Files
helm-charts-hardened/charts/spiffe-step-ssh/templates/fetchca-deployment.yaml
T
kfox1111andFaisal Memon ec7259699f spiffe-step-ssh server (#198)
* Initial prototype of spire-step-ssh integration

Signed-off-by: Kevin Fox <[email protected]>

* Ingress work, image cleanup and misc cleanup

Signed-off-by: Kevin Fox <[email protected]>

* More values rework

Signed-off-by: Kevin Fox <[email protected]>

* Rename chart spiffe-step-ssh

Signed-off-by: Kevin Fox <[email protected]>

* Update to use shared lib

Signed-off-by: Kevin Fox <[email protected]>

* Update spiffe-helper

Signed-off-by: Kevin Fox <[email protected]>

* Use URLSAN rather then CN

Signed-off-by: Kevin Fox <[email protected]>

* Lookup the sans.

Signed-off-by: Kevin Fox <[email protected]>

* Make trust domain configurable

Signed-off-by: Kevin Fox <[email protected]>

* Add flag

Signed-off-by: Kevin Fox <[email protected]>

* Make driver configurable

Signed-off-by: Kevin Fox <[email protected]>

* Add more configurables. Fix up docs to pass test.

Signed-off-by: Kevin Fox <[email protected]>

* Add some metadata

Signed-off-by: Kevin Fox <[email protected]>

* Fix metadata

Signed-off-by: Kevin Fox <[email protected]>

* Add default values for lint

Signed-off-by: Kevin Fox <[email protected]>

* Forgot values updates

Signed-off-by: Kevin Fox <[email protected]>

* Fix metadata

Signed-off-by: Kevin Fox <[email protected]>

* Start working on integration test

Signed-off-by: Kevin Fox <[email protected]>

* Test

Signed-off-by: Kevin Fox <[email protected]>

* Test

Signed-off-by: Kevin Fox <[email protected]>

* Fix names

Signed-off-by: Kevin Fox <[email protected]>

* More test bits

Signed-off-by: Kevin Fox <[email protected]>

* More test bits

Signed-off-by: Kevin Fox <[email protected]>

* More test bits

Signed-off-by: Kevin Fox <[email protected]>

* More test bits

Signed-off-by: Kevin Fox <[email protected]>

* More test bits

Signed-off-by: Kevin Fox <[email protected]>

* More test bits

Signed-off-by: Kevin Fox <[email protected]>

* More fixes

Signed-off-by: Kevin Fox <[email protected]>

* More fixes

Signed-off-by: Kevin Fox <[email protected]>

* More fixes

Signed-off-by: Kevin Fox <[email protected]>

* Fix name conflict. Align naming

Signed-off-by: Kevin Fox <[email protected]>

* Fix name

Signed-off-by: Kevin Fox <[email protected]>

* Add more logging

Signed-off-by: Kevin Fox <[email protected]>

* Disable unneeded test. Add missing file.

Signed-off-by: Kevin Fox <[email protected]>

* Setup more things

Signed-off-by: Kevin Fox <[email protected]>

* Add missing conf file

Signed-off-by: Kevin Fox <[email protected]>

* Fix multiple svids

Signed-off-by: Kevin Fox <[email protected]>

* Fix ci defaults

Signed-off-by: Kevin Fox <[email protected]>

* Fix filename

Signed-off-by: Kevin Fox <[email protected]>

* Try and get the linter to stop complaining...

