9f4d4ace84
Add aws_pca to the spire-server ( #404 )
...
This change allows aws_pca to be configured via values of this chart.
__Requires 1.7.1 version__ per
[bug](https://github.com/spiffe/spire/issues/4351 ) - this will not work
until 1.7.1 is released.
---------
Signed-off-by: Petr McAllister <[email protected] >
Signed-off-by: Petr McAllister <[email protected] >
Signed-off-by: Kevin Fox <[email protected] >
Co-authored-by: Marco Franssen <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2023-07-27 14:27:51 -07:00
af13f1fc64
Bump test chart dependencies ( #401 )
...
Bump the Helm charts used in test scenarios to latest available
versions.
Signed-off-by: GitHub <[email protected] >
Co-authored-by: marcofranssen <[email protected] >
Co-authored-by: kfox1111 <[email protected] >
2023-07-27 11:20:48 -07:00
Faisal Memon
9a6768bca1
Add support for disabling container selectors ( #399 )
2023-07-27 13:27:57 -04:00
Edwin Buck
4687e20dbf
Merge pull request #315 from spiffe/persistence-type
...
Add persistence type flag
2023-07-26 10:05:50 -05:00
kfox1111
e16210c653
Merge branch 'main' into persistence-type
2023-07-21 09:36:18 -07:00
kfox1111
624ca9cc49
Remove misadded lockfile ( #400 )
2023-07-20 15:28:32 -07:00
dependabot[bot]
7ce67c624c
Bump actions/checkout from 3.5.2 to 3.5.3 ( #395 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-20 07:30:54 -07:00
dependabot[bot]
b85ba64dea
Bump helm/kind-action from 1.7.0 to 1.8.0 ( #396 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-20 07:29:08 -07:00
Marco Franssen
1898a18f0b
Bump spire Helm Chart version from 0.10.1 to 0.11.0 ( #394 )
2023-07-19 15:23:43 -07:00
Kevin Fox
a6bdb4d1e7
Add persistence type flag
...
This patch adds a type flag to the persistence settings to enable
specifying the backing volume's type.
Signed-off-by: Kevin Fox <[email protected] >
2023-07-19 23:40:23 +02:00
Marco Franssen
94a2b7235b
Merge pull request #324 from spiffe/enable-testing-multiple-charts
2023-07-19 23:06:28 +02:00
Marco Franssen
e426bc06e9
Downgrade chart-testing tool to 3.8.0
...
Unfortunatily it fails on linting
Signed-off-by: Marco Franssen <[email protected] >
2023-07-19 22:54:04 +02:00
Marco Franssen
09b466466a
Utilize ct install --github-groups in ci workflow
...
https://github.com/helm/chart-testing/pull/556
Signed-off-by: Marco Franssen <[email protected] >
2023-07-19 22:54:04 +02:00
Marco Franssen
42086bd66a
Run example tests also on all k8s versions
...
Signed-off-by: Marco Franssen <[email protected] >
2023-07-19 22:49:25 +02:00
Marco Franssen
4848c48b1f
Improve Makefile help and implementation
...
This allows more granular tasks and composition.
Also improved the documentation.
Signed-off-by: Marco Franssen <[email protected] >
2023-07-19 22:49:25 +02:00
Marco Franssen
db0603825c
Increase some timeouts, trying to fix the tests
...
Signed-off-by: Marco Franssen <[email protected] >
2023-07-19 22:49:25 +02:00
Marco Franssen
54ed71f969
Add back tests for examples
...
Signed-off-by: Marco Franssen <[email protected] >
2023-07-19 22:49:22 +02:00
Marco Franssen
4b4cef1eae
Skip namespace-override test because of #330
...
Signed-off-by: Marco Franssen <[email protected] >
2023-07-19 22:48:20 +02:00
Marco Franssen
380979c71c
Prevent ci folder ending up in Helm package
...
Signed-off-by: Marco Franssen <[email protected] >
2023-07-19 22:48:20 +02:00
Marco Franssen
06ddb7cd3f
Use chart-testing ci/*-values.yaml for testing
...
