kfox1111 and Marco Franssen
6997d6a904
Add recommendation for securityContext and podSecurityContext ( #125 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-12-19 11:26:26 +00:00
kfox1111
50c4ac35b0
Add recommendation for strictMode ( #143 )
2023-12-19 12:12:53 +01:00
kfox1111 and Faisal Memon
a097606d77
Remove extra example values that are already set by default ( #128 )
...
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-12-12 16:23:23 +00:00
kfox1111
1524537318
Update default for additionalDomains not to include localhost ( #146 )
...
Its pretty much only useful if you want to port forward the
discovery provider and use localhost to access it. An uncommon
use case. Its easy to add back for that case. This simplifies
production deploymnet.
Signed-off-by: Kevin Fox <[email protected] >
2023-12-12 08:14:16 -08:00
kfox1111 and Faisal Memon
e35838c309
Add recommendation for priorityClass ( #124 )
...
* Add a flag to enable recommendations
Signed-off-by: Kevin Fox <[email protected] >
* Add recommendation for priorityClass
Signed-off-by: Kevin Fox <[email protected] >
* Fix vars
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Update docs. Fix typo.
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-12-11 11:42:40 -08:00
kfox1111 and Faisal Memon
3e8335c0ee
Add a flag to enable recommendations ( #121 )
...
* Add a flag to enable recommendations
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge issue
Signed-off-by: Kevin Fox <[email protected] >
* Update after reaching consensus.
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-12-02 05:15:32 -08:00
Mariusz Sabath
c9885de539
Introduce ReadOnlyRootFilesystem for Tornjak frontend ( #110 )
...
Signed-off-by: Mariusz Sabath <[email protected] >
2023-11-16 15:47:04 -08:00
kfox1111
50825d9fc9
Deny production runs of example.org trust domains ( #229 )
2023-09-25 12:06:48 -07:00
Inverse Integral
1f908676bb
Allow configuration of priorityClassName on spire-server statefulset ( #480 )
2023-09-12 22:31:23 +02:00
kfox1111
ae8941c49d
Support Nested Spire with External Agent ( #117 )
2023-08-16 16:35:41 +02:00
kfox1111 and Marco Franssen
c1b1dd3d88
Add additional domains to JWT issued items. ( #230 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-07-03 22:26:28 +02:00
a6dcf267d1
Allow for SPIRE Agent to run as non root user ( #209 )
...
Co-authored-by: Marco Franssen <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-06-17 10:32:41 +02:00
kfox1111
f8db5a313b
Fix Tornjak persistence issue ( #294 )
2023-05-18 01:54:26 +02:00
5e827ee45e
Add Tornjak Tests ( #220 )
...
Signed-off-by: Mariusz Sabath <[email protected] >
Signed-off-by: Marco Franssen <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Marco Franssen <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2023-05-16 19:31:38 +02:00
kfox1111
b82abab357
Revert "Switch to persistence" ( #210 )
...
Reverts spiffe/helm-charts#200
Signed-off-by: Kevin Fox <[email protected] >
2023-04-12 16:12:07 -04:00
kfox1111
0dec80e1d5
Switch to persistence ( #200 )
...
This patch switches the value to persistence to follow the helm
convention.
fixes: https://github.com/spiffe/helm-charts/issues/199
Signed-off-by: Kevin Fox <[email protected] >
2023-04-12 08:56:10 -07:00
Marco Franssen
b54c41aee0
Enhance the production example
...
Signed-off-by: Marco Franssen <[email protected] >
2023-03-31 15:48:40 +02:00
Marco Franssen
64d010757c
Resolve issue in prod example on volume mount ( #143 )
2023-03-21 04:39:59 -07:00
Kevin Fox
25c77fc0cb
Fix the driver not coming up on overloaded nodes
...
Add to the reference production example a fix for overloaded nodes.
fixes: https://github.com/spiffe/helm-charts/issues/80
Signed-off-by: Kevin Fox <[email protected] >
2023-03-14 20:10:51 +01:00
kfox1111
03db6bb5fe
Namespace override
...
This patch makes it possible to install the subcharts in different
namespaces as needed.
Signed-off-by: Kevin Fox <[email protected] >
2023-03-13 15:03:16 -07:00