Mariusz Sabath and Faisal Memon
0e41a7d1b4
Fix failing Tornjak ingress port ( #28 )
...
Co-authored-by: Faisal Memon <[email protected] >
2023-10-11 14:36:15 +00:00
kfox1111
0fa43a507d
Add plugin support to the spire agent ( #22 )
...
* Exit code from diff indicating changes should not block commit.
Signed-off-by: Kevin Fox <[email protected] >
* Push the changes that update-tags creates
Signed-off-by: Kevin Fox <[email protected] >
* Add plugin support to the spire agent
This adapts the existing spire server plugin support to be usable by
the agent as well.
Signed-off-by: Kevin Fox <[email protected] >
* Fix notes
Signed-off-by: Kevin Fox <[email protected] >
* Add plugin support to the spire agent
This adapts the existing spire server plugin support to be usable by
the agent as well.
Signed-off-by: Kevin Fox <[email protected] >
* Fix notes
Signed-off-by: Kevin Fox <[email protected] >
* Update documentation
Signed-off-by: Kevin Fox <[email protected] >
* Update example
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
2023-10-10 08:09:11 +00:00
Mariusz Sabath and Marco Franssen
03ff618958
Add Tornjak ingress ( #16 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-10-09 11:31:55 +00:00
kfox1111
50825d9fc9
Deny production runs of example.org trust domains ( #229 )
2023-09-25 12:06:48 -07:00
Faisal Memon
f04bdc3618
Add support for experimental flags ( #492 )
...
Add support for the experimental section of the config. Needed for
developers. This PR doesnt add support for the `auth_opa_policy_engine`
experimental config.
---------
Signed-off-by: Faisal Memon <[email protected] >
2023-09-22 14:55:03 -07:00
unufr33 and Faisal Memon
d3091a829c
Fix spire-server configmap UpstreamAuthority/aws_pca and KeyManager/a… ( #489 )
...
Current configmap template renders to a wrong KeyManager and
UpstreamAuthority configurarion when aws_kms and aws_pca are enabled and
container is crashing. The proposed changes will fix the issue.
---------
Signed-off-by: unufree <[email protected] >
Signed-off-by: unufr33 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-09-20 09:12:11 -07:00
LaithLite and Marco Franssen
38f0af4491
Add support for Vault UpstreamAuthority plugin - K8s Auth ( #415 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-09-15 08:48:56 +02:00
Inverse Integral
1f908676bb
Allow configuration of priorityClassName on spire-server statefulset ( #480 )
2023-09-12 22:31:23 +02:00
kfox1111 and Marco Franssen
e81a59a7e5
ingress-nginx production tests and spiffe-oidc-discovery-provider example ( #136 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-08-29 15:22:00 +00:00
51cba5b530
Add customPlugins and unsupportedBuiltInPlugins sections to spire-server ( #198 )
...
This patch enables end users to configure external plugins in the
spire-server config. Unsupported internal plugins are not able to be
set.
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Edwin Buck <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-08-24 21:13:28 +00:00
grameshtwilio and Faisal Memon
c817dd2411
support datastore password secret created by external resources ( #464 )
...
This allows the datastore secret object to be created by external agents
such as https://github.com/external-secrets/external-secrets
---------
Signed-off-by: grameshtwilio <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-08-22 16:08:52 -07:00
Marco Franssen and Faisal Memon
c298510701
Fix initContainers spire-server statefulset ( #458 )
...
To allow for inplace upgrades of spire-server statefulset we are not
allowed to
make changes to all fields of the statefulset spec.
When bumping from 0.8.1 to the latest version the `initContainers:`
field is added in the spec and therefore does not allow for updating the
statefulset.
This fix prevents the empty initContainers block when bumping from a
previous chart version.
Signed-off-by: Marco Franssen <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-08-21 10:38:42 -07:00
5e2e8a9188
Adds AWS KMS KeyManager support ( #435 )
...
Co-authored-by: Marco Franssen <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2023-08-18 09:52:51 +02:00
b7e15255f3
Allow job hooks to be disabled ( #434 )
...
