spire-helm-version-checker[bot] and marcofranssen
c507ee0ea3
Bump test chart dependencies ( #397 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
2024-07-15 15:14:13 +02:00
tuxotron and kfox1111
199bb6f998
Add connect by hostname to agent cofigmap ( #392 )
...
When setting the kubeletConnectByHostname to "true", the charts update the agent daemonset to define the MY_NODE_NAME environment variable, but it doesn't set the "node_name_env" setting in the WorkloadAttestor:k8s plugin, therefore the agent continues trying to connect to the kubelet using the localhost interface
Signed-off-by: tuxotron <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2024-07-11 12:47:57 -07:00
Mariusz Sabath and kfox1111
eb6d89b472
Update charts/spire/README.md
...
Co-authored-by: kfox1111 <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
2024-07-09 14:08:55 -04:00
Mariusz Sabath
c93ad87c15
Add valid kubectl version to examples
...
Signed-off-by: Mariusz Sabath <[email protected] >
2024-07-09 11:42:27 -04:00
spire-helm-version-checker[bot] and marcofranssen
500fdd9ac3
Bump test chart dependencies ( #391 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
2024-07-08 12:03:03 +02:00
spire-helm-version-checker[bot] and marcofranssen
08fc5f3d46
Bump test chart dependencies ( #390 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
2024-07-01 08:20:53 +00:00
spire-helm-version-checker[bot] and marcofranssen
690429525c
Bump test chart dependencies ( #389 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
2024-06-24 08:20:59 +00:00
Mariusz Sabath
fb7fb809fa
Fix format for ignoreNamespaces ( #388 )
...
Signed-off-by: Mariusz Sabath <[email protected] >
2024-06-23 16:29:39 -07:00
knp-sap
7a0a77b6b8
Fix host path of "spire-agent-admin-socket-dir" volume ( #386 )
...
Signed-off-by: knp-sap <[email protected] >
2024-06-23 09:54:39 -07:00
kfox1111 and aniket patel
1d2d7550c5
Add resource limits for upgrade and delete hook batch jobs ( #366 )
...
* Add resource limits for upgrade and delete hook batch jobs
Signed-off-by: aniket patel <[email protected] >
* Fix value of resource
Signed-off-by: aniket patel <[email protected] >
* Fix resource limit in server template
Signed-off-by: aniket patel <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Fix up doc comment
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: aniket patel <[email protected] >
Signed-off-by: Kevin Fox <[email protected] >
Co-authored-by: aniket patel <[email protected] >
2024-06-19 12:50:21 -07:00
tuxotron and kfox1111
f7e0d4b831
Update _spire-system-namespace.yaml ( #381 )
...
set right namespace labels
Signed-off-by: tuxotron <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2024-06-17 16:56:35 -07:00
marcofranssen
29d4b57373
Bump test chart dependencies
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2024-06-17 11:37:20 +02:00
spire-helm-version-checker[bot] and marcofranssen
4c9059ea52
Bump test chart dependencies ( #379 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
2024-06-10 05:24:55 -07:00
1dc650f06e
Apply wildcard for ignoreNamespaces in Controller Manager ( #378 )
...
* Apply wildcard for ignoreNamespaces in Controller Manager
Signed-off-by: Mariusz Sabath <[email protected] >
* Add the doc updates
Signed-off-by: Mariusz Sabath <[email protected] >
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: kfox1111 <[email protected] >
Signed-off-by: Edwin Buck <[email protected] >
---------
Signed-off-by: Mariusz Sabath <[email protected] >
Signed-off-by: Edwin Buck <[email protected] >
Co-authored-by: Edwin Buck <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2024-06-06 15:56:15 -07:00
spire-helm-version-checker[bot] and marcofranssen
6c2b5e64cc
Bump test chart dependencies ( #376 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
2024-06-03 06:50:32 -07:00
Faisal Memon
7eb8c6c98d
Bump spire-nested Helm Chart version from 0.20.0 to 0.21.0
...
