Michael Munch and kfox1111
1ce42d587a
fix(spire-server): support postgres TLS client-certificate (passwordless) auth ( #922 )
...
* fix(spire-server): support postgres TLS client-certificate (passwordless) auth
The postgres datastore always injected a password into the connection
string, always created the -dbpw Secret, and always set the DBPW env var,
with no way to use TLS client-certificate (or IAM) authentication. This
forced a dummy password (e.g. "unused") when authenticating with certs.
- Map dataStore.sql.rootCAPath / clientCertPath / clientKeyPath to the
postgres connection-string options sslrootcert / sslcert / sslkey
(previously these were mysql-only and rejected for postgres). MySQL keeps
using the root_ca_path / client_cert_path / client_key_path plugin fields,
now correctly gated to mysql/aws_mysql only.
- For postgres/aws_postgres, when dataStore.sql.password is empty, omit
"password=${DBPW}" from the connection string and skip creating the -dbpw
Secret and the DBPW/RODBPW env vars (mirrors the existing gcp_mysql_sa_iam
passwordless behavior).
- Add a guard: for postgres, dataStore.sql.password and clientCertPath are
mutually exclusive.
- Fix a stray tab in the mysql client_key_path config field.
- Update value docs and regenerate the README.
Existing configurations with a password set are unaffected.
Signed-off-by: Michael Munch <[email protected] >
* 🐛 fix(spire-server): keep postgres password when external secret is used
The postgres passwordless path keyed only on an empty password, so
enabling dataStore.sql.externalSecret (or readOnly.externalSecret) with
an empty password dropped the password token from the connection string
and skipped the DBPW/RODBPW env vars, breaking external-secret auth.
- Add shared passwordless predicates that also require external secrets
to be disabled, evaluated independently for read-write and read-only.
- Use the predicates in datastore-config, secret.yaml, and
server-resource.yaml so the gating cannot drift.
- Add unit tests for postgres with read-write and read-only external
secrets plus the cert-auth passwordless case.
Signed-off-by: Michael Munch <[email protected] >
* 🔁 ci: re-trigger checks
Re-run CI; the previous spiffe-step-ssh integration job failed on an
unrelated flaky SSH host-key verification on k8s v1.35.1 (passed on
v1.33.7 and v1.34.3).
Signed-off-by: Michael Munch <[email protected] >
---------
Signed-off-by: Michael Munch <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2026-08-20 11:15:26 -07:00
Michael Munch and kfox1111
ab5e5d8677
fix(spiffe-oidc-discovery-provider): run under restricted PSA/SCC on OpenShift ( #920 )
...
* fix(spiffe-oidc-discovery-provider): run under restricted PSA/SCC on OpenShift
The OIDC discovery provider does not require any elevated privileges: it
runs fine under OpenShift's built-in restricted-v2 SCC (non-root, no
privilege escalation, all capabilities dropped, RuntimeDefault seccomp,
read-only root filesystem) and mounts only restricted-compatible volumes
(csi, configMap, emptyDir, secret, projected, downwardAPI).
Despite this, on OpenShift the chart:
- downgraded the spire-server namespace from restricted to privileged PSA
whenever the OIDC provider was enabled, and
- created a fully privileged SecurityContextConstraints (host network/IPC/
PID, privileged container, hostPath, arbitrary seccomp, RunAsAny) bound
to the provider's ServiceAccount.
Both contradict the chart's own Namespaces documentation, which specifies
restricted PSA for spire-server, and violate least privilege for an
internet-facing OIDC endpoint.
Remove the privileged PSA override for the OIDC provider (spire-server
stays restricted; the scc.podSecurityLabelSync=false label is retained)
and drop the privileged SCC so the provider falls through to restricted-v2.
With spire-server enforcing restricted PSA, the inline-CSI PodSecurity
check reads the cluster-scoped CSIDriver's
security.openshift.io/csi-ephemeral-volume-profile label. If the CSIDriver
is not committed before the spire-server StatefulSet (which mounts the
inline upstream.csi.spiffe.io volume) is admitted, the profile defaults to
privileged and admission is denied. Under ArgoCD the CSIDriver and the
server StatefulSet can land in the same sync wave, racing admission.
Annotate the CSIDriver with argocd.argoproj.io/sync-wave: "-1" (OpenShift
only) so it is applied before the default-wave server workloads; the
annotation is inert for plain helm installs.
Signed-off-by: Michael Munch <[email protected] >
* ✨ make CSIDriver sync-wave ordering configurable
Add syncWave and csiDriverAnnotations values to the spiffe-csi-driver
chart so the OpenShift argocd.argoproj.io/sync-wave annotation number
can be overridden (e.g. when the chart is nested) and arbitrary
annotations can be applied to the CSIDriver.
