Faisal Memon
63853f5494
Bump spire Helm Chart version from 0.20.0 to 0.21.0 ( #373 )
...
* 54a2f03 Change cleanup default (#349 )
* d29ad06 Bump test chart dependencies (#369 )
* 7dabbf1 Add Openshift ignore namespaces to Controller Manager (#363 )
* db177d4 Fix spelling error in Controller Manager config (#362 )
* d236154 Fix upstream ca name suffix issue (#361 )
* bfcf418 Bump test chart dependencies (#359 )
* c31a2e9 Bump up spire to 1.9.6 (#356 )
* 2c5dfa0 Improve Tornjak NOTES. Fixes #132 (#354 )
* a453a2c Bump test chart dependencies (#355 )
* b6575c1 Update Tornjak deployment docs (#288 )
* be560d9 Check for a misconfiguration of bundle endpoint profiles (#348 )
* b2e9f40 Bump spire version (#352 )
* 7165b20 Bump test chart dependencies (#350 )
* da4ebdf Fix federation certificate name when upstream enabled (#347 )
* c37de1e Fix Tornjak logsDir for Openshift (#344 )
* 8fef1bd Add external spire-controller-managers (#284 )
* ee12404 set refresh hint to 1/3 of default CA TTL value fixes #335 (#343 )
* 2d9866a Bump test chart dependencies (#338 )
* 6de23d3 Don't create role/binding when bundle disabled (#336 )
* c132cc4 Add support for externalServer=true (#303 )
* a2494ee Add auth option for Tornjak (#259 )
* f679a0d Bump test chart dependencies (#333 )
* 5149256 Work around curl change
* 3d2ac16 Bump test chart dependencies
* 08f699b Add spire-lib chart (#289 )
* 260b02f Add an easy to use identity for child servers (#302 )
Signed-off-by: Faisal Memon <[email protected] >
2024-05-30 22:00:00 +00:00
kfox1111 and Faisal Memon
54a2f036bf
Change cleanup default ( #349 )
...
* Change cleanup default
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Update charts/spire/README.md
Signed-off-by: kfox1111 <[email protected] >
* Update charts/spire/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix merge issue and incorperate feedback.
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-05-30 12:22:03 -07:00
d29ad0649f
Bump test chart dependencies ( #369 )
...
* Bump test chart dependencies
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* Remove workaround as they fixed curl
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: Kevin Fox <[email protected] >
Co-authored-by: marcofranssen <[email protected] >
Co-authored-by: Kevin Fox <[email protected] >
2024-05-27 06:36:36 -07:00
dependabot[bot]
39084afa71
Bump github.com/onsi/ginkgo/v2 from 2.18.0 to 2.19.0 in /tests
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.18.0 to 2.19.0.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.18.0...v2.19.0 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
2024-05-27 09:39:46 +02:00
dependabot[bot]
6ff84393fc
Bump helm.sh/helm/v3 from 3.15.0 to 3.15.1 in /tests ( #365 )
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.15.0 to 3.15.1.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.15.0...v3.15.1 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-26 15:03:39 +00:00
Mariusz Sabath
7dabbf16d3
Add Openshift ignore namespaces to Controller Manager ( #363 )
...
* Fix spelling error in Controller Manager config
Signed-off-by: Mariusz Sabath <[email protected] >
* Add ignoreNamespaces to ControllerManager for Openshift
Signed-off-by: Mariusz Sabath <[email protected] >
---------
Signed-off-by: Mariusz Sabath <[email protected] >
2024-05-26 07:55:26 -07:00
Mariusz Sabath
db177d4b85
Fix spelling error in Controller Manager config ( #362 )
...
Signed-off-by: Mariusz Sabath <[email protected] >
2024-05-23 19:26:44 +00:00
kfox1111
d2361549db
Fix upstream ca name suffix issue ( #361 )
...
* Fix upstream ca name suffix issue
Signed-off-by: Kevin Fox <[email protected] >
* Fix quoting
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
2024-05-23 09:43:19 -07:00
dependabot[bot]
f613d1ad5b
--- ( #360 )
2024-05-22 00:15:28 -07:00
kfox1111 and Faisal Memon
a2689c986c
Add spire-nested chart ( #294 )
...
