Commit Graph
738 Commits
Author SHA1 Message Date
spire-helm-version-checker[bot]andmarcofranssen 7afffd75ca Bump test chart dependencies (#771)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-03-16 11:36:52 +01:00
anhpatel 60899fc9d2 Add configurable hostNetwork support to spiffe-csi-driver (#769)
Signed-off-by: aniket patel <[email protected]>
2026-03-10 14:09:31 -07:00
spire-helm-version-checker[bot]andmarcofranssen 2de363a4a6 Bump test chart dependencies (#767)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-03-09 09:01:33 -07:00
Shubham Hibare 6631349bbb feat(spire-server): add logEncoding parameter for controller-manager (#766)
Signed-off-by: Shubham Hibare <[email protected]>
2026-03-05 09:57:44 -08:00
Faisal Memon 8afe8cf6e7 Bump spire Helm Chart version from 0.28.2 to 0.28.3
* 2385c2d7 Bump spire to 1.14.2 (#763)

Signed-off-by: Faisal Memon <[email protected]>
2026-03-04 07:58:57 -08:00
Faisal Memon 20940774d1 Bump spire-nested Helm Chart version from 0.28.2 to 0.28.3
* 2385c2d7 Bump spire to 1.14.2 (#763)

Signed-off-by: Faisal Memon <[email protected]>
2026-03-04 07:38:32 -08:00
kfox1111 2385c2d7a2 Bump spire to 1.14.2 (#763) 2026-03-04 00:57:14 +00:00
Faisal Memon 85989b45eb Bump spire Helm Chart version from 0.28.1 to 0.28.2
* 24b3a173 Change hostNetwork to auto (#758)
* 0133d4a5 add key experimental.requirePQKEM for spire-server and spire-agent (#755)
* 0a841c76 Bump test chart dependencies (#759)
* a9bee70c feat(spiffe-oidc-discovery-provider): Add configurable log format option. (#757)
* bb4c0f33 chore: Bump controller manager image tag to 0.6.3 in README and values.yaml (#756)
* 3e8f3f18 Bump test chart dependencies (#753)
* b0aa3e42 Fix duplicate port names in controller-manager containers (#751)
* 3daadc64 fix(spire-server): Support duration strings for connMaxLifetime (#752)
* 730b76bb Bump test chart dependencies (#750)
* e849a1fb Add configurable hostNetwork parameter for spire-agent (#749)
* 982d53c2 Add ContainerResource scaling to spire-server HPA (#746)
* 8abac78a Support leaderElection values in controller manager (#740)
* 75ffbd06 Add imagePullSecrets support to helm hook jobs (#741)
* 141c8865 Add pobLabels support to csi and oidc (#744)
* 6b5d01b7 Bump test chart dependencies (#743)
* ba2b6a5a Add controller-manager metrics to PodMonitor (#748)
* 86a806f3 Add tolerations to spire-server hook pods (#742)
* 7d266454 Fix keyManager check stopping use of unsupported bulit-in plugin (#715)
* 666d304c Bump test chart dependencies (#738)
* a7ac6a49 feat(spire-server): add logFormat configuration option (#735)

Signed-off-by: Faisal Memon <[email protected]>
2026-03-03 15:21:39 -08:00
Faisal Memon 6937ae01a2 Bump spire-nested Helm Chart version from 0.28.1 to 0.28.2
Signed-off-by: Faisal Memon <[email protected]>
2026-03-03 15:02:10 -08:00
Faisal Memon 24b3a1730e Change hostNetwork to auto (#758) 2026-03-03 21:56:48 +00:00
Daniel Schlatterandkfox1111 0133d4a5a7 add key experimental.requirePQKEM for spire-server and spire-agent (#755)
Signed-off-by: Daniel Schlatter <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-03-03 06:31:44 -08:00
spire-helm-version-checker[bot]andmarcofranssen 0a841c76a2 Bump test chart dependencies (#759)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-03-02 10:03:57 +01:00
Shubham Hibare a9bee70c0b feat(spiffe-oidc-discovery-provider): Add configurable log format option. (#757)
Signed-off-by: Shubham Hibare <[email protected]>
2026-02-25 14:20:59 -08:00
Shubham Hibare bb4c0f33ce chore: Bump controller manager image tag to 0.6.3 in README and values.yaml (#756)
* chore: Bump controller manager image tag to 0.6.3 in README and values.yaml

