Add example of mysql using spire (#164)
* Add example of mysql using spire Signed-off-by: Kevin Fox <[email protected]> * Finish up the implementation Signed-off-by: Kevin Fox <[email protected]> * Update the image Signed-off-by: Kevin Fox <[email protected]> * Apply suggestions from code review Signed-off-by: kfox1111 <[email protected]> * Update. Restested. Signed-off-by: Kevin Fox <[email protected]> --------- Signed-off-by: Kevin Fox <[email protected]> Signed-off-by: kfox1111 <[email protected]>
This commit is contained in:
@@ -0,0 +1,21 @@
|
||||
```
|
||||
helm upgrade --install -n spire-server spire-crds spire-crds --repo https://spiffe.github.io/helm-charts-hardened/ --create-namespace --version 0.3.0
|
||||
helm upgrade --install -n spire-server spire spire --repo https://spiffe.github.io/helm-charts-hardened/ --version 0.17.1 -f spire-values.yaml
|
||||
|
||||
kubectl apply -f mysqlclient-configmap.yaml
|
||||
kubectl apply -f mysqlclient-statefulset.yaml
|
||||
|
||||
kubectl wait pod mysqlclient-0 --for=condition=ready --timeout=60s
|
||||
|
||||
# Run, and get the x500UniqueIdentifier value:
|
||||
kubectl exec -it mysqlclient-0 -c main -- bash -c 'openssl x509 -in /certs/tls.crt -noout -text | grep Subject:'
|
||||
|
||||
# Edit mysql-values.yaml and update the x509UniqueIdentifer
|
||||
vim mysql-values.yaml
|
||||
|
||||
helm upgrade --install -f mysql-values.yaml mysql mysql --version 9.15.0 --repo https://charts.bitnami.com/bitnami
|
||||
|
||||
kubectl wait pod mysql-0 --for=condition=ready --timeout=60s
|
||||
|
||||
kubectl exec -it mysqlclient-0 -- bash -c 'mysql -u mysqlclient --protocol tcp --ssl-key /certs/tls.key --ssl-cert /certs/tls.crt --ssl-ca /certs/ca.pem -h mysql.default.svc.cluster.local'
|
||||
```
|
||||
@@ -0,0 +1,122 @@
|
||||
initdbScripts:
|
||||
usertls.sql: |
|
||||
CREATE USER 'mysqlclient'@'%' REQUIRE SUBJECT '/C=US/O=SPIRE/CN=mysqlclient.default.svc.cluster.local/x500UniqueIdentifier=a753b06724b81d4a2f14f615d40550ed';
|
||||
GRANT ALL PRIVILEGES ON *.* TO 'mysqlclient'@'%' WITH GRANT OPTION;
|
||||
|
||||
primary:
|
||||
extraFlags: "--ssl-ca=/certs/ca.pem --ssl-cert=/certs/tls.crt --ssl-key=/certs/tls.key --require-secure-transport=ON"
|
||||
|
||||
initContainers: |
|
||||
- name: setup-helper-volume-p1
|
||||
image: busybox:1.36.1-uclibc
|
||||
imagePullPolicy: IfNotPresent
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- 'cp -a /bin/busybox /helper'
|
||||
securityContext: {{- omit .Values.primary.containerSecurityContext "enabled" | toYaml | nindent 8 }}
|
||||
volumeMounts:
|
||||
- name: spiffe-helper
|
||||
mountPath: /helper
|
||||
- name: setup-helper-volume-p2
|
||||
image: ghcr.io/spiffe/spiffe-helper:nightly@sha256:8cee346ffdcee5c996d394f1c3bb761c2c06834a0e779a78db6dc6a46fd13ae6
|
||||
imagePullPolicy: IfNotPresent
|
||||
command:
|
||||
- /helper/busybox
|
||||
- sh
|
||||
- -c
|
||||
- '/helper/busybox cp -a /spiffe-helper /helper && /helper/busybox rm -f /helper/busybox'
|
||||
securityContext: {{- omit .Values.primary.containerSecurityContext "enabled" | toYaml | nindent 8 }}
|
||||
volumeMounts:
|
||||
- name: spiffe-helper
|
||||
mountPath: /helper
|
||||
- name: init-tls
|
||||
