Initial spike support (#591)
* Initial spike support Signed-off-by: Kevin Fox <[email protected]> * Fix lint and docs Signed-off-by: Kevin Fox <[email protected]> * Update spike to 0.4.1 Signed-off-by: Kevin Fox <[email protected]> * Update for multiarch Signed-off-by: Kevin Fox <[email protected]> * Update Signed-off-by: Kevin Fox <[email protected]> * Fix values and docs Signed-off-by: Kevin Fox <[email protected]> * Pull in changes from Volkan Signed-off-by: Kevin Fox <[email protected]> * Fix service Signed-off-by: Kevin Fox <[email protected]> * Typo fix Signed-off-by: Volkan Özçelik <[email protected]> * Apply suggestions from code review Co-authored-by: Faisal Memon <[email protected]> Signed-off-by: kfox1111 <[email protected]> * Update docs Signed-off-by: Kevin Fox <[email protected]> --------- Signed-off-by: Kevin Fox <[email protected]> Signed-off-by: Volkan Özçelik <[email protected]> Signed-off-by: kfox1111 <[email protected]> Co-authored-by: Volkan Özçelik <[email protected]> Co-authored-by: Faisal Memon <[email protected]>
This commit is contained in:
co-authored by
Faisal Memon
Volkan Özçelik
parent
38314ed6de
commit
e78400ebcd
@@ -55,6 +55,18 @@ dependencies:
|
|||||||
condition: tornjak-frontend.enabled
|
condition: tornjak-frontend.enabled
|
||||||
repository: file://./charts/tornjak-frontend
|
repository: file://./charts/tornjak-frontend
|
||||||
version: 0.1.0
|
version: 0.1.0
|
||||||
|
- name: spike-keeper
|
||||||
|
condition: spike-keeper.enabled
|
||||||
|
repository: file://./charts/spike-keeper
|
||||||
|
version: 0.1.0
|
||||||
|
- name: spike-nexus
|
||||||
|
condition: spike-nexus.enabled
|
||||||
|
repository: file://./charts/spike-nexus
|
||||||
|
version: 0.1.0
|
||||||
|
- name: spike-pilot
|
||||||
|
condition: spike-pilot.enabled
|
||||||
|
repository: file://./charts/spike-pilot
|
||||||
|
version: 0.1.0
|
||||||
annotations:
|
annotations:
|
||||||
artifacthub.io/category: security
|
artifacthub.io/category: security
|
||||||
artifacthub.io/license: Apache-2.0
|
artifacthub.io/license: Apache-2.0
|
||||||
|
|||||||
@@ -373,3 +373,21 @@ Now you can interact with the Spire agent socket from your own application. The
|
|||||||
| Name | Description | Value |
|
| Name | Description | Value |
|
||||||
| -------------------------- | -------------------------------------------------------------- | ------- |
|
| -------------------------- | -------------------------------------------------------------- | ------- |
|
||||||
| `tornjak-frontend.enabled` | Enables deployment of Tornjak frontend/UI (Not for production) | `false` |
|
| `tornjak-frontend.enabled` | Enables deployment of Tornjak frontend/UI (Not for production) | `false` |
|
||||||
|
|
||||||
|
### SPIKE Keeper parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| ---------------------- | ------------------------------------------------------- | ------- |
|
||||||
|
| `spike-keeper.enabled` | Enables deployment of SPIKE Keeper (Not for production) | `false` |
|
||||||
|
|
||||||
|
### SPIKE Nexus parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| --------------------- | ------------------------------------------------------ | ------- |
|
||||||
|
| `spike-nexus.enabled` | Enables deployment of SPIKE Nexus (Not for production) | `false` |
|
||||||
|
|
||||||
|
### SPIKE Pilot parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| --------------------- | ------------------------------------------------------ | ------- |
|
||||||
|
| `spike-pilot.enabled` | Enables deployment of SPIKE Pilot (Not for production) | `false` |
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: spike-keeper
|
||||||
|
description: A Helm chart to deploy SPIKE Keeper
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "0.4.1"
|
||||||
|
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
|
||||||
|
sources:
|
||||||
|
- https://github.com/spiffe/spike
|
||||||
|
icon: https://spike.ist/assets/spike-banner.png
|
||||||
|
maintainers:
|
||||||
|
- name: kfox1111
|
||||||
|
email: [email protected]
|
||||||
@@ -0,0 +1,72 @@
|
|||||||
|
# spike-keeper
|
||||||
|
|
||||||
|
  
|
||||||
|
[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
|
||||||
|
|
||||||
|
A Helm chart to deploy spike keepers
|
||||||
|
|
||||||
|
**Homepage:** <https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire>
|
||||||
|
|
||||||
|
## Version support
|
||||||
|
|
||||||
|
> [!Note]
|
||||||
|
> This Chart is still in development and still subject to change the API (`values.yaml`).
|
||||||
|
> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although
|
||||||
|
> we do aim for as much stability as possible.
|
||||||
|
|
||||||
|
| Dependency | Supported Versions |
|
||||||
|
|:-----------|:-------------------|
|
||||||
|
| Helm | `3.x` |
|
||||||
|
|
||||||
|
## Source Code
|
||||||
|
|
||||||
|
* <https://github.com/spiffe/spike>
|
||||||
|
|
||||||
|
<!-- The parameters section is generated using helm-docs.sh and should not be edited by hand. -->
|
||||||
|
|
||||||
|
## Parameters
|
||||||
|
|
||||||
|
### Chart parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------- |
|
||||||
|
| `image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
||||||
|
| `image.repository` | The repository within the registry | `spiffe/spike-keeper` |
|
||||||
|
| `image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
|
| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
|
||||||
|
| `replicas` | The number of keepers to launch | `3` |
|
||||||
|
| `trustRoot.nexus` | Override which trustRoot Nexus is in | `""` |
|
||||||
|
| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `debug` |
|
||||||
|
| `agentSocketName` | The name of the spire-agent unix socket | `spire-agent.sock` |
|
||||||
|
| `csiDriverName` | The csi driver to use | `csi.spiffe.io` |
|
||||||
|
| `imagePullSecrets` | Pull secrets for images | `[]` |
|
||||||
|
| `nameOverride` | Name override | `""` |
|
||||||
|
| `namespaceOverride` | Namespace override | `""` |
|
||||||
|
| `fullnameOverride` | Fullname override | `""` |
|
||||||
|
| `serviceAccount.create` | Specifies whether a service account should be created | `true` |
|
||||||
|
| `serviceAccount.annotations` | Annotations to add to the service account | `{}` |
|
||||||
|
| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` |
|
||||||
|
| `labels` | Labels for pods | `{}` |
|
||||||
|
| `podSecurityContext` | Pod security context | `{}` |
|
||||||
|
| `securityContext` | Security context | `{}` |
|
||||||
|
| `service.type` | Service type | `ClusterIP` |
|
||||||
|
| `service.port` | Service port | `443` |
|
||||||
|
| `service.annotations` | Annotations for service resource | `{}` |
|
||||||
|
| `nodeSelector` | (Optional) Select specific nodes to run on. | `{}` |
|
||||||
|
| `affinity` | Affinity rules | `{}` |
|
||||||
|
| `tolerations` | List of tolerations | `[]` |
|
||||||
|
| `topologySpreadConstraints` | List of topology spread constraints for resilience | `[]` |
|
||||||
|
| `startupProbe.enabled` | Enable startupProbe | `true` |
|
||||||
|
| `startupProbe.initialDelaySeconds` | Initial delay seconds for startupProbe | `5` |
|
||||||
|
| `startupProbe.periodSeconds` | Period seconds for startupProbe | `10` |
|
||||||
|
| `startupProbe.timeoutSeconds` | Timeout seconds for startupProbe | `5` |
|
||||||
|
| `startupProbe.failureThreshold` | Failure threshold count for startupProbe | `6` |
|
||||||
|
| `startupProbe.successThreshold` | Success threshold count for startupProbe | `1` |
|
||||||
|
| `ingress.enabled` | Flag to enable ingress | `false` |
|
||||||
|
| `ingress.className` | Ingress class name | `""` |
|
||||||
|
| `ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` |
|
||||||
|
| `ingress.annotations` | Annotations | `{}` |
|
||||||
|
| `ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `keeper` |
|
||||||
|
| `ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` |
|
||||||
|
| `ingress.hosts` | Host paths for ingress object. If empty, rules will be built based on the host var. | `[]` |
|
||||||
|
| `ingress.tls` | Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. | `[]` |
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
Installed {{ .Chart.Name }}…
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-keeper.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-keeper.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||||
|
{{- if contains $name .Release.Name }}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Allow the release namespace to be overridden for multi-namespace deployments in combined charts
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-keeper.namespace" -}}
|
||||||
|
{{- if .Values.namespaceOverride -}}
|
||||||
|
{{- .Values.namespaceOverride -}}
|
||||||
|
{{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }}
|
||||||
|
{{- if ne (len (dig "spire" "namespaces" "server" "name" "" .Values.global)) 0 }}
|
||||||
|
{{- .Values.global.spire.namespaces.server.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "spire-server" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- else -}}
|
||||||
|
{{- .Release.Namespace -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-keeper.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-keeper.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "spike-keeper.chart" . }}
|
||||||
|
