Commit Graph
1101 Commits
Author SHA1 Message Date
spire-helm-version-checker[bot]andmarcofranssen f78c1d4246 Bump test chart dependencies (#773)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-03-23 06:59:16 -07:00
spire-helm-version-checker[bot]andmarcofranssen 7afffd75ca Bump test chart dependencies (#771)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-03-16 11:36:52 +01:00
dependabot[bot] 0370d3170a Bump helm.sh/helm/v3 from 3.20.0 to 3.20.1 in /tests
Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.20.0 to 3.20.1.
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](https://github.com/helm/helm/compare/v3.20.0...v3.20.1)

---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.20.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
2026-03-13 16:02:53 +01:00
anhpatel 60899fc9d2 Add configurable hostNetwork support to spiffe-csi-driver (#769)
Signed-off-by: aniket patel <[email protected]>
2026-03-10 14:09:31 -07:00
spire-helm-version-checker[bot]andmarcofranssen 2de363a4a6 Bump test chart dependencies (#767)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-03-09 09:01:33 -07:00
Shubham Hibare 6631349bbb feat(spire-server): add logEncoding parameter for controller-manager (#766)
Signed-off-by: Shubham Hibare <[email protected]>
2026-03-05 09:57:44 -08:00
Faisal Memon 8afe8cf6e7 Bump spire Helm Chart version from 0.28.2 to 0.28.3
* 2385c2d7 Bump spire to 1.14.2 (#763)

Signed-off-by: Faisal Memon <[email protected]>
2026-03-04 07:58:57 -08:00
Faisal Memon 20940774d1 Bump spire-nested Helm Chart version from 0.28.2 to 0.28.3
* 2385c2d7 Bump spire to 1.14.2 (#763)

Signed-off-by: Faisal Memon <[email protected]>
2026-03-04 07:38:32 -08:00
kfox1111 2385c2d7a2 Bump spire to 1.14.2 (#763) 2026-03-04 00:57:14 +00:00
Faisal Memon 85989b45eb Bump spire Helm Chart version from 0.28.1 to 0.28.2
* 24b3a173 Change hostNetwork to auto (#758)
* 0133d4a5 add key experimental.requirePQKEM for spire-server and spire-agent (#755)
* 0a841c76 Bump test chart dependencies (#759)
* a9bee70c feat(spiffe-oidc-discovery-provider): Add configurable log format option. (#757)
* bb4c0f33 chore: Bump controller manager image tag to 0.6.3 in README and values.yaml (#756)
* 3e8f3f18 Bump test chart dependencies (#753)
* b0aa3e42 Fix duplicate port names in controller-manager containers (#751)
* 3daadc64 fix(spire-server): Support duration strings for connMaxLifetime (#752)
* 730b76bb Bump test chart dependencies (#750)
* e849a1fb Add configurable hostNetwork parameter for spire-agent (#749)
* 982d53c2 Add ContainerResource scaling to spire-server HPA (#746)
* 8abac78a Support leaderElection values in controller manager (#740)
* 75ffbd06 Add imagePullSecrets support to helm hook jobs (#741)
* 141c8865 Add pobLabels support to csi and oidc (#744)
* 6b5d01b7 Bump test chart dependencies (#743)
* ba2b6a5a Add controller-manager metrics to PodMonitor (#748)
* 86a806f3 Add tolerations to spire-server hook pods (#742)
* 7d266454 Fix keyManager check stopping use of unsupported bulit-in plugin (#715)
* 666d304c Bump test chart dependencies (#738)
* a7ac6a49 feat(spire-server): add logFormat configuration option (#735)

Signed-off-by: Faisal Memon <[email protected]>
2026-03-03 15:21:39 -08:00
Faisal Memon 6937ae01a2 Bump spire-nested Helm Chart version from 0.28.1 to 0.28.2
Signed-off-by: Faisal Memon <[email protected]>
2026-03-03 15:02:10 -08:00
Faisal Memon 24b3a1730e Change hostNetwork to auto (#758) 2026-03-03 21:56:48 +00:00
Daniel Schlatterandkfox1111 0133d4a5a7 add key experimental.requirePQKEM for spire-server and spire-agent (#755)
Signed-off-by: Daniel Schlatter <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-03-03 06:31:44 -08:00
Marco Franssen 50afee93c0 Bump CI to last 3 k8s minors
Signed-off-by: Marco Franssen <[email protected]>
2026-03-02 19:32:48 +01:00
spire-helm-version-checker[bot]andmarcofranssen 0a841c76a2 Bump test chart dependencies (#759)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-03-02 10:03:57 +01:00
Shubham Hibare a9bee70c0b feat(spiffe-oidc-discovery-provider): Add configurable log format option. (#757)
Signed-off-by: Shubham Hibare <[email protected]>
2026-02-25 14:20:59 -08:00
Shubham Hibare bb4c0f33ce chore: Bump controller manager image tag to 0.6.3 in README and values.yaml (#756)
* chore: Bump controller manager image tag to 0.6.3 in README and values.yaml

