diff --git a/.github/tests/spire-oidc-insecure/pre-install.sh b/.github/tests/spire-oidc-insecure/pre-install.sh new file mode 100755 index 0000000..e2541a9 --- /dev/null +++ b/.github/tests/spire-oidc-insecure/pre-install.sh @@ -0,0 +1,3 @@ +#!/bin/bash +helm install ingress-nginx ingress-nginx --version 4.5.2 --repo https://kubernetes.github.io/ingress-nginx -n "$VALUES" --set controller.extraArgs.enable-ssl-passthrough= +kubectl wait --namespace ingress-nginx --for=condition=ready pod --selector=app.kubernetes.io/component=controller -n "$VALUES" diff --git a/.github/tests/spire-oidc-insecure/values.yaml b/.github/tests/spire-oidc-insecure/values.yaml index 7b1a720..76693c8 100644 --- a/.github/tests/spire-oidc-insecure/values.yaml +++ b/.github/tests/spire-oidc-insecure/values.yaml @@ -6,7 +6,16 @@ spiffe-oidc-discovery-provider: config: domains: - - oidc-discovery.example.org + - ingress-nginx-controller acme: tosAccepted: false + + ingress: + enabled: true + className: "nginx" + hosts: + - host: ingress-nginx-controller + paths: + - path: / + pathType: Prefix diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md index f350d02..5beb0b7 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md @@ -34,6 +34,13 @@ A Helm chart to install the SPIFFE OIDC discovery provider. | image.repository | string | `"spiffe/oidc-discovery-provider"` | | | image.version | string | `""` | | | imagePullSecrets | list | `[]` | | +| ingress.annotations | object | `{}` | | +| ingress.className | string | `""` | | +| ingress.enabled | bool | `false` | | +| ingress.hosts[0].host | string | `"chart-example.local"` | | +| ingress.hosts[0].paths[0].path | string | `"/"` | | +| ingress.hosts[0].paths[0].pathType | string | `"Prefix"` | | +| ingress.tls | list | `[]` | | | insecureScheme.enabled | bool | `false` | | | insecureScheme.nginx.image.pullPolicy | string | `"IfNotPresent"` | | | insecureScheme.nginx.image.registry | string | `"docker.io"` | | diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/templates/ingress.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/templates/ingress.yaml new file mode 100644 index 0000000..e8f2e87 --- /dev/null +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/templates/ingress.yaml @@ -0,0 +1,41 @@ +{{- if .Values.ingress.enabled -}} +{{- $fullName := include "spiffe-oidc-discovery-provider.fullname" . }} +{{- $port := .Values.service.port }} +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: {{ $fullName }} + labels: + {{- include "spiffe-oidc-discovery-provider.labels" . | nindent 4 }} + {{- with .Values.ingress.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + ingressClassName: {{ .Values.ingress.className }} + {{- if .Values.ingress.tls }} + tls: + {{- range .Values.ingress.tls }} + - hosts: + {{- range .hosts }} + - {{ . | quote }} + {{- end }} + secretName: {{ .secretName }} + {{- end }} + {{- end }} + rules: + {{- range .Values.ingress.hosts }} + - host: {{ .host | quote }} + http: + paths: + {{- range .paths }} + - path: {{ .path }} + pathType: {{ .pathType }} + backend: + service: + name: {{ $fullName }} + port: + number: {{ $port }} + {{- end }} + {{- end }} +{{- end }} diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/templates/tests/test-connection.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/templates/tests/test-connection.yaml index 7c222c5..4734612 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/templates/tests/test-connection.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/templates/tests/test-connection.yaml @@ -29,4 +29,12 @@ spec: args: ['-O', '/dev/null', '{{ include "spiffe-oidc-discovery-provider.fullname" . }}.{{ include "spiffe-oidc-discovery-provider.namespace" . }}.svc.cluster.local:{{ .Values.service.port }}/.well-known/openid-configuration'] securityContext: {{- toYaml .Values.securityContext | nindent 8 }} + {{- if and .Values.ingress.enabled .Values.ingress.test.enabled }} + - name: wget-ingress + image: busybox + command: ['wget'] + args: ['{{ index .Values.config.domains 0 }}/.well-known/openid-configuration'] + securityContext: + {{- toYaml .Values.securityContext | nindent 8 }} + {{- end }} restartPolicy: Never diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml index 7b33987..c1ecf89 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml @@ -137,3 +137,19 @@ telemetry: # limits: # cpu: 100m # memory: 64Mi + +ingress: + enabled: false + className: "" + annotations: {} + # kubernetes.io/ingress.class: nginx + # kubernetes.io/tls-acme: "true" + hosts: + - host: chart-example.local + paths: + - path: / + pathType: Prefix + tls: [] + # - secretName: chart-example-tls + # hosts: + # - chart-example.local