Signed-off-by: Michael Munch <[email protected] >
---------
Signed-off-by: Michael Munch <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2026-08-20 10:51:35 -07:00
Daniel Schlatter
59bb8a774c
Allow sqlite3 in memory when kind is deployment ( #923 )
...
* Allow sqlite3 in memory when kind is deployment
Signed-off-by: Daniel Schlatter <[email protected] >
* Warn on unsafe in-memory datastore combinations
Signed-off-by: Daniel Schlatter <[email protected] >
---------
Signed-off-by: Daniel Schlatter <[email protected] >
2026-08-18 14:22:50 -07:00
Daniel Schlatter and kfox1111
e46ad1594a
Make spire-server rollout strategy configurable ( #924 )
...
Signed-off-by: Daniel Schlatter <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2026-08-18 11:47:36 -07:00
dependabot[bot]
de48d14312
Bump helm.sh/helm/v3 from 3.21.3 to 3.21.4 in /tests
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.21.3 to 3.21.4.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.21.3...v3.21.4 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-version: 3.21.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-08-17 09:51:25 +02:00
dependabot[bot]
d56bfd6804
Bump github.com/onsi/ginkgo/v2 from 2.32.0 to 2.32.1 in /tests ( #915 )
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.32.0 to 2.32.1.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.32.0...v2.32.1 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.32.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-14 08:55:49 -07:00
sabsari and Claude Opus 4.8
648e0e45e5
Add JWT-SVID exec-auth source for kubeConfigs entries ( #907 )
...
Add jwtSVIDExec as a fourth exactly-one kubeConfigs source: the chart
generates an exec-credential kubeconfig that authenticates to an external
cluster with short-lived SPIFFE JWT-SVIDs instead of a static credential.
Signed-off-by: sabsari <[email protected] >
Co-authored-by: Claude Opus 4.8 <[email protected] >
2026-08-11 06:40:05 -07:00
savitha-qs and Savitha Ganapathi
80705999dd
feat(spire-server): support x509pop externalPKI ca bundle ( #908 )
...
* feat(spire-server): support x509pop externalPKI ca bundle
Add externalPKI mode support to the x509pop node attestor configuration.
Allows operators to configure CA bundles for external PKI-based node
attestation via two approaches:
- Inline PEM content (chart creates and manages ConfigMap)
- Reference to existing ConfigMap with ca-bundle.pem key
Includes volume/volumeMount definitions for CA bundle mounting at
/run/spire/data/x509pop-ca-bundle.pem and unit tests for both modes.
Signed-off-by: Savitha Ganapathi <[email protected] >
* refactor: simplify x509pop externalPKI template guard logic
Remove nested conditional guard for ca_bundle_path rendering. When
externalPKI mode is enabled, ca_bundle_path is always rendered; if no
CA bundle is provided, SPIRE will fail at startup with a clear error.
Drop unit tests pending fix to the unit test framework (which currently
has issues loading values from chart, forcing overly-defensive template
guards for test compatibility). Tests can be re-added once framework is
fixed.
Signed-off-by: Savitha Ganapathi <[email protected] >
* refactor: simplify x509pop volume/volumeMount guard logic
Remove nested caBundle existence checks from volume and volumeMount
guard conditions. When externalPKI mode is enabled, volume/volumeMount
are created; if no CA bundle is provided, SPIRE fails at startup with
clear error (missing mount).
Signed-off-by: Savitha Ganapathi <[email protected] >
* refactor: reorder if/with clauses for clarity
Move if condition checks to outer scope before entering with blocks.
This is more idiomatic Helm pattern and avoids unnecessary context
switching if condition fails.
Signed-off-by: Savitha Ganapathi <[email protected] >
* refactor: simplify conditionals to match chart patterns
Replace complex toString/eq comparisons with simpler boolean checks that
match existing patterns in the chart (e.g., federation.tls.certManager.enabled).
Changes:
- .enabled checks: remove toString wrapping, use simple boolean test
- .mode checks: remove toString, use simple eq comparison
- .caBundle checks: simplify from 'ne (... | default "") ""' to simple boolean test
This aligns with chart conventions and avoids tripping broken unit test
framework that struggles with complex conditionals.
Signed-off-by: Savitha Ganapathi <[email protected] >
* test: resurrect x509POP unit tests with simplified conditionals
Re-add unit tests for externalPKI mode now that template conditionals
have been simplified to match chart patterns. Simplified conditionals
should be less fragile with unit test framework.
