5.7 KiB
5.7 KiB
spire-server
A Helm chart to install the SPIRE server.
Note
: Minimum Spire version is
1.5.3. The recommended version is1.6.0to support arm64 nodes. If running with any prior version to1.6.0you have to use anodeSelectorto limit tokubernetes.io/arch: amd64.The recommended spire-controller-manager version is
0.2.2to support arm64 nodes. If running with any prior version to0.2.2you have to use anodeSelectorto limit tokubernetes.io/arch: amd64.
Values
| Key | Type | Default | Description |
|---|---|---|---|
| affinity | object | {} |
|
| autoscaling.enabled | bool | false |
|
| autoscaling.maxReplicas | int | 100 |
|
| autoscaling.minReplicas | int | 1 |
|
| autoscaling.targetCPUUtilizationPercentage | int | 80 |
|
| bundleConfigMap | string | "spire-server" |
|
| caKeyType | string | "rsa-2048" |
The CA key type to use, possible values are rsa-2048, rsa-4096, ec-p256, ec-p384 (AWS requires the use of RSA. EC cryptography is not supported) |
| caTTL | string | "24h" |
|
| ca_subject.common_name | string | "example.org" |
|
| ca_subject.country | string | "NL" |
|
| ca_subject.organization | string | "Example" |
|
| clusterName | string | "example-cluster" |
|
| controllerManager.enabled | bool | false |
|
| controllerManager.identities.dnsNameTemplates | list | [] |
|
| controllerManager.identities.enabled | bool | true |
|
| controllerManager.identities.namespaceSelector | object | {} |
|
| controllerManager.identities.podSelector | object | {} |
|
| controllerManager.identities.spiffeIDTemplate | string | "spiffe://{{ .TrustDomain }}/ns/{{ .PodMeta.Namespace }}/sa/{{ .PodSpec.ServiceAccountName }}" |
|
| controllerManager.ignoreNamespaces[0] | string | "kube-system" |
|
| controllerManager.ignoreNamespaces[1] | string | "kube-public" |
|
| controllerManager.ignoreNamespaces[2] | string | "local-path-storage" |
|
| controllerManager.image.pullPolicy | string | "IfNotPresent" |
|
| controllerManager.image.registry | string | "ghcr.io" |
|
| controllerManager.image.repository | string | "spiffe/spire-controller-manager" |
|
| controllerManager.image.version | string | "0.2.2" |
|
| controllerManager.resources | object | {} |
|
| controllerManager.securityContext | object | {} |
|
| controllerManager.service.annotations | object | {} |
|
| controllerManager.service.port | int | 443 |
|
| controllerManager.service.type | string | "ClusterIP" |
|
| dataStorage.accessMode | string | "ReadWriteOnce" |
|
| dataStorage.enabled | bool | true |
|
| dataStorage.size | string | "1Gi" |
|
| dataStorage.storageClass | string | nil |
|
| defaultJwtSvidTTL | string | "1h" |
|
| defaultX509SvidTTL | string | "4h" |
|
| extraContainers | list | [] |
|
| extraVolumeMounts | list | [] |
|
| extraVolumes | list | [] |
|
| fullnameOverride | string | "" |
|
| image.pullPolicy | string | "IfNotPresent" |
|
| image.registry | string | "ghcr.io" |
|
| image.repository | string | "spiffe/spire-server" |
|
| image.version | string | "" |
|
| imagePullSecrets | list | [] |
|
| initContainers | list | [] |
|
| jwtIssuer | string | "oidc-discovery.example.org" |
|
| logLevel | string | "info" |
|
| nameOverride | string | "" |
|
| nodeAttestor.k8sPsat.enabled | bool | true |
|
| nodeAttestor.k8sPsat.serviceAccountAllowList | list | [] |
|
| nodeSelector | object | {} |
|
| podAnnotations | object | {} |
|
| podSecurityContext | object | {} |
|
| replicaCount | int | 1 |
SPIRE server currently runs with a sqlite database. Scaling to multiple instances will not work until we use an external database. |
| resources | object | {} |
|
| securityContext | object | {} |
|
| service.annotations | object | {} |
|
| service.port | int | 8081 |
|
| service.type | string | "ClusterIP" |
|
| serviceAccount.annotations | object | {} |
|
| serviceAccount.create | bool | true |
|
| serviceAccount.name | string | "" |
|
| telemetry.prometheus.enabled | bool | false |
|
| tolerations | list | [] |
|
| topologySpreadConstraints | list | [] |
|
| trustDomain | string | "example.org" |
|
| upstreamAuthority.certManager.enabled | bool | false |
|
| upstreamAuthority.certManager.issuer_group | string | "cert-manager.io" |
|
| upstreamAuthority.certManager.issuer_kind | string | "Issuer" |
|
| upstreamAuthority.certManager.issuer_name | string | "spire-ca" |
|
| upstreamAuthority.certManager.kube_config_file | string | "" |
|
| upstreamAuthority.certManager.namespace | string | "" |
Specify to use a namespace other then the one the chart is installed into |
| upstreamAuthority.certManager.rbac.create | bool | true |
|
| upstreamAuthority.disk.enabled | bool | false |
|
| upstreamAuthority.disk.secret.create | bool | true |
If disabled requires you to create a secret with the given keys (certificate, key and optional bundle) yourself. |
| upstreamAuthority.disk.secret.data | object | {"bundle":"","certificate":"","key":""} |
If secret creation is enabled, will create a secret with following certificate info |
| upstreamAuthority.disk.secret.name | string | "spiffe-upstream-ca" |
If secret creation is disabled, the secret with this name will be used. |