|
||||||
|
}
|
||||||
|
|
||||||
|
health_checks {
|
||||||
|
bind_port = "8008"
|
||||||
|
ready_path = "/ready"
|
||||||
|
live_path = "/live"
|
||||||
|
}
|
||||||
|
{{- if .Values.insecureScheme.enabled }}
|
||||||
|
default.conf.template: |
|
||||||
|
upstream oidc {
|
||||||
|
server unix:{{ $oidcSocket }};
|
||||||
|
}
|
||||||
|
|
||||||
|
server {
|
||||||
|
listen 80;
|
||||||
|
listen [::]:80;
|
||||||
|
|
||||||
|
location / {
|
||||||
|
proxy_pass http://oidc;
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
{{- end }}
|
||||||
+24
-27
@@ -1,47 +1,45 @@
|
|||||||
{{- if eq (.Values.oidc.enabled | toString) "true" }}
|
|
||||||
{{- $fullname := include "spire.fullname" . }}
|
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
kind: Deployment
|
kind: Deployment
|
||||||
metadata:
|
metadata:
|
||||||
name: {{ printf "%s-oidc" $fullname }}
|
name: {{ include "spiffe-oidc-discovery-provider.fullname" . }}
|
||||||
labels:
|
labels:
|
||||||
{{- include "spire.oidc.labels" . | nindent 4 }}
|
{{- include "spiffe-oidc-discovery-provider.labels" . | nindent 4 }}
|
||||||
spec:
|
spec:
|
||||||
replicas: {{ .Values.oidc.replicaCount }}
|
{{- if not .Values.autoscaling.enabled }}
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
{{- end }}
|
||||||
selector:
|
selector:
|
||||||
matchLabels:
|
matchLabels:
|
||||||
{{- include "spire.oidc.selectorLabels" . | nindent 6 }}
|
{{- include "spiffe-oidc-discovery-provider.selectorLabels" . | nindent 6 }}
|
||||||
template:
|
template:
|
||||||
metadata:
|
metadata:
|
||||||
{{- with .Values.oidc.podAnnotations }}
|
{{- with .Values.podAnnotations }}
|
||||||
annotations:
|
annotations:
|
||||||
{{- toYaml . | nindent 8 }}
|
{{- toYaml . | nindent 8 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
labels:
|
labels:
|
||||||
{{- include "spire.oidc.selectorLabels" . | nindent 8 }}
|
{{- include "spiffe-oidc-discovery-provider.selectorLabels" . | nindent 8 }}
|
||||||
spec:
|
spec:
|
||||||
{{- with .Values.imagePullSecrets }}
|
{{- with .Values.imagePullSecrets }}
|
||||||
imagePullSecrets:
|
imagePullSecrets:
|
||||||
{{- range . }}
|
{{- toYaml . | nindent 8 }}
|
||||||
- name: {{ printf "%s-%s" $fullname .name }}
|
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
serviceAccountName: {{ include "spiffe-oidc-discovery-provider.serviceAccountName" . }}
|
||||||
serviceAccountName: {{ include "spire.serviceAccountName" . }}-agent
|
|
||||||
securityContext:
|
securityContext:
|
||||||
{{- toYaml .Values.oidc.podSecurityContext | nindent 8 }}
|
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||||
containers:
|
containers:
|
||||||
- name: spire-oidc
|
- name: {{ .Chart.Name }}
|
||||||
securityContext:
|
securityContext:
|
||||||
{{- toYaml .Values.securityContext | nindent 12 }}
|
{{- toYaml .Values.securityContext | nindent 12 }}
|
||||||
image: {{ template "spire.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.oidc.image) }}
|
image: {{ template "spiffe-oidc-discovery-provider.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image) }}
|
||||||
imagePullPolicy: {{ .Values.oidc.image.pullPolicy }}
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
args:
|
args:
|
||||||
- -config
|
- -config
|
||||||
- /run/spire/oidc/config/oidc-discovery-provider.conf
|
- /run/spire/oidc/config/oidc-discovery-provider.conf
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 8008
|
- containerPort: 8008
|
||||||
name: health
|
name: health
|
||||||
{{- if not .Values.oidc.insecureScheme.enabled }}
|
{{- if not .Values.insecureScheme.enabled }}
|
||||||
- containerPort: 443
|
- containerPort: 443
|
||||||
name: https
|
name: https
|
||||||
{{- end }}
|
{{- end }}
|
||||||
@@ -68,13 +66,13 @@ spec:
|
|||||||
initialDelaySeconds: 5
|
initialDelaySeconds: 5
|
||||||
periodSeconds: 5
|
periodSeconds: 5
|
||||||
resources:
|
resources:
|
||||||
{{- toYaml .Values.oidc.resources | nindent 12 }}
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
{{- if .Values.oidc.insecureScheme.enabled }}
|
{{- if .Values.insecureScheme.enabled }}
|
||||||
- name: nginx
|
- name: nginx
|
||||||
securityContext:
|
securityContext:
|
||||||
{{- toYaml .Values.securityContext | nindent 12 }}
|
{{- toYaml .Values.securityContext | nindent 12 }}
|
||||||
image: {{ template "spire.image" .Values.oidc.insecureScheme.nginx }}
|
