From c0bee5ee159b1c0cf95c2c1829b7f6175062a677 Mon Sep 17 00:00:00 2001 From: kfox1111 Date: Thu, 30 Jul 2026 11:53:13 -0700 Subject: [PATCH] Upgrade the spire-controller-manager (#896) Signed-off-by: Kevin Fox --- ...piffe.io_clusterfederatedtrustdomains.yaml | 40 +-- .../spire.spiffe.io_clusterspiffeids.yaml | 249 ++++++++++-------- .../spire.spiffe.io_clusterstaticentries.yaml | 24 +- charts/spire/README.md | 1 + charts/spire/charts/spire-server/README.md | 2 +- charts/spire/charts/spire-server/values.yaml | 2 +- 6 files changed, 178 insertions(+), 140 deletions(-) diff --git a/charts/spire-crds/templates/spire.spiffe.io_clusterfederatedtrustdomains.yaml b/charts/spire-crds/templates/spire.spiffe.io_clusterfederatedtrustdomains.yaml index 112249f..8c3daa8 100644 --- a/charts/spire-crds/templates/spire.spiffe.io_clusterfederatedtrustdomains.yaml +++ b/charts/spire-crds/templates/spire.spiffe.io_clusterfederatedtrustdomains.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.11.1 + controller-gen.kubebuilder.io/version: v0.19.0 {{- .Values.annotations | toYaml | nindent 4 }} creationTimestamp: null name: clusterfederatedtrustdomains.spire.spiffe.io @@ -30,14 +30,19 @@ spec: API properties: apiVersion: - description: 'APIVersion defines the versioned schema of this representation - of an object. Servers should convert recognized schemas to the latest - internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources' + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: - description: 'Kind is a string value representing the REST resource this - object represents. Servers may infer this from the endpoint the client - submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds' + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object @@ -49,8 +54,9 @@ spec: description: BundleEndpointProfile is the profile for the bundle endpoint. properties: endpointSPIFFEID: - description: EndpointSPIFFEID is the SPIFFE ID of the bundle endpoint. - It is required for the "https_spiffe" profile. + description: |- + EndpointSPIFFEID is the SPIFFE ID of the bundle endpoint. It is + required for the "https_spiffe" profile. type: string type: description: Type is the type of the bundle endpoint profile. @@ -62,11 +68,12 @@ spec: - type type: object bundleEndpointURL: - description: BundleEndpointURL is the URL of the bundle endpoint. - It must be an HTTPS URL and cannot contain userinfo (i.e. username/password). + description: |- + BundleEndpointURL is the URL of the bundle endpoint. It must be an + HTTPS URL and cannot contain userinfo (i.e. username/password). type: string className: - description: Set the class of controller to handle this object. + description: Set which Controller Class will act on this object type: string trustDomain: description: TrustDomain is the name of the trust domain to federate @@ -74,9 +81,9 @@ spec: pattern: '[a-z0-9._-]{1,255}' type: string trustDomainBundle: - description: TrustDomainBundle is the contents of the bundle for the - referenced trust domain. This field is optional when the resource - is created. + description: |- + TrustDomainBundle is the contents of the bundle for the referenced trust + domain. This field is optional when the resource is created. type: string required: - bundleEndpointProfile @@ -87,6 +94,9 @@ spec: description: ClusterFederatedTrustDomainStatus defines the observed state of ClusterFederatedTrustDomain type: object + required: + - metadata + - spec type: object served: true storage: true diff --git a/charts/spire-crds/templates/spire.spiffe.io_clusterspiffeids.yaml b/charts/spire-crds/templates/spire.spiffe.io_clusterspiffeids.yaml index 2f34894..4cb1d08 100644 --- a/charts/spire-crds/templates/spire.spiffe.io_clusterspiffeids.yaml +++ b/charts/spire-crds/templates/spire.spiffe.io_clusterspiffeids.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.11.1 + controller-gen.kubebuilder.io/version: v0.19.0 {{- .Values.annotations | toYaml | nindent 4 }} creationTimestamp: null name: clusterspiffeids.spire.spiffe.io @@ -22,14 +22,19 @@ spec: description: ClusterSPIFFEID is the Schema for the clusterspiffeids API properties: apiVersion: - description: 'APIVersion defines the versioned schema of this representation - of an object. Servers should convert recognized schemas to the latest - internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources' + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: - description: 'Kind is a string value representing the REST resource this - object represents. Servers may infer this from the endpoint the client - submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds' + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object @@ -37,24 +42,24 @@ spec: description: ClusterSPIFFEIDSpec defines the desired state of ClusterSPIFFEID properties: admin: - description: Admin indicates whether or not the SVID can be used to - access the SPIRE administrative APIs. Extra care should be taken - to only apply this SPIFFE ID to admin workloads. + description: |- + Admin indicates whether or not the SVID can be used to access the SPIRE + administrative APIs. Extra care should be taken to only apply this + SPIFFE ID to admin workloads. type: boolean autoPopulateDNSNames: description: AutoPopulateDNSNames indicates whether or not to auto populate service DNS names. type: boolean - fallback: - description: |- - Apply this ID only if there are no other matching non fallback - ClusterSPIFFEIDs - type: boolean + className: + description: Set which Controller Class will act on this object + type: string dnsNameTemplates: - description: DNSNameTemplate represents templates for extra DNS names - that are applicable to SVIDs minted for this ClusterSPIFFEID. The - node and pod spec are made available to the template under .NodeSpec, - .PodSpec respectively. + description: |- + DNSNameTemplate represents templates for extra DNS names that are + applicable to SVIDs minted for this ClusterSPIFFEID. + The node and pod spec are made available to the template under + .NodeSpec, .PodSpec respectively. items: type: string type: array @@ -62,12 +67,14 @@ spec: description: Downstream indicates that the entry describes a downstream SPIRE server. type: boolean - className: - description: Set the class of controller to handle this object. - type: string + fallback: + description: Apply this ID only if there are no other matching non + fallback ClusterSPIFFEIDs. + type: boolean federatesWith: - description: FederatesWith is a list of trust domain names that workloads - that obtain this SPIFFE ID will federate with. + description: |- + FederatesWith is a list of trust domain names that workloads that + obtain this SPIFFE ID will federate with. items: type: string type: array @@ -75,118 +82,125 @@ spec: description: Set the entry hint type: string jwtTtl: - description: JWTTTL indicates an upper-bound time-to-live for JWT - SVIDs minted for this ClusterSPIFFEID. + description: |- + JWTTTL indicates an upper-bound time-to-live for JWT SVIDs minted for this + ClusterSPIFFEID. type: string namespaceSelector: - description: NamespaceSelector selects the namespaces that are targeted - by this CRD. - properties: - matchExpressions: - description: matchExpressions is a list of label selector requirements. - The requirements are ANDed. - items: - description: A label selector requirement is a selector that - contains values, a key, and an operator that relates the key - and values. - properties: - key: - description: key is the label key that the selector applies - to. - type: string - operator: - description: operator represents a key's relationship to - a set of values. Valid operators are In, NotIn, Exists - and DoesNotExist. - type: string - values: - description: values is an array of string values. If the - operator is In or NotIn, the values array must be non-empty. - If the operator is Exists or DoesNotExist, the values - array must be empty. This array is replaced during a strategic - merge patch. - items: - type: string - type: array - required: - - key - - operator - type: object - type: array - matchLabels: - additionalProperties: - type: string - description: matchLabels is a map of {key,value} pairs. A single - {key,value} in the matchLabels map is equivalent to an element - of matchExpressions, whose key field is "key", the operator - is "In", and the values array contains only "value". The requirements - are ANDed. - type: object - type: object - x-kubernetes-map-type: atomic - podSelector: - description: PodSelector selects the pods that are targeted by this + description: |- + NamespaceSelector selects the namespaces that are targeted by this CRD. properties: matchExpressions: description: matchExpressions is a list of label selector requirements. The requirements are ANDed. items: - description: A label selector requirement is a selector that - contains values, a key, and an operator that relates the key - and values. + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. properties: key: description: key is the label key that the selector applies to. type: string operator: - description: operator represents a key's relationship to - a set of values. Valid operators are In, NotIn, Exists - and DoesNotExist. + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. type: string values: - description: values is an array of string values. If the - operator is In or NotIn, the values array must be non-empty. - If the operator is Exists or DoesNotExist, the values - array must be empty. This array is replaced during a strategic + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic merge patch. items: type: string type: array + x-kubernetes-list-type: atomic required: - key - operator type: object type: array + x-kubernetes-list-type: atomic matchLabels: additionalProperties: type: string - description: matchLabels is a map of {key,value} pairs. A single - {key,value} in the matchLabels map is equivalent to an element - of matchExpressions, whose key field is "key", the operator - is "In", and the values array contains only "value". The requirements - are ANDed. + description: |- + matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, whose key field is "key", the + operator is "In", and the values array contains only "value". The requirements are ANDed. + type: object + type: object + x-kubernetes-map-type: atomic + podSelector: + description: |- + PodSelector selects the pods that are targeted by this + CRD. + properties: + matchExpressions: + description: matchExpressions is a list of label selector requirements. + The requirements are ANDed. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key that the selector applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + matchLabels: + additionalProperties: + type: string + description: |- + matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, whose key field is "key", the + operator is "In", and the values array contains only "value". The requirements are ANDed. type: object type: object x-kubernetes-map-type: atomic spiffeIDTemplate: - description: SPIFFEID is the SPIFFE ID template. The node and pod - spec are made available to the template under .NodeSpec, .PodSpec - respectively. + description: |- + SPIFFEID is the SPIFFE ID template. The node and pod spec are made + available to the template under .NodeSpec, .PodSpec respectively. type: string ttl: - description: TTL indicates an upper-bound time-to-live for X509 SVIDs - minted for this ClusterSPIFFEID. If unset, a default will be chosen. + description: |- + TTL indicates an upper-bound time-to-live for X509 SVIDs minted for this + ClusterSPIFFEID. If unset, a default will be chosen. type: string workloadSelectorTemplates: - description: WorkloadSelectorTemplates are templates to produce arbitrary - workload selectors that apply to a given workload before it will - receive this SPIFFE ID. The rendered value is interpreted by SPIRE - and are of the form type:value, where the value may, and often does, - contain semicolons, .e.g., k8s:container-image:docker/hello-world - The node and pod spec are made available to the template under .NodeSpec, - .PodSpec respectively. + description: |- + WorkloadSelectorTemplates are templates to produce arbitrary workload + selectors that apply to a given workload before it will receive this + SPIFFE ID. The rendered value is interpreted by SPIRE and are of the + form type:value, where the value may, and often does, contain + semicolons, .e.g., k8s:container-image:docker/hello-world + The node and pod spec are made available to the template under + .NodeSpec, .PodSpec respectively. items: type: string type: array @@ -200,21 +214,22 @@ spec: description: Stats produced by the last entry reconciliation run properties: entriesMasked: - description: How many entries were masked by entries for other - ClusterSPIFFEIDs. This happens when one or more ClusterSPIFFEIDs - produce an entry for the same pod with the same set of workload - selectors. + description: |- + How many entries were masked by entries for other ClusterSPIFFEIDs. + This happens when one or more ClusterSPIFFEIDs produce an entry for + the same pod with the same set of workload selectors. type: integer entriesToSet: - description: How many entries are to be set for this ClusterSPIFFEID. - In nominal conditions, this should reflect the number of pods - selected, but not always if there were problems encountered - rendering an entry for the pod (RenderFailures) or entries are - masked (EntriesMasked). + description: |- + How many entries are to be set for this ClusterSPIFFEID. In nominal + conditions, this should reflect the number of pods selected, but not + always if there were problems encountered rendering an entry for the pod + (RenderFailures) or entries are masked (EntriesMasked). type: integer entryFailures: - description: How many entries were unable to be set due to failures - to create or update the entries