Co-authored-by: Marco Franssen <[email protected] >
Co-authored-by: Kevin Fox <[email protected] >
2023-08-18 09:48:14 +02:00
kfox1111
ae8941c49d
Support Nested Spire with External Agent ( #117 )
2023-08-16 16:35:41 +02:00
grameshtwilio
e60f5287e0
option to set KeyManager memory in spire server ( #444 )
2023-08-12 20:55:40 +02:00
Mariusz Sabath
7a6e4f8d75
Change Tornjak backend default port ( #436 )
2023-08-09 16:46:08 +02:00
Drew Wells and Faisal Memon
d2e1606286
issuer naming should respect issuer_name override ( #378 )
...
align the spire-server configmap and issuer CR naming
---------
Signed-off-by: Drew Wells <[email protected] >
Signed-off-by: Faisal Memon <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-08-02 14:22:59 -07:00
9f4d4ace84
Add aws_pca to the spire-server ( #404 )
...
This change allows aws_pca to be configured via values of this chart.
__Requires 1.7.1 version__ per
[bug](https://github.com/spiffe/spire/issues/4351 ) - this will not work
until 1.7.1 is released.
---------
Signed-off-by: Petr McAllister <[email protected] >
Signed-off-by: Petr McAllister <[email protected] >
Signed-off-by: Kevin Fox <[email protected] >
Co-authored-by: Marco Franssen <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2023-07-27 14:27:51 -07:00
Kevin Fox
a6bdb4d1e7
Add persistence type flag
...
This patch adds a type flag to the persistence settings to enable
specifying the backing volume's type.
Signed-off-by: Kevin Fox <[email protected] >
2023-07-19 23:40:23 +02:00
Marco Franssen
088b29608e
Improve tornjak service API to have object structure ( #392 )
2023-07-19 09:17:45 -07:00
Marco Franssen
522066e9f9
Align tornjak clientCA naming convention ( #393 )
2023-07-19 09:13:50 -07:00
Mariusz Sabath and Marco Franssen
f05cb4fe1e
Add option to configure TLS/mTLS endpoint for Tornjak ( #338 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-07-19 14:32:32 +02:00
kfox1111 and Marco Franssen
c1b1dd3d88
Add additional domains to JWT issued items. ( #230 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-07-03 22:26:28 +02:00
Marco Franssen
d7a03f620d
Fix bug in cert-manager upstream authority
...
The arguments for default function need to be the other way around
Signed-off-by: Marco Franssen <[email protected] >
2023-06-29 17:39:21 +02:00
kfox1111
8409674a3e
Fix the init container flags of the statefulset ( #366 )
2023-06-22 18:57:07 +02:00
Drew Wells
3b6666016c
add missing federatesWith option ( #361 )
...
DEMO
```
spire-server-0 -- spire-server entry show -spiffeID spiffe://box-4.example.com/ns/dwells/sa/dwells-rc-realm-client
Defaulted container "spire-server" out of: spire-server, spire-controller-manager, wait (init)
Found 1 entry
Entry ID : 09301666-010e-4ba9-9dcb-44370d4e49e4
SPIFFE ID : spiffe://box-4.example.com/ns/dwells/sa/dwells-rc-realm-client
Parent ID : spiffe://box-4.example.com/spire/agent/k8s_psat/example-cluster/ff93872d-791f-4bf3-a532-475775d03d3e
Revision : 0
X509-SVID TTL : default
JWT-SVID TTL : default
Selector : k8s:pod-uid:40e0bcad-6ec8-460b-a839-659654549d7a
FederatesWith : box-3.example.com
```
Signed-off-by: Drew Wells <[email protected] >
2023-06-22 08:45:37 -07:00
Drew Wells
0533d92594
fixes missing template ( #362 )
2023-06-22 09:40:08 -04:00
Faisal Memon
1333b6ab34
Always add parseTime=true for mysql query string ( #352 )
2023-06-20 21:14:42 +02:00
Marco Franssen
c11a8c00e7
Implement pre-delete hook for graceful delete of spiffe-oidc-discovery-provider ( #353 )
2023-06-17 06:06:27 -07:00
Faisal Memon
e88f7f6fe2
Add configmap annotation to spire-bundle configmap ( #351 )
2023-06-16 23:22:44 +02:00
Drew Wells and Kevin Fox
020bde8561
Add support to create a issuer and CA via cert-manager ( #342 )
...
Co-authored-by: Kevin Fox <[email protected] >
2023-06-16 21:04:11 +00:00
kfox1111
c97a788c85
Fix bundle role/rolebinding naming conflict ( #333 )
2023-06-16 08:55:49 +02:00
kfox1111
4c0a1d52c5
Allow overriding test images ( #186 )
2023-06-14 21:17:08 +02:00
Drew Wells
8748933548
Update upstream-ca-secret.yaml ( #341 )
...