Signed-off-by: Shubham Hibare <[email protected]>

* chore: Trigger CI rerun

Signed-off-by: Shubham Hibare <[email protected]>

---------

Signed-off-by: Shubham Hibare <[email protected]>
2026-02-25 06:55:42 -08:00
3e8f3f1893 Bump test chart dependencies (#753)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-02-23 16:15:40 +00:00
Rowan Ruselerandkfox1111 b0aa3e4266 Fix duplicate port names in controller-manager containers (#751)
* Fix duplicate port names in controller-manager containers

Multiple controller-manager containers were using the same "heathz" port
name, causing Kubernetes warnings about duplicate ports in the
StatefulSet. This also affected the prometheus port "prom-cm".

Changes:
* Renamed healthz port to hp-cm (health port - controller manager)
* Renamed prom-cm to pm-cm for consistency
* Addedd {{ .portSuffix }} variable to differentiate external controller
  ports
* Implemented port suffix logic

The suffix logic handles cluster names by:
1. Names <9 chars: use full name as suffic
  * e.g.: child01 -> -child01
2. Names with trailing numbers: preserve the number format users chose
  * Detects 1-2 digit numbers with optional hyphen
  * Truncates base name to fit within 15 chars
  * e.g.: verlongcluster-01 -> -verylo-01
3. Names without numbers: use SHA-256 hash for uniqueness
  * Trunactes name to 5 chars and appends 3-char hash
  * e.g.: verlongclustername -> -veryl-a3f

The logic separates container suffix (full name) from port suffix
(truncated) so container names remain descriptive while port names stay
compliant.

Fixes #525 #655

Signed-off-by: Rowan Ruseler <[email protected]>

* Add optional port name overrides for ext. controller

The auto-generated port name suffixes for external controller manager
can collide when cluster names are similar, as the 3-character has
provides only 4,096 possibilities. With the optional healthPortName and
prometheusPortName fields to cluster configuration, allows users to
explicity set port names when automatica generation creates collisions.

Signed-off-by: Rowan Ruseler <[email protected]>

* Fix portSuffix generation

Changed from "and" to "or", so portSuffic is calculated when either
healthPortName or prometheusPortName is unset.

Signed-off-by: Rowan Ruseler <[email protected]>

---------

Signed-off-by: Rowan Ruseler <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-02-23 15:20:25 +01:00
Shubham Hibare 3daadc6456 fix(spire-server): Support duration strings for connMaxLifetime (#752)
* fix(spire-server): Support duration strings for connMaxLifetime

Signed-off-by: Shubham Hibare <[email protected]>

* fix

Signed-off-by: Shubham Hibare <[email protected]>

---------

Signed-off-by: Shubham Hibare <[email protected]>
2026-02-19 10:55:11 -08:00
spire-helm-version-checker[bot]andmarcofranssen 730b76bbaa Bump test chart dependencies (#750)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-02-16 05:48:10 -08:00
Rowan Ruselerandkfox1111 e849a1fbd6 Add configurable hostNetwork parameter for spire-agent (#749)
* Add configurable hostNetwork parameter for spire-agent

Adds `hostNetwork` as a configurable parameter in the spire-agent chart.
We can now explicitly control whether the spire-agent daemonset uses
host networking.

Changes:
* Updated daemonset template
* Changed `dnsPolicy` logic to follow the computed `hostNetwork` instead
  of kubelet mode directly
* Updated documentation

Behaviour:
If you leave `hostNetwork` empty (the default), it behaves like PR #705:
* automatically disables when using hostname or hostip kubelet modes
* automatically enables for localhost

If you set it explicitly to `true` or `false`, that overrides the
automatic behaviour. When `hostNetwork` is enabled and you haven't set a
custom `dnsPolicy`, it defaults to `ClusterFirstWithHostNet`.

