From e78400ebcd0a0b353c1f33c710ae4eecc65ed487 Mon Sep 17 00:00:00 2001 From: kfox1111 Date: Mon, 23 Jun 2025 23:07:40 -0700 Subject: [PATCH] Initial spike support (#591) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * Initial spike support Signed-off-by: Kevin Fox * Fix lint and docs Signed-off-by: Kevin Fox * Update spike to 0.4.1 Signed-off-by: Kevin Fox * Update for multiarch Signed-off-by: Kevin Fox * Update Signed-off-by: Kevin Fox * Fix values and docs Signed-off-by: Kevin Fox * Pull in changes from Volkan Signed-off-by: Kevin Fox * Fix service Signed-off-by: Kevin Fox * Typo fix Signed-off-by: Volkan Özçelik * Apply suggestions from code review Co-authored-by: Faisal Memon Signed-off-by: kfox1111 * Update docs Signed-off-by: Kevin Fox --------- Signed-off-by: Kevin Fox Signed-off-by: Volkan Özçelik Signed-off-by: kfox1111 Co-authored-by: Volkan Özçelik Co-authored-by: Faisal Memon --- charts/spire/Chart.yaml | 12 ++ charts/spire/README.md | 18 ++ charts/spire/charts/spike-keeper/Chart.yaml | 13 ++ charts/spire/charts/spike-keeper/README.md | 72 ++++++++ .../charts/spike-keeper/templates/NOTES.txt | 1 + .../spike-keeper/templates/_helpers.tpl | 83 +++++++++ .../spike-keeper/templates/ingress.yaml | 44 +++++ .../spike-keeper/templates/service.yaml | 48 +++++ .../templates/serviceaccount.yaml | 13 ++ .../spike-keeper/templates/statefulset.yaml | 84 +++++++++ charts/spire/charts/spike-keeper/values.yaml | 139 ++++++++++++++ charts/spire/charts/spike-nexus/Chart.yaml | 13 ++ charts/spire/charts/spike-nexus/README.md | 82 +++++++++ .../charts/spike-nexus/templates/NOTES.txt | 1 + .../charts/spike-nexus/templates/_helpers.tpl | 83 +++++++++ .../charts/spike-nexus/templates/ingress.yaml | 31 ++++ .../charts/spike-nexus/templates/service.yaml | 20 ++ .../spike-nexus/templates/serviceaccount.yaml | 13 ++ .../spike-nexus/templates/statefulset.yaml | 112 ++++++++++++ charts/spire/charts/spike-nexus/values.yaml | 172 ++++++++++++++++++ charts/spire/charts/spike-pilot/Chart.yaml | 13 ++ charts/spire/charts/spike-pilot/README.md | 63 +++++++ .../charts/spike-pilot/templates/NOTES.txt | 1 + .../charts/spike-pilot/templates/_helpers.tpl | 83 +++++++++ .../spike-pilot/templates/deployment.yaml | 96 ++++++++++ .../spike-pilot/templates/serviceaccount.yaml | 13 ++ charts/spire/charts/spike-pilot/values.yaml | 116 ++++++++++++ charts/spire/charts/spire-server/README.md | 9 + .../controller-manager-cluster-ids.yaml | 19 +- charts/spire/charts/spire-server/values.yaml | 22 +++ charts/spire/values.yaml | 21 +++ examples/spike/values.yaml | 15 ++ 32 files changed, 1523 insertions(+), 2 deletions(-) create mode 100644 charts/spire/charts/spike-keeper/Chart.yaml create mode 100644 charts/spire/charts/spike-keeper/README.md create mode 100644 charts/spire/charts/spike-keeper/templates/NOTES.txt create mode 100644 charts/spire/charts/spike-keeper/templates/_helpers.tpl create mode 100644 charts/spire/charts/spike-keeper/templates/ingress.yaml create mode 100644 charts/spire/charts/spike-keeper/templates/service.yaml create mode 100644 charts/spire/charts/spike-keeper/templates/serviceaccount.yaml create mode 100644 charts/spire/charts/spike-keeper/templates/statefulset.yaml create mode 100644 charts/spire/charts/spike-keeper/values.yaml create mode 100644 charts/spire/charts/spike-nexus/Chart.yaml create mode 100644 charts/spire/charts/spike-nexus/README.md create mode 100644 charts/spire/charts/spike-nexus/templates/NOTES.txt create mode 100644 charts/spire/charts/spike-nexus/templates/_helpers.tpl create mode 100644 charts/spire/charts/spike-nexus/templates/ingress.yaml create mode 100644 charts/spire/charts/spike-nexus/templates/service.yaml create mode 100644 charts/spire/charts/spike-nexus/templates/serviceaccount.yaml create mode 100644 charts/spire/charts/spike-nexus/templates/statefulset.yaml create mode 100644 charts/spire/charts/spike-nexus/values.yaml create mode 100644 charts/spire/charts/spike-pilot/Chart.yaml create mode 100644 charts/spire/charts/spike-pilot/README.md create mode 100644 charts/spire/charts/spike-pilot/templates/NOTES.txt create mode 100644 charts/spire/charts/spike-pilot/templates/_helpers.tpl create mode 100644 charts/spire/charts/spike-pilot/templates/deployment.yaml create mode 100644 charts/spire/charts/spike-pilot/templates/serviceaccount.yaml create mode 100644 charts/spire/charts/spike-pilot/values.yaml create mode 100644 examples/spike/values.yaml diff --git a/charts/spire/Chart.yaml b/charts/spire/Chart.yaml index b9c3528..3ef2cad 100644 --- a/charts/spire/Chart.yaml +++ b/charts/spire/Chart.yaml @@ -55,6 +55,18 @@ dependencies: condition: tornjak-frontend.enabled repository: file://./charts/tornjak-frontend version: 0.1.0 + - name: spike-keeper + condition: spike-keeper.enabled + repository: file://./charts/spike-keeper + version: 0.1.0 + - name: spike-nexus + condition: spike-nexus.enabled + repository: file://./charts/spike-nexus + version: 0.1.0 + - name: spike-pilot + condition: spike-pilot.enabled + repository: file://./charts/spike-pilot + version: 0.1.0 annotations: artifacthub.io/category: security artifacthub.io/license: Apache-2.0 diff --git a/charts/spire/README.md b/charts/spire/README.md index 69d6857..0fb63c3 100644 --- a/charts/spire/README.md +++ b/charts/spire/README.md @@ -373,3 +373,21 @@ Now you can interact with the Spire agent socket from your own application. The | Name | Description | Value | | -------------------------- | -------------------------------------------------------------- | ------- | | `tornjak-frontend.enabled` | Enables deployment of Tornjak frontend/UI (Not for production) | `false` | + +### SPIKE Keeper parameters + +| Name | Description | Value | +| ---------------------- | ------------------------------------------------------- | ------- | +| `spike-keeper.enabled` | Enables deployment of SPIKE Keeper (Not for production) | `false` | + +### SPIKE Nexus parameters + +| Name | Description | Value | +| --------------------- | ------------------------------------------------------ | ------- | +| `spike-nexus.enabled` | Enables deployment of SPIKE Nexus (Not for production) | `false` | + +### SPIKE Pilot parameters + +| Name | Description | Value | +| --------------------- | ------------------------------------------------------ | ------- | +| `spike-pilot.enabled` | Enables deployment of SPIKE Pilot (Not for production) | `false` | diff --git a/charts/spire/charts/spike-keeper/Chart.yaml b/charts/spire/charts/spike-keeper/Chart.yaml new file mode 100644 index 0000000..9cb2683 --- /dev/null +++ b/charts/spire/charts/spike-keeper/Chart.yaml @@ -0,0 +1,13 @@ +apiVersion: v2 +name: spike-keeper +description: A Helm chart to deploy SPIKE Keeper +type: application +version: 0.1.0 +appVersion: "0.4.1" +home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire +sources: + - https://github.com/spiffe/spike +icon: https://spike.ist/assets/spike-banner.png +maintainers: + - name: kfox1111 + email: Kevin.Fox@pnnl.gov diff --git a/charts/spire/charts/spike-keeper/README.md b/charts/spire/charts/spike-keeper/README.md new file mode 100644 index 0000000..2552edf --- /dev/null +++ b/charts/spire/charts/spike-keeper/README.md @@ -0,0 +1,72 @@ +# spike-keeper + +![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v0.4.1](https://img.shields.io/badge/AppVersion-v0.4.1-informational?style=flat-square) +[![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) + +A Helm chart to deploy spike keepers + +**Homepage:** + +## Version support + +> [!Note] +> This Chart is still in development and still subject to change the API (`values.yaml`). +> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although +> we do aim for as much stability as possible. + +| Dependency | Supported Versions | +|:-----------|:-------------------| +| Helm | `3.x` | + +## Source Code + +* + + + +## Parameters + +### Chart parameters + +| Name | Description | Value | +| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------- | +| `image.registry` | The OCI registry to pull the image from | `ghcr.io` | +| `image.repository` | The repository within the registry | `spiffe/spike-keeper` | +| `image.pullPolicy` | The image pull policy | `IfNotPresent` | +| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` | +| `replicas` | The number of keepers to launch | `3` | +| `trustRoot.nexus` | Override which trustRoot Nexus is in | `""` | +| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `debug` | +| `agentSocketName` | The name of the spire-agent unix socket | `spire-agent.sock` | +| `csiDriverName` | The csi driver to use | `csi.spiffe.io` | +| `imagePullSecrets` | Pull secrets for images | `[]` | +| `nameOverride` | Name override | `""` | +| `namespaceOverride` | Namespace override | `""` | +| `fullnameOverride` | Fullname override | `""` | +| `serviceAccount.create` | Specifies whether a service account should be created | `true` | +| `serviceAccount.annotations` | Annotations to add to the service account | `{}` | +| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` | +| `labels` | Labels for pods | `{}` | +| `podSecurityContext` | Pod security context | `{}` | +| `securityContext` | Security context | `{}` | +| `service.type` | Service type | `ClusterIP` | +| `service.port` | Service port | `443` | +| `service.annotations` | Annotations for service resource | `{}` | +| `nodeSelector` | (Optional) Select specific nodes to run on. | `{}` | +| `affinity` | Affinity rules | `{}` | +| `tolerations` | List of tolerations | `[]` | +| `topologySpreadConstraints` | List of topology spread constraints for resilience | `[]` | +| `startupProbe.enabled` | Enable startupProbe | `true` | +| `startupProbe.initialDelaySeconds` | Initial delay seconds for startupProbe | `5` | +| `startupProbe.periodSeconds` | Period seconds for startupProbe | `10` | +| `startupProbe.timeoutSeconds` | Timeout seconds for startupProbe | `5` | +| `startupProbe.failureThreshold` | Failure threshold count for startupProbe | `6` | +| `startupProbe.successThreshold` | Success threshold count for startupProbe | `1` | +| `ingress.enabled` | Flag to enable ingress | `false` | +| `ingress.className` | Ingress class name | `""` | +| `ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` | +| `ingress.annotations` | Annotations | `{}` | +| `ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `keeper` | +| `ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` | +| `ingress.hosts` | Host paths for ingress object. If empty, rules will be built based on the host var. | `[]` | +| `ingress.tls` | Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. | `[]` | diff --git a/charts/spire/charts/spike-keeper/templates/NOTES.txt b/charts/spire/charts/spike-keeper/templates/NOTES.txt new file mode 100644 index 0000000..dfe3e24 --- /dev/null +++ b/charts/spire/charts/spike-keeper/templates/NOTES.txt @@ -0,0 +1 @@ +Installed {{ .Chart.Name }}… diff --git a/charts/spire/charts/spike-keeper/templates/_helpers.tpl b/charts/spire/charts/spike-keeper/templates/_helpers.tpl new file mode 100644 index 0000000..66c9019 --- /dev/null +++ b/charts/spire/charts/spike-keeper/templates/_helpers.tpl @@ -0,0 +1,83 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "spike-keeper.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "spike-keeper.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Allow the release namespace to be overridden for multi-namespace deployments in combined charts +*/}} +{{- define "spike-keeper.namespace" -}} + {{- if .Values.namespaceOverride -}} + {{- .Values.namespaceOverride -}} + {{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }} + {{- if ne (len (dig "spire" "namespaces" "server" "name" "" .Values.global)) 0 }} + {{- .Values.global.spire.namespaces.server.name }} + {{- else }} + {{- printf "spire-server" }} + {{- end }} + {{- else -}} + {{- .Release.Namespace -}} + {{- end -}} +{{- end -}} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "spike-keeper.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "spike-keeper.labels" -}} +helm.sh/chart: {{ include "spike-keeper.chart" . }} +{{ include "spike-keeper.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "spike-keeper.selectorLabels" -}} +app.kubernetes.io/name: {{ include "spike-keeper.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} + +{{/* +Create the name of the service account to use +*/}} +{{- define "spike-keeper.serviceAccountName" -}} +{{- if .Values.serviceAccount.create }} +{{- default (include "spike-keeper.fullname" .) .Values.serviceAccount.name }} +{{- else }} +{{- default "default" .Values.serviceAccount.name }} +{{- end }} +{{- end }} + +{{- define "spike-keeper.workload-api-socket-path" -}} +{{- printf "/spiffe-workload-api/%s" .Values.agentSocketName }} +{{- end }} diff --git a/charts/spire/charts/spike-keeper/templates/ingress.yaml b/charts/spire/charts/spike-keeper/templates/ingress.yaml new file mode 100644 index 0000000..af2ff0c --- /dev/null +++ b/charts/spire/charts/spike-keeper/templates/ingress.yaml @@ -0,0 +1,44 @@ +{{- if .Values.ingress.enabled -}} +{{ $root := . }} +{{- $ingressControllerType := include "spire-lib.ingress-controller-type" (dict "global" .Values.global "ingress" .Values.ingress) }} +{{- $fullName := include "spike-keeper.fullname" . -}} +{{- $tlsSection := true }} +{{- $annotations := deepCopy .Values.ingress.annotations }} +{{- if eq $ingressControllerType "ingress-nginx" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-redirect" "true" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/force-ssl-redirect" "true" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/backend-protocol" "HTTPS" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-passthrough" "true" }} +{{- else if eq $ingressControllerType "openshift" }} +{{- $path = "" }} +{{- $_ := set $annotations "route.openshift.io/termination" "passthrough" }} +{{- $tlsSection = false }} +{{- end }} +{{ $last := sub (.Values.replicas | int) 1 | int }} +{{ range (seq 0 ($last) | toString | split " ") }} +{{ $i := . }} +--- +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: {{ $fullName }}-{{ $i }} + namespace: {{ include "spike-keeper.namespace" $root }} + labels: + {{ include "spike-keeper.labels" $root | nindent 4}} + {{- with $annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + {{- $host := $root.Values.ingress.host }} + {{- if contains "." $host }} + {{- $hostParts := regexSplit "[.]" $host 2 }} + {{- $host = printf "%s-%s.%s" (index $hostParts 0) $i (index $hostParts 1) }} + {{- else }} + {{- $host = printf "%s-%s" $host $i }} + {{- end }} + {{ $ingress := deepCopy $root.Values.ingress }} + {{ $_ := set $ingress "host" $host }} + {{ include "spire-lib.ingress-spec" (dict "ingress" $ingress "svcName" (printf "%s-%s" $fullName $i) "port" $root.Values.service.port "path" "/" "pathType" "Prefix" "tlsSection" $tlsSection "Values" $root.Values) | nindent 2 }} +{{- end }} +{{- end }} diff --git a/charts/spire/charts/spike-keeper/templates/service.yaml b/charts/spire/charts/spike-keeper/templates/service.yaml new file mode 100644 index 0000000..1d86355 --- /dev/null +++ b/charts/spire/charts/spike-keeper/templates/service.yaml @@ -0,0 +1,48 @@ +{{ $root := . }} +{{ $last := sub (.Values.replicas | int) 1 | int }} +{{ range (seq 0 ($last) | toString | split " ") }} +{{ $i := . }} +--- +apiVersion: v1 +kind: Service +metadata: + namespace: {{ include "spike-keeper.namespace" $root }} + name: {{ include "spike-keeper.fullname" $root }}-{{ $i }} + {{- with $root.Values.service.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + labels: + apps.kubernetes.io/pod-index: {{ $i | quote }} + {{- include "spike-keeper.labels" $root | nindent 4 }} +spec: + type: {{ $root.Values.service.type }} + selector: + apps.kubernetes.io/pod-index: {{ $i | quote }} + {{- include "spike-keeper.selectorLabels" $root | nindent 4 }} + ports: + - name: {{ include "spike-keeper.fullname" $root }} + port: {{ $root.Values.service.port }} + targetPort: http +{{ end }} +--- +apiVersion: v1 +kind: Service +metadata: + namespace: {{ include "spike-keeper.namespace" $root }} + name: {{ include "spike-keeper.fullname" $root }}-headless + {{- with $root.Values.service.