Commit Graph
771 Commits
Author SHA1 Message Date
Bronson Mirafuentesanddependabot[bot] 86c60b186f feat(spire-server): add terminationGracePeriodSeconds (#835)
* feat(spire-server): add terminationGracePeriodSeconds and lifecycle support

Adds two new top-level values to the spire-server chart:

- `terminationGracePeriodSeconds` (nullable, pod-spec level): overrides the
  default 30s termination grace period. Useful when the server is behind a
  load balancer that needs time to deregister the target (e.g. AWS NLB with
  a deregistration delay > 30s).

- `lifecycle` (object, container level): lifecycle hooks for the spire-server
  container. The primary use case is a preStop hook to hold the pod alive
  while the load balancer deregisters the target before SIGTERM is sent:

  lifecycle:
    preStop:
      sleep:
        seconds: 60

Both fields default to their absent/empty equivalents (null and {}) so
existing deployments are unaffected.

Signed-off-by: Bronson Mirafuentes <[email protected]>

* Bump docker/login-action from 4.1.0 to 4.2.0 (#836)

Bumps [docker/login-action](https://github.com/docker/login-action) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](https://github.com/docker/login-action/compare/v4.1.0...v4.2.0)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Bronson Mirafuentes <[email protected]>

* feat(spire-server): remove lifecycle hook support

Lifecycle hooks are not needed for the terminationGracePeriodSeconds
use case; preStop semantics can be handled outside the chart.

Signed-off-by: Bronson Mirafuentes <[email protected]>

* update README

Signed-off-by: Bronson Mirafuentes <[email protected]>

* update README

Signed-off-by: Bronson Mirafuentes <[email protected]>

---------

Signed-off-by: Bronson Mirafuentes <[email protected]>
Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 12:12:33 -07:00
Faisal MemonandKevin Fox 98ec4e680b Bump spire-lib Helm Chart version from 0.1.0 to 0.2.0 (#822)
* Bump spire-lib and dependent Helm Chart versions (minor)

* 3c1dec30 fix casing of svidStore (#787)

Signed-off-by: Faisal Memon <[email protected]>

* Add missing repo reference

Signed-off-by: Kevin Fox <[email protected]>

---------

Signed-off-by: Faisal Memon <[email protected]>
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: Kevin Fox <[email protected]>
2026-06-06 10:33:41 -07:00
kfox1111 1afb4626f1 Update spire-controller-manager (#840)
Signed-off-by: Kevin Fox <[email protected]>
2026-06-04 18:11:03 +00:00
kfox1111 1031167b84 Implement easy Bottom Turtle HA support in the charts (#816)
* Implement easy Bottom Turtle HA support in the charts

