kfox1111 and Faisal Memon
d724d1e690
Update the documentation ( #172 )
...
* SPIFFE OIDC Discovery Provider Rework
Fixes: https://github.com/spiffe/helm-charts-hardened/issues/151
Signed-off-by: Kevin Fox <[email protected] >
* Enhance clusterspiffeid's so the discovery provider is independently configurable
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* More fix tests
Signed-off-by: Kevin Fox <[email protected] >
* More fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Undo
Signed-off-by: Kevin Fox <[email protected] >
* Fix logging
Signed-off-by: Kevin Fox <[email protected] >
* Try to get output
Signed-off-by: Kevin Fox <[email protected] >
* Try and get error code
Signed-off-by: Kevin Fox <[email protected] >
* Fix more logging. Switch port used.
Signed-off-by: Kevin Fox <[email protected] >
* Fix logging
Signed-off-by: Kevin Fox <[email protected] >
* Fix port
Signed-off-by: Kevin Fox <[email protected] >
* Fix up logs for nested test and fix values
Signed-off-by: Kevin Fox <[email protected] >
* Make consistent
Signed-off-by: Kevin Fox <[email protected] >
* Fix nested test
Signed-off-by: Kevin Fox <[email protected] >
* Fix insecure mode and test.
Signed-off-by: Kevin Fox <[email protected] >
* Fix test.
Signed-off-by: Kevin Fox <[email protected] >
* Fix var scoping issue
Signed-off-by: Kevin Fox <[email protected] >
* Set the right flags for ingress
Signed-off-by: Kevin Fox <[email protected] >
* Update dns template
Signed-off-by: Kevin Fox <[email protected] >
* Use more standard port
Signed-off-by: Kevin Fox <[email protected] >
* Fix test logging
Signed-off-by: Kevin Fox <[email protected] >
* Allow reencrypt.
Signed-off-by: Kevin Fox <[email protected] >
* Remove testing changes
Signed-off-by: Kevin Fox <[email protected] >
* Fix formatting
Signed-off-by: Kevin Fox <[email protected] >
* Add LetsEncrypt/ACME/cert-manager support. Remove broken ACME support.
Signed-off-by: Kevin Fox <[email protected] >
* Use spiffe-helper as a sidecar. Significant space savings and read only cert dir
Signed-off-by: Kevin Fox <[email protected] >
* Fix the nested test
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge issue
Signed-off-by: Kevin Fox <[email protected] >
* Remove 1.29.0 until deps catch up.
Related issue: https://github.com/rancher/kubectl/pull/94
Signed-off-by: Kevin Fox <[email protected] >
* Add more error checking
Signed-off-by: Kevin Fox <[email protected] >
* Remove testing code
Signed-off-by: Kevin Fox <[email protected] >
* Simplify the ids. Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix logic
Signed-off-by: Kevin Fox <[email protected] >
* Fix var
Signed-off-by: Kevin Fox <[email protected] >
* Make cert-manager bits more readable
Signed-off-by: Kevin Fox <[email protected] >
* Fix template
Signed-off-by: Kevin Fox <[email protected] >
* Fix openshift ingress
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Update docs
Signed-off-by: Kevin Fox <[email protected] >
* Add resource spec
Signed-off-by: Kevin Fox <[email protected] >
* Remove parts that cant merge yet
Signed-off-by: Kevin Fox <[email protected] >
* Add support for running spiffe secured discovery provider (default)
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Remove defaults
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Add missing configurable for the discovery providers csi driver
Signed-off-by: Kevin Fox <[email protected] >
* Update the documentation
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Signed-off-by: kfox1111 <[email protected] >
* Apply suggestions from code review
Signed-off-by: kfox1111 <[email protected] >
* Apply suggestions from code review
Signed-off-by: kfox1111 <[email protected] >
* Apply suggestions from code review
Signed-off-by: kfox1111 <[email protected] >
* Add missing file
Signed-off-by: Kevin Fox <[email protected] >
* Update for changes in spiffe-helper
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-01-23 08:05:49 -08:00
kfox1111 and Marco Franssen
c39dd44526
Add recommendation for namespacePSS ( #131 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-12-21 00:15:56 +00:00
kfox1111 and Marco Franssen
6997d6a904
Add recommendation for securityContext and podSecurityContext ( #125 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-12-19 11:26:26 +00:00
kfox1111 and Faisal Memon
a097606d77
Remove extra example values that are already set by default ( #128 )
...