Signed-off-by: Shubham Hibare <[email protected]>

* chore: Trigger CI rerun

Signed-off-by: Shubham Hibare <[email protected]>

---------

Signed-off-by: Shubham Hibare <[email protected]>
2026-02-25 06:55:42 -08:00
3e8f3f1893 Bump test chart dependencies (#753)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-02-23 16:15:40 +00:00
Rowan Ruselerandkfox1111 b0aa3e4266 Fix duplicate port names in controller-manager containers (#751)
* Fix duplicate port names in controller-manager containers

Multiple controller-manager containers were using the same "heathz" port
name, causing Kubernetes warnings about duplicate ports in the
StatefulSet. This also affected the prometheus port "prom-cm".

Changes:
* Renamed healthz port to hp-cm (health port - controller manager)
* Renamed prom-cm to pm-cm for consistency
* Addedd {{ .portSuffix }} variable to differentiate external controller
  ports
* Implemented port suffix logic

The suffix logic handles cluster names by:
1. Names <9 chars: use full name as suffic
  * e.g.: child01 -> -child01
2. Names with trailing numbers: preserve the number format users chose
  * Detects 1-2 digit numbers with optional hyphen
  * Truncates base name to fit within 15 chars
  * e.g.: verlongcluster-01 -> -verylo-01
3. Names without numbers: use SHA-256 hash for uniqueness
  * Trunactes name to 5 chars and appends 3-char hash
  * e.g.: verlongclustername -> -veryl-a3f

The logic separates container suffix (full name) from port suffix
(truncated) so container names remain descriptive while port names stay
compliant.

Fixes #525 #655

Signed-off-by: Rowan Ruseler <[email protected]>

* Add optional port name overrides for ext. controller

The auto-generated port name suffixes for external controller manager
can collide when cluster names are similar, as the 3-character has
provides only 4,096 possibilities. With the optional healthPortName and
prometheusPortName fields to cluster configuration, allows users to
explicity set port names when automatica generation creates collisions.

Signed-off-by: Rowan Ruseler <[email protected]>

* Fix portSuffix generation

Changed from "and" to "or", so portSuffic is calculated when either
healthPortName or prometheusPortName is unset.

Signed-off-by: Rowan Ruseler <[email protected]>

---------

Signed-off-by: Rowan Ruseler <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-02-23 15:20:25 +01:00
Shubham Hibare 3daadc6456 fix(spire-server): Support duration strings for connMaxLifetime (#752)
* fix(spire-server): Support duration strings for connMaxLifetime

Signed-off-by: Shubham Hibare <[email protected]>

* fix

Signed-off-by: Shubham Hibare <[email protected]>

---------

Signed-off-by: Shubham Hibare <[email protected]>
2026-02-19 10:55:11 -08:00
spire-helm-version-checker[bot]andmarcofranssen 730b76bbaa Bump test chart dependencies (#750)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-02-16 05:48:10 -08:00
Rowan Ruselerandkfox1111 e849a1fbd6 Add configurable hostNetwork parameter for spire-agent (#749)
* Add configurable hostNetwork parameter for spire-agent

Adds `hostNetwork` as a configurable parameter in the spire-agent chart.
We can now explicitly control whether the spire-agent daemonset uses
host networking.

Changes:
* Updated daemonset template
* Changed `dnsPolicy` logic to follow the computed `hostNetwork` instead
  of kubelet mode directly
* Updated documentation

Behaviour:
If you leave `hostNetwork` empty (the default), it behaves like PR #705:
* automatically disables when using hostname or hostip kubelet modes
* automatically enables for localhost

If you set it explicitly to `true` or `false`, that overrides the
automatic behaviour. When `hostNetwork` is enabled and you haven't set a
custom `dnsPolicy`, it defaults to `ClusterFirstWithHostNet`.