Signed-off-by: Kevin Fox <[email protected]>

* Add diagram

Signed-off-by: Kevin Fox <[email protected]>

* Update docs

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes and tightened defaults

Signed-off-by: Kevin Fox <[email protected]>

* More diagrams

Signed-off-by: Kevin Fox <[email protected]>

* More instructions

Signed-off-by: Kevin Fox <[email protected]>

* More instructions

Signed-off-by: Kevin Fox <[email protected]>

* More instructions

Signed-off-by: Kevin Fox <[email protected]>

* More instructions

Signed-off-by: Kevin Fox <[email protected]>

* More instructions

Signed-off-by: Kevin Fox <[email protected]>

* Install some bottom turtle spire bits

Signed-off-by: Kevin Fox <[email protected]>

* Trigger in github

Signed-off-by: Kevin Fox <[email protected]>

* Fix path

Signed-off-by: Kevin Fox <[email protected]>

* Fix path

Signed-off-by: Kevin Fox <[email protected]>

* Fix path

Signed-off-by: Kevin Fox <[email protected]>

* Fix path

Signed-off-by: Kevin Fox <[email protected]>

* Fix path

Signed-off-by: Kevin Fox <[email protected]>

* Fix path

Signed-off-by: Kevin Fox <[email protected]>

* Fix shell code

Signed-off-by: Kevin Fox <[email protected]>

* Add some more testing

Signed-off-by: Kevin Fox <[email protected]>

* Add some more testing

Signed-off-by: Kevin Fox <[email protected]>

* Add some more testing

Signed-off-by: Kevin Fox <[email protected]>

* Add some more debug logging

Signed-off-by: Kevin Fox <[email protected]>

* More logging

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* Some fixes

Signed-off-by: Kevin Fox <[email protected]>

* More updates

Signed-off-by: Kevin Fox <[email protected]>

* More updates

Signed-off-by: Kevin Fox <[email protected]>

* More updates

Signed-off-by: Kevin Fox <[email protected]>

* More updates

Signed-off-by: Kevin Fox <[email protected]>

* More updates

Signed-off-by: Kevin Fox <[email protected]>

* More updates

Signed-off-by: Kevin Fox <[email protected]>

* More updates

Signed-off-by: Kevin Fox <[email protected]>

* More updates

Signed-off-by: Kevin Fox <[email protected]>

* More updates

Signed-off-by: Kevin Fox <[email protected]>

* More updates

Signed-off-by: Kevin Fox <[email protected]>

* More updates

Signed-off-by: Kevin Fox <[email protected]>

* Add x509POP support and more testing

Signed-off-by: Kevin Fox <[email protected]>

* x509pop attestor support and more tests

Signed-off-by: Kevin Fox <[email protected]>

* More updates

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Update docs

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Fix pages artifact upload

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Test some more bits

Signed-off-by: Kevin Fox <[email protected]>

* Initial stab at dynamic registration

Signed-off-by: Kevin Fox <[email protected]>

* Dynamic registration working but not integrated with test

Signed-off-by: Kevin Fox <[email protected]>

* Wire in dynamic registration into the test

Signed-off-by: Kevin Fox <[email protected]>

* Fix missing props

Signed-off-by: Kevin Fox <[email protected]>

* Update the svids to align

Signed-off-by: Kevin Fox <[email protected]>

* Update the svids to align

Signed-off-by: Kevin Fox <[email protected]>

* Fix service name

Signed-off-by: Kevin Fox <[email protected]>

* Look at data

Signed-off-by: Kevin Fox <[email protected]>

* Look at data

Signed-off-by: Kevin Fox <[email protected]>

* Look at data

Signed-off-by: Kevin Fox <[email protected]>

* Fix ca type

Signed-off-by: Kevin Fox <[email protected]>

* Test out new packages

Signed-off-by: Kevin Fox <[email protected]>

* Test out new packages

Signed-off-by: Kevin Fox <[email protected]>

* Test out new packages

Signed-off-by: Kevin Fox <[email protected]>

* Test out new packages

Signed-off-by: Kevin Fox <[email protected]>

* Test out new packages

Signed-off-by: Kevin Fox <[email protected]>

* Test out new packages

Signed-off-by: Kevin Fox <[email protected]>

* Test out new packages

Signed-off-by: Kevin Fox <[email protected]>

* Test out new packages

Signed-off-by: Kevin Fox <[email protected]>

* Test out new packages

Signed-off-by: Kevin Fox <[email protected]>

* Test out new packages

Signed-off-by: Kevin Fox <[email protected]>

* Update ports

Signed-off-by: Kevin Fox <[email protected]>

* Update ports

Signed-off-by: Kevin Fox <[email protected]>

* Work on debugging dynamic registration some more

Signed-off-by: Kevin Fox <[email protected]>

* Fix service account name

Signed-off-by: Kevin Fox <[email protected]>

* Fix service account name

Signed-off-by: Kevin Fox <[email protected]>

* Working... Cleanup.

Signed-off-by: Kevin Fox <[email protected]>

* Working... Cleanup.