image: {{ template "spiffe-oidc-discovery-provider.image" .Values.insecureScheme.nginx }}
|
||||||
imagePullPolicy: {{ .Values.oidc.insecureScheme.nginx.image.pullPolicy }}
|
imagePullPolicy: {{ .Values.insecureScheme.nginx.image.pullPolicy }}
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 80
|
- containerPort: 80
|
||||||
name: http
|
name: http
|
||||||
@@ -87,7 +85,7 @@ spec:
|
|||||||
subPath: default.conf.template
|
subPath: default.conf.template
|
||||||
readOnly: true
|
readOnly: true
|
||||||
resources:
|
resources:
|
||||||
{{- toYaml .Values.oidc.insecureScheme.nginx.resources | nindent 12 }}
|
{{- toYaml .Values.insecureScheme.nginx.resources | nindent 12 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
volumes:
|
volumes:
|
||||||
- name: spiffe-workload-api
|
- name: spiffe-workload-api
|
||||||
@@ -100,17 +98,16 @@ spec:
|
|||||||
type: DirectoryOrCreate
|
type: DirectoryOrCreate
|
||||||
- name: spire-oidc-config
|
- name: spire-oidc-config
|
||||||
configMap:
|
configMap:
|
||||||
name: {{ include "spire.fullname" . }}-oidc-discovery-provider
|
name: {{ include "spiffe-oidc-discovery-provider.fullname" . }}
|
||||||
{{- with .Values.oidc.nodeSelector }}
|
{{- with .Values.nodeSelector }}
|
||||||
nodeSelector:
|
nodeSelector:
|
||||||
{{- toYaml . | nindent 8 }}
|
{{- toYaml . | nindent 8 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- with .Values.oidc.affinity }}
|
{{- with .Values.affinity }}
|
||||||
affinity:
|
affinity:
|
||||||
{{- toYaml . | nindent 8 }}
|
{{- toYaml . | nindent 8 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- with .Values.oidc.tolerations }}
|
{{- with .Values.tolerations }}
|
||||||
tolerations:
|
tolerations:
|
||||||
{{- toYaml . | nindent 8 }}
|
{{- toYaml . | nindent 8 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{ end }}
|
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
{{- if .Values.autoscaling.enabled }}
|
||||||
|
apiVersion: autoscaling/v2beta1
|
||||||
|
kind: HorizontalPodAutoscaler
|
||||||
|
metadata:
|
||||||
|
name: {{ include "spiffe-oidc-discovery-provider.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "spiffe-oidc-discovery-provider.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
scaleTargetRef:
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
name: {{ include "spiffe-oidc-discovery-provider.fullname" . }}
|
||||||
|
minReplicas: {{ .Values.autoscaling.minReplicas }}
|
||||||
|
maxReplicas: {{ .Values.autoscaling.maxReplicas }}
|
||||||
|
metrics:
|
||||||
|
{{- if .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||||
|
- type: Resource
|
||||||
|
resource:
|
||||||
|
name: cpu
|
||||||
|
targetAverageUtilization: {{ .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||||
|
- type: Resource
|
||||||
|
resource:
|
||||||
|
name: memory
|
||||||
|
targetAverageUtilization: {{ .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "spiffe-oidc-discovery-provider.fullname" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
{{- with .Values.service.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
ports:
|
||||||
|
{{- if .Values.insecureScheme.enabled }}
|
||||||
|
- name: http
|
||||||
|
port: {{ .Values.service.port }}
|
||||||
|
targetPort: http
|
||||||
|
protocol: TCP
|
||||||
|
{{- else }}
|
||||||
|
- name: https
|
||||||
|
port: 443
|
||||||
|
targetPort: https
|
||||||
|
protocol: TCP
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
{{- include "spiffe-oidc-discovery-provider.selectorLabels" . | nindent 4 }}
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
{{- if .Values.serviceAccount.create -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "spiffe-oidc-discovery-provider.serviceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "spiffe-oidc-discovery-provider.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.serviceAccount.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
+15
@@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: "{{ include "spiffe-oidc-discovery-provider.fullname" . }}-test-connection"
|
||||||
|
labels:
|
||||||
|
{{- include "spiffe-oidc-discovery-provider.labels" . | nindent 4 }}
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": test
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: wget
|
||||||
|
image: busybox
|
||||||
|
command: ['wget']
|
||||||
|
args: ['{{ include "spiffe-oidc-discovery-provider.fullname" . }}:{{ .Values.service.port }}']
