* Update spike bits
Signed-off-by: Kevin Fox <[email protected]>
* Update
Signed-off-by: Kevin Fox <[email protected]>
* Update
Signed-off-by: Kevin Fox <[email protected]>
* Add trust roots.
SPIKE SDK uses the appropriate trust root from the environment which makes SDK usage easier, but it requires additional env vars on the pod meta.
Signed-off-by: Volkan Özçelik <[email protected]>
* Chart updates to make it work with the new SDK changes of SPIKE.
Signed-off-by: Volkan Özçelik <[email protected]>
* Making the self-reference more evident.
Signed-off-by: Volkan Özçelik <[email protected]>
* Documentation update.
Signed-off-by: Volkan Özçelik <[email protected]>
* Documentation update.
Signed-off-by: Volkan Özçelik <[email protected]>
* updates to align with recent SPIKE.
* SPIKE assumes all trust roots can be arrays (for distributed setups), modified values accordingly.
* Added cross-references between bootstrap and keeper job/statefulsets for PoP validation to work.
* other possible minor updates.
Signed-off-by: Volkan Özçelik <[email protected]>
* minor changes.
Signed-off-by: Volkan Özçelik <[email protected]>
* Update docs
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: Volkan Özçelik <[email protected]>
Co-authored-by: Volkan Özçelik <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
* Update for 1.12.3
Signed-off-by: Kevin Fox <[email protected]>
* Fix typo. Use test image
Signed-off-by: Kevin Fox <[email protected]>
* Fix lint
Signed-off-by: Kevin Fox <[email protected]>
* Fix format flag. Update config location for k8s configmap bp
Signed-off-by: Kevin Fox <[email protected]>
* Fix role
Signed-off-by: Kevin Fox <[email protected]>
* Update rbac
Signed-off-by: Kevin Fox <[email protected]>
* Fix key
Signed-off-by: Kevin Fox <[email protected]>
* Fix format
Signed-off-by: Kevin Fox <[email protected]>
* Fix the bundle format for the fetchca bits
Signed-off-by: Kevin Fox <[email protected]>
* Update key
Signed-off-by: Kevin Fox <[email protected]>
* Fix test rather then reconfigure
Signed-off-by: Kevin Fox <[email protected]>
* Add namespace
Signed-off-by: Kevin Fox <[email protected]>
* Update to follow the new patch
Signed-off-by: Kevin Fox <[email protected]>
* Fix formatting
Signed-off-by: Kevin Fox <[email protected]>
* Fix formatting
Signed-off-by: Kevin Fox <[email protected]>
* Update filename based on format
Signed-off-by: Kevin Fox <[email protected]>
* Add upgrade notes
Signed-off-by: Kevin Fox <[email protected]>
* Enable running the oidc discovery provider without cluster-admin/CSI
Signed-off-by: Kevin Fox <[email protected]>
* Calm lint
Signed-off-by: Kevin Fox <[email protected]>
* Switch to testing nightly. Dont manage bundle configmap.
Signed-off-by: Kevin Fox <[email protected]>
* Update permissions
Signed-off-by: Kevin Fox <[email protected]>
* Update permissions
Signed-off-by: Kevin Fox <[email protected]>
* Update permissions
Signed-off-by: Kevin Fox <[email protected]>
* Update for final release
Signed-off-by: Kevin Fox <[email protected]>
* Update for final 1.12.4 release
Signed-off-by: Kevin Fox <[email protected]>
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Update docs
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
* Update for 1.12.3
Signed-off-by: Kevin Fox <[email protected]>
* Fix typo. Use test image
Signed-off-by: Kevin Fox <[email protected]>
* Fix lint
Signed-off-by: Kevin Fox <[email protected]>
* Fix format flag. Update config location for k8s configmap bp
Signed-off-by: Kevin Fox <[email protected]>
* Fix role
Signed-off-by: Kevin Fox <[email protected]>
* Update rbac
Signed-off-by: Kevin Fox <[email protected]>
* Fix key
Signed-off-by: Kevin Fox <[email protected]>
* Fix format
Signed-off-by: Kevin Fox <[email protected]>
* Fix the bundle format for the fetchca bits
Signed-off-by: Kevin Fox <[email protected]>
* Update key
Signed-off-by: Kevin Fox <[email protected]>
* Fix test rather then reconfigure
Signed-off-by: Kevin Fox <[email protected]>
* Add namespace
Signed-off-by: Kevin Fox <[email protected]>
* Update to follow the new patch
Signed-off-by: Kevin Fox <[email protected]>
* Fix formatting
Signed-off-by: Kevin Fox <[email protected]>
* Fix formatting
Signed-off-by: Kevin Fox <[email protected]>
* Update filename based on format
Signed-off-by: Kevin Fox <[email protected]>
* Add upgrade notes
Signed-off-by: Kevin Fox <[email protected]>
* Switch to testing nightly. Dont manage bundle configmap.