Fixes #704

Signed-off-by: Rowan Ruseler <[email protected]>

* Fix merge conflict, different default value for fsGroupFix.image.tag

Signed-off-by: Rowan Ruseler <[email protected]>

---------

Signed-off-by: Rowan Ruseler <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-02-14 00:57:20 +00:00
Jayme Howardandkfox1111 982d53c200 Add ContainerResource scaling to spire-server HPA (#746)
* Add ContainerResource scaling to spire-server HPA

Signed-off-by: Jayme Howard <[email protected]>

* Amend flag name to address feedback

Signed-off-by: Jayme Howard <[email protected]>

---------

Signed-off-by: Jayme Howard <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-02-14 00:29:22 +00:00
Pratik Lotia 8abac78a15 Support leaderElection values in controller manager (#740) 2026-02-11 15:58:54 -08:00
Rowan Ruseler 75ffbd06f5 Add imagePullSecrets support to helm hook jobs (#741)
* Add imagePullSecrets support to helm hook jobs

Hook jobs lacked imagePullSecrets configuration on their pod specs,
causing image pull failures in environments using private registries
with authentication

* spire-server: post-install, pre-upgrade, post-upgrade, pre-delete
  hooks
* spire-oidc-discovery-provider: pre-delete hook
* spike-nexus: bootstrap hook
* spire: global imagePullSecrets

Fixes #649

Signed-off-by: Rowan Ruseler <[email protected]>

* Document global.imagePullSecrets parameter

Signed-off-by: Rowan Ruseler <[email protected]>

* Replaced non functioning 'or' with 'coalesce'

Signed-off-by: Rowan Ruseler <[email protected]>

---------

Signed-off-by: Rowan Ruseler <[email protected]>
2026-02-11 15:16:16 -08:00
Rowan Ruselerandkfox1111 141c8865a3 Add pobLabels support to csi and oidc (#744)
spiffe-csi-driver and spiffe-oidc-discovery provider are now brought in
line with spire-server and spire-agent, which already support podLabels.

Changes:
* Add podLabels parameter

Fixes #719

Signed-off-by: Rowan Ruseler <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-02-10 15:03:54 -08:00
6b5d01b74c Bump test chart dependencies (#743)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-02-10 22:03:09 +00:00
Pratik Lotia ba2b6a5a02 Add controller-manager metrics to PodMonitor (#748)
Signed-off-by: pratik-lotia <[email protected]>
2026-02-10 13:23:33 -08:00
Alec Wilson 86a806f3c6 Add tolerations to spire-server hook pods (#742)
Applies the tolerations in the spire-server chart to the pods created
by the hooks. Previously they were only applied to the pods of the
server itself.

Signed-off-by: Alec Wilson <[email protected]>
2026-02-09 00:32:56 +00:00
Alec Wilson 7d2664544d Fix keyManager check stopping use of unsupported bulit-in plugin (#715)
Adds unsupported built-in plugins (built-in plugins that do not have
direct toggles in the helm chart) to the check that exactly one
key manager plugin is enabled - the previous check only allowed usage
of key manager plugins with explicit values in the helm chart.

This still doesn't allow usage of custom key manager plugins - as they
will not be present in the count that is checked.

Signed-off-by: Alec Wilson <[email protected]>
2026-02-08 16:13:43 -08:00
spire-helm-version-checker[bot]andmarcofranssen 666d304ce2 Bump test chart dependencies (#738)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-02-02 11:52:44 +01:00
Shubham Hibare a7ac6a494d feat(spire-server): add logFormat configuration option (#735)
* Add logFormat support to spire-server chart

Adds the ability to configure SPIRE server log format (text or json)
via the logFormat helm value. When set, it renders as log_format in
the server configuration.

Signed-off-by: Shubham Hibare <[email protected]>

* add default value

Signed-off-by: Shubham Hibare <[email protected]>

* fix

Signed-off-by: Shubham Hibare <[email protected]>

* fix

Signed-off-by: Shubham Hibare <[email protected]>

---------

Signed-off-by: Shubham Hibare <[email protected]>
2026-01-30 13:39:47 -08:00
Faisal Memon 28f95d263b Bump spire-nested Helm Chart version from 0.28.0 to 0.28.1
Signed-off-by: Faisal Memon <[email protected]>
2026-01-27 09:17:32 -08:00
Faisal Memon c826e29705 Bump spire Helm Chart version from 0.28.0 to 0.28.1
* e99d9609 Bump test chart dependencies (#732)
* a7abf7d7 disable hostNetwork on spire-agent daemonset if connect by hostname is true (#705)