* Complete Server K8S PSAT support
Add all the SPIRE Server supported options for the K8S PSAT attestor. This retains the
ease of use for configuring local cluster support while adding the ability to configure
multiple/external clusters as well. Kubeconfig support is added in its own config block
as it will be used/shared with spire-controller-manager support in the future.
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Add support for integration tests in the tests/integration dir
Signed-off-by: Kevin Fox <[email protected] >
* Fix split issue and typo
Signed-off-by: Kevin Fox <[email protected] >
* Add basic psat test
Signed-off-by: Kevin Fox <[email protected] >
* Fix linter
Signed-off-by: Kevin Fox <[email protected] >
* Fix up test
Signed-off-by: Kevin Fox <[email protected] >
* Add missing file
Signed-off-by: Kevin Fox <[email protected] >
* Better encode config
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Update docs
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Add external k8s bundler
Adds support to sync the CA bundle to configmaps in external
Kubernetes clusters
Signed-off-by: Kevin Fox <[email protected] >
* Update default
Signed-off-by: Kevin Fox <[email protected] >
* Fix config file layout. Incorperate feedback.
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Update based on parent pr feedback
Signed-off-by: Kevin Fox <[email protected] >
* Reformat config file
Signed-off-by: Kevin Fox <[email protected] >
* Fix some things
Signed-off-by: Kevin Fox <[email protected] >
* Reconfigure kind
Signed-off-by: Kevin Fox <[email protected] >
* More debugging
Signed-off-by: Kevin Fox <[email protected] >
* Fix up kind
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Add external spire-controller-managers
Only one external controller manager is supported at a time until
https://github.com/spiffe/spire/issues/4898 is resolved.
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Add Entry ID Prefix support
Signed-off-by: Kevin Fox <[email protected] >
* Mulitcluster test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Implement cleanup setting too
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Make spire-lib bits into its own library chart.
Signed-off-by: Kevin Fox <[email protected] >
* Add spire-nested chart
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Fix lint issue
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Add missing file
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Add nameOverride option
Signed-off-by: Kevin Fox <[email protected] >
* Simplify upstream config. Reorder test for faster executation
Signed-off-by: Kevin Fox <[email protected] >
* Enable service account allow list to calculate namespace
Signed-off-by: Kevin Fox <[email protected] >
* Add identity type for child servers
Signed-off-by: Kevin Fox <[email protected] >
* Enable name override setting
Signed-off-by: Kevin Fox <[email protected] >
* Fix printing
Signed-off-by: Kevin Fox <[email protected] >
* Fix formatting
Signed-off-by: Kevin Fox <[email protected] >
* Fix name length issue
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Switch to non cluster-admin user
Signed-off-by: Kevin Fox <[email protected] >
* Test out adding roles
Signed-off-by: Kevin Fox <[email protected] >
* Namespace needs to exist
Signed-off-by: Kevin Fox <[email protected] >
* Remove tty
Signed-off-by: Kevin Fox <[email protected] >
* Fix name
Signed-off-by: Kevin Fox <[email protected] >
* Add missing role
Signed-off-by: Kevin Fox <[email protected] >
* Add kind=none to not require extra objects
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Remove unneeded code
Signed-off-by: Kevin Fox <[email protected] >
* Add security cluster example
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Dont preinstall crds for nested-security
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Fix address
Signed-off-by: Kevin Fox <[email protected] >
* Update port
Signed-off-by: Kevin Fox <[email protected] >
* Update psat setting
Signed-off-by: Kevin Fox <[email protected] >
* Update psat setting
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Remove older tests that newer tests cover
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix kind logic
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Seems unneeded. Try and remove
Signed-off-by: Kevin Fox <[email protected] >
* Update the default ports to be more user friendly
Signed-off-by: Kevin Fox <[email protected] >
* See if we can leave controller manager port alone
Signed-off-by: Kevin Fox <[email protected] >
* Change the agent default port too
Signed-off-by: Kevin Fox <[email protected] >
* Bump up test container
Signed-off-by: Kevin Fox <[email protected] >
* Swith to testing with nightly
Signed-off-by: Kevin Fox <[email protected] >
* Fix value name
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Upgrade to spire-controller-manager 0.5.0
Signed-off-by: Kevin Fox <[email protected] >
