kfox1111 and Faisal Memon
d724d1e690
Update the documentation ( #172 )
...
* SPIFFE OIDC Discovery Provider Rework
Fixes: https://github.com/spiffe/helm-charts-hardened/issues/151
Signed-off-by: Kevin Fox <[email protected] >
* Enhance clusterspiffeid's so the discovery provider is independently configurable
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* More fix tests
Signed-off-by: Kevin Fox <[email protected] >
* More fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Undo
Signed-off-by: Kevin Fox <[email protected] >
* Fix logging
Signed-off-by: Kevin Fox <[email protected] >
* Try to get output
Signed-off-by: Kevin Fox <[email protected] >
* Try and get error code
Signed-off-by: Kevin Fox <[email protected] >
* Fix more logging. Switch port used.
Signed-off-by: Kevin Fox <[email protected] >
* Fix logging
Signed-off-by: Kevin Fox <[email protected] >
* Fix port
Signed-off-by: Kevin Fox <[email protected] >
* Fix up logs for nested test and fix values
Signed-off-by: Kevin Fox <[email protected] >
* Make consistent
Signed-off-by: Kevin Fox <[email protected] >
* Fix nested test
Signed-off-by: Kevin Fox <[email protected] >
* Fix insecure mode and test.
Signed-off-by: Kevin Fox <[email protected] >
* Fix test.
Signed-off-by: Kevin Fox <[email protected] >
* Fix var scoping issue
Signed-off-by: Kevin Fox <[email protected] >
* Set the right flags for ingress
Signed-off-by: Kevin Fox <[email protected] >
* Update dns template
Signed-off-by: Kevin Fox <[email protected] >
* Use more standard port
Signed-off-by: Kevin Fox <[email protected] >
* Fix test logging
Signed-off-by: Kevin Fox <[email protected] >
* Allow reencrypt.
Signed-off-by: Kevin Fox <[email protected] >
* Remove testing changes
Signed-off-by: Kevin Fox <[email protected] >
* Fix formatting
Signed-off-by: Kevin Fox <[email protected] >
* Add LetsEncrypt/ACME/cert-manager support. Remove broken ACME support.
Signed-off-by: Kevin Fox <[email protected] >
* Use spiffe-helper as a sidecar. Significant space savings and read only cert dir
Signed-off-by: Kevin Fox <[email protected] >
* Fix the nested test
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge issue
Signed-off-by: Kevin Fox <[email protected] >
* Remove 1.29.0 until deps catch up.
Related issue: https://github.com/rancher/kubectl/pull/94
Signed-off-by: Kevin Fox <[email protected] >
* Add more error checking
Signed-off-by: Kevin Fox <[email protected] >
* Remove testing code
Signed-off-by: Kevin Fox <[email protected] >
* Simplify the ids. Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix logic
Signed-off-by: Kevin Fox <[email protected] >
* Fix var
Signed-off-by: Kevin Fox <[email protected] >
* Make cert-manager bits more readable
Signed-off-by: Kevin Fox <[email protected] >
* Fix template
Signed-off-by: Kevin Fox <[email protected] >
* Fix openshift ingress
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Update docs
Signed-off-by: Kevin Fox <[email protected] >
* Add resource spec
Signed-off-by: Kevin Fox <[email protected] >
* Remove parts that cant merge yet
Signed-off-by: Kevin Fox <[email protected] >
* Add support for running spiffe secured discovery provider (default)
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Remove defaults
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Add missing configurable for the discovery providers csi driver
Signed-off-by: Kevin Fox <[email protected] >
* Update the documentation
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Signed-off-by: kfox1111 <[email protected] >
* Apply suggestions from code review
Signed-off-by: kfox1111 <[email protected] >
* Apply suggestions from code review
Signed-off-by: kfox1111 <[email protected] >
* Apply suggestions from code review
Signed-off-by: kfox1111 <[email protected] >
* Add missing file
Signed-off-by: Kevin Fox <[email protected] >
* Update for changes in spiffe-helper
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-01-23 08:05:49 -08:00
kfox1111 and Faisal Memon
af155c2edc
Add support for running spiffe secured discovery provider (default) ( #163 )
...
* SPIFFE OIDC Discovery Provider Rework
Fixes: https://github.com/spiffe/helm-charts-hardened/issues/151
Signed-off-by: Kevin Fox <[email protected] >
* Enhance clusterspiffeid's so the discovery provider is independently configurable
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* More fix tests
Signed-off-by: Kevin Fox <[email protected] >
* More fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Undo
Signed-off-by: Kevin Fox <[email protected] >
* Fix logging
Signed-off-by: Kevin Fox <[email protected] >
* Try to get output
Signed-off-by: Kevin Fox <[email protected] >
* Try and get error code
Signed-off-by: Kevin Fox <[email protected] >
* Fix more logging. Switch port used.
Signed-off-by: Kevin Fox <[email protected] >
* Fix logging
Signed-off-by: Kevin Fox <[email protected] >
* Fix port
Signed-off-by: Kevin Fox <[email protected] >
* Fix up logs for nested test and fix values
Signed-off-by: Kevin Fox <[email protected] >
* Make consistent
Signed-off-by: Kevin Fox <[email protected] >
* Fix nested test
Signed-off-by: Kevin Fox <[email protected] >
* Fix insecure mode and test.
Signed-off-by: Kevin Fox <[email protected] >
* Fix test.
Signed-off-by: Kevin Fox <[email protected] >
* Fix var scoping issue
Signed-off-by: Kevin Fox <[email protected] >
* Set the right flags for ingress
Signed-off-by: Kevin Fox <[email protected] >
* Update dns template
Signed-off-by: Kevin Fox <[email protected] >
* Use more standard port
Signed-off-by: Kevin Fox <[email protected] >
* Fix test logging
Signed-off-by: Kevin Fox <[email protected] >
* Allow reencrypt.