Signed-off-by: Faisal Memon <[email protected]>
2026-01-27 09:09:02 -08:00
e99d96097c Bump test chart dependencies (#732)
* Bump test chart dependencies

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* Update docs

Signed-off-by: Kevin Fox <[email protected]>

---------

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: kfox1111 <[email protected]>
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: marcofranssen <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-01-26 14:43:53 -08:00
Daniel SchlatterandFaisal Memon a7abf7d7ec disable hostNetwork on spire-agent daemonset if connect by hostname is true (#705)
* disable hostNetwork on spire-agent daemonset if connect by hostname is true

Signed-off-by: Daniel Schlatter <[email protected]>

* allow spire-agent daemonset dnsPolicy to be configured

Signed-off-by: Daniel Schlatter <[email protected]>

---------

Signed-off-by: Daniel Schlatter <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
2026-01-26 12:40:57 -08:00
Faisal Memonandkfox1111 3c724632ee Bump spire Helm Chart version from 0.27.1 to 0.28.0 (#731)
* 6f2c71b0 Update spire to 1.14.1 (#729)
* f8f1e21f CSI driver: Support setting podSecurityContext and securityContext (#642)
* 813203a4 Update spike to the newest version (#665)
* 97c383b1 Add Configurable Kubelet Address for SPIRE Agent (#709)
* 8555efc6 Bump test chart dependencies
* e6c9d975 Bump test chart dependencies
* 87da80a8 Add support for AWS KMS key tagging (#721)
* db8f1352 Bump test chart dependencies (#720)
* b1f902b6 Bump test chart dependencies
* 198cdb60 Bump test chart dependencies
* dfbbecf0 Add guard to the validating admission policy to stop errors when there are no volumes in the spec. This fixes errors with HTTP solver pods in cert manager. (#706)
* 1e1e8daa Add support for attested node pruning configuration (#713)
* a2130ff7 Bump test chart dependencies (#712)
* adc5f3e8 Bump test chart dependencies
* 4e0cdb13 Bump test chart dependencies
* 95fa0deb Allow configuring spire-agent prometheus listening address (#701)

Signed-off-by: Faisal Memon <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-01-26 19:42:54 +00:00
Faisal Memon 0ceaed05cc Bump spire-nested Helm Chart version from 0.27.1 to 0.28.0 (#730)
* 6f2c71b0 Update spire to 1.14.1 (#729)

Signed-off-by: Faisal Memon <[email protected]>
2026-01-26 11:22:17 -08:00
kfox1111 6f2c71b04d Update spire to 1.14.1 (#729)
Signed-off-by: Kevin Fox <[email protected]>
2026-01-23 21:15:49 +00:00
f8f1e21f7d CSI driver: Support setting podSecurityContext and securityContext (#642)
* Allow for both the pod security context and container security contexts to be overriden through the spiffe-csi-driver values file

Signed-off-by: Alec Holmes <[email protected]>

* newline

Signed-off-by: Alec Holmes <[email protected]>

* fix space

Signed-off-by: Alec Holmes <[email protected]>

* Update docs

Signed-off-by: Kevin Fox <[email protected]>

---------

Signed-off-by: Alec Holmes <[email protected]>
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
2026-01-23 20:55:14 +00:00
813203a4d2 Update spike to the newest version (#665)
* Update spike bits

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Add trust roots.

SPIKE SDK uses the appropriate trust root from the environment which makes SDK usage easier, but it requires additional env vars on the pod meta.

Signed-off-by: Volkan Özçelik <[email protected]>

* Chart updates to make it work with the new SDK changes of SPIKE.

Signed-off-by: Volkan Özçelik <[email protected]>

* Making the self-reference more evident.

Signed-off-by: Volkan Özçelik <[email protected]>

* Documentation update.

Signed-off-by: Volkan Özçelik <[email protected]>

* Documentation update.

Signed-off-by: Volkan Özçelik <[email protected]>

* updates to align with recent SPIKE.

