* Update spire-identity-exchange for 0.4.0 Signed-off-by: Kevin Fox <[email protected]> * Understand the plugin config Signed-off-by: Kevin Fox <[email protected]> * Fix test Signed-off-by: Kevin Fox <[email protected]> * Update ip Signed-off-by: Kevin Fox <[email protected]> * Update name Signed-off-by: Kevin Fox <[email protected]> * Update name Signed-off-by: Kevin Fox <[email protected]> * Update name Signed-off-by: Kevin Fox <[email protected]> * Fix broken socket path Signed-off-by: Kevin Fox <[email protected]> * Nope, it was right before Signed-off-by: Kevin Fox <[email protected]> * Try disabling the spiffe plugin for now Signed-off-by: Kevin Fox <[email protected]> * Try logging more Signed-off-by: Kevin Fox <[email protected]> * Map non container behavior Signed-off-by: Kevin Fox <[email protected]> * Map non container behavior Signed-off-by: Kevin Fox <[email protected]> * Map non container behavior Signed-off-by: Kevin Fox <[email protected]> * Map non container behavior Signed-off-by: Kevin Fox <[email protected]> * Map non container behavior Signed-off-by: Kevin Fox <[email protected]> * Map non container behavior Signed-off-by: Kevin Fox <[email protected]> * Map non container behavior Signed-off-by: Kevin Fox <[email protected]> * Add missing csi driver settings Signed-off-by: Kevin Fox <[email protected]> * Test Signed-off-by: Kevin Fox <[email protected]> * Test Signed-off-by: Kevin Fox <[email protected]> * Fix Signed-off-by: Kevin Fox <[email protected]> * Use local oidc discovery provider path by default Signed-off-by: Kevin Fox <[email protected]> * Enable spire-identity-exchange in shared infrastructure Signed-off-by: Kevin Fox <[email protected]> * Update timeout Signed-off-by: Kevin Fox <[email protected]> * Update timeout Signed-off-by: Kevin Fox <[email protected]> * Test config Signed-off-by: Kevin Fox <[email protected]> * Test config Signed-off-by: Kevin Fox <[email protected]> * Test config Signed-off-by: Kevin Fox <[email protected]> * Test config Signed-off-by: Kevin Fox <[email protected]> * Fix Signed-off-by: Kevin Fox <[email protected]> * Fix Signed-off-by: Kevin Fox <[email protected]> * Bump spire-ha-agent version to fix issue Signed-off-by: Kevin Fox <[email protected]> * Fix Signed-off-by: Kevin Fox <[email protected]> * Fix Signed-off-by: Kevin Fox <[email protected]> * Bump version Signed-off-by: Kevin Fox <[email protected]> * Update version bits to match what it should be, minus final bump Signed-off-by: Kevin Fox <[email protected]> --------- Signed-off-by: Kevin Fox <[email protected]> Signed-off-by: kfox1111 <[email protected]> Co-authored-by: Faisal Memon <[email protected]>
122 lines
3.4 KiB
Bash
Executable File
122 lines
3.4 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
|
|
GITHUB_STEP_SUMMARY="${GITHUB_STEP_SUMMARY:-/tmp/summary}"
|
|
|
|
get_namespace_details () {
|
|
cat <<EOF >>"$GITHUB_STEP_SUMMARY"
|
|
### Namespace $1
|
|
|
|
#### Events
|
|
|
|
\`\`\`shell
|
|
$(kubectl --request-timeout=30s get events --output wide --namespace "$1")
|
|
\`\`\`
|
|
|
|
#### Pods
|
|
|
|
\`\`\`shell
|
|
$(kubectl --request-timeout=30s describe pods --namespace "$1")
|
|
\`\`\`
|
|
|
|
#### Logs
|
|
|
|
\`\`\`shell
