From 37cd9f25e25806d515e01f2726d58c434ec94d63 Mon Sep 17 00:00:00 2001 From: Faisal Memon Date: Wed, 8 Nov 2023 03:26:21 -0800 Subject: [PATCH 1/2] Update to SPIRE 1.8.4 (#84) --- charts/spire/Chart.yaml | 2 +- charts/spire/README.md.gotmpl | 2 +- charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml | 2 +- charts/spire/charts/spire-agent/Chart.yaml | 2 +- charts/spire/charts/spire-server/Chart.yaml | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) diff --git a/charts/spire/Chart.yaml b/charts/spire/Chart.yaml index dba8bd3..eb46d46 100644 --- a/charts/spire/Chart.yaml +++ b/charts/spire/Chart.yaml @@ -4,7 +4,7 @@ description: > A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager. type: application version: 0.14.0 -appVersion: "1.8.2" +appVersion: "1.8.4" keywords: ["spiffe", "spire", "spire-server", "spire-agent", "oidc", "spire-controller-manager"] home: https://github.com/spiffe/helm-charts/tree/main/charts/spire sources: diff --git a/charts/spire/README.md.gotmpl b/charts/spire/README.md.gotmpl index 5939f32..2ffb5e8 100644 --- a/charts/spire/README.md.gotmpl +++ b/charts/spire/README.md.gotmpl @@ -19,7 +19,7 @@ | Dependency | Supported Versions | |:-----------|:-------------------| -| SPIRE | `1.5.3+`, `1.6.3+` | +| SPIRE | `1.8.4` | | Helm | `3.x` | | Kubernetes | `1.22+` | diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml index 0d446fc..d38ddbf 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/Chart.yaml @@ -3,7 +3,7 @@ name: spiffe-oidc-discovery-provider description: A Helm chart to install the SPIFFE OIDC discovery provider. type: application version: 0.1.0 -appVersion: "1.8.2" +appVersion: "1.8.4" keywords: ["spiffe", "oidc"] home: https://github.com/spiffe/helm-charts/tree/main/charts/spire sources: diff --git a/charts/spire/charts/spire-agent/Chart.yaml b/charts/spire/charts/spire-agent/Chart.yaml index 6d411b5..514744f 100644 --- a/charts/spire/charts/spire-agent/Chart.yaml +++ b/charts/spire/charts/spire-agent/Chart.yaml @@ -3,7 +3,7 @@ name: spire-agent description: A Helm chart to install the SPIRE agent. type: application version: 0.1.0 -appVersion: "1.8.2" +appVersion: "1.8.4" keywords: ["spiffe", "spire-agent"] home: https://github.com/spiffe/helm-charts/tree/main/charts/spire sources: diff --git a/charts/spire/charts/spire-server/Chart.yaml b/charts/spire/charts/spire-server/Chart.yaml index 2335de4..a150171 100644 --- a/charts/spire/charts/spire-server/Chart.yaml +++ b/charts/spire/charts/spire-server/Chart.yaml @@ -3,7 +3,7 @@ name: spire-server description: A Helm chart to install the SPIRE server. type: application version: 0.1.0 -appVersion: "1.8.2" +appVersion: "1.8.4" keywords: ["spiffe", "spire-server", "spire-controller-manager"] home: https://github.com/spiffe/helm-charts/tree/main/charts/spire sources: From 0320c3f75541be672fa5df4e97f3e29872d3e6f0 Mon Sep 17 00:00:00 2001 From: Marco Franssen Date: Wed, 8 Nov 2023 11:54:57 +0100 Subject: [PATCH 2/2] Cleanup documentation Signed-off-by: Marco Franssen --- CODE-OF-CONDUCT.md | 6 +- CONTRIBUTING.md | 5 +- FAQ.md | 12 +- README.md | 2 +- charts/spire-crds/README.md | 5 +- charts/spire/README.md | 9 +- charts/spire/README.md.gotmpl | 75 ------------ .../spire/charts/spiffe-csi-driver/README.md | 7 +- .../charts/spiffe-csi-driver/README.md.gotmpl | 24 ---- .../spiffe-oidc-discovery-provider/README.md | 7 +- .../README.md.gotmpl | 25 ---- .../values.yaml | 6 +- charts/spire/charts/spire-agent/README.md | 7 +- .../spire/charts/spire-agent/README.md.gotmpl | 25 ---- charts/spire/charts/spire-agent/values.yaml | 6 +- charts/spire/charts/spire-server/README.md | 113 ++++++++++-------- charts/spire/charts/spire-server/values.yaml | 6 +- .../spire/charts/tornjak-frontend/README.md | 7 +- .../charts/tornjak-frontend/README.md.gotmpl | 54 --------- .../spire/charts/tornjak-frontend/values.yaml | 2 +- examples/openshift/README.md | 10 +- examples/production/README.md | 9 +- examples/tornjak/README.md | 3 +- helm-docs.sh | 2 +- release-chart.sh | 3 +- 25 files changed, 130 insertions(+), 300 deletions(-) delete mode 100644 charts/spire/README.md.gotmpl delete mode 100644 charts/spire/charts/spiffe-csi-driver/README.md.gotmpl delete mode 100644 charts/spire/charts/spiffe-oidc-discovery-provider/README.md.gotmpl delete mode 100644 charts/spire/charts/spire-agent/README.md.gotmpl delete mode 100644 charts/spire/charts/tornjak-frontend/README.md.gotmpl diff --git a/CODE-OF-CONDUCT.md b/CODE-OF-CONDUCT.md index e758eac..19a1b34 100644 --- a/CODE-OF-CONDUCT.md +++ b/CODE-OF-CONDUCT.md @@ -1,8 +1,8 @@ -### Contributor Code of Conduct +# Contributor Code of Conduct We follow the [CNCF Contributor Code of Conduct](https://github.com/cncf/foundation/blob/master/code-of-conduct.md). Additionally, we commit to the following guidelines as detailed on the [Linkerd Code of Conduct](https://github.com/linkerd/linkerd/wiki/Linkerd-code-of-conduct): -### Community Guidelines +## Community Guidelines - Our goal is to foster an inclusive and diverse community of technology enthusiasts. @@ -14,6 +14,6 @@ We follow the [CNCF Contributor Code of Conduct](https://github.com/cncf/foundat - We do our best to avoid [subtle-isms](https://www.recurse.com/manual#sub-sec-social-rules): small actions that make others feel uncomfortable. If you witness a