{{ include "spike-keeper.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-keeper.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "spike-keeper.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-keeper.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
{{- default (include "spike-keeper.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- define "spike-keeper.workload-api-socket-path" -}}
|
||||||
|
{{- printf "/spiffe-workload-api/%s" .Values.agentSocketName }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
{{- if .Values.ingress.enabled -}}
|
||||||
|
{{ $root := . }}
|
||||||
|
{{- $ingressControllerType := include "spire-lib.ingress-controller-type" (dict "global" .Values.global "ingress" .Values.ingress) }}
|
||||||
|
{{- $fullName := include "spike-keeper.fullname" . -}}
|
||||||
|
{{- $tlsSection := true }}
|
||||||
|
{{- $annotations := deepCopy .Values.ingress.annotations }}
|
||||||
|
{{- if eq $ingressControllerType "ingress-nginx" }}
|
||||||
|
{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-redirect" "true" }}
|
||||||
|
{{- $_ := set $annotations "nginx.ingress.kubernetes.io/force-ssl-redirect" "true" }}
|
||||||
|
{{- $_ := set $annotations "nginx.ingress.kubernetes.io/backend-protocol" "HTTPS" }}
|
||||||
|
{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-passthrough" "true" }}
|
||||||
|
{{- else if eq $ingressControllerType "openshift" }}
|
||||||
|
{{- $path = "" }}
|
||||||
|
{{- $_ := set $annotations "route.openshift.io/termination" "passthrough" }}
|
||||||
|
{{- $tlsSection = false }}
|
||||||
|
{{- end }}
|
||||||
|
{{ $last := sub (.Values.replicas | int) 1 | int }}
|
||||||
|
{{ range (seq 0 ($last) | toString | split " ") }}
|
||||||
|
{{ $i := . }}
|
||||||
|
---
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: {{ $fullName }}-{{ $i }}
|
||||||
|
namespace: {{ include "spike-keeper.namespace" $root }}
|
||||||
|
labels:
|
||||||
|
{{ include "spike-keeper.labels" $root | nindent 4}}
|
||||||
|
{{- with $annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- $host := $root.Values.ingress.host }}
|
||||||
|
{{- if contains "." $host }}
|
||||||
|
{{- $hostParts := regexSplit "[.]" $host 2 }}
|
||||||
|
{{- $host = printf "%s-%s.%s" (index $hostParts 0) $i (index $hostParts 1) }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $host = printf "%s-%s" $host $i }}
|
||||||
|
{{- end }}
|
||||||
|
{{ $ingress := deepCopy $root.Values.ingress }}
|
||||||
|
{{ $_ := set $ingress "host" $host }}
|
||||||
|
{{ include "spire-lib.ingress-spec" (dict "ingress" $ingress "svcName" (printf "%s-%s" $fullName $i) "port" $root.Values.service.port "path" "/" "pathType" "Prefix" "tlsSection" $tlsSection "Values" $root.Values) | nindent 2 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,48 @@
|
|||||||
|
{{ $root := . }}
|
||||||
|
{{ $last := sub (.Values.replicas | int) 1 | int }}
|
||||||
|
{{ range (seq 0 ($last) | toString | split " ") }}
|
||||||
|
{{ $i := . }}
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
namespace: {{ include "spike-keeper.namespace" $root }}
|
||||||
|
name: {{ include "spike-keeper.fullname" $root }}-{{ $i }}
|
||||||
|
{{- with $root.Values.service.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
apps.kubernetes.io/pod-index: {{ $i | quote }}
|
||||||
|
{{- include "spike-keeper.labels" $root | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ $root.Values.service.type }}
|
||||||
|
selector:
|
||||||
|
apps.kubernetes.io/pod-index: {{ $i | quote }}
|
||||||
|
{{- include "spike-keeper.selectorLabels" $root | nindent 4 }}
|
||||||
|
ports:
|
||||||
|
- name: {{ include "spike-keeper.fullname" $root }}
|
||||||
|
port: {{ $root.Values.service.port }}
|
||||||
|
targetPort: http
|
||||||
|
{{ end }}
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
namespace: {{ include "spike-keeper.namespace" $root }}
|
||||||
|
name: {{ include "spike-keeper.fullname" $root }}-headless
|
||||||
|
{{- with $root.Values.service.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
{{- include "spike-keeper.labels" $root | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ $root.Values.service.type }}
|
||||||
|
clusterIP: None
|
||||||
|
selector:
|
||||||
|
{{- include "spike-keeper.selectorLabels" $root | nindent 4 }}
|
||||||
|
ports:
|
||||||
|
- name: {{ include "spike-keeper.fullname" $root }}
|
||||||
|
port: {{ $root.Values.service.port }}
|
||||||
|
targetPort: http
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
{{- if .Values.serviceAccount.create -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "spike-keeper.serviceAccountName" . }}
|
||||||
|
namespace: {{ include "spike-keeper.namespace" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "spike-keeper.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.serviceAccount.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,84 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: StatefulSet
|
||||||
|
metadata:
|
||||||
|
name: {{ include "spike-keeper.fullname" . }}
|
||||||
|
namespace: {{ include "spike-keeper.namespace" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "spike-keeper.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
serviceName: {{ include "spike-keeper.fullname" . }}-headless
|
||||||
|
replicas: {{ .Values.replicas }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "spike-keeper.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
{{- include "spike-keeper.selectorLabels" . | nindent 8 }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
release-namespace: {{ .Release.Namespace }}
|
||||||
|
component: spike-keeper
|
||||||
|
spec:
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
serviceAccountName: {{ include "spike-keeper.serviceAccountName" . }}
|
||||||
|
securityContext:
|
||||||
|
{{- include "spire-lib.podsecuritycontext" . | nindent 8 }}
|
||||||
|
containers:
|
||||||
|
- name: {{ include "spike-keeper.fullname" . }}
|
||||||
|
image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image "global" .Values.global "ubi" true) }}
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
securityContext:
|
||||||
|
{{- include "spire-lib.securitycontext" . | nindent 12 }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: 8443
|
||||||
|
protocol: TCP
|
||||||
|
env:
|
||||||
|
- name: SPIFFE_ENDPOINT_SOCKET
|
||||||
|
value: unix://{{ include "spike-keeper.workload-api-socket-path" . }}
|
||||||
|
- name: SPIKE_SYSTEM_LOG_LEVEL
|
||||||
|
value: {{ .Values.logLevel | upper }}
|
||||||
|
- name: SPIKE_TRUST_ROOT
|
||||||
|
value: {{ include "spire-lib.trust-domain" . }}
|
||||||
|
- name: SPIKE_TRUST_ROOT_NEXUS
|
||||||
|
value: {{if eq .Values.trustRoot.nexus "" }}{{ include "spire-lib.trust-domain" . }}{{ else }}{{.Values.trustRoot.nexus }}{{ end }}
|
||||||
|
- name: SPIKE_KEEPER_TLS_PORT
|
||||||
|
value: ":8443"
|
||||||
|
{{- if .Values.startupProbe.enabled }}
|
||||||
|
startupProbe:
|
||||||
|
tcpSocket:
|
||||||
|
port: 8443
|
||||||
|
failureThreshold: {{ .Values.startupProbe.failureThreshold }}
|
||||||
|
initialDelaySeconds: {{ .Values.startupProbe.initialDelaySeconds }}
|
||||||
|
periodSeconds: {{ .Values.startupProbe.periodSeconds }}
|
||||||
|
successThreshold: {{ .Values.startupProbe.successThreshold }}
|
||||||
|
timeoutSeconds: {{ .Values.startupProbe.timeoutSeconds }}
|
||||||
|
{{- end }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: spiffe-workload-api
|
||||||
|
mountPath: {{ include "spike-keeper.workload-api-socket-path" . | dir }}
|
||||||
|
readOnly: true
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.topologySpreadConstraints }}
|
||||||
|
topologySpreadConstraints:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
volumes:
|
||||||
|
- name: spiffe-workload-api
|
||||||
|
csi:
|
||||||
|
driver: "{{ .Values.csiDriverName }}"
|
||||||
|
readOnly: true
|
||||||
@@ -0,0 +1,139 @@
|
|||||||
|
# Default configuration for SPIKE Keeper
|
||||||
|
# SPDX-License-Identifier: APACHE-2.0
|
||||||
|
|
||||||
|
## @skip global
|
||||||
|
global: {}
|
||||||
|
|
||||||
|
## @section Chart parameters
|
||||||
|
##
|
||||||
|
## @param image.registry The OCI registry to pull the image from
|
||||||
|
## @param image.repository The repository within the registry
|
||||||
|
## @param image.pullPolicy The image pull policy
|
||||||
|
## @param image.tag Overrides the image tag whose default is the chart appVersion
|
||||||
|
##
|
||||||
|
image:
|
||||||
|
registry: ghcr.io
|
||||||
|
repository: spiffe/spike-keeper
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
tag: ""
|
||||||
|
|
||||||
|
## @param replicas The number of keepers to launch
|
||||||
|
replicas: 3
|
||||||
|
|
||||||
|
trustRoot:
|
||||||
|
## @param trustRoot.nexus Override which trustRoot Nexus is in
|
||||||
|
nexus: ""
|
||||||
|
|
||||||
|
## @param logLevel The log level, valid values are "debug", "info", "warn", and "error"
|
||||||
|
logLevel: debug
|
||||||
|
|
||||||
|
## @param agentSocketName The name of the spire-agent unix socket
|
||||||
|
agentSocketName: spire-agent.sock
|
||||||
|
## @param csiDriverName The csi driver to use
|
||||||
|
csiDriverName: csi.spiffe.io
|
||||||
|
|
||||||
|
## @param imagePullSecrets [array] Pull secrets for images
|
||||||
|
imagePullSecrets: []
|
||||||
|
|
||||||
|
## @param nameOverride Name override
|
||||||
|
nameOverride: ""
|
||||||
|
|
||||||
|
## @param namespaceOverride Namespace override
|
||||||
|
namespaceOverride: ""
|
||||||
|
|
||||||
|
## @param fullnameOverride Fullname override
|
||||||
|
fullnameOverride: ""