Tests cover:
- externalPKI with chart-managed CA bundle (inline)
- externalPKI with existing ConfigMap reference
Signed-off-by: Savitha Ganapathi <[email protected] >
* docs: regenerate spire-server README for x509pop caBundle params
Updated parameter documentation for nodeAttestor.x509POP section to
include new caBundle configuration options (inline bundle and existing
ConfigMap reference).
Auto-generated documentation based on @param comments in values.yaml.
Signed-off-by: Savitha Ganapathi <[email protected] >
---------
Signed-off-by: Savitha Ganapathi <[email protected] >
Co-authored-by: Savitha Ganapathi <[email protected] >
2026-08-06 16:48:09 -07:00
sabsari and Claude Opus 4.8
ecf6324d67
Make the external server's downstream RBAC subject configurable ( #899 )
...
Replace the hardcoded `User: spire-root` subject with an `externalServerSubject`
block (`kind`/`name`/`namespace`) so the downstream RBAC can bind to a User,
Group, or ServiceAccount. Defaults preserve the previous behavior.
Signed-off-by: sabsari <[email protected] >
Co-authored-by: Claude Opus 4.8 <[email protected] >
2026-08-03 05:21:14 -07:00
kfox1111 and Faisal Memon
f4c7df239e
Add broker suport to the spire-ha-agent ( #884 )
...
* Add broker suport to the spire-ha-agent
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2026-07-30 13:15:55 -07:00
kfox1111
3cfefb72ba
Gateway api support ( #890 )
...
* Gateway api support
Signed-off-by: Kevin Fox <[email protected] >
* Update readme
Signed-off-by: Kevin Fox <[email protected] >
* Fix gateway name. a gateway doesnt need to be named gateway
Signed-off-by: Kevin Fox <[email protected] >
* Fix naming issue
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
2026-07-30 19:38:43 +00:00
sabsari and Claude Opus 4.8
203183f73c
Add externalSecret support to spire-server kubeConfigs ( #889 )
...
Allow each kubeConfigs entry to reference an externally-managed Secret
(externalSecret{name,key}) instead of embedding the kubeconfig in values.
Entries may reference different Secrets and mix inline with external ones.
The kubeconfigs volume becomes a projected volume; consumer mount paths are
unchanged. Each entry must set exactly one of kubeConfig, kubeConfigBase64,
or externalSecret.
Signed-off-by: sabsari <[email protected] >
Co-authored-by: Claude Opus 4.8 <[email protected] >
2026-07-29 08:07:39 -07:00
sabsari and Claude Opus 4.8
cc164bad6b
Add EJBCA UpstreamAuthority plugin support to spire-server chart ( #873 )
...
Add support for the EJBCA UpstreamAuthority plugin, allowing the SPIRE
server to use an EJBCA instance as its upstream CA over mTLS.
- Add upstreamAuthority.ejbca values (hostname, caName, endEntityProfileName,
certificateProfileName, optional endEntityName and accountBindingId).
- Render the ejbca UpstreamAuthority block in the server config and count it
toward the single-upstream-authority guard.
- Mount the mTLS client credentials (and optional CA cert) from a secret,
either chart-created (secret.create) or externally provided.
- Gate ca_cert_path on secret.data.caCert, mirroring the disk plugin's bundle
handling for deterministic rendering.
- Regenerate the chart README and add a unit render test.
Signed-off-by: sabsari <[email protected] >
Co-authored-by: Claude Opus 4.8 <[email protected] >
2026-07-13 01:14:37 +00:00
dependabot[bot]
c273251dc7
Bump helm.sh/helm/v3 from 3.21.2 to 3.21.3 in /tests
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.21.2 to 3.21.3.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.21.2...v3.21.3 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-version: 3.21.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-07-10 21:10:01 +02:00
kfox1111
e44f006dde
Experimental support for spire-identity-exchange ( #860 )
...