Signed-off-by: Faisal Memon <[email protected] >
2024-05-30 15:27:28 -07:00
Faisal Memon
63853f5494
Bump spire Helm Chart version from 0.20.0 to 0.21.0 ( #373 )
...
* 54a2f03 Change cleanup default (#349 )
* d29ad06 Bump test chart dependencies (#369 )
* 7dabbf1 Add Openshift ignore namespaces to Controller Manager (#363 )
* db177d4 Fix spelling error in Controller Manager config (#362 )
* d236154 Fix upstream ca name suffix issue (#361 )
* bfcf418 Bump test chart dependencies (#359 )
* c31a2e9 Bump up spire to 1.9.6 (#356 )
* 2c5dfa0 Improve Tornjak NOTES. Fixes #132 (#354 )
* a453a2c Bump test chart dependencies (#355 )
* b6575c1 Update Tornjak deployment docs (#288 )
* be560d9 Check for a misconfiguration of bundle endpoint profiles (#348 )
* b2e9f40 Bump spire version (#352 )
* 7165b20 Bump test chart dependencies (#350 )
* da4ebdf Fix federation certificate name when upstream enabled (#347 )
* c37de1e Fix Tornjak logsDir for Openshift (#344 )
* 8fef1bd Add external spire-controller-managers (#284 )
* ee12404 set refresh hint to 1/3 of default CA TTL value fixes #335 (#343 )
* 2d9866a Bump test chart dependencies (#338 )
* 6de23d3 Don't create role/binding when bundle disabled (#336 )
* c132cc4 Add support for externalServer=true (#303 )
* a2494ee Add auth option for Tornjak (#259 )
* f679a0d Bump test chart dependencies (#333 )
* 5149256 Work around curl change
* 3d2ac16 Bump test chart dependencies
* 08f699b Add spire-lib chart (#289 )
* 260b02f Add an easy to use identity for child servers (#302 )
Signed-off-by: Faisal Memon <[email protected] >
2024-05-30 22:00:00 +00:00
kfox1111 and Faisal Memon
54a2f036bf
Change cleanup default ( #349 )
...
* Change cleanup default
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Update charts/spire/README.md
Signed-off-by: kfox1111 <[email protected] >
* Update charts/spire/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix merge issue and incorperate feedback.
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-05-30 12:22:03 -07:00
d29ad0649f
Bump test chart dependencies ( #369 )
...
* Bump test chart dependencies
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* Remove workaround as they fixed curl
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: Kevin Fox <[email protected] >
Co-authored-by: marcofranssen <[email protected] >
Co-authored-by: Kevin Fox <[email protected] >
2024-05-27 06:36:36 -07:00
Mariusz Sabath
7dabbf16d3
Add Openshift ignore namespaces to Controller Manager ( #363 )
...
* Fix spelling error in Controller Manager config
Signed-off-by: Mariusz Sabath <[email protected] >
* Add ignoreNamespaces to ControllerManager for Openshift
Signed-off-by: Mariusz Sabath <[email protected] >
---------
Signed-off-by: Mariusz Sabath <[email protected] >
2024-05-26 07:55:26 -07:00
Mariusz Sabath
db177d4b85
Fix spelling error in Controller Manager config ( #362 )
...
Signed-off-by: Mariusz Sabath <[email protected] >
2024-05-23 19:26:44 +00:00
kfox1111
d2361549db
Fix upstream ca name suffix issue ( #361 )
...
* Fix upstream ca name suffix issue
Signed-off-by: Kevin Fox <[email protected] >
* Fix quoting
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
2024-05-23 09:43:19 -07:00
kfox1111 and Faisal Memon
a2689c986c
Add spire-nested chart ( #294 )
...