* Try to isolate config differences just to child cluster
Signed-off-by: Kevin Fox <[email protected] >
* Update for released 0.5.0
Signed-off-by: Kevin Fox <[email protected] >
* Merge in some of the id prefix pr
Signed-off-by: Kevin Fox <[email protected] >
* Entry ID Prefix (#287 )
* Add Entry ID Prefix support
Signed-off-by: Kevin Fox <[email protected] >
* Mulitcluster test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Implement cleanup setting too
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Bump up test container
Signed-off-by: Kevin Fox <[email protected] >
* Swith to testing with nightly
Signed-off-by: Kevin Fox <[email protected] >
* Fix value name
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix up doc formatting
Signed-off-by: Kevin Fox <[email protected] >
* Revert notes
Signed-off-by: Kevin Fox <[email protected] >
* Use tags for nested chart
Signed-off-by: Kevin Fox <[email protected] >
* Add missing tag
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix formatting
Signed-off-by: Kevin Fox <[email protected] >
* Fix class name
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict issue
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge issue
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge issue
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback. Switch setting to be externalServer.
Signed-off-by: Kevin Fox <[email protected] >
* Update nested chart to use new setting
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge issue
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Add docs about which sections are used with which tags
Signed-off-by: Kevin Fox <[email protected] >
* Update versions
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-05-20 08:58:22 -07:00
spire-helm-version-checker[bot] and marcofranssen
bfcf418301
Bump test chart dependencies ( #359 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
2024-05-20 06:33:31 -07:00
dependabot[bot]
39453a1365
Bump helm.sh/helm/v3 from 3.14.4 to 3.15.0 in /tests ( #357 )
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.14.4 to 3.15.0.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.14.4...v3.15.0 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-16 16:39:17 +00:00
kfox1111
c31a2e9f65
Bump up spire to 1.9.6 ( #356 )
...
Signed-off-by: Kevin Fox <[email protected] >
2024-05-16 09:20:14 -07:00
Mariusz Sabath
2c5dfa010f
Improve Tornjak NOTES. Fixes #132 ( #354 )
...
* Improve Tornjak NOTES. Fixes #132
Signed-off-by: Mariusz Sabath <[email protected] >
* Fix Tornjak ingress value
Signed-off-by: Mariusz Sabath <[email protected] >
---------
Signed-off-by: Mariusz Sabath <[email protected] >
2024-05-14 13:52:55 -07:00
spire-helm-version-checker[bot] and marcofranssen
a453a2c1b4
Bump test chart dependencies ( #355 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
2024-05-13 13:11:02 +02:00
b6575c172d
Update Tornjak deployment docs ( #288 )
...
* Update Tornjak deployment docs
Signed-off-by: Mariusz Sabath <[email protected] >
* Change the reference for installing standard Tornjak
Signed-off-by: Mariusz Sabath <[email protected] >
* Update examples/tornjak/README.md
Co-authored-by: kfox1111 <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
* Adjust deployment paths
Signed-off-by: Mariusz Sabath <[email protected] >
* Remove the production README changes
Signed-off-by: Mariusz Sabath <[email protected] >
* Minor text edits
Signed-off-by: Mariusz Sabath <[email protected] >
* Fix incorrect namespace value
Signed-off-by: Mariusz Sabath <[email protected] >
* Updat Tornjak README
Signed-off-by: Mariusz Sabath <[email protected] >
* Update Keycloak README
Signed-off-by: Mariusz Sabath <[email protected] >
* Text updates in Keycloak doc
Signed-off-by: Mariusz Sabath <[email protected] >
* Post-review updates
Signed-off-by: Mariusz Sabath <[email protected] >
* Update Tornjak message for User Management
Signed-off-by: Mariusz Sabath <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Mohammed Abdi <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
* Update Tornjak deployment doc
Signed-off-by: Mariusz Sabath <[email protected] >
* Improve the Tornjak Auth message
Signed-off-by: Mariusz Sabath <[email protected] >
* Fix error with incorrect Ingress value
Signed-off-by: Mariusz Sabath <[email protected] >
* Fix documentation format
Signed-off-by: Mariusz Sabath <[email protected] >
* Update parameter format
Signed-off-by: Mariusz Sabath <[email protected] >
* Removed redundand doc sections
Signed-off-by: Mariusz Sabath <[email protected] >
---------
Signed-off-by: Mariusz Sabath <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
Co-authored-by: Mohammed Abdi <[email protected] >
2024-05-09 04:26:17 -07:00
dependabot[bot]
a9b04fd86c
Bump github.com/onsi/ginkgo/v2 from 2.17.2 to 2.17.3 in /tests ( #353 )
2024-05-07 22:16:18 -07:00
kfox1111 and Faisal Memon
be560d95d8
Check for a misconfiguration of bundle endpoint profiles ( #348 )
...
