Files
helm-charts-hardened/charts/spire-nested
kfox1111 e44f006dde Experimental support for spire-identity-exchange (#860)
* Experimental support for spire-identity-exchange

Signed-off-by: Kevin Fox <[email protected]>

* Fix image name

Signed-off-by: Kevin Fox <[email protected]>

* Fix flags

Signed-off-by: Kevin Fox <[email protected]>

* Fix ghosted section

Signed-off-by: Kevin Fox <[email protected]>

* Fix working dir

Signed-off-by: Kevin Fox <[email protected]>

* Fix working dir

Signed-off-by: Kevin Fox <[email protected]>

* Fix working dir

Signed-off-by: Kevin Fox <[email protected]>

* Fix working dir

Signed-off-by: Kevin Fox <[email protected]>

* Fix working dir

Signed-off-by: Kevin Fox <[email protected]>

* Fix working dir

Signed-off-by: Kevin Fox <[email protected]>

* Add some missing bits

Signed-off-by: Kevin Fox <[email protected]>

* Some more implementation

Signed-off-by: Kevin Fox <[email protected]>

* Update tests

Signed-off-by: Kevin Fox <[email protected]>

* Add ci

Signed-off-by: Kevin Fox <[email protected]>

* Fix ci

Signed-off-by: Kevin Fox <[email protected]>

* Fix ci

Signed-off-by: Kevin Fox <[email protected]>

* Fix ci

Signed-off-by: Kevin Fox <[email protected]>

* Fix ci

Signed-off-by: Kevin Fox <[email protected]>

* Fix ci

Signed-off-by: Kevin Fox <[email protected]>

* Fix ci

Signed-off-by: Kevin Fox <[email protected]>

* Fix ci

Signed-off-by: Kevin Fox <[email protected]>

* Fix ci

Signed-off-by: Kevin Fox <[email protected]>

* Rework x509pop to work shared

Signed-off-by: Kevin Fox <[email protected]>

* Rework x509pop to work shared

Signed-off-by: Kevin Fox <[email protected]>

* Fix docs

Signed-off-by: Kevin Fox <[email protected]>

* Fix docs

Signed-off-by: Kevin Fox <[email protected]>

* Fix

Signed-off-by: Kevin Fox <[email protected]>

* Fix

Signed-off-by: Kevin Fox <[email protected]>

* Fix path

Signed-off-by: Kevin Fox <[email protected]>

* Fix path

Signed-off-by: Kevin Fox <[email protected]>

* Fix docs

Signed-off-by: Kevin Fox <[email protected]>

* Fixes

Signed-off-by: Kevin Fox <[email protected]>

* Fixes

Signed-off-by: Kevin Fox <[email protected]>

* Fixes

Signed-off-by: Kevin Fox <[email protected]>

* Fixes

Signed-off-by: Kevin Fox <[email protected]>

* Fix static entry

Signed-off-by: Kevin Fox <[email protected]>

* Cleanup

Signed-off-by: Kevin Fox <[email protected]>

* Remove unused change

Signed-off-by: Kevin Fox <[email protected]>

* Update spire-identity-exchange. Start to test.

Signed-off-by: Kevin Fox <[email protected]>

* fixes

Signed-off-by: Kevin Fox <[email protected]>

* Update lock

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Update

Signed-off-by: Kevin Fox <[email protected]>

* Fix broken test. Correct default dns names.

Signed-off-by: Kevin Fox <[email protected]>

* Fix merge issue

Signed-off-by: Kevin Fox <[email protected]>

* Incorperate feedback

Signed-off-by: Kevin Fox <[email protected]>

---------

Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
2026-07-05 07:49:12 -07:00
..
2024-05-20 08:58:22 -07:00
2024-05-20 08:58:22 -07:00
2024-05-20 08:58:22 -07:00

spire

Version: 0.28.5 Type: application AppVersion: 1.15.1 Development Phase

A Helm chart for deploying the complete Spire stack including: spire-server, spire-agent, spiffe-csi-driver, spiffe-oidc-discovery-provider and spire-controller-manager.

Homepage: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire

Install Instructions

Non Production

To do a quick install suitable for testing in something like minikube:

helm upgrade --install -n spire-server spire-crds spire-crds --repo https://spiffe.github.io/helm-charts-hardened/ --create-namespace
helm upgrade --install -n spire-server spire spire-nested --repo https://spiffe.github.io/helm-charts-hardened/

Production

Preparing a production deployment requires a few steps.

