* Add set_key_use configuration option
Add a setKeyUse boolean configuration option to control the set_key_use
field in the SPIFFE OIDC Discovery Provider configuration.
When enabled, this adds the 'use': 'sig' field to JWKS keys, which is
required for compatibility with Keycloak's SPIFFE identity provider.
Defaults to false to maintain backward compatibility.
Signed-off-by: Alan Cha <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Alan Cha <[email protected]>
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: Kevin Fox <[email protected]>
* Check each conditional of gather host cert in case a command to create the host cert fails
Signed-off-by: Daniel Schlatter <[email protected]>
* Change curl command to use --cacert in gather-host-cert init container
--capath is for directories. --cacert is the correct option for a single cert.
Signed-off-by: Daniel Schlatter <[email protected]>
---------
Signed-off-by: Daniel Schlatter <[email protected]>
* Fix duplicate port names in controller-manager containers
Multiple controller-manager containers were using the same "heathz" port
name, causing Kubernetes warnings about duplicate ports in the
StatefulSet. This also affected the prometheus port "prom-cm".
Changes:
* Renamed healthz port to hp-cm (health port - controller manager)
* Renamed prom-cm to pm-cm for consistency
* Addedd {{ .portSuffix }} variable to differentiate external controller
ports
* Implemented port suffix logic
The suffix logic handles cluster names by:
1. Names <9 chars: use full name as suffic
* e.g.: child01 -> -child01
2. Names with trailing numbers: preserve the number format users chose
* Detects 1-2 digit numbers with optional hyphen
* Truncates base name to fit within 15 chars
* e.g.: verlongcluster-01 -> -verylo-01
3. Names without numbers: use SHA-256 hash for uniqueness
* Trunactes name to 5 chars and appends 3-char hash
* e.g.: verlongclustername -> -veryl-a3f
The logic separates container suffix (full name) from port suffix
(truncated) so container names remain descriptive while port names stay
compliant.
Fixes#525#655
Signed-off-by: Rowan Ruseler <[email protected]>
* Add optional port name overrides for ext. controller
The auto-generated port name suffixes for external controller manager
can collide when cluster names are similar, as the 3-character has
provides only 4,096 possibilities. With the optional healthPortName and
prometheusPortName fields to cluster configuration, allows users to
explicity set port names when automatica generation creates collisions.
Signed-off-by: Rowan Ruseler <[email protected]>
* Fix portSuffix generation
Changed from "and" to "or", so portSuffic is calculated when either
healthPortName or prometheusPortName is unset.
Signed-off-by: Rowan Ruseler <[email protected]>
---------
Signed-off-by: Rowan Ruseler <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
* Add configurable hostNetwork parameter for spire-agent
Adds `hostNetwork` as a configurable parameter in the spire-agent chart.
We can now explicitly control whether the spire-agent daemonset uses
host networking.
Changes:
* Updated daemonset template
* Changed `dnsPolicy` logic to follow the computed `hostNetwork` instead
of kubelet mode directly
* Updated documentation
Behaviour:
If you leave `hostNetwork` empty (the default), it behaves like PR #705:
* automatically disables when using hostname or hostip kubelet modes
* automatically enables for localhost
If you set it explicitly to `true` or `false`, that overrides the
automatic behaviour. When `hostNetwork` is enabled and you haven't set a
custom `dnsPolicy`, it defaults to `ClusterFirstWithHostNet`.
Fixes#704
Signed-off-by: Rowan Ruseler <[email protected]>
* Fix merge conflict, different default value for fsGroupFix.image.tag
Signed-off-by: Rowan Ruseler <[email protected]>
---------
Signed-off-by: Rowan Ruseler <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
* Add ContainerResource scaling to spire-server HPA
Signed-off-by: Jayme Howard <[email protected]>
* Amend flag name to address feedback
Signed-off-by: Jayme Howard <[email protected]>
---------
Signed-off-by: Jayme Howard <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
spiffe-csi-driver and spiffe-oidc-discovery provider are now brought in
line with spire-server and spire-agent, which already support podLabels.
Changes:
* Add podLabels parameter
Fixes#719
Signed-off-by: Rowan Ruseler <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
Applies the tolerations in the spire-server chart to the pods created
by the hooks. Previously they were only applied to the pods of the
server itself.
Signed-off-by: Alec Wilson <[email protected]>
Adds unsupported built-in plugins (built-in plugins that do not have
direct toggles in the helm chart) to the check that exactly one
key manager plugin is enabled - the previous check only allowed usage
of key manager plugins with explicit values in the helm chart.
This still doesn't allow usage of custom key manager plugins - as they
will not be present in the count that is checked.
Signed-off-by: Alec Wilson <[email protected]>
* Add logFormat support to spire-server chart
Adds the ability to configure SPIRE server log format (text or json)
via the logFormat helm value. When set, it renders as log_format in
the server configuration.
Signed-off-by: Shubham Hibare <[email protected]>
* add default value
Signed-off-by: Shubham Hibare <[email protected]>
* fix
Signed-off-by: Shubham Hibare <[email protected]>
* fix
Signed-off-by: Shubham Hibare <[email protected]>
---------
Signed-off-by: Shubham Hibare <[email protected]>
* disable hostNetwork on spire-agent daemonset if connect by hostname is true
Signed-off-by: Daniel Schlatter <[email protected]>
* allow spire-agent daemonset dnsPolicy to be configured
Signed-off-by: Daniel Schlatter <[email protected]>
---------
Signed-off-by: Daniel Schlatter <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
* 6f2c71b0 Update spire to 1.14.1 (#729)
* f8f1e21f CSI driver: Support setting podSecurityContext and securityContext (#642)
* 813203a4 Update spike to the newest version (#665)
* 97c383b1 Add Configurable Kubelet Address for SPIRE Agent (#709)
* 8555efc6 Bump test chart dependencies
* e6c9d975 Bump test chart dependencies
* 87da80a8 Add support for AWS KMS key tagging (#721)
* db8f1352 Bump test chart dependencies (#720)
* b1f902b6 Bump test chart dependencies
* 198cdb60 Bump test chart dependencies
* dfbbecf0 Add guard to the validating admission policy to stop errors when there are no volumes in the spec. This fixes errors with HTTP solver pods in cert manager. (#706)
* 1e1e8daa Add support for attested node pruning configuration (#713)
* a2130ff7 Bump test chart dependencies (#712)
* adc5f3e8 Bump test chart dependencies
* 4e0cdb13 Bump test chart dependencies
* 95fa0deb Allow configuring spire-agent prometheus listening address (#701)
Signed-off-by: Faisal Memon <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
* Allow for both the pod security context and container security contexts to be overriden through the spiffe-csi-driver values file
Signed-off-by: Alec Holmes <[email protected]>
* newline
Signed-off-by: Alec Holmes <[email protected]>
* fix space
Signed-off-by: Alec Holmes <[email protected]>
* Update docs
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Alec Holmes <[email protected]>
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>