subtle-ism, you may respectfully point it out to the person publicly or privately, or you may ask a moderator to say something. Accidentally saying something biased is common, expected, and readily forgiven. It is not in and of itself a bannable offense. -### Moderation +## Moderation - If you feel any of SPIFFE's communication channels require moderation, please e-mail the [SPIFFE Steering Committee (SSC)](mailto:ssc@spiffe.io). diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 005d03c..1d4a7ae 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -38,7 +38,8 @@ git rebase main Our CI pipeline takes care of the majority of the testing of this Chart. Other ways for you to test are by running `make test` locally using: -> **Warning**: Ensure to run the test on a dedicated k8s cluster that does not have Spire installed yet. +> [!Warning] +> Ensure to run the test on a dedicated k8s cluster that does not have Spire installed yet. ```shell make test @@ -48,7 +49,7 @@ Another approach to testing the chart is by installing one of the examples in yo ## Generating documentation -Any changes to Chart.yaml or values.yaml require an update of the README.md. This update can easily be generated using [readme-generator](https://github.com/bitnami-labs/readme-generator-for-helm). +Any changes to Chart.yaml or values.yaml require an update of the README.md. This update can easily be generated using [readme-generator][]. ```shell ./helm-docs.sh diff --git a/FAQ.md b/FAQ.md index 25313ea..eda231e 100644 --- a/FAQ.md +++ b/FAQ.md @@ -36,7 +36,8 @@ helm repo add spiffe https://spiffe.github.io/helm-charts-hardened If you uninstall the SPIRE chart before all users of the CSI driver are removed, Pods will get stuck in a terminating state waiting for the driver, that no longer is installed, to unmount the volumes for the Pod. In order to fix this, reinstall the chart and remove all affected workloads that are not part of the SPIRE helm chart itself, before attempting to remove SPIRE again. You can discover Pods that use the driver with the following command: -``` + +```shell kubectl get pods --all-namespaces -o go-template='{{range .items}}{{$nn := printf "%s %s" .metadata.namespace .metadata.name}}{{range .spec.volumes}}{{if .csi.driver}}{{if eq .csi.driver "csi.spiffe.io"}}{{printf "%s\n" $nn}}{{end}}{{end}}{{end}}{{end}}' ``` @@ -44,17 +45,20 @@ kubectl get pods --all-namespaces -o go-template='{{range .items}}{{$nn := print If you uninstall the SPIFFE CSI driver manually before removing the chart, Pods can still be using the driver and are unable to unmount the CSI volume. -To resolve, reinstall the chart before trying to remove it again. +To resolve, reinstall the chart before trying to remove it again. ## The PSAT plugin is not working The chart requires `Projected Service Account Tokens` which has to be enabled on your Kubernetes API server. In most cases this is already done for you. -> **Note**: This is enabled by default with newer versions as shown by the existence of: +> [!Note] +> This is enabled by default with newer versions as shown by the existence of: > +> ```yaml > - --service-account-issuer > - --service-account-key-file > - --service-account-signing-key-file +> ``` See [Service Account Token Volume Projection](https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/#serviceaccount-token-volume-projection) in the Kubernetes docs for more details. @@ -64,7 +68,9 @@ command to SSH into the Docker Desktop K8s VM. ```bash docker run -it --privileged --pid=host debian nsenter -t 1 -m -u -n -i sh ``` + Then add the following to `/etc/kubernetes/manifests/kube-apiserver.yaml` + ```yaml spec: containers: diff --git a/README.md b/README.md index 48077bd..ea0704a 100644 --- a/README.md +++ b/README.md @@ -14,7 +14,7 @@ A suite of [Helm Charts](https://helm.sh/docs) for standardized installations of ## How to install or upgrade You most likely want to do an integrated setup based on the spire chart. -[Instructions](https://artifacthub.io/packages/helm/spiffe/spire) +See the [Instructions](https://artifacthub.io/packages/helm/spiffe/spire). ## Contributing diff --git a/charts/spire-crds/README.md b/charts/spire-crds/README.md index 7eb21c2..9f69df4 100644 --- a/charts/spire-crds/README.md +++ b/charts/spire-crds/README.md @@ -7,6 +7,7 @@ A Helm chart to install the SPIRE CRDS. **Homepage:** ## Maintainers + | Name | Email | Url | | ---- | ------ | --- | | marcofranssen | | | @@ -16,8 +17,8 @@ A Helm chart to install the SPIRE CRDS. ## Source Code -* +* - + ## Parameters diff --git a/charts/spire/README.md b/charts/spire/README.md index 2f203e2..a4756a1 100644 --- a/charts/spire/README.md +++ b/charts/spire/README.md @@ -36,7 +36,7 @@ For production installs, please see [the production example](https://github.com/ The spire-crds chart has been updated. Please ensure you have upgraded spire-crds before upgrading the spire chart. -The chart now supports multiple parallel installs of spire-controller-manager. Each install will handle all custom resources with a matching `className` field. By default this is set to `Release.Namespace-Release.Name` and the controller manager will only pick up custom resources with this `className`. +The chart now supports multiple parallel installs of spire-controller-manager. Each install will handle