80705999dda3598f0b1ee82cf3e920df48905863
* feat(spire-server): support x509pop externalPKI ca bundle Add externalPKI mode support to the x509pop node attestor configuration. Allows operators to configure CA bundles for external PKI-based node attestation via two approaches: - Inline PEM content (chart creates and manages ConfigMap) - Reference to existing ConfigMap with ca-bundle.pem key Includes volume/volumeMount definitions for CA bundle mounting at /run/spire/data/x509pop-ca-bundle.pem and unit tests for both modes. Signed-off-by: Savitha Ganapathi <[email protected]> * refactor: simplify x509pop externalPKI template guard logic Remove nested conditional guard for ca_bundle_path rendering. When externalPKI mode is enabled, ca_bundle_path is always rendered; if no CA bundle is provided, SPIRE will fail at startup with a clear error. Drop unit tests pending fix to the unit test framework (which currently has issues loading values from chart, forcing overly-defensive template guards for test compatibility). Tests can be re-added once framework is fixed. Signed-off-by: Savitha Ganapathi <[email protected]> * refactor: simplify x509pop volume/volumeMount guard logic Remove nested caBundle existence checks from volume and volumeMount guard conditions. When externalPKI mode is enabled, volume/volumeMount are created; if no CA bundle is provided, SPIRE fails at startup with clear error (missing mount). Signed-off-by: Savitha Ganapathi <[email protected]> * refactor: reorder if/with clauses for clarity Move if condition checks to outer scope before entering with blocks. This is more idiomatic Helm pattern and avoids unnecessary context switching if condition fails. Signed-off-by: Savitha Ganapathi <[email protected]> * refactor: simplify conditionals to match chart patterns Replace complex toString/eq comparisons with simpler boolean checks that match existing patterns in the chart (e.g., federation.tls.certManager.enabled). Changes: - .enabled checks: remove toString wrapping, use simple boolean test - .mode checks: remove toString, use simple eq comparison - .caBundle checks: simplify from 'ne (... | default "") ""' to simple boolean test This aligns with chart conventions and avoids tripping broken unit test framework that struggles with complex conditionals. Signed-off-by: Savitha Ganapathi <[email protected]> * test: resurrect x509POP unit tests with simplified conditionals Re-add unit tests for externalPKI mode now that template conditionals have been simplified to match chart patterns. Simplified conditionals should be less fragile with unit test framework. Tests cover: - externalPKI with chart-managed CA bundle (inline) - externalPKI with existing ConfigMap reference Signed-off-by: Savitha Ganapathi <[email protected]> * docs: regenerate spire-server README for x509pop caBundle params Updated parameter documentation for nodeAttestor.x509POP section to include new caBundle configuration options (inline bundle and existing ConfigMap reference). Auto-generated documentation based on @param comments in values.yaml. Signed-off-by: Savitha Ganapathi <[email protected]> --------- Signed-off-by: Savitha Ganapathi <[email protected]> Co-authored-by: Savitha Ganapathi <[email protected]>
Note
Things to consider:
- We do not support running out of the git main branch. This is where development happens. Please use released versions via the published repo or git tags.
- All the helm charts in this repo are beta. We encourage you to try them out and contribute. The API may change as we move towards a production ready release.
SPIFFE Helm Charts
A suite of Helm Charts for standardized installations of SPIRE components in Kubernetes environments.
How to install or upgrade
You most likely want to do an integrated setup based on the spire chart. See the Instructions.
Contributing
Before contributing ensure to check our CONTRIBUTING guidelines.
LICENSE
This project is licensed under Apache License, Version 2.0.
Reporting a Vulnerability
Vulnerabilities can be reported by sending an email to [email protected]. A confirmation email will be sent to acknowledge the report within 72 hours. A second acknowledgement will be sent within 7 days when the vulnerability has been positively or negatively confirmed.
Languages
Go Template
49.2%
Shell
23.7%
Go
16.2%
Python
7.9%
Makefile
1.6%
Other
1.4%