* README.md version match check Signed-off-by: Kevin Fox <[email protected]> * Fix existing version issues Signed-off-by: Kevin Fox <[email protected]> * Fix existing version issues Signed-off-by: Kevin Fox <[email protected]> --------- Signed-off-by: Kevin Fox <[email protected]>
spire
A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.
Homepage: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
Install Instructions
Non Production
To do a quick install suitable for testing in something like minikube:
helm upgrade --install -n spire-server spire-crds spire-crds --repo https://spiffe.github.io/helm-charts-hardened/ --create-namespace
helm upgrade --install -n spire-server spire spire-nested --repo https://spiffe.github.io/helm-charts-hardened/
Production
Preparing a production deployment requires a few steps.
- Save the following to your-values.yaml, ideally in your git repo.
global:
openshift: false # If running on openshift, set to true
spire:
recommendations:
enabled: true
namespaces:
create: true
ingressControllerType: "" # If not openshift, and want to expose services, set to a supported option [ingress-nginx]
# Update these
clusterName: example-cluster
trustDomain: example.org
caSubject:
country: ARPA
organization: Example
commonName: example.org
- If you need a non default storageClass, append the following to the spire-server section and update:
persistence:
storageClass: your-storage-class
- If your Kubernetes cluster is OpenShift based, use the output of the following command to update the trustDomain setting:
oc get cm -n openshift-config-managed console-public -o go-template="{{ .data.consoleURL }}" | sed 's@https://@@; s/^[^.]*\.//'
- Find any additional values you might want to set based on the documentation below or using the examples
In particular, consider using an external database.
- Deploy
helm upgrade --install -n spire-mgmt spire-crds spire-crds --repo https://spiffe.github.io/helm-charts-hardened/ --create-namespace
helm upgrade --install -n spire-mgmt spire spire-nested --repo https://spiffe.github.io/helm-charts-hardened/ -f your-values.yaml
Clean up
helm -n spire-mgmt uninstall spire-crds
helm -n spire-mgmt uninstall spire
kubectl -n spire-server delete pvc -l app.kubernetes.io/instance=spire
kubectl delete crds clusterfederatedtrustdomains.spire.spiffe.io clusterspiffeids.spire.spiffe.io clusterstaticentries.spire.spiffe.io
Upgrade notes
We only support upgrading one major version at a time. Version skipping isn't supported.
0.17.X
-
If you set spire-server.replicaCount > 1, update it to 1 before upgrading and after upgrade you can set it back to its previous value.
-
The SPIFFE OIDC Discovery Provider now has many new TLS options and defaults to using SPIRE to issue its certificate.
-
The
spiffe-oidc-discovery-provider.insecureScheme.enabledflag was removed. If you previously set that flag, remove the setting from your values.yaml and see if the new default of using a SPIRE issued certificate is suitable for your deployment. If it isn't, please consider one of the other options underspiffe-oidc-discovery-provider.tls. If all other options are still unsuitable, you can still enable the previous mode by disabling TLS. (spiffe-oidc-discovery-provider.tls.spire.enabled=false) -
The SPIFFE OIDC Discovery Provider is now enabled by default. If you previously chose to have it off, you can disable it explicitly with
spiffe-oidc-discovery-provider.enabled=false.
0.16.X
The settings under "spire-server.controllerManager.identities" have all been moved under "spire-server.controllerManager.identities.clusterSPIFFEIDs.default". If you have changed any from the defaults, please update them to the new location during upgrade.
0.15.X
The spire-crds chart has been updated. Please ensure you have upgraded spire-crds before upgrading the spire chart.
The chart now supports multiple parallel installs of spire-controller-manager. Each install will handle all custom resources with a matching className field. By default this is set to Release.Namespace-Release.Name and the controller manager will only pick up custom resources with this className.
If you have not loaded any SPIRE custom resources yourself, the upgrade process will be transparent. If you have loaded your own SPIRE custom resources, set spire-server.controllerManager.watchClassless=true until you can update your SPIRE custom resources to have the className for the instance specified.
0.14.X
If coming from a chart version before 0.14.0, you must relabel your crds to switch to using the new spire-crds chart. To migrate to the spire-crds chart run the following:
Replace the spire-server namespace in the commands below with the namespace you want to install the spire-crds chart in.
kubectl label crd "clusterfederatedtrustdomains.spire.spiffe.io" "app.kubernetes.io/managed-by=Helm"
kubectl annotate crd "clusterfederatedtrustdomains.spire.spiffe.io" "meta.helm.sh/release-name=spire-crds"
kubectl annotate crd "clusterfederatedtrustdomains.spire.spiffe.io" "meta.helm.sh/release-namespace=spire-server"
kubectl label crd "clusterspiffeids.spire.spiffe.io" "app.kubernetes.io/managed-by=Helm"
kubectl annotate crd "clusterspiffeids.spire.spiffe.io" "meta.helm.sh/release-name=spire-crds"
kubectl annotate crd "clusterspiffeids.spire.spiffe.io" "meta.helm.sh/release-namespace=spire-server"
kubectl label crd "controllermanagerconfigs.spire.spiffe.io" "app.kubernetes.io/managed-by=Helm"
kubectl annotate crd "controllermanagerconfigs.spire.spiffe.io" "meta.helm.sh/release-name=spire-crds"
kubectl annotate crd "controllermanagerconfigs.spire.spiffe.io" "meta.helm.sh/release-namespace=spire-server"
helm install -n spire-server spire-crds charts/spire-crds
Version support
Warning
This Chart is still in development and still subject to change the API (
values.yaml). Until we reach a1.0.0version of the chart we can't guarantee backwards compatibility although we do aim for as much stability as possible.
| Dependency | Supported Versions |
|---|---|
| Helm | 3.x |
| Kubernetes | 1.22+ |
Note
For Kubernetes, we will officially support the last 3 versions as described in k8s versioning. Any version before the last 3 we will try to support as long it doesn't bring security issues or any big maintenance burden.
FAQ
For any issues see our FAQ…
Usage
To utilize Spire in your own workloads you should add the following to your workload:
apiVersion: v1
kind: Pod
metadata:
name: my-app
spec:
containers:
- name: my-app
image: "my-app:latest"
imagePullPolicy: Always
+ volumeMounts:
+ - name: spiffe-workload-api
+ mountPath: /spiffe-workload-api
+ readOnly: true
resources:
requests:
cpu: 200m
memory: 32Mi
limits:
cpu: 500m
memory: 64Mi
+ volumes:
+ - name: spiffe-workload-api
+ csi:
+ driver: "csi.spiffe.io"
+ readOnly: true
Now you can interact with the Spire agent socket from your own application. The socket is mounted on /spiffe-workload-api/spire-agent.sock.