all custom resources with a matching `className` field. By default this is set to `Release.Namespace-Release.Name` and the controller manager will only pick up custom resources with this `className`. If you have not loaded any SPIRE custom resources yourself, the upgrade process will be transparent. If you have loaded your own SPIRE custom resources, set `spire-server.controllerManager.watchClassless=true` until you can update your SPIRE custom resources to have the `className` for the instance specified. @@ -62,7 +62,8 @@ helm install -n spire-server spire-crds charts/spire-crds ## Version support -> **Note**: This Chart is still in development and still subject to change the API (`values.yaml`). +> [!Warning] +> This Chart is still in development and still subject to change the API (`values.yaml`). > Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although > we do aim for as much stability as possible. @@ -71,9 +72,11 @@ helm install -n spire-server spire-crds charts/spire-crds | Helm | `3.x` | | Kubernetes | `1.22+` | -> **Note**: For Kubernetes, we will officially support the last 3 versions as described in [k8s versioning](https://kubernetes.io/releases/version-skew-policy/#supported-versions). Any version before the last 3 we will try to support as long it doesn't bring security issues or any big maintenance burden. +> [!Note] +> For Kubernetes, we will officially support the last 3 versions as described in [k8s versioning](https://kubernetes.io/releases/version-skew-policy/#supported-versions). Any version before the last 3 we will try to support as long it doesn't bring security issues or any big maintenance burden. ## FAQ + For any issues see our [FAQ](../../FAQ.md)… ## Usage diff --git a/charts/spire/README.md.gotmpl b/charts/spire/README.md.gotmpl deleted file mode 100644 index 2ffb5e8..0000000 --- a/charts/spire/README.md.gotmpl +++ /dev/null @@ -1,75 +0,0 @@ -{{ template "chart.header" . }} - - - -{{ template "chart.deprecationWarning" . }} - -{{ template "chart.badgesSection" . }} -[![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) - -{{ template "chart.description" . }} - -{{ template "chart.homepageLine" . }} - -## Version support - -> **Note**: This Chart is still in development and still subject to change the API (`values.yaml`). -> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although -> we do aim for as much stability as possible. - -| Dependency | Supported Versions | -|:-----------|:-------------------| -| SPIRE | `1.8.4` | -| Helm | `3.x` | -| Kubernetes | `1.22+` | - -> **Note**: For Kubernetes, we will officially support the last 3 versions as described in [k8s versioning](https://kubernetes.io/releases/version-skew-policy/#supported-versions). Any version before the last 3 we will try to support as long it doesn't bring security issues or any big maintenance burden. - -## FAQ -For any issues see our [FAQ](../../FAQ.md)… - -## Usage - -To utilize Spire in your own workloads you should add the following to your workload: - -```diff - apiVersion: v1 - kind: Pod - metadata: - name: my-app - spec: - containers: - - name: my-app - image: "my-app:latest" - imagePullPolicy: Always -+ volumeMounts: -+ - name: spiffe-workload-api -+ mountPath: /spiffe-workload-api -+ readOnly: true - resources: - requests: - cpu: 200m - memory: 32Mi - limits: - cpu: 500m - memory: 64Mi -+ volumes: -+ - name: spiffe-workload-api -+ csi: -+ driver: "csi.spiffe.io" -+ readOnly: true -``` - -Now you can interact with the Spire agent socket from your own application. The socket is mounted on `/spiffe-workload-api/spire-agent.sock`. - -{{ template "chart.maintainersSection" . }} - -{{ template "chart.sourcesSection" . }} - -{{ template "chart.requirementsHeader" . }} - -{{ template "chart.requirementsTable" . }} - -{{ template "chart.valuesSection" . }} - ----------------------------------------------- diff --git a/charts/spire/charts/spiffe-csi-driver/README.md b/charts/spire/charts/spiffe-csi-driver/README.md index 1e1150d..2b2b115 100644 --- a/charts/spire/charts/spiffe-csi-driver/README.md +++ b/charts/spire/charts/spiffe-csi-driver/README.md @@ -1,14 +1,13 @@ # spiffe-csi-driver - - ![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 0.2.3](https://img.shields.io/badge/AppVersion-0.2.3-informational?style=flat-square) A Helm chart to install the SPIFFE CSI driver. **Homepage:** -> **Note**: The recommended version is `0.2.3` to support arm64 nodes. If running with any +> [!Note] +> The recommended version is `0.2.3` to support arm64 nodes. If running with any > prior version to `0.2.3` you have to use a `nodeSelector` to limit to `kubernetes.io/arch: amd64`. ## Maintainers @@ -24,6 +23,8 @@ A Helm chart to install the SPIFFE CSI driver. * + + ## Parameters ### SPIFFE CSI Driver Chart parameters diff --git a/charts/spire/charts/spiffe-csi-driver/README.md.gotmpl b/charts/spire/charts/spiffe-csi-driver/README.md.gotmpl deleted file mode 100644 index 657bce3..0000000 --- a/charts/spire/charts/spiffe-csi-driver/README.md.gotmpl +++ /dev/null @@ -1,24 +0,0 @@ -{{ template "chart.header" . }} - - - -{{ template "chart.deprecationWarning" . }} - -{{ template "chart.badgesSection" . }} - -{{ template "chart.description" . }} - -{{ template "chart.homepageLine" . }} - -> **Note**: The recommended version is `0.2.3` to support arm64 nodes. If running with any -> prior version to `0.2.3` you have to use a `nodeSelector` to limit to `kubernetes.io/arch: amd64`. - -{{ template "chart.maintainersSection" . }} - -{{ template "chart.sourcesSection" . }} - -{{ template "chart.requirementsSection" . }} - -{{ template "chart.valuesSection" . }} - ----------------------------------------------- diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md index 968de3c..d5cbe79 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md @@ -1,14 +1,13 @@ # spiffe-oidc-discovery-provider - - ![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.7.2](https://img.shields.io/badge/AppVersion-1.7.2-informational?style=flat-square) A Helm chart to install the SPIFFE OIDC discovery provider. **Homepage:** -> **Note**: Minimum Spire version is `1.5.3`. +> [!Note] +> Minimum Spire version is `1.5.3`. > The recommended version is `1.6.0` to support arm64 nodes. If running with any > prior version to `1.6.0` you have to use a `nodeSelector` to limit to `kubernetes.io/arch: amd64`. @@ -25,6 +24,8 @@ A Helm chart to install the SPIFFE OIDC discovery provider. * + + ## Parameters ### Chart parameters diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md.gotmpl b/charts/spire/charts/spiffe-oidc-discovery-provider/README.md.gotmpl deleted file mode 100644 index f9dafb6..0000000 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/README.md.gotmpl +++ /dev/null @@ -1,25 +0,0 @@ -{{ template "chart.header" . }} - - - -{{ template "chart.deprecationWarning" . }} - -{{ template "chart.badgesSection" . }} - -{{ template "chart.description" . }} - -{{ template "chart.homepageLine" . }} - -> **Note**: Minimum Spire version is `1.5.3`. -> The recommended version is `1.6.0` to support arm64 nodes. If running with any -> prior version to `1.6.0` you have to use a `nodeSelector` to limit to `kubernetes.io/arch: amd64`. - -{{ template "chart.maintainersSection" . }} - -{{ template "chart.sourcesSection" . }} - -{{ template "chart.requirementsSection" . }} - -{{ template "chart.valuesSection" . }} - ----------------------------------------------- diff --git a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml index ebdfa57..19bb438 100644 --- a/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml +++ b/charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml @@ -9,10 +9,10 @@ global: {} ## @param agentSocketName The name of the spire-agent unix socket agentSocketName: spire-agent.sock -## @param replicaCount Replica count +## @param replicaCount Replica count replicaCount: 1 -## @param namespaceOverride Namespace override +## @param namespaceOverride Namespace override namespaceOverride: "" ## @param annotations [object] Annotations for the deployment @@ -250,7 +250,7 @@ ingress: # nginx.ingress.kubernetes.io/ssl-redirect: "true" # nginx.ingress.kubernetes.io/force-ssl-redirect: "true" - ## @param ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. + ## @param ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. host: "oidc-discovery" ## @param ingress.tlsSecret Secret that has the certs. If blank will use default certs. Used with host var. diff --git a/charts/spire/charts/spire-agent/README.md b/charts/spire/charts/spire-agent/README.md index d2a55e5..976eca7 100644 --- a/charts/spire/charts/spire-agent/README.md +++ b/charts/spire/charts/spire-agent/README.md @@ -1,14 +1,13 @@ # spire-agent - - ![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.7.2](https://img.shields.io/badge/AppVersion-1.7.2-informational?style=flat-square) A Helm chart to install the SPIRE agent. **Homepage:** -> **Note**: Minimum Spire version is `1.5.3`. +> [!Note] +> Minimum Spire version is `1.5.3`. > The recommended version is `1.6.0` to support arm64 nodes. If running with any > prior version to `1.6.0` you have to use a `nodeSelector` to limit to `kubernetes.io/arch: amd64`. @@ -25,6 +24,8 @@ A Helm chart to install the SPIRE agent. * + + ## Parameters ### Chart parameters diff --git a/charts/spire/charts/spire-agent/README.md.gotmpl b/charts/spire/charts/spire-agent/README.md.gotmpl deleted file mode 100644 index f9dafb6..0000000 --- a/charts/spire/charts/spire-agent/README.md.gotmpl +++ /dev/null @@ -1,25 +0,0 @@ -{{ template "chart.header" . }} - - - -{{ template "chart.deprecationWarning" . }} - -{{ template "chart.badgesSection" . }} - -{{ template "chart.description" . }} - -{{ template "chart.homepageLine" . }} - -> **Note**: Minimum Spire version is `1.5.3`. -> The recommended version is `1.6.0` to support arm64 nodes. If running with any -> prior version to `1.6.0` you have to use a `nodeSelector` to limit to `kubernetes.io/arch: amd64`. - -{{ template "chart.maintainersSection" . }} - -{{ template "chart.sourcesSection" . }} - -{{ template "chart.requirementsSection" . }} - -{{ template "chart.valuesSection" . }} - ----------------------------------------------- diff --git a/charts/spire/charts/spire-agent/values.yaml b/charts/spire/charts/spire-agent/values.yaml index 8e9561a..5b2f44e 100644 --- a/charts/spire/charts/spire-agent/values.yaml +++ b/charts/spire/charts/spire-agent/values.yaml @@ -22,13 +22,13 @@ image: ## @param imagePullSecrets [array] Pull secrets for images imagePullSecrets: [] -## @param nameOverride Name override +## @param nameOverride