* Check for a misconfiguration of bundle endpoint profiles
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/charts/spire-server/templates/configmap.yaml
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-05-08 03:38:04 +00:00
kfox1111
b2e9f40774
Bump spire version ( #352 )
...
Signed-off-by: Kevin Fox <[email protected] >
2024-05-07 20:16:15 -07:00
spire-helm-version-checker[bot] and marcofranssen
7165b20ddf
Bump test chart dependencies ( #350 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
2024-05-06 12:57:43 -07:00
kfox1111
da4ebdfcaf
Fix federation certificate name when upstream enabled ( #347 )
...
When both federation certificates and upstream authority both
use cert-manager, there is a naming conflict.
Signed-off-by: Kevin Fox <[email protected] >
2024-05-03 14:17:31 -07:00
Mariusz Sabath and kfox1111
c37de1ea0c
Fix Tornjak logsDir for Openshift ( #344 )
...
* Fix Tornjak logsDir for Openshift
Signed-off-by: Mariusz Sabath <[email protected] >
* Update docs
Signed-off-by: Mariusz Sabath <[email protected] >
* Update charts/spire/charts/tornjak-frontend/templates/_helpers.tpl
Co-authored-by: kfox1111 <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
---------
Signed-off-by: Mariusz Sabath <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2024-05-03 08:04:38 -07:00
kfox1111 and Faisal Memon
8fef1bd050
Add external spire-controller-managers ( #284 )
...
* Complete Server K8S PSAT support
Add all the SPIRE Server supported options for the K8S PSAT attestor. This retains the
ease of use for configuring local cluster support while adding the ability to configure
multiple/external clusters as well. Kubeconfig support is added in its own config block
as it will be used/shared with spire-controller-manager support in the future.
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Add support for integration tests in the tests/integration dir
Signed-off-by: Kevin Fox <[email protected] >
* Fix split issue and typo
Signed-off-by: Kevin Fox <[email protected] >
* Add basic psat test
Signed-off-by: Kevin Fox <[email protected] >
* Fix linter
Signed-off-by: Kevin Fox <[email protected] >
* Fix up test
Signed-off-by: Kevin Fox <[email protected] >
* Add missing file
Signed-off-by: Kevin Fox <[email protected] >
* Better encode config
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Update docs
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Add external k8s bundler
Adds support to sync the CA bundle to configmaps in external
Kubernetes clusters
Signed-off-by: Kevin Fox <[email protected] >
* Update default
Signed-off-by: Kevin Fox <[email protected] >
* Fix config file layout. Incorperate feedback.
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Update based on parent pr feedback
Signed-off-by: Kevin Fox <[email protected] >
* Reformat config file
Signed-off-by: Kevin Fox <[email protected] >
* Fix some things
Signed-off-by: Kevin Fox <[email protected] >
* Reconfigure kind
Signed-off-by: Kevin Fox <[email protected] >
* More debugging
Signed-off-by: Kevin Fox <[email protected] >
* Fix up kind
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Add external spire-controller-managers
Only one external controller manager is supported at a time until
https://github.com/spiffe/spire/issues/4898 is resolved.