Signed-off-by: Kevin Fox <[email protected]>

* Fix broken ssh test

Signed-off-by: Kevin Fox <[email protected]>

* Fix broken ssh test

Signed-off-by: Kevin Fox <[email protected]>

* Simplify a bit

Signed-off-by: Kevin Fox <[email protected]>

* Update to use the released images

Signed-off-by: Kevin Fox <[email protected]>

* Allow x509POP cluster name adding

Signed-off-by: Kevin Fox <[email protected]>

* Restrict cluster registration

Signed-off-by: Kevin Fox <[email protected]>

* Fix var name

Signed-off-by: Kevin Fox <[email protected]>

* Fix missing slash

Signed-off-by: Kevin Fox <[email protected]>

* Make defaults work better

Signed-off-by: Kevin Fox <[email protected]>

* Make defaults work better

Signed-off-by: Kevin Fox <[email protected]>

* Fix readme

Signed-off-by: Kevin Fox <[email protected]>

* updated diagram

Signed-off-by: Kevin Fox <[email protected]>

* Regenerate image

Signed-off-by: Kevin Fox <[email protected]>

* Bump spire versions

Signed-off-by: Kevin Fox <[email protected]>

* Fix issues identified during review

Signed-off-by: Kevin Fox <[email protected]>

* Update docs

Signed-off-by: Kevin Fox <[email protected]>

---------

Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
2026-06-03 12:15:28 -07:00
Bronson Mirafuentes 7c532f10bb feat(spire-server): add maxAttestedNodeInfoStaleness config option (#828)
* feat(spire-server): add maxAttestedNodeInfoStaleness configuration option

Wire max_attested_node_info_staleness into the spire-server ConfigMap.
When unset (default ""), the SPIRE server uses its built-in default of 0s.

Signed-off-by: Bronson Mirafuentes <[email protected]>

* docs: regenerate spire-server README via helm-docs.sh

Fixes trailing whitespace in the maxAttestedNodeInfoStaleness table row.

Signed-off-by: Bronson Mirafuentes <[email protected]>

---------

Signed-off-by: Bronson Mirafuentes <[email protected]>
2026-05-19 08:00:53 -07:00
Bronson Mirafuentesandkfox1111 9bdfc10ffe wire ratelimit configuration option in spire-server configMap (#826)
* feat(spire-server): add ratelimit.attestation and ratelimit.signing values

Signed-off-by: Bronson Mirafuentes <[email protected]>

* feat(spire-server): render ratelimit block in server config from values

Signed-off-by: Bronson Mirafuentes <[email protected]>

* chore: bump spire-server and spire chart versions for ratelimit feature

Signed-off-by: Bronson Mirafuentes <[email protected]>

* revert version bumps, use camelcase for rateLimit

Signed-off-by: Bronson Mirafuentes <[email protected]>

* update readme

Signed-off-by: Bronson Mirafuentes <[email protected]>

---------

Signed-off-by: Bronson Mirafuentes <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-05-14 13:18:56 -07:00
Pratik Lotia 806c6ae59e aws node attester: add org verification support (#825)
* add verify org support for aws node attester

Signed-off-by: pratik-lotia <[email protected]>

* refactor with suggested changes

Signed-off-by: pratik-lotia <[email protected]>

---------

Signed-off-by: pratik-lotia <[email protected]>
2026-05-12 12:25:07 -07:00
Faisal Memonandkfox1111 574fa87d57 Bump spire Helm Chart version from 0.28.4 to 0.28.5 (#817)
* c489dfc4 Update helper images in spiffe-csi-driver (#815)
* f537f770 allow unsupported built-in key manager plugins to be used (#798)
* c5ba8213 Bump test chart dependencies (#797)
* dfe80891 feat: add gcp_iit node attestor configuration options (#796)
* 21969d20 Bump test chart dependencies (#795)

Signed-off-by: Faisal Memon <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-05-07 05:04:38 -07:00
Faisal Memon 146cf1add6 Bump spire-nested Helm Chart version from 0.28.4 to 0.28.5 (#818)
Signed-off-by: Faisal Memon <[email protected]>
2026-05-03 05:52:41 -07:00
Daniel Schlatter c489dfc4db Update helper images in spiffe-csi-driver (#815)
csi-node-driver-registrar -> 2.15.0
ubi9 -> ubi10/ubi-minimal:10.1-1776834797