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + labels: + {{- include "spike-keeper.labels" $root | nindent 4 }} +spec: + type: {{ $root.Values.service.type }} + clusterIP: None + selector: + {{- include "spike-keeper.selectorLabels" $root | nindent 4 }} + ports: + - name: {{ include "spike-keeper.fullname" $root }} + port: {{ $root.Values.service.port }} + targetPort: http diff --git a/charts/spire/charts/spike-keeper/templates/serviceaccount.yaml b/charts/spire/charts/spike-keeper/templates/serviceaccount.yaml new file mode 100644 index 0000000..7f13cb3 --- /dev/null +++ b/charts/spire/charts/spike-keeper/templates/serviceaccount.yaml @@ -0,0 +1,13 @@ +{{- if .Values.serviceAccount.create -}} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ include "spike-keeper.serviceAccountName" . }} + namespace: {{ include "spike-keeper.namespace" . }} + labels: + {{- include "spike-keeper.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +{{- end }} diff --git a/charts/spire/charts/spike-keeper/templates/statefulset.yaml b/charts/spire/charts/spike-keeper/templates/statefulset.yaml new file mode 100644 index 0000000..baf33f8 --- /dev/null +++ b/charts/spire/charts/spike-keeper/templates/statefulset.yaml @@ -0,0 +1,84 @@ +apiVersion: apps/v1 +kind: StatefulSet +metadata: + name: {{ include "spike-keeper.fullname" . }} + namespace: {{ include "spike-keeper.namespace" . }} + labels: + {{- include "spike-keeper.labels" . | nindent 4 }} +spec: + serviceName: {{ include "spike-keeper.fullname" . }}-headless + replicas: {{ .Values.replicas }} + selector: + matchLabels: + {{- include "spike-keeper.selectorLabels" . | nindent 6 }} + template: + metadata: + labels: + {{- include "spike-keeper.selectorLabels" . | nindent 8 }} + release: {{ .Release.Name }} + release-namespace: {{ .Release.Namespace }} + component: spike-keeper + spec: + {{- with .Values.imagePullSecrets }} + imagePullSecrets: + {{- toYaml . | nindent 8 }} + {{- end }} + serviceAccountName: {{ include "spike-keeper.serviceAccountName" . }} + securityContext: + {{- include "spire-lib.podsecuritycontext" . | nindent 8 }} + containers: + - name: {{ include "spike-keeper.fullname" . }} + image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image "global" .Values.global "ubi" true) }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + securityContext: + {{- include "spire-lib.securitycontext" . | nindent 12 }} + ports: + - name: http + containerPort: 8443 + protocol: TCP + env: + - name: SPIFFE_ENDPOINT_SOCKET + value: unix://{{ include "spike-keeper.workload-api-socket-path" . }} + - name: SPIKE_SYSTEM_LOG_LEVEL + value: {{ .Values.logLevel | upper }} + - name: SPIKE_TRUST_ROOT + value: {{ include "spire-lib.trust-domain" . }} + - name: SPIKE_TRUST_ROOT_NEXUS + value: {{if eq .Values.trustRoot.nexus "" }}{{ include "spire-lib.trust-domain" . }}{{ else }}{{.Values.trustRoot.nexus }}{{ end }} + - name: SPIKE_KEEPER_TLS_PORT + value: ":8443" + {{- if .Values.startupProbe.enabled }} + startupProbe: + tcpSocket: + port: 8443 + failureThreshold: {{ .Values.startupProbe.failureThreshold }} + initialDelaySeconds: {{ .Values.startupProbe.initialDelaySeconds }} + periodSeconds: {{ .Values.startupProbe.periodSeconds }} + successThreshold: {{ .Values.startupProbe.successThreshold }} + timeoutSeconds: {{ .Values.startupProbe.timeoutSeconds }} + {{- end }} + volumeMounts: + - name: spiffe-workload-api + mountPath: {{ include "spike-keeper.workload-api-socket-path" . | dir }} + readOnly: true + {{- with .Values.nodeSelector }} + nodeSelector: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.tolerations }} + tolerations: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.topologySpreadConstraints }} + topologySpreadConstraints: + {{- toYaml . | nindent 8 }} + {{- end }} + volumes: + - name: spiffe-workload-api + csi: + driver: "{{ .Values.csiDriverName }}" + readOnly: true diff --git a/charts/spire/charts/spike-keeper/values.yaml b/charts/spire/charts/spike-keeper/values.yaml new file mode 100644 index 0000000..312280d --- /dev/null +++ b/charts/spire/charts/spike-keeper/values.yaml @@ -0,0 +1,139 @@ +# Default configuration for SPIKE Keeper +# SPDX-License-Identifier: APACHE-2.0 + +## @skip global +global: {} + +## @section Chart parameters +## +## @param image.registry The OCI registry to pull the image from +## @param image.repository The repository within the registry +## @param image.pullPolicy The image pull policy +## @param image.tag Overrides the image tag whose default is the chart appVersion +## +image: + registry: ghcr.io + repository: spiffe/spike-keeper + pullPolicy: IfNotPresent + tag: "" + +## @param replicas The number of keepers to launch +replicas: 3 + +trustRoot: + ## @param trustRoot.nexus Override which trustRoot Nexus is in + nexus: "" + +## @param logLevel The log level, valid values are "debug", "info", "warn", and "error" +logLevel: debug + +## @param agentSocketName The name of the spire-agent unix socket +agentSocketName: spire-agent.sock +## @param csiDriverName The csi driver to use +csiDriverName: csi.spiffe.io + +## @param imagePullSecrets [array] Pull secrets for images +imagePullSecrets: [] + +## @param nameOverride Name override +nameOverride: "" + +## @param namespaceOverride Namespace override +namespaceOverride: "" + +## @param fullnameOverride Fullname override +fullnameOverride: "" + +## @param serviceAccount.create Specifies whether a service account should be created +## @param serviceAccount.annotations [object] Annotations to add to the service account +## @param serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated. +## +serviceAccount: + create: true + annotations: {} + name: "" + +## @param labels [object] Labels for pods +labels: {} + +## @param podSecurityContext [object] Pod security context +podSecurityContext: {} + # fsGroup: 2000 + +## @param securityContext [object] Security context +securityContext: {} + # capabilities: + # drop: + # - ALL + # readOnlyRootFilesystem: true + # runAsNonRoot: true + # runAsUser: 1000 + +## @param service.type Service type +## @param service.port Service port +## @param service.annotations Annotations for service resource +## +service: + type: ClusterIP + port: 443 + annotations: {} + +## @param nodeSelector (Optional) Select specific nodes to run on. +nodeSelector: {} + +## @param affinity [object] Affinity rules +affinity: {} + +## @param tolerations [array] List of tolerations +tolerations: [] + +## @param topologySpreadConstraints [array] List of topology spread constraints for resilience +topologySpreadConstraints: [] + +## Provide minimal resources to prevent accidental crashes due to resource exhaustion +# resources: +# requests: +# cpu: 50m +# memory: 128Mi +# limits: +# cpu: 100m +# memory: 512Mi + +## Configure extra options for startup probe +## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-startup-probes +## @param startupProbe.enabled Enable startupProbe +## @param startupProbe.initialDelaySeconds Initial delay seconds for startupProbe +## @param startupProbe.periodSeconds Period seconds for startupProbe +## @param startupProbe.timeoutSeconds Timeout seconds for startupProbe +## @param startupProbe.failureThreshold Failure threshold count for startupProbe +## @param startupProbe.successThreshold Success threshold count for startupProbe +## +startupProbe: + enabled: true + initialDelaySeconds: 5 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 6 + successThreshold: 1 + +## @param ingress.enabled Flag to enable ingress +## @param ingress.className Ingress class name +## @param ingress.controllerType Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. +## @param ingress.annotations [object] Annotations +ingress: + enabled: false + className: "" + controllerType: "" + annotations: {} + + ## @param ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. + host: "keeper" + + ## @param ingress.tlsSecret Secret that has the certs. If blank will use default certs. Used with host var. + tlsSecret: "" + + ## @param ingress.hosts [array] Host paths for ingress object. If empty, rules will be built based on the host var. + hosts: [] + + ## @param ingress.tls [array] Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. + tls: [] diff --git a/charts/spire/charts/spike-nexus/Chart.yaml b/charts/spire/charts/spike-nexus/Chart.yaml new file mode 100644 index 0000000..c125986 --- /dev/null +++ b/charts/spire/charts/spike-nexus/Chart.yaml @@ -0,0 +1,13 @@ +apiVersion: v2 +name: spike-nexus +description: A Helm chart to deploy SPIKE Nexus +type: application +version: 0.1.0 +appVersion: "0.4.1" +home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire +sources: + - https://github.com/spiffe/spike +icon: https://spike.ist/assets/spike-banner.png +maintainers: + - name: kfox1111 + email: Kevin.Fox@pnnl.gov diff --git a/charts/spire/charts/spike-nexus/README.md b/charts/spire/charts/spike-nexus/README.md new file mode 100644 index 0000000..9d20a00 --- /dev/null +++ b/charts/spire/charts/spike-nexus/README.md @@ -0,0 +1,82 @@ +# spike-nexus + +![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v0.4.1](https://img.shields.io/badge/AppVersion-v0.4.1-informational?style=flat-square) +[![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) + +A Helm chart to deploy spike nexus + +**Homepage:** + +## Version support + +> [!Note] +> This Chart is still in development and still subject to change the API (`values.yaml`). +> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although +> we do aim for as much stability as possible. + +| Dependency | Supported Versions | +|:-----------|:-------------------| +| Helm | `3.x` | + +## Source Code + +* + + + +## Parameters + +### Chart parameters + +| Name | Description | Value | +| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------- | +| `image.registry` | The OCI registry to pull the image from | `ghcr.io` | +| `image.repository` | The repository within the registry | `spiffe/spike-nexus` | +| `image.pullPolicy` | The image pull policy | `IfNotPresent` | +| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` | +| `replicas` | The number of keepers to launch | `1` | +| `shamir.shares` | How many shares to configure for shamir secrets | `3` | +| `shamir.threshold` | How many shares needed to recover | `2` | +| `keeperPeers` | Keeper peer configuration. If blank, it will be autodetected | `[]` | +| `trustRoot.nexus` | Override which trustRoot Nexus is in | `""` | +| `trustRoot.keepers` | Override which trustRoot Keepers are in | `[]` | +| `trustRoot.pilot` | Override which trustRoot Pilot is in | `""` | +| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `debug` | +| `agentSocketName` | The name of the spire-agent unix socket | `spire-agent.sock` | +| `csiDriverName` | The csi driver to use | `csi.spiffe.io` | +| `imagePullSecrets` | Pull secrets for images | `[]` | +| `nameOverride` | Name override | `""` | +| `namespaceOverride` | Namespace override | `""` | +| `fullnameOverride` | Fullname override | `""` | +| `serviceAccount.create` | Specifies whether a service account should be created | `true` | +| `serviceAccount.annotations` | Annotations to add to the service account | `{}` | +| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` | +| `labels` | Labels for pods | `{}` | +| `podSecurityContext` | Pod security context | `{}` | +| `securityContext` | Security context | `{}` | +| `service.type` | Service type | `ClusterIP` | +| `service.port` | Service port | `443` | +| `service.annotations` | Annotations for service resource | `{}` | +| `nodeSelector` | (Optional) Select specific nodes to run on. | `{}` | +| `affinity` | Affinity rules | `{}` | +| `tolerations` | List of tolerations | `[]` | +| `topologySpreadConstraints` | List of topology spread constraints for resilience | `[]` | +| `startupProbe.enabled` | Enable startupProbe | `true` | +| `startupProbe.initialDelaySeconds` | Initial delay seconds for startupProbe | `5` | +| `startupProbe.periodSeconds` | Period seconds for startupProbe | `10` | +| `startupProbe.timeoutSeconds` | Timeout seconds for startupProbe | `5` | +| `startupProbe.failureThreshold` | Failure threshold count for startupProbe | `6` | +| `startupProbe.successThreshold` | Success threshold count for startupProbe | `1` | +| `ingress.enabled` | Flag to enable ingress | `false` | +| `ingress.className` | Ingress class name | `""` | +| `ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` | +| `ingress.annotations` | Annotations | `{}` | +| `ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `nexus` | +| `ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` | +| `ingress.hosts` | Host paths for ingress object. If empty, rules will be built based on the host var. | `[]` | +| `ingress.tls` | Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. | `[]` | +| `persistence.type` | What type of volume to use for persistence. Valid options pvc (recommended), hostPath, emptyDir (testing only) | `pvc` | +| `persistence.size` | What size volume to use for persistence | `1Gi` | +| `persistence.accessMode` | What access mode to use for persistence. Valid options are ReadWriteOnce (recommended), ReadWriteOncePod, ReadWriteMany (not recommended) | `ReadWriteOnce` | +| `persistence.storageClass` | What storage class to use for persistence | `nil` | +| `persistence.hostPath` | Which path to use on the host when persistence.type = hostPath | `""` | diff --git a/charts/spire/charts/spike-nexus/templates/NOTES.txt b/charts/spire/charts/spike-nexus/templates/NOTES.txt new file mode 100644 index 0000000..dfe3e24 --- /dev/null +++ b/charts/spire/charts/spike-nexus/templates/NOTES.txt @@ -0,0 +1 @@ +Installed {{ .Chart.Name }}… diff --git a/charts/spire/charts/spike-nexus/templates/_helpers.tpl b/charts/spire/charts/spike-nexus/templates/_helpers.tpl new file mode 100644 index 0000000..22df59e --- /dev/null +++ b/charts/spire/charts/spike-nexus/templates/_helpers.tpl @@ -0,0 +1,83 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "spike-nexus.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "spike-nexus.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Allow the release namespace to be overridden for multi-namespace deployments in combined charts +*/}} +{{- define "spike-nexus.namespace" -}} + {{- if .Values.namespaceOverride -}} + {{- .Values.namespaceOverride -}} + {{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }} + {{- if ne (len (dig "spire" "namespaces" "server" "name" "" .Values.global)) 0 }} + {{- .Values.global.spire.namespaces.server.name }} + {{- else }} + {{- printf "spire-server" }} + {{- end }} + {{- else -}} + {{- .Release.Namespace -}} + {{- end -}} +{{- end -}} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "spike-nexus.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "spike-nexus.labels" -}} +helm.sh/chart: {{ include "spike-nexus.chart" . }} +{{ include "spike-nexus.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "spike-nexus.selectorLabels" -}} +app.kubernetes.io/name: {{ include "spike-nexus.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} + +{{/* +Create the name of the service account to use +*/}} +{{- define "spike-nexus.serviceAccountName" -}} +{{- if .Values.serviceAccount.create }} +{{- default (include "spike-nexus.fullname" .) .Values.serviceAccount.name }} +{{- else }} +{{- default "default" .Values.serviceAccount.name }} +{{- end }} +{{- end }} + +{{- define "spike-nexus.workload-api-socket-path" -}} +{{- printf "/spiffe-workload-api/%s" .Values.agentSocketName }} +{{- end }} diff --git a/charts/spire/charts/spike-nexus/templates/ingress.yaml b/charts/spire/charts/spike-nexus/templates/ingress.yaml new file mode 100644 index 0000000..82c1b8a --- /dev/null +++ b/charts/spire/charts/spike-nexus/templates/ingress.yaml @@ -0,0 +1,31 @@ +{{- if .Values.ingress.enabled -}} +{{ $root := . }} +{{- $ingressControllerType := include "spire-lib.ingress-controller-type" (dict "global" .Values.global "ingress" .Values.ingress) }} +{{- $fullName := include "spike-nexus.fullname" . -}} +{{- $tlsSection := true }} +{{- $annotations := deepCopy .Values.ingress.annotations }} +{{- if eq $ingressControllerType "ingress-nginx" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-redirect" "true" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/force-ssl-redirect" "true" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/backend-protocol" "HTTPS" }} +{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-passthrough" "true" }} +{{- else if eq $ingressControllerType "openshift" }} +{{- $path = "" }} +{{- $_ := set $annotations "route.openshift.io/termination" "passthrough" }} +{{- $tlsSection = false }} +{{- end }} +{{ $last := sub (.Values.replicas | int) 1 | int }} +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: {{ $fullName }} + namespace: {{ include "spike-nexus.namespace" $root }} + labels: + {{ include "spike-nexus.labels" $root | nindent 4}} + {{- with $annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + {{ include "spire-lib.ingress-spec" (dict "ingress" .Values.ingress "svcName" $fullName "port" $root.Values.service.port "path" "/" "pathType" "Prefix" "tlsSection" $tlsSection "Values" $root.Values) | nindent 2 }} +{{- end }} diff --git a/charts/spire/charts/spike-nexus/templates/service.yaml b/charts/spire/charts/spike-nexus/templates/service.yaml new file mode 100644 index 0000000..40d2733 --- /dev/null +++ b/charts/spire/charts/spike-nexus/templates/service.yaml @@ -0,0 +1,20 @@ +{{ $root := . }} +apiVersion: v1 +kind: Service +metadata: + namespace: {{ include "spike-nexus.namespace" $root }} + name: {{ include "spike-nexus.fullname" $root }} + {{- with $root.Values.service.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + labels: + {{- include "spike-nexus.labels" $root | nindent 4 }} +spec: + type: {{ $root.Values.service.type }} + selector: + {{- include "spike-nexus.selectorLabels" $root | nindent 4 }} + ports: + - name: {{ include "spike-nexus.fullname" $root }} + port: {{ $root.Values.service.port }} + targetPort: http diff --git a/charts/spire/charts/spike-nexus/templates/serviceaccount.yaml b/charts/spire/charts/spike-nexus/templates/serviceaccount.yaml new file mode 100644 index 0000000..01380df --- /dev/null +++ b/charts/spire/charts/spike-nexus/templates/serviceaccount.yaml @@ -0,0 +1,13 @@ +{{- if .Values.serviceAccount.create -}} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ include "spike-nexus.serviceAccountName" . }} + namespace: {{ include "spike-nexus.namespace" . }} + labels: + {{- include "spike-nexus.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +{{- end }} diff --git a/charts/spire/charts/spike-nexus/templates/statefulset.yaml b/charts/spire/charts/spike-nexus/templates/statefulset.yaml new file mode 100644 index 0000000..1dfeb6b --- /dev/null +++ b/charts/spire/charts/spike-nexus/templates/statefulset.yaml @@ -0,0 +1,112 @@ +apiVersion: apps/v1 +kind: StatefulSet +metadata: + name: {{ include "spike-nexus.fullname" . }} + namespace: {{ include "spike-nexus.namespace" . }} + labels: + {{- include "spike-nexus.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicas }} + selector: + matchLabels: + {{- include "spike-nexus.selectorLabels" . | nindent 6 }} + template: + metadata: + labels: + {{- include "spike-nexus.selectorLabels" . | nindent 8 }} + release: {{ .Release.Name }} + release-namespace: {{ .Release.Namespace }} + component: spike-nexus + spec: + {{- with .Values.imagePullSecrets }} + imagePullSecrets: + {{- toYaml . | nindent 8 }} + {{- end }} + serviceAccountName: {{ include "spike-nexus.serviceAccountName" . }} + securityContext: + {{- include "spire-lib.podsecuritycontext" . | nindent 8 }} + containers: + - name: {{ include "spike-nexus.fullname" . }} + image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image "global" .Values.global "ubi" true) }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + securityContext: + {{- include "spire-lib.securitycontext" . | nindent 12 }} + ports: + - name: http + containerPort: 8443 + protocol: TCP + env: + - name: SPIKE_NEXUS_SHAMIR_SHARES + value: {{ .Values.shamir.shares | quote }} + - name: SPIKE_NEXUS_SHAMIR_THRESHOLD + value: {{ .Values.shamir.threshold | quote }} + # Note: IP will depend on the testbed. + - name: SPIKE_NEXUS_KEEPER_PEERS + {{- if gt (len .Values.keeperPeers) 0 }} + value: {{ .Values.keeperPeers | join "," | quote }} + {{- else }} + value: https://{{ .Release.Name }}-spike-keeper-0.{{ .Release.Name }}-spike-keeper-headless:8443,https://{{ .Release.Name }}-spike-keeper-1.{{ .Release.Name }}-spike-keeper-headless:8443,https://{{ .Release.Name }}-spike-keeper-2.{{ .Release.Name }}-spike-keeper-headless:8443 + {{- end }} + - name: SPIFFE_ENDPOINT_SOCKET + value: unix://{{ include "spike-nexus.workload-api-socket-path" . }} + - name: SPIKE_SYSTEM_LOG_LEVEL + value: {{ .Values.logLevel | upper }} + - name: SPIKE_TRUST_ROOT + value: {{ include "spire-lib.trust-domain" . }} + - name: SPIKE_TRUST_ROOT_KEEPER + value: {{ if gt (len .Values.trustRoot.keepers) 0 }}{{ .Values.trustRoot.keepers | join "," | quote}}{{ else }}{{ include "spire-lib.trust-domain" . }}{{ end }} + - name: SPIKE_TRUST_ROOT_PILOT + value: {{if eq .Values.trustRoot.pilot "" }}{{ include "spire-lib.trust-domain" . }}{{ else }}{{.Values.trustRoot.pilot }}{{ end }} + - name: SPIKE_NEXUS_TLS_PORT + value: ":8443" + {{- if .Values.startupProbe.enabled }} + startupProbe: + tcpSocket: + port: 8443 + failureThreshold: {{ .Values.startupProbe.failureThreshold }} + initialDelaySeconds: {{ .Values.startupProbe.initialDelaySeconds }} + periodSeconds: {{ .Values.startupProbe.periodSeconds }} + successThreshold: {{ .Values.startupProbe.successThreshold }} + timeoutSeconds: {{ .Values.startupProbe.timeoutSeconds }} + {{- end }} + volumeMounts: + - name: spiffe-workload-api + mountPath: {{ include "spike-nexus.workload-api-socket-path" . | dir }} + readOnly: true + - name: nexus-data + mountPath: /.spike + {{- with .Values.nodeSelector }} + + nodeSelector: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.tolerations }} + tolerations: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.topologySpreadConstraints }} + topologySpreadConstraints: + {{- toYaml . | nindent 8 }} + {{- end }} + volumes: + - name: spiffe-workload-api + csi: + driver: "{{ .Values.csiDriverName }}" + readOnly: true + volumeClaimTemplates: + - metadata: + name: nexus-data + spec: + accessModes: + - {{ .Values.persistence.accessMode | default "ReadWriteOnce" }} + resources: + requests: + storage: {{ .Values.persistence.size }} + {{- $storageClass := (dig "spire" "persistence" "storageClass" nil .Values.global) | default .Values.persistence.storageClass }} + {{- if $storageClass }} + storageClassName: {{ $storageClass }} + {{- end }} diff --git a/charts/spire/charts/spike-nexus/values.yaml b/charts/spire/charts/spike-nexus/values.yaml new file mode 100644 index 0000000..4d51f78 --- /dev/null +++ b/charts/spire/charts/spike-nexus/values.yaml @@ -0,0 +1,172 @@ +# Default configuration for SPIKE Keeper +# SPDX-License-Identifier: APACHE-2.0 + +## @skip global +global: {} + +## @section Chart parameters +## +## @param image.registry The OCI registry to pull the image from +## @param image.repository The repository within the registry +## @param image.pullPolicy The image pull policy +## @param image.tag Overrides the image tag whose default is the chart appVersion +## +image: + registry: ghcr.io + repository: spiffe/spike-nexus + pullPolicy: IfNotPresent + tag: "" + +## @param replicas The number of keepers to launch +replicas: 1 + +shamir: + ## @param shamir.shares How many shares to configure for shamir secrets + shares: 3 + ## @param shamir.threshold How many shares needed to recover + threshold: 2 + +## @param keeperPeers Keeper peer configuration. If blank, it will be autodetected +keeperPeers: [] + +trustRoot: + ## @param trustRoot.nexus Override which trustRoot Nexus is in + nexus: "" + ## @param trustRoot.keepers Override which trustRoot Keepers are in + keepers: [] + ## @param trustRoot.pilot Override which trustRoot Pilot is in + pilot: "" + +## @param logLevel The log level, valid values are "debug", "info", "warn", and "error" +logLevel: debug + +## @param agentSocketName The name of the spire-agent unix socket +agentSocketName: spire-agent.sock +## @param csiDriverName The csi driver to use +csiDriverName: csi.spiffe.io + +## @param imagePullSecrets [array] Pull secrets