|
|
$(kubectl get pods -o name -n "$1" | while read -r line; do echo logs for "${line}"; kubectl logs -n "$1" "${line}" --prefix --all-containers=true --ignore-errors=true; done)
|
|
$( ([[ -n "$2" ]] && kubectl get pods -o name -n "$2") | while read -r line; do echo logs for "${line}"; kubectl logs -n "$2" "${line}" --all-containers=true --ignore-errors=true; done)
|
|
\`\`\`
|
|
|
|
MAX_BYTES=1048576
|
|
if [ "$(wc -c < "${GITHUB_STEP_SUMMARY}")" -gt "${MAX_BYTES}" ]; then
|
|
# shellcheck disable=SC2094
|
|
truncate -s $((MAX_BYTES - 14)) "${GITHUB_STEP_SUMMARY}"
|
|
# shellcheck disable=SC2094
|
|
printf "\ntruncated...\n" >> "${GITHUB_STEP_SUMMARY}"
|
|
fi
|
|
|
|
EOF
|
|
}
|
|
|
|
k_wait () {
|
|
kubectl wait --for condition=available --timeout 30s --namespace "$1" "$2" "$3" | tail -n 1
|
|
}
|
|
|
|
k_rollout_status () {
|
|
kubectl rollout status --watch --timeout 30s --namespace "$1" "$2" "$3" | tail -n 1
|
|
}
|
|
|
|
get_spire_release_name () {
|
|
helm ls -A | grep '^spire' | grep -v spire-crds | awk '{print $1}'
|
|
}
|
|
|
|
print_spire_workload_status () {
|
|
local ns1
|
|
local ns2
|
|
|
|
ns1="$1"
|
|
ns2="${2:-$1}"
|
|
|
|
release_name="$(get_spire_release_name)"
|
|
|
|
cat <<EOF >>"$GITHUB_STEP_SUMMARY"
|
|
### Spire
|
|
|
|
| Namespace | Workload | Status |
|
|
| --------- | ---------------------------------------------- | ------ |
|
|
| ${ns1} | ${release_name}-server | <pre>$(k_rollout_status "${ns1}" statefulset "${release_name}-server")</pre> |
|
|
| ${ns1} | ${release_name}-server | <pre>$(k_rollout_status "${ns1}" deployments.apps "${release_name}-server")</pre> |
|
|
| ${ns2} | ${release_name}-spiffe-csi-driver | <pre>$(k_rollout_status "${ns2}" daemonset "${release_name}-spiffe-csi-driver")</pre> |
|
|
| ${ns2} | ${release_name}-agent | <pre>$(k_rollout_status "${ns2}" daemonset "${release_name}-agent")</pre> |
|
|
| ${ns1} | ${release_name}-spiffe-oidc-discovery-provider | <pre>$(k_rollout_status "${ns1}" deployments.apps "${release_name}-spiffe-oidc-discovery-provider")</pre> |
|
|
|
|
EOF
|
|
}
|
|
|
|
print_helm_releases () {
|
|
cat <<EOF >>"$GITHUB_STEP_SUMMARY"
|
|
### Releases
|
|
|
|
$(helm ls -A | sed 's/\t/ | /g' | sed 's/^/| /' | sed 's/$/ |/' | sed '/^| NAME.*/a| - | - | - | - | - | - | - |')
|
|
|
|
EOF
|
|
}
|
|
|
|
common_test_url () (
|
|
count=10
|
|
while true; do
|
|
if curl "$1"; then exit 0; fi
|
|
sleep 2
|
|
count=$((count-1))
|
|
[ $count -le 0 ] && exit 1
|
|
done
|
|
)
|
|
|
|
common_test_file_exists () (
|
|
count=20
|
|
while true; do
|
|
if [ -f "$1" ]; then exit 0; fi
|
|
sleep 2
|
|
count=$((count-1))
|
|
[ $count -le 0 ] && exit 1
|
|
done
|
|
)
|
|
|
|
# Used just for testing. You should provide your own values as described in the install instructions.
|
|
common_test_your_values () {
|
|
cat > /tmp/$$.example-your-values.yaml <<EOF
|
|
global:
|
|
spire:
|
|
recommendations:
|
|
enabled: true
|
|
clusterName: production
|
|
trustDomain: production.other
|
|
caSubject:
|
|
country: US
|
|
organization: Production
|
|
commonName: production.other
|
|
EOF
|
|
echo "/tmp/$$.example-your-values.yaml"
|
|
}
|
|
|
|
COMMON_TEST_YOUR_VALUES="$(common_test_your_values)"
|
|
export COMMON_TEST_YOUR_VALUES
|