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Upgrade to spire-controller-manager 0.5.0
Signed-off-by: Kevin Fox <[email protected] >
* Update for released 0.5.0
Signed-off-by: Kevin Fox <[email protected] >
* Merge in some of the id prefix pr
Signed-off-by: Kevin Fox <[email protected] >
* Entry ID Prefix (#287 )
* Add Entry ID Prefix support
Signed-off-by: Kevin Fox <[email protected] >
* Mulitcluster test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Implement cleanup setting too
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Bump up test container
Signed-off-by: Kevin Fox <[email protected] >
* Swith to testing with nightly
Signed-off-by: Kevin Fox <[email protected] >
* Fix value name
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix up doc formatting
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-05-02 21:08:31 +00:00
Drew Wells
ee124042c2
set refresh hint to 1/3 of default CA TTL value fixes #335 ( #343 )
...
Signed-off-by: Drew Wells <[email protected] >
2024-05-02 13:24:51 -07:00
dependabot[bot]
f8fd46a28d
Bump github.com/onsi/gomega from 1.33.0 to 1.33.1 in /tests ( #340 )
...
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega ) from 1.33.0 to 1.33.1.
- [Release notes](https://github.com/onsi/gomega/releases )
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/gomega/compare/v1.33.0...v1.33.1 )
---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-30 08:10:29 -07:00
2d9866ada2
Bump test chart dependencies ( #338 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2024-04-29 06:10:16 -07:00
dependabot[bot]
d92e8b0497
Bump github.com/onsi/ginkgo/v2 from 2.17.1 to 2.17.2 in /tests ( #337 )
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.17.1 to 2.17.2.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.17.1...v2.17.2 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-29 05:15:11 -07:00
kfox1111
6de23d3303
Don't create role/binding when bundle disabled ( #336 )
...
When the bundle notifier is disabled, there is no need to create
a role and role binding for it.
Signed-off-by: Kevin Fox <[email protected] >
2024-04-26 14:21:16 -07:00
kfox1111
c132cc481e
Add support for externalServer=true ( #303 )
2024-04-26 19:19:01 +00:00
a2494ee45e
Add auth option for Tornjak ( #259 )
...
* Added auth option, specifically keycloak for tornjak production use
Signed-off-by: Mohammed Abdi <[email protected] >
* Added auth values for tornjak
Signed-off-by: Mohammed Abdi <[email protected] >
* Update charts/spire/charts/tornjak-frontend/values.yaml
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* nit
Signed-off-by: Mohammed Abdi <[email protected] >
* nit
Signed-off-by: Mohammed Abdi <[email protected] >
* nit
Signed-off-by: Mohammed Abdi <[email protected] >
* Update examples/tornjak/keycloak/README.md
Co-authored-by: Mariusz Sabath <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
* nit
Signed-off-by: Mohammed Abdi <[email protected] >
* install keycloak first
Signed-off-by: Mohammed Abdi <[email protected] >
* add logs volume back
Signed-off-by: Mohammed Abdi <[email protected] >
* Fixed NPM init error
Signed-off-by: Mariusz Sabath <[email protected] >
* Fixed the values documentation errors
Signed-off-by: Mariusz Sabath <[email protected] >
* Post-review suggestion fixes
Signed-off-by: Mariusz Sabath <[email protected] >
* Fixed typo
Signed-off-by: Mariusz Sabath <[email protected] >
* Updating Keyclaok examples README
Signed-off-by: Mariusz Sabath <[email protected] >
* Fixed the parameter reference
Signed-off-by: Mariusz Sabath <[email protected] >
* Fix typo
Signed-off-by: Mariusz Sabath <[email protected] >
* use keycloak-config-cli to simplify tornjak realm import
Signed-off-by: MohammedAbdi <[email protected] >
* edit client id
Signed-off-by: MohammedAbdi <[email protected] >
* reverse client id
Signed-off-by: MohammedAbdi <[email protected] >
* fix the doc
Signed-off-by: Mariusz Sabath <[email protected] >