Signed-off-by: Daniel Schlatter <[email protected]>
2026-05-02 00:25:29 -07:00
Daniel Schlatter f537f7702f allow unsupported built-in key manager plugins to be used (#798)
Signed-off-by: Daniel Schlatter <[email protected]>
2026-04-23 05:31:17 -07:00
spire-helm-version-checker[bot]andmarcofranssen c5ba8213df Bump test chart dependencies (#797)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-04-20 04:27:18 -07:00
Jesper Engbergandkfox1111 dfe8089160 feat: add gcp_iit node attestor configuration options (#796)
* feat: add gcp_iit node attestor configuration options

Signed-off-by: Jesper Engberg <[email protected]>

* fix: align indentation

Signed-off-by: Jesper Engberg <[email protected]>

* fix: remove unused var

Signed-off-by: Jesper Engberg <[email protected]>

---------

Signed-off-by: Jesper Engberg <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-04-15 16:33:53 +00:00
Dávid Szakállas 3c1dec3035 fix casing of svidStore (#787)
Signed-off-by: Dávid Szakállas <[email protected]>
2026-04-15 09:08:25 -07:00
spire-helm-version-checker[bot]andmarcofranssen 21969d20f3 Bump test chart dependencies (#795)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-04-14 11:34:08 +02:00
Faisal Memon d334bfde50 Bump spiffe-step-ssh Helm Chart version from 0.1.1 to 0.1.2 (#794)
* 9273f11f Support root-level spire-lib chart reuse (#785)

Signed-off-by: Faisal Memon <[email protected]>
2026-04-11 08:52:09 -07:00
Faisal Memonandkfox1111 d65890e409 Bump spire-nested Helm Chart version from 0.28.3 to 0.28.4 (#792)
* 86787b59 Add initial spire-ha-agent support to the spire-nested chart (#790)
* 040ccf90 Bump versions to 1.14.5 (#789)
* 9273f11f Support root-level spire-lib chart reuse (#785)
* 96773a31 Bump versions (#777)

Signed-off-by: Faisal Memon <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-04-10 23:32:47 -07:00
Faisal Memon a062e49c91 Bump spire Helm Chart version from 0.28.3 to 0.28.4
* 01342172 Fix typos in error messages (#788)
* 040ccf90 Bump versions to 1.14.5 (#789)
* 9273f11f Support root-level spire-lib chart reuse (#785)
* 145f3a36 chore: Add configurable probes for controller-manager (#784)
* a27acbcb Bump test chart dependencies (#786)
* 838a3535 Label chart (#783)
* 59de7aa3 Bump test chart dependencies (#779)
* 96773a31 Bump versions (#777)
* aad7527c Add set_key_use configuration option (#774)
* de59147f fix gather hostcert edge case issues (#775)
* bf4bd819 feature: add awsSecretsManager upstreamAuthority (#772)
* f78c1d42 Bump test chart dependencies (#773)
* 7afffd75 Bump test chart dependencies (#771)
* 60899fc9 Add configurable hostNetwork support to spiffe-csi-driver (#769)
* 2de363a4 Bump test chart dependencies (#767)
* 6631349b feat(spire-server): add logEncoding parameter for controller-manager (#766)

Signed-off-by: Faisal Memon <[email protected]>
2026-04-10 15:48:58 -07:00
013421724f Fix typos in error messages (#788)
* nit: fix typos

Signed-off-by: Dávid Szakállas <[email protected]>

* Apply suggestion from @kfox1111

Signed-off-by: kfox1111 <[email protected]>

---------

Signed-off-by: Dávid Szakállas <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-04-10 16:56:50 +00:00
kfox1111 86787b5912 Add initial spire-ha-agent support to the spire-nested chart (#790)
* Add initial spire-ha-agent support to the spire-nested chart

Signed-off-by: Kevin Fox <[email protected]>

* Fix docs

Signed-off-by: Kevin Fox <[email protected]>

* Fix lint issue

Signed-off-by: Kevin Fox <[email protected]>

---------

Signed-off-by: Kevin Fox <[email protected]>
2026-04-10 08:46:28 +00:00
kfox1111 040ccf905b Bump versions to 1.14.5 (#789)
Signed-off-by: Kevin Fox <[email protected]>
2026-04-09 10:07:37 -07:00
Faisal Memon 9273f11f0a Support root-level spire-lib chart reuse (#785)
* Add root-level spire-lib chart