* SPIKE assumes all trust roots can be arrays (for distributed setups), modified values accordingly.
* Added cross-references between bootstrap and keeper job/statefulsets for PoP validation to work.
* other possible minor updates.

Signed-off-by: Volkan Özçelik <[email protected]>

* minor changes.

Signed-off-by: Volkan Özçelik <[email protected]>

* Update docs

---------

Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: Volkan Özçelik <[email protected]>
Co-authored-by: Volkan Özçelik <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
2026-01-23 12:32:18 -08:00
Oliver Bassettandkfox1111 97c383b1cb Add Configurable Kubelet Address for SPIRE Agent (#709)
* Add kubeletAddress.mode configuration to spire-agent

Introduces new enum-based configuration for kubelet connection modes:
- auto (default): hostname for OpenShift, localhost otherwise
- localhost: SPIRE default behavior (127.0.0.1:10250)
- hostname: Connect via node hostname
- hostip: Connect via node IP
- custom: User-provided configuration

Deprecates kubeletConnectByHostname but maintains backward compatibility.

Signed-off-by: Oliver Bassett <[email protected]>

* Replace connect-by-hostname helper with mode resolution

Adds three new helpers:
- spire-agent.kubelet-address-mode: Determine mode with backward compat
- spire-agent.kubelet-address-mode-resolved: Resolve auto to actual mode
- spire-agent.should-set-node-name-env: Determine if node_name_env needed

Includes validation of enum values and maintains backward compatibility
by keeping the old connect-by-hostname helper as deprecated.

Signed-off-by: Oliver Bassett <[email protected]>

* Update daemonset to use KUBELET_ADDR env variable

- Sets KUBELET_ADDR from downward API for hostname/hostip modes
- Maintains MY_NODE_NAME for backward compatibility
- No env var set for localhost mode (SPIRE default)
- Custom mode allows user control via extraEnvVars
- Updates init container env to support both hostname and hostip modes

Signed-off-by: Oliver Bassett <[email protected]>

* Update workload attestor config and add validation

- Changes node_name_env from MY_NODE_NAME to KUBELET_ADDR
- Adds validation for kubeletAddress.mode enum
- Prevents using both old and new config simultaneously

Signed-off-by: Oliver Bassett <[email protected]>

* Improve documentation for custom mode

Clarifies that custom mode does not validate KUBELET_ADDR presence,
allowing for external secret injection and other advanced configuration
methods.

Signed-off-by: Oliver Bassett <[email protected]>

* Fix backward compatibility for kubeletConnectByHostname

Two critical fixes for backward compatibility:

1. Helper template priority: Reorder kubelet-address-mode helper to
   prioritize kubeletConnectByHostname when kubeletAddress.mode is
   'auto' or empty. This ensures deprecated config still works.

2. Type-safe validation: Convert kubeletConnectByHostname to string
   in validation and helper to handle both boolean and string types
   consistently. Original chart required string type.

3. Smart dual-config validation: Only fail when both configs are
   explicitly set to non-default values. Allow kubeletConnectByHostname
   with mode='auto' for backward compatibility.

Tested scenarios:
- kubeletConnectByHostname='true' maps to hostname mode
- kubeletConnectByHostname='false' maps to localhost mode
- Both set with mode='auto' allows backward compat to take priority
- Both set with different non-defaults triggers validation error
- OpenShift auto mode correctly resolves to hostname mode

Signed-off-by: Oliver Bassett <[email protected]>

* Use parentheses for DEPRECATED tag in values.yaml

Change [DEPRECATED] to (DEPRECATED) to avoid conflicts with automated
README generator which uses square brackets for special tags.

Signed-off-by: Oliver Bassett <[email protected]>

* Update generated README documentation

Regenerate README.md from values.yaml using documentation generator.
Includes new kubeletAddress.mode configuration and deprecation notice
for kubeletConnectByHostname.

Signed-off-by: Oliver Bassett <[email protected]>

* Remove MY_NODE_NAME environment variable

Remove MY_NODE_NAME as it is not used within the spire-agent chart.
Initially kept for backwards compatibility concerns, but confirmed
unnecessary after review.

The KUBELET_ADDR environment variable is sufficient for the workload
attestor configuration via node_name_env setting.