|
||||||
|
|
||||||
|
## @param serviceAccount.create Specifies whether a service account should be created
|
||||||
|
## @param serviceAccount.annotations [object] Annotations to add to the service account
|
||||||
|
## @param serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated.
|
||||||
|
##
|
||||||
|
serviceAccount:
|
||||||
|
create: true
|
||||||
|
annotations: {}
|
||||||
|
name: ""
|
||||||
|
|
||||||
|
## @param labels [object] Labels for pods
|
||||||
|
labels: {}
|
||||||
|
|
||||||
|
## @param podSecurityContext [object] Pod security context
|
||||||
|
podSecurityContext: {}
|
||||||
|
# fsGroup: 2000
|
||||||
|
|
||||||
|
## @param securityContext [object] Security context
|
||||||
|
securityContext: {}
|
||||||
|
# capabilities:
|
||||||
|
# drop:
|
||||||
|
# - ALL
|
||||||
|
# readOnlyRootFilesystem: true
|
||||||
|
# runAsNonRoot: true
|
||||||
|
# runAsUser: 1000
|
||||||
|
|
||||||
|
## @param service.type Service type
|
||||||
|
## @param service.port Service port
|
||||||
|
## @param service.annotations Annotations for service resource
|
||||||
|
##
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 443
|
||||||
|
annotations: {}
|
||||||
|
|
||||||
|
## @param nodeSelector (Optional) Select specific nodes to run on.
|
||||||
|
nodeSelector: {}
|
||||||
|
|
||||||
|
## @param affinity [object] Affinity rules
|
||||||
|
affinity: {}
|
||||||
|
|
||||||
|
## @param tolerations [array] List of tolerations
|
||||||
|
tolerations: []
|
||||||
|
|
||||||
|
## @param topologySpreadConstraints [array] List of topology spread constraints for resilience
|
||||||
|
topologySpreadConstraints: []
|
||||||
|
|
||||||
|
## Provide minimal resources to prevent accidental crashes due to resource exhaustion
|
||||||
|
# resources:
|
||||||
|
# requests:
|
||||||
|
# cpu: 50m
|
||||||
|
# memory: 128Mi
|
||||||
|
# limits:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 512Mi
|
||||||
|
|
||||||
|
## Configure extra options for startup probe
|
||||||
|
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-startup-probes
|
||||||
|
## @param startupProbe.enabled Enable startupProbe
|
||||||
|
## @param startupProbe.initialDelaySeconds Initial delay seconds for startupProbe
|
||||||
|
## @param startupProbe.periodSeconds Period seconds for startupProbe
|
||||||
|
## @param startupProbe.timeoutSeconds Timeout seconds for startupProbe
|
||||||
|
## @param startupProbe.failureThreshold Failure threshold count for startupProbe
|
||||||
|
## @param startupProbe.successThreshold Success threshold count for startupProbe
|
||||||
|
##
|
||||||
|
startupProbe:
|
||||||
|
enabled: true
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
timeoutSeconds: 5
|
||||||
|
failureThreshold: 6
|
||||||
|
successThreshold: 1
|
||||||
|
|
||||||
|
## @param ingress.enabled Flag to enable ingress
|
||||||
|
## @param ingress.className Ingress class name
|
||||||
|
## @param ingress.controllerType Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""].
|
||||||
|
## @param ingress.annotations [object] Annotations
|
||||||
|
ingress:
|
||||||
|
enabled: false
|
||||||
|
className: ""
|
||||||
|
controllerType: ""
|
||||||
|
annotations: {}
|
||||||
|
|
||||||
|
## @param ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead.
|
||||||
|
host: "keeper"
|
||||||
|
|
||||||
|
## @param ingress.tlsSecret Secret that has the certs. If blank will use default certs. Used with host var.
|
||||||
|
tlsSecret: ""
|
||||||
|
|
||||||
|
## @param ingress.hosts [array] Host paths for ingress object. If empty, rules will be built based on the host var.
|
||||||
|
hosts: []
|
||||||
|
|
||||||
|
## @param ingress.tls [array] Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars.
|
||||||
|
tls: []
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: spike-nexus
|
||||||
|
description: A Helm chart to deploy SPIKE Nexus
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "0.4.1"
|
||||||
|
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
|
||||||
|
sources:
|
||||||
|
- https://github.com/spiffe/spike
|
||||||
|
icon: https://spike.ist/assets/spike-banner.png
|
||||||
|
maintainers:
|
||||||
|
- name: kfox1111
|
||||||
|
email: [email protected]
|
||||||
@@ -0,0 +1,82 @@
|
|||||||
|
# spike-nexus
|
||||||
|
|
||||||
|
  
|
||||||
|
[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
|
||||||
|
|
||||||
|
A Helm chart to deploy spike nexus
|
||||||
|
|
||||||
|
**Homepage:** <https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire>
|
||||||
|
|
||||||
|
## Version support
|
||||||
|
|
||||||
|
> [!Note]
|
||||||
|
> This Chart is still in development and still subject to change the API (`values.yaml`).
|
||||||
|
> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although
|
||||||
|
> we do aim for as much stability as possible.