This also enables the refactor to have multiple root level charts.
Resolves #100
Signed-off-by: Marco Franssen <[email protected] >
2023-07-19 22:48:19 +02:00
kfox1111 and Marco Franssen
a4c1de7b30
Add basic unit test framework ( #390 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-07-19 18:36:07 +00:00
Marco Franssen
088b29608e
Improve tornjak service API to have object structure ( #392 )
2023-07-19 09:17:45 -07:00
Marco Franssen
522066e9f9
Align tornjak clientCA naming convention ( #393 )
2023-07-19 09:13:50 -07:00
Mariusz Sabath and Marco Franssen
f05cb4fe1e
Add option to configure TLS/mTLS endpoint for Tornjak ( #338 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-07-19 14:32:32 +02:00
github-actions[bot]
f461a01701
Bump test chart dependencies ( #386 )
2023-07-18 17:32:02 +00:00
ce39e82767
Bump test chart dependencies ( #382 )
...
Bump the Helm charts used in test scenarios to latest available
versions.
Signed-off-by: GitHub <[email protected] >
Co-authored-by: marcofranssen <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-07-14 08:05:36 -07:00
kfox1111
19d3208740
Fix oidc provider config change not rolling out ( #383 )
2023-07-12 21:05:09 +02:00
dependabot[bot]
0197621fa4
Bump helm/kind-action from 1.7.0 to 1.8.0 ( #384 )
...
Bumps [helm/kind-action](https://github.com/helm/kind-action ) from 1.7.0
to 1.8.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/helm/kind-action/releases ">helm/kind-action's
releases</a>.</em></p>
<blockquote>
<h2>v1.8.0</h2>
<h2>What's Changed</h2>
<ul>
<li><a
href="https://redirect.github.com/helm/kind-action/issues/54 ">#54</a>
ignore the occasional post delete cluster by <a
href="https://github.com/jerry153fish "><code>@jerry153fish</code></a>
in <a
href="https://redirect.github.com/helm/kind-action/pull/79 ">helm/kind-action#79</a></li>
<li>bump kind to v0.20.0 and script cleanup by <a
href="https://github.com/cpanato "><code>@cpanato</code></a> in <a
href="https://redirect.github.com/helm/kind-action/pull/88 ">helm/kind-action#88</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/jerry153fish "><code>@jerry153fish</code></a>
made their first contribution in <a
href="https://redirect.github.com/helm/kind-action/pull/79 ">helm/kind-action#79</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/helm/kind-action/compare/v1.7.0...v1.8.0 ">https://github.com/helm/kind-action/compare/v1.7.0...v1.8.0 </a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/helm/kind-action/commit/dda0770415bac9fc20092cacbc54aa298604d140 "><code>dda0770</code></a>
bump kind to v0.20.0 and script cleanup (<a
href="https://redirect.github.com/helm/kind-action/issues/88 ">#88</a>)</li>
<li><a
href="https://github.com/helm/kind-action/commit/a2c862bdb666af911f88f48ba22f76a4f33c4588 "><code>a2c862b</code></a>
<a href="https://redirect.github.com/helm/kind-action/issues/54 ">#54</a>
ignore the occasional post delete cluster (<a
href="https://redirect.github.com/helm/kind-action/issues/79 ">#79</a>)</li>
<li><a
href="https://github.com/helm/kind-action/commit/1307bb2fdec64b9400f7865196ea57b0f2efb30f "><code>1307bb2</code></a>
Bump actions/checkout from 3.5.2 to 3.5.3 (<a
href="https://redirect.github.com/helm/kind-action/issues/87 ">#87</a>)</li>
<li>See full diff in <a
href="https://github.com/helm/kind-action/compare/v1.7.0...v1.8.0 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-12 09:01:07 -07:00
kfox1111
3ed1859cd1
Add missing tolerations config to daemonsets ( #381 )
...
spiffe-csi-driver and spire-agent are missing the ability to specify
tolerations. This PR adds the missing functionality.
fixes: https://github.com/spiffe/helm-charts/issues/380
Signed-off-by: Kevin Fox <[email protected] >
2023-07-06 12:48:59 -05:00
Drew Wells
4ad68b154b
Add namespace to spiffe-oidc-discovery-provider RBAC definitions ( #379 )
2023-07-06 09:50:46 -07:00
kfox1111 and Marco Franssen
c1b1dd3d88
Add additional domains to JWT issued items. ( #230 )
...
