Files
helm-charts-hardened/charts/spire-ha-agent
kfox1111andFaisal Memon 07ba722da0 Update spire-identity-exchange for 0.4.0 (#900)
* Update spire-identity-exchange for 0.4.0

Signed-off-by: Kevin Fox <[email protected]>

* Understand the plugin config

Signed-off-by: Kevin Fox <[email protected]>

* Fix test

Signed-off-by: Kevin Fox <[email protected]>

* Update ip

Signed-off-by: Kevin Fox <[email protected]>

* Update name

Signed-off-by: Kevin Fox <[email protected]>

* Update name

Signed-off-by: Kevin Fox <[email protected]>

* Update name

Signed-off-by: Kevin Fox <[email protected]>

* Fix broken socket path

Signed-off-by: Kevin Fox <[email protected]>

* Nope, it was right before

Signed-off-by: Kevin Fox <[email protected]>

* Try disabling the spiffe plugin for now

Signed-off-by: Kevin Fox <[email protected]>

* Try logging more

Signed-off-by: Kevin Fox <[email protected]>

* Map non container behavior

Signed-off-by: Kevin Fox <[email protected]>

* Map non container behavior

Signed-off-by: Kevin Fox <[email protected]>

* Map non container behavior

Signed-off-by: Kevin Fox <[email protected]>

* Map non container behavior

Signed-off-by: Kevin Fox <[email protected]>

* Map non container behavior

Signed-off-by: Kevin Fox <[email protected]>

* Map non container behavior

Signed-off-by: Kevin Fox <[email protected]>

* Map non container behavior

Signed-off-by: Kevin Fox <[email protected]>

* Add missing csi driver settings

Signed-off-by: Kevin Fox <[email protected]>

* Test

Signed-off-by: Kevin Fox <[email protected]>

* Test

Signed-off-by: Kevin Fox <[email protected]>

* Fix

Signed-off-by: Kevin Fox <[email protected]>

* Use local oidc discovery provider path by default

Signed-off-by: Kevin Fox <[email protected]>

* Enable spire-identity-exchange in shared infrastructure

Signed-off-by: Kevin Fox <[email protected]>

* Update timeout

Signed-off-by: Kevin Fox <[email protected]>

* Update timeout

Signed-off-by: Kevin Fox <[email protected]>

* Test config

Signed-off-by: Kevin Fox <[email protected]>

* Test config

Signed-off-by: Kevin Fox <[email protected]>

* Test config

Signed-off-by: Kevin Fox <[email protected]>

* Test config

Signed-off-by: Kevin Fox <[email protected]>

* Fix

Signed-off-by: Kevin Fox <[email protected]>

* Fix

Signed-off-by: Kevin Fox <[email protected]>

* Bump spire-ha-agent version to fix issue

Signed-off-by: Kevin Fox <[email protected]>

* Fix

Signed-off-by: Kevin Fox <[email protected]>

* Fix

Signed-off-by: Kevin Fox <[email protected]>

* Bump version

Signed-off-by: Kevin Fox <[email protected]>

* Update version bits to match what it should be, minus final bump

Signed-off-by: Kevin Fox <[email protected]>

---------

Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
2026-08-18 05:17:43 +00:00
..

spire-ha-agent

Version: 0.1.0 Type: application AppVersion: 1.7.2

A Helm chart to install the SPIRE HA agent.

Homepage: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire

Maintainers

Name Email Url
marcofranssen [email protected] https://marcofranssen.nl
kfox1111 [email protected]
faisal-memon [email protected]