via the SPIRE Server API. + description: |- + How many entries were unable to be set due to failures to create or + update the entries via the SPIRE Server API. type: integer namespacesIgnored: description: How many (selected) namespaces were ignored (based @@ -224,16 +239,20 @@ spec: description: How many namespaces were selected. type: integer podEntryRenderFailures: - description: How many failures were encountered rendering an entry - selected pods. This could be due to either a bad template in - the ClusterSPIFFEID or Pod metadata that when applied to the - template did not produce valid entry values. + description: |- + How many failures were encountered rendering an entry selected pods. + This could be due to either a bad template in the ClusterSPIFFEID or + Pod metadata that when applied to the template did not produce valid + entry values. type: integer podsSelected: description: How many pods were selected out of the namespaces. type: integer type: object type: object + required: + - metadata + - spec type: object served: true storage: true diff --git a/charts/spire-crds/templates/spire.spiffe.io_clusterstaticentries.yaml b/charts/spire-crds/templates/spire.spiffe.io_clusterstaticentries.yaml index 6754b7e..aa76338 100644 --- a/charts/spire-crds/templates/spire.spiffe.io_clusterstaticentries.yaml +++ b/charts/spire-crds/templates/spire.spiffe.io_clusterstaticentries.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.11.1 + controller-gen.kubebuilder.io/version: v0.19.0 {{- .Values.annotations | toYaml | nindent 4 }} creationTimestamp: null name: clusterstaticentries.spire.spiffe.io @@ -23,14 +23,19 @@ spec: API properties: apiVersion: - description: 'APIVersion defines the versioned schema of this representation - of an object. Servers should convert recognized schemas to the latest - internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources' + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: - description: 'Kind is a string value representing the REST resource this - object represents. Servers may infer this from the endpoint the client - submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds' + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object @@ -40,7 +45,7 @@ spec: admin: type: boolean className: - description: Set the class of controller to handle this object. + description: Set which Controller Class will act on this object type: string dnsNames: items: @@ -90,6 +95,9 @@ spec: - rendered - set type: object + required: + - metadata + - spec type: object served: true storage: true diff --git a/charts/spire/README.md b/charts/spire/README.md index c1393b7..b32985f 100644 --- a/charts/spire/README.md +++ b/charts/spire/README.md @@ -81,6 +81,7 @@ We only support upgrading one major/minor version at a time. Version skipping is ### 0.30.X +- Upgrade the spire-crds chart first - The OIDC discovery issuer is now set automatically. We do not anticipate any negative impact; however, please verify your OIDC provider's integration with other services during your upgrade testing. - The x509POP plugin in spiffe mode has had its defaults changed. It allows easier and more secure setups. If using and upgrading, please review the settings. - To add the spike entries, you now must also specify spire-server.spike.enabled=true. diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index 3541bb7..52ca00e 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -325,7 +325,7 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `controllerManager.image.registry` | The OCI registry to pull the image from | `ghcr.io` | | `controllerManager.image.repository` | The repository within the registry | `spiffe/spire-controller-manager` | | `controllerManager.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `controllerManager.image.tag` | Overrides the image tag whose default is the chart appVersion | `0.6.6` | +| `controllerManager.image.tag` | Overrides the image tag whose default is the chart appVersion | `0.7.0` | | `controllerManager.resources` | Resource requests and limits for controller manager | `{}` | | `controllerManager.securityContext` | Security context | `{}` | | `controllerManager.service.type` | Service type for controller manager | `ClusterIP` | diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index 49b7c2e..994526f 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -692,7 +692,7 @@ controllerManager: registry: ghcr.io repository: spiffe/spire-controller-manager pullPolicy: IfNotPresent - tag: "0.6.6" + tag: "0.7.0" ## @param controllerManager.resources [object] Resource requests and limits for controller manager resources: {}