|
||||||
|
restartPolicy: Never
|
||||||
@@ -0,0 +1,113 @@
|
|||||||
|
# Default values for spiffe-oidc-discovery-provider.
|
||||||
|
# This is a YAML-formatted file.
|
||||||
|
# Declare variables to be passed into your templates.
|
||||||
|
|
||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
# registry: gcr.io
|
||||||
|
# repository: spiffe-io/oidc-discovery-provider
|
||||||
|
registry: ghcr.io
|
||||||
|
repository: spiffe/oidc-discovery-provider
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
version: ""
|
||||||
|
|
||||||
|
resources: {}
|
||||||
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||||
|
# choice for the user. This also increases chances charts run on environments with little
|
||||||
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||||
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||||
|
# requests:
|
||||||
|
# cpu: 50m
|
||||||
|
# memory: 32Mi
|
||||||
|
# limits:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 64Mi
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 80
|
||||||
|
annotations: {}
|
||||||
|
# external-dns.alpha.kubernetes.io/hostname: oidc-discovery.example.org
|
||||||
|
|
||||||
|
podSecurityContext: {}
|
||||||
|
# fsGroup: 2000
|
||||||
|
|
||||||
|
securityContext: {}
|
||||||
|
# capabilities:
|
||||||
|
# drop:
|
||||||
|
# - ALL
|
||||||
|
# readOnlyRootFilesystem: true
|
||||||
|
# runAsNonRoot: true
|
||||||
|
# runAsUser: 1000
|
||||||
|
|
||||||
|
podAnnotations: {}
|
||||||
|
|
||||||
|
insecureScheme:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
nginx:
|
||||||
|
image:
|
||||||
|
registry: docker.io
|
||||||
|
repository: nginx
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
version: 1.23.2-alpine
|
||||||
|
# chainguard image does not support the templates feature
|
||||||
|
# https://github.com/chainguard-images/nginx/issues/43
|
||||||
|
# registry: cgr.dev
|
||||||
|
# repository: chainguard/nginx
|
||||||
|
# pullPolicy: IfNotPresent
|
||||||
|
# version: "1.23.2"
|
||||||
|
resources: {}
|
||||||
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||||
|
# choice for the user. This also increases chances charts run on environments with little
|
||||||
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||||
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||||
|
# requests:
|
||||||
|
# cpu: 50m
|
||||||
|
# memory: 32Mi
|
||||||
|
# limits:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 64Mi
|
||||||
|
|
||||||
|
config:
|
||||||
|
logLevel: info
|
||||||
|
domains:
|
||||||
|
- localhost
|
||||||
|
- oidc-discovery.example.org
|
||||||
|
|
||||||
|
acme:
|
||||||
|
tosAccepted: false
|
||||||
|
cacheDir: /run/spire
|
||||||
|
directoryUrl: https://acme-v02.api.letsencrypt.org/directory
|
||||||
|
emailAddress: [email protected]
|
||||||
|
|
||||||
|
imagePullSecrets: []
|
||||||
|
nameOverride: ""
|
||||||
|
fullnameOverride: ""