Signed-off-by: Faisal Memon <[email protected]>

* Make spire consume root-level spire-lib

Signed-off-by: Faisal Memon <[email protected]>

* Prepare chart dependencies in CI

Signed-off-by: Faisal Memon <[email protected]>

* Document DCO requirement in CODEX

Signed-off-by: Faisal Memon <[email protected]>

* Centralize local chart dependency prep

Signed-off-by: Faisal Memon <[email protected]>

* Exclude spire-lib from chart-testing install

Signed-off-by: Faisal Memon <[email protected]>

* Rename CODEX guide to AGENTS

Signed-off-by: Faisal Memon <[email protected]>

* Add make target for chart dependencies

Signed-off-by: Faisal Memon <[email protected]>

---------

Signed-off-by: Faisal Memon <[email protected]>
2026-04-09 05:14:05 -07:00
Shubham Hibareandkfox1111 145f3a36b5 chore: Add configurable probes for controller-manager (#784)
Signed-off-by: Shubham Hibare <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-04-06 18:30:43 +00:00
spire-helm-version-checker[bot]andmarcofranssen a27acbcbca Bump test chart dependencies (#786)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-04-06 07:12:47 -07:00
kfox1111 838a353567 Label chart (#783)
Signed-off-by: Kevin Fox <[email protected]>
2026-04-05 08:47:27 -07:00
kfox1111 419af5c901 Update package version for spire-ha-agent (#778)
Signed-off-by: Kevin Fox <[email protected]>
2026-03-30 04:09:20 -07:00
spire-helm-version-checker[bot]andmarcofranssen 59de7aa314 Bump test chart dependencies (#779)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-03-30 12:03:11 +02:00
kfox1111 96773a310f Bump versions (#777)
* Bump versions

Signed-off-by: Kevin Fox <[email protected]>

* Try this

Signed-off-by: Kevin Fox <[email protected]>

* Fix test for newer spire

Signed-off-by: Kevin Fox <[email protected]>

* Bump controller manager version

Signed-off-by: Kevin Fox <[email protected]>

---------

Signed-off-by: Kevin Fox <[email protected]>
2026-03-29 12:13:59 -07:00
Alan ChaandKevin Fox aad7527c0c Add set_key_use configuration option (#774)
* Add set_key_use configuration option

Add a setKeyUse boolean configuration option to control the set_key_use
field in the SPIFFE OIDC Discovery Provider configuration.

When enabled, this adds the 'use': 'sig' field to JWKS keys, which is
required for compatibility with Keycloak's SPIFFE identity provider.

Defaults to false to maintain backward compatibility.

Signed-off-by: Alan Cha <[email protected]>

* Fix docs

Signed-off-by: Kevin Fox <[email protected]>

---------

Signed-off-by: Alan Cha <[email protected]>
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: Kevin Fox <[email protected]>
2026-03-29 09:34:30 -07:00
Daniel Schlatter de59147fc5 fix gather hostcert edge case issues (#775)
* Check each conditional of gather host cert in case a command to create the host cert fails

Signed-off-by: Daniel Schlatter <[email protected]>

* Change curl command to use --cacert in gather-host-cert init container

--capath is for directories. --cacert is the correct option for a single cert.

Signed-off-by: Daniel Schlatter <[email protected]>

---------

Signed-off-by: Daniel Schlatter <[email protected]>
2026-03-29 16:13:20 +00:00
kfox1111 9960e106eb spire-ha-agent chart (#519)
* Initial swag at a spire-ha-agent chart