Maintainers
| Name | Url | |
|---|---|---|
| marcofranssen | [email protected] | https://marcofranssen.nl |
| kfox1111 | [email protected] | |
| faisal-memon | [email protected] | |
| edwbuck | [email protected] |
Source Code
Requirements
| Repository | Name | Version |
|---|---|---|
| file://./charts/spiffe-csi-driver | spiffe-csi-driver | 0.1.0 |
| file://./charts/spiffe-csi-driver | upstream-spiffe-csi-driver(spiffe-csi-driver) | 0.1.0 |
| file://./charts/spiffe-oidc-discovery-provider | spiffe-oidc-discovery-provider | 0.1.0 |
| file://./charts/spire-agent | spire-agent | 0.1.0 |
| file://./charts/spire-agent | upstream-spire-agent(spire-agent) | 0.1.0 |
| file://./charts/spire-server | spire-server | 0.1.0 |
| file://./charts/tornjak-frontend | tornjak-frontend | 0.1.0 |
Parameters
Global parameters
| Name | Description | Value |
|---|---|---|
global.k8s.clusterDomain |
Cluster domain name configured for Spire install | cluster.local |
global.spire.clusterName |
The name of the k8s cluster for Spire install | example-cluster |
global.spire.jwtIssuer |
The issuer for Spire JWT tokens. Defaults to oidc-discovery.$trustDomain if unset | "" |
global.spire.trustDomain |
The trust domain for Spire install | example.org |
global.spire.caSubject.country |
Country for Spire server CA | "" |
global.spire.caSubject.organization |
Organization for Spire server CA | "" |
global.spire.caSubject.commonName |
Common Name for Spire server CA | "" |
global.spire.recommendations.enabled |
Use recommended settings for production deployments. Default is off. | false |
global.spire.recommendations.namespaceLayout |
Set to true to use recommended values for installing across namespaces | true |
global.spire.recommendations.namespacePSS |
When chart namespace creation is enabled, label them with preffered Pod Security Standard labels | true |
global.spire.recommendations.priorityClassName |
Set to true to use recommended values for Pod Priority Class Names | true |
global.spire.recommendations.strictMode |
Check values, such as trustDomain, are overridden with a suitable value for production. | true |
global.spire.recommendations.securityContexts |
Set to true to use recommended values for Pod and Container Security Contexts | true |
global.spire.recommendations.prometheus |
Enable prometheus exporters for monitoring | true |
global.spire.image.registry |
Override all Spire image registries at once | "" |
global.spire.namespaces.create |
Set to true to Create all namespaces. If this or either of the namespace specific create flags is set, the namespace will be created. | false |
global.spire.namespaces.system.name |
Name of the Spire system Namespace. | spire-system |
global.spire.namespaces.system.create |
Create a Namespace for Spire system resources. | false |
global.spire.namespaces.system.annotations |
Annotations to apply to the Spire system Namespace. | {} |
global.spire.namespaces.system.labels |
Labels to apply to the Spire system Namespace. | {} |
global.spire.namespaces.server.name |
Name of the Spire server Namespace. | spire-server |
global.spire.namespaces.server.create |
Create a Namespace for Spire server resources. | false |
global.spire.namespaces.server.annotations |
Annotations to apply to the Spire server Namespace. | {} |
global.spire.namespaces.server.labels |
Labels to apply to the Spire server Namespace. | {} |
global.spire.strictMode |
Check values, such as trustDomain, are overridden with a suitable value for production. | false |
global.spire.ingressControllerType |
Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, autodetection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | "" |
global.spire.gatewayAPI.manageListenerSets |
Default policy for whether services render a ListenerSet for their SNI listener. Each service may override via its gatewayAPI.listenerSet.enabled. | true |
global.spire.gatewayAPI.gateway.name |
Name of the shared Gateway object that routes and ListenerSets attach to | spire |
global.spire.gatewayAPI.gateway.namespace |
Namespace of the shared Gateway object. Defaults to the release namespace if blank. | spire-server |
global.spire.gatewayAPI.gateway.port |
Port the shared Gateway listens on. ListenerSet listeners must match this. | 443 |
global.spire.tools.kubectl.tag |
Set to force the tag to use for all kubectl instances | "" |
global.installAndUpgradeHooks.enabled |
Enable Helm hooks to autofix common install/upgrade issues (should be disabled when using helm template) |
true |
global.deleteHooks.enabled |
Enable Helm hooks to autofix common delete issues (should be disabled when using helm template) |
true |
tags.nestedRoot |
Set the chart architecture to root nested | false |
tags.nestedChildFull |
Set the chart mode to a child cluster with its own nested server | false |
tags.nestedChildSecurity |
Set the chart mode to a child cluster for use with a security cluster | false |
tags.haAgentCommon |
Set the chart mode to deploy the common portion of a spire-ha-agent setup | false |
tags.bottomTurtleHAA |
Setup HA side A for use with a Bottom Turtle architecture | false |
tags.bottomTurtleHAB |
Setup HA side B for use with a Bottom Turtle architecture | false |
gatewayAPI.gateway.enabled |
Render the shared Gateway object | false |
gatewayAPI.gateway.className |
gatewayClassName for the shared Gateway (e.g. "eg"). Required when enabled. | "" |
gatewayAPI.gateway.annotations |
Annotations for the Gateway object | {} |
gatewayAPI.gateway.allowedListenersNamespaces |
From which namespaces ListenerSets may attach to the Gateway. One of All, Same, Selector. | All |
gatewayAPI.gateway.allowedRoutesNamespaces |
From which namespaces routes may attach directly to the base listener (used when ListenerSet management is off). One of All, Same, Selector. | All |
gatewayAPI.gateway.extraListeners |
Additional listeners to add to the Gateway | [] |
spireIdentityExchange.podSelector |
Labels selecting the exchange pods of both sides. Narrow it (for example by adding release-namespace) when other exchanges share the namespace. | {} |
spireIdentityExchange.tls.rest.enabled |
Expose the combined REST endpoint served with the on-disk certificate | false |
spireIdentityExchange.tls.rest.service.type |
Service type | ClusterIP |
spireIdentityExchange.tls.rest.service.port |
port for the service | 443 |
spireIdentityExchange.tls.rest.service.annotations |
Annotations for service resource | {} |
spireIdentityExchange.tls.rest.service.loadBalancerIP |
IP address to assign to load balancer (if supported) | "" |
spireIdentityExchange.tls.rest.ingress.enabled |
Flag to enable ingress | false |
spireIdentityExchange.tls.rest.ingress.className |