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-12-12 16:23:23 +00:00
kfox1111
9f72a8f971
Use good and automatic defaults for tornjak frontend workingDir ( #129 )
...
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
2023-12-11 07:52:44 -08:00
kfox1111 and Mariusz Sabath
7726351955
Tornjak UBI support ( #123 )
...
* Tornjak UBI support
The Tornjak containers now have two different flavors. Vanilla and UBI.
Automatically select the UBI image when deploying on OpenShift.
Signed-off-by: Kevin Fox <[email protected] >
Co-authored-by: Mariusz Sabath <[email protected] >
2023-12-11 06:56:58 -08:00
kfox1111
13f6028ccd
SELinux support ( #122 )
...
* SELinux support
Add support to the chart to set the SELinux context to enable a working
system. Enable it by default on OpenShift clusters.
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
2023-12-07 11:02:06 -08:00
8422b8d141
Added ability to create namespaces ( #103 )
...
* Added ability to create namespaces
Signed-off-by: Andrew Block <[email protected] >
* Add openshift labels
Signed-off-by: Mariusz Sabath <[email protected] >
---------
Signed-off-by: Andrew Block <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
Co-authored-by: Mariusz Sabath <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2023-12-01 15:42:27 +00:00
kfox1111 and Marco Franssen
d936293d50
Enable agent to kubelet connection to use hostname ( #112 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-11-28 08:43:09 +01:00
Kevin Fox
966061c6c7
Auto add default CSIDriver labels on OpenShift
...
Signed-off-by: Kevin Fox <[email protected] >
2023-11-20 10:24:53 +01:00
821ca1290e
Add Tornjak ingress example ( #30 )
...
Co-authored-by: Marco Franssen <[email protected] >
Co-authored-by: Mariusz Sabath <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2023-11-10 12:30:40 +00:00
Marco Franssen
0320c3f755
Cleanup documentation
...
Signed-off-by: Marco Franssen <[email protected] >
2023-11-08 13:11:58 +01:00
3b016841da
Support Openshift deployment ( #13 )
...
* Add support for SPIRE deployment on OpenShift 4.13
Signed-off-by: Mariusz Sabath <[email protected] >
Co-authored-by: Trilok Geer <[email protected] >
Co-authored-by: Andrew Block <[email protected] >
* Render README
Signed-off-by: Mariusz Sabath <[email protected] >
* Fix tornjak HTTP/HTTPS port values
Signed-off-by: Mariusz Sabath <[email protected] >
* Update Frontend README
Signed-off-by: Mariusz Sabath <[email protected] >
* Add env. variable to Agent to inject node name
Signed-off-by: Mariusz Sabath <[email protected] >
* Implement Marco's suggestion on CSI CSS version
Signed-off-by: Mariusz Sabath <[email protected] >
* Add MY_NODE_NAME env. variable to agent for openshift example
Signed-off-by: Mariusz Sabath <[email protected] >
* Move Openshift examples to dedicated directory
Signed-off-by: Mariusz Sabath <[email protected] >
* Simplified the install instructions
Signed-off-by: Mariusz Sabath <[email protected] >
* Suggested changes
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Andrew Block <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Update docs, fix default for backwards compat
Signed-off-by: Kevin Fox <[email protected] >
* Don't recommend experimental features by default, dont debug helm install by default and explain how to add additional features
Signed-off-by: Kevin Fox <[email protected] >
* Add notes about openshift to the project for other reviewers.
Signed-off-by: Kevin Fox <[email protected] >
* Fix incorrectly reverted change
Signed-off-by: Kevin Fox <[email protected] >
* Correct notes
Signed-off-by: Kevin Fox <[email protected] >
* Update default
Signed-off-by: Kevin Fox <[email protected] >
* Fix issue created from bad merge conflict resolution
Signed-off-by: kfox1111 <[email protected] >
* Update examples/openshift/openshift-values.yaml
Co-authored-by: kfox1111 <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
* Update examples/openshift/openshift-values.yaml
Co-authored-by: kfox1111 <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
* Update examples/openshift/openshift-values.yaml
Co-authored-by: kfox1111 <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
* Update examples/openshift/openshift-values.yaml
Co-authored-by: kfox1111 <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
---------
Signed-off-by: Mariusz Sabath <[email protected] >
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Trilok Geer <[email protected] >
Co-authored-by: Andrew Block <[email protected] >
Co-authored-by: Kevin Fox <[email protected] >
2023-10-31 16:27:23 +00:00