From c39dd44526b8fcca6810ec0ce54adfa6c4f89cfa Mon Sep 17 00:00:00 2001 From: kfox1111 Date: Wed, 20 Dec 2023 16:15:56 -0800 Subject: [PATCH] Add recommendation for namespacePSS (#131) Co-authored-by: Marco Franssen --- charts/spire/README.md | 2 ++ .../templates/spire-server-namespace.yaml | 26 +++++++++++++++---- .../templates/spire-system-namespace.yaml | 23 ++++++++++++---- charts/spire/values.yaml | 4 +++ examples/openshift/openshift-values.yaml | 14 ---------- 5 files changed, 45 insertions(+), 24 deletions(-) diff --git a/charts/spire/README.md b/charts/spire/README.md index 301f7c3..076d383 100644 --- a/charts/spire/README.md +++ b/charts/spire/README.md @@ -160,11 +160,13 @@ Now you can interact with the Spire agent socket from your own application. The | `global.spire.upstreamServerAddress` | Set what address to use for the upstream server when using nested spire | `""` | | `global.spire.recommendations.enabled` | Use recommended settings for production deployments. Default is off. | `false` | | `global.spire.recommendations.namespaceLayout` | Set to true to use recommended values for installing across namespaces | `true` | +| `global.spire.recommendations.namespacePSS` | When chart namespace creation is enabled, label them with preffered Pod Security Standard labels | `true` | | `global.spire.recommendations.priorityClassName` | Set to true to use recommended values for Pod Priority Class Names | `true` | | `global.spire.recommendations.strictMode` | Check values, such as trustDomain, are overridden with a suitable value for production. | `true` | | `global.spire.recommendations.securityContexts` | Set to true to use recommended values for Pod and Container Security Contexts | `true` | | `global.spire.recommendations.prometheus` | Enable prometheus exporters for monitoring | `true` | | `global.spire.image.registry` | Override all Spire image registries at once | `""` | +| `global.spire.namespaces.create` | Set to true to Create all namespaces. If this or either of the namespace specific create flags is set, the namespace will be created. | `false` | | `global.spire.namespaces.system.name` | Name of the Spire system Namespace. | `spire-system` | | `global.spire.namespaces.system.create` | Create a Namespace for Spire system resources. | `false` | | `global.spire.namespaces.system.annotations` | Annotations to apply to the Spire system Namespace. | `{}` | diff --git a/charts/spire/templates/spire-server-namespace.yaml b/charts/spire/templates/spire-server-namespace.yaml index 4eae22d..a0ac41b 100644 --- a/charts/spire/templates/spire-server-namespace.yaml +++ b/charts/spire/templates/spire-server-namespace.yaml @@ -1,14 +1,30 @@ -{{- if .Values.global.spire.namespaces.server.create }} +{{- define "spire.namespace.default_server_labels" }} +"pod-security.kubernetes.io/warn": restricted +"pod-security.kubernetes.io/audit": restricted +"pod-security.kubernetes.io/enforce": restricted +{{- end }} +{{- if or .Values.global.spire.namespaces.create .Values.global.spire.namespaces.server.create }} +{{- $labels := dict }} +{{- if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespacePSS" true .Values.global) }} +{{- $labels = mergeOverwrite $labels (include "spire.namespace.default_server_labels" . | fromYaml) }} +{{- if (dig "openshift" false .Values.global) }} +{{- $_ := set $labels "security.openshift.io/scc.podSecurityLabelSync" "false" }} +{{- if (index .Values "spiffe-oidc-discovery-provider").enabled }} +{{- $_ := set $labels "pod-security.kubernetes.io/enforce" "privileged" }} +{{- end }} +{{- end }} +{{- end }} +{{- $labels = mergeOverwrite $labels .Values.global.spire.namespaces.server.labels }} apiVersion: v1 kind: Namespace metadata: name: {{ .Values.global.spire.namespaces.server.name }} - {{- if .Values.global.spire.namespaces.server.labels }} + {{- with $labels }} labels: - {{- .Values.global.spire.namespaces.server.labels | toYaml | nindent 4 }} + {{- toYaml . | nindent 4 }} {{- end }} - {{- if .Values.global.spire.namespaces.server.annotations }} + {{- with .Values.global.spire.namespaces.server.annotations }} annotations: - {{- .Values.global.spire.namespaces.server.annotations | toYaml | nindent 4 }} + {{- toYaml . | nindent 4 }} {{- end }} {{- end }} diff --git a/charts/spire/templates/spire-system-namespace.yaml b/charts/spire/templates/spire-system-namespace.yaml index 689038e..3ddf3c1 100644 --- a/charts/spire/templates/spire-system-namespace.yaml +++ b/charts/spire/templates/spire-system-namespace.yaml @@ -1,14 +1,27 @@ -{{- if .Values.global.spire.namespaces.system.create }} +{{- define "spire.namespace.default_system_labels" }} +"pod-security.kubernetes.io/warn": privileged +"pod-security.kubernetes.io/audit": privileged +"pod-security.kubernetes.io/enforce": privileged +{{- end }} +{{- if or .Values.global.spire.namespaces.create .Values.global.spire.namespaces.system.create }} +{{- $labels := dict }} +{{- if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespacePSS" true .Values.global) }} +{{- $labels = mergeOverwrite $labels (include "spire.namespace.default_system_labels" . | fromYaml) }} +{{- if (dig "openshift" false .Values.global) }} +{{- $_ := set $labels "security.openshift.io/scc.podSecurityLabelSync" "false" }} +{{- end }} +{{- end }} +{{- $labels = mergeOverwrite $labels .Values.global.spire.namespaces.server.labels }} apiVersion: v1 kind: Namespace metadata: name: {{ .Values.global.spire.namespaces.system.name }} - {{- if .Values.global.spire.namespaces.system.labels }} + {{- with $labels }} labels: - {{- .Values.global.spire.namespaces.system.labels | toYaml | nindent 4 }} + {{- toYaml . | nindent 4 }} {{- end }} - {{- if .Values.global.spire.namespaces.system.annotations }} + {{- with .Values.global.spire.namespaces.system.annotations }} annotations: - {{- .Values.global.spire.namespaces.system.annotations | toYaml | nindent 4 }} + {{- toYaml . | nindent 4 }} {{- end }} {{- end }} diff --git a/charts/spire/values.yaml b/charts/spire/values.yaml index c52ebe2..6d2cfef 100644 --- a/charts/spire/values.yaml +++ b/charts/spire/values.yaml @@ -23,6 +23,7 @@ global: ## @param global.spire.recommendations.enabled Use recommended settings for production deployments. Default is off. ## @param global.spire.recommendations.namespaceLayout Set to true to use recommended values for installing across namespaces + ## @param global.spire.recommendations.namespacePSS When chart namespace creation is enabled, label them with preffered Pod Security Standard labels ## @param global.spire.recommendations.priorityClassName Set to true to use recommended values for Pod Priority Class Names ## @param global.spire.recommendations.strictMode Check values, such as trustDomain, are overridden with a suitable value for production. ## @param global.spire.recommendations.securityContexts Set to true to use recommended values for Pod and Container Security Contexts @@ -30,6 +31,7 @@ global: recommendations: enabled: false namespaceLayout: true + namespacePSS: true priorityClassName: true strictMode: true securityContexts: true @@ -40,6 +42,8 @@ global: registry: "" namespaces: + ## @param global.spire.namespaces.create Set to true to Create all namespaces. If this or either of the namespace specific create flags is set, the namespace will be created. + create: false system: ## @param global.spire.namespaces.system.name Name of the Spire system Namespace. name: "spire-system" diff --git a/examples/openshift/openshift-values.yaml b/examples/openshift/openshift-values.yaml index d0d01d3..87ea5a3 100644 --- a/examples/openshift/openshift-values.yaml +++ b/examples/openshift/openshift-values.yaml @@ -1,16 +1,2 @@ global: openshift: true - spire: - namespaces: - system: - labels: - security.openshift.io/scc.podSecurityLabelSync: "false" - pod-security.kubernetes.io/enforce: privileged - pod-security.kubernetes.io/warn: privileged - pod-security.kubernetes.io/audit: privileged - server: - labels: - security.openshift.io/scc.podSecurityLabelSync: "false" - pod-security.kubernetes.io/enforce: privileged - pod-security.kubernetes.io/warn: privileged - pod-security.kubernetes.io/audit: privileged