Ingress class name | "" |
spireIdentityExchange.tls.rest.ingress.controllerType |
Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, autodetection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | "" |
spireIdentityExchange.tls.rest.ingress.annotations |
Annotations for ingress object | {} |
spireIdentityExchange.tls.rest.ingress.host |
Host name for the ingress. If no '.' in host, trustDomain is automatically appended. Must differ from the per-side hosts. | spire-identity-exchange-rest |
spireIdentityExchange.tls.rest.ingress.tlsSecret |
Secret that has the certs. If blank will use default certs. Used with host var. | "" |
spireIdentityExchange.tls.rest.ingress.hosts |
Host paths for ingress object. If emtpy, rules will be built based on the host var. | [] |
spireIdentityExchange.tls.rest.ingress.tls |
Secrets containining TLS certs to enable https on ingress. If emtpy, rules will be built based on the host and tlsSecret vars. | [] |
spireIdentityExchange.tls.rest.gatewayAPI.enabled |
Flag to expose the endpoint via Gateway API | false |
spireIdentityExchange.tls.rest.gatewayAPI.host |
Host name for the route. If no '.' in host, trustDomain is automatically appended. | spire-identity-exchange-rest |
spireIdentityExchange.tls.rest.gatewayAPI.tlsSecret |
Secret with the TLS cert for edge termination. Blank keeps passthrough. | "" |
spireIdentityExchange.tls.rest.gatewayAPI.annotations |
Annotations for the route (and its ListenerSet) | {} |
spireIdentityExchange.tls.rest.gatewayAPI.listenerSet.enabled |
Manage a ListenerSet for this service's SNI listener. Null inherits global.spire.gatewayAPI.manageListenerSets. | nil |
spireIdentityExchange.tls.rest.gatewayAPI.parentRefs |
parentRefs used when ListenerSet management is disabled (direct attach) | [] |
spireIdentityExchange.tls.rest.gatewayAPI.sectionName |
Listener sectionName override when attaching directly to a Gateway | "" |
spireIdentityExchange.tls.rest.gatewayAPI.backendTLS.caCertificateRefs |
ConfigMap refs holding the backend CA used to validate the re-encrypted connection. Defaults to the SPIRE bundle configmap. | [] |
spireIdentityExchange.tls.grpc.enabled |
Expose the combined gRPC endpoint served with the on-disk certificate | false |
spireIdentityExchange.tls.grpc.service.type |
Service type | ClusterIP |
spireIdentityExchange.tls.grpc.service.port |
port for the service | 443 |
spireIdentityExchange.tls.grpc.service.annotations |
Annotations for service resource | {} |
spireIdentityExchange.tls.grpc.service.loadBalancerIP |
IP address to assign to load balancer (if supported) | "" |
spireIdentityExchange.tls.grpc.ingress.enabled |
Flag to enable ingress | false |
spireIdentityExchange.tls.grpc.ingress.className |
Ingress class name | "" |
spireIdentityExchange.tls.grpc.ingress.controllerType |
Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, autodetection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | "" |
spireIdentityExchange.tls.grpc.ingress.annotations |
Annotations for ingress object | {} |
spireIdentityExchange.tls.grpc.ingress.host |
Host name for the ingress. If no '.' in host, trustDomain is automatically appended. Must differ from the per-side hosts. | spire-identity-exchange-grpc |
spireIdentityExchange.tls.grpc.ingress.tlsSecret |
Secret that has the certs. If blank will use default certs. Used with host var. | "" |
spireIdentityExchange.tls.grpc.ingress.hosts |
Host paths for ingress object. If emtpy, rules will be built based on the host var. | [] |
spireIdentityExchange.tls.grpc.ingress.tls |
Secrets containining TLS certs to enable https on ingress. If emtpy, rules will be built based on the host and tlsSecret vars. | [] |
spireIdentityExchange.tls.grpc.gatewayAPI.enabled |
Flag to expose the endpoint via Gateway API | false |
spireIdentityExchange.tls.grpc.gatewayAPI.host |
Host name for the route. If no '.' in host, trustDomain is automatically appended. | spire-identity-exchange-grpc |
spireIdentityExchange.tls.grpc.gatewayAPI.tlsSecret |
Secret with the TLS cert for edge termination. Blank keeps passthrough. | "" |
spireIdentityExchange.tls.grpc.gatewayAPI.annotations |
Annotations for the route (and its ListenerSet) | {} |
spireIdentityExchange.tls.grpc.gatewayAPI.listenerSet.enabled |
Manage a ListenerSet for this service's SNI listener. Null inherits global.spire.gatewayAPI.manageListenerSets. | nil |
spireIdentityExchange.tls.grpc.gatewayAPI.parentRefs |
parentRefs used when ListenerSet management is disabled (direct attach) | [] |
spireIdentityExchange.tls.grpc.gatewayAPI.sectionName |
Listener sectionName override when attaching directly to a Gateway | "" |
spireIdentityExchange.tls.grpc.gatewayAPI.backendTLS.caCertificateRefs |
ConfigMap refs holding the backend CA used to validate the re-encrypted connection. Defaults to the SPIRE bundle configmap. | [] |
spireIdentityExchange.spiffe.rest.enabled |
Expose the combined REST endpoint served with each side's own X509-SVID | false |
spireIdentityExchange.spiffe.rest.service.type |
Service type | ClusterIP |
spireIdentityExchange.spiffe.rest.service.port |
port for the service | 443 |
spireIdentityExchange.spiffe.rest.service.annotations |
Annotations for service resource | {} |
spireIdentityExchange.spiffe.rest.service.loadBalancerIP |
IP address to assign to load balancer (if supported) | "" |
spireIdentityExchange.spiffe.rest.ingress.enabled |
Flag to enable ingress | false |
spireIdentityExchange.spiffe.rest.ingress.className |
Ingress class name | "" |
spireIdentityExchange.spiffe.rest.ingress.controllerType |
Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, autodetection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | "" |
spireIdentityExchange.spiffe.rest.ingress.annotations |
Annotations for ingress object | {} |
spireIdentityExchange.spiffe.rest.ingress.host |
Host name for the ingress. If no '.' in host, trustDomain is automatically appended. Must differ from the per-side hosts. | spire-identity-exchange-rest-spiffe |
spireIdentityExchange.spiffe.rest.ingress.tlsSecret |
Secret that has the certs. If blank will use default certs. Used with host var. | "" |
spireIdentityExchange.spiffe.rest.ingress.hosts |
Host paths for ingress object. If emtpy, rules will be built based on the host var. | [] |
spireIdentityExchange.spiffe.rest.ingress.tls |
Secrets containining TLS certs to enable https on ingress. If emtpy, rules will be built based on the host and tlsSecret vars. | [] |
spireIdentityExchange.spiffe.rest.gatewayAPI.enabled |
Flag to expose the endpoint via Gateway API | false |
spireIdentityExchange.spiffe.rest.gatewayAPI.host |
