kfox1111 and Marco Franssen
c39dd44526
Add recommendation for namespacePSS ( #131 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-12-21 00:15:56 +00:00
dependabot[bot] and kfox1111
0555c87eef
Bump golang.org/x/crypto from 0.14.0 to 0.17.0 in /tests ( #162 )
...
Bumps [golang.org/x/crypto](https://github.com/golang/crypto ) from 0.14.0 to 0.17.0.
- [Commits](https://github.com/golang/crypto/compare/v0.14.0...v0.17.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/crypto
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: kfox1111 <[email protected] >
2023-12-20 09:50:41 -08:00
kfox1111
80f9d3823c
Revert to older ingress-nginx to fix tests ( #161 )
...
Signed-off-by: Kevin Fox <[email protected] >
2023-12-20 09:05:23 -08:00
kfox1111
cb7e7e82c0
Remove 1.29.0 until deps catch up. ( #159 )
...
Related issue: https://github.com/rancher/kubectl/pull/94
Signed-off-by: Kevin Fox <[email protected] >
2023-12-19 19:00:41 -08:00
kfox1111
ad905d9c3e
Fix the nested test ( #158 )
...
Signed-off-by: Kevin Fox <[email protected] >
2023-12-19 16:12:46 -08:00
kfox1111 and Marco Franssen
49beb64584
Add recommendation for namespaceLayout ( #127 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-12-19 15:02:57 +00:00
Marco Franssen
2496c71164
Bump k8s versions for ci workflow ( #156 )
2023-12-19 15:52:45 +01:00
kfox1111 and Marco Franssen
f642feafef
Fix test logging ( #154 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-12-19 11:52:21 +00:00
kfox1111
33cacd2ee8
Add recommendation for prometheus exporter ( #144 )
2023-12-19 11:38:20 +00:00
kfox1111 and Marco Franssen
6997d6a904
Add recommendation for securityContext and podSecurityContext ( #125 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-12-19 11:26:26 +00:00
kfox1111
50c4ac35b0
Add recommendation for strictMode ( #143 )
2023-12-19 12:12:53 +01:00
4fb9d18f50
Bump test chart dependencies ( #155 )
...
* Bump test chart dependencies
Signed-off-by: GitHub <[email protected] >
* Revert broken image for now
Signed-off-by: kfox1111 <[email protected] >
---------
Signed-off-by: GitHub <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: marcofranssen <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2023-12-18 09:12:59 -08:00
Mariusz Sabath
811123a207
Update the Tornjak image version ( #150 )
2023-12-14 23:15:04 +01:00
dependabot[bot]
1f74f6bc13
Bump helm.sh/helm/v3 from 3.13.2 to 3.13.3 in /tests ( #149 )
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.13.2 to 3.13.3.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.13.2...v3.13.3 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-13 19:47:49 -08:00
Marco Franssen
94498c0a31
Bump cosign to v2.2.2
...
Signed-off-by: Marco Franssen <[email protected] >
2023-12-13 08:56:31 +01:00
dependabot[bot]
b7e98c4c95
Bump sigstore/cosign-installer from 3.2.0 to 3.3.0
...
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer ) from 3.2.0 to 3.3.0.
- [Release notes](https://github.com/sigstore/cosign-installer/releases )
- [Commits](https://github.com/sigstore/cosign-installer/compare/v3.2.0...v3.3.0 )
---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
2023-12-13 08:56:31 +01:00
kfox1111 and Faisal Memon
a097606d77
Remove extra example values that are already set by default ( #128 )
...
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-12-12 16:23:23 +00:00
kfox1111
1524537318
Update default for additionalDomains not to include localhost ( #146 )
...
Its pretty much only useful if you want to port forward the
discovery provider and use localhost to access it. An uncommon
use case. Its easy to add back for that case. This simplifies
production deploymnet.
Signed-off-by: Kevin Fox <[email protected] >
2023-12-12 08:14:16 -08:00
Marco Franssen
6e997d4f47
Bump cosign to v2.2.2
...
