Commit Graph
354 Commits
Author SHA1 Message Date
Marco Franssen 059d5fb89f Bump spire Helm Chart version from 0.5.0 to 0.5.1
* 64585ba Fix formatting issues introduced with #152
* 0dac0db Improve Spire Chart documentation
* f709ed9 Bump actions/checkout from 3.4.0 to 3.5.0
* faef439 Bump helm/chart-testing-action from 2.3.1 to 2.4.0
* ae62dd1 Bump spire version to 1.6.1
* 02fda80 Add Artifact Hub badge to README.md
* 901e670 Disable default Tornjak deployment (#153)
* 05d0f47 Introduction of Tornjak to SPIRE Server helm charts (#144)
* b25dc77 Test fixing the tests (#148)
* b4be9ed Add maturity tag (#138)
* d4fd2ce Extract the namespace override test out of the old lockdown test. (#145)
* 4f85802 Update lockdown test to test the production example
* 04a1305 Fork the lockdown test to two tests as it is doing the work of 2 (#134)
* 64d0107 Resolve issue in prod example on volume mount (#143)
* 5b6708b Remove @dennisgove from CODEOWNERS (#140)
* a516caa Remove k8s 1.21 from test matrix + small syntax error fix (#133)
* 811a2f6 Add option to enable federation on spire-server (#97)

Signed-off-by: Marco Franssen <[email protected]>
2023-03-28 14:57:48 +02:00
Marco Franssen 64585ba2b5 Fix formatting issues introduced with #152
Signed-off-by: Marco Franssen <[email protected]>
2023-03-27 17:56:47 +02:00
Marco Franssen 0dac0dbd95 Improve Spire Chart documentation
Signed-off-by: Marco Franssen <[email protected]>
2023-03-27 17:41:35 +02:00
Marco Franssen ae62dd1af7 Bump spire version to 1.6.1
Signed-off-by: Marco Franssen <[email protected]>
2023-03-25 00:40:24 +01:00
Mariusz Sabath 901e670d49 Disable default Tornjak deployment (#153) 2023-03-22 12:16:38 -07:00
05d0f4778d Introduction of Tornjak to SPIRE Server helm charts (#144)
This PR introduces a simplified version of
[Tornjak](https://github.com/spiffe/tornjak) to support UI and SPIRE
control plane.

It extends the `/charts/spire-server` sub-chart by injecting *tornjak*
container to the *spire-server* pod. Tornjak image consists of Tornjak
API (Tornjak Backend), Tornjak UI (Frontend), and database for storing
Tornjak specific information.

Tornjak Backend communicates with SPIRE API via SPIRE Server socket. 

Since Tornjak UI (Frontend) is a React code that renders in a browser,
it needs to communicate with Tornjak APIs, and that requires
communication ports to be open, either via Ingress (in Cloud deployment)
or via port forwarding in local deployments (e.g. kind, minikube etc).
Typically port 10000 is used for HTTP connection to Backend, and port
3000 for the HTTP connection to Frontend.

End user management, TLS, and mTLS connections will be addressed by
future PRs.