Fix an issue with nested context being used for namespace
Fixes this issue:
```
Error: UPGRADE FAILED: template: spire/charts/spire-server/templates/upstream-ca-secret.yaml:8:16: executing "spire/charts/spire-server/templates/upstream-ca-secret.yaml" at <include "spire-server.names
pace" .>: error calling include: template: spire/charts/spire-server/templates/_helpers.tpl:30:16: executing "spire-server.namespace" at <.Values.namespaceOverride>: nil pointer evaluating interface {}.
namespaceOverride
helm.go:84: [debug] template: spire/charts/spire-server/templates/upstream-ca-secret.yaml:8:16: executing "spire/charts/spire-server/templates/upstream-ca-secret.yaml" at <include "spire-server.namespac
e" .>: error calling include: template: spire/charts/spire-server/templates/_helpers.tpl:30:16: executing "spire-server.namespace" at <.Values.namespaceOverride>: nil pointer evaluating interface {}.nam
espaceOverride
```
Signed-off-by: Drew Wells <[email protected] >
2023-06-12 11:25:14 -07:00
kfox1111
4e07450781
Fix ingress annotations for federation ( #337 )
...
fixes: https://github.com/spiffe/helm-charts/issues/336
Signed-off-by: Kevin Fox <[email protected] >
2023-06-12 05:50:26 -07:00
Mariusz Sabath
9fa1ec28a7
Improve Tornjak backend test ( #321 )
2023-05-30 23:29:29 +02:00
Mariusz Sabath
1247b68f4d
Parametrize probes ( #310 )
...
This PR addresses #307 by parametrizing Probes and moving them to
values.yaml
---------
Signed-off-by: Mariusz Sabath <[email protected] >
2023-05-25 08:53:44 -04:00
Mariusz Sabath
e4447fd8eb
Upgrade Tornjak to new image v1.2.1 ( #299 )
...
This upgrade enables the production version of React in Tornjak Frontend
with a smaller footprint and faster startup time.
Using Tornjak v1.2.1 release
https://github.com/spiffe/tornjak/releases/tag/v1.2.1
---------
Signed-off-by: Mariusz Sabath <[email protected] >
2023-05-23 13:32:20 -04:00
Faisal Memon and kfox1111
1922085ba7
Fix hooks for K3s ( #305 )
...
Co-authored-by: kfox1111 <[email protected] >
2023-05-23 08:59:21 -07:00
kfox1111 and Marco Franssen
88efc77bee
Allow to use spire-server as an upstream authority ( #304 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-05-23 14:39:37 +00:00
0ba03880a1
Add support for spire-server ingress ( #68 )
...
Co-authored-by: Faisal Memon <[email protected] >
Co-authored-by: Marco Franssen <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-23 13:58:58 +00:00
Marco Franssen
9975e58f5c
Merge pull request #245 from spiffe/tags
2023-05-18 09:18:22 +02:00
kfox1111
f8db5a313b
Fix Tornjak persistence issue ( #294 )
2023-05-18 01:54:26 +02:00
Marco Franssen
90c9eb50f9
Fix kubectl-image macro to handle version deprecation
...
Signed-off-by: Marco Franssen <[email protected] >
2023-05-17 20:21:07 +02:00
kfox1111
aed6fdfe4e
Use the correct kubectl for the cluster ( #248 )
2023-05-16 20:28:53 +02:00
Marco Franssen
a11cfc99ac
Allow to define the resources for tornjak backend
...
Signed-off-by: Marco Franssen <[email protected] >
2023-05-16 19:31:38 +02:00
Mariusz Sabath and Marco Franssen
7521cafcc6
Update charts/spire/charts/spire-server/templates/tornjak-config.yaml
...
Co-authored-by: Marco Franssen <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
2023-05-16 19:31:38 +02:00
Mariusz Sabath and Marco Franssen
b64c352b15
Update charts/spire/charts/spire-server/templates/tests/test-tornjak-connection.yaml
...
Co-authored-by: Marco Franssen <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
2023-05-16 19:31:38 +02:00
Marco Franssen
6ddf6ab9fa
Improve tornjak docs ( #276 )
...
- Align tornjak backend naming with same convention as frontend
- Align Tornjak backend and frontend notes style
- Add disclaimer for Tornjak usage to example
---------
Signed-off-by: Marco Franssen <[email protected] >
2023-05-16 19:31:38 +02:00