|
||||||
|
|
||||||
|
| Dependency | Supported Versions |
|
||||||
|
|:-----------|:-------------------|
|
||||||
|
| Helm | `3.x` |
|
||||||
|
|
||||||
|
## Source Code
|
||||||
|
|
||||||
|
* <https://github.com/spiffe/spike>
|
||||||
|
|
||||||
|
<!-- The parameters section is generated using helm-docs.sh and should not be edited by hand. -->
|
||||||
|
|
||||||
|
## Parameters
|
||||||
|
|
||||||
|
### Chart parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------- |
|
||||||
|
| `image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
||||||
|
| `image.repository` | The repository within the registry | `spiffe/spike-nexus` |
|
||||||
|
| `image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
|
| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
|
||||||
|
| `replicas` | The number of keepers to launch | `1` |
|
||||||
|
| `shamir.shares` | How many shares to configure for shamir secrets | `3` |
|
||||||
|
| `shamir.threshold` | How many shares needed to recover | `2` |
|
||||||
|
| `keeperPeers` | Keeper peer configuration. If blank, it will be autodetected | `[]` |
|
||||||
|
| `trustRoot.nexus` | Override which trustRoot Nexus is in | `""` |
|
||||||
|
| `trustRoot.keepers` | Override which trustRoot Keepers are in | `[]` |
|
||||||
|
| `trustRoot.pilot` | Override which trustRoot Pilot is in | `""` |
|
||||||
|
| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `debug` |
|
||||||
|
| `agentSocketName` | The name of the spire-agent unix socket | `spire-agent.sock` |
|
||||||
|
| `csiDriverName` | The csi driver to use | `csi.spiffe.io` |
|
||||||
|
| `imagePullSecrets` | Pull secrets for images | `[]` |
|
||||||
|
| `nameOverride` | Name override | `""` |
|
||||||
|
| `namespaceOverride` | Namespace override | `""` |
|
||||||
|
| `fullnameOverride` | Fullname override | `""` |
|
||||||
|
| `serviceAccount.create` | Specifies whether a service account should be created | `true` |
|
||||||
|
| `serviceAccount.annotations` | Annotations to add to the service account | `{}` |
|
||||||
|
| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` |
|
||||||
|
| `labels` | Labels for pods | `{}` |
|
||||||
|
| `podSecurityContext` | Pod security context | `{}` |
|
||||||
|
| `securityContext` | Security context | `{}` |
|
||||||
|
| `service.type` | Service type | `ClusterIP` |
|
||||||
|
| `service.port` | Service port | `443` |
|
||||||
|
| `service.annotations` | Annotations for service resource | `{}` |
|
||||||
|
| `nodeSelector` | (Optional) Select specific nodes to run on. | `{}` |
|
||||||
|
| `affinity` | Affinity rules | `{}` |
|
||||||
|
| `tolerations` | List of tolerations | `[]` |
|
||||||
|
| `topologySpreadConstraints` | List of topology spread constraints for resilience | `[]` |
|
||||||
|
| `startupProbe.enabled` | Enable startupProbe | `true` |
|
||||||
|
| `startupProbe.initialDelaySeconds` | Initial delay seconds for startupProbe | `5` |
|
||||||
|
| `startupProbe.periodSeconds` | Period seconds for startupProbe | `10` |
|
||||||
|
| `startupProbe.timeoutSeconds` | Timeout seconds for startupProbe | `5` |
|
||||||
|
| `startupProbe.failureThreshold` | Failure threshold count for startupProbe | `6` |
|
||||||
|
| `startupProbe.successThreshold` | Success threshold count for startupProbe | `1` |
|
||||||
|
| `ingress.enabled` | Flag to enable ingress | `false` |
|
||||||
|
| `ingress.className` | Ingress class name | `""` |
|
||||||
|
| `ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` |
|
||||||
|
| `ingress.annotations` | Annotations | `{}` |
|
||||||
|
| `ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `nexus` |
|
||||||
|
| `ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` |
|
||||||
|
| `ingress.hosts` | Host paths for ingress object. If empty, rules will be built based on the host var. | `[]` |
|
||||||
|
| `ingress.tls` | Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. | `[]` |
|
||||||
|
| `persistence.type` | What type of volume to use for persistence. Valid options pvc (recommended), hostPath, emptyDir (testing only) | `pvc` |
|
||||||
|
| `persistence.size` | What size volume to use for persistence | `1Gi` |
|
||||||
|
| `persistence.accessMode` | What access mode to use for persistence. Valid options are ReadWriteOnce (recommended), ReadWriteOncePod, ReadWriteMany (not recommended) | `ReadWriteOnce` |
|
||||||
|
| `persistence.storageClass` | What storage class to use for persistence | `nil` |
|
||||||
|
| `persistence.hostPath` | Which path to use on the host when persistence.type = hostPath | `""` |
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
Installed {{ .Chart.Name }}…
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-nexus.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-nexus.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||||
|
{{- if contains $name .Release.Name }}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Allow the release namespace to be overridden for multi-namespace deployments in combined charts
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-nexus.namespace" -}}
|
||||||
|
{{- if .Values.namespaceOverride -}}
|
||||||
|
{{- .Values.namespaceOverride -}}
|
||||||
|
{{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }}
|
||||||
|
{{- if ne (len (dig "spire" "namespaces" "server" "name" "" .Values.global)) 0 }}
|
||||||
|
{{- .Values.global.spire.namespaces.server.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "spire-server" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- else -}}
|
||||||
|
{{- .Release.Namespace -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-nexus.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-nexus.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "spike-nexus.chart" . }}
|
||||||
|
{{ include "spike-nexus.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-nexus.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "spike-nexus.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-nexus.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
{{- default (include "spike-nexus.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- define "spike-nexus.workload-api-socket-path" -}}
|
||||||
|
{{- printf "/spiffe-workload-api/%s" .Values.agentSocketName }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
{{- if .Values.ingress.enabled -}}
|
||||||
|
{{ $root := . }}
|
||||||
|
{{- $ingressControllerType := include "spire-lib.ingress-controller-type" (dict "global" .Values.global "ingress" .Values.ingress) }}
|
||||||
|
{{- $fullName := include "spike-nexus.fullname" . -}}
|
||||||
|
{{- $tlsSection := true }}
|
||||||
|
{{- $annotations := deepCopy .Values.ingress.annotations }}
|
||||||
|
{{- if eq $ingressControllerType "ingress-nginx" }}
|
||||||
|
{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-redirect" "true" }}
|
||||||
|
{{- $_ := set $annotations "nginx.ingress.kubernetes.io/force-ssl-redirect" "true" }}
|
||||||
|
{{- $_ := set $annotations "nginx.ingress.kubernetes.io/backend-protocol" "HTTPS" }}
|
||||||
|
{{- $_ := set $annotations "nginx.ingress.kubernetes.io/ssl-passthrough" "true" }}
|
||||||
|
{{- else if eq $ingressControllerType "openshift" }}
|
||||||
|
{{- $path = "" }}
|
||||||
|
{{- $_ := set $annotations "route.openshift.io/termination" "passthrough" }}
|
||||||
|
{{- $tlsSection = false }}
|
||||||
|
{{- end }}
|
||||||
|
{{ $last := sub (.Values.replicas | int) 1 | int }}
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: {{ $fullName }}
|
||||||
|
namespace: {{ include "spike-nexus.namespace" $root }}
|
||||||
|
labels:
|
||||||
|
{{ include "spike-nexus.labels" $root | nindent 4}}
|
||||||
|
{{- with $annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{ include "spire-lib.ingress-spec" (dict "ingress" .Values.ingress "svcName" $fullName "port" $root.Values.service.port "path" "/" "pathType" "Prefix" "tlsSection" $tlsSection "Values" $root.Values) | nindent 2 }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
{{ $root := . }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
namespace: {{ include "spike-nexus.namespace" $root }}
|
||||||
|
name: {{ include "spike-nexus.fullname" $root }}
|
||||||
|
{{- with $root.Values.service.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
{{- include "spike-nexus.labels" $root | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ $root.Values.service.type }}
|
||||||
|
selector:
|
||||||
|
{{- include "spike-nexus.selectorLabels" $root | nindent 4 }}
|
||||||
|
ports:
|
||||||
|
- name: {{ include "spike-nexus.fullname" $root }}
|
||||||
|
port: {{ $root.Values.service.port }}
|
||||||
|
targetPort: http
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
{{- if .Values.serviceAccount.create -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "spike-nexus.serviceAccountName" . }}
|
||||||
|
namespace: {{ include "spike-nexus.namespace" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "spike-nexus.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.serviceAccount.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,112 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: StatefulSet
|
||||||
|
metadata:
|
||||||
|
name: {{ include "spike-nexus.fullname" . }}
|
||||||
|
namespace: {{ include "spike-nexus.namespace" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "spike-nexus.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicas }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "spike-nexus.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
{{- include "spike-nexus.selectorLabels" . | nindent 8 }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
release-namespace: {{ .Release.Namespace }}
|
||||||
|
component: spike-nexus
|
||||||
|
spec:
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
serviceAccountName: {{ include "spike-nexus.serviceAccountName" . }}
|
||||||
|
securityContext:
|
||||||
|
{{- include "spire-lib.podsecuritycontext" . | nindent 8 }}
|
||||||
|
containers:
|
||||||
|
- name: {{ include "spike-nexus.fullname" . }}
|
||||||
|
image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image "global" .Values.global "ubi" true) }}
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
securityContext:
|
||||||
|
{{- include "spire-lib.securitycontext" . | nindent 12 }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: 8443
|
||||||
|
protocol: TCP
|
||||||
|
env:
|
||||||
|
- name: SPIKE_NEXUS_SHAMIR_SHARES
|
||||||
|
value: {{ .Values.shamir.shares | quote }}
|
||||||
|
- name: SPIKE_NEXUS_SHAMIR_THRESHOLD
|
||||||
|
value: {{ .Values.shamir.threshold | quote }}
|
||||||
|
# Note: IP will depend on the testbed.
|
||||||
|
- name: SPIKE_NEXUS_KEEPER_PEERS
|
||||||
|
{{- if gt (len .Values.keeperPeers) 0 }}
|
||||||
|
value: {{ .Values.keeperPeers | join "," | quote }}
|
||||||
|
{{- else }}
|
||||||
|
value: https://{{ .Release.Name }}-spike-keeper-0.{{ .Release.Name }}-spike-keeper-headless:8443,https://{{ .Release.Name }}-spike-keeper-1.{{ .Release.Name }}-spike-keeper-headless:8443,https://{{ .Release.Name }}-spike-keeper-2.{{ .Release.Name }}-spike-keeper-headless:8443
|
||||||
|
{{- end }}
|
||||||
|
- name: SPIFFE_ENDPOINT_SOCKET
|
||||||
|
value: unix://{{ include "spike-nexus.workload-api-socket-path" . }}
|
||||||
|
- name: SPIKE_SYSTEM_LOG_LEVEL
|
||||||
|
value: {{ .Values.logLevel | upper }}
|
||||||
|
- name: SPIKE_TRUST_ROOT
|
||||||
|
value: {{ include "spire-lib.trust-domain" . }}
|
||||||
|
- name: SPIKE_TRUST_ROOT_KEEPER
|
||||||
|
value: {{ if gt (len .Values.trustRoot.keepers) 0 }}{{ .Values.trustRoot.keepers | join "," | quote}}{{ else }}{{ include "spire-lib.trust-domain" . }}{{ end }}
|
||||||
|
- name: SPIKE_TRUST_ROOT_PILOT
|
||||||
|
value: {{if eq .Values.trustRoot.pilot "" }}{{ include "spire-lib.trust-domain" . }}{{ else }}{{.Values.trustRoot.pilot }}{{ end }}
|
||||||
|
- name: SPIKE_NEXUS_TLS_PORT
|
||||||
|
value: ":8443"
|
||||||
|
{{- if .Values.startupProbe.enabled }}
|
||||||
|
startupProbe:
|
||||||
|
tcpSocket:
|
||||||
|
port: 8443
|
||||||
|
failureThreshold: {{ .Values.startupProbe.failureThreshold }}
|
||||||
|
initialDelaySeconds: {{ .Values.startupProbe.initialDelaySeconds }}
|
||||||
|
periodSeconds: {{ .Values.startupProbe.periodSeconds }}
|
||||||
|
successThreshold: {{ .Values.startupProbe.successThreshold }}
|
||||||
|
timeoutSeconds: {{ .Values.startupProbe.timeoutSeconds }}
|
||||||
|
{{- end }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: spiffe-workload-api
|
||||||
|
mountPath: {{ include "spike-nexus.workload-api-socket-path" . | dir }}
|
||||||
|
readOnly: true
|
||||||
|
- name: nexus-data
|
||||||
|
mountPath: /.spike
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.topologySpreadConstraints }}
|
||||||
|
topologySpreadConstraints:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
volumes:
|
||||||
|
- name: spiffe-workload-api
|
||||||
|
csi:
|
||||||
|
driver: "{{ .Values.csiDriverName }}"
|
||||||
|
readOnly: true
|
||||||
|
volumeClaimTemplates:
|
||||||
|
- metadata:
|
||||||
|
name: nexus-data
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- {{ .Values.persistence.accessMode | default "ReadWriteOnce" }}
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: {{ .Values.persistence.size }}
|
||||||
|
{{- $storageClass := (dig "spire" "persistence" "storageClass" nil .Values.global) | default .Values.persistence.storageClass }}
|
||||||
|
{{- if $storageClass }}
|
||||||
|
storageClassName: {{ $storageClass }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,172 @@
|
|||||||
|
# Default configuration for SPIKE Keeper
|
||||||
|
# SPDX-License-Identifier: APACHE-2.0
|
||||||
|
|
||||||
|
## @skip global
|
||||||
|
global: {}
|
||||||
|
|
||||||
|
## @section Chart parameters
|
||||||
|
##
|
||||||
|
## @param image.registry The OCI registry to pull the image from
|
||||||
|
## @param image.repository The repository within the registry
|
||||||
|
## @param image.pullPolicy The image pull policy
|
||||||
|
## @param image.tag Overrides the image tag whose default is the chart appVersion
|
||||||
|
##
|
||||||
|
image:
|
||||||
|
registry: ghcr.io
|
||||||
|
repository: spiffe/spike-nexus
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
tag: ""
|
||||||
|
|
||||||
|
## @param replicas The number of keepers to launch
|
||||||
|
replicas: 1
|
||||||
|
|
||||||
|
shamir:
|
||||||
|
## @param shamir.shares How many shares to configure for shamir secrets
|
||||||
|
shares: 3
|
||||||
|
## @param shamir.threshold How many shares needed to recover
|
||||||
|
threshold: 2
|
||||||
|
|
||||||
|
## @param keeperPeers Keeper peer configuration. If blank, it will be autodetected
|
||||||
|
keeperPeers: []
|
||||||
|
|
||||||
|
trustRoot:
|
||||||
|
## @param trustRoot.nexus Override which trustRoot Nexus is in
|
||||||
|
nexus: ""
|
||||||
|
## @param trustRoot.keepers Override which trustRoot Keepers are in
|
||||||
|
keepers: []
|
||||||
|
## @param trustRoot.pilot Override which trustRoot Pilot is in
|
||||||
|
pilot: ""
|
||||||
|
|
||||||
|
## @param logLevel The log level, valid values are "debug", "info", "warn", and "error"
|
||||||
|
logLevel: debug
|
||||||
|
|
||||||
|
## @param agentSocketName The name of the spire-agent unix socket
|
||||||
|
agentSocketName: spire-agent.sock
|
||||||
|
## @param csiDriverName The csi driver to use
|
||||||
|
csiDriverName: csi.spiffe.io
|
||||||
|
|
||||||
|
## @param imagePullSecrets [array] Pull secrets for images
|
||||||
|
imagePullSecrets: []
|
||||||
|
|
||||||
|
## @param nameOverride Name override
|
||||||
|
nameOverride: ""
|
||||||
|
|
||||||
|
## @param namespaceOverride Namespace override
|
||||||
|
namespaceOverride: ""
|
||||||
|
|
||||||
|
## @param fullnameOverride Fullname override
|
||||||
|
fullnameOverride: ""
|
||||||
|
|
||||||
|
## @param serviceAccount.create Specifies whether a service account should be created
|
||||||
|
## @param serviceAccount.annotations [object] Annotations to add to the service account
|
||||||
|
## @param serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated.
|
||||||
|
##
|
||||||
|
serviceAccount:
|
||||||
|
create: true
|
||||||
|
annotations: {}
|
||||||
|
name: ""
|
||||||
|
|
||||||
|
## @param labels [object] Labels for pods
|
||||||
|
labels: {}
|
||||||
|
|
||||||
|
## @param podSecurityContext [object] Pod security context
|
||||||
|
podSecurityContext: {}
|
||||||
|
# fsGroup: 2000
|
||||||
|
|
||||||
|
## @param securityContext [object] Security context
|
||||||
|
securityContext:
|
||||||
|
# capabilities:
|
||||||
|
# drop:
|
||||||
|
# - ALL
|
||||||
|
# readOnlyRootFilesystem: true
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 1000
|
||||||
|
|
||||||
|
## @param service.type Service type
|
||||||
|
## @param service.port Service port
|
||||||
|
## @param service.annotations Annotations for service resource
|
||||||
|
##
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 443
|
||||||
|
annotations: {}
|
||||||
|
|
||||||
|
## @param nodeSelector (Optional) Select specific nodes to run on.
|
||||||
|
nodeSelector: {}
|
||||||
|
|
||||||
|
## @param affinity [object] Affinity rules
|
||||||
|
affinity: {}
|
||||||
|
|
||||||
|
## @param tolerations [array] List of tolerations
|
||||||
|
tolerations: []
|
||||||
|
|
||||||
|
## @param topologySpreadConstraints [array] List of topology spread constraints for resilience
|
||||||
|
topologySpreadConstraints: []
|
||||||
|
|
||||||
|
## Provide minimal resources to prevent accidental crashes due to resource exhaustion
|
||||||
|
# resources:
|
||||||
|
# requests:
|
||||||
|
# cpu: 50m
|
||||||
|
# memory: 128Mi
|
||||||
|
# limits:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 512Mi
|
||||||
|
|
||||||
|
## Configure extra options for startup probe
|
||||||
|
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-startup-probes
|
||||||
|
## @param startupProbe.enabled Enable startupProbe
|
||||||
|
## @param startupProbe.initialDelaySeconds Initial delay seconds for startupProbe
|
||||||
|
## @param startupProbe.periodSeconds Period seconds for startupProbe
|
||||||
|
## @param startupProbe.timeoutSeconds Timeout seconds for startupProbe
|
||||||
|
## @param startupProbe.failureThreshold Failure threshold count for startupProbe
|
||||||
|
## @param startupProbe.successThreshold Success threshold count for startupProbe
|
||||||
|
##
|
||||||
|
startupProbe:
|
||||||
|
enabled: true
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
timeoutSeconds: 5
|
||||||
|
failureThreshold: 6
|
||||||
|
successThreshold: 1
|
||||||
|
|
||||||
|
## @param ingress.enabled Flag to enable ingress
|
||||||
|
## @param ingress.className Ingress class name
|
||||||
|
## @param ingress.controllerType Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""].
|
||||||
|
## @param ingress.annotations [object] Annotations
|
||||||
|
ingress:
|
||||||
|
enabled: false
|
||||||
|
className: ""
|
||||||
|
controllerType: ""
|
||||||
|
annotations: {}
|
||||||
|
|
||||||
|
## @param ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead.
|
||||||
|
host: "nexus"
|
||||||
|
|
||||||
|
## @param ingress.tlsSecret Secret that has the certs. If blank will use default certs. Used with host var.
|
||||||
|
tlsSecret: ""
|
||||||
|
|
||||||
|
## @param ingress.hosts [array] Host paths for ingress object. If empty, rules will be built based on the host var.
|
||||||
|
hosts: []
|
||||||
|
# - host: nexus.example.org
|
||||||
|
# paths:
|
||||||
|
# - path: /
|
||||||
|
# pathType: Prefix
|
||||||
|
|
||||||
|
## @param ingress.tls [array] Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars.
|
||||||
|
tls: []
|
||||||
|
# - secretName: chart-example-tls
|
||||||
|
# hosts:
|
||||||
|
# - nexus.example.org
|
||||||
|
|
||||||
|
## @param persistence.type What type of volume to use for persistence. Valid options pvc (recommended), hostPath, emptyDir (testing only)
|
||||||
|
## @param persistence.size What size volume to use for persistence
|
||||||
|
## @param persistence.accessMode What access mode to use for persistence. Valid options are ReadWriteOnce (recommended), ReadWriteOncePod, ReadWriteMany (not recommended)
|
||||||
|
## @param persistence.storageClass What storage class to use for persistence
|
||||||
|
## @param persistence.hostPath Which path to use on the host when persistence.type = hostPath
|
||||||
|
##
|
||||||
|
persistence:
|
||||||
|
type: pvc
|
||||||
|
size: 1Gi
|
||||||
|
accessMode: ReadWriteOnce
|
||||||
|
storageClass: null
|
||||||
|
hostPath: ""
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: spike-pilot
|
||||||
|
description: A Helm chart to deploy SPIKE Pilot
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "0.4.1"
|
||||||
|
home: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
|
||||||
|
sources:
|
||||||
|
- https://github.com/spiffe/spike
|
||||||
|
icon: https://spike.ist/assets/spike-banner.png
|
||||||
|
maintainers:
|
||||||
|
- name: kfox1111
|
||||||
|
email: [email protected]
|
||||||
@@ -0,0 +1,63 @@
|
|||||||
|
# spike-pilot
|
||||||
|
|
||||||
|
  
|
||||||
|
[](https://github.com/spiffe/spiffe/blob/main/MATURITY.md#development)
|
||||||
|
|
||||||
|
A Helm chart to deploy spike pilot
|
||||||
|
|
||||||
|
**Homepage:** <https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire>
|
||||||
|
|
||||||
|
## Version support
|
||||||
|
|
||||||
|
> [!Note]
|
||||||
|
> This Chart is still in development and still subject to change the API (`values.yaml`).
|
||||||
|
> Until we reach a `1.0.0` version of the chart we can't guarantee backwards compatibility although
|
||||||
|
> we do aim for as much stability as possible.
|
||||||
|
|
||||||
|
| Dependency | Supported Versions |
|
||||||
|
|:-----------|:-------------------|
|
||||||
|
| Helm | `3.x` |
|
||||||
|
|
||||||
|
## Source Code
|
||||||
|
|
||||||
|
* <https://github.com/spiffe/spike>
|
||||||
|
|
||||||
|
<!-- The parameters section is generated using helm-docs.sh and should not be edited by hand. -->
|
||||||
|
|
||||||
|
## Parameters
|
||||||
|
|
||||||
|
### Chart parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| -------------------------------- | ------------------------------------------------------------------------------------------- | -------------------- |
|
||||||
|
| `image.registry` | The OCI registry to pull the image from | `ghcr.io` |
|
||||||
|
| `image.repository` | The repository within the registry | `spiffe/spike-pilot` |
|
||||||
|
| `image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
|
| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
|
||||||
|
| `shell.image.registry` | The OCI registry to pull the image from | `""` |
|
||||||
|
| `shell.image.repository` | The repository within the registry | `busybox` |
|
||||||
|
| `shell.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
|
| `shell.image.tag` | Overrides the image tag whose default is the chart appVersion | `1.37.0-uclibc` |
|
||||||
|
| `tools.busybox.image.registry` | The OCI registry to pull the image from | `""` |
|
||||||
|
| `tools.busybox.image.repository` | The repository within the registry | `busybox` |
|
||||||
|
| `tools.busybox.image.pullPolicy` | The image pull policy | `IfNotPresent` |
|
||||||
|
| `tools.busybox.image.tag` | Overrides the image tag whose default is the chart appVersion | `1.37.0-uclibc` |
|
||||||
|
| `replicas` | The number of keepers to launch | `1` |
|
||||||
|
| `trustRoot.nexus` | Override which trustRoot Nexus is in | `""` |
|
||||||
|
| `logLevel` | The log level, valid values are "debug", "info", "warn", and "error" | `debug` |
|
||||||
|
| `agentSocketName` | The name of the spire-agent unix socket | `spire-agent.sock` |
|
||||||
|
| `csiDriverName` | The csi driver to use | `csi.spiffe.io` |
|
||||||
|
| `imagePullSecrets` | Pull secrets for images | `[]` |
|
||||||
|
| `nameOverride` | Name override | `""` |
|
||||||
|
| `namespaceOverride` | Namespace override | `""` |
|
||||||
|
| `fullnameOverride` | Fullname override | `""` |
|
||||||
|
| `serviceAccount.create` | Specifies whether a service account should be created | `true` |
|
||||||
|
| `serviceAccount.annotations` | Annotations to add to the service account | `{}` |
|
||||||
|
| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` |
|
||||||
|
| `labels` | Labels for pods | `{}` |
|
||||||
|
| `podSecurityContext` | Pod security context | `{}` |
|
||||||
|
| `securityContext` | Security context | `{}` |
|
||||||
|
| `nodeSelector` | (Optional) Select specific nodes to run on. | `{}` |
|
||||||
|
| `affinity` | Affinity rules | `{}` |
|
||||||
|
| `tolerations` | List of tolerations | `[]` |
|
||||||
|
| `topologySpreadConstraints` | List of topology spread constraints for resilience | `[]` |
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
Installed {{ .Chart.Name }}…
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-pilot.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-pilot.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||||
|
{{- if contains $name .Release.Name }}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Allow the release namespace to be overridden for multi-namespace deployments in combined charts
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-pilot.namespace" -}}
|
||||||
|
{{- if .Values.namespaceOverride -}}
|
||||||
|
{{- .Values.namespaceOverride -}}
|
||||||
|
{{- else if and (dig "spire" "recommendations" "enabled" false .Values.global) (dig "spire" "recommendations" "namespaceLayout" true .Values.global) }}
|
||||||
|
{{- if ne (len (dig "spire" "namespaces" "server" "name" "" .Values.global)) 0 }}
|
||||||
|
{{- .Values.global.spire.namespaces.server.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "spire-server" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- else -}}
|
||||||
|
{{- .Release.Namespace -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-pilot.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-pilot.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "spike-pilot.chart" . }}
|
||||||
|