image: ghcr.io/spiffe/spiffe-helper:nightly@sha256:8cee346ffdcee5c996d394f1c3bb761c2c06834a0e779a78db6dc6a46fd13ae6
|
||||
imagePullPolicy: Always
|
||||
command:
|
||||
- /spiffe-helper
|
||||
- -config
|
||||
- /etc/spiffe-helper.conf
|
||||
- -exitWhenReady
|
||||
securityContext: {{- omit .Values.primary.containerSecurityContext "enabled" | toYaml | nindent 8 }}
|
||||
volumeMounts:
|
||||
- name: spiffe-workload-api
|
||||
mountPath: /spiffe-workload-api
|
||||
readOnly: true
|
||||
- name: spiffe-helper-configmap
|
||||
mountPath: /etc/spiffe-helper.conf
|
||||
subPath: spiffe-helper.conf
|
||||
readOnly: true
|
||||
- name: certdir
|
||||
mountPath: /certs
|
||||
|
||||
sidecars: |
|
||||
- name: refresh-tls
|
||||
image: {{ include "mysql.image" . }}
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy | quote }}
|
||||
command:
|
||||
- /helper/spiffe-helper
|
||||
- -config
|
||||
- /etc/spiffe-helper.conf
|
||||
env:
|
||||
- name: MYSQL_PWD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ template "mysql.secretName" . }}
|
||||
key: mysql-root-password
|
||||
securityContext: {{- omit .Values.primary.containerSecurityContext "enabled" | toYaml | nindent 8 }}
|
||||
volumeMounts:
|
||||
- name: spiffe-workload-api
|
||||
mountPath: /spiffe-workload-api
|
||||
readOnly: true
|
||||
- name: spiffe-helper-configmap
|
||||
mountPath: /etc/spiffe-helper.conf
|
||||
subPath: spiffe-helper.conf
|
||||
readOnly: true
|
||||
- name: certdir
|
||||
mountPath: /certs
|
||||
- name: spiffe-helper
|
||||
mountPath: /helper
|
||||
- name: mysql-sockdir
|
||||
mountPath: /opt/bitnami/mysql/tmp
|
||||
|
||||
extraVolumeMounts:
|
||||
- name: certdir
|
||||
mountPath: /certs
|
||||
- name: mysql-sockdir
|
||||
mountPath: /opt/bitnami/mysql/tmp
|
||||
|
||||
extraVolumes: |
|
||||
- name: certdir
|
||||
emptyDir: {}
|
||||
- name: spiffe-helper
|
||||
emptyDir: {}
|
||||
- name: mysql-sockdir
|
||||
emptyDir: {}
|
||||
- name: spiffe-helper-configmap
|
||||
configMap:
|
||||
name: {{ include "mysql.primary.fullname" . }}-spiffe-helper
|
||||
- name: spiffe-workload-api
|
||||
csi:
|
||||
driver: "csi.spiffe.io"
|
||||
readOnly: true
|
||||
|
||||
extraDeploy:
|
||||
- |
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: {{ include "mysql.primary.fullname" . }}-spiffe-helper
|
||||
namespace: {{ include "common.names.namespace" . | quote }}
|
||||
data:
|
||||
spiffe-helper.conf: |
|
||||
agent_address = "/spiffe-workload-api/spire-agent.sock"
|
||||
cmd = "/opt/bitnami/mysql/bin/mysql"
|
||||
cmd_args = "-uroot -e \"ALTER INSTANCE RELOAD TLS;\""
|
||||
renew_signal = ""
|
||||
cert_dir = "/certs"
|
||||
renew_signal = ""
|
||||
svid_file_name = "tls.crt"
|
||||
svid_key_file_name = "tls.key"
|
||||
svid_bundle_file_name = "ca.pem"
|
||||
add_intermediates_to_bundle = true
|
||||
@@ -0,0 +1,15 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: mysqlclient
|
||||
data:
|
||||
spiffe-helper.conf: |
|
||||
agent_address = "/spiffe-workload-api/spire-agent.sock"
|
||||
cmd = ""
|
||||
cmd_args = ""
|
||||
cert_dir = "/certs"
|
||||
renew_signal = ""
|
||||
svid_file_name = "tls.crt"
|
||||
svid_key_file_name = "tls.key"
|
||||
svid_bundle_file_name = "ca.pem"
|
||||
add_intermediates_to_bundle = true