Host name for the route. If no '.' in host, trustDomain is automatically appended. | spire-identity-exchange-rest-spiffe |
spireIdentityExchange.spiffe.rest.gatewayAPI.annotations |
Annotations for the route (and its ListenerSet) | {} |
spireIdentityExchange.spiffe.rest.gatewayAPI.listenerSet.enabled |
Manage a ListenerSet for this service's SNI listener. Null inherits global.spire.gatewayAPI.manageListenerSets. | nil |
spireIdentityExchange.spiffe.rest.gatewayAPI.parentRefs |
parentRefs used when ListenerSet management is disabled (direct attach) | [] |
spireIdentityExchange.spiffe.rest.gatewayAPI.sectionName |
Listener sectionName override when attaching directly to a Gateway | "" |
spireIdentityExchange.spiffe.grpc.enabled |
Expose the combined gRPC endpoint served with each side's own X509-SVID | false |
spireIdentityExchange.spiffe.grpc.service.type |
Service type | ClusterIP |
spireIdentityExchange.spiffe.grpc.service.port |
port for the service | 443 |
spireIdentityExchange.spiffe.grpc.service.annotations |
Annotations for service resource | {} |
spireIdentityExchange.spiffe.grpc.service.loadBalancerIP |
IP address to assign to load balancer (if supported) | "" |
spireIdentityExchange.spiffe.grpc.ingress.enabled |
Flag to enable ingress | false |
spireIdentityExchange.spiffe.grpc.ingress.className |
Ingress class name | "" |
spireIdentityExchange.spiffe.grpc.ingress.controllerType |
Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, autodetection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | "" |
spireIdentityExchange.spiffe.grpc.ingress.annotations |
Annotations for ingress object | {} |
spireIdentityExchange.spiffe.grpc.ingress.host |
Host name for the ingress. If no '.' in host, trustDomain is automatically appended. Must differ from the per-side hosts. | spire-identity-exchange-grpc-spiffe |
spireIdentityExchange.spiffe.grpc.ingress.tlsSecret |
Secret that has the certs. If blank will use default certs. Used with host var. | "" |
spireIdentityExchange.spiffe.grpc.ingress.hosts |
Host paths for ingress object. If emtpy, rules will be built based on the host var. | [] |
spireIdentityExchange.spiffe.grpc.ingress.tls |
Secrets containining TLS certs to enable https on ingress. If emtpy, rules will be built based on the host and tlsSecret vars. | [] |
spireIdentityExchange.spiffe.grpc.gatewayAPI.enabled |
Flag to expose the endpoint via Gateway API | false |
spireIdentityExchange.spiffe.grpc.gatewayAPI.host |
Host name for the route. If no '.' in host, trustDomain is automatically appended. | spire-identity-exchange-grpc-spiffe |
spireIdentityExchange.spiffe.grpc.gatewayAPI.annotations |
Annotations for the route (and its ListenerSet) | {} |
spireIdentityExchange.spiffe.grpc.gatewayAPI.listenerSet.enabled |
Manage a ListenerSet for this service's SNI listener. Null inherits global.spire.gatewayAPI.manageListenerSets. | nil |
spireIdentityExchange.spiffe.grpc.gatewayAPI.parentRefs |
parentRefs used when ListenerSet management is disabled (direct attach) | [] |
spireIdentityExchange.spiffe.grpc.gatewayAPI.sectionName |
Listener sectionName override when attaching directly to a Gateway | "" |
Spire agent parameters
| Name | Description | Value |
|---|---|---|
downstream-spire-agent-full.nameOverride |
Overrides the name of Spire agent pods | agent-downstream |
downstream-spire-agent-full.server.nameOverride |
The name override setting of the internal SPIRE server | internal-server |
downstream-spire-agent-full.bundleConfigMap |
The name of the configmap that contains the downstream bundle | spire-bundle-downstream |
downstream-spire-agent-full.persistence.hostPath |
Which path to use on the host when persistence.type = hostPath | /var/lib/spire/k8s/downstream-agent |
Spire agent parameters
| Name | Description | Value |
|---|---|---|
downstream-spire-agent-security.nameOverride |
Overrides the name of Spire agent pods | agent-downstream |
downstream-spire-agent-security.bundleConfigMap |
The name of the configmap that contains the downstream bundle | spire-bundle-upstream |
downstream-spire-agent-security.serviceAccount.name |
The name of the service account to use | spire-agent-upstream |
downstream-spire-agent-security.persistence.hostPath |
Which path to use on the host when persistence.type = hostPath | /var/lib/spire/k8s/downstream-agent |
Upstream Spire agent parameters
| Name | Description | Value |
|---|---|---|
upstream-spire-agent.upstream |
Flag for enabling upstream Spire agent | true |
upstream-spire-agent.nameOverride |
Name override for upstream Spire agent | agent-upstream |
upstream-spire-agent.bundleConfigMap |
The configmap name for upstream Spire agent bundle | spire-bundle-upstream |
upstream-spire-agent.socketPath |
Socket path where Spire agent socket is mounted | /run/spire/agent-sockets-upstream/spire-agent.sock |
upstream-spire-agent.serviceAccount.name |
Service account name for upstream Spire agent | spire-agent-upstream |
upstream-spire-agent.healthChecks.port |
Health check port number for upstream Spire agent | 9981 |
upstream-spire-agent.telemetry.prometheus.port |
The port where prometheus metrics are available | 9989 |
upstream-spire-agent.server.nameOverride |
The name override setting of the root SPIRE server | root-server |
upstream-spire-agent.persistence.hostPath |
Which path to use on the host when persistence.type = hostPath | /var/lib/spire/k8s/upstream-agent |
SPIFFE CSI Driver parameters
| Name | Description | Value |
|---|---|---|
downstream-spiffe-csi-driver.fullnameOverride |
Fullname override | spiffe-csi-driver-downstream |
Upstream SPIFFE CSI Driver parameters
| Name | Description | Value |
|---|---|---|
upstream-spiffe-csi-driver.fullnameOverride |
Fullname override | spiffe-csi-driver-upstream |
upstream-spiffe-csi-driver.pluginName |
The plugin name for configuring upstream Spiffe CSI driver | upstream.csi.spiffe.io |
upstream-spiffe-csi-driver.agentSocketPath |
The socket path where Spiffe CSI driver mounts agent socket | /run/spire/agent-sockets-upstream/spire-agent.sock |
upstream-spiffe-csi-driver.healthChecks.port |
The port where Spiffe CSI driver health checks are exposed | 9810 |
SPIFFE oidc discovery provider parameters
| Name | Description | Value |
|---|---|---|
spiffe-oidc-discovery-provider.fullnameOverride |
Fullname override | spiffe-oidc-discovery-provider |
Tornjak frontend parameters
| Name | Description | Value |
|---|---|---|
tornjak-frontend.enabled |
Enables deployment of Tornjak frontend/UI (Not for production) | false |
root-spire-server.nameOverride |
Name override | root-server |
root-spire-server.crNameOverride |
Custom Resource name override | root |