* Experimental support for spire-identity-exchange
Signed-off-by: Kevin Fox <[email protected] >
* Fix image name
Signed-off-by: Kevin Fox <[email protected] >
* Fix flags
Signed-off-by: Kevin Fox <[email protected] >
* Fix ghosted section
Signed-off-by: Kevin Fox <[email protected] >
* Fix working dir
Signed-off-by: Kevin Fox <[email protected] >
* Fix working dir
Signed-off-by: Kevin Fox <[email protected] >
* Fix working dir
Signed-off-by: Kevin Fox <[email protected] >
* Fix working dir
Signed-off-by: Kevin Fox <[email protected] >
* Fix working dir
Signed-off-by: Kevin Fox <[email protected] >
* Fix working dir
Signed-off-by: Kevin Fox <[email protected] >
* Add some missing bits
Signed-off-by: Kevin Fox <[email protected] >
* Some more implementation
Signed-off-by: Kevin Fox <[email protected] >
* Update tests
Signed-off-by: Kevin Fox <[email protected] >
* Add ci
Signed-off-by: Kevin Fox <[email protected] >
* Fix ci
Signed-off-by: Kevin Fox <[email protected] >
* Fix ci
Signed-off-by: Kevin Fox <[email protected] >
* Fix ci
Signed-off-by: Kevin Fox <[email protected] >
* Fix ci
Signed-off-by: Kevin Fox <[email protected] >
* Fix ci
Signed-off-by: Kevin Fox <[email protected] >
* Fix ci
Signed-off-by: Kevin Fox <[email protected] >
* Fix ci
Signed-off-by: Kevin Fox <[email protected] >
* Fix ci
Signed-off-by: Kevin Fox <[email protected] >
* Rework x509pop to work shared
Signed-off-by: Kevin Fox <[email protected] >
* Rework x509pop to work shared
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix
Signed-off-by: Kevin Fox <[email protected] >
* Fix
Signed-off-by: Kevin Fox <[email protected] >
* Fix path
Signed-off-by: Kevin Fox <[email protected] >
* Fix path
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fixes
Signed-off-by: Kevin Fox <[email protected] >
* Fixes
Signed-off-by: Kevin Fox <[email protected] >
* Fixes
Signed-off-by: Kevin Fox <[email protected] >
* Fixes
Signed-off-by: Kevin Fox <[email protected] >
* Fix static entry
Signed-off-by: Kevin Fox <[email protected] >
* Cleanup
Signed-off-by: Kevin Fox <[email protected] >
* Remove unused change
Signed-off-by: Kevin Fox <[email protected] >
* Update spire-identity-exchange. Start to test.
Signed-off-by: Kevin Fox <[email protected] >
* fixes
Signed-off-by: Kevin Fox <[email protected] >
* Update lock
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Update
Signed-off-by: Kevin Fox <[email protected] >
* Fix broken test. Correct default dns names.
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge issue
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
2026-07-05 07:49:12 -07:00
dependabot[bot]
a8a94544e2
Bump github.com/onsi/ginkgo/v2 from 2.31.0 to 2.32.0 in /tests
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.31.0 to 2.32.0.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.31.0...v2.32.0 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.32.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-06-24 14:16:32 +02:00
dependabot[bot]
4c47699e8a
Bump github.com/onsi/gomega from 1.42.0 to 1.42.1 in /tests
...
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega ) from 1.42.0 to 1.42.1.
- [Release notes](https://github.com/onsi/gomega/releases )
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/gomega/compare/v1.42.0...v1.42.1 )
---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
dependency-version: 1.42.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-06-24 10:57:11 +02:00
dependabot[bot]
08fd19f272
Bump helm.sh/helm/v3 from 3.21.1 to 3.21.2 in /tests
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.21.1 to 3.21.2.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.21.1...v3.21.2 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-version: 3.21.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-06-22 10:53:19 +02:00
dependabot[bot]
d7d4f03265
Bump helm.sh/helm/v3 from 3.21.0 to 3.21.1 in /tests
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.21.0 to 3.21.1.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.21.0...v3.21.1 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-version: 3.21.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-06-15 11:37:35 +02:00
dependabot[bot]
0eaa756379
Bump github.com/onsi/ginkgo/v2 from 2.30.0 to 2.31.0 in /tests
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.30.0 to 2.31.0.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.30.0...v2.31.0 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.31.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-06-15 11:35:19 +02:00
dependabot[bot]
96dcf10f8f
Bump github.com/onsi/gomega from 1.41.0 to 1.42.0 in /tests
...
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega ) from 1.41.0 to 1.42.0.
- [Release notes](https://github.com/onsi/gomega/releases )
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/gomega/compare/v1.41.0...v1.42.0 )
---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
dependency-version: 1.42.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-06-15 11:26:45 +02:00
Guillermo Gaston and kfox1111
4f8ac5af06
Configure jwt_issuer in SPIRE OIDC Provider ( #829 )
...
The SPIRE OIDC Discovery Provider binary supports a top-level
`jwt_issuer` configuration key. When set, the provider returns that
exact string as the `issuer` field in the OIDC discovery document
(`.well-known/openid-configuration`) regardless of how the request was
routed. When unset, it derives `issuer` from the inbound HTTP Host
header. This chart did not render that key into the OIDC provider
config, leaving the discovery document Host-derived even when the
operator had a fixed issuer in mind.