{{ include "spike-pilot.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-pilot.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "spike-pilot.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "spike-pilot.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
{{- default (include "spike-pilot.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- define "spike-pilot.workload-api-socket-path" -}}
|
||||||
|
{{- printf "/spiffe-workload-api/%s" .Values.agentSocketName }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,96 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "spike-pilot.fullname" . }}
|
||||||
|
namespace: {{ include "spike-pilot.namespace" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "spike-pilot.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicas }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "spike-pilot.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
{{- include "spike-pilot.selectorLabels" . | nindent 8 }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
release-namespace: {{ .Release.Namespace }}
|
||||||
|
component: spike-pilot
|
||||||
|
spec:
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
serviceAccountName: {{ include "spike-pilot.serviceAccountName" . }}
|
||||||
|
securityContext:
|
||||||
|
{{- include "spire-lib.podsecuritycontext" . | nindent 8 }}
|
||||||
|
initContainers:
|
||||||
|
- name: init
|
||||||
|
image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.tools.busybox.image "global" .Values.global "ubi" true) }}
|
||||||
|
imagePullPolicy: {{ .Values.tools.busybox.image.pullPolicy }}
|
||||||
|
command: ["/bin/sh", "-c", "cp -a /bin/busybox /data"]
|
||||||
|
securityContext:
|
||||||
|
{{- include "spire-lib.securitycontext" . | nindent 12 }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: pilot
|
||||||
|
mountPath: /data
|
||||||
|
- name: init2
|
||||||
|
image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.image "global" .Values.global "ubi" true) }}
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
command: ["/data/busybox", "sh", "-c", "/data/busybox cp -a /usr/local/bin/spike /data && /data/busybox rm -f /data/busybox"]
|
||||||
|
securityContext:
|
||||||
|
{{- include "spire-lib.securitycontext" . | nindent 12 }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: pilot
|
||||||
|
mountPath: /data
|
||||||
|
containers:
|
||||||
|
- name: {{ include "spike-pilot.fullname" . }}
|
||||||
|
image: {{ template "spire-lib.image" (dict "appVersion" $.Chart.AppVersion "image" .Values.shell.image "global" .Values.global "ubi" true) }}
|
||||||
|
imagePullPolicy: {{ .Values.shell.image.pullPolicy }}
|
||||||
|
command: ["/bin/sh", "-c", "echo I live; while true; do sleep 1000; done"]
|
||||||
|
securityContext:
|
||||||
|
{{- include "spire-lib.securitycontext" . | nindent 12 }}
|
||||||
|
env:
|
||||||
|
#FIXME make this configurable
|
||||||
|
- name: SPIKE_NEXUS_API_URL
|
||||||
|
value: https://{{ .Release.Name }}-spike-nexus:443
|
||||||
|
- name: SPIFFE_ENDPOINT_SOCKET
|
||||||
|
value: unix://{{ include "spike-pilot.workload-api-socket-path" . }}
|
||||||
|
- name: SPIKE_SYSTEM_LOG_LEVEL
|
||||||
|
value: {{ .Values.logLevel | upper }}
|
||||||
|
- name: SPIKE_TRUST_ROOT
|
||||||
|
value: {{ include "spire-lib.trust-domain" . }}
|
||||||
|
- name: SPIKE_TRUST_ROOT_NEXUS
|
||||||
|
value: {{if eq .Values.trustRoot.Nexus "" }}{{ include "spire-lib.trust-domain" . }}{{ else }}{{.Values.trustRoot.Nexus }}{{ end }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: spiffe-workload-api
|
||||||
|
mountPath: {{ include "spike-pilot.workload-api-socket-path" . | dir }}
|
||||||
|
readOnly: true
|
||||||
|
- name: pilot
|
||||||
|
mountPath: /bin/spike
|
||||||
|
subPath: spike
|
||||||
|
readOnly: true
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.topologySpreadConstraints }}
|
||||||
|
topologySpreadConstraints:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
volumes:
|
||||||
|
- name: pilot
|
||||||
|
emptyDir: {}
|
||||||
|
- name: spiffe-workload-api
|
||||||
|
csi:
|
||||||
|
driver: "{{ .Values.csiDriverName }}"
|
||||||
|
readOnly: true
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
{{- if .Values.serviceAccount.create -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "spike-pilot.serviceAccountName" . }}
|
||||||
|
namespace: {{ include "spike-pilot.namespace" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "spike-pilot.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.serviceAccount.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,116 @@
|
|||||||
|
# Default configuration for SPIKE Keeper
|
||||||
|
# SPDX-License-Identifier: APACHE-2.0
|
||||||
|
|
||||||
|
## @skip global
|
||||||
|
global: {}
|
||||||
|
|
||||||
|
## @section Chart parameters
|
||||||
|
##
|
||||||
|
## @param image.registry The OCI registry to pull the image from
|
||||||
|
## @param image.repository The repository within the registry
|
||||||
|
## @param image.pullPolicy The image pull policy
|
||||||
|
## @param image.tag Overrides the image tag whose default is the chart appVersion
|
||||||
|
##
|
||||||
|
image:
|
||||||
|
registry: ghcr.io
|
||||||
|
repository: spiffe/spike-pilot
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
tag: ""
|
||||||
|
|
||||||
|
shell:
|
||||||
|
## @param shell.image.registry The OCI registry to pull the image from
|
||||||
|
## @param shell.image.repository The repository within the registry
|
||||||
|
## @param shell.image.pullPolicy The image pull policy
|
||||||
|
## @param shell.image.tag Overrides the image tag whose default is the chart appVersion
|
||||||
|
##
|
||||||
|
image:
|
||||||
|
registry: ""
|
||||||
|
repository: busybox
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
tag: 1.37.0-uclibc
|
||||||
|
|
||||||
|
tools:
|
||||||
|
busybox:
|
||||||
|
## @param tools.busybox.image.registry The OCI registry to pull the image from
|
||||||
|
## @param tools.busybox.image.repository The repository within the registry
|
||||||
|
## @param tools.busybox.image.pullPolicy The image pull policy
|
||||||
|
## @param tools.busybox.image.tag Overrides the image tag whose default is the chart appVersion
|
||||||
|
##
|
||||||
|
image:
|
||||||
|
registry: ""
|
||||||
|
repository: busybox
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
tag: 1.37.0-uclibc
|
||||||
|
|
||||||
|
## @param replicas The number of keepers to launch
|
||||||
|
replicas: 1
|
||||||
|
|
||||||
|
trustRoot:
|
||||||
|
## @param trustRoot.nexus Override which trustRoot Nexus is in
|
||||||
|
nexus: ""
|
||||||
|
|
||||||
|
## @param logLevel The log level, valid values are "debug", "info", "warn", and "error"
|
||||||
|
logLevel: debug
|
||||||
|
|
||||||
|
## @param agentSocketName The name of the spire-agent unix socket
|
||||||
|
agentSocketName: spire-agent.sock
|
||||||
|
## @param csiDriverName The csi driver to use
|
||||||
|
csiDriverName: csi.spiffe.io
|
||||||
|
|
||||||
|
## @param imagePullSecrets [array] Pull secrets for images
|
||||||
|
imagePullSecrets: []
|
||||||
|
|
||||||
|
## @param nameOverride Name override
|
||||||
|
nameOverride: ""
|
||||||
|
|
||||||
|
## @param namespaceOverride Namespace override
|
||||||
|
namespaceOverride: ""
|
||||||
|
|
||||||
|
## @param fullnameOverride Fullname override
|
||||||
|
fullnameOverride: ""
|
||||||
|
|
||||||
|
## @param serviceAccount.create Specifies whether a service account should be created
|
||||||
|
## @param serviceAccount.annotations [object] Annotations to add to the service account
|
||||||
|
## @param serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated.
|
||||||
|
##
|
||||||
|
serviceAccount:
|
||||||
|
create: true
|
||||||
|
annotations: {}
|
||||||
|
name: ""