root-spire-server.controllerManager.enabled |
Enable controller manager and provision CRD's | true |
root-spire-server.controllerManager.externalControllerManagers.enabled |
Flag to enable external controller managers | true |
root-spire-server.controllerManager.validatingWebhookConfiguration.enabled |
Disable only when you have another instance on the k8s cluster with webhooks enabled. | false |
root-spire-server.controllerManager.className |
specify to use an explicit class name. | spire-mgmt-root-server |
root-spire-server.controllerManager.identities.clusterSPIFFEIDs.child-servers.enabled |
Enable child servers | true |
root-spire-server.controllerManager.identities.clusterSPIFFEIDs.default.enabled |
Enable the default cluster spiffe id | false |
root-spire-server.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.enabled |
Enable the test-keys identity | false |
root-spire-server.controllerManager.identities.clusterSPIFFEIDs.test-keys.enabled |
Enable the test-keys identity | false |
root-spire-server.externalControllerManagers.enabled |
Flag to enable external controller managers | true |
root-spire-server.nodeAttestor.k8sPSAT.serviceAccountAllowList |
Allowed service accounts for PSAT nodeattestor | [] |
root-spire-server.bundleConfigMap |
The name of the configmap to store the upstream bundle | spire-bundle-upstream |
external-root-spire-server-full.externalServer |
Set to true to setup the bundle configmap, rbac rules, and identity documents but doesn't deploy the server locally. Useful for external servers. | true |
external-root-spire-server-full.nameOverride |
Name override | root-server |
external-root-spire-server-full.crNameOverride |
Custom Resource name override | root |
external-root-spire-server-full.controllerManager.enabled |
Enable controller manager and provision CRD's | true |
external-root-spire-server-full.controllerManager.validatingWebhookConfiguration.enabled |
Disable only when you have another instance on the k8s cluster with webhooks enabled. | false |
external-root-spire-server-full.controllerManager.className |
specify to use an explicit class name. | spire-mgmt-external-server |
external-root-spire-server-full.controllerManager.identities.clusterSPIFFEIDs.child-servers.enabled |
Enable child servers | true |
external-root-spire-server-full.controllerManager.identities.clusterSPIFFEIDs.child-servers.labels |
Default label spire.spiffe.io/child-server is set to enable label-based informer filtering on the root cluster's external controller manager. | {} |
external-root-spire-server-full.controllerManager.identities.clusterSPIFFEIDs.default.enabled |
Enable the default cluster spiffe id | false |
external-root-spire-server-full.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.enabled |
Enable the test-keys identity | false |
external-root-spire-server-full.controllerManager.identities.clusterSPIFFEIDs.test-keys.enabled |
Enable the test-keys identity | false |
external-root-spire-server-full.nodeAttestor.k8sPSAT.serviceAccountAllowList |
Allowed service accounts for PSAT nodeattestor | [] |
external-root-spire-server-full.bundleConfigMap |
The name of the configmap to store the upstream bundle | spire-bundle-upstream |
external-root-spire-server-security.externalServer |
Set to true to setup the bundle configmap, rbac rules, and identity documents but doesn't deploy the server locally. Useful for external servers. | true |
external-root-spire-server-security.nameOverride |
Name override | root-server |
external-root-spire-server-security.crNameOverride |
Custom Resource name override | root |
external-root-spire-server-security.controllerManager.enabled |
Enable controller manager and provision CRD's | true |
external-root-spire-server-security.controllerManager.validatingWebhookConfiguration.enabled |
Disable only when you have another instance on the k8s cluster with webhooks enabled. | false |
external-root-spire-server-security.controllerManager.className |
specify to use an explicit class name. | spire-mgmt-external-server |
external-root-spire-server-security.nodeAttestor.k8sPSAT.serviceAccountAllowList |
Allowed service accounts for PSAT nodeattestor | [] |
external-root-spire-server-security.bundleConfigMap |
The name of the configmap to store the upstream bundle | spire-bundle-upstream |
Spire server parameters
| Name | Description | Value |
|---|---|---|
internal-spire-server.nameOverride |
Overrides the name of Spire server pods | internal-server |
internal-spire-server.controllerManager.enabled |
Enable controller manager and provision CRD's | true |
internal-spire-server.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.autoPopulateDNSNames |
Auto populate dns entries | false |
internal-spire-server.externalControllerManagers.enabled |
Flag to enable external controller managers | true |
internal-spire-server.upstreamAuthority.spire.enabled |
Enable upstream SPIRE server | true |
internal-spire-server.upstreamAuthority.spire.upstreamDriver |
Use an upstream driver for authentication | upstream.csi.spiffe.io |
internal-spire-server.upstreamAuthority.spire.server.nameOverride |
The name override setting of the root SPIRE server | root-server |
internal-spire-server.bundleConfigMap |
The name of the configmap to store the downstream bundle | spire-bundle-downstream |
external-spire-server.nameOverride |
Overrides the name of Spire server pods | external-server |
external-spire-server.crNameOverride |
Custom Resource name override | external |
external-spire-server.controllerManager.enabled |
Enable controller manager and provision CRD's | true |
external-spire-server.controllerManager.validatingWebhookConfiguration.enabled |
Disable only when you have another instance on the k8s cluster with webhooks enabled. | false |
external-spire-server.controllerManager.className |
specify to use an explicit class name. | spire-mgmt-external-server |
external-spire-server.controllerManager.identities.clusterSPIFFEIDs.default.enabled |
Enable the default identity | false |
external-spire-server.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.enabled |
Enable the oidc-discovery-provider identity | false |
external-spire-server.controllerManager.identities.clusterSPIFFEIDs.test-keys.enabled |
Enable the test-keys identity | false |
external-spire-server.externalControllerManagers.enabled |
Flag to enable external controller managers | true |
external-spire-server.upstreamAuthority.spire.enabled |
Enable upstream SPIRE server | true |
external-spire-server.upstreamAuthority.spire.upstreamDriver |
Use an upstream driver for authentication | upstream.csi.spiffe.io |