  1. Save the following to your-values.yaml, ideally in your git repo.
global:
  openshift: false # If running on openshift, set to true
  spire:
    recommendations:
      enabled: true
    namespaces:
      create: true
    ingressControllerType: "" # If not openshift, and want to expose services, set to a supported option [ingress-nginx]
    # Update these
    clusterName: example-cluster
    trustDomain: example.org
    caSubject:
      country: ARPA
      organization: Example
      commonName: example.org
  1. If you need a non default storageClass, append the following to the spire-server section and update:
  persistence:
    storageClass: your-storage-class
  1. If your Kubernetes cluster is OpenShift based, use the output of the following command to update the trustDomain setting:
oc get cm -n openshift-config-managed  console-public -o go-template="{{ .data.consoleURL }}" | sed 's@https://@@; s/^[^.]*\.//'
  1. Find any additional values you might want to set based on the documentation below or using the examples

In particular, consider using an external database.

  1. Deploy
helm upgrade --install -n spire-mgmt spire-crds spire-crds --repo https://spiffe.github.io/helm-charts-hardened/ --create-namespace
helm upgrade --install -n spire-mgmt spire spire-nested --repo https://spiffe.github.io/helm-charts-hardened/ -f your-values.yaml

Clean up

helm -n spire-mgmt uninstall spire-crds
helm -n spire-mgmt uninstall spire
kubectl -n spire-server delete pvc -l app.kubernetes.io/instance=spire
kubectl delete crds clusterfederatedtrustdomains.spire.spiffe.io clusterspiffeids.spire.spiffe.io clusterstaticentries.spire.spiffe.io

Upgrade notes

We only support upgrading one major version at a time. Version skipping isn't supported.

0.17.X

  • If you set spire-server.replicaCount > 1, update it to 1 before upgrading and after upgrade you can set it back to its previous value.

  • The SPIFFE OIDC Discovery Provider now has many new TLS options and defaults to using SPIRE to issue its certificate.

  • The spiffe-oidc-discovery-provider.insecureScheme.enabled flag was removed. If you previously set that flag, remove the setting from your values.yaml and see if the new default of using a SPIRE issued certificate is suitable for your deployment. If it isn't, please consider one of the other options under spiffe-oidc-discovery-provider.tls. If all other options are still unsuitable, you can still enable the previous mode by disabling TLS. (spiffe-oidc-discovery-provider.tls.spire.enabled=false)

  • The SPIFFE OIDC Discovery Provider is now enabled by default. If you previously chose to have it off, you can disable it explicitly with spiffe-oidc-discovery-provider.enabled=false.

0.16.X

The settings under "spire-server.controllerManager.identities" have all been moved under "spire-server.controllerManager.identities.clusterSPIFFEIDs.default". If you have changed any from the defaults, please update them to the new location during upgrade.

0.15.X

The spire-crds chart has been updated. Please ensure you have upgraded spire-crds before upgrading the spire chart.

The chart now supports multiple parallel installs of spire-controller-manager. Each install will handle all custom resources with a matching className field. By default this is set to Release.Namespace-Release.Name and the controller manager will only pick up custom resources with this className.

If you have not loaded any SPIRE custom resources yourself, the upgrade process will be transparent. If you have loaded your own SPIRE custom resources, set spire-server.controllerManager.watchClassless=true until you can update your SPIRE custom resources to have the className for the instance specified.

0.14.X

If coming from a chart version before 0.14.0, you must relabel your crds to switch to using the new spire-crds chart. To migrate to the spire-crds chart run the following:

Replace the spire-server namespace in the commands below with the namespace you want to install the spire-crds chart in.

kubectl label crd "clusterfederatedtrustdomains.spire.spiffe.io" "app.kubernetes.io/managed-by=Helm"
kubectl annotate crd "clusterfederatedtrustdomains.spire.spiffe.io" "meta.helm.sh/release-name=spire-crds"
kubectl annotate crd "clusterfederatedtrustdomains.spire.spiffe.io" "meta.helm.sh/release-namespace=spire-server"
kubectl label crd "clusterspiffeids.spire.spiffe.io" "app.kubernetes.io/managed-by=Helm"
kubectl annotate crd "clusterspiffeids.spire.spiffe.io" "meta.helm.sh/release-name=spire-crds"
kubectl annotate crd "clusterspiffeids.spire.spiffe.io" "meta.helm.sh/release-namespace=spire-server"
kubectl label crd "controllermanagerconfigs.spire.spiffe.io" "app.kubernetes.io/managed-by=Helm"
kubectl annotate crd "controllermanagerconfigs.spire.spiffe.io" "meta.helm.sh/release-name=spire-crds"
kubectl annotate crd "controllermanagerconfigs.spire.spiffe.io" "meta.helm.sh/release-namespace=spire-server"
helm install -n spire-server spire-crds charts/spire-crds

Version support

Warning

This Chart is still in development and still subject to change the API (values.yaml). Until we reach a 1.0.0 version of the chart we can't guarantee backwards compatibility although we do aim for as much stability as possible.