* Complete Server K8S PSAT support
Add all the SPIRE Server supported options for the K8S PSAT attestor. This retains the
ease of use for configuring local cluster support while adding the ability to configure
multiple/external clusters as well. Kubeconfig support is added in its own config block
as it will be used/shared with spire-controller-manager support in the future.
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Add support for integration tests in the tests/integration dir
Signed-off-by: Kevin Fox <[email protected] >
* Fix split issue and typo
Signed-off-by: Kevin Fox <[email protected] >
* Add basic psat test
Signed-off-by: Kevin Fox <[email protected] >
* Fix linter
Signed-off-by: Kevin Fox <[email protected] >
* Fix up test
Signed-off-by: Kevin Fox <[email protected] >
* Add missing file
Signed-off-by: Kevin Fox <[email protected] >
* Better encode config
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Update docs
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Add external k8s bundler
Adds support to sync the CA bundle to configmaps in external
Kubernetes clusters
Signed-off-by: Kevin Fox <[email protected] >
* Update default
Signed-off-by: Kevin Fox <[email protected] >
* Fix config file layout. Incorperate feedback.
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Update based on parent pr feedback
Signed-off-by: Kevin Fox <[email protected] >
* Reformat config file
Signed-off-by: Kevin Fox <[email protected] >
* Fix some things
Signed-off-by: Kevin Fox <[email protected] >
* Reconfigure kind
Signed-off-by: Kevin Fox <[email protected] >
* More debugging
Signed-off-by: Kevin Fox <[email protected] >
* Fix up kind
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Add external spire-controller-managers
Only one external controller manager is supported at a time until
https://github.com/spiffe/spire/issues/4898 is resolved.
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Add Entry ID Prefix support
Signed-off-by: Kevin Fox <[email protected] >
* Mulitcluster test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Implement cleanup setting too
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Make spire-lib bits into its own library chart.
Signed-off-by: Kevin Fox <[email protected] >
* Add spire-nested chart
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Fix lint issue
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Add missing file
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Add nameOverride option
Signed-off-by: Kevin Fox <[email protected] >
* Simplify upstream config. Reorder test for faster executation
Signed-off-by: Kevin Fox <[email protected] >
* Enable service account allow list to calculate namespace
Signed-off-by: Kevin Fox <[email protected] >
* Add identity type for child servers
Signed-off-by: Kevin Fox <[email protected] >
* Enable name override setting
Signed-off-by: Kevin Fox <[email protected] >
* Fix printing
Signed-off-by: Kevin Fox <[email protected] >
* Fix formatting
Signed-off-by: Kevin Fox <[email protected] >
* Fix name length issue
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Switch to non cluster-admin user
Signed-off-by: Kevin Fox <[email protected] >
* Test out adding roles
Signed-off-by: Kevin Fox <[email protected] >
* Namespace needs to exist
Signed-off-by: Kevin Fox <[email protected] >
* Remove tty
Signed-off-by: Kevin Fox <[email protected] >
* Fix name
Signed-off-by: Kevin Fox <[email protected] >
* Add missing role
Signed-off-by: Kevin Fox <[email protected] >
* Add kind=none to not require extra objects
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Remove unneeded code
Signed-off-by: Kevin Fox <[email protected] >
* Add security cluster example
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Dont preinstall crds for nested-security
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Fix address
Signed-off-by: Kevin Fox <[email protected] >
* Update port
Signed-off-by: Kevin Fox <[email protected] >
* Update psat setting
Signed-off-by: Kevin Fox <[email protected] >
* Update psat setting
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Remove older tests that newer tests cover
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix kind logic
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Seems unneeded. Try and remove
Signed-off-by: Kevin Fox <[email protected] >
* Update the default ports to be more user friendly
Signed-off-by: Kevin Fox <[email protected] >
* See if we can leave controller manager port alone
Signed-off-by: Kevin Fox <[email protected] >
* Change the agent default port too
Signed-off-by: Kevin Fox <[email protected] >
* Bump up test container
Signed-off-by: Kevin Fox <[email protected] >
* Swith to testing with nightly