This PR resolves issue #31

---------

Signed-off-by: Mariusz Sabath <[email protected]>
Signed-off-by: Marco Franssen <[email protected]>
Co-authored-by: Kevin Fox <[email protected]>
Co-authored-by: Marco Franssen <[email protected]>
Co-authored-by: Pete Cable <[email protected]>
Co-authored-by: Dennis Gove <[email protected]>
2023-03-22 13:09:09 -04:00
Pete Cable 811a2f6b01 Add option to enable federation on spire-server (#97) 2023-03-16 20:36:13 +01:00
Marco Franssen 382c1f4334 Bump spire Helm Chart version from 0.4.0 to 0.5.0
* fae12af Merge pull request #60 from spiffe/oidc-ingress
* 6322a9a Fix tests
* a9b99fe Add some commented lines for best practice annotations on ingress
* e970d52 Align ingress hostname with jwtIssues in spire-server chart
* cc7121e Add ingress support for OIDC discovery provider
* eaed7c9 Bump actions/checkout from 3.3.0 to 3.4.0 (#129)
* 2e3f045 Make webhook fail policy configurable (#124)
* 9ccbd3c Make kubelet path configurable (#123)
* 80e3b58 Remove dead file from failed rebase. (#121)
* 7155d71 Add documentation how to use Spire in own workloads
* 25c77fc Fix the driver not coming up on overloaded nodes
* 5fdd35b Improve Chart API (#119)
* 03db6bb Namespace override
* 661000a Make the agent socket configurable (#114)
* f3a81ad Make csi driver configurable to be able to run multiple instances (#115)
* b198bc7 Fix the tests so they can run locked down. (#111)
* 09b21ac Fix the gate
* b6716ae Test that it is possible to lock down security of pods (#84)
* bfeb217 Fix cluster role name uniqueness
* 490fe8f Enhance the test workflow scripts
* 9e22d2c Make the namespace the bundle is dropped into configurable
* 7d1f821 Fix test.
* 493ad8f Remove some duplication on chart-testing CI
* b6dd136 Add tmp mount so that server can run locked down (#105)
* aaaf2f7 Remove dead role code
* d2eba22 Fix docs
* 6d43625 Add kfox as a maintainer
* dfa4e6c Ensure CI also runs when test scripts are changed

Signed-off-by: Marco Franssen <[email protected]>
2023-03-16 19:15:39 +01:00
Kevin FoxandMarco Franssen 6322a9a138 Fix tests
Signed-off-by: Kevin Fox <[email protected]>

Co-authored-by: Marco Franssen <[email protected]>
2023-03-16 18:58:31 +01:00
Marco Franssen a9b99febb3 Add some commented lines for best practice annotations on ingress
Signed-off-by: Marco Franssen <[email protected]>
2023-03-16 10:08:00 +01:00
Marco Franssen e970d52ea4 Align ingress hostname with jwtIssues in spire-server chart
Signed-off-by: Marco Franssen <[email protected]>
2023-03-16 10:05:33 +01:00
Kevin FoxandMarco Franssen cc7121e021 Add ingress support for OIDC discovery provider
This patch enables exposing the oidc server out with an ingress
along with tests to ensure it works.

Signed-off-by: Kevin Fox <[email protected]>

Co-authored-by: Marco Franssen <[email protected]>
2023-03-16 10:02:22 +01:00
kfox1111 2e3f045826 Make webhook fail policy configurable (#124)
This patch makes the webhook fail policy configurable.

---------

Signed-off-by: Kevin Fox <[email protected]>
2023-03-15 12:55:07 -07:00
kfox1111 9ccbd3c67f Make kubelet path configurable (#123) 2023-03-15 10:25:06 +01:00
Marco Franssen 7155d71c38 Add documentation how to use Spire in own workloads
Signed-off-by: Marco Franssen <[email protected]>
2023-03-14 20:18:19 +01:00
Marco Franssen 5fdd35b426 Improve Chart API (#119)
Because we are already in the context of spire-agent the API looks more
logical to not have another 'agent' part in the name.

Furthermore to make it more clear the oidc provider only requires the
name of the socket as opposed to the entire path like in the other
charts I made that more explicit in the name of the value.

---------

Signed-off-by: Marco Franssen <[email protected]>
2023-03-14 09:55:24 -07:00
kfox1111 03db6bb5fe Namespace override
This patch makes it possible to install the subcharts in different
namespaces as needed.

Signed-off-by: Kevin Fox <[email protected]>
2023-03-13 15:03:16 -07:00
kfox1111 661000a29a Make the agent socket configurable (#114) 2023-03-13 20:35:27 +01:00
kfox1111andMarco Franssen f3a81ad78d Make csi driver configurable to be able to run multiple instances (#115)
Co-authored-by: Marco Franssen <[email protected]>
2023-03-13 14:12:37 +01:00
kfox1111 b198bc7e39 Fix the tests so they can run locked down. (#111) 2023-03-11 22:10:14 +01:00
Kevin Fox bfeb217558 Fix cluster role name uniqueness
Adds namespace to the ClusterRole and ClusterRoleBinding so that it
doesn't conflict when you have two instances of the chart, in different
namespaces with the same release name.