Name override nameOverride: "" -## @param namespaceOverride Namespace override +## @param namespaceOverride Namespace override namespaceOverride: "" -## @param fullnameOverride Fullname override +## @param fullnameOverride Fullname override fullnameOverride: "" serviceAccount: diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index 726bcb5..70c61d7 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -1,14 +1,13 @@ # spire-server - - ![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.7.2](https://img.shields.io/badge/AppVersion-1.7.2-informational?style=flat-square) A Helm chart to install the SPIRE server. **Homepage:** -> **Note**: Minimum Spire version is `1.5.3`. +> [!Note] +> Minimum Spire version is `1.5.3`. > The recommended version is `1.6.0` to support arm64 nodes. If running with any > prior version to `1.6.0` you have to use a `nodeSelector` to limit to `kubernetes.io/arch: amd64`. > @@ -39,7 +38,8 @@ When Tornjak is enabled, it is exposed on both http and https (if TLS server cer In addition, you can configure a `client certificate authority`, this will make Tornjak backend verify Client certificates signed by this authority to enable mTLS authentication. -**Warning**: For production, we recommend configuring TLS certificates and client CA to protect Tornjak from unauthorized access. +> [!Important] +> For production, we recommend configuring TLS certificates and client CA to protect Tornjak from unauthorized access. ### Tornjak with TLS Connection Type @@ -47,13 +47,13 @@ TLS connection requires Tornjak to have access to TLS key and certificate. Complete instruction on creating your own TLS certificate can be found [here](https://github.com/spiffe/tornjak/blob/main/examples/tls_mtls/README.md). TLS Certificate and the private key must be provided to Tornjak via *TLS Secret*. Prior to deploying this Helm chart, create TLS Secret in the deployment namespace (e.g. `spire-server`) -```console +```shell kubectl -n spire-server create secret tls tornjak-tls-secret --cert=client.crt --key=client.key ``` Once the charts are deployed, you can test the TLS connection with the following command (assuming localhost): -```console +```shell curl --cacert CA/rootCA.crt https://localhost:10443 ``` @@ -67,13 +67,13 @@ Follow the steps to [create user CA for mTLS](https://github.com/spiffe/tornjak/ Here is an example using a *Secret* in `spire-server` namespace: -```console +```shell kubectl -n spire-server create secret generic tornjak-client-ca --from-file=ca.crt="CA/rootCA.crt" ``` Once the charts are deployed, you can test the mTLS connection with the following command (assuming localhost): -```console +```shell curl --cacert CA/rootCA.crt --key client.key --cert client.crt https://localhost:10443 ``` @@ -81,6 +81,8 @@ curl --cacert CA/rootCA.crt --key client.key --cert client.crt https://localhos In order to run Tornjak with simple HTTP Connection only, make sure you don't create any `Secrets` or `ConfigMaps` listed above. + + ## Parameters ### Chart parameters @@ -271,48 +273,53 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `defaultJwtSvidTTL` | TTL for JWT Svids | `1h` | | `nodeAttestor.k8sPsat.enabled` | Enable Psat k8s nodeattestor | `true` | | `nodeAttestor.k8sPsat.serviceAccountAllowList` | Allowed service accounts for Psat nodeattestor | `[]` | -| `tornjak.enabled` | Deploys Tornjak API (backend) (Not for production) | `false` | -| `tornjak.image.registry` | The OCI registry to pull the image from | `ghcr.io` | -| `tornjak.image.repository` | The repository within the registry | `spiffe/tornjak-backend` | -| `tornjak.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tornjak.image.version` | This value is deprecated in favor of tag. (Will be removed in a future release) | `""` | -| `tornjak.image.tag` | Overrides the image tag whose default is the chart appVersion | `v1.4.0` | -| `tornjak.service.type` | Type of service resource | `ClusterIP` | -| `tornjak.service.ports.http` | Insecure port for tornjak service | `10000` | -| `tornjak.service.ports.https` | Secure port for tornjak service | `10443` | -| `tornjak.service.annotations` | Annotations for the service | `{}` | -| `tornjak.ingress.enabled` | Flag to enable ingress for Tornjak backend service | `false` | -| `tornjak.ingress.className` | Ingress class name for Tornjak backend service | `""` | -| `tornjak.ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, autodetection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` | -| `tornjak.ingress.annotations` | Annotations for Tornjak backend service | `{}` | -| `tornjak.ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `tornjak-backend` | -| `tornjak.ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` | -| `tornjak.ingress.hosts` | Host paths for ingress object. If emtpy, rules will be built based on the host var. | `[]` | -| `tornjak.ingress.tls` | Secrets containing TLS certs to enable https on ingress. If emtpy, rules will be built based on the host and tlsSecret vars. | `[]` | -| `tornjak.startupProbe.failureThreshold` | Failure threshold count | `3` | -| `tornjak.startupProbe.initialDelaySeconds` | Initial delay seconds | `5` | -| `tornjak.startupProbe.periodSeconds` | Period seconds | `10` | -| `tornjak.startupProbe.successThreshold` | Success threshold count | `1` | -| `tornjak.startupProbe.timeoutSeconds` | Timeout in seconds | `5` | -| `tornjak.config.dataStore` | Persistent DB for storing Tornjak specific information | | -| `tornjak.config.dataStore.driver` | Database driver name | `sqlite3` | -| `tornjak.config.dataStore.file` | File path for sqlite3 file | `/run/spire/data/tornjak.sqlite3` | -| `tornjak.config.tlsSecret` | Name of the secret containing server side key and certificate for TLS verification (required for `tls` or `mtls` connectionType) | `tornjak-tls-secret` | -| `tornjak.config.clientCA.type` | Type of delivery for the user CA for TLS client verification. Options are `Secret` or `ConfigMap` (required for `mtls` connectionType) | `Secret` | -| `tornjak.config.clientCA.name` | Name of the resource secret or configMap with user CA for TLS | `tornjak-client-ca` | -| `tornjak.resources` | Resource requests and limits | `{}` | -| `customPlugins.keyManager` | Custom plugins of type KeyManager are configured here | `{}` | -| `customPlugins.nodeAttestor` | Custom plugins of type NodeAttestor are configured here | `{}` | -| `customPlugins.upstreamAuthority` | Custom plugins of type upstreamAuthority are configured here | `{}` | -| `customPlugins.notifier` | Custom plugins of type notifier are configured here | `{}` | -| `experimental.enabled` | Allow configuration of experimental features | `false` | -| `experimental.cacheReloadInterval` | The amount of time between two reloads of the in-memory entry cache. | `5s` | -| `experimental.featureFlags` | List of developer feature flags | `[]` | -| `tests.hostAliases` | List of host aliases for testing | `[]` | -| `tests.tls.enabled` | Flag for enabling tls for tests | `false` | -| `tests.tls.customCA` | Custom CA value for tests | `""` | -| `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | -| `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | -| `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | -| `tests.bash.image.version` | This value is deprecated in favor of tag. (Will be removed in a future release) | `""` | -| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:3d077aae77eb552abd85a015d087047a7a7353d974e5f7fc6a402180c1501214` | + +### Tornjak + +| Name | Description | Value | +| ------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | +| `tornjak.enabled` | Deploys Tornjak API (backend) (Not for production) | `false` | +| `tornjak.image.registry` | The OCI registry to pull the image from | `ghcr.io` | +| `tornjak.image.repository` | The repository within the registry | `spiffe/tornjak-backend` | +| `tornjak.image.pullPolicy` | The image pull policy | `IfNotPresent` | +| `tornjak.image.version` | This value is deprecated in favor of tag. (Will be removed in a future release) | `""` | +| `tornjak.image.tag` | Overrides the image tag whose default is the chart appVersion | `v1.4.0` | +| `tornjak.service.type` | Type of service resource | `ClusterIP` | +| `tornjak.service.ports.http` | Insecure port for tornjak service | `10000` | +| `tornjak.service.ports.https` | Secure port for tornjak service | `10443` | +| `tornjak.service.annotations` | Annotations for the service | `{}` | +| `tornjak.ingress.enabled` | Flag to enable ingress for Tornjak backend service | `false` | +| `tornjak.ingress.className` | Ingress class name for Tornjak backend service | `""` | +| `tornjak.ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, autodetection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` | +| `tornjak.ingress.annotations` | Annotations for Tornjak backend service | `{}` | +| `tornjak.ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `tornjak-backend` | +| `tornjak.ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` | +| `tornjak.ingress.hosts` | Host paths for ingress object. If emtpy, rules will be built based on the host var. | `[]` | +| `tornjak.ingress.tls` | Secrets containing TLS certs to enable https on ingress. If emtpy, rules will be built based on the host and tlsSecret vars. | `[]` | +| `tornjak.startupProbe.failureThreshold` | Failure threshold count | `3` | +| `tornjak.startupProbe.initialDelaySeconds` | Initial delay seconds | `5` | +| `tornjak.startupProbe.periodSeconds` | Period seconds | `10` | +| `tornjak.startupProbe.successThreshold` | Success threshold count | `1` | +| `tornjak.startupProbe.timeoutSeconds` | Timeout in seconds | `5` | +| `tornjak.config.dataStore` | Persistent DB for storing Tornjak specific information | | +| `tornjak.config.dataStore.driver` | Database driver name | `sqlite3` | +| `tornjak.config.dataStore.file` | File path for sqlite3 file | `/run/spire/data/tornjak.sqlite3` | +| `tornjak.config.tlsSecret` | Name of the secret containing server side key and certificate for TLS verification (required for `tls` or `mtls` connectionType) | `tornjak-tls-secret` | +| `tornjak.config.clientCA.type` | Type of delivery for the user CA for TLS client verification. Options are `Secret` or `ConfigMap` (required for `mtls` connectionType) | `Secret` | +| `tornjak.config.clientCA.name` | Name of the resource secret or configMap with user CA for TLS | `tornjak-client-ca` | +| `tornjak.resources` | Resource requests and limits | `{}` | +| `customPlugins.keyManager` | Custom plugins of type KeyManager are configured here | `{}` | +| `customPlugins.nodeAttestor` | Custom plugins