Fixes #704

Signed-off-by: Rowan Ruseler <[email protected]>

* Fix merge conflict, different default value for fsGroupFix.image.tag

Signed-off-by: Rowan Ruseler <[email protected]>

---------

Signed-off-by: Rowan Ruseler <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-02-14 00:57:20 +00:00
Jayme Howardandkfox1111 982d53c200 Add ContainerResource scaling to spire-server HPA (#746)
* Add ContainerResource scaling to spire-server HPA

Signed-off-by: Jayme Howard <[email protected]>

* Amend flag name to address feedback

Signed-off-by: Jayme Howard <[email protected]>

---------

Signed-off-by: Jayme Howard <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-02-14 00:29:22 +00:00
Pratik Lotia 8abac78a15 Support leaderElection values in controller manager (#740) 2026-02-11 15:58:54 -08:00
Rowan Ruseler 75ffbd06f5 Add imagePullSecrets support to helm hook jobs (#741)
* Add imagePullSecrets support to helm hook jobs

Hook jobs lacked imagePullSecrets configuration on their pod specs,
causing image pull failures in environments using private registries
with authentication

* spire-server: post-install, pre-upgrade, post-upgrade, pre-delete
  hooks
* spire-oidc-discovery-provider: pre-delete hook
* spike-nexus: bootstrap hook
* spire: global imagePullSecrets

Fixes #649

Signed-off-by: Rowan Ruseler <[email protected]>

* Document global.imagePullSecrets parameter

Signed-off-by: Rowan Ruseler <[email protected]>

* Replaced non functioning 'or' with 'coalesce'

Signed-off-by: Rowan Ruseler <[email protected]>

---------

Signed-off-by: Rowan Ruseler <[email protected]>
2026-02-11 15:16:16 -08:00
Rowan Ruselerandkfox1111 141c8865a3 Add pobLabels support to csi and oidc (#744)
spiffe-csi-driver and spiffe-oidc-discovery provider are now brought in
line with spire-server and spire-agent, which already support podLabels.

Changes:
* Add podLabels parameter

Fixes #719

Signed-off-by: Rowan Ruseler <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-02-10 15:03:54 -08:00
6b5d01b74c Bump test chart dependencies (#743)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-02-10 22:03:09 +00:00
Pratik Lotia ba2b6a5a02 Add controller-manager metrics to PodMonitor (#748)
Signed-off-by: pratik-lotia <[email protected]>
2026-02-10 13:23:33 -08:00
Alec Wilson 86a806f3c6 Add tolerations to spire-server hook pods (#742)
Applies the tolerations in the spire-server chart to the pods created
by the hooks. Previously they were only applied to the pods of the
server itself.

Signed-off-by: Alec Wilson <[email protected]>
2026-02-09 00:32:56 +00:00
Alec Wilson 7d2664544d Fix keyManager check stopping use of unsupported bulit-in plugin (#715)
Adds unsupported built-in plugins (built-in plugins that do not have
direct toggles in the helm chart) to the check that exactly one
key manager plugin is enabled - the previous check only allowed usage
of key manager plugins with explicit values in the helm chart.

This still doesn't allow usage of custom key manager plugins - as they
will not be present in the count that is checked.

Signed-off-by: Alec Wilson <[email protected]>
2026-02-08 16:13:43 -08:00
dependabot[bot] 45fdf9f7c0 Bump github.com/onsi/gomega from 1.39.0 to 1.39.1 in /tests (#739)
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.39.0 to 1.39.1.
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/gomega/compare/v1.39.0...v1.39.1)

---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.39.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-03 08:40:14 +01:00
spire-helm-version-checker[bot]andmarcofranssen 666d304ce2 Bump test chart dependencies (#738)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: marcofranssen <[email protected]>
2026-02-02 11:52:44 +01:00
Shubham Hibare a7ac6a494d feat(spire-server): add logFormat configuration option (#735)
* Add logFormat support to spire-server chart

Adds the ability to configure SPIRE server log format (text or json)
via the logFormat helm value. When set, it renders as log_format in
the server configuration.