Source Code

Parameters

Chart parameters

Name Description Value
image.registry The OCI registry to pull the image from ghcr.io
image.repository The repository within the registry spiffe/spire-ha-agent
image.pullPolicy The image pull policy IfNotPresent
image.tag Overrides the image tag whose default is the chart appVersion ""
mode If the spire-ha-agent will run in delegated or broker mode delegated
singleSocket If in singleSocket mode, only one driver is used false
sockets.single.admin.hostPath Where the admin socket is on disk when in single socket mode /var/run/spire/agent/sockets/main/csi.spiffe.io/admin
sockets.a.admin.hostPath Where the a admin socket is on disk /var/run/spire/agent/sockets/a/csi.spiffe.io/admin
sockets.b.admin.hostPath Where the b admin sockets is on disk /var/run/spire/agent/sockets/b/csi.spiffe.io/admin
sockets.single.broker.hostPath Where the broker socket is on disk when in single socket mode /var/run/spire/agent/sockets/main/csi.spiffe.io/broker
sockets.a.broker.hostPath Where the a broker socket is on disk /var/run/spire/agent/sockets/a/csi.spiffe.io/broker
sockets.b.broker.hostPath Where the b broker socket is on disk /var/run/spire/agent/sockets/b/csi.spiffe.io/broker
sockets.single.workload.hostPath Where the broker socket is on disk when in single socket mode /var/run/spire/agent-sockets
sockets.a.workload.hostPath Where the a workload socket is on disk /var/run/spire/agent/sockets/a/csi.spiffe.io/public
sockets.b.workload.hostPath Where the b workload socket is on disk /var/run/spire/agent/sockets/b/csi.spiffe.io/public
vsock Use a vsockets to expose the service rather then a unix socket false
port Port number to listen on 999
imagePullSecrets Pull secrets for images []
nameOverride Name override ""
namespaceOverride Namespace override ""
fullnameOverride Fullname override ""
serviceAccount.create Specifies whether a service account should be created true
serviceAccount.annotations Annotations to add to the service account {}
serviceAccount.name The name of the service account to use. ""
podAnnotations Annotations to add to pods {}
podLabels Labels to add to pods {}
podSecurityContext Pod security context {}
securityContext Security context {}
resources Resource requests and limits {}
nodeSelector Node selector {}
tolerations List of tolerations []
affinity Node affinity {}
updateStrategy.type The update strategy to use to replace existing DaemonSet pods with new pods. Can be RollingUpdate or OnDelete. RollingUpdate
updateStrategy.rollingUpdate.maxUnavailable Max unavailable pods during update. Can be a number or a percentage. 1
fsGroupFix.image.registry The OCI registry to pull the image from cgr.dev
fsGroupFix.image.repository The repository within the registry chainguard/bash
fsGroupFix.image.pullPolicy The image pull policy Always
fsGroupFix.image.tag Overrides the image tag whose default is the chart appVersion latest@sha256:ea74a5487d6a76198fb651b48e953a01d13128c68ecf38df3d6e22307f0b93c1
fsGroupFix.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ {}
cid2PID.image.registry The OCI registry to pull the image from ghcr.io
cid2PID.image.repository The repository within the registry kfox1111/cid2pid
cid2PID.image.pullPolicy The image pull policy Always
cid2PID.image.tag Overrides the image tag whose default is the chart appVersion v0.0.3
cid2PID.busybox.image.registry The OCI registry to pull the image from docker.io
cid2PID.busybox.image.repository The repository within the registry library/busybox
cid2PID.busybox.image.pullPolicy The image pull policy IfNotPresent
cid2PID.busybox.image.tag Overrides the image tag whose default is the chart appVersion 1.36.1-uclibc
cid2PID.busybox.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ {}
socketPath The unix socket path to the spire-agent /run/spire/agent-sockets/spire-agent.sock
socketAlternate.names List of alternate names for the socket that workloads might expect to be able to access in the driver mount. ["socket","spire-agent.sock","api.sock"]
socketAlternate.image.registry The OCI registry to pull the image from cgr.dev
socketAlternate.image.repository The repository within the registry chainguard/bash
socketAlternate.image.pullPolicy The image pull policy Always
socketAlternate.image.tag Overrides the image tag whose default is the chart appVersion latest@sha256:ea74a5487d6a76198fb651b48e953a01d13128c68ecf38df3d6e22307f0b93c1
socketAlternate.resources Specify resource needs as per https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ {}
priorityClassName Priority class assigned to daemonset pods. Can be auto set with global.recommendations.priorityClassName. ""
extraEnvVars Extra environment variables to be added to the Spire Agent container []
extraVolumes Extra volumes to be mounted on Spire Agent pods []
extraVolumeMounts Extra volume mounts for Spire Agent pods []
extraContainers Additional containers to create with Spire Agent pods []
initContainers Additional init containers to create with Spire Agent pods []
hostAliases Customize /etc/hosts file as described here https://kubernetes.io/docs/tasks/network/customize-hosts-file-for-pods/ []