Signed-off-by: Kevin Fox <[email protected]>
2023-03-10 15:45:49 +01:00
Kevin Fox 9e22d2c303 Make the namespace the bundle is dropped into configurable
When the server and agent are not in the same namespace, the bundle needs to be
uploadable in the agent's namespace.

Signed-off-by: Kevin Fox <[email protected]>
2023-03-09 12:00:41 -08:00
kfox1111 b6dd136af2 Add tmp mount so that server can run locked down (#105)
This pr adds a tmp mount to the spire server pod so that it can run with
read only root.

Signed-off-by: Kevin Fox <[email protected]>
2023-03-08 14:21:45 -08:00
Kevin Fox aaaf2f7625 Remove dead role code
The cluster role does the same thing, but at the cluster level
where it belongs. The extra role code does nothing so we remove
it here.

Signed-off-by: Kevin Fox <[email protected]>
2023-03-08 12:36:35 -08:00
Kevin Fox d2eba226d4 Fix docs
Signed-off-by: Kevin Fox <[email protected]>
2023-03-08 19:31:54 +01:00
Kevin Fox 6d43625f4d Add kfox as a maintainer
Signed-off-by: Kevin Fox <[email protected]>
2023-03-08 19:31:54 +01:00
Marco Franssen 02ed2021c8 Bump spire Helm Chart version from 0.3.0 to 0.4.0
* 7984bbd Add script to automate cutting a release
* eb186ca Add values for server TTL configurables
* f123296 Add a flag to configure the Kubernetes NodeAttestor (#83)
* 0275569 Incorperate feedback
* a00c97b Incorperate feedback
* f93434a Make server service account allow list configurable
* f0b7f5b Make spire agent server address configurable
* cb627f0 Allow all subchart to conditionally disable (#90)
* 2e9510f Switch to non root nginx (#89)
* a901751 Fix Homepage URL
* 06c395f Fix sources in Chart.yaml (#85)
* d341c5a UpstreamAuthority cert-manager support (#82)
* a82ee69 Make sure all configmap changes rollout
* b7f8c86 Add extra initContainers, containers, volumes to agent and server
* 81ac89a Add k8s 1.26.0 (Kind) to the test matrix
* bb6abfc Merge pull request #76 from spiffe/dependabot/github_actions/sigstore/cosign-installer-3.0.1
* c0e5665 Bump cosign to v2.0.0
* d729a44 Bump sigstore/cosign-installer from 2.8.1 to 3.0.1
* fe7cd73 Merge pull request #74 from spiffe/arm64-support
* a3c04c0 Update supported versions
* 75480ed Bump spiffe-csi-driver image to 0.2.3 (arm64 support)
* 79889ff Bump spiffe-oidc-discovery-provider image to 1.6.0 (arm64 support)
* a632f76 Bump spire-agent image to 1.6.0 (arm64 support)
* b92e81d Bump spire-server image to 1.6.0 (arm64 support)
* fea2aa5 Fix sigstore/cosign-installer usage in release workflow
* fe93346 Use quote function instead of actual quotes
* 9480ab7 Add beta note to readme (#62)
* 4681498 Better spire-server entry commands (#59)

Signed-off-by: Marco Franssen <[email protected]>
2023-03-08 09:44:02 +01:00
Marco Franssen 3b7b3564da Allow to configure spire-server CA key type
Resolves #18

Signed-off-by: Marco Franssen <[email protected]>
2023-03-07 22:07:54 +01:00
Marco Franssen eb186ca346 Add values for server TTL configurables
Signed-off-by: Marco Franssen <[email protected]>
2023-03-07 09:47:25 +01:00
kfox1111 f123296032 Add a flag to configure the Kubernetes NodeAttestor (#83) 2023-03-06 19:59:54 +01:00
Kevin Fox 027556904d Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
2023-03-06 06:53:29 -08:00
Kevin Fox a00c97ba87 Incorperate feedback
Signed-off-by: Kevin Fox <[email protected]>
2023-03-06 06:53:29 -08:00
Kevin Fox f93434a926 Make server service account allow list configurable
If you don't have the agent and server in the same namespace or the same
cluster, or want to bind additional clusters, you need the ability to
configure the service account allow list.