Signed-off-by: Kevin Fox <[email protected]>
* Update permissions
Signed-off-by: Kevin Fox <[email protected]>
* Update permissions
Signed-off-by: Kevin Fox <[email protected]>
* Update permissions
Signed-off-by: Kevin Fox <[email protected]>
* Update for final release
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
* Update spire-controller-manager to 0.6.2 and add its staticManifest support
Signed-off-by: Kevin Fox <[email protected]>
* Update docs
Signed-off-by: Kevin Fox <[email protected]>
* Fix indent
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
* Fix bitnami chart dependencies
There have been problems with the old style bitami repo. Bitnami is
suggesting users switch to oci for their charts.
Signed-off-by: Kevin Fox <[email protected]>
* Fix repos
Signed-off-by: Kevin Fox <[email protected]>
* Fix repos
Signed-off-by: Kevin Fox <[email protected]>
* Fix updater script
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
* Add validating admission policy to restrict upstream driver access
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/charts/spiffe-csi-driver/templates/policy.yaml
Signed-off-by: kfox1111 <[email protected]>
* Fix logic
Signed-off-by: Kevin Fox <[email protected]>
* Upgrade helm
Signed-off-by: Kevin Fox <[email protected]>
* Upgrade kind and fix node version
Signed-off-by: Kevin Fox <[email protected]>
* Upgrade kind and fix node version
Signed-off-by: Kevin Fox <[email protected]>
* Upgrade kind and fix node version
Signed-off-by: Kevin Fox <[email protected]>
* Upgrade kind and fix node version
Signed-off-by: Kevin Fox <[email protected]>
* Add version info
Signed-off-by: Kevin Fox <[email protected]>
* Add version info
Signed-off-by: Kevin Fox <[email protected]>
* Fix kind version
Signed-off-by: Kevin Fox <[email protected]>
* Fix kind version
Signed-off-by: Kevin Fox <[email protected]>
* Fix kind version
Signed-off-by: Kevin Fox <[email protected]>
* Fix detection
Signed-off-by: Kevin Fox <[email protected]>
* Just for testing...
Signed-off-by: Kevin Fox <[email protected]>
* Just for testing...
Signed-off-by: Kevin Fox <[email protected]>
* Just for testing
Signed-off-by: Kevin Fox <[email protected]>
* Fix policy
Signed-off-by: Kevin Fox <[email protected]>
* Fix policy
Signed-off-by: Kevin Fox <[email protected]>
* Fix policy
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/charts/spiffe-csi-driver/values.yaml
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Update docs
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
* Add support for the new hint spire-controller-manager feature
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Add support for the new fallback spire-controller-manager feature
Signed-off-by: Kevin Fox <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
* Add a spire-agent auto kubelet verification mode
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
* Support ipv4 only clusters
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/charts/spiffe-oidc-discovery-provider/templates/configmap.yaml
Signed-off-by: kfox1111 <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Fix permission issue with 1.10 and defaults when upgraded
Signed-off-by: Kevin Fox <[email protected]>
* Fix indenting
Signed-off-by: Kevin Fox <[email protected]>
* incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
* Allow configuring persistence in the spire-agent
Signed-off-by: Kevin Fox <[email protected]>
* Better wording. Leave space for other services if needed some day.
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
* Update to SPIRE 1.10.0
Remove the options that were removed in 1.10, and update.
Signed-off-by: Kevin Fox <[email protected]>
* Update docs
Signed-off-by: Kevin Fox <[email protected]>
* Fix uid mismatch issue on 1.10.0+
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
When both federation certificates and upstream authority both
use cert-manager, there is a naming conflict.
Signed-off-by: Kevin Fox <[email protected]>
* Complete Server K8S PSAT support
Add all the SPIRE Server supported options for the K8S PSAT attestor. This retains the
ease of use for configuring local cluster support while adding the ability to configure
multiple/external clusters as well. Kubeconfig support is added in its own config block
as it will be used/shared with spire-controller-manager support in the future.
Signed-off-by: Kevin Fox <[email protected]>
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected]>
* Add support for integration tests in the tests/integration dir
Signed-off-by: Kevin Fox <[email protected]>
* Fix split issue and typo
Signed-off-by: Kevin Fox <[email protected]>
* Add basic psat test
Signed-off-by: Kevin Fox <[email protected]>
* Fix linter
Signed-off-by: Kevin Fox <[email protected]>
* Fix up test
Signed-off-by: Kevin Fox <[email protected]>
* Add missing file
Signed-off-by: Kevin Fox <[email protected]>
* Better encode config
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Update docs
Signed-off-by: Kevin Fox <[email protected]>
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
* Add external k8s bundler
Adds support to sync the CA bundle to configmaps in external
Kubernetes clusters
Signed-off-by: Kevin Fox <[email protected]>
* Update default
Signed-off-by: Kevin Fox <[email protected]>
* Fix config file layout. Incorperate feedback.