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
# Specifies whether a service account should be created
|
||||||
|
create: true
|
||||||
|
# Annotations to add to the service account
|
||||||
|
annotations: {}
|
||||||
|
# The name of the service account to use.
|
||||||
|
# If not set and create is true, a name is generated using the fullname template
|
||||||
|
name: ""
|
||||||
|
|
||||||
|
autoscaling:
|
||||||
|
enabled: false
|
||||||
|
minReplicas: 1
|
||||||
|
maxReplicas: 5
|
||||||
|
targetCPUUtilizationPercentage: 80
|
||||||
|
targetMemoryUtilizationPercentage: 80
|
||||||
|
|
||||||
|
nodeSelector:
|
||||||
|
kubernetes.io/arch: amd64
|
||||||
|
|
||||||
|
tolerations: []
|
||||||
|
|
||||||
|
affinity: {}
|
||||||
|
|
||||||
|
agentSocketPath: /run/spire/agent-sockets/spire-agent.sock
|
||||||
|
trustDomain: "example.org"
|
||||||
@@ -1,58 +0,0 @@
|
|||||||
{{- if eq (.Values.oidc.enabled | toString) "true" }}
|
|
||||||
{{- $oidcSocket := "/run/spire/oidc-sockets/spire-oidc-server.sock" }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: {{ include "spire.fullname" . }}-oidc-discovery-provider
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
data:
|
|
||||||
oidc-discovery-provider.conf: |
|
|
||||||
log_level = "{{ .Values.oidc.config.logLevel }}"
|
|
||||||
|
|
||||||
domains = [
|
|
||||||
"spire-oidc.{{ .Release.Namespace }}",
|
|
||||||
"spire-oidc.{{ .Release.Namespace }}.svc.cluster.local",
|
|
||||||
{{- if gt (len .Values.oidc.config.domains) 0 }}
|
|
||||||
"{{- join "\",\n \"" .Values.oidc.config.domains }}"
|
|
||||||
{{- end }}
|
|
||||||
]
|
|
||||||
|
|
||||||
{{- if .Values.oidc.insecureScheme.enabled }}
|
|
||||||
allow_insecure_scheme = {{ .Values.oidc.insecureScheme.enabled }}
|
|
||||||
listen_socket_path = {{ $oidcSocket | quote }}
|
|
||||||
{{- else }}
|
|
||||||
acme {
|
|
||||||
directory_url = "{{ .Values.oidc.config.acme.directoryUrl }}"
|
|
||||||
cache_dir = "{{ .Values.oidc.config.acme.cacheDir }}"
|
|
||||||
tos_accepted = {{ .Values.oidc.config.acme.tosAccepted }}
|
|
||||||
email = "{{ .Values.oidc.config.acme.emailAddress }}"
|
|
||||||
}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
workload_api {
|
|
||||||
socket_path = "/spiffe-workload-api/{{ splitList "/" .Values.agent.config.socketPath | last }}"
|
|
||||||
trust_domain = "{{ .Values.spire.trustDomain }}"
|
|
||||||
}
|
|
||||||
|
|
||||||
health_checks {
|
|
||||||
bind_port = "8008"
|
|
||||||
ready_path = "/ready"
|
|
||||||
live_path = "/live"
|
|
||||||
}
|
|
||||||
{{- if .Values.oidc.insecureScheme.enabled }}
|
|
||||||
default.conf.template: |
|
|
||||||
upstream oidc {
|
|
||||||
server unix:{{ $oidcSocket }};
|
|
||||||
}
|
|
||||||
|
|
||||||
server {
|
|
||||||
listen 80;
|
|
||||||
listen [::]:80;
|
|
||||||
|
|
||||||
location / {
|
|
||||||
proxy_pass http://oidc;
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
{{- end }}
|
|
||||||
{{ end }}
|
|
||||||
@@ -1,25 +0,0 @@
|
|||||||
{{- if eq (.Values.oidc.enabled | toString) "true" }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "spire.fullname" . }}-oidc
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
{{- with .Values.oidc.service.annotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.oidc.service.type }}
|
|
||||||
ports:
|
|
||||||
{{- if .Values.oidc.insecureScheme.enabled }}
|
|
||||||
- name: http
|
|
||||||
port: {{ .Values.oidc.service.port }}
|
|
||||||
targetPort: http
|
|
||||||
{{- else }}
|
|
||||||
- name: https
|
|
||||||
port: 443
|
|
||||||
targetPort: https
|
|
||||||
{{- end }}
|
|
||||||
selector:
|
|
||||||
{{- include "spire.oidc.selectorLabels" . | nindent 4 }}
|
|
||||||
{{ end }}
|
|
||||||
@@ -15,7 +15,7 @@ data:
|
|||||||
# AWS requires the use of RSA. EC cryptography is not supported
|
