Add aws_pca to the spire-server (#404)
This change allows aws_pca to be configured via values of this chart. __Requires 1.7.1 version__ per [bug](https://github.com/spiffe/spire/issues/4351) - this will not work until 1.7.1 is released. --------- Signed-off-by: Petr McAllister <[email protected]> Signed-off-by: Petr McAllister <[email protected]> Signed-off-by: Kevin Fox <[email protected]> Co-authored-by: Marco Franssen <[email protected]> Co-authored-by: kfox1111 <[email protected]>
This commit is contained in:
co-authored by
Marco Franssen
kfox1111
parent
af13f1fc64
commit
9f4d4ace84
@@ -99,6 +99,30 @@ plugins:
|
||||
workload_api_socket: "/run/spire/upstream_agent/spire-agent.sock"
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- with .Values.upstreamAuthority.awsPCA }}
|
||||
{{- if eq (.enabled | toString) "true" }}
|
||||
{{- $upstreamAuthorityUsed = add1 $upstreamAuthorityUsed }}
|
||||
UpstreamAuthority:
|
||||
- aws_pca:
|
||||
plugin_data:
|
||||
region: {{ .region | quote }}
|
||||
certificate_authority_arn: {{ .certificateAuthorityARN | quote }}
|
||||
ca_signing_template_arn: {{ .caSigningTemplateARN | default "arn:aws:acm-pca:::template/SubordinateCACertificate_PathLen0/V1" | quote }}
|
||||
{{- if ne .signingAlgorithm "" }}
|
||||
signing_algorithm: {{ .signingAlgorithm | quote }}
|
||||
{{- end }}
|
||||
{{- if ne .assumeRoleARN "" }}
|
||||
assume_role_arn: {{ .assumeRoleARN | quote }}
|
||||
{{- end }}
|
||||
{{- if ne .endpoint "" }}
|
||||
endpoint: {{ .endpoint | quote }}
|
||||
{{- end }}
|
||||
{{- if ne .supplementalBundlePath "" }}
|
||||
supplemental_bundle_path: {{ .supplementalBundlePath | quote }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if gt $upstreamAuthorityUsed 1 }}
|
||||
{{- fail "You can only enable a single Upstream Authority." }}
|
||||
{{- end }}
|
||||
|
||||
Reference in New Issue
Block a user