Why this matters
OpenID Connect Discovery requires the discovery doc's `issuer` to be
byte-equal to the JWT `iss` claim. Conformant verifiers reject the chain
when the two differ. Production OIDC consumers routinely reach the
discovery endpoint at a URL different from the canonical issuer:
- a load balancer, ingress, or NodePort exposes the provider on an
IP or host different from the canonical issuer name;
- TLS terminates at a hostname different from the one advertised to
clients;
- the discovery URL is fetched by an internal service (e.g. the API
server in a private cluster) over a different DNS view than
external clients use;
- a pinned issuer URL is contractually required and must survive
infrastructure changes that move the actual service endpoint.
In all of these the JWT's `iss` claim is a logical, stable URL; the
discovery doc must report that same value, or downstream verifiers
reject the tokens.
Current chart behavior
The chart already has `global.spire.jwtIssuer` (and a subchart-local
`jwtIssuer`), resolved by the `spire-lib.jwt-issuer` helper to
`global.spire.jwtIssuer` -> subchart-local `jwtIssuer` ->
`https://oidc-discovery .<trustDomain>`. The spire-server subchart writes
that helper's result unconditionally as `jwt_issuer:` into the server's
config -- this controls the `iss` claim of every JWT-SVID the server
mints. In the OIDC subchart, however, the same helper was only used for
two things:
1. as the strict-mode assertion gate (fails the render when the
resolved value is the `example.org` default);
2. as the default source for `config.jwtDomain` (the Host
allow-list).
It was never written into the rendered OIDC provider configuration file.
The asymmetry means the chart shipped a structurally invalid OIDC setup
by default: the spire-server signs JWTs with `iss = <resolved issuer>`,
while the OIDC discovery endpoint advertises whatever Host header was
used to reach it. The only way to correct that today is to patch the
rendered ConfigMap out of band (`kubectl patch`, a CMP, a kustomize
post-renderer), which defeats the purpose of the chart.
Backward compatibility and behavior changes
Operators who set `global.spire.jwtIssuer` will see one additional
`jwt_issuer:` line in the rendered OIDC ConfigMap. The discovery doc's
`issuer` will start returning that pinned value instead of being
Host-derived, bringing the chain into spec compliance; this is a fix for
any spec-compliant verifier that previously rejected tokens. Operators
who only set the OIDC subchart-local `jwtIssuer` see the same fix
applied via the helper's fallback chain. Operators with nothing set will
see the new line default to `https://oidc-discovery .<trustDomain>`,
matching what the spire-server config already emits today.
Signed-off-by: Guillermo Gaston <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2026-06-14 01:25:43 +00:00
dependabot[bot]
528cc89f99
Bump github.com/onsi/ginkgo/v2 from 2.29.0 to 2.30.0 in /tests ( #844 )
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.29.0 to 2.30.0.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.29.0...v2.30.0 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.30.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-12 05:30:08 -07:00
kfox1111
1031167b84
Implement easy Bottom Turtle HA support in the charts ( #816 )
...