Signed-off-by: Shubham Hibare <[email protected]>

* add default value

Signed-off-by: Shubham Hibare <[email protected]>

* fix

Signed-off-by: Shubham Hibare <[email protected]>

* fix

Signed-off-by: Shubham Hibare <[email protected]>

---------

Signed-off-by: Shubham Hibare <[email protected]>
2026-01-30 13:39:47 -08:00
dependabot[bot] c620065ef6 Bump github.com/onsi/ginkgo/v2 from 2.27.5 to 2.28.1 in /tests (#736)
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.27.5 to 2.28.1.
- [Release notes](https://github.com/onsi/ginkgo/releases)
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/ginkgo/compare/v2.27.5...v2.28.1)

---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
  dependency-version: 2.28.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-30 00:29:17 -08:00
Faisal Memon 28f95d263b Bump spire-nested Helm Chart version from 0.28.0 to 0.28.1
Signed-off-by: Faisal Memon <[email protected]>
2026-01-27 09:17:32 -08:00
Faisal Memon c826e29705 Bump spire Helm Chart version from 0.28.0 to 0.28.1
* e99d9609 Bump test chart dependencies (#732)
* a7abf7d7 disable hostNetwork on spire-agent daemonset if connect by hostname is true (#705)

Signed-off-by: Faisal Memon <[email protected]>
2026-01-27 09:09:02 -08:00
e99d96097c Bump test chart dependencies (#732)
* Bump test chart dependencies

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* Update docs

Signed-off-by: Kevin Fox <[email protected]>

---------

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: kfox1111 <[email protected]>
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: marcofranssen <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-01-26 14:43:53 -08:00
Daniel SchlatterandFaisal Memon a7abf7d7ec disable hostNetwork on spire-agent daemonset if connect by hostname is true (#705)
* disable hostNetwork on spire-agent daemonset if connect by hostname is true

Signed-off-by: Daniel Schlatter <[email protected]>

* allow spire-agent daemonset dnsPolicy to be configured

Signed-off-by: Daniel Schlatter <[email protected]>

---------

Signed-off-by: Daniel Schlatter <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
2026-01-26 12:40:57 -08:00
Faisal Memonandkfox1111 3c724632ee Bump spire Helm Chart version from 0.27.1 to 0.28.0 (#731)
* 6f2c71b0 Update spire to 1.14.1 (#729)
* f8f1e21f CSI driver: Support setting podSecurityContext and securityContext (#642)
* 813203a4 Update spike to the newest version (#665)
* 97c383b1 Add Configurable Kubelet Address for SPIRE Agent (#709)
* 8555efc6 Bump test chart dependencies
* e6c9d975 Bump test chart dependencies
* 87da80a8 Add support for AWS KMS key tagging (#721)
* db8f1352 Bump test chart dependencies (#720)
* b1f902b6 Bump test chart dependencies
* 198cdb60 Bump test chart dependencies
* dfbbecf0 Add guard to the validating admission policy to stop errors when there are no volumes in the spec. This fixes errors with HTTP solver pods in cert manager. (#706)
* 1e1e8daa Add support for attested node pruning configuration (#713)
* a2130ff7 Bump test chart dependencies (#712)
* adc5f3e8 Bump test chart dependencies
* 4e0cdb13 Bump test chart dependencies
* 95fa0deb Allow configuring spire-agent prometheus listening address (#701)

Signed-off-by: Faisal Memon <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-01-26 19:42:54 +00:00
Faisal Memon 0ceaed05cc Bump spire-nested Helm Chart version from 0.27.1 to 0.28.0 (#730)
* 6f2c71b0 Update spire to 1.14.1 (#729)

Signed-off-by: Faisal Memon <[email protected]>
2026-01-26 11:22:17 -08:00
dependabot[bot] ffc473889c Bump helm.sh/helm/v3 from 3.19.5 to 3.20.0 in /tests (#728)
Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.19.5 to 3.20.0.
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](https://github.com/helm/helm/compare/v3.19.5...v3.20.0)

---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-23 21:29:03 +00:00
kfox1111 6f2c71b04d Update spire to 1.14.1 (#729)
Signed-off-by: Kevin Fox <[email protected]>
2026-01-23 21:15:49 +00:00
f8f1e21f7d CSI driver: Support setting podSecurityContext and securityContext (#642)
* Allow for both the pod security context and container security contexts to be overriden through the spiffe-csi-driver values file

Signed-off-by: Alec Holmes <[email protected]>

* newline

Signed-off-by: Alec Holmes <[email protected]>

* fix space

Signed-off-by: Alec Holmes <[email protected]>

* Update docs

Signed-off-by: Kevin Fox <[email protected]>

---------

Signed-off-by: Alec Holmes <[email protected]>
Signed-off-by: Kevin Fox <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
2026-01-23 20:55:14 +00:00
813203a4d2 Update spike to the newest version (#665)
* Update spike bits

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Add trust roots.