external-spire-server.upstreamAuthority.spire.server.nameOverride |
The name override setting of the root SPIRE server | root-server |
external-spire-server.bundlePublisher.k8sConfigMap.enabled |
Enable local k8s bundle uploader | false |
external-spire-server.nodeAttestor.k8sPSAT.enabled |
Enable PSAT k8s nodeattestor | false |
external-spire-server.nodeAttestor.joinToken.enabled |
Enable the join_token nodeattestor | true |
spiffe-csi-driver.fullnameOverride |
Fullname override | spiffe-csi-driver |
spiffe-csi-driver.agentSocketPath |
The socket path where Spiffe CSI driver mounts agent socket | /var/run/spire/agent-sockets/spire-agent.sock |
spiffe-csi-driver.healthChecks.port |
Health check port number for upstream Spire agent | 9814 |
spire-ha-agent.fullnameOverride |
Fullname override | spire-ha-agent |
Upstream SPIFFE CSI Driver for Bottom Turtle HA A parameters
| Name | Description | Value |
|---|---|---|
upstream-spiffe-csi-driver-bottom-turtle-ha-a.fullnameOverride |
Fullname override | spiffe-csi-driver-upstream-a |
upstream-spiffe-csi-driver-bottom-turtle-ha-a.pluginName |
The plugin name for configuring upstream Spiffe CSI driver | upstream-a.csi.spiffe.io |
upstream-spiffe-csi-driver-bottom-turtle-ha-a.agentSocketPath |
The socket path where Spiffe CSI driver mounts agent socket | /var/run/spiffe/socat/unix/k8s-spire-server-a/public/spire-agent.sock |
upstream-spiffe-csi-driver-bottom-turtle-ha-a.healthChecks.port |
The port where Spiffe CSI driver health checks are exposed | 9810 |
upstream-spiffe-csi-driver-bottom-turtle-ha-a.validatingAdmissionPolicy.enabled |
Flag to enable validating policy | true |
Upstream SPIFFE CSI Driver for Bottom Turtle HA B parameters
| Name | Description | Value |
|---|---|---|
upstream-spiffe-csi-driver-bottom-turtle-ha-b.fullnameOverride |
Fullname override | spiffe-csi-driver-upstream-b |
upstream-spiffe-csi-driver-bottom-turtle-ha-b.pluginName |
The plugin name for configuring upstream Spiffe CSI driver | upstream-b.csi.spiffe.io |
upstream-spiffe-csi-driver-bottom-turtle-ha-b.agentSocketPath |
The socket path where Spiffe CSI driver mounts agent socket | /var/run/spiffe/socat/unix/k8s-spire-server-b/public/spire-agent.sock |
upstream-spiffe-csi-driver-bottom-turtle-ha-b.healthChecks.port |
The port where Spiffe CSI driver health checks are exposed | 9812 |
upstream-spiffe-csi-driver-bottom-turtle-ha-b.validatingAdmissionPolicy.enabled |
Flag to enable validating policy | true |
Spire server parameters
| Name | Description | Value |
|---|---|---|
internal-spire-server-bottom-turtle-ha-a.nameOverride |
Overrides the name of Spire server pods | internal-server |
internal-spire-server-bottom-turtle-ha-a.caKeyType |
Key type to use for the ca | ec-p256 |
internal-spire-server-bottom-turtle-ha-a.experimental.enabled |
enable experimental features | true |
internal-spire-server-bottom-turtle-ha-a.experimental.agentSPIFFEIDAsSelector |
enable adding spiffe_id selectors to all agents | true |
internal-spire-server-bottom-turtle-ha-a.dynamicRegistration.enabled |
Enable dynamic registration | true |
internal-spire-server-bottom-turtle-ha-a.dynamicRegistration.allowedIDPrefix |
The allowed ID prefix | spire/agent/x509pop/k8s |
internal-spire-server-bottom-turtle-ha-a.dynamicRegistration.serviceAccount |
The service account to allow in for dynamic registration | spire-a-agent |
internal-spire-server-bottom-turtle-ha-a.controllerManager.enabled |
Enable controller manager and provision CRD's | true |
internal-spire-server-bottom-turtle-ha-a.controllerManager.parentIDTemplate |
parent id template | spiffe://{{ .TrustDomain }}/k8s_psat/{{ .ClusterName }}/{{ .NodeMeta.UID }} |
internal-spire-server-bottom-turtle-ha-a.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.autoPopulateDNSNames |
Auto populate dns entries | false |
internal-spire-server-bottom-turtle-ha-a.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.type |
The type of the entry | oidc-discovery-provider-common |
internal-spire-server-bottom-turtle-ha-a.controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.enabled |
Enables the spire-ha-agent identity | true |
internal-spire-server-bottom-turtle-ha-a.controllerManager.identities.clusterSPIFFEIDs.spire-identity-exchange-service.federatesWith |
List of trust domains to federate with | [] |
internal-spire-server-bottom-turtle-ha-a.persistence.type |
What type to use for peristence | emptyDir |
internal-spire-server-bottom-turtle-ha-a.nodeAttestor.k8sPSAT.enabled |
Enable the k8s projected access token node attestor | false |
internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.enabled |
Enable the x509 pop node attestor | true |
internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.spiffePrefix |
What prefix to use when mode is spiffe | /spire-exchange/k8s${HELM_ADD_CLUSTER_NAME}/ |
internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.agentPathTemplate |
Override the default agent path template | /{{ .PluginName }}/k8s${HELM_ADD_CLUSTER_NAME}/{{ .SVIDPathTrimmed }} |
internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.addClusterName.spiffePrefix |
Suffix the cluster name onto the spiffePrefix | true |
internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.addClusterName.agentPathTemplate |
Suffix the cluster name onto the agentPathTemplate | true |
internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.enabled |
Enable upstream SPIRE server | true |
internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.upstreamDriver |
Use an upstream driver for authentication | upstream-a.csi.spiffe.io |
internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.server.nameOverride |
The name override setting of the root SPIRE server | root-server |
internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.server.address |
Address for upstream Spire server | spire-server-a |
internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.server.port |
The port setting of the root SPIRE server | 8081 |
internal-spire-server-bottom-turtle-ha-a.bundleConfigMap |
The name of the configmap to store the downstream bundle | spire-server-a-bundle |
internal-spire-server-bottom-turtle-ha-a.trustSync.enabled |
Enable trust syncing | true |
internal-spire-server-bottom-turtle-ha-a.trustSync.domains |
the trust domains to sync | ["spire-ha"] |
Spire server parameters
| Name | Description | Value |
|---|---|---|
internal-spire-server-bottom-turtle-ha-b.nameOverride |
Overrides the name of Spire server pods | internal-server |
internal-spire-server-bottom-turtle-ha-b.caKeyType |
Key type to use for the ca | ec-p256 |
internal-spire-server-bottom-turtle-ha-b.experimental.enabled |
enable experimental features | true |