for images +imagePullSecrets: [] + +## @param nameOverride Name override +nameOverride: "" + +## @param namespaceOverride Namespace override +namespaceOverride: "" + +## @param fullnameOverride Fullname override +fullnameOverride: "" + +## @param serviceAccount.create Specifies whether a service account should be created +## @param serviceAccount.annotations [object] Annotations to add to the service account +## @param serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated. +## +serviceAccount: + create: true + annotations: {} + name: "" + +## @param labels [object] Labels for pods +labels: {} + +## @param podSecurityContext [object] Pod security context +podSecurityContext: {} + # fsGroup: 2000 + +## @param securityContext [object] Security context +securityContext: + # capabilities: + # drop: + # - ALL + # readOnlyRootFilesystem: true + runAsNonRoot: true + runAsUser: 1000 + +## @param service.type Service type +## @param service.port Service port +## @param service.annotations Annotations for service resource +## +service: + type: ClusterIP + port: 443 + annotations: {} + +## @param nodeSelector (Optional) Select specific nodes to run on. +nodeSelector: {} + +## @param affinity [object] Affinity rules +affinity: {} + +## @param tolerations [array] List of tolerations +tolerations: [] + +## @param topologySpreadConstraints [array] List of topology spread constraints for resilience +topologySpreadConstraints: [] + +## Provide minimal resources to prevent accidental crashes due to resource exhaustion +# resources: +# requests: +# cpu: 50m +# memory: 128Mi +# limits: +# cpu: 100m +# memory: 512Mi + +## Configure extra options for startup probe +## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-startup-probes +## @param startupProbe.enabled Enable startupProbe +## @param startupProbe.initialDelaySeconds Initial delay seconds for startupProbe +## @param startupProbe.periodSeconds Period seconds for startupProbe +## @param startupProbe.timeoutSeconds Timeout seconds for startupProbe +## @param startupProbe.failureThreshold Failure threshold count for startupProbe +## @param startupProbe.successThreshold Success threshold count for startupProbe +## +startupProbe: + enabled: true + initialDelaySeconds: 5 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 6 + successThreshold: 1 + +## @param ingress.enabled Flag to enable ingress +## @param ingress.className Ingress class name +## @param ingress.controllerType Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. +## @param ingress.annotations [object] Annotations +ingress: + enabled: false + className: "" + controllerType: "" + annotations: {} + + ## @param ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. + host: "nexus" + + ## @param ingress.tlsSecret Secret that has the certs. If blank will use default certs. Used with host var. + tlsSecret: "" + + ## @param ingress.hosts [array] Host paths for ingress object. If empty, rules will be built based on the host var. + hosts: [] + # - host: nexus.example.org + # paths: + # - path: / + # pathType: Prefix + + ## @param ingress.tls [array] Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. + tls: [] + # - secretName: chart-example-tls + # hosts: + # - nexus.example.org + +## @param persistence.type What type of volume to use for persistence. Valid options pvc (recommended), hostPath, emptyDir (testing only) +## @param persistence.size What size volume to use for persistence +## @param persistence.accessMode What access mode to use for persistence. Valid options are ReadWriteOnce (recommended), ReadWriteOncePod, ReadWriteMany (not recommended) +## @param persistence.storageClass What storage class to use for persistence +## @param persistence.hostPath Which path to use on the host when persistence.type = hostPath +## +persistence: + type: pvc + size: 1Gi + accessMode: ReadWriteOnce + storageClass: null + hostPath: "" diff --git a/charts/spire/charts/spike-pilot/Chart.yaml b/charts/spire/charts/spike-pilot/Chart.yaml new file mode 100644 index 0000000..34c265a --- /dev/null +++ b/charts/spire/charts/spike-pilot/Chart.yaml @@ -0,0 +1,13 @@ +apiVersion: v2 +name: spike-pilot +description: A Helm chart to deploy SPIKE Pilot +type: application +version: 0.1.0 +appVersion: "0.4.1" +home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire +sources: + - https://github.com/spiffe/spike +icon: https://spike.ist/assets/spike-banner.png +maintainers: + - name: kfox1111 + email: Kevin.Fox@pnnl.gov diff --git a/charts/spire/charts/spike-pilot/README.md b/charts/spire/charts/spike-pilot/README.md new file mode 100644 index 0000000..0bc3b31 --- /dev/null +++ b/charts/spire/charts/spike-pilot/README.md @@ -0,0 +1,63 @@ +# spike-pilot + +![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v0.4.1](https://img.shields.io/badge/AppVersion-v0.4.1-informational?style=flat-square) +[![Development Phase](https://github.com/spiffe/spiffe/blob/main/.img/maturity/dev.svg)](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development) + +A Helm chart to deploy spike pilot + +**Homepage:** + +## Version support + +> [!Note] +> This Chart is still in development and still subject to change the API (`values.yaml`). +> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although +> we do aim for as much stability as possible. + +| Dependency | Supported Versions | +|:-----------|:-------------------| +| Helm | `3.x` | + +## Source Code + +* + + + +## Parameters + +### Chart parameters + +| Name | Description | Value | +| -------------------------------- | ------------------------------------------------------------------------------------------- | -------------------- | +| `image.registry` | The OCI registry to pull the image from | `ghcr.io` | +| `image.repository` | The repository within the registry | `spiffe/spike-pilot` | +| `image.pullPolicy` | The image pull policy | `IfNotPresent` | +| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` | +| `shell.image.registry` | The OCI registry to pull the image from | `""` | +| `shell.image.repository` | The repository within the registry | `busybox` | +| `shell.image.pullPolicy` | The image pull policy | `IfNotPresent` | +| `shell.image.tag` | Overrides the image tag whose default is the chart appVersion | `1.37.0-uclibc` | +| `tools.busybox.image.registry` | The OCI registry to pull the image from | `""` | +| `tools.busybox.image.repository` | The repository within the registry | `busybox` | +| `tools.busybox.image.pullPolicy` | The image pull policy | `IfNotPresent` | +| `tools.busybox.image.tag` | Overrides the image tag whose default is the chart appVersion | `1.37.0-uclibc` | +| `replicas` | The number of keepers to launch | `1` | +| `trustRoot.nexus` | Override which trustRoot Nexus is in | `""` | +| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `debug` | +| `agentSocketName` | The name of the spire-agent unix socket | `spire-agent.sock` | +| `csiDriverName` | The csi driver to use | `csi.spiffe.io` | +| `imagePullSecrets` | Pull secrets for images | `[]` | +| `nameOverride` | Name override | `""` | +| `namespaceOverride` | Namespace override | `""` | +| `fullnameOverride` | Fullname override | `""` | +| `serviceAccount.create` | Specifies whether a service account should be created | `true` | +| `serviceAccount.annotations` | Annotations to add to the service account | `{}` | +| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` | +| `labels` | Labels for pods | `{}` | +| `podSecurityContext` | Pod security context | `{}` | +| `securityContext` | Security context | `{}` | +| `nodeSelector` | (Optional) Select specific nodes to run on. | `{}` | +| `affinity` | Affinity rules | `{}` | +| `tolerations` | List of tolerations | `[]` | +| `topologySpreadConstraints` | List of topology spread constraints for resilience | `[]` | diff --git a/charts/spire/charts/spike-pilot/templates/NOTES.txt b/charts/spire/charts/spike-pilot/templates/NOTES.txt new file mode 100644 index 0000000..dfe3e24 --- /dev/null +++ b/charts/spire/charts/spike-pilot/templates/NOTES.txt @@ -0,0 +1 @@ +Installed {{ .Chart.Name }}… diff --git a/charts/spire/charts/spike-pilot/templates/_helpers.tpl b/charts/spire/charts/spike-pilot/templates/_helpers.tpl new file mode 100644 index 0000000..899776d --- /dev/null +++ b/charts/spire/charts/spike-pilot/templates/_helpers.tpl @@ -0,0 +1,83 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "spike-pilot.