Signed-off-by: Kevin Fox <[email protected] >
* Fix value name
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Upgrade to spire-controller-manager 0.5.0
Signed-off-by: Kevin Fox <[email protected] >
* Try to isolate config differences just to child cluster
Signed-off-by: Kevin Fox <[email protected] >
* Update for released 0.5.0
Signed-off-by: Kevin Fox <[email protected] >
* Merge in some of the id prefix pr
Signed-off-by: Kevin Fox <[email protected] >
* Entry ID Prefix (#287 )
* Add Entry ID Prefix support
Signed-off-by: Kevin Fox <[email protected] >
* Mulitcluster test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Implement cleanup setting too
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Bump up test container
Signed-off-by: Kevin Fox <[email protected] >
* Swith to testing with nightly
Signed-off-by: Kevin Fox <[email protected] >
* Fix value name
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix up doc formatting
Signed-off-by: Kevin Fox <[email protected] >
* Revert notes
Signed-off-by: Kevin Fox <[email protected] >
* Use tags for nested chart
Signed-off-by: Kevin Fox <[email protected] >
* Add missing tag
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix formatting
Signed-off-by: Kevin Fox <[email protected] >
* Fix class name
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict issue
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge issue
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge issue
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback. Switch setting to be externalServer.
Signed-off-by: Kevin Fox <[email protected] >
* Update nested chart to use new setting
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge issue
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Add docs about which sections are used with which tags
Signed-off-by: Kevin Fox <[email protected] >
* Update versions
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-05-20 08:58:22 -07:00
spire-helm-version-checker[bot] and marcofranssen
bfcf418301
Bump test chart dependencies ( #359 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
2024-05-20 06:33:31 -07:00
kfox1111
c31a2e9f65
Bump up spire to 1.9.6 ( #356 )
...
Signed-off-by: Kevin Fox <[email protected] >
2024-05-16 09:20:14 -07:00
Mariusz Sabath
2c5dfa010f
Improve Tornjak NOTES. Fixes #132 ( #354 )
...
* Improve Tornjak NOTES. Fixes #132
Signed-off-by: Mariusz Sabath <[email protected] >
* Fix Tornjak ingress value
Signed-off-by: Mariusz Sabath <[email protected] >
---------
Signed-off-by: Mariusz Sabath <[email protected] >
2024-05-14 13:52:55 -07:00
spire-helm-version-checker[bot] and marcofranssen
a453a2c1b4
Bump test chart dependencies ( #355 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
2024-05-13 13:11:02 +02:00
b6575c172d
Update Tornjak deployment docs ( #288 )
...
* Update Tornjak deployment docs
Signed-off-by: Mariusz Sabath <[email protected] >
* Change the reference for installing standard Tornjak
Signed-off-by: Mariusz Sabath <[email protected] >
* Update examples/tornjak/README.md
Co-authored-by: kfox1111 <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
* Adjust deployment paths
Signed-off-by: Mariusz Sabath <[email protected] >
* Remove the production README changes
Signed-off-by: Mariusz Sabath <[email protected] >
* Minor text edits
Signed-off-by: Mariusz Sabath <[email protected] >
* Fix incorrect namespace value
Signed-off-by: Mariusz Sabath <[email protected] >
* Updat Tornjak README
Signed-off-by: Mariusz Sabath <[email protected] >
* Update Keycloak README
Signed-off-by: Mariusz Sabath <[email protected] >
* Text updates in Keycloak doc
Signed-off-by: Mariusz Sabath <[email protected] >
* Post-review updates
Signed-off-by: Mariusz Sabath <[email protected] >
* Update Tornjak message for User Management
Signed-off-by: Mariusz Sabath <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Mohammed Abdi <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
* Update Tornjak deployment doc
Signed-off-by: Mariusz Sabath <[email protected] >
* Improve the Tornjak Auth message
Signed-off-by: Mariusz Sabath <[email protected] >
* Fix error with incorrect Ingress value
Signed-off-by: Mariusz Sabath <[email protected] >
* Fix documentation format
Signed-off-by: Mariusz Sabath <[email protected] >
* Update parameter format
Signed-off-by: Mariusz Sabath <[email protected] >
* Removed redundand doc sections
Signed-off-by: Mariusz Sabath <[email protected] >
---------
Signed-off-by: Mariusz Sabath <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
Co-authored-by: Mohammed Abdi <[email protected] >
2024-05-09 04:26:17 -07:00
kfox1111 and Faisal Memon
be560d95d8
Check for a misconfiguration of bundle endpoint profiles ( #348 )
...