* update tornjak version and backend auth
Signed-off-by: MohammedAbdi <[email protected] >
* update client id
Signed-off-by: MohammedAbdi <[email protected] >
* updates values yaml
Signed-off-by: MohammedAbdi <[email protected] >
* update documentation
Signed-off-by: MohammedAbdi <[email protected] >
* nit
Signed-off-by: MohammedAbdi <[email protected] >
* update doc
Signed-off-by: MohammedAbdi <[email protected] >
* add audience check tornjak
Signed-off-by: MohammedAbdi <[email protected] >
* remove unused file
Signed-off-by: MohammedAbdi <[email protected] >
* update doc
Signed-off-by: MohammedAbdi <[email protected] >
* nit and add auth not enabled warning back
Signed-off-by: MohammedAbdi <[email protected] >
* adjust liveness probe until tornjak handles liveendpoint for auth and direct connection to discovery
Signed-off-by: MohammedAbdi <[email protected] >
* update doc and add keycloak proxy
Signed-off-by: MohammedAbdi <[email protected] >
---------
Signed-off-by: Mohammed Abdi <[email protected] >
Signed-off-by: Mohammed Abdi <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
Signed-off-by: MohammedAbdi <[email protected] >
Co-authored-by: Mohammed Abdi <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
Co-authored-by: Mariusz Sabath <[email protected] >
2024-04-25 15:49:20 -07:00
spire-helm-version-checker[bot] and marcofranssen
f679a0dab6
Bump test chart dependencies ( #333 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected] >
2024-04-22 06:34:39 -07:00
Kevin Fox
5149256671
Work around curl change
...
Signed-off-by: Kevin Fox <[email protected] >
2024-04-19 16:36:40 +02:00
marcofranssen
3d2ac166b9
Bump test chart dependencies
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2024-04-19 16:36:40 +02:00
dependabot[bot]
184372690a
Bump github.com/onsi/gomega from 1.32.0 to 1.33.0 in /tests ( #332 )
...
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega ) from 1.32.0 to 1.33.0.
- [Release notes](https://github.com/onsi/gomega/releases )
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/gomega/compare/v1.32.0...v1.33.0 )
---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-19 06:58:44 -07:00
kfox1111 and Marco Franssen
08f699bdb0
Add spire-lib chart ( #289 )
...
* Add spire-lib chart
Make spire-lib bits into its own library chart.
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Marco Franssen <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Move notes back
Signed-off-by: Kevin Fox <[email protected] >
* Fix NOTES
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Marco Franssen <[email protected] >
2024-04-18 08:21:31 -07:00
kfox1111 and Faisal Memon
260b02f973
Add an easy to use identity for child servers ( #302 )
...
Signed-off-by: Kevin Fox <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-04-16 08:35:07 -07:00
dependabot[bot] and kfox1111
1304364770
Bump helm.sh/helm/v3 from 3.14.3 to 3.14.4 in /tests ( #325 )
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.14.3 to 3.14.4.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.14.3...v3.14.4 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: kfox1111 <[email protected] >
2024-04-11 19:27:38 -07:00
Faisal Memon
27689e797b
Bump spire Helm Chart version from 0.19.2 to 0.20.0 ( #329 )
...
* 1bf3aa7 Default spire-server port 443 (#308 )
* 1ef979c Remove upgrade hook needed in 0.19.x (#317 )
* aa92791 Upgrade to spire-controller-manager 0.5.0 (#316 )
* c1e4feb Fix ingress host with a dot (#323 )
* 5b1bf43 Update spire to 1.9.4 (#324 )
* dcd11e9 Fix chainguard issue (#326 )
* bc79f58 AWS KMS key_identifier upgrade (#314 )
Signed-off-by: Faisal Memon <[email protected] >
2024-04-11 16:10:50 -07:00
Faisal Memon
a5613b8cd7
Bump spire-crds Helm Chart version from 0.3.0 to 0.4.0 ( #328 )
...
* aa92791 Upgrade to spire-controller-manager 0.5.0 (#316 )
Signed-off-by: Faisal Memon <[email protected] >
2024-04-11 15:56:57 -07:00
kfox1111 and Faisal Memon
1bf3aa77ef
Default spire-server port 443 ( #308 )
...