Co-authored-by: Marco Franssen <[email protected] >
2023-07-03 22:26:28 +02:00
marcofranssen
3405e13944
Bump test chart dependencies
...
Signed-off-by: GitHub <[email protected] >
Signed-off-by: Faisal Memon <[email protected] >
2023-07-03 17:38:56 +02:00
LaithLite
81452d5e7e
Fix missing spiffe-csi-driver imagePullSecrets template ( #376 )
2023-07-03 12:52:31 +02:00
Marco Franssen
ac5977288e
Bump spire Helm Chart version from 0.10.0 to 0.10.1
...
* d7a03f62 Fix bug in cert-manager upstream authority
* e57c13ac Bump test chart dependencies (#370 )
Signed-off-by: Marco Franssen <[email protected] >
2023-06-30 16:06:21 +02:00
Marco Franssen
d7a03f620d
Fix bug in cert-manager upstream authority
...
The arguments for default function need to be the other way around
Signed-off-by: Marco Franssen <[email protected] >
2023-06-29 17:39:21 +02:00
github-actions[bot] and marcofranssen
e57c13ac13
Bump test chart dependencies ( #370 )
...
Co-authored-by: marcofranssen <[email protected] >
2023-06-29 08:16:31 +02:00
Marco Franssen
5500d36b1a
Bump spire Helm Chart version from 0.9.1 to 0.10.0
...
* f4c421af Ensure the released OCI artifact is also captured in rekor
* 386e736e Bump sigstore/cosign-installer from 3.0.5 to 3.1.0 (#368 )
* 99e01c67 Bump spire-controller-manager from 0.2.2 to 0.2.3 (#367 )
* 4dccb0d3 Bump spire Helm Chart version from 0.9.0 to 0.9.1 (#365 )
* 8409674a Fix the init container flags of the statefulset (#366 )
* 3b666601 add missing federatesWith option (#361 )
* 0533d925 fixes missing template (#362 )
* 1333b6ab Always add parseTime=true for mysql query string (#352 )
* ac3be716 Bump test chart dependencies (#358 )
Signed-off-by: Marco Franssen <[email protected] >
2023-06-28 19:01:25 +02:00
dependabot[bot] and Marco Franssen
731c8b45b5
Bump sigstore/cosign-installer from 3.1.0 to 3.1.1 ( #373 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Marco Franssen <[email protected] >
2023-06-28 08:40:55 -07:00
Marco Franssen
f4c421afa0
Ensure the released OCI artifact is also captured in rekor
...
Signed-off-by: Marco Franssen <[email protected] >
2023-06-27 09:30:09 +02:00
dependabot[bot] and Marco Franssen
386e736e78
Bump sigstore/cosign-installer from 3.0.5 to 3.1.0 ( #368 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Marco Franssen <[email protected] >
2023-06-26 08:54:42 -07:00
Marco Franssen
99e01c6722
Bump spire-controller-manager from 0.2.2 to 0.2.3 ( #367 )
...
resolves a bunch of vulnerabilities in the Image
Signed-off-by: Marco Franssen <[email protected] >
Signed-off-by: Marco Franssen <[email protected] >
2023-06-22 16:16:43 -07:00
Marco Franssen
4dccb0d3b6
Bump spire Helm Chart version from 0.9.0 to 0.9.1 ( #365 )
2023-06-22 18:57:33 +02:00
kfox1111
8409674a3e
Fix the init container flags of the statefulset ( #366 )
2023-06-22 18:57:07 +02:00
Drew Wells
3b6666016c
add missing federatesWith option ( #361 )
...