internal-spire-server-bottom-turtle-ha-b.experimental.agentSPIFFEIDAsSelector |
enable adding spiffe_id selectors to all agents | true |
internal-spire-server-bottom-turtle-ha-b.dynamicRegistration.enabled |
Enable dynamic registration | true |
internal-spire-server-bottom-turtle-ha-b.dynamicRegistration.allowedIDPrefix |
The allowed ID prefix | spire/agent/x509pop/k8s |
internal-spire-server-bottom-turtle-ha-b.dynamicRegistration.serviceAccount |
The service account to allow in for dynamic registration | spire-b-agent |
internal-spire-server-bottom-turtle-ha-b.controllerManager.enabled |
Enable controller manager and provision CRD's | true |
internal-spire-server-bottom-turtle-ha-b.controllerManager.parentIDTemplate |
parent id template | spiffe://{{ .TrustDomain }}/k8s_psat/{{ .ClusterName }}/{{ .NodeMeta.UID }} |
internal-spire-server-bottom-turtle-ha-b.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.autoPopulateDNSNames |
Auto populate dns entries | false |
internal-spire-server-bottom-turtle-ha-b.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.type |
The type of the entry | oidc-discovery-provider-common |
internal-spire-server-bottom-turtle-ha-b.controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.enabled |
Enables the spire-ha-agent identity | true |
internal-spire-server-bottom-turtle-ha-b.controllerManager.identities.clusterSPIFFEIDs.spire-identity-exchange-service.federatesWith |
List of trust domains to federate with | [] |
internal-spire-server-bottom-turtle-ha-b.persistence.type |
What type to use for peristence | emptyDir |
internal-spire-server-bottom-turtle-ha-b.nodeAttestor.k8sPSAT.enabled |
Enable the k8s projected access token node attestor | false |
internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.enabled |
Enable the x509 pop node attestor | true |
internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.spiffePrefix |
What prefix to use when mode is spiffe | /spire-exchange/k8s${HELM_ADD_CLUSTER_NAME}/ |
internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.agentPathTemplate |
Override the default agent path template | /{{ .PluginName }}/k8s${HELM_ADD_CLUSTER_NAME}/{{ .SVIDPathTrimmed }} |
internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.addClusterName.spiffePrefix |
Suffix the cluster name onto the spiffePrefix | true |
internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.addClusterName.agentPathTemplate |
Suffix the cluster name onto the agentPathTemplate | true |
internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.enabled |
Enable upstream SPIRE server | true |
internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.upstreamDriver |
Use an upstream driver for authentication | upstream-b.csi.spiffe.io |
internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.server.nameOverride |
The name override setting of the root SPIRE server | root-server |
internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.server.address |
Address for upstream Spire server | spire-server-b |
internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.server.port |
The port setting of the root SPIRE server | 8081 |
internal-spire-server-bottom-turtle-ha-b.bundleConfigMap |
The name of the configmap to store the downstream bundle | spire-server-b-bundle |
internal-spire-server-bottom-turtle-ha-b.trustSync.enabled |
Enable trust syncing | true |
internal-spire-server-bottom-turtle-ha-b.trustSync.domains |
the trust domains to sync | ["spire-ha"] |
downstream-spire-agent-bottom-turtle-ha-a.nameOverride |
Overrides the name of Spire agent pods | agent-downstream |
downstream-spire-agent-bottom-turtle-ha-a.server.nameOverride |
The name override setting of the internal SPIRE server | internal-server |
downstream-spire-agent-bottom-turtle-ha-a.bundleConfigMap |
The name of the configmap that contains the downstream bundle | spire-server-a-bundle |
downstream-spire-agent-bottom-turtle-ha-a.persistence.hostPath |
Which path to use on the host when persistence.type = hostPath | /var/lib/spire/k8s/downstream-agent-a |
downstream-spire-agent-bottom-turtle-ha-a.dynamicRegistration.enabled |
Enable dynamic registration | true |
downstream-spire-agent-bottom-turtle-ha-a.dynamicRegistration.nameOverride |
The name override to use to contact the server | internal-server |
downstream-spire-agent-bottom-turtle-ha-a.nodeAttestor.k8sPSAT.enabled |
Enable the k8s projected access token node attestor | false |
downstream-spire-agent-bottom-turtle-ha-a.nodeAttestor.x509POP.enabled |
Enable the x509 pop node attestor | true |
downstream-spire-agent-bottom-turtle-ha-a.nodeAttestor.x509POP.spiffeEndpointSocket |
Where the socket is to use for mode spiffe | /var/run/spiffe/socat/unix/k8s-spire-agent-a/public/api.sock |
downstream-spire-agent-bottom-turtle-ha-a.keyManager.memory.enabled |
Enable the memory based Key Manager | false |
downstream-spire-agent-bottom-turtle-ha-a.keyManager.disk.enabled |
Enable the disk key manager | true |
downstream-spire-agent-bottom-turtle-ha-a.keyManager.disk.mode |
Where the disk plugin will write out its data | emptyDir |
downstream-spire-agent-bottom-turtle-ha-a.healthChecks.port |
Health check port | 9981 |
downstream-spire-agent-bottom-turtle-ha-a.telemetry.prometheus.port |
Prometheus port to use | 9989 |
downstream-spire-agent-bottom-turtle-ha-a.socketPath |
Socket path to use | /var/run/spire/agent/sockets/a/csi.spiffe.io/public/spire-agent.sock |
downstream-spire-agent-bottom-turtle-ha-a.sockets.hostBasePath |
Path on the host to place sockets | /var/run/spire/agent/sockets/a |
downstream-spire-agent-bottom-turtle-ha-a.sockets.admin.enabled |
Enable admin socket | true |
downstream-spire-agent-bottom-turtle-ha-a.sockets.admin.mountOnHost |
Mount admin socket on host | true |
downstream-spire-agent-bottom-turtle-ha-a.authorizedDelegates |
List of workloads able to use the delegation api | ["/spire-ha-agent"] |
downstream-spire-agent-bottom-turtle-ha-a.brokerAPI.brokers.spire-ha-agent.enabled |
Enable the spire-ha-agent by default | true |
downstream-spire-agent-bottom-turtle-ha-a.workloadAttestors.k8s.brokerAPI.accessPolicy |
The default accessPolicy | permissive |
downstream-spire-agent-bottom-turtle-ha-a.workloadAttestors.k8s.brokerAPI.brokers.spire-ha-agent.enabled |
Enable the spire-ha-agent by default | true |
downstream-spire-agent-bottom-turtle-ha-b.nameOverride |
Overrides the name of Spire agent pods | agent-downstream |
downstream-spire-agent-bottom-turtle-ha-b.server.nameOverride |
The name override setting of the internal SPIRE server | internal-server |
downstream-spire-agent-bottom-turtle-ha-b.bundleConfigMap |