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Update based on parent pr feedback
Signed-off-by: Kevin Fox <[email protected]>
* Reformat config file
Signed-off-by: Kevin Fox <[email protected]>
* Fix some things
Signed-off-by: Kevin Fox <[email protected]>
* Reconfigure kind
Signed-off-by: Kevin Fox <[email protected]>
* More debugging
Signed-off-by: Kevin Fox <[email protected]>
* Fix up kind
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Add external spire-controller-managers
Only one external controller manager is supported at a time until
https://github.com/spiffe/spire/issues/4898 is resolved.
Signed-off-by: Kevin Fox <[email protected]>
* Fix tests
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Upgrade to spire-controller-manager 0.5.0
Signed-off-by: Kevin Fox <[email protected]>
* Update for released 0.5.0
Signed-off-by: Kevin Fox <[email protected]>
* Merge in some of the id prefix pr
Signed-off-by: Kevin Fox <[email protected]>
* Entry ID Prefix (#287)
* Add Entry ID Prefix support
Signed-off-by: Kevin Fox <[email protected]>
* Mulitcluster test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Implement cleanup setting too
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
* Bump up test container
Signed-off-by: Kevin Fox <[email protected]>
* Swith to testing with nightly
Signed-off-by: Kevin Fox <[email protected]>
* Fix value name
Signed-off-by: Kevin Fox <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Fix up doc formatting
Signed-off-by: Kevin Fox <[email protected]>
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
Changes the default service port for the spire-server to 443 to allow easier switching between internal access and external access through an ingress controller.
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: Faisal Memon <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
When you have multiple spire servers, they often all need to be
configured to use the same storage class. Let them all be set
to the same value all at once.
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
* nameOverride autoconfig support
When setting up nested charts with nameOverride, you need to
be able to inform other charts about the override.
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
When installing with nodeAttestor.k8sPsat.enabled=false and no
kubeConfig yet or with .Values.notifier.k8sbundle.enabled=false and no
kubeConfig yet, it produces a bad config file.
Signed-off-by: Kevin Fox <[email protected]>
* Change production example to be an integration test
The documentation is a better example then the test now. Separate the
two.
Signed-off-by: Kevin Fox <[email protected]>
* Fix job name reference
Signed-off-by: Kevin Fox <[email protected]>
* Fix job name reference
Signed-off-by: Kevin Fox <[email protected]>
* Update postgresql example
Signed-off-by: Kevin Fox <[email protected]>
* Update mysql example
Signed-off-by: Kevin Fox <[email protected]>
* Update nested and mysql
Signed-off-by: Kevin Fox <[email protected]>
* Fix typo
Signed-off-by: Kevin Fox <[email protected]>
* Add support for integration tests in the tests/integration dir
Signed-off-by: Kevin Fox <[email protected]>
* Fix split issue and typo
Signed-off-by: Kevin Fox <[email protected]>
* Fix split issue
Signed-off-by: Kevin Fox <[email protected]>
* Try folding example your values into bash so that its not laying around in an fs for a user to accidently use.
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Fix test
Signed-off-by: Kevin Fox <[email protected]>
* Cleanup
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
* Add direct tpm support for spire-agent
Signed-off-by: Kevin Fox <[email protected]>
* Add fingerprinting support
Signed-off-by: Kevin Fox <[email protected]>
* Add example
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/charts/spire-agent/templates/configmap.yaml
Signed-off-by: kfox1111 <[email protected]>
* Support hybrid nodes with different attestors
In some clusters, you may have a mix of nodes with differing attestor
needs. For example, some nodes have hardware TPMs and some without.
This patch enables configuring multiple daemonsets for the agent
that you can target to pools of nodes.
Signed-off-by: Kevin Fox <[email protected]>
* Remove extra slash
Signed-off-by: Kevin Fox <[email protected]>
* Update docs
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/charts/spire-agent/templates/configmap.yaml
Signed-off-by: kfox1111 <[email protected]>
* Fix broken tests
Signed-off-by: Kevin Fox <[email protected]>
* Add daemonset labels
Signed-off-by: Kevin Fox <[email protected]>
* Add temporary upgrade hook
Signed-off-by: Kevin Fox <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
* Fix include
Signed-off-by: Kevin Fox <[email protected]>
* Add missing values
Signed-off-by: Kevin Fox <[email protected]>
* Fix perms, add upgrade note
Signed-off-by: Kevin Fox <[email protected]>
* Fix hardcoded nodeAttestor and keyManager in spire-agent
Fixes: https://github.com/spiffe/helm-charts-hardened/issues/220
Signed-off-by: Kevin Fox <[email protected]>
* Fix merge issues
Signed-off-by: Kevin Fox <[email protected]>
* Fix unit tests
Signed-off-by: Kevin Fox <[email protected]>
* Pass the agent's securityContext on to Kubernetes
Currently its ignored.