Signed-off-by: Kevin Fox <[email protected]>

* Fix default

Signed-off-by: Kevin Fox <[email protected]>

* Fix docs

Signed-off-by: Kevin Fox <[email protected]>

* Use released cid2pid

Signed-off-by: Kevin Fox <[email protected]>

* Fix test and pdate chart

Signed-off-by: Kevin Fox <[email protected]>

* Bump version

Signed-off-by: Kevin Fox <[email protected]>

* Fix docs

Signed-off-by: Kevin Fox <[email protected]>

---------

Signed-off-by: Kevin Fox <[email protected]>
2026-03-29 08:09:50 -07:00
bf4bd8199e feature: add awsSecretsManager upstreamAuthority (#772)
* feature: add awsSecretsManager upstreamAuthority

Signed-off-by: gcavalcante8808 <[email protected]>

* Bump test chart dependencies (#773)

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Signed-off-by: gcavalcante8808 <[email protected]>

* Fix docs (#1)

Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: gcavalcante8808 <[email protected]>

---------

Signed-off-by: gcavalcante8808 <[email protected]>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: spire-helm-version-checker[bot] <161522935+spire-helm-version-checker[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-03-26 11:43:19 -07:00
spire-helm-version-checker[bot]andmarcofranssen f78c1d4246 Bump test chart dependencies (#773)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-03-23 06:59:16 -07:00
spire-helm-version-checker[bot]andmarcofranssen 7afffd75ca Bump test chart dependencies (#771)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-03-16 11:36:52 +01:00
anhpatel 60899fc9d2 Add configurable hostNetwork support to spiffe-csi-driver (#769)
Signed-off-by: aniket patel <[email protected]>
2026-03-10 14:09:31 -07:00
spire-helm-version-checker[bot]andmarcofranssen 2de363a4a6 Bump test chart dependencies (#767)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-03-09 09:01:33 -07:00
Shubham Hibare 6631349bbb feat(spire-server): add logEncoding parameter for controller-manager (#766)
Signed-off-by: Shubham Hibare <[email protected]>
2026-03-05 09:57:44 -08:00
Faisal Memon 8afe8cf6e7 Bump spire Helm Chart version from 0.28.2 to 0.28.3
* 2385c2d7 Bump spire to 1.14.2 (#763)

Signed-off-by: Faisal Memon <[email protected]>
2026-03-04 07:58:57 -08:00
Faisal Memon 20940774d1 Bump spire-nested Helm Chart version from 0.28.2 to 0.28.3
* 2385c2d7 Bump spire to 1.14.2 (#763)

Signed-off-by: Faisal Memon <[email protected]>
2026-03-04 07:38:32 -08:00
kfox1111 2385c2d7a2 Bump spire to 1.14.2 (#763) 2026-03-04 00:57:14 +00:00
Faisal Memon 85989b45eb Bump spire Helm Chart version from 0.28.1 to 0.28.2
* 24b3a173 Change hostNetwork to auto (#758)
* 0133d4a5 add key experimental.requirePQKEM for spire-server and spire-agent (#755)
* 0a841c76 Bump test chart dependencies (#759)
* a9bee70c feat(spiffe-oidc-discovery-provider): Add configurable log format option. (#757)
* bb4c0f33 chore: Bump controller manager image tag to 0.6.3 in README and values.yaml (#756)
* 3e8f3f18 Bump test chart dependencies (#753)
* b0aa3e42 Fix duplicate port names in controller-manager containers (#751)
* 3daadc64 fix(spire-server): Support duration strings for connMaxLifetime (#752)
* 730b76bb Bump test chart dependencies (#750)
* e849a1fb Add configurable hostNetwork parameter for spire-agent (#749)
* 982d53c2 Add ContainerResource scaling to spire-server HPA (#746)
* 8abac78a Support leaderElection values in controller manager (#740)
* 75ffbd06 Add imagePullSecrets support to helm hook jobs (#741)
* 141c8865 Add pobLabels support to csi and oidc (#744)
* 6b5d01b7 Bump test chart dependencies (#743)
* ba2b6a5a Add controller-manager metrics to PodMonitor (#748)
* 86a806f3 Add tolerations to spire-server hook pods (#742)
* 7d266454 Fix keyManager check stopping use of unsupported bulit-in plugin (#715)
* 666d304c Bump test chart dependencies (#738)
* a7ac6a49 feat(spire-server): add logFormat configuration option (#735)