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "spike-pilot.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Allow the release namespace to be overridden for multi-namespace deployments in combined charts +*/}} +{{- define "spike-pilot.namespace" -}} + {{- if .Values.namespaceOverride -}} + {{- .Values.namespaceOverride -}} + {{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }} + {{- if ne (len (dig "spire" "namespaces" "server" "name" "" .Values.global)) 0 }} + {{- .Values.global.spire.namespaces.server.name }} + {{- else }} + {{- printf "spire-server" }} + {{- end }} + {{- else -}} + {{- .Release.Namespace -}} + {{- end -}} +{{- end -}} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "spike-pilot.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "spike-pilot.labels" -}} +helm.sh/chart: {{ include "spike-pilot.chart" . }} +{{ include "spike-pilot.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "spike-pilot.selectorLabels" -}} +app.kubernetes.io/name: {{ include "spike-pilot.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} + +{{/* +Create the name of the service account to use +*/}} +{{- define "spike-pilot.serviceAccountName" -}} +{{- if .Values.serviceAccount.create }} +{{- default (include "spike-pilot.fullname" .) .Values.serviceAccount.name }} +{{- else }} +{{- default "default" .Values.serviceAccount.name }} +{{- end }} +{{- end }} + +{{- define "spike-pilot.workload-api-socket-path" -}} +{{- printf "/spiffe-workload-api/%s" .Values.agentSocketName }} +{{- end }} diff --git a/charts/spire/charts/spike-pilot/templates/deployment.yaml b/charts/spire/charts/spike-pilot/templates/deployment.yaml new file mode 100644 index 0000000..0c0958a --- /dev/null +++ b/charts/spire/charts/spike-pilot/templates/deployment.yaml @@ -0,0 +1,96 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "spike-pilot.fullname" . }} + namespace: {{ include "spike-pilot.namespace" . }} + labels: + {{- include "spike-pilot.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicas }} + selector: + matchLabels: + {{- include "spike-pilot.selectorLabels" . | nindent 6 }} + template: + metadata: + labels: + {{- include "spike-pilot.selectorLabels" . | nindent 8 }} + release: {{ .Release.Name }} + release-namespace: {{ .Release.Namespace }} + component: spike-pilot + spec: + {{- with .Values.imagePullSecrets }} + imagePullSecrets: + {{- toYaml . | nindent 8 }} + {{- end }} + serviceAccountName: {{ include "spike-pilot.serviceAccountName" . }} + securityContext: + {{- include "spire-lib.podsecuritycontext" . | nindent 8 }} + initContainers: + - name: init + image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.tools.busybox.image "global" .Values.global "ubi" true) }} + imagePullPolicy: {{ .Values.tools.busybox.image.pullPolicy }} + command: ["/bin/sh", "-c", "cp -a /bin/busybox /data"] + securityContext: + {{- include "spire-lib.securitycontext" . | nindent 12 }} + volumeMounts: + - name: pilot + mountPath: /data + - name: init2 + image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image "global" .Values.global "ubi" true) }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: ["/data/busybox", "sh", "-c", "/data/busybox cp -a /usr/local/bin/spike /data && /data/busybox rm -f /data/busybox"] + securityContext: + {{- include "spire-lib.securitycontext" . | nindent 12 }} + volumeMounts: + - name: pilot + mountPath: /data + containers: + - name: {{ include "spike-pilot.fullname" . }} + image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.shell.image "global" .Values.global "ubi" true) }} + imagePullPolicy: {{ .Values.shell.image.pullPolicy }} + command: ["/bin/sh", "-c", "echo I live; while true; do sleep 1000; done"] + securityContext: + {{- include "spire-lib.securitycontext" . | nindent 12 }} + env: + #FIXME make this configurable + - name: SPIKE_NEXUS_API_URL + value: https://{{ .Release.Name }}-spike-nexus:443 + - name: SPIFFE_ENDPOINT_SOCKET + value: unix://{{ include "spike-pilot.workload-api-socket-path" . }} + - name: SPIKE_SYSTEM_LOG_LEVEL + value: {{ .Values.logLevel | upper }} + - name: SPIKE_TRUST_ROOT + value: {{ include "spire-lib.trust-domain" . }} + - name: SPIKE_TRUST_ROOT_NEXUS + value: {{if eq .Values.trustRoot.Nexus "" }}{{ include "spire-lib.trust-domain" . }}{{ else }}{{.Values.trustRoot.Nexus }}{{ end }} + volumeMounts: + - name: spiffe-workload-api + mountPath: {{ include "spike-pilot.workload-api-socket-path" . | dir }} + readOnly: true + - name: pilot + mountPath: /bin/spike + subPath: spike + readOnly: true + {{- with .Values.nodeSelector }} + nodeSelector: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.tolerations }} + tolerations: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.topologySpreadConstraints }} + topologySpreadConstraints: + {{- toYaml . | nindent 8 }} + {{- end }} + volumes: + - name: pilot + emptyDir: {} + - name: spiffe-workload-api + csi: + driver: "{{ .Values.csiDriverName }}" + readOnly: true diff --git a/charts/spire/charts/spike-pilot/templates/serviceaccount.yaml b/charts/spire/charts/spike-pilot/templates/serviceaccount.yaml new file mode 100644 index 0000000..47daf93 --- /dev/null +++ b/charts/spire/charts/spike-pilot/templates/serviceaccount.yaml @@ -0,0 +1,13 @@ +{{- if .Values.serviceAccount.create -}} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ include "spike-pilot.serviceAccountName" . }} + namespace: {{ include "spike-pilot.namespace" . }} + labels: + {{- include "spike-pilot.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +{{- end }} diff --git a/charts/spire/charts/spike-pilot/values.yaml b/charts/spire/charts/spike-pilot/values.yaml new file mode 100644 index 0000000..6bf2310 --- /dev/null +++ b/charts/spire/charts/spike-pilot/values.yaml @@ -0,0 +1,116 @@ +# Default configuration for SPIKE Keeper +# SPDX-License-Identifier: APACHE-2.0 + +## @skip global +global: {} + +## @section Chart parameters +## +## @param image.registry The OCI registry to pull the image from +## @param image.repository The repository within the registry +## @param image.pullPolicy The image pull policy +## @param image.tag Overrides the image tag whose default is the chart appVersion +## +image: + registry: ghcr.io + repository: spiffe/spike-pilot + pullPolicy: IfNotPresent + tag: "" + +shell: + ## @param shell.image.registry The OCI registry to pull the image from + ## @param shell.image.repository The repository within the registry + ## @param shell.image.pullPolicy The image pull policy + ## @param shell.image.tag Overrides the image tag whose default is the chart appVersion + ## + image: + registry: "" + repository: busybox + pullPolicy: IfNotPresent + tag: 1.37.0-uclibc + +tools: + busybox: + ## @param tools.busybox.image.registry The OCI registry to pull the image from + ## @param tools.busybox.image.repository The repository within the registry + ## @param tools.busybox.image.pullPolicy The image pull policy + ## @param tools.busybox.image.tag Overrides the image tag whose default is the chart appVersion + ## + image: + registry: "" + repository: busybox + pullPolicy: IfNotPresent + tag: 1.37.0-uclibc + +## @param replicas The number of keepers to launch +replicas: 1 + +trustRoot: + ## @param trustRoot.nexus Override which trustRoot Nexus is in + nexus: "" + +## @param logLevel The log level, valid values are "debug", "info", "warn", and "error" +logLevel: debug + +## @param agentSocketName The name of the spire-agent unix socket +agentSocketName: spire-agent.sock +## @param csiDriverName The csi driver to use +csiDriverName: csi.spiffe.io + +## @param imagePullSecrets [array] Pull secrets for images +imagePullSecrets: [] + +## @param nameOverride Name override +nameOverride: "" + +## @param namespaceOverride Namespace override +namespaceOverride: "" + +## @param fullnameOverride Fullname override +fullnameOverride: "" + +## @param serviceAccount.create Specifies whether a service account should be created +## @param serviceAccount.annotations [object] Annotations to add to the service account +## @param serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated. +## +serviceAccount: + create: true + annotations: {} + name: "" + +## @param labels [object] Labels for pods +labels: {} + +## @param podSecurityContext [object] Pod security context +podSecurityContext: {} + # fsGroup: 2000 + +## @param securityContext [object] Security context +securityContext: {} + # capabilities: + # drop: + # - ALL + # readOnlyRootFilesystem: true + # runAsNonRoot: true + # runAsUser: 1000 + +## @param nodeSelector (Optional) Select specific nodes to run on. +nodeSelector: {} + +## @param affinity [object] Affinity rules +affinity: {} + +## @param tolerations [array] List of tolerations +tolerations: [] + +## @param topologySpreadConstraints [array] List of topology spread constraints for resilience +topologySpreadConstraints: [] + +## Provide minimal resources to prevent accidental crashes due to resource exhaustion +# resources: +# requests: +# cpu: 50m +# memory: 128Mi +# limits: +# cpu: 100m +# memory: 512Mi diff --git a/charts/spire/charts/spire-server/README.md b/charts/spire/charts/spire-server/README.md index 172716a..717b1ae 100644 --- a/charts/spire/charts/spire-server/README.md +++ b/charts/spire/charts/spire-server/README.md @@ -311,6 +311,15 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr | `controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.dnsNameTemplates` | DNS name template for issued identities | `[]` | | `controllerManager.identities.clusterSPIFFEIDs.test-keys.enabled` | Enable this identity for controller manager | `true` | | `controllerManager.identities.clusterSPIFFEIDs.test-keys.type` | The type of rule this is. | `test-keys` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.enabled` | Enable this identity for controller manager | `true` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.type` | The type of rule this is. | `spike-keeper` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/keeper` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.enabled` | Enable this identity for controller manager | `true` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.type` | The type of rule this is. | `spike-nexus` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/nexus` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.enabled` | Enable this identity for controller manager | `true` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.type` | The type of rule this is. | `spike-pilot` | +| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/pilot/role/superuser` | | `controllerManager.identities.clusterStaticEntries` | Specify ClusterStaticEntry objects. | `{}` | | `controllerManager.identities.clusterFederatedTrustDomains` | Specify ClusterFederatedTrustDomain objects. | `{}` | | `controllerManager.validatingWebhookConfiguration.enabled` | Disable only when you have another chart instance on the k8s cluster with webhooks enabled. | `true` | diff --git a/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml b/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml index f16c4de..26027a8 100644 --- a/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml +++ b/charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml @@ -17,6 +17,21 @@ matchLabels: release: {{ .Release.Name }} release-namespace: {{ .Release.Namespace }} component: oidc-discovery-provider +{{- else if eq .type "spike-keeper" }} +matchLabels: + release: {{ .Release.Name }} + release-namespace: {{ .Release.Namespace }} + component: spike-keeper +{{- else if eq .type "spike-nexus" }} +matchLabels: + release: {{ .Release.Name }} + release-namespace: {{ .Release.Namespace }} + component: spike-nexus +{{- else if eq .type "spike-pilot" }} +matchLabels: + release: {{ .Release.Name }} + release-namespace: {{ .Release.Namespace }} + component: spike-pilot {{- else if eq .type "test-keys" }} matchLabels: release: {{ .Release.Name }} @@ -38,8 +53,8 @@ matchLabels: {{- if eq ($root.Values.controllerManager.enabled | toString) "true" }} {{- if or (not (hasKey $value "enabled")) (eq ($value.enabled | toString) "true") }} {{- $type := dig "type" "base" $value }} -{{- if not (has $type (list "base" "raw" "child-servers" "oidc-discovery-provider" "test-keys")) }} -{{- fail (printf "Type given: %s, must be one of [base, raw, child-servers, oidc-discovery-provider, test-keys]" $type) }} +{{- if not (has $type (list "base" "raw" "child-servers" "oidc-discovery-provider" "spike-keeper" "spike-nexus" "spike-pilot" "test-keys")) }} +{{- fail (printf "Type given: %s, must be one of [base, raw, child-servers, oidc-discovery-provider, spike-keeper, spike-nexus, spike-pilot, test-keys]" $type) }} {{- end }} {{- $namespaceSelector := deepCopy (dig "namespaceSelector" (dict) $value) }} {{- if ne $type "raw" }} diff --git a/charts/spire/charts/spire-server/values.yaml b/charts/spire/charts/spire-server/values.yaml index fb24a49..710e2d0 100644 --- a/charts/spire/charts/spire-server/values.yaml +++ b/charts/spire/charts/spire-server/values.yaml @@ -695,6 +695,28 @@ controllerManager: ## @param controllerManager.identities.clusterSPIFFEIDs.test-keys.type The type of rule this is. type: test-keys + spike-keeper: + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-keeper.enabled Enable this identity for controller manager + enabled: true + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-keeper.type The type of rule this is. + type: spike-keeper + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-keeper.spiffeIDTemplate The template to use for this rule. + spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spike/keeper + spike-nexus: + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-nexus.enabled Enable this identity for controller manager + enabled: true + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-nexus.type The type of rule this is. + type: spike-nexus + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-nexus.spiffeIDTemplate The template to use for this rule. + spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spike/nexus + spike-pilot: + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-pilot.enabled Enable this identity for controller manager + enabled: true + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-pilot.type The type of rule this is. + type: spike-pilot + ## @param controllerManager.identities.clusterSPIFFEIDs.spike-pilot.spiffeIDTemplate The template to use for this rule. + spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spike/pilot/role/superuser + # You can specify additional ClusterSPIFFEIDs following this example: # foo: # labels: diff --git a/charts/spire/values.yaml b/charts/spire/values.yaml index bb76fee..1cff2cf 100644 --- a/charts/spire/values.yaml +++ b/charts/spire/values.yaml @@ -219,3 +219,24 @@ spiffe-oidc-discovery-provider: tornjak-frontend: ## @param tornjak-frontend.enabled Enables deployment of Tornjak frontend/UI (Not for production) enabled: false + +## @section SPIKE Keeper parameters +## Parameter values for SPIKE Keeper +## +spike-keeper: + ## @param spike-keeper.enabled Enables deployment of SPIKE Keeper (Not for production) + enabled: false + +## @section SPIKE Nexus parameters +## Parameter values for SPIKE Nexus +## +spike-nexus: + ## @param spike-nexus.enabled Enables deployment of SPIKE Nexus (Not for production) + enabled: false + +## @section SPIKE Pilot parameters +## Parameter values for SPIKE Pilot +## +spike-pilot: + ## @param spike-pilot.enabled Enables deployment of SPIKE Pilot (Not for production) + enabled: false diff --git a/examples/spike/values.yaml b/examples/spike/values.yaml new file mode 100644 index 0000000..bda38ae --- /dev/null +++ b/examples/spike/values.yaml @@ -0,0 +1,15 @@ +global: + spire: + ingressControllerType: ingress-nginx +spike-keeper: + enabled: true + #ingress: + # enabled: true + # className: nginx +spike-nexus: + enabled: true + ingress: + enabled: true + className: nginx +spike-pilot: + enabled: true