DEMO
```
spire-server-0 -- spire-server entry show -spiffeID spiffe://box-4.example.com/ns/dwells/sa/dwells-rc-realm-client
Defaulted container "spire-server" out of: spire-server, spire-controller-manager, wait (init)
Found 1 entry
Entry ID : 09301666-010e-4ba9-9dcb-44370d4e49e4
SPIFFE ID : spiffe://box-4.example.com/ns/dwells/sa/dwells-rc-realm-client
Parent ID : spiffe://box-4.example.com/spire/agent/k8s_psat/example-cluster/ff93872d-791f-4bf3-a532-475775d03d3e
Revision : 0
X509-SVID TTL : default
JWT-SVID TTL : default
Selector : k8s:pod-uid:40e0bcad-6ec8-460b-a839-659654549d7a
FederatesWith : box-3.example.com
```
Signed-off-by: Drew Wells <[email protected] >
2023-06-22 08:45:37 -07:00
Drew Wells
0533d92594
fixes missing template ( #362 )
2023-06-22 09:40:08 -04:00
Faisal Memon
1333b6ab34
Always add parseTime=true for mysql query string ( #352 )
2023-06-20 21:14:42 +02:00
ac3be716dd
Bump test chart dependencies ( #358 )
...
Co-authored-by: marcofranssen <[email protected] >
Co-authored-by: Faisal Memon <[email protected] >
2023-06-20 08:41:41 +02:00
Marco Franssen
44f3554708
Bump spire Helm Chart version from 0.8.1 to 0.9.0
...
* 57a9320 Add SPIRE 1.7.0 to main readme (#357 )
* af36f7c Align the bash image version with other instances for spire-agent (#356 )
* c11a8c0 Implement pre-delete hook for graceful delete of spiffe-oidc-discovery-provider (#353 )
* a6dcf26 Allow for SPIRE Agent to run as non root user (#209 )
* 9cf6049 Allow contributors to run linting easily on local
* e88f7f6 Add configmap annotation to spire-bundle configmap (#351 )
* 020bde8 Add support to create a issuer and CA via cert-manager (#342 )
* 9d504de Ignore .DS_Store files
* e6b608c Bump spire images to 1.7.0 (#348 )
* c97a788 Fix bundle role/rolebinding naming conflict (#333 )
* b66077e Bump peter-evans/create-pull-request from 5.0.1 to 5.0.2 (#349 )
* d0da864 Add missing metadata to subcharts (#347 )
* 4c0a1d5 Allow overriding test images (#186 )
* 250fd5d Add missing global values to charts (#311 )
* 5d8c907 Dropping k8s versions in CI older than 3, as per readme (#344 )
* 8748933 Update upstream-ca-secret.yaml (#341 )
* 4e07450 Fix ingress annotations for federation (#337 )
* ea09199 Bump actions/checkout from 3.5.0 to 3.5.3
* 87fe198 Merge pull request #331 from edwbuck/key_conventions
* ddc0166 Fix line wrapping.
* 0cae9ce Update project/conventions.md
* cb18255 Update project/conventions.md
* 52e5c24 Upgrade Tornjak to image v1.2.2 (#328 )
* 28e2abf Choose a different example for dotted Acronyms.
* d60d68c Added accidentally clipped explicit name guidelines.
* abe9fde Merge branch 'main' into key_conventions
* f6a7b62 Update project/conventions.md
* c4d19db Update project/conventions.md
* cfa9f78 Bump test chart dependencies (#332 )
* c3213ab Initial submission of Helm Chart key naming conventions.
* 28c0824 Bump test chart dependencies (#322 )
* d333154 Add Makefile for local testing (#327 )
* 9fa1ec2 Improve Tornjak backend test (#321 )
* 5b779dc Improve Tornjak frontend test (#320 )
Signed-off-by: Marco Franssen <[email protected] >
2023-06-20 00:14:48 +02:00
Faisal Memon
57a93205a7
Add SPIRE 1.7.0 to main readme ( #357 )
2023-06-19 20:29:17 +02:00
Marco Franssen
af36f7c09b
Align the bash image version with other instances for spire-agent ( #356 )
...
Signed-off-by: Marco Franssen <[email protected] >
Signed-off-by: Marco Franssen <[email protected] >
2023-06-19 11:28:35 -07:00