Signed-off-by: Kevin Fox <[email protected]>

* Fix perms

Signed-off-by: Kevin Fox <[email protected]>

* More logs

Signed-off-by: Kevin Fox <[email protected]>

* More setup

Signed-off-by: Kevin Fox <[email protected]>

* Fixes

Signed-off-by: Kevin Fox <[email protected]>

* Fixes

Signed-off-by: Kevin Fox <[email protected]>

* Add wait

Signed-off-by: Kevin Fox <[email protected]>

* More logging

Signed-off-by: Kevin Fox <[email protected]>

* Test ssh

Signed-off-by: Kevin Fox <[email protected]>

* Restart fetchca on updates too

Signed-off-by: Kevin Fox <[email protected]>

* Fix formating

Signed-off-by: Kevin Fox <[email protected]>

* Add missing file flag

Signed-off-by: Kevin Fox <[email protected]>

* Increase timeout

Signed-off-by: Kevin Fox <[email protected]>

* More flags

Signed-off-by: Kevin Fox <[email protected]>

* Fix name

Signed-off-by: Kevin Fox <[email protected]>

* Finish end to end test

Signed-off-by: Kevin Fox <[email protected]>

* Fix ingress setting

Signed-off-by: Kevin Fox <[email protected]>

* More logging/tests

Signed-off-by: Kevin Fox <[email protected]>

* More testing

Signed-off-by: Kevin Fox <[email protected]>

* Fix namespace

Signed-off-by: Kevin Fox <[email protected]>

* Fetch correct bundle

Signed-off-by: Kevin Fox <[email protected]>

* Chart testing will fail as it depends on spire to be preinstalled. Weird dependency loop.

Signed-off-by: Kevin Fox <[email protected]>

* Dont skip tls for testing

Signed-off-by: Kevin Fox <[email protected]>

* More logging

Signed-off-by: Kevin Fox <[email protected]>

* More debug

Signed-off-by: Kevin Fox <[email protected]>

* More debug

Signed-off-by: Kevin Fox <[email protected]>

* Pass intermediates

Signed-off-by: Kevin Fox <[email protected]>

* Fix trustdomain

Signed-off-by: Kevin Fox <[email protected]>

* Add ca authority prefix

Signed-off-by: Kevin Fox <[email protected]>

* fix

Signed-off-by: Kevin Fox <[email protected]>

* fix

Signed-off-by: Kevin Fox <[email protected]>

* fix

Signed-off-by: Kevin Fox <[email protected]>

* ci test is just broken. Revert trying to fix it.

