From c93ad87c157a29d12b0d7b8491e21c3e11cc5672 Mon Sep 17 00:00:00 2001 From: Mariusz Sabath Date: Tue, 9 Jul 2024 11:42:27 -0400 Subject: [PATCH] Add valid kubectl version to examples Signed-off-by: Mariusz Sabath --- charts/spire/README.md | 25 ++++++++++++++++++++++--- 1 file changed, 22 insertions(+), 3 deletions(-) diff --git a/charts/spire/README.md b/charts/spire/README.md index 3335aff..bbd20b4 100644 --- a/charts/spire/README.md +++ b/charts/spire/README.md @@ -10,6 +10,7 @@ A Helm chart for deploying the complete Spire stack including: spire-server, spi ## Install Instructions ### Non Production + To do a quick install suitable for testing in something like minikube: ```shell @@ -22,6 +23,12 @@ helm upgrade --install -n spire-server spire spire --repo https://spiffe.github. Preparing a production deployment requires a few steps. 1. Save the following to your-values.yaml, ideally in your git repo. + +> [!NOTE] +> Please note that `rancher/kubectl` image does not always correspond to the most +> recent version of Kubernetes. In order to find the most up-to-date version, +> please visit their [releases](https://github.com/rancher/kubectl/releases) page. + ```yaml global: openshift: false # If running on openshift, set to true @@ -38,15 +45,27 @@ global: country: ARPA organization: Example commonName: example.org +spire-server: + tools: + kubectl: + image: + tag: "v1.23.3" +spiffe-oidc-discovery-provider: + tools: + kubectl: + image: + tag: "v1.23.3" ``` 2. If you need a non default storageClass, append the following to the global.spire section and update: + ``` persistence: storageClass: your-storage-class ``` 3. If your Kubernetes cluster is OpenShift based, use the output of the following command to update the trustDomain setting: + ```shell oc get cm -n openshift-config-managed console-public -o go-template="{{ .data.consoleURL }}" | sed 's@https://@@; s/^[^.]*\.//' ``` @@ -73,7 +92,7 @@ kubectl delete crds clusterfederatedtrustdomains.spire.spiffe.io clusterspiffeid ## Upgrade notes -We only support upgrading one major/minor version at a time. Version skipping isn't supported. Please see https://spiffe.io/docs/latest/spire-helm-charts-hardened-about/upgrading/ for details. +We only support upgrading one major/minor version at a time. Version skipping isn't supported. Please see for details. ### 0.21.X @@ -98,8 +117,8 @@ setting and waiting for a spire-controller-manager sync. ### 0.18.X -- SPIRE no longer emits x509UniqueIdentifiers in x509-SVIDS by default. The old behavior can be reenabled with spire-server.credentialComposer.uniqueID.enabled=true. See https://github.com/spiffe/spire/pull/4862 for details. -- SPIRE agents will now automatically reattest when they can. The old behavior can be reenabled with spire-agent.disableReattestToRenew=true. See https://github.com/spiffe/spire/pull/4791 for details. +- SPIRE no longer emits x509UniqueIdentifiers in x509-SVIDS by default. The old behavior can be reenabled with spire-server.credentialComposer.uniqueID.enabled=true. See for details. +- SPIRE agents will now automatically reattest when they can. The old behavior can be reenabled with spire-agent.disableReattestToRenew=true. See for details. ### 0.17.X