Signed-off-by: Marco Franssen <[email protected] >
2023-12-12 12:53:15 +01:00
dependabot[bot]
9d483e276e
Bump sigstore/cosign-installer from 3.2.0 to 3.3.0
...
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer ) from 3.2.0 to 3.3.0.
- [Release notes](https://github.com/sigstore/cosign-installer/releases )
- [Commits](https://github.com/sigstore/cosign-installer/compare/v3.2.0...v3.3.0 )
---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <[email protected] >
2023-12-12 12:53:15 +01:00
kfox1111
8615cb0840
Add devcontainer support to the repo ( #98 )
2023-12-12 12:50:32 +01:00
kfox1111 and Faisal Memon
e35838c309
Add recommendation for priorityClass ( #124 )
...
* Add a flag to enable recommendations
Signed-off-by: Kevin Fox <[email protected] >
* Add recommendation for priorityClass
Signed-off-by: Kevin Fox <[email protected] >
* Fix vars
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Update docs. Fix typo.
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-12-11 11:42:40 -08:00
kfox1111
9f72a8f971
Use good and automatic defaults for tornjak frontend workingDir ( #129 )
...
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
2023-12-11 07:52:44 -08:00
kfox1111 and Mariusz Sabath
7726351955
Tornjak UBI support ( #123 )
...
* Tornjak UBI support
The Tornjak containers now have two different flavors. Vanilla and UBI.
Automatically select the UBI image when deploying on OpenShift.
Signed-off-by: Kevin Fox <[email protected] >
Co-authored-by: Mariusz Sabath <[email protected] >
2023-12-11 06:56:58 -08:00
kfox1111
89c07e2d04
Revert openssl 3.2 change ( #142 )
...
Signed-off-by: Kevin Fox <[email protected] >
2023-12-11 06:33:24 -08:00
marcofranssen
a3d3702049
Bump test chart dependencies
...
Signed-off-by: GitHub <[email protected] >
2023-12-11 10:44:48 +01:00
80c7653a21
Bump test chart dependencies ( #134 )
...
* Bump test chart dependencies
Signed-off-by: GitHub <[email protected] >
* Update charts/spire/charts/spiffe-oidc-discovery-provider/values.yaml
Signed-off-by: kfox1111 <[email protected] >
* Fix Docs
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: GitHub <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Signed-off-by: Kevin Fox <[email protected] >
Co-authored-by: marcofranssen <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2023-12-07 22:47:38 +00:00
kfox1111
13f6028ccd
SELinux support ( #122 )
...
* SELinux support
Add support to the chart to set the SELinux context to enable a working
system. Enable it by default on OpenShift clusters.
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
2023-12-07 11:02:06 -08:00
dependabot[bot]
c017d82594
Bump actions/setup-python from 4 to 5 ( #137 )
...
Bumps [actions/setup-python](https://github.com/actions/setup-python ) from 4 to 5.
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](https://github.com/actions/setup-python/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: actions/setup-python
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-07 12:40:31 +00:00
dependabot[bot]
6fda639237
Bump actions/setup-go from 4.1.0 to 5.0.0 ( #136 )
...
Bumps [actions/setup-go](https://github.com/actions/setup-go ) from 4.1.0 to 5.0.0.
- [Release notes](https://github.com/actions/setup-go/releases )
- [Commits](https://github.com/actions/setup-go/compare/v4.1.0...v5.0.0 )
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-07 04:32:42 -08:00
kfox1111 and Faisal Memon
3e8335c0ee
Add a flag to enable recommendations ( #121 )
...
* Add a flag to enable recommendations
Signed-off-by: Kevin Fox <[email protected] >
* Fix merge issue
Signed-off-by: Kevin Fox <[email protected] >
* Update after reaching consensus.
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-12-02 05:15:32 -08:00
kfox1111 and Faisal Memon
692d463718
Remove unneeded lookup function from upgrade hook ( #104 )
...
Those upgrading to 0.17.0 should no longer need the code to check for the old webhook.