Changes the default service port for the spire-server to 443 to allow easier switching between internal access and external access through an ingress controller.
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: Faisal Memon <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-04-11 12:29:28 -07:00
kfox1111 and Faisal Memon
1ef979c4e7
Remove upgrade hook needed in 0.19.x ( #317 )
...
Signed-off-by: Kevin Fox <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-04-11 12:00:34 -07:00
kfox1111
aa92791df2
Upgrade to spire-controller-manager 0.5.0 ( #316 )
...
* Upgrade to spire-controller-manager 0.5.0
Signed-off-by: Kevin Fox <[email protected] >
* Update for released 0.5.0
Signed-off-by: Kevin Fox <[email protected] >
* Fix up doc formatting
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
2024-04-11 11:58:00 -07:00
kfox1111
c1e4feb34d
Fix ingress host with a dot ( #323 )
...
Fixes: https://github.com/spiffe/helm-charts-hardened/issues/312
Signed-off-by: Kevin Fox <[email protected] >
2024-04-11 11:16:08 -07:00
kfox1111
5b1bf432f4
Update spire to 1.9.4 ( #324 )
...
Signed-off-by: Kevin Fox <[email protected] >
2024-04-11 11:15:05 -07:00
kfox1111
dcd11e9ff4
Fix chainguard issue ( #326 )
...
Chainguard renamed an image we depend on. Update to the new name.
Signed-off-by: Kevin Fox <[email protected] >
2024-04-11 11:14:05 -07:00
anhpatel and kfox1111
bc79f58ab7
AWS KMS key_identifier upgrade ( #314 )
...
* Allow use of key_identifier_file or key_identifier_value in place of key_metadata_file
Signed-off-by: aniket patel <[email protected] >
* Change key identifier values to have enabled flags
Signed-off-by: aniket patel <[email protected] >
* Update charts/spire/charts/spire-server/templates/configmap.yaml
Co-authored-by: kfox1111 <[email protected] >
Signed-off-by: anhpatel <[email protected] >
* Update charts/spire/charts/spire-server/templates/configmap.yaml
Co-authored-by: kfox1111 <[email protected] >
Signed-off-by: anhpatel <[email protected] >
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: kfox1111 <[email protected] >
Signed-off-by: anhpatel <[email protected] >
* Update docs
Signed-off-by: aniket patel <[email protected] >
* Update charts/spire/charts/spire-server/values.yaml
Co-authored-by: kfox1111 <[email protected] >
Signed-off-by: anhpatel <[email protected] >
* Update docs
Signed-off-by: aniket patel <[email protected] >
---------
Signed-off-by: aniket patel <[email protected] >
Signed-off-by: anhpatel <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2024-04-10 06:26:10 -07:00
Faisal Memon
7aa8cb360e
Bump spire Helm Chart version from 0.19.1 to 0.19.2
...
* 38e72d1 Update spire-controller-manager to 0.4.4 (#318 )
* 3736010 Update spire to 1.9.3 (#315 )
* fafed66 Add global for storageClass (#307 )
* 0b99a72 Add config for experimental events based cache (#311 )
* 8a542ab nameOverride autoconfig support (#305 )
* af2639e Bump test chart dependencies (#310 )
Signed-off-by: Faisal Memon <[email protected] >
2024-04-05 16:42:33 -07:00
kfox1111
38e72d111d
Update spire-controller-manager to 0.4.4 ( #318 )
...
* Update spire-controller-manager to 0.4.4
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
2024-04-05 23:19:59 +00:00
kfox1111
373601086e
Update spire to 1.9.3 ( #315 )
...
Signed-off-by: Kevin Fox <[email protected] >
2024-04-05 13:37:37 -07:00
kfox1111 and Faisal Memon
fafed66866
Add global for storageClass ( #307 )
...
When you have multiple spire servers, they often all need to be
configured to use the same storage class. Let them all be set
to the same value all at once.
Signed-off-by: Kevin Fox <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-04-02 23:28:55 +00:00