SPIKE SDK uses the appropriate trust root from the environment which makes SDK usage easier, but it requires additional env vars on the pod meta.

Signed-off-by: Volkan Özçelik <[email protected]>

* Chart updates to make it work with the new SDK changes of SPIKE.

Signed-off-by: Volkan Özçelik <[email protected]>

* Making the self-reference more evident.

Signed-off-by: Volkan Özçelik <[email protected]>

* Documentation update.

Signed-off-by: Volkan Özçelik <[email protected]>

* Documentation update.

Signed-off-by: Volkan Özçelik <[email protected]>

* updates to align with recent SPIKE.

* SPIKE assumes all trust roots can be arrays (for distributed setups), modified values accordingly.
* Added cross-references between bootstrap and keeper job/statefulsets for PoP validation to work.
* other possible minor updates.

Signed-off-by: Volkan Özçelik <[email protected]>

* minor changes.

Signed-off-by: Volkan Özçelik <[email protected]>

* Update docs

---------

Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: Volkan Özçelik <[email protected]>
Co-authored-by: Volkan Özçelik <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
2026-01-23 12:32:18 -08:00
Oliver Bassettandkfox1111 97c383b1cb Add Configurable Kubelet Address for SPIRE Agent (#709)
* Add kubeletAddress.mode configuration to spire-agent

Introduces new enum-based configuration for kubelet connection modes:
- auto (default): hostname for OpenShift, localhost otherwise
- localhost: SPIRE default behavior (127.0.0.1:10250)
- hostname: Connect via node hostname
- hostip: Connect via node IP
- custom: User-provided configuration

Deprecates kubeletConnectByHostname but maintains backward compatibility.

Signed-off-by: Oliver Bassett <[email protected]>

* Replace connect-by-hostname helper with mode resolution

Adds three new helpers:
- spire-agent.kubelet-address-mode: Determine mode with backward compat
- spire-agent.kubelet-address-mode-resolved: Resolve auto to actual mode
- spire-agent.should-set-node-name-env: Determine if node_name_env needed

Includes validation of enum values and maintains backward compatibility
by keeping the old connect-by-hostname helper as deprecated.

Signed-off-by: Oliver Bassett <[email protected]>

* Update daemonset to use KUBELET_ADDR env variable

- Sets KUBELET_ADDR from downward API for hostname/hostip modes
- Maintains MY_NODE_NAME for backward compatibility
- No env var set for localhost mode (SPIRE default)
- Custom mode allows user control via extraEnvVars
- Updates init container env to support both hostname and hostip modes

Signed-off-by: Oliver Bassett <[email protected]>

* Update workload attestor config and add validation

- Changes node_name_env from MY_NODE_NAME to KUBELET_ADDR
- Adds validation for kubeletAddress.mode enum
- Prevents using both old and new config simultaneously

Signed-off-by: Oliver Bassett <[email protected]>

* Improve documentation for custom mode

Clarifies that custom mode does not validate KUBELET_ADDR presence,
allowing for external secret injection and other advanced configuration
methods.

Signed-off-by: Oliver Bassett <[email protected]>

* Fix backward compatibility for kubeletConnectByHostname

Two critical fixes for backward compatibility:

1. Helper template priority: Reorder kubelet-address-mode helper to
   prioritize kubeletConnectByHostname when kubeletAddress.mode is
   'auto' or empty. This ensures deprecated config still works.

2. Type-safe validation: Convert kubeletConnectByHostname to string
   in validation and helper to handle both boolean and string types
   consistently. Original chart required string type.

3. Smart dual-config validation: Only fail when both configs are
   explicitly set to non-default values. Allow kubeletConnectByHostname
   with mode='auto' for backward compatibility.

