* Better spire-server entry commands Currently in order to use the cli tools such as spire-server entry show You must know the path within the container to the binary along with what the path is to the socket. This patch makes that unnessisary. This now works: kubectl exec -it spire-server-0 -- spire-server entry show Signed-off-by: Kevin Fox <[email protected]> * Remove setting thats set to default Signed-off-by: Kevin Fox <[email protected]> --------- Signed-off-by: Kevin Fox <[email protected]>
spire
A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.
Homepage: https://github.com/philips-labs/helm-charts/tree/main/charts/spire
Warning
: Please note this chart requires Projected Service Account Tokens which has to be enabled on your k8s api server.
Note
: Minimum Spire version is
v1.5.3.
To enable Projected Service Account Tokens on Docker for Mac/Windows run the following command to SSH into the Docker Desktop K8s VM.
docker run -it --privileged --pid=host debian nsenter -t 1 -m -u -n -i sh
Then add the following to /etc/kubernetes/manifests/kube-apiserver.yaml
spec:
containers:
- command:
- kube-apiserver
- --api-audiences=api,spire-server
- --service-account-issuer=api,spire-agent
- --service-account-key-file=/run/config/pki/sa.pub
- --service-account-signing-key-file=/run/config/pki/sa.key
Maintainers
| Name | Url | |
|---|---|---|
| marcofranssen | [email protected] | https://marcofranssen.nl |
Source Code
Requirements
Kubernetes: >=1.21.0-0
| Repository | Name | Version |
|---|---|---|
| file://./charts/spiffe-csi-driver | spiffe-csi-driver | 0.1.0 |
| file://./charts/spiffe-oidc-discovery-provider | spiffe-oidc-discovery-provider | 0.1.0 |
| file://./charts/spire-agent | spire-agent | 0.1.0 |
| file://./charts/spire-server | spire-server | 0.1.0 |
Values
| Key | Type | Default | Description |
|---|---|---|---|
| fullnameOverride | string | "" |
|
| nameOverride | string | "" |
|
| spiffe-csi-driver | object | {} |
|
| spiffe-oidc-discovery-provider.enabled | bool | false |
|
| spiffe-oidc-discovery-provider.trustDomain | string | "example.org" |
|
| spire-agent.bundleConfigMap | string | "spire-bundle" |
|
| spire-agent.clusterName | string | "example-cluster" |
|
| spire-agent.nameOverride | string | "agent" |
|
| spire-agent.trustDomain | string | "example.org" |
|
| spire-server.bundleConfigMap | string | "spire-bundle" |
|
| spire-server.clusterName | string | "example-cluster" |
|
| spire-server.controllerManager.enabled | bool | true |
|
| spire-server.nameOverride | string | "server" |
|
| spire-server.trustDomain | string | "example.org" |