* Implement easy Bottom Turtle HA support in the charts
Signed-off-by: Kevin Fox <[email protected] >
* Add diagram
Signed-off-by: Kevin Fox <[email protected] >
* Update docs
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes and tightened defaults
Signed-off-by: Kevin Fox <[email protected] >
* More diagrams
Signed-off-by: Kevin Fox <[email protected] >
* More instructions
Signed-off-by: Kevin Fox <[email protected] >
* More instructions
Signed-off-by: Kevin Fox <[email protected] >
* More instructions
Signed-off-by: Kevin Fox <[email protected] >
* More instructions
Signed-off-by: Kevin Fox <[email protected] >
* More instructions
Signed-off-by: Kevin Fox <[email protected] >
* Install some bottom turtle spire bits
Signed-off-by: Kevin Fox <[email protected] >
* Trigger in github
Signed-off-by: Kevin Fox <[email protected] >
* Fix path
Signed-off-by: Kevin Fox <[email protected] >
* Fix path
Signed-off-by: Kevin Fox <[email protected] >
* Fix path
Signed-off-by: Kevin Fox <[email protected] >
* Fix path
Signed-off-by: Kevin Fox <[email protected] >
* Fix path
Signed-off-by: Kevin Fox <[email protected] >
* Fix path
Signed-off-by: Kevin Fox <[email protected] >
* Fix shell code
Signed-off-by: Kevin Fox <[email protected] >
* Add some more testing
Signed-off-by: Kevin Fox <[email protected] >
* Add some more testing
Signed-off-by: Kevin Fox <[email protected] >
* Add some more testing
Signed-off-by: Kevin Fox <[email protected] >
* Add some more debug logging
Signed-off-by: Kevin Fox <[email protected] >
* More logging
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* Some fixes
Signed-off-by: Kevin Fox <[email protected] >
* More updates
Signed-off-by: Kevin Fox <[email protected] >
* More updates
Signed-off-by: Kevin Fox <[email protected] >
* More updates
Signed-off-by: Kevin Fox <[email protected] >
* More updates
Signed-off-by: Kevin Fox <[email protected] >
* More updates
Signed-off-by: Kevin Fox <[email protected] >
* More updates
Signed-off-by: Kevin Fox <[email protected] >
* More updates
Signed-off-by: Kevin Fox <[email protected] >
* More updates
Signed-off-by: Kevin Fox <[email protected] >
* More updates
Signed-off-by: Kevin Fox <[email protected] >
* More updates
Signed-off-by: Kevin Fox <[email protected] >
* More updates
Signed-off-by: Kevin Fox <[email protected] >
* Add x509POP support and more testing
Signed-off-by: Kevin Fox <[email protected] >
* x509pop attestor support and more tests
Signed-off-by: Kevin Fox <[email protected] >
* More updates
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Update docs
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Fix pages artifact upload
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Test some more bits
Signed-off-by: Kevin Fox <[email protected] >
* Initial stab at dynamic registration
Signed-off-by: Kevin Fox <[email protected] >
* Dynamic registration working but not integrated with test
Signed-off-by: Kevin Fox <[email protected] >
* Wire in dynamic registration into the test
Signed-off-by: Kevin Fox <[email protected] >
* Fix missing props
Signed-off-by: Kevin Fox <[email protected] >
* Update the svids to align
Signed-off-by: Kevin Fox <[email protected] >
* Update the svids to align
Signed-off-by: Kevin Fox <[email protected] >
* Fix service name
Signed-off-by: Kevin Fox <[email protected] >
* Look at data
Signed-off-by: Kevin Fox <[email protected] >
* Look at data
Signed-off-by: Kevin Fox <[email protected] >
* Look at data
Signed-off-by: Kevin Fox <[email protected] >
* Fix ca type
Signed-off-by: Kevin Fox <[email protected] >
* Test out new packages
Signed-off-by: Kevin Fox <[email protected] >
* Test out new packages
Signed-off-by: Kevin Fox <[email protected] >
* Test out new packages
Signed-off-by: Kevin Fox <[email protected] >
* Test out new packages
Signed-off-by: Kevin Fox <[email protected] >
* Test out new packages
Signed-off-by: Kevin Fox <[email protected] >
* Test out new packages
Signed-off-by: Kevin Fox <[email protected] >
* Test out new packages
Signed-off-by: Kevin Fox <[email protected] >
* Test out new packages
Signed-off-by: Kevin Fox <[email protected] >
* Test out new packages
Signed-off-by: Kevin Fox <[email protected] >
* Test out new packages
Signed-off-by: Kevin Fox <[email protected] >
* Update ports
Signed-off-by: Kevin Fox <[email protected] >
* Update ports
Signed-off-by: Kevin Fox <[email protected] >
* Work on debugging dynamic registration some more
Signed-off-by: Kevin Fox <[email protected] >
* Fix service account name
Signed-off-by: Kevin Fox <[email protected] >
* Fix service account name
Signed-off-by: Kevin Fox <[email protected] >
* Working... Cleanup.
Signed-off-by: Kevin Fox <[email protected] >
* Working... Cleanup.
Signed-off-by: Kevin Fox <[email protected] >
* Fix broken ssh test
Signed-off-by: Kevin Fox <[email protected] >
* Fix broken ssh test
Signed-off-by: Kevin Fox <[email protected] >
* Simplify a bit
Signed-off-by: Kevin Fox <[email protected] >
* Update to use the released images
Signed-off-by: Kevin Fox <[email protected] >
* Allow x509POP cluster name adding
Signed-off-by: Kevin Fox <[email protected] >
* Restrict cluster registration
Signed-off-by: Kevin Fox <[email protected] >
* Fix var name
Signed-off-by: Kevin Fox <[email protected] >
* Fix missing slash
Signed-off-by: Kevin Fox <[email protected] >
* Make defaults work better
Signed-off-by: Kevin Fox <[email protected] >
* Make defaults work better
Signed-off-by: Kevin Fox <[email protected] >
* Fix readme
Signed-off-by: Kevin Fox <[email protected] >
* updated diagram
Signed-off-by: Kevin Fox <[email protected] >
* Regenerate image
Signed-off-by: Kevin Fox <[email protected] >
* Bump spire versions
Signed-off-by: Kevin Fox <[email protected] >
* Fix issues identified during review
Signed-off-by: Kevin Fox <[email protected] >
* Update docs
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
2026-06-03 12:15:28 -07:00
dependabot[bot]
7f4377f4b0
Bump github.com/onsi/gomega from 1.40.0 to 1.41.0 in /tests
...