Signed-off-by: Kevin Fox <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-12-01 10:49:29 -08:00
8422b8d141
Added ability to create namespaces ( #103 )
...
* Added ability to create namespaces
Signed-off-by: Andrew Block <[email protected] >
* Add openshift labels
Signed-off-by: Mariusz Sabath <[email protected] >
---------
Signed-off-by: Andrew Block <[email protected] >
Signed-off-by: Mariusz Sabath <[email protected] >
Co-authored-by: Mariusz Sabath <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2023-12-01 15:42:27 +00:00
Marco Franssen and kfox1111
78bb95ba35
Bump spire Helm Chart version from 0.15.1 to 0.16.0
...
* b7d8590 Fix missing protocol in JWT Issuer (#120 )
* 1ef207c Add note about supported version upgrades (#119 )
* 4281114 Fix missing release name from install documentation (#118 )
* e030fa1 Allow additional CRs to be managed by the chart (#117 )
* d936293 Enable agent to kubelet connection to use hostname (#112 )
* e68f617 Bump test chart dependencies (#116 )
* d616632 Bump spire version to 1.8.5 (#115 )
* 95e1eb7 Bump test chart dependencies
* 966061c Auto add default CSIDriver labels on OpenShift
* c9885de Introduce ReadOnlyRootFilesystem for Tornjak frontend (#110 )
* 8107095 Fix typo ClusterSPIFFEID for workloadTSelectoremplates (#107 )
* 5c0ce97 Ordering of SecurityContextConstraint array items (#105 )
* 889d0af Bump test chart dependencies
* f5d1376 Documentation cleanup (#97 )
Signed-off-by: Marco Franssen <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2023-12-01 16:03:24 +01:00
Marco Franssen
a22838a532
Add additional instructions to release PR to also check other charts
...
Signed-off-by: Marco Franssen <[email protected] >
2023-11-30 17:29:27 +01:00
dependabot[bot]
7145ebccc8
Bump github.com/onsi/ginkgo/v2 from 2.13.1 to 2.13.2 in /tests ( #126 )
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.13.1 to 2.13.2.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.13.1...v2.13.2 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-29 20:03:27 -08:00
Mariusz Sabath
b7d8590b77
Fix missing protocol in JWT Issuer ( #120 )
...
* Add missing protocol to jwt_issuer
Signed-off-by: Mariusz Sabath <[email protected] >
* Removed trailing spaces
Signed-off-by: Mariusz Sabath <[email protected] >
---------
Signed-off-by: Mariusz Sabath <[email protected] >
2023-11-29 00:13:32 +00:00
Faisal Memon
1ef207c7b2
Add note about supported version upgrades ( #119 )
...
Signed-off-by: Faisal Memon <[email protected] >
2023-11-28 22:01:16 +00:00
kfox1111
4281114b49
Fix missing release name from install documentation ( #118 )
...
Signed-off-by: Kevin Fox <[email protected] >
2023-11-28 12:57:11 -08:00
e030fa171b
Allow additional CRs to be managed by the chart ( #117 )
...
* Add support for the new spire-controller-manager class feature
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs. Swich nested deployment to use controller manager
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Test with nightly
Signed-off-by: Kevin Fox <[email protected] >
* Fix global object naming clash
Signed-off-by: Kevin Fox <[email protected] >
* Fix missing dot
Signed-off-by: Kevin Fox <[email protected] >
* Fix naming conflict with cluster ids
Signed-off-by: Kevin Fox <[email protected] >
* Fix scoping issue
Signed-off-by: Kevin Fox <[email protected] >
* Fix typo
Signed-off-by: Kevin Fox <[email protected] >
* Fix webhook name collision
Signed-off-by: Kevin Fox <[email protected] >
* Fix webhook reference and add note to user about className
Signed-off-by: Kevin Fox <[email protected] >
* Upgrade has to work on the old version of the object before rename
Signed-off-by: Kevin Fox <[email protected] >
* Fix formatting
Signed-off-by: Kevin Fox <[email protected] >
* Remove extra junk from job
Signed-off-by: Kevin Fox <[email protected] >
* Easier local runs and wait for crds
Signed-off-by: Kevin Fox <[email protected] >
* Add missing crd upgrade
Signed-off-by: Kevin Fox <[email protected] >
* Update upgrade notes
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/charts/spire-server/templates/controller-manager-cluster-ids.yaml
Co-authored-by: Marco Franssen <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Bump version to the released 0.4.0
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Merge in crd changes from upstream
Signed-off-by: Kevin Fox <[email protected] >
* Add auto populate dns
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/README.md
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Add missing ClusterSPIFFEID fields
There are a few options in the CRD not available via the chart.