The name of the configmap that contains the downstream bundle | spire-server-b-bundle |
downstream-spire-agent-bottom-turtle-ha-b.persistence.hostPath |
Which path to use on the host when persistence.type = hostPath | /var/lib/spire/k8s/downstream-agent-b |
downstream-spire-agent-bottom-turtle-ha-b.dynamicRegistration.enabled |
Enable dynamic registration | true |
downstream-spire-agent-bottom-turtle-ha-b.dynamicRegistration.nameOverride |
The name override to use to contact the server | internal-server |
downstream-spire-agent-bottom-turtle-ha-b.nodeAttestor.k8sPSAT.enabled |
Enable the k8s projected access token node attestor | false |
downstream-spire-agent-bottom-turtle-ha-b.nodeAttestor.x509POP.enabled |
Enable the x509 pop node attestor | true |
downstream-spire-agent-bottom-turtle-ha-b.nodeAttestor.x509POP.spiffeEndpointSocket |
Where the socket is to use for mode spiffe | /var/run/spiffe/socat/unix/k8s-spire-agent-b/public/api.sock |
downstream-spire-agent-bottom-turtle-ha-b.keyManager.memory.enabled |
Enable the memory based Key Manager | false |
downstream-spire-agent-bottom-turtle-ha-b.keyManager.disk.enabled |
Enable the disk key manager | true |
downstream-spire-agent-bottom-turtle-ha-b.keyManager.disk.mode |
Where the disk plugin will write out its data | emptyDir |
downstream-spire-agent-bottom-turtle-ha-b.healthChecks.port |
Health check port | 9982 |
downstream-spire-agent-bottom-turtle-ha-b.telemetry.prometheus.port |
Prometheus port to use | 9990 |
downstream-spire-agent-bottom-turtle-ha-b.socketPath |
Socket path to use | /var/run/spire/agent/sockets/b/csi.spiffe.io/public/spire-agent.sock |
downstream-spire-agent-bottom-turtle-ha-b.sockets.hostBasePath |
Path on the host to place sockets | /var/run/spire/agent/sockets/b |
downstream-spire-agent-bottom-turtle-ha-b.sockets.admin.enabled |
Enable admin socket | true |
downstream-spire-agent-bottom-turtle-ha-b.sockets.admin.mountOnHost |
Mount admin socket on host | true |
downstream-spire-agent-bottom-turtle-ha-b.authorizedDelegates |
List of workloads able to use the delegation api | ["/spire-ha-agent"] |
downstream-spire-agent-bottom-turtle-ha-b.brokerAPI.brokers.spire-ha-agent.enabled |
Enable the spire-ha-agent by default | true |
downstream-spire-agent-bottom-turtle-ha-b.workloadAttestors.k8s.brokerAPI.accessPolicy |
The default accessPolicy | permissive |
downstream-spire-agent-bottom-turtle-ha-b.workloadAttestors.k8s.brokerAPI.brokers.spire-ha-agent.enabled |
Enable the spire-ha-agent by default | true |
downstream-spiffe-csi-driver-bottom-turtle-ha-a.fullnameOverride |
Fullname override | spiffe-csi-driver-downstream-a |
downstream-spiffe-csi-driver-bottom-turtle-ha-a.agentSocketPath |
path to agent socket | /var/run/spire/agent/sockets/a/csi.spiffe.io/public/spire-agent.sock |
downstream-spiffe-csi-driver-bottom-turtle-ha-a.pluginName |
The name of the plugin instance | a.csi.spiffe.io |
downstream-spiffe-csi-driver-bottom-turtle-ha-a.healthChecks.port |
The health check port | 9814 |
downstream-spiffe-csi-driver-bottom-turtle-ha-b.fullnameOverride |
Fullname override | spiffe-csi-driver-downstream-b |
downstream-spiffe-csi-driver-bottom-turtle-ha-b.agentSocketPath |
path to agent socket | /var/run/spire/agent/sockets/b/csi.spiffe.io/public/spire-agent.sock |
downstream-spiffe-csi-driver-bottom-turtle-ha-b.pluginName |
The name of the plugin instance | b.csi.spiffe.io |
downstream-spiffe-csi-driver-bottom-turtle-ha-b.healthChecks.port |
The health check port | 9816 |
spire-identity-exchange-bottom-turtle-ha-a.enabled |
Enable the spire-identity-exchange | false |
spire-identity-exchange-bottom-turtle-ha-a.nameOverride |
name override | identity-exchange |
spire-identity-exchange-bottom-turtle-ha-a.csiDriverName |
CSI driver name to use | a.csi.spiffe.io |
spire-identity-exchange-bottom-turtle-ha-a.tls.rest.ingress.host |
Hostname override for the rest ingress service | spire-identity-exchange-a-rest |
spire-identity-exchange-bottom-turtle-ha-a.tls.grpc.ingress.host |
Hostname override for the grpc ingress service | spire-identity-exchange-a-grpc |
spire-identity-exchange-bottom-turtle-ha-a.spiffe.rest.ingress.host |
Hostname override for the SVID-served rest ingress service | spire-identity-exchange-a-rest-spiffe |
spire-identity-exchange-bottom-turtle-ha-a.spiffe.grpc.ingress.host |
Hostname override for the SVID-served grpc ingress service | spire-identity-exchange-a-grpc-spiffe |
spire-identity-exchange-bottom-turtle-ha-a.server.nameOverride |
The name override setting of the internal SPIRE server | internal-server |
spire-identity-exchange-bottom-turtle-ha-a.auth.plugins.spiffe.csiDriverName |
The csi driver the spiffe plugin reads its trust bundle from. The shared ha-agent, since that is what mints the oidc discovery provider's serving svid. | csi.spiffe.io |
spire-identity-exchange-bottom-turtle-ha-a.auth.plugins.spiffe.config.discoveryURL |
The OIDC discovery provider to fetch keys from. This chart gives it a fullnameOverride, so the keySource convention does not apply. | https://spiffe-oidc-discovery-provider |
spire-identity-exchange-bottom-turtle-ha-b.enabled |
Enable the spire-identity-exchange | false |
spire-identity-exchange-bottom-turtle-ha-b.nameOverride |
name override | identity-exchange |
spire-identity-exchange-bottom-turtle-ha-b.csiDriverName |
CSI driver name to use | b.csi.spiffe.io |
spire-identity-exchange-bottom-turtle-ha-b.server.nameOverride |
The name override setting of the internal SPIRE server | internal-server |
spire-identity-exchange-bottom-turtle-ha-b.tls.rest.ingress.host |
Hostname override for the rest ingress service | spire-identity-exchange-b-rest |
spire-identity-exchange-bottom-turtle-ha-b.tls.grpc.ingress.host |
Hostname override for the grpc ingress service | spire-identity-exchange-b-grpc |
spire-identity-exchange-bottom-turtle-ha-b.spiffe.rest.ingress.host |
Hostname override for the SVID-served rest ingress service | spire-identity-exchange-b-rest-spiffe |
spire-identity-exchange-bottom-turtle-ha-b.spiffe.grpc.ingress.host |
Hostname override for the SVID-served grpc ingress service | spire-identity-exchange-b-grpc-spiffe |
spire-identity-exchange-bottom-turtle-ha-b.auth.plugins.spiffe.csiDriverName |
The csi driver the spiffe plugin reads its trust bundle from. The shared ha-agent, since that is what mints the oidc discovery provider's serving svid. | csi.spiffe.io |
spire-identity-exchange-bottom-turtle-ha-b.auth.plugins.spiffe.config.discoveryURL |
The OIDC discovery provider to fetch keys from. This chart gives it a fullnameOverride, so the keySource convention does not apply. | https://spiffe-oidc-discovery-provider |