Signed-off-by: Kevin Fox <[email protected]>

* Update charts/spiffe-step-ssh/files/ssh_x5c.tpl

Signed-off-by: kfox1111 <[email protected]>

* Self review feedback

Signed-off-by: Kevin Fox <[email protected]>

* Switch ingress to our more functional/easy type

Signed-off-by: Kevin Fox <[email protected]>

* Simplify the template

Signed-off-by: Kevin Fox <[email protected]>

* Add cast

Signed-off-by: Kevin Fox <[email protected]>

* Add install notes

Signed-off-by: Kevin Fox <[email protected]>

* Fix test

Signed-off-by: Kevin Fox <[email protected]>

* Update tests for updated client

Signed-off-by: Kevin Fox <[email protected]>

* Fix logging and entry

Signed-off-by: Kevin Fox <[email protected]>

* Add missing dir

Signed-off-by: Kevin Fox <[email protected]>

* Fix file location

Signed-off-by: Kevin Fox <[email protected]>

* Update timeout

Signed-off-by: Kevin Fox <[email protected]>

* More logging

Signed-off-by: Kevin Fox <[email protected]>

* Fix filename

Signed-off-by: Kevin Fox <[email protected]>

* Fix perms

Signed-off-by: Kevin Fox <[email protected]>

* Update charts/spiffe-step-ssh/README.md

Signed-off-by: kfox1111 <[email protected]>

* Apply suggestions from code review

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>

---------

Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
2024-11-07 23:43:26 -08:00

183 lines
5.9 KiB
YAML

apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "spiffe-step-ssh.fullname" . }}-fetchca
labels:
{{- include "spiffe-step-ssh.labels" . | nindent 4 }}
app: spiffe-step-ssh
component: fetchca
spec:
{{- if not .Values.fetchCA.autoscaling.enabled }}
replicas: {{ .Values.fetchCA.replicaCount }}
{{- end }}
selector:
matchLabels:
{{- include "spiffe-step-ssh.selectorLabels" . | nindent 6 }}
app: spiffe-step-ssh
component: fetchca
template:
metadata:
{{- with .Values.podAnnotations }}
annotations:
{{- toYaml . | nindent 8 }}
{{- end }}
labels:
{{- include "spiffe-step-ssh.labels" . | nindent 8 }}
{{- with .Values.podLabels }}
{{- toYaml . | nindent 8 }}
{{- end }}
app: spiffe-step-ssh
component: fetchca
spec:
shareProcessNamespace: true
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
serviceAccountName: {{ include "spiffe-step-ssh.serviceAccountName" . }}-fetchca
securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }}
initContainers:
- name: busybox-volume
image: {{ template "spire-lib.image" (dict "image" .Values.busybox.image "global" .Values.global) }}
imagePullPolicy: {{ .Values.busybox.image.pullPolicy }}
command:
- sh
- -c
- 'cp -a /bin/busybox /busybox'
volumeMounts:
- name: busybox
mountPath: /busybox
resources:
{{- toYaml .Values.fetchCA.spiffeHelper.resources | nindent 12 }}
- name: init-tls
image: {{ template "spire-lib.image" (dict "image" .Values.spiffeHelper.image "global" .Values.global) }}
imagePullPolicy: {{ .Values.spiffeHelper.image.pullPolicy }}
command:
- /spiffe-helper
- -config
- /etc/spiffe-helper.conf
- -daemon-mode=false
volumeMounts:
- name: spiffe-workload-api
mountPath: /spiffe-workload-api
readOnly: true
- name: config
mountPath: /etc/spiffe-helper.conf
subPath: spiffe-helper-init.conf
readOnly: true
- name: certs
mountPath: /certs
resources:
{{- toYaml .Values.fetchCA.spiffeHelper.resources | nindent 12 }}
containers:
- name: {{ .Chart.Name }}-fetchca
securityContext:
{{- toYaml .Values.securityContext | nindent 12 }}
image: {{ template "spire-lib.image" (dict "image" .Values.nginx.image "global" .Values.global) }}
imagePullPolicy: {{ .Values.nginx.image.pullPolicy }}
command:
- /bin/sh
- -c
- |
echo $$$$ > /pid/pid
cat > /etc/nginx/conf.d/ssl.conf <<EOF
server {
listen 8443 ssl;
server_name localhost;
ssl_certificate /certs/tls.crt;
ssl_certificate_key /certs/tls.key;
location / {
root /usr/share/nginx/html;
index root_ca.crt index.html index.htm;
}
error_page 500 502 503 504 /50x.html;
location = /50x.html {
root /usr/share/nginx/html;
}
}
EOF
exec nginx -g "daemon off;"
ports:
- name: http
containerPort: 8443
protocol: TCP
livenessProbe:
httpGet:
path: /
port: http
scheme: HTTPS
readinessProbe:
httpGet:
path: /
port: http
scheme: HTTPS
resources:
{{- toYaml .Values.fetchCA.resources | nindent 12 }}
volumeMounts:
- name: certs
mountPath: /certs
readOnly: true
- name: pid
mountPath: /pid
- name: share
mountPath: /usr/share/nginx/html
- name: update-tls
image: {{ template "spire-lib.image" (dict "image" .Values.spiffeHelper.image "global" .Values.global) }}
imagePullPolicy: {{ .Values.spiffeHelper.image.pullPolicy }}
command:
- /spiffe-helper
- -config
- /etc/spiffe-helper.conf
volumeMounts:
- name: certs
mountPath: /certs
- name: spiffe-workload-api
mountPath: /spiffe-workload-api
readOnly: true
- name: config
mountPath: /etc/spiffe-helper.conf
subPath: spiffe-helper-sidecar.conf
readOnly: true
- name: config
mountPath: /update.sh
subPath: update.sh
readOnly: true
- name: pid
mountPath: /pid
readOnly: true
- name: busybox
mountPath: /busybox
readOnly: true
resources:
{{- toYaml .Values.fetchCA.spiffeHelper.resources | nindent 12 }}
volumes:
- name: certs
emptyDir: {}
- name: pid
emptyDir: {}
- name: busybox
emptyDir: {}
- name: config
configMap:
name: {{ include "spiffe-step-ssh.fullname" . }}-fetchca
- name: spiffe-workload-api
csi:
driver: {{ .Values.csiDriver | quote }}
readOnly: true
- name: share
configMap:
name: {{ include "spiffe-step-ssh.fullname" . }}-certs
{{- with .Values.fetchCA.nodeSelector }}
nodeSelector:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.fetchCA.affinity }}
affinity:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.fetchCA.tolerations }}
tolerations:
{{- toYaml . | nindent 8 }}
{{- end }}