Signed-off-by: Faisal Memon <[email protected]>
2026-03-03 15:21:39 -08:00
Faisal Memon 6937ae01a2 Bump spire-nested Helm Chart version from 0.28.1 to 0.28.2
Signed-off-by: Faisal Memon <[email protected]>
2026-03-03 15:02:10 -08:00
Faisal Memon 24b3a1730e Change hostNetwork to auto (#758) 2026-03-03 21:56:48 +00:00
Daniel Schlatterandkfox1111 0133d4a5a7 add key experimental.requirePQKEM for spire-server and spire-agent (#755)
Signed-off-by: Daniel Schlatter <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-03-03 06:31:44 -08:00
spire-helm-version-checker[bot]andmarcofranssen 0a841c76a2 Bump test chart dependencies (#759)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-03-02 10:03:57 +01:00
Shubham Hibare a9bee70c0b feat(spiffe-oidc-discovery-provider): Add configurable log format option. (#757)
Signed-off-by: Shubham Hibare <[email protected]>
2026-02-25 14:20:59 -08:00
Shubham Hibare bb4c0f33ce chore: Bump controller manager image tag to 0.6.3 in README and values.yaml (#756)
* chore: Bump controller manager image tag to 0.6.3 in README and values.yaml

Signed-off-by: Shubham Hibare <[email protected]>

* chore: Trigger CI rerun

Signed-off-by: Shubham Hibare <[email protected]>

---------

Signed-off-by: Shubham Hibare <[email protected]>
2026-02-25 06:55:42 -08:00
3e8f3f1893 Bump test chart dependencies (#753)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-02-23 16:15:40 +00:00
Rowan Ruselerandkfox1111 b0aa3e4266 Fix duplicate port names in controller-manager containers (#751)
* Fix duplicate port names in controller-manager containers

Multiple controller-manager containers were using the same "heathz" port
name, causing Kubernetes warnings about duplicate ports in the
StatefulSet. This also affected the prometheus port "prom-cm".

Changes:
* Renamed healthz port to hp-cm (health port - controller manager)
* Renamed prom-cm to pm-cm for consistency
* Addedd {{ .portSuffix }} variable to differentiate external controller
  ports
* Implemented port suffix logic

The suffix logic handles cluster names by:
1. Names <9 chars: use full name as suffic
  * e.g.: child01 -> -child01
2. Names with trailing numbers: preserve the number format users chose
  * Detects 1-2 digit numbers with optional hyphen
  * Truncates base name to fit within 15 chars
  * e.g.: verlongcluster-01 -> -verylo-01
3. Names without numbers: use SHA-256 hash for uniqueness
  * Trunactes name to 5 chars and appends 3-char hash
  * e.g.: verlongclustername -> -veryl-a3f

The logic separates container suffix (full name) from port suffix
(truncated) so container names remain descriptive while port names stay
compliant.

Fixes #525 #655

Signed-off-by: Rowan Ruseler <[email protected]>

* Add optional port name overrides for ext. controller

The auto-generated port name suffixes for external controller manager
can collide when cluster names are similar, as the 3-character has
provides only 4,096 possibilities. With the optional healthPortName and
prometheusPortName fields to cluster configuration, allows users to
explicity set port names when automatica generation creates collisions.

Signed-off-by: Rowan Ruseler <[email protected]>

* Fix portSuffix generation

Changed from "and" to "or", so portSuffic is calculated when either
healthPortName or prometheusPortName is unset.

Signed-off-by: Rowan Ruseler <[email protected]>

---------

Signed-off-by: Rowan Ruseler <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-02-23 15:20:25 +01:00
Shubham Hibare 3daadc6456 fix(spire-server): Support duration strings for connMaxLifetime (#752)
* fix(spire-server): Support duration strings for connMaxLifetime

Signed-off-by: Shubham Hibare <[email protected]>

* fix

Signed-off-by: Shubham Hibare <[email protected]>

---------

Signed-off-by: Shubham Hibare <[email protected]>
2026-02-19 10:55:11 -08:00