Signed-off-by: Kevin Fox <[email protected]>
* Update example to be usable
Signed-off-by: Kevin Fox <[email protected]>
* Apply suggestions from code review
Signed-off-by: kfox1111 <[email protected]>
* Update example
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Fix merge conflict issue
Signed-off-by: Kevin Fox <[email protected]>
* Update to the newest release
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Apply suggestions from code review
Signed-off-by: kfox1111 <[email protected]>
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Fix version numbers in docs
Signed-off-by: Kevin Fox <[email protected]>
* Remove merge conflicted extra code
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
* Complete Server K8S PSAT support
Add all the SPIRE Server supported options for the K8S PSAT attestor. This retains the
ease of use for configuring local cluster support while adding the ability to configure
multiple/external clusters as well. Kubeconfig support is added in its own config block
as it will be used/shared with spire-controller-manager support in the future.
Signed-off-by: Kevin Fox <[email protected]>
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected]>
* Add support for integration tests in the tests/integration dir
Signed-off-by: Kevin Fox <[email protected]>
* Fix split issue and typo
Signed-off-by: Kevin Fox <[email protected]>
* Add basic psat test
Signed-off-by: Kevin Fox <[email protected]>
* Fix linter
Signed-off-by: Kevin Fox <[email protected]>
* Fix up test
Signed-off-by: Kevin Fox <[email protected]>
* Add missing file
Signed-off-by: Kevin Fox <[email protected]>
* Better encode config
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Update docs
Signed-off-by: Kevin Fox <[email protected]>
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
* Add external k8s bundler
Adds support to sync the CA bundle to configmaps in external
Kubernetes clusters
Signed-off-by: Kevin Fox <[email protected]>
* Update default
Signed-off-by: Kevin Fox <[email protected]>
* Fix config file layout. Incorperate feedback.
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Update based on parent pr feedback
Signed-off-by: Kevin Fox <[email protected]>
* Reformat config file
Signed-off-by: Kevin Fox <[email protected]>
* Fix some things
Signed-off-by: Kevin Fox <[email protected]>
* Reconfigure kind
Signed-off-by: Kevin Fox <[email protected]>
* More debugging
Signed-off-by: Kevin Fox <[email protected]>
* Fix up kind
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
* Complete Server K8S PSAT support
Add all the SPIRE Server supported options for the K8S PSAT attestor. This retains the
ease of use for configuring local cluster support while adding the ability to configure
multiple/external clusters as well. Kubeconfig support is added in its own config block
as it will be used/shared with spire-controller-manager support in the future.
Signed-off-by: Kevin Fox <[email protected]>
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected]>
* Add support for integration tests in the tests/integration dir
Signed-off-by: Kevin Fox <[email protected]>
* Fix split issue and typo
Signed-off-by: Kevin Fox <[email protected]>
* Add basic psat test
Signed-off-by: Kevin Fox <[email protected]>
* Fix linter
Signed-off-by: Kevin Fox <[email protected]>
* Fix up test
Signed-off-by: Kevin Fox <[email protected]>
* Add missing file
Signed-off-by: Kevin Fox <[email protected]>
* Better encode config
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Update docs
Signed-off-by: Kevin Fox <[email protected]>
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
* Update default
Signed-off-by: Kevin Fox <[email protected]>
* Fix config file layout. Incorperate feedback.
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Fix up kind
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
A duplicate section was added due to incorrect merge conflict resolution.
Helm seems ok with it but Kustomize + FluxCD has issues with it.
Signed-off-by: Kevin Fox <[email protected]>
Adds a global.spire.caSubject section where you can set the CA
subject information for all spire-server instances.
Signed-off-by: Kevin Fox <[email protected]>
* Add support for specifying server admin_ids
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/charts/spire-server/templates/configmap.yaml
Signed-off-by: kfox1111 <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
* Add support for integration tests in the tests/integration dir
Signed-off-by: Kevin Fox <[email protected]>
* Fix split issue and typo
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
* Add alternate name support for the socket
Signed-off-by: Kevin Fox <[email protected]>
* Fix missing image reference
Signed-off-by: Kevin Fox <[email protected]>
* Make user changing socket work smoothly.
Signed-off-by: Kevin Fox <[email protected]>
* Apply suggestions from code review
Signed-off-by: kfox1111 <[email protected]>
* Update charts/spire/charts/spire-agent/values.yaml
Signed-off-by: kfox1111 <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>