Fix spire-server configmap UpstreamAuthority/aws_pca and KeyManager/a… (#489)
Current configmap template renders to a wrong KeyManager and UpstreamAuthority configurarion when aws_kms and aws_pca are enabled and container is crashing. The proposed changes will fix the issue. --------- Signed-off-by: unufree <[email protected]> Signed-off-by: unufr33 <[email protected]> Co-authored-by: Faisal Memon <[email protected]>
This commit is contained in:
@@ -89,19 +89,19 @@ plugins:
|
|||||||
{{- if eq (.enabled | toString) "true" }}
|
{{- if eq (.enabled | toString) "true" }}
|
||||||
{{- $keyManagerUsed = add1 $keyManagerUsed }}
|
{{- $keyManagerUsed = add1 $keyManagerUsed }}
|
||||||
KeyManager:
|
KeyManager:
|
||||||
- aws_kms:
|
aws_kms:
|
||||||
plugin_data:
|
plugin_data:
|
||||||
region: {{ .region | quote }}
|
region: {{ .region | quote }}
|
||||||
key_metadata_file: "/run/spire/data/aws-kms-key-metadata"
|
key_metadata_file: "/run/spire/data/aws-kms-key-metadata"
|
||||||
{{- if ne .accessKeyID "" }}
|
{{- if ne .accessKeyID "" }}
|
||||||
access_key_id: "${AWS_KMS_ACCESS_KEY_ID}"
|
access_key_id: "${AWS_KMS_ACCESS_KEY_ID}"
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if ne .secretAccessKey "" }}
|
{{- if ne .secretAccessKey "" }}
|
||||||
secret_access_key: "${AWS_KMS_SECRET_ACCESS_KEY}"
|
secret_access_key: "${AWS_KMS_SECRET_ACCESS_KEY}"
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if or (ne .keyPolicy.policy "") (ne .keyPolicy.existingConfigMap "") }}
|
{{- if or (ne .keyPolicy.policy "") (ne .keyPolicy.existingConfigMap "") }}
|
||||||
key_policy_file: "/run/spire/data/aws-kms-key-policy.json"
|
key_policy_file: "/run/spire/data/aws-kms-key-policy.json"
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|
||||||
@@ -193,23 +193,23 @@ plugins:
|
|||||||
{{- if eq (.enabled | toString) "true" }}
|
{{- if eq (.enabled | toString) "true" }}
|
||||||
{{- $upstreamAuthorityUsed = add1 $upstreamAuthorityUsed }}
|
{{- $upstreamAuthorityUsed = add1 $upstreamAuthorityUsed }}
|
||||||
UpstreamAuthority:
|
UpstreamAuthority:
|
||||||
- aws_pca:
|
aws_pca:
|
||||||
plugin_data:
|
plugin_data:
|
||||||
region: {{ .region | quote }}
|
region: {{ .region | quote }}
|
||||||
certificate_authority_arn: {{ .certificateAuthorityARN | quote }}
|
certificate_authority_arn: {{ .certificateAuthorityARN | quote }}
|
||||||
ca_signing_template_arn: {{ .caSigningTemplateARN | default "arn:aws:acm-pca:::template/SubordinateCACertificate_PathLen0/V1" | quote }}
|
ca_signing_template_arn: {{ .caSigningTemplateARN | default "arn:aws:acm-pca:::template/SubordinateCACertificate_PathLen0/V1" | quote }}
|
||||||
{{- if ne .signingAlgorithm "" }}
|
{{- if ne .signingAlgorithm "" }}
|
||||||
signing_algorithm: {{ .signingAlgorithm | quote }}
|
signing_algorithm: {{ .signingAlgorithm | quote }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if ne .assumeRoleARN "" }}
|
{{- if ne .assumeRoleARN "" }}
|
||||||
assume_role_arn: {{ .assumeRoleARN | quote }}
|
assume_role_arn: {{ .assumeRoleARN | quote }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if ne .endpoint "" }}
|
{{- if ne .endpoint "" }}
|
||||||
endpoint: {{ .endpoint | quote }}
|
endpoint: {{ .endpoint | quote }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if ne .supplementalBundlePath "" }}
|
{{- if ne .supplementalBundlePath "" }}
|
||||||
supplemental_bundle_path: {{ .supplementalBundlePath | quote }}
|
supplemental_bundle_path: {{ .supplementalBundlePath | quote }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if gt $upstreamAuthorityUsed 1 }}
|
{{- if gt $upstreamAuthorityUsed 1 }}
|
||||||
|
|||||||
@@ -16,7 +16,7 @@ func ValueStringRender(chart *helmchart.Chart, values string) (map[string]string
|
|||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
ro := helmutil.ReleaseOptions{Name: "spire", Namespace: "spire-server", Revision: 1, IsUpgrade: false, IsInstall: true}
|
ro := helmutil.ReleaseOptions{Name: "spire", Namespace: "spire-server", Revision: 1, IsUpgrade: false, IsInstall: true}
|
||||||
v, err = helmutil.ToRenderValues(chart, v, ro, helmutil.DefaultCapabilities);
|
v, err = helmutil.ToRenderValues(chart, v, ro, helmutil.DefaultCapabilities)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
@@ -71,4 +71,36 @@ spire-server:
|
|||||||
Expect(notes).Should(ContainSubstring("join_token"))
|
Expect(notes).Should(ContainSubstring("join_token"))
|
||||||
})
|
})
|
||||||
})
|
})
|
||||||
|
Describe("spire-server.keyManager.aws_kms", func() {
|
||||||
|
It("plugin set ok", func() {
|
||||||
|
objs, err := ValueStringRender(chart, `
|
||||||
|
spire-server:
|
||||||
|
keyManager:
|
||||||
|
awsKMS:
|
||||||
|
enabled: true
|
||||||
|
region: us-west-2
|
||||||
|
plugin_data: {}
|
||||||
|
disk:
|
||||||
|
enabled: false
|
||||||
|
`)
|
||||||
|
Expect(err).Should(Succeed())
|
||||||
|
notes := objs["spire/charts/spire-server/templates/configmap.yaml"]
|
||||||
|
Expect(notes).Should(ContainSubstring("\"aws_kms\": {"))
|
||||||
|
})
|
||||||
|
})
|
||||||
|
Describe("spire-server.UpstreamAuthority.aws_pca", func() {
|
||||||
|
It("plugin set ok", func() {
|
||||||
|
objs, err := ValueStringRender(chart, `
|
||||||
|
spire-server:
|
||||||
|
upstreamAuthority:
|
||||||
|
awsPCA:
|
||||||
|
enabled: true
|
||||||
|
region: us-west-2
|
||||||
|
plugin_data: {}
|
||||||
|
`)
|
||||||
|
Expect(err).Should(Succeed())
|
||||||
|
notes := objs["spire/charts/spire-server/templates/configmap.yaml"]
|
||||||
|
Expect(notes).Should(ContainSubstring("\"aws_pca\": {"))
|
||||||
|
})
|
||||||
|
})
|
||||||
})
|
})
|
||||||
|
|||||||
Reference in New Issue
Block a user