Addresses PR feedback: https://github.com/spiffe/helm-charts-hardened/pull/709#discussion_r1909855869

Signed-off-by: Oliver Bassett <[email protected]>

* Fix init container for custom kubelet address mode

Address PR #709 feedback by standardizing on KUBELET_ADDR environment
variable and passing extraEnvVars to init containers.

Changes:

1. Init container env variable:
   - Renamed NODE_NAME to KUBELET_ADDR for consistency
   - Made hostip check explicit with 'else if'
   - Passes extraEnvVars to init container for custom mode support

2. Init container script:
   - Updated URL construction to use KUBELET_ADDR for all modes
   - Added validation for custom mode: fails with clear error if
     KUBELET_ADDR is not set via extraEnvVars
   - hostname/hostip modes: Use KUBELET_ADDR from downward API
   - custom mode: Use KUBELET_ADDR from extraEnvVars with validation
   - localhost mode: Use hardcoded 'localhost'

3. Documentation updates:
   - Updated custom mode docs to explain extraEnvVars is passed to
     both main and init containers
   - Noted init container validation behavior
   - Updated extraEnvVars param docs to mention init containers

Testing verified:
- Template rendering for all modes (hostname, hostip, custom, localhost)
- Runtime validation: deployed custom mode without KUBELET_ADDR to kind
  cluster, init container correctly failed with clear error message

Addresses: https://github.com/spiffe/helm-charts-hardened/pull/709#discussion_r1909855869
Signed-off-by: Oliver Bassett <[email protected]>

* Update generated README for init container changes

Regenerate README.md to reflect that extraEnvVars is now passed
to both the main container and init containers.

Signed-off-by: Oliver Bassett <[email protected]>

---------

Signed-off-by: Oliver Bassett <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-01-21 16:47:55 -08:00
marcofranssen 8555efc6f9 Bump test chart dependencies
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-01-19 18:38:03 +01:00
marcofranssen e6c9d975e7 Bump test chart dependencies
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-01-12 11:04:24 +01:00
Shubham HibareandMarco Franssen 87da80a89a Add support for AWS KMS key tagging (#721)
* Add support for AWS KMS key tagging

Signed-off-by: Shubham Hibare <[email protected]>

* fix doc

Signed-off-by: Shubham Hibare <[email protected]>

* Update charts/spire/charts/spire-server/templates/configmap.yaml

Co-authored-by: Marco Franssen <[email protected]>
Signed-off-by: Shubham Hibare <[email protected]>

---------

Signed-off-by: Shubham Hibare <[email protected]>
Signed-off-by: Shubham Hibare <[email protected]>
Co-authored-by: Marco Franssen <[email protected]>
2026-01-06 12:43:18 +01:00
spire-helm-version-checker[bot]andmarcofranssen db8f135204 Bump test chart dependencies (#720)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-01-05 08:20:43 +00:00
marcofranssen b1f902b670 Bump test chart dependencies
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-12-29 10:25:43 +01:00
marcofranssen 198cdb6075 Bump test chart dependencies
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-12-22 18:01:42 +01:00
Oliver Bassettandkfox1111 dfbbecf077 Add guard to the validating admission policy to stop errors when there are no volumes in the spec. This fixes errors with HTTP solver pods in cert manager. (#706)
Signed-off-by: Oliver Bassett <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2025-12-18 14:47:45 -08:00
Pratik Lotia 1e1e8daa69 Add support for attested node pruning configuration (#713)
Expose SPIRE server's prune_attested_nodes_expired_for and prune_tofu_nodes
configuration through new Helm values: pruneAttestedNodesExpiredFor and
pruneTOFUNodes.

This prevents database bloat from expired attested nodes in long-running
deployments with node churn.

Signed-off-by: pratik-lotia <[email protected]>
2025-12-18 14:23:30 -08:00
spire-helm-version-checker[bot]andmarcofranssen a2130ff72e Bump test chart dependencies (#712)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2025-12-15 10:10:05 +01:00
marcofranssen adc5f3e8c3 Bump test chart dependencies
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-12-08 09:26:17 +01:00
marcofranssen 4e0cdb1306 Bump test chart dependencies
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-12-01 10:56:08 +01:00