|
||||
@@ -0,0 +1,78 @@
|
||||
apiVersion: apps/v1
|
||||
kind: StatefulSet
|
||||
metadata:
|
||||
name: mysqlclient
|
||||
spec:
|
||||
replicas: 1
|
||||
#serviceName: mysqlclient
|
||||
selector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/instance: mysqlclient
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/instance: mysqlclient
|
||||
spec:
|
||||
terminationGracePeriodSeconds: 0
|
||||
initContainers:
|
||||
- name: init-tls
|
||||
image: ghcr.io/spiffe/spiffe-helper:nightly@sha256:8cee346ffdcee5c996d394f1c3bb761c2c06834a0e779a78db6dc6a46fd13ae6
|
||||
imagePullPolicy: Always
|
||||
command:
|
||||
- /spiffe-helper
|
||||
- -config
|
||||
- /etc/spiffe-helper.conf
|
||||
- -exitWhenReady
|
||||
securityContext:
|
||||
runAsUser: 1001
|
||||
runAsGroup: 1001
|
||||
volumeMounts:
|
||||
- name: spiffe-workload-api
|
||||
mountPath: /spiffe-workload-api
|
||||
readOnly: true
|
||||
- name: spiffe-helper-configmap
|
||||
mountPath: /etc/spiffe-helper.conf
|
||||
subPath: spiffe-helper.conf
|
||||
readOnly: true
|
||||
- name: certdir
|
||||
mountPath: /certs
|
||||
containers:
|
||||
- name: main
|
||||
image: docker.io/bitnami/mysql:8.0.35-debian-11-r0
|
||||
command: [sleep, inf]
|
||||
securityContext:
|
||||
runAsUser: 1001
|
||||
runAsGroup: 1001
|
||||
volumeMounts:
|
||||
- name: certdir
|
||||
mountPath: /certs
|
||||
- name: refresh-tls
|
||||
image: ghcr.io/spiffe/spiffe-helper:nightly@sha256:8cee346ffdcee5c996d394f1c3bb761c2c06834a0e779a78db6dc6a46fd13ae6
|
||||
imagePullPolicy: Always
|
||||
command:
|
||||
- /spiffe-helper
|
||||
- -config
|
||||
- /etc/spiffe-helper.conf
|
||||
securityContext:
|
||||
runAsUser: 1001
|
||||
runAsGroup: 1001
|
||||
volumeMounts:
|
||||
- name: spiffe-workload-api
|
||||
mountPath: /spiffe-workload-api
|
||||
readOnly: true
|
||||
- name: spiffe-helper-configmap
|
||||
mountPath: /etc/spiffe-helper.conf
|
||||
subPath: spiffe-helper.conf
|
||||
readOnly: true
|
||||
- name: certdir
|
||||
mountPath: /certs
|
||||
volumes:
|
||||
- name: certdir
|
||||
emptyDir: {}
|
||||
- name: spiffe-helper-configmap
|
||||
configMap:
|
||||
name: mysqlclient
|
||||
- name: spiffe-workload-api
|
||||
csi:
|
||||
driver: "csi.spiffe.io"
|
||||
readOnly: true
|
||||
@@ -0,0 +1,26 @@
|
||||
spire-server:
|
||||
controllerManager:
|
||||
identities:
|
||||
clusterSPIFFEIDs:
|
||||
default:
|
||||
enabled: false
|
||||
mysql:
|
||||
spiffeIDTemplate: spiffe://{{ .TrustDomain }}/ns/{{ .PodMeta.Namespace }}/sa/{{ .PodSpec.ServiceAccountName }}
|
||||
namespaceSelector:
|
||||
matchLabels:
|
||||
kubernetes.io/metadata.name: default
|
||||
podSelector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/instance: mysql
|
||||
dnsNameTemplates:
|
||||
- mysql.default.svc.cluster.local
|
||||
mysqlclient:
|
||||
spiffeIDTemplate: spiffe://{{ .TrustDomain }}/ns/{{ .PodMeta.Namespace }}/sa/{{ .PodSpec.ServiceAccountName }}
|
||||
namespaceSelector:
|
||||
matchLabels:
|
||||
kubernetes.io/metadata.name: default
|
||||
podSelector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/instance: mysqlclient
|
||||
dnsNameTemplates:
|
||||
- mysqlclient.default.svc.cluster.local
|
||||
Reference in New Issue
Block a user