* Check for a misconfiguration of bundle endpoint profiles
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/charts/spire-server/templates/configmap.yaml
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-05-08 03:38:04 +00:00
kfox1111
b2e9f40774
Bump spire version ( #352 )
...
Signed-off-by: Kevin Fox <[email protected] >
2024-05-07 20:16:15 -07:00
spire-helm-version-checker[bot] and marcofranssen
7165b20ddf
Bump test chart dependencies ( #350 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
2024-05-06 12:57:43 -07:00
kfox1111
da4ebdfcaf
Fix federation certificate name when upstream enabled ( #347 )
...
When both federation certificates and upstream authority both
use cert-manager, there is a naming conflict.
Signed-off-by: Kevin Fox <[email protected] >
2024-05-03 14:17:31 -07:00
Mariusz Sabath and kfox1111
c37de1ea0c
Fix Tornjak logsDir for Openshift ( #344 )
...
* Fix Tornjak logsDir for Openshift
Signed-off-by: Mariusz Sabath <[email protected] >
* Update docs
Signed-off-by: Mariusz Sabath <[email protected] >
* Update charts/spire/charts/tornjak-frontend/templates/_helpers.tpl
Co-authored-by: kfox1111 <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
---------
Signed-off-by: Mariusz Sabath <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2024-05-03 08:04:38 -07:00
kfox1111 and Faisal Memon
8fef1bd050
Add external spire-controller-managers ( #284 )
...
* Complete Server K8S PSAT support
Add all the SPIRE Server supported options for the K8S PSAT attestor. This retains the
ease of use for configuring local cluster support while adding the ability to configure
multiple/external clusters as well. Kubeconfig support is added in its own config block
as it will be used/shared with spire-controller-manager support in the future.
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Add support for integration tests in the tests/integration dir
Signed-off-by: Kevin Fox <[email protected] >
* Fix split issue and typo
Signed-off-by: Kevin Fox <[email protected] >
* Add basic psat test
Signed-off-by: Kevin Fox <[email protected] >
* Fix linter
Signed-off-by: Kevin Fox <[email protected] >
* Fix up test
Signed-off-by: Kevin Fox <[email protected] >
* Add missing file
Signed-off-by: Kevin Fox <[email protected] >
* Better encode config
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Update docs
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Add external k8s bundler
Adds support to sync the CA bundle to configmaps in external
Kubernetes clusters
Signed-off-by: Kevin Fox <[email protected] >
* Update default
Signed-off-by: Kevin Fox <[email protected] >
* Fix config file layout. Incorperate feedback.
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Update based on parent pr feedback
Signed-off-by: Kevin Fox <[email protected] >
* Reformat config file
Signed-off-by: Kevin Fox <[email protected] >
* Fix some things
Signed-off-by: Kevin Fox <[email protected] >
* Reconfigure kind
Signed-off-by: Kevin Fox <[email protected] >
* More debugging
Signed-off-by: Kevin Fox <[email protected] >
* Fix up kind
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Add external spire-controller-managers
Only one external controller manager is supported at a time until
https://github.com/spiffe/spire/issues/4898 is resolved.