Signed-off-by: Kevin Fox <[email protected]>
2023-03-06 06:53:29 -08:00
Kevin Fox f0b7f5bd8d Make spire agent server address configurable
If your server is not in the same namespace or cluster as the
agent, you need a config option to specify where it is.

Signed-off-by: Kevin Fox <[email protected]>
2023-03-06 06:40:58 -08:00
kfox1111 cb627f04b2 Allow all subchart to conditionally disable (#90) 2023-03-04 16:09:36 +01:00
kfox1111 2e9510f3ad Switch to non root nginx (#89) 2023-03-04 15:43:03 +01:00
Marco Franssen a901751ee7 Fix Homepage URL
Signed-off-by: Marco Franssen <[email protected]>
2023-03-04 14:35:39 +01:00
kfox1111 06c395f4d9 Fix sources in Chart.yaml (#85) 2023-03-04 14:22:45 +01:00
kfox1111 d341c5ad58 UpstreamAuthority cert-manager support (#82) 2023-03-03 20:48:35 +01:00
Kevin Fox a82ee694bf Make sure all configmap changes rollout
Signed-off-by: Kevin Fox <[email protected]>
2023-03-03 08:39:11 -08:00
Kevin Fox b7f8c86478 Add extra initContainers, containers, volumes to agent and server
With plugin support, agents and servers need more customization.
This patch enables initContainers, extraContainers, extraVolumes
and extraVolumeMounts to be added to those services.

Signed-off-by: Kevin Fox <[email protected]>
2023-03-02 08:02:19 -08:00
Marco Franssen 75480ede45 Bump spiffe-csi-driver image to 0.2.3 (arm64 support)
Signed-off-by: Marco Franssen <[email protected]>
2023-03-01 15:41:47 +01:00
Marco Franssen 79889ff3ed Bump spiffe-oidc-discovery-provider image to 1.6.0 (arm64 support)
Signed-off-by: Marco Franssen <[email protected]>
2023-03-01 15:41:47 +01:00
Marco Franssen a632f76021 Bump spire-agent image to 1.6.0 (arm64 support)
Signed-off-by: Marco Franssen <[email protected]>
2023-03-01 15:41:47 +01:00
Marco Franssen b92e81d416 Bump spire-server image to 1.6.0 (arm64 support)
Signed-off-by: Marco Franssen <[email protected]>
2023-03-01 15:41:47 +01:00
Faisal Memon fe93346b66 Use quote function instead of actual quotes
Signed-off-by: Faisal Memon <[email protected]>
2023-03-01 11:10:08 +01:00
kfox1111 4681498559 Better spire-server entry commands (#59)
* Better spire-server entry commands

Currently in order to use the cli tools such as spire-server entry show
You must know the path within the container to the binary along with what
the path is to the socket. This patch makes that unnessisary. This now
works:
kubectl exec -it spire-server-0 -- spire-server entry show

Signed-off-by: Kevin Fox <[email protected]>

* Remove setting thats set to default

Signed-off-by: Kevin Fox <[email protected]>

---------

Signed-off-by: Kevin Fox <[email protected]>
2023-02-28 22:43:49 +01:00
Marco Franssen 72d4929670 Bump spire chart to v0.3.0
Signed-off-by: Marco Franssen <[email protected]>
2023-02-28 19:21:29 +01:00
Kevin Fox 9d7881f8b4 Switch hostpath to emptydir in spire-server
The api of the server does not need to be exported out of the
server pod.

Signed-off-by: Kevin Fox <[email protected]>
2023-02-28 09:49:13 -08:00
Marco Franssen f8cdec3f99 Allow to configure a priorityClassName for Daemonsets
Signed-off-by: Marco Franssen <[email protected]>
2023-02-27 08:09:00 -08:00