of type NodeAttestor are configured here | `{}` | +| `customPlugins.upstreamAuthority` | Custom plugins of type upstreamAuthority are configured here | `{}` | +| `customPlugins.notifier` | Custom plugins of type notifier are configured here | `{}` | +| `experimental.enabled` | Allow configuration of experimental features | `false` | +| `experimental.cacheReloadInterval` | The amount of time between two reloads of the in-memory entry cache. | `5s` | +| `experimental.featureFlags` | List of developer feature flags | `[]` | +| `tests.hostAliases` | List of host aliases for testing | `[]` | +| `tests.tls.enabled` | Flag for enabling tls for tests | `false` | +| `tests.tls.customCA` | Custom CA value for tests | `""` | +| `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` | +| `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` | +| `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` | +| `tests.bash.image.version` | This value is deprecated in favor of tag. (Will be removed in a future release) | `""` | +| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:3d077aae77eb552abd85a015d087047a7a7353d974e5f7fc6a402180c1501214` | diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index 63c6647..c86bf00 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -212,7 +212,7 @@ federation: # If Profile Type == https_spiffe: # nginx.ingress.kubernetes.io/ssl-passthrough: "true" - ## @param federation.ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. + ## @param federation.ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. host: "spire-server-federation" ## @param federation.ingress.tlsSecret Secret that has the certs. If blank will use default certs. Used with host var. @@ -523,7 +523,7 @@ ingress: # nginx.ingress.kubernetes.io/backend-protocol: "HTTPS" # nginx.ingress.kubernetes.io/ssl-passthrough: "true" - ## @param ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. + ## @param ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. host: "spire-server" ## @param ingress.tlsSecret Secret that has the certs. If blank will use default certs. Used with host var. @@ -570,7 +570,7 @@ nodeAttestor: ## @param nodeAttestor.k8sPsat.serviceAccountAllowList [array] Allowed service accounts for Psat nodeattestor serviceAccountAllowList: [] -# tornjak - Tornjak default values +## @section Tornjak tornjak: ## @param tornjak.enabled Deploys Tornjak API (backend) (Not for production) enabled: false diff --git a/charts/spire/charts/tornjak-frontend/README.md b/charts/spire/charts/tornjak-frontend/README.md index c6cdd55..e8df4a2 100644 --- a/charts/spire/charts/tornjak-frontend/README.md +++ b/charts/spire/charts/tornjak-frontend/README.md @@ -1,7 +1,5 @@ # tornjak-frontend - - ![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v1.2.2](https://img.shields.io/badge/AppVersion-v1.2.2-informational?style=flat-square) [![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) @@ -11,7 +9,8 @@ A Helm chart to deploy Tornjak frontend ## Version support -> **Note**: This Chart is still in development and still subject to change the API (`values.yaml`). +> [!Note] +> This Chart is still in development and still subject to change the API (`values.yaml`). > Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although > we do aim for as much stability as possible. @@ -52,6 +51,8 @@ port forwarding. See the chart NOTES output for more details. * + + ## Parameters ### Chart parameters diff --git a/charts/spire/charts/tornjak-frontend/README.md.gotmpl b/charts/spire/charts/tornjak-frontend/README.md.gotmpl deleted file mode 100644 index c980a92..0000000 --- a/charts/spire/charts/tornjak-frontend/README.md.gotmpl +++ /dev/null @@ -1,54 +0,0 @@ -{{ template "chart.header" . }} - - - -{{ template "chart.deprecationWarning" . }} - -{{ template "chart.badgesSection" . }} -[![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) - -{{ template "chart.description" . }} - -{{ template "chart.homepageLine" . }} - -## Version support - -> **Note**: This Chart is still in development and still subject to change the API (`values.yaml`). -> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although -> we do aim for as much stability as possible. - -| Dependency | Supported Versions | -|:-----------|:-------------------| -| SPIRE | `1.5.3+`, `1.6.x` | -| Tornjak | `1.0.x` | -| Helm | `3.x` | - -## Tornjak - -Tornjak is the UI and Control Plane for SPIRE [https://github.com/spiffe/tornjak](https://github.com/spiffe/tornjak) and it is composed of two components: - -* [Backend](../spire-server/README.md) - Tornjak APIs that extend SPIRE APIs with Control Plane functionality -* Frontend (this chart) - Tornjak UI - -## Prerequisites - -This chart requires access to Tornjak Backend (`tornjakFrontend.apiServerURL`). -This URL needs to be reachable from your web browser and can therefore not be a cluster internal URL. - -Obtain the URL for Tornjak APIs. If deployed in the same cluster, locally, -Tornjak APIs are typically available at `http://localhost:10000`. -Review Tornjak documentation for more details. - -## Usage - -Since this is just a demo version, to access Tornjak APIs you can use -port forwarding. See the chart NOTES output for more details. - -{{ template "chart.maintainersSection" . }} - -{{ template "chart.sourcesSection" . }} - -{{ template "chart.requirementsSection" . }} - -{{ template "chart.valuesSection" . }} ----------------------------------------------- diff --git a/charts/spire/charts/tornjak-frontend/values.yaml b/charts/spire/charts/tornjak-frontend/values.yaml index 6b204e4..34ddb7e 100644 --- a/charts/spire/charts/tornjak-frontend/values.yaml +++ b/charts/spire/charts/tornjak-frontend/values.yaml @@ -126,7 +126,7 @@ ingress: controllerType: "" annotations: {} - ## @param ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. + ## @param ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. host: "tornjak-frontend" ## @param ingress.tlsSecret Secret that has the certs. If blank will use default certs. Used with host var. diff --git a/examples/openshift/README.md b/examples/openshift/README.md index da3d5b2..1e51815 100644 --- a/examples/openshift/README.md +++ b/examples/openshift/README.md @@ -1,6 +1,7 @@ # Recommended setup for installing Spire on Openshift -> **Note**: This functionality is under development. It works but has no automated testing and will have security tightened in the future. +> [!Note] +> This functionality is under development. It works but has no automated testing and will have security tightened in the future. This deployment works only with Openshift version 4.13 or higher. Get the Openshift platform here: [try.openshift.com](try.openshift.com) @@ -31,7 +32,8 @@ echo "$appdomain" Update the `example-your-values.yaml` file with your subdomain. -_Note: The location of the apps subdomain may be different in certain environments_ +> [!Note] +> The location of the apps subdomain may be different in certain environments_ ## Standard Deployment @@ -62,7 +64,8 @@ helm upgrade --install --namespace spire-server spire charts/spire \ Additional features such as tornjak can be enabled by including their example values files before --values examples/production/example-your-values.yaml For example: -``` + +```shell --values examples/openshift/openshift-values.yaml \ --values examples/tornjak/values.yaml \ --values examples/production/example-your-values.yaml \ @@ -71,6 +74,7 @@ For example: ## Finish install Once installed, the namespace security can be tightened back up. + ```shell kubectl label namespace "spire-server" pod-security.kubernetes.io/enforce=restricted --overwrite ``` diff --git a/examples/production/README.md b/examples/production/README.md index a8561e6..2982094 100644 --- a/examples/production/README.md +++ b/examples/production/README.md @@ -28,21 +28,25 @@ If you want to expose your spire-server outside of Kubernetes and are using ingr ```shell -f values-expose-spire-server-ingress-nginx.yaml ``` + For example: + ```shell helm upgrade --install --namespace spire-server spire charts/spire -f values.yaml -f values-expose-spire-server-ingress-nginx.yaml ``` If you want to expose your federation endpoint outside of Kubernetes and are using ingress-nginx you have two options as described here: -https://github.com/spiffe/spiffe/blob/main/standards/SPIFFE_Federation.md#52-endpoint-profiles +[github.com/spiffe/spiffe/blob/main/standards/SPIFFE_Federation.md#52-endpoint-profiles](https://github.com/spiffe/spiffe/blob/main/standards/SPIFFE_Federation.md#52-endpoint-profiles) If you chose profile https_web, use: ```shell -f values-expose-federation-https-web-ingress-nginx.yaml ``` + For example: + ```shell helm upgrade --install --namespace spire-server spire charts/spire -f values.yaml -f values-expose-federation-https-web-ingress-nginx.yaml ``` @@ -52,10 +56,11 @@ If you chose profile https_spiffe, use: ```shell -f values-expose-federation-https-spiffe-ingress-nginx.yaml ``` + For example: + ```shell helm upgrade --install --namespace spire-server spire charts/spire -f values.yaml -f values-expose-federation-https-spiffe-ingress-nginx.yaml ``` See [values.yaml](./values.yaml) for more details on the chart configurations to achieve this setup. - diff --git a/examples/tornjak/README.md b/examples/tornjak/README.md index 913ccc8..cbe7418 100644 --- a/examples/tornjak/README.md +++ b/examples/tornjak/README.md @@ -1,6 +1,7 @@ # Recommended setup to deploy Tornjak -> **Warning**: The current version of Tornjak in this chart is deployed without authentication. Therefore it is not suitable to run this version in production. +> [!Warning] +> The current version of Tornjak in this chart is deployed without authentication. Therefore it is not suitable to run this version in production. To install Spire with the least privileges possible we deploy spire across 2 namespaces. diff --git a/helm-docs.sh b/helm-docs.sh index 91cc2bb..43bfde7 100755 --- a/helm-docs.sh +++ b/helm-docs.sh @@ -3,7 +3,7 @@ set -euo pipefail SCRIPTPATH=$(dirname "$0") -README_GENERATOR_VERSION="2.5.1" +README_GENERATOR_VERSION="2.6.0" README_GENERATOR_EXE="readme-generator" if ! hash "${README_GENERATOR_EXE}" 2>/dev/null; then diff --git a/release-chart.sh b/release-chart.sh index 54eedf2..ee856cd 100755 --- a/release-chart.sh +++ b/release-chart.sh @@ -117,7 +117,8 @@ git push -u origin --force-with-lease cat < **Note**: **Maintainers** ensure to run following after merging this PR to trigger the release workflow: +> [!Note] +> **Maintainers** ensure to run following after merging this PR to trigger the release workflow: > > \`\`\`shell > git checkout main