Signed-off-by: Kevin Fox <[email protected] >
* Remove testing changes
Signed-off-by: Kevin Fox <[email protected] >
* Fix formatting
Signed-off-by: Kevin Fox <[email protected] >
* Add LetsEncrypt/ACME/cert-manager support. Remove broken ACME support.
Signed-off-by: Kevin Fox <[email protected] >
* Use spiffe-helper as a sidecar. Significant space savings and read only cert dir
Signed-off-by: Kevin Fox <[email protected] >
* Fix the nested test
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge issue
Signed-off-by: Kevin Fox <[email protected] >
* Remove 1.29.0 until deps catch up.
Related issue: https://github.com/rancher/kubectl/pull/94
Signed-off-by: Kevin Fox <[email protected] >
* Add more error checking
Signed-off-by: Kevin Fox <[email protected] >
* Remove testing code
Signed-off-by: Kevin Fox <[email protected] >
* Simplify the ids. Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Fix logic
Signed-off-by: Kevin Fox <[email protected] >
* Fix var
Signed-off-by: Kevin Fox <[email protected] >
* Make cert-manager bits more readable
Signed-off-by: Kevin Fox <[email protected] >
* Fix template
Signed-off-by: Kevin Fox <[email protected] >
* Fix openshift ingress
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Update docs
Signed-off-by: Kevin Fox <[email protected] >
* Add resource spec
Signed-off-by: Kevin Fox <[email protected] >
* Remove parts that cant merge yet
Signed-off-by: Kevin Fox <[email protected] >
* Add support for running spiffe secured discovery provider (default)
Signed-off-by: Kevin Fox <[email protected] >
* Fix tests
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix test
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge conflict
Signed-off-by: Kevin Fox <[email protected] >
* Remove defaults
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Add missing configurable for the discovery providers csi driver
Signed-off-by: Kevin Fox <[email protected] >
* Update for changes in spiffe-helper
Signed-off-by: Kevin Fox <[email protected] >
* Point at upstream
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2024-01-18 16:08:22 -08:00
kfox1111 and Faisal Memon
183e9aa534
SPIFFE OIDC Discovery Provider Rework ( #152 )
...
Co-authored-by: Faisal Memon <[email protected] >
2024-01-03 11:40:14 +01:00
kfox1111 and Marco Franssen
f642feafef
Fix test logging ( #154 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-12-19 11:52:21 +00:00
e030fa171b
Allow additional CRs to be managed by the chart ( #117 )
...
* Add support for the new spire-controller-manager class feature
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs. Swich nested deployment to use controller manager
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Test with nightly
Signed-off-by: Kevin Fox <[email protected] >
* Fix global object naming clash
Signed-off-by: Kevin Fox <[email protected] >
* Fix missing dot
Signed-off-by: Kevin Fox <[email protected] >
* Fix naming conflict with cluster ids
Signed-off-by: Kevin Fox <[email protected] >
* Fix scoping issue
Signed-off-by: Kevin Fox <[email protected] >
* Fix typo
Signed-off-by: Kevin Fox <[email protected] >
* Fix webhook name collision
Signed-off-by: Kevin Fox <[email protected] >
* Fix webhook reference and add note to user about className
Signed-off-by: Kevin Fox <[email protected] >
* Upgrade has to work on the old version of the object before rename
Signed-off-by: Kevin Fox <[email protected] >
* Fix formatting
Signed-off-by: Kevin Fox <[email protected] >
* Remove extra junk from job
Signed-off-by: Kevin Fox <[email protected] >
* Easier local runs and wait for crds
Signed-off-by: Kevin Fox <[email protected] >
* Add missing crd upgrade
Signed-off-by: Kevin Fox <[email protected] >
* Update upgrade notes
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml
Co-authored-by: Marco Franssen <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Bump version to the released 0.4.0
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Merge in crd changes from upstream
Signed-off-by: Kevin Fox <[email protected] >
* Add auto populate dns
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Add missing ClusterSPIFFEID fields
There are a few options in the CRD not available via the chart.
Sync them to the chart.
Signed-off-by: Kevin Fox <[email protected] >
* Add another missing one
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Allow additional CRs to be managed by the chart
Sometimes additional ClusterSPIFFEIDs and the other CRs are needed. Add
support for the end user to manage those extra CRs via the chart.
Signed-off-by: Kevin Fox <[email protected] >
* Add validation
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Add className to crs
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Fix readme formatting
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/README.md
Signed-off-by: kfox1111 <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Remove dead code
Signed-off-by: Kevin Fox <[email protected] >
* Fix extra newline
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Marco Franssen <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-11-28 09:15:23 -08:00
kfox1111 and Faisal Memon
8f542f2170
Add some nested diagrams ( #102 )
...
* Add some nested diagrams
Signed-off-by: Kevin Fox <[email protected] >
* Fix typo
Signed-off-by: Kevin Fox <[email protected] >
* Add md
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-11-13 14:14:24 -08:00
805d8696d0
spire-controller-manager 0.4.0 support ( #60 )
...
Co-authored-by: Marco Franssen <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-11-08 10:43:19 +00:00
kfox1111
d6583be179
Add missing no cleanup flags to example tests ( #79 )
2023-11-05 14:10:16 +01:00
kfox1111
50825d9fc9
Deny production runs of example.org trust domains ( #229 )
2023-09-25 12:06:48 -07:00
kfox1111
ae8941c49d
Support Nested Spire with External Agent ( #117 )
2023-08-16 16:35:41 +02:00