|
||||||
|
|
||||||
|
## @param labels [object] Labels for pods
|
||||||
|
labels: {}
|
||||||
|
|
||||||
|
## @param podSecurityContext [object] Pod security context
|
||||||
|
podSecurityContext: {}
|
||||||
|
# fsGroup: 2000
|
||||||
|
|
||||||
|
## @param securityContext [object] Security context
|
||||||
|
securityContext: {}
|
||||||
|
# capabilities:
|
||||||
|
# drop:
|
||||||
|
# - ALL
|
||||||
|
# readOnlyRootFilesystem: true
|
||||||
|
# runAsNonRoot: true
|
||||||
|
# runAsUser: 1000
|
||||||
|
|
||||||
|
## @param nodeSelector (Optional) Select specific nodes to run on.
|
||||||
|
nodeSelector: {}
|
||||||
|
|
||||||
|
## @param affinity [object] Affinity rules
|
||||||
|
affinity: {}
|
||||||
|
|
||||||
|
## @param tolerations [array] List of tolerations
|
||||||
|
tolerations: []
|
||||||
|
|
||||||
|
## @param topologySpreadConstraints [array] List of topology spread constraints for resilience
|
||||||
|
topologySpreadConstraints: []
|
||||||
|
|
||||||
|
## Provide minimal resources to prevent accidental crashes due to resource exhaustion
|
||||||
|
# resources:
|
||||||
|
# requests:
|
||||||
|
# cpu: 50m
|
||||||
|
# memory: 128Mi
|
||||||
|
# limits:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 512Mi
|
||||||
@@ -311,6 +311,15 @@ In order to run Tornjak with simple HTTP Connection only, make sure you don't cr
|
|||||||
| `controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.dnsNameTemplates` | DNS name template for issued identities | `[]` |
|
| `controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.dnsNameTemplates` | DNS name template for issued identities | `[]` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.test-keys.enabled` | Enable this identity for controller manager | `true` |
|
| `controllerManager.identities.clusterSPIFFEIDs.test-keys.enabled` | Enable this identity for controller manager | `true` |
|
||||||
| `controllerManager.identities.clusterSPIFFEIDs.test-keys.type` | The type of rule this is. | `test-keys` |
|
| `controllerManager.identities.clusterSPIFFEIDs.test-keys.type` | The type of rule this is. | `test-keys` |
|
||||||
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.enabled` | Enable this identity for controller manager | `true` |
|
||||||
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.type` | The type of rule this is. | `spike-keeper` |
|
||||||
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-keeper.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/keeper` |
|
||||||
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.enabled` | Enable this identity for controller manager | `true` |
|
||||||
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.type` | The type of rule this is. | `spike-nexus` |
|
||||||
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-nexus.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/nexus` |
|
||||||
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.enabled` | Enable this identity for controller manager | `true` |
|
||||||
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.type` | The type of rule this is. | `spike-pilot` |
|
||||||
|
| `controllerManager.identities.clusterSPIFFEIDs.spike-pilot.spiffeIDTemplate` | The template to use for this rule. | `spiffe://{{ .TrustDomain }}/spike/pilot/role/superuser` |
|
||||||
| `controllerManager.identities.clusterStaticEntries` | Specify ClusterStaticEntry objects. | `{}` |
|
| `controllerManager.identities.clusterStaticEntries` | Specify ClusterStaticEntry objects. | `{}` |
|
||||||
| `controllerManager.identities.clusterFederatedTrustDomains` | Specify ClusterFederatedTrustDomain objects. | `{}` |
|
| `controllerManager.identities.clusterFederatedTrustDomains` | Specify ClusterFederatedTrustDomain objects. | `{}` |
|
||||||
| `controllerManager.validatingWebhookConfiguration.enabled` | Disable only when you have another chart instance on the k8s cluster with webhooks enabled. | `true` |
|
| `controllerManager.validatingWebhookConfiguration.enabled` | Disable only when you have another chart instance on the k8s cluster with webhooks enabled. | `true` |
|
||||||
|
|||||||
@@ -17,6 +17,21 @@ matchLabels:
|
|||||||
release: {{ .Release.Name }}
|
release: {{ .Release.Name }}
|
||||||
release-namespace: {{ .Release.Namespace }}
|
release-namespace: {{ .Release.Namespace }}
|
||||||
component: oidc-discovery-provider
|
component: oidc-discovery-provider
|
||||||
|
{{- else if eq .type "spike-keeper" }}
|
||||||
|
matchLabels:
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
release-namespace: {{ .Release.Namespace }}
|
||||||
|
component: spike-keeper
|
||||||
|
{{- else if eq .type "spike-nexus" }}
|
||||||
|
matchLabels:
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
release-namespace: {{ .Release.Namespace }}
|
||||||
|
component: spike-nexus
|
||||||
|
{{- else if eq .type "spike-pilot" }}
|
||||||
|
matchLabels:
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
release-namespace: {{ .Release.Namespace }}
|
||||||
|
component: spike-pilot
|
||||||
{{- else if eq .type "test-keys" }}
|
{{- else if eq .type "test-keys" }}
|
||||||
matchLabels:
|
matchLabels:
|
||||||
release: {{ .Release.Name }}
|
release: {{ .Release.Name }}
|
||||||
@@ -38,8 +53,8 @@ matchLabels:
|
|||||||
{{- if eq ($root.Values.controllerManager.enabled | toString) "true" }}
|
{{- if eq ($root.Values.controllerManager.enabled | toString) "true" }}
|
||||||
{{- if or (not (hasKey $value "enabled")) (eq ($value.enabled | toString) "true") }}
|
{{- if or (not (hasKey $value "enabled")) (eq ($value.enabled | toString) "true") }}
|
||||||
{{- $type := dig "type" "base" $value }}
|
{{- $type := dig "type" "base" $value }}
|
||||||
{{- if not (has $type (list "base" "raw" "child-servers" "oidc-discovery-provider" "test-keys")) }}
|
{{- if not (has $type (list "base" "raw" "child-servers" "oidc-discovery-provider" "spike-keeper" "spike-nexus" "spike-pilot" "test-keys")) }}
|
||||||
{{- fail (printf "Type given: %s, must be one of [base, raw, child-servers, oidc-discovery-provider, test-keys]" $type) }}
|
{{- fail (printf "Type given: %s, must be one of [base, raw, child-servers, oidc-discovery-provider, spike-keeper, spike-nexus, spike-pilot, test-keys]" $type) }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- $namespaceSelector := deepCopy (dig "namespaceSelector" (dict) $value) }}
|
{{- $namespaceSelector := deepCopy (dig "namespaceSelector" (dict) $value) }}
|
||||||
{{- if ne $type "raw" }}
|
{{- if ne $type "raw" }}
|
||||||
|
|||||||
@@ -695,6 +695,28 @@ controllerManager:
|
|||||||
## @param controllerManager.identities.clusterSPIFFEIDs.test-keys.type The type of rule this is.
|
## @param controllerManager.identities.clusterSPIFFEIDs.test-keys.type The type of rule this is.
|
||||||
type: test-keys
|
type: test-keys
|
||||||
|
|
||||||
|
spike-keeper:
|
||||||
|
## @param controllerManager.identities.clusterSPIFFEIDs.spike-keeper.enabled Enable this identity for controller manager
|
||||||
|
enabled: true
|
||||||
|
## @param controllerManager.identities.clusterSPIFFEIDs.spike-keeper.type The type of rule this is.
|
||||||
|
type: spike-keeper
|
||||||
|
## @param controllerManager.identities.clusterSPIFFEIDs.spike-keeper.spiffeIDTemplate The template to use for this rule.
|
||||||
|
spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spike/keeper
|
||||||
|
spike-nexus:
|
||||||
|
## @param controllerManager.identities.clusterSPIFFEIDs.spike-nexus.enabled Enable this identity for controller manager
|
||||||
|
enabled: true
|
||||||
|
## @param controllerManager.identities.clusterSPIFFEIDs.spike-nexus.type The type of rule this is.
|
||||||
|
type: spike-nexus
|
||||||
|
## @param controllerManager.identities.clusterSPIFFEIDs.spike-nexus.spiffeIDTemplate The template to use for this rule.
|
||||||
|
spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spike/nexus
|
||||||
|
spike-pilot:
|
||||||
|
## @param controllerManager.identities.clusterSPIFFEIDs.spike-pilot.enabled Enable this identity for controller manager
|
||||||
|
enabled: true
|
||||||
|
## @param controllerManager.identities.clusterSPIFFEIDs.spike-pilot.type The type of rule this is.
|
||||||
|
type: spike-pilot
|
||||||
|
## @param controllerManager.identities.clusterSPIFFEIDs.spike-pilot.spiffeIDTemplate The template to use for this rule.
|
||||||
|
spiffeIDTemplate: spiffe://{{ .TrustDomain }}/spike/pilot/role/superuser
|
||||||
|
|
||||||
# You can specify additional ClusterSPIFFEIDs following this example:
|
# You can specify additional ClusterSPIFFEIDs following this example:
|
||||||
# foo:
|
# foo:
|
||||||
# labels:
|
# labels:
|
||||||
|
|||||||
@@ -219,3 +219,24 @@ spiffe-oidc-discovery-provider:
|
|||||||
tornjak-frontend:
|
tornjak-frontend:
|
||||||
## @param tornjak-frontend.enabled Enables deployment of Tornjak frontend/UI (Not for production)
|
## @param tornjak-frontend.enabled Enables deployment of Tornjak frontend/UI (Not for production)
|
||||||
enabled: false
|
enabled: false
|
||||||
|
|
||||||
|
## @section SPIKE Keeper parameters
|
||||||
|
## Parameter values for SPIKE Keeper
|
||||||
|
##
|
||||||
|
spike-keeper:
|
||||||
|
## @param spike-keeper.enabled Enables deployment of SPIKE Keeper (Not for production)
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
## @section SPIKE Nexus parameters
|
||||||
|
## Parameter values for SPIKE Nexus
|
||||||
|
##
|
||||||
|
spike-nexus:
|
||||||
|
## @param spike-nexus.enabled Enables deployment of SPIKE Nexus (Not for production)
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
## @section SPIKE Pilot parameters
|
||||||
|
## Parameter values for SPIKE Pilot
|
||||||
|
##
|
||||||
|
spike-pilot:
|
||||||
|
## @param spike-pilot.enabled Enables deployment of SPIKE Pilot (Not for production)
|
||||||
|
enabled: false
|
||||||
|
|||||||
@@ -0,0 +1,15 @@
|
|||||||
|
global:
|
||||||
|
spire:
|
||||||
|
ingressControllerType: ingress-nginx
|
||||||
|
spike-keeper:
|
||||||
|
enabled: true
|
||||||
|
#ingress:
|
||||||
|
# enabled: true
|
||||||
|
# className: nginx
|
||||||
|
spike-nexus:
|
||||||
|
enabled: true
|
||||||
|
ingress:
|
||||||
|
enabled: true
|
||||||
|
className: nginx
|
||||||
|
spike-pilot:
|
||||||
|
enabled: true
|
||||||
Reference in New Issue
Block a user