* 4c307c1 Add missing bundlePublisher section and extraEnv so settings can be set (#201)
* d724d1e Update the documentation (#172)
* e59a29b Bump test chart dependencies (#200)
* 4668151 Add missing extraVolumeMounts to the controllerManager (#196)
* b9ac3c4 Update to spire-controller-manager 0.4.1 (#193)
* 6fec1e5 Update SPIRE to 1.8.7 (#194)
* af155c2 Add support for running spiffe secured discovery provider (default) (#163)
* 3ccdb5e Add tls section to federation bundle endpoint and fix up annotations (#173)
* c7ab131 Add join_token server nodeattestor support (#187)
* 81e9523 Bump test chart dependencies (#186)
* 6d19a76 Fix agent daemonset format (#184)
* b61d4f5 Add spire-agent to spire-agent pod path (#180)
* befa074 Fix notes bug (#178)
* 912c61e Remove deprecated version values (#179)
* ae4ef6e Update HorizontalPodAutoscaler API to autoscaling/v2 (#153)
* e7a61a9 Bump test chart dependencies
* 183e9aa SPIFFE OIDC Discovery Provider Rework (#152)
* 8f1aba8 Bump test chart dependencies (#171)
* 2454b8c Fix links still pointing at older git repo (#167)
* e5c5527 Bump test chart dependencies (#165)
* e630008 Update jwt test to work with newer slim images (#139)
* c39dd44 Add recommendation for namespacePSS (#131)
* 49beb64 Add recommendation for namespaceLayout (#127)
* 33cacd2 Add recommendation for prometheus exporter (#144)
* 6997d6a Add recommendation for securityContext and podSecurityContext (#125)
* 50c4ac3 Add recommendation for strictMode (#143)
* 4fb9d18 Bump test chart dependencies (#155)
* 811123a Update the Tornjak image version (#150)
* 1524537 Update default for additionalDomains not to include localhost (#146)
* e35838c Add recommendation for priorityClass (#124)
* 9f72a8f Use good and automatic defaults for tornjak frontend workingDir (#129)
* 7726351 Tornjak UBI support (#123)
* 89c07e2 Revert openssl 3.2 change (#142)
* a3d3702 Bump test chart dependencies
* 80c7653 Bump test chart dependencies (#134)
* 13f6028 SELinux support (#122)
* 3e8335c Add a flag to enable recommendations (#121)
* 692d463 Remove unneeded lookup function from upgrade hook (#104)
* 8422b8d Added ability to create namespaces (#103)
Signed-off-by: Kevin Fox <[email protected]>
* Add cert-manager support to the federation bundle endpoint and fix up bundle endpoint ingress annotations
Signed-off-by: Kevin Fox <[email protected]>
* Add external secret too
Signed-off-by: Kevin Fox <[email protected]>
* Add forgotten files
Signed-off-by: Kevin Fox <[email protected]>
* Apply suggestions from code review
Signed-off-by: kfox1111 <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* install newer version of slim debug
- switch to step tool for jwt verification against jwk public keys
Signed-off-by: Drew Wells <[email protected]>
* use step-cli image
Signed-off-by: Drew Wells <[email protected]>
* Fix image tag and add upgrade logic
Signed-off-by: Kevin Fox <[email protected]>
* use registry for consistency
Signed-off-by: Kevin Fox <[email protected]>
* Fix merge conflicts
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Drew Wells <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
Its pretty much only useful if you want to port forward the
discovery provider and use localhost to access it. An uncommon
use case. Its easy to add back for that case. This simplifies
production deploymnet.
Signed-off-by: Kevin Fox <[email protected]>
* Tornjak UBI support
The Tornjak containers now have two different flavors. Vanilla and UBI.
Automatically select the UBI image when deploying on OpenShift.
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: Mariusz Sabath <[email protected]>
* SELinux support
Add support to the chart to set the SELinux context to enable a working
system. Enable it by default on OpenShift clusters.
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Those upgrading to 0.17.0 should no longer need the code to check for the old webhook.
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
* Add support for the new spire-controller-manager class feature
Signed-off-by: Kevin Fox <[email protected]>
* Fix docs. Swich nested deployment to use controller manager
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Test with nightly
Signed-off-by: Kevin Fox <[email protected]>
* Fix global object naming clash
Signed-off-by: Kevin Fox <[email protected]>
* Fix missing dot
Signed-off-by: Kevin Fox <[email protected]>
* Fix naming conflict with cluster ids
Signed-off-by: Kevin Fox <[email protected]>
* Fix scoping issue
Signed-off-by: Kevin Fox <[email protected]>
* Fix typo
Signed-off-by: Kevin Fox <[email protected]>
* Fix webhook name collision
Signed-off-by: Kevin Fox <[email protected]>
* Fix webhook reference and add note to user about className
Signed-off-by: Kevin Fox <[email protected]>
* Upgrade has to work on the old version of the object before rename
Signed-off-by: Kevin Fox <[email protected]>
* Fix formatting
Signed-off-by: Kevin Fox <[email protected]>
* Remove extra junk from job
Signed-off-by: Kevin Fox <[email protected]>
* Easier local runs and wait for crds
Signed-off-by: Kevin Fox <[email protected]>
* Add missing crd upgrade
Signed-off-by: Kevin Fox <[email protected]>
* Update upgrade notes
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml
Co-authored-by: Marco Franssen <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Bump version to the released 0.4.0
Signed-off-by: kfox1111 <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
* Merge in crd changes from upstream
Signed-off-by: Kevin Fox <[email protected]>
* Add auto populate dns
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/README.md
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Add missing ClusterSPIFFEID fields
There are a few options in the CRD not available via the chart.
Sync them to the chart.
Signed-off-by: Kevin Fox <[email protected]>
* Add another missing one
Signed-off-by: Kevin Fox <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
* Allow additional CRs to be managed by the chart
Sometimes additional ClusterSPIFFEIDs and the other CRs are needed. Add
support for the end user to manage those extra CRs via the chart.
Signed-off-by: Kevin Fox <[email protected]>
* Add validation
Signed-off-by: Kevin Fox <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
* Add className to crs
Signed-off-by: Kevin Fox <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Fix readme formatting
Signed-off-by: Kevin Fox <[email protected]>
* Update charts/spire/README.md
Signed-off-by: kfox1111 <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
* Fix docs
Signed-off-by: Kevin Fox <[email protected]>
* Remove dead code
Signed-off-by: Kevin Fox <[email protected]>
* Fix extra newline
Signed-off-by: Kevin Fox <[email protected]>
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
---------
Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Marco Franssen <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>