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Upgrade to spire-controller-manager 0.5.0
Signed-off-by: Kevin Fox <[email protected] >
* Update for released 0.5.0
Signed-off-by: Kevin Fox <[email protected] >
* Merge in some of the id prefix pr
Signed-off-by: Kevin Fox <[email protected] >
* Entry ID Prefix (#287 )
* Add Entry ID Prefix support
Signed-off-by: Kevin Fox <[email protected] >
* Mulitcluster test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Implement cleanup setting too
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Bump up test container
Signed-off-by: Kevin Fox <[email protected] >
* Swith to testing with nightly
Signed-off-by: Kevin Fox <[email protected] >
* Fix value name
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix up doc formatting
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-05-02 21:08:31 +00:00
Drew Wells
ee124042c2
set refresh hint to 1/3 of default CA TTL value fixes #335 ( #343 )
...
Signed-off-by: Drew Wells <[email protected] >
2024-05-02 13:24:51 -07:00
2d9866ada2
Bump test chart dependencies ( #338 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2024-04-29 06:10:16 -07:00
kfox1111
6de23d3303
Don't create role/binding when bundle disabled ( #336 )
...
When the bundle notifier is disabled, there is no need to create
a role and role binding for it.
Signed-off-by: Kevin Fox <[email protected] >
2024-04-26 14:21:16 -07:00
kfox1111
c132cc481e
Add support for externalServer=true ( #303 )
2024-04-26 19:19:01 +00:00
a2494ee45e
Add auth option for Tornjak ( #259 )
...
* Added auth option, specifically keycloak for tornjak production use
Signed-off-by: Mohammed Abdi <[email protected] >
* Added auth values for tornjak
Signed-off-by: Mohammed Abdi <[email protected] >
* Update charts/spire/charts/tornjak-frontend/values.yaml
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* nit
Signed-off-by: Mohammed Abdi <[email protected] >
* nit
Signed-off-by: Mohammed Abdi <[email protected] >
* nit
Signed-off-by: Mohammed Abdi <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Mariusz Sabath <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* nit
Signed-off-by: Mohammed Abdi <[email protected] >
* install keycloak first
Signed-off-by: Mohammed Abdi <[email protected] >
* add logs volume back
Signed-off-by: Mohammed Abdi <[email protected] >
* Fixed NPM init error
Signed-off-by: Mariusz Sabath <[email protected] >
* Fixed the values documentation errors
Signed-off-by: Mariusz Sabath <[email protected] >
* Post-review suggestion fixes
Signed-off-by: Mariusz Sabath <[email protected] >
* Fixed typo
Signed-off-by: Mariusz Sabath <[email protected] >
* Updating Keyclaok examples README
Signed-off-by: Mariusz Sabath <[email protected] >
* Fixed the parameter reference
Signed-off-by: Mariusz Sabath <[email protected] >
* Fix typo
Signed-off-by: Mariusz Sabath <[email protected] >
* use keycloak-config-cli to simplify tornjak realm import
Signed-off-by: MohammedAbdi <[email protected] >
* edit client id
Signed-off-by: MohammedAbdi <[email protected] >
* reverse client id
Signed-off-by: MohammedAbdi <[email protected] >
* fix the doc
Signed-off-by: Mariusz Sabath <[email protected] >
* update tornjak version and backend auth
Signed-off-by: MohammedAbdi <[email protected] >
* update client id
Signed-off-by: MohammedAbdi <[email protected] >
* updates values yaml
Signed-off-by: MohammedAbdi <[email protected] >
* update documentation
Signed-off-by: MohammedAbdi <[email protected] >
* nit
Signed-off-by: MohammedAbdi <[email protected] >
* update doc
Signed-off-by: MohammedAbdi <[email protected] >
* add audience check tornjak
Signed-off-by: MohammedAbdi <[email protected] >
* remove unused file
Signed-off-by: MohammedAbdi <[email protected] >
* update doc
Signed-off-by: MohammedAbdi <[email protected] >
* nit and add auth not enabled warning back
Signed-off-by: MohammedAbdi <[email protected] >
* adjust liveness probe until tornjak handles liveendpoint for auth and direct connection to discovery
Signed-off-by: MohammedAbdi <[email protected] >
* update doc and add keycloak proxy
Signed-off-by: MohammedAbdi <[email protected] >
---------
Signed-off-by: Mohammed Abdi <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
Signed-off-by: MohammedAbdi <[email protected] >
Co-authored-by: Mohammed Abdi <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
Co-authored-by: Mariusz Sabath <[email protected] >
2024-04-25 15:49:20 -07:00
spire-helm-version-checker[bot] and marcofranssen
f679a0dab6
Bump test chart dependencies ( #333 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
2024-04-22 06:34:39 -07:00
Kevin Fox
5149256671
Work around curl change
...