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega ) from 1.40.0 to 1.41.0.
- [Release notes](https://github.com/onsi/gomega/releases )
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/gomega/compare/v1.40.0...v1.41.0 )
---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
dependency-version: 1.41.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-05-18 19:25:39 +02:00
dependabot[bot]
3f339664b1
Bump github.com/onsi/ginkgo/v2 from 2.28.3 to 2.29.0 in /tests
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.28.3 to 2.29.0.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.28.3...v2.29.0 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.29.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-05-18 19:11:01 +02:00
dependabot[bot]
75bf39f853
Bump helm.sh/helm/v3 from 3.20.2 to 3.21.0 in /tests ( #827 )
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.20.2 to 3.21.0.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.20.2...v3.21.0 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-version: 3.21.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-15 21:21:59 +02:00
Pratik Lotia
806c6ae59e
aws node attester: add org verification support ( #825 )
...
* add verify org support for aws node attester
Signed-off-by: pratik-lotia <[email protected] >
* refactor with suggested changes
Signed-off-by: pratik-lotia <[email protected] >
---------
Signed-off-by: pratik-lotia <[email protected] >
2026-05-12 12:25:07 -07:00
dependabot[bot]
9226e4f147
Bump github.com/onsi/ginkgo/v2 from 2.28.2 to 2.28.3 in /tests
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.28.2 to 2.28.3.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.28.2...v2.28.3 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.28.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-04-29 11:08:16 +02:00
dependabot[bot]
53889562c4
Bump github.com/onsi/gomega from 1.39.1 to 1.40.0 in /tests
...
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega ) from 1.39.1 to 1.40.0.
- [Release notes](https://github.com/onsi/gomega/releases )
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/gomega/compare/v1.39.1...v1.40.0 )
---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
dependency-version: 1.40.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-04-29 10:56:22 +02:00
dependabot[bot]
7f311dcd5e
Bump github.com/onsi/ginkgo/v2 from 2.28.1 to 2.28.2 in /tests
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.28.1 to 2.28.2.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.28.1...v2.28.2 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.28.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-04-28 14:13:02 +02:00
dependabot[bot]
c71ffc3c4e
Bump helm.sh/helm/v3 from 3.20.1 to 3.20.2 in /tests ( #791 )
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.20.1 to 3.20.2.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.20.1...v3.20.2 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-version: 3.20.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-10 01:28:51 -07:00
Faisal Memon
9273f11f0a
Support root-level spire-lib chart reuse ( #785 )
...
* Add root-level spire-lib chart
Signed-off-by: Faisal Memon <[email protected] >
* Make spire consume root-level spire-lib
Signed-off-by: Faisal Memon <[email protected] >
* Prepare chart dependencies in CI
Signed-off-by: Faisal Memon <[email protected] >
* Document DCO requirement in CODEX
Signed-off-by: Faisal Memon <[email protected] >
* Centralize local chart dependency prep
Signed-off-by: Faisal Memon <[email protected] >
* Exclude spire-lib from chart-testing install
Signed-off-by: Faisal Memon <[email protected] >
* Rename CODEX guide to AGENTS
Signed-off-by: Faisal Memon <[email protected] >
* Add make target for chart dependencies
Signed-off-by: Faisal Memon <[email protected] >
---------
Signed-off-by: Faisal Memon <[email protected] >
2026-04-09 05:14:05 -07:00
dependabot[bot]
0370d3170a
Bump helm.sh/helm/v3 from 3.20.0 to 3.20.1 in /tests
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.20.0 to 3.20.1.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.20.0...v3.20.1 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-version: 3.20.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-03-13 16:02:53 +01:00
dependabot[bot]
45fdf9f7c0
Bump github.com/onsi/gomega from 1.39.0 to 1.39.1 in /tests ( #739 )
...
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega ) from 1.39.0 to 1.39.1.