Tested scenarios:
- kubeletConnectByHostname='true' maps to hostname mode
- kubeletConnectByHostname='false' maps to localhost mode
- Both set with mode='auto' allows backward compat to take priority
- Both set with different non-defaults triggers validation error
- OpenShift auto mode correctly resolves to hostname mode

Signed-off-by: Oliver Bassett <[email protected]>

* Use parentheses for DEPRECATED tag in values.yaml

Change [DEPRECATED] to (DEPRECATED) to avoid conflicts with automated
README generator which uses square brackets for special tags.

Signed-off-by: Oliver Bassett <[email protected]>

* Update generated README documentation

Regenerate README.md from values.yaml using documentation generator.
Includes new kubeletAddress.mode configuration and deprecation notice
for kubeletConnectByHostname.

Signed-off-by: Oliver Bassett <[email protected]>

* Remove MY_NODE_NAME environment variable

Remove MY_NODE_NAME as it is not used within the spire-agent chart.
Initially kept for backwards compatibility concerns, but confirmed
unnecessary after review.

The KUBELET_ADDR environment variable is sufficient for the workload
attestor configuration via node_name_env setting.

Addresses PR feedback: https://github.com/spiffe/helm-charts-hardened/pull/709#discussion_r1909855869

Signed-off-by: Oliver Bassett <[email protected]>

* Fix init container for custom kubelet address mode

Address PR #709 feedback by standardizing on KUBELET_ADDR environment
variable and passing extraEnvVars to init containers.

Changes:

1. Init container env variable:
   - Renamed NODE_NAME to KUBELET_ADDR for consistency
   - Made hostip check explicit with 'else if'
   - Passes extraEnvVars to init container for custom mode support

2. Init container script:
   - Updated URL construction to use KUBELET_ADDR for all modes
   - Added validation for custom mode: fails with clear error if
     KUBELET_ADDR is not set via extraEnvVars
   - hostname/hostip modes: Use KUBELET_ADDR from downward API
   - custom mode: Use KUBELET_ADDR from extraEnvVars with validation
   - localhost mode: Use hardcoded 'localhost'

3. Documentation updates:
   - Updated custom mode docs to explain extraEnvVars is passed to
     both main and init containers
   - Noted init container validation behavior
   - Updated extraEnvVars param docs to mention init containers

Testing verified:
- Template rendering for all modes (hostname, hostip, custom, localhost)
- Runtime validation: deployed custom mode without KUBELET_ADDR to kind
  cluster, init container correctly failed with clear error message

Addresses: https://github.com/spiffe/helm-charts-hardened/pull/709#discussion_r1909855869
Signed-off-by: Oliver Bassett <[email protected]>

* Update generated README for init container changes

Regenerate README.md to reflect that extraEnvVars is now passed
to both the main container and init containers.

Signed-off-by: Oliver Bassett <[email protected]>

---------

Signed-off-by: Oliver Bassett <[email protected]>
Co-authored-by: kfox1111 <[email protected]>
2026-01-21 16:47:55 -08:00
dependabot[bot] 894cbb1089 Bump helm.sh/helm/v3 from 3.19.4 to 3.19.5 in /tests
Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.19.4 to 3.19.5.
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](https://github.com/helm/helm/compare/v3.19.4...v3.19.5)

---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.19.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
2026-01-20 19:03:25 +01:00
marcofranssen 8555efc6f9 Bump test chart dependencies
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-01-19 18:38:03 +01:00
dependabot[bot] 4a85c49e30 Bump github.com/onsi/ginkgo/v2 from 2.27.4 to 2.27.5 in /tests (#725)
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.27.4 to 2.27.5.
- [Release notes](https://github.com/onsi/ginkgo/releases)
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/ginkgo/compare/v2.27.4...v2.27.5)

---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
  dependency-version: 2.27.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-13 13:28:25 -08:00
marcofranssen e6c9d975e7 Bump test chart dependencies
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-01-12 11:04:24 +01:00
dependabot[bot] 4a7fb8e2b8 Bump github.com/onsi/ginkgo/v2 from 2.27.3 to 2.27.4 in /tests
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.27.3 to 2.27.4.
- [Release notes](https://github.com/onsi/ginkgo/releases)
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/ginkgo/compare/v2.27.3...v2.27.4)

---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
  dependency-version: 2.27.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
2026-01-09 12:46:32 +01:00