Signed-off-by: Kevin Fox <[email protected] >
2024-04-19 16:36:40 +02:00
marcofranssen
3d2ac166b9
Bump test chart dependencies
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2024-04-19 16:36:40 +02:00
kfox1111 and Marco Franssen
08f699bdb0
Add spire-lib chart ( #289 )
...
* Add spire-lib chart
Make spire-lib bits into its own library chart.
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Marco Franssen <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Move notes back
Signed-off-by: Kevin Fox <[email protected] >
* Fix NOTES
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Marco Franssen <[email protected] >
2024-04-18 08:21:31 -07:00
kfox1111 and Faisal Memon
260b02f973
Add an easy to use identity for child servers ( #302 )
...
Signed-off-by: Kevin Fox <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-04-16 08:35:07 -07:00
Faisal Memon
27689e797b
Bump spire Helm Chart version from 0.19.2 to 0.20.0 ( #329 )
...
* 1bf3aa7 Default spire-server port 443 (#308 )
* 1ef979c Remove upgrade hook needed in 0.19.x (#317 )
* aa92791 Upgrade to spire-controller-manager 0.5.0 (#316 )
* c1e4feb Fix ingress host with a dot (#323 )
* 5b1bf43 Update spire to 1.9.4 (#324 )
* dcd11e9 Fix chainguard issue (#326 )
* bc79f58 AWS KMS key_identifier upgrade (#314 )
Signed-off-by: Faisal Memon <[email protected] >
2024-04-11 16:10:50 -07:00
Faisal Memon
a5613b8cd7
Bump spire-crds Helm Chart version from 0.3.0 to 0.4.0 ( #328 )
...
* aa92791 Upgrade to spire-controller-manager 0.5.0 (#316 )
Signed-off-by: Faisal Memon <[email protected] >
2024-04-11 15:56:57 -07:00
kfox1111 and Faisal Memon
1bf3aa77ef
Default spire-server port 443 ( #308 )
...
Changes the default service port for the spire-server to 443 to allow easier switching between internal access and external access through an ingress controller.
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: Faisal Memon <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-04-11 12:29:28 -07:00
kfox1111 and Faisal Memon
1ef979c4e7
Remove upgrade hook needed in 0.19.x ( #317 )
...
Signed-off-by: Kevin Fox <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-04-11 12:00:34 -07:00
kfox1111
aa92791df2
Upgrade to spire-controller-manager 0.5.0 ( #316 )
...
* Upgrade to spire-controller-manager 0.5.0
Signed-off-by: Kevin Fox <[email protected] >
* Update for released 0.5.0
Signed-off-by: Kevin Fox <[email protected] >
* Fix up doc formatting
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
2024-04-11 11:58:00 -07:00
kfox1111
c1e4feb34d
Fix ingress host with a dot ( #323 )
...
Fixes: https://github.com/spiffe/helm-charts-hardened/issues/312
Signed-off-by: Kevin Fox <[email protected] >
2024-04-11 11:16:08 -07:00