- [Release notes](https://github.com/onsi/gomega/releases )
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/gomega/compare/v1.39.0...v1.39.1 )
---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
dependency-version: 1.39.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-03 08:40:14 +01:00
dependabot[bot]
c620065ef6
Bump github.com/onsi/ginkgo/v2 from 2.27.5 to 2.28.1 in /tests ( #736 )
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.27.5 to 2.28.1.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.27.5...v2.28.1 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.28.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-30 00:29:17 -08:00
dependabot[bot]
ffc473889c
Bump helm.sh/helm/v3 from 3.19.5 to 3.20.0 in /tests ( #728 )
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.19.5 to 3.20.0.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.19.5...v3.20.0 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-version: 3.20.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-23 21:29:03 +00:00
dependabot[bot]
894cbb1089
Bump helm.sh/helm/v3 from 3.19.4 to 3.19.5 in /tests
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.19.4 to 3.19.5.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.19.4...v3.19.5 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-version: 3.19.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-01-20 19:03:25 +01:00
dependabot[bot]
4a85c49e30
Bump github.com/onsi/ginkgo/v2 from 2.27.4 to 2.27.5 in /tests ( #725 )
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.27.4 to 2.27.5.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.27.4...v2.27.5 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.27.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-13 13:28:25 -08:00
dependabot[bot]
4a7fb8e2b8
Bump github.com/onsi/ginkgo/v2 from 2.27.3 to 2.27.4 in /tests
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.27.3 to 2.27.4.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.27.3...v2.27.4 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.27.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-01-09 12:46:32 +01:00
dependabot[bot]
ee85b8d084
Bump github.com/onsi/gomega from 1.38.3 to 1.39.0 in /tests
...
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega ) from 1.38.3 to 1.39.0.
- [Release notes](https://github.com/onsi/gomega/releases )
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/gomega/compare/v1.38.3...v1.39.0 )
---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
dependency-version: 1.39.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-01-09 12:34:45 +01:00
dependabot[bot]
eb60ff0ed3
Bump helm.sh/helm/v3 from 3.19.3 to 3.19.4 in /tests ( #711 )
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.19.3 to 3.19.4.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.19.3...v3.19.4 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-version: 3.19.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-12-15 09:19:16 +00:00
dependabot[bot]
6cadd91e57
Bump helm.sh/helm/v3 from 3.19.2 to 3.19.3 in /tests
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.19.2 to 3.19.3.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.19.2...v3.19.3 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-version: 3.19.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2025-12-12 13:56:25 +01:00
dependabot[bot]
0ee45931da
Bump github.com/onsi/gomega from 1.38.2 to 1.38.3 in /tests
...
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega ) from 1.38.2 to 1.38.3.
- [Release notes](https://github.com/onsi/gomega/releases )
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/gomega/compare/v1.38.2...v1.38.3 )
---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
dependency-version: 1.38.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2025-12-09 13:03:27 +01:00
dependabot[bot]
325287a490
Bump github.com/onsi/ginkgo/v2 from 2.27.2 to 2.27.3 in /tests
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.27.2 to 2.27.3.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.27.2...v2.27.3 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.27.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2025-12-09 12:55:29 +01:00
dependabot[bot]
a2dee44207
Bump helm.sh/helm/v3 from 3.19.1 to 3.19.2 in /tests
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.19.1 to 3.19.2.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.19.1...v3.19.2 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-version: 3.19.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2025-11-13 11:48:51 +01:00
dependabot[bot]
3fb6ddfe0c
Bump helm.sh/helm/v3 from 3.19.0 to 3.19.1 in /tests
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.19.0 to 3.19.1.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.19.0...v3.19.1 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-version: 3.19.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2025-11-11 17:09:20 +01:00
dependabot[bot]
02d610077d
Bump github.com/onsi/ginkgo/v2 from 2.27.1 to 2.27.2 in /tests
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.27.1 to 2.27.2.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.27.1...v2.27.2 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.27.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
2025-10-29 10:48:35 +01:00
dependabot[bot]
55f7a095c2
Bump github.com/onsi/ginkgo/v2 from 2.26.0 to 2.27.1 in /tests ( #686 )
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.26.0 to 2.27.1.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.26.0...v2.27.1 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.27.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-23 06:49:13 -07:00
dependabot[bot] and kfox1111
a3d3c0bc6c
Bump github.com/onsi/ginkgo/v2 from 2.25.3 to 2.26.0 in /tests ( #673 )
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.25.3 to 2.26.0.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.25.3...v2.26.0 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.26.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: kfox1111 <[email protected] >
2025-10-09 07:50:25 -07:00