# AWS requires the use of RSA. EC cryptography is not supported
|
||||||
ca_key_type = "rsa-2048"
|
ca_key_type = "rsa-2048"
|
||||||
|
|
||||||
{{- if eq (.Values.oidc.enabled | toString) "true" }}
|
{{- if eq (index .Values "spiffe-oidc-discovery-provider" "enabled" | toString) "true" }}
|
||||||
jwt_issuer = "{{ .Values.server.config.jwtIssuer }}"
|
jwt_issuer = "{{ .Values.server.config.jwtIssuer }}"
|
||||||
{{ end }}
|
{{ end }}
|
||||||
default_x509_svid_ttl = "1h"
|
default_x509_svid_ttl = "1h"
|
||||||
|
|||||||
@@ -140,93 +140,8 @@ agent:
|
|||||||
logLevel: info
|
logLevel: info
|
||||||
socketPath: /run/spire/agent-sockets/spire-agent.sock
|
socketPath: /run/spire/agent-sockets/spire-agent.sock
|
||||||
|
|
||||||
oidc:
|
spiffe-oidc-discovery-provider:
|
||||||
enabled: false
|
enabled: false
|
||||||
replicaCount: 1
|
|
||||||
|
|
||||||
image:
|
|
||||||
# registry: gcr.io
|
|
||||||
# repository: spiffe-io/oidc-discovery-provider
|
|
||||||
registry: ghcr.io
|
|
||||||
repository: spiffe/oidc-discovery-provider
|
|
||||||
pullPolicy: IfNotPresent
|
|
||||||
version: ""
|
|
||||||
|
|
||||||
nodeSelector:
|
|
||||||
kubernetes.io/arch: amd64
|
|
||||||
|
|
||||||
resources: {}
|
|
||||||
# We usually recommend not to specify default resources and to leave this as a conscious
|
|
||||||
# choice for the user. This also increases chances charts run on environments with little
|
|
||||||
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
|
||||||
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
|
||||||
# requests:
|
|
||||||
# cpu: 50m
|
|
||||||
# memory: 32Mi
|
|
||||||
# limits:
|
|
||||||
# cpu: 100m
|
|
||||||
# memory: 64Mi
|
|
||||||
|
|
||||||
service:
|
|
||||||
type: NodePort
|
|
||||||
port: 80
|
|
||||||
annotations: {}
|
|
||||||
# external-dns.alpha.kubernetes.io/hostname: oidc-discovery.example.org
|
|
||||||
|
|
||||||
podSecurityContext: {}
|
|
||||||
# fsGroup: 2000
|
|
||||||
|
|
||||||
securityContext: {}
|
|
||||||
# capabilities:
|
|
||||||
# drop:
|
|
||||||
# - ALL
|
|
||||||
# readOnlyRootFilesystem: true
|
|
||||||
# runAsNonRoot: true
|
|
||||||
# runAsUser: 1000
|
|
||||||
|
|
||||||
tolerations: []
|
|
||||||
|
|
||||||
affinity: {}
|
|
||||||
podAnnotations: {}
|
|
||||||
|
|
||||||
insecureScheme:
|
|
||||||
enabled: false
|
|
||||||
|
|
||||||
nginx:
|
|
||||||
image:
|
|
||||||
registry: docker.io
|
|
||||||
repository: nginx
|
|
||||||
pullPolicy: IfNotPresent
|
|
||||||
version: 1.23.2-alpine
|
|
||||||
# chainguard image does not support the templates feature
|
|
||||||
# https://github.com/chainguard-images/nginx/issues/43
|
|
||||||
# registry: cgr.dev
|
|
||||||
# repository: chainguard/nginx
|
|
||||||
# pullPolicy: IfNotPresent
|
|
||||||
# version: "1.23.2"
|
|
||||||
resources: {}
|
|
||||||
# We usually recommend not to specify default resources and to leave this as a conscious
|
|
||||||
# choice for the user. This also increases chances charts run on environments with little
|
|
||||||
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
|
||||||
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
|
||||||
# requests:
|
|
||||||
# cpu: 50m
|
|
||||||
# memory: 32Mi
|
|
||||||
# limits:
|
|
||||||
# cpu: 100m
|
|
||||||
# memory: 64Mi
|
|
||||||
|
|
||||||
config:
|
|
||||||
logLevel: info
|
|
||||||
domains:
|
|
||||||
- localhost
|
|
||||||
- oidc-discovery.example.org
|
|
||||||
|
|
||||||
acme:
|
|
||||||
tosAccepted: false
|
|
||||||
cacheDir: /run/spire
|
|
||||||
directoryUrl: https://acme-v02.api.letsencrypt.org/directory
|
|
||||||
emailAddress: [email protected]
|
|
||||||
|
|
||||||
imagePullSecrets: []
|
imagePullSecrets: []
|
||||||
# - name: my-docker-registry
|
# - name: my-docker-registry
|
||||||
|
|||||||
Reference in New Issue
Block a user