Sync them to the chart.
Signed-off-by: Kevin Fox <[email protected] >
* Add another missing one
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Allow additional CRs to be managed by the chart
Sometimes additional ClusterSPIFFEIDs and the other CRs are needed. Add
support for the end user to manage those extra CRs via the chart.
Signed-off-by: Kevin Fox <[email protected] >
* Add validation
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Add className to crs
Signed-off-by: Kevin Fox <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Fix readme formatting
Signed-off-by: Kevin Fox <[email protected] >
* Update charts/spire/README.md
Signed-off-by: kfox1111 <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
* Fix docs
Signed-off-by: Kevin Fox <[email protected] >
* Remove dead code
Signed-off-by: Kevin Fox <[email protected] >
* Fix extra newline
Signed-off-by: Kevin Fox <[email protected] >
* Incorperate feedback
Signed-off-by: Kevin Fox <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Marco Franssen <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-11-28 09:15:23 -08:00
kfox1111 and Marco Franssen
d936293d50
Enable agent to kubelet connection to use hostname ( #112 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-11-28 08:43:09 +01:00
github-actions[bot] and marcofranssen
e68f6170a6
Bump test chart dependencies ( #116 )
...
Signed-off-by: GitHub <[email protected] >
Co-authored-by: marcofranssen <[email protected] >
2023-11-27 06:20:42 -08:00
kfox1111
d616632810
Bump spire version to 1.8.5 ( #115 )
2023-11-24 09:32:27 -08:00
marcofranssen
95e1eb7c57
Bump test chart dependencies
...
Signed-off-by: GitHub <[email protected] >
Signed-off-by: Marco Franssen <[email protected] >
2023-11-20 10:34:08 +01:00
Kevin Fox
966061c6c7
Auto add default CSIDriver labels on OpenShift
...
Signed-off-by: Kevin Fox <[email protected] >
2023-11-20 10:24:53 +01:00
Mariusz Sabath
c9885de539
Introduce ReadOnlyRootFilesystem for Tornjak frontend ( #110 )
...
Signed-off-by: Mariusz Sabath <[email protected] >
2023-11-16 15:47:04 -08:00
Mariusz Sabath
911f51b679
Consolidate all the examples to a common relative path ( #109 )
...
Signed-off-by: Mariusz Sabath <[email protected] >
2023-11-16 13:14:55 -08:00
Mattias Gees
810709533b
Fix typo ClusterSPIFFEID for workloadTSelectoremplates ( #107 )
...
Signed-off-by: Mattias Gees <[email protected] >
2023-11-16 06:34:56 -08:00
Andrew Block and Faisal Memon
5c0ce97ad1
Ordering of SecurityContextConstraint array items ( #105 )
...
Signed-off-by: Andrew Block <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-11-15 04:54:17 +00:00
kfox1111 and Faisal Memon
8f542f2170
Add some nested diagrams ( #102 )
...
* Add some nested diagrams
Signed-off-by: Kevin Fox <[email protected] >
* Fix typo
Signed-off-by: Kevin Fox <[email protected] >
* Add md
Signed-off-by: Kevin Fox <[email protected] >
* Apply suggestions from code review
Co-authored-by: Faisal Memon <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
---------
Signed-off-by: Kevin Fox <[email protected] >
Signed-off-by: kfox1111 <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-11-13 14:14:24 -08:00