Dependency Supported Versions
Helm 3.x
Kubernetes 1.22+

Note

For Kubernetes, we will officially support the last 3 versions as described in k8s versioning. Any version before the last 3 we will try to support as long it doesn't bring security issues or any big maintenance burden.

FAQ

For any issues see our FAQ…

Usage

To utilize Spire in your own workloads you should add the following to your workload:

 apiVersion: v1
 kind: Pod
 metadata:
   name: my-app
 spec:
   containers:
     - name: my-app
       image: "my-app:latest"
       imagePullPolicy: Always
+      volumeMounts:
+        - name: spiffe-workload-api
+          mountPath: /spiffe-workload-api
+          readOnly: true
       resources:
         requests:
           cpu: 200m
           memory: 32Mi
         limits:
           cpu: 500m
           memory: 64Mi
+  volumes:
+    - name: spiffe-workload-api
+      csi:
+        driver: "csi.spiffe.io"
+        readOnly: true

Now you can interact with the Spire agent socket from your own application. The socket is mounted on /spiffe-workload-api/spire-agent.sock.

Maintainers

Name Email Url
marcofranssen [email protected] https://marcofranssen.nl
kfox1111 [email protected]
faisal-memon [email protected]
edwbuck [email protected]

Source Code

Requirements

Repository Name Version
file://./charts/spiffe-csi-driver spiffe-csi-driver 0.1.0
file://./charts/spiffe-csi-driver upstream-spiffe-csi-driver(spiffe-csi-driver) 0.1.0
file://./charts/spiffe-oidc-discovery-provider spiffe-oidc-discovery-provider 0.1.0
file://./charts/spire-agent spire-agent 0.1.0
file://./charts/spire-agent upstream-spire-agent(spire-agent) 0.1.0
file://./charts/spire-server spire-server 0.1.0
file://./charts/tornjak-frontend tornjak-frontend 0.1.0

Parameters

Global parameters

Name Description Value
global.k8s.clusterDomain Cluster domain name configured for Spire install cluster.local
global.spire.clusterName The name of the k8s cluster for Spire install example-cluster
global.spire.jwtIssuer The issuer for Spire JWT tokens. Defaults to oidc-discovery.$trustDomain if unset ""
global.spire.trustDomain The trust domain for Spire install example.org
global.spire.caSubject.country Country for Spire server CA ""
global.spire.caSubject.organization Organization for Spire server CA ""
global.spire.caSubject.commonName Common Name for Spire server CA ""
global.spire.recommendations.enabled Use recommended settings for production deployments. Default is off. false
global.spire.recommendations.namespaceLayout Set to true to use recommended values for installing across namespaces true
global.spire.recommendations.namespacePSS When chart namespace creation is enabled, label them with preffered Pod Security Standard labels true
global.spire.recommendations.priorityClassName Set to true to use recommended values for Pod Priority Class Names true
global.spire.recommendations.strictMode Check values, such as trustDomain, are overridden with a suitable value for production. true
global.spire.recommendations.securityContexts Set to true to use recommended values for Pod and Container Security Contexts true
global.spire.recommendations.prometheus Enable prometheus exporters for monitoring true
global.spire.image.registry Override all Spire image registries at once ""
global.spire.namespaces.create Set to true to Create all namespaces. If this or either of the namespace specific create flags is set, the namespace will be created. false
global.spire.namespaces.system.name Name of the Spire system Namespace. spire-system
global.spire.namespaces.system.create Create a Namespace for Spire system resources. false
global.spire.namespaces.system.annotations Annotations to apply to the Spire system Namespace. {}
global.spire.namespaces.system.labels Labels to apply to the Spire system Namespace. {}
global.spire.namespaces.server.name Name of the Spire server Namespace. spire-server
global.spire.namespaces.server.create Create a Namespace for Spire server resources. false
global.spire.namespaces.server.annotations Annotations to apply to the Spire server Namespace. {}
global.spire.namespaces.server.labels Labels to apply to the Spire server Namespace. {}
global.spire.strictMode Check values, such as trustDomain, are overridden with a suitable value for production. false
global.spire.ingressControllerType Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, autodetection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. ""
global.spire.tools.kubectl.tag Set to force the tag to use for all kubectl instances ""
global.installAndUpgradeHooks.enabled Enable Helm hooks to autofix common install/upgrade issues (should be disabled when using helm template) true
global.deleteHooks.enabled Enable Helm hooks to autofix common delete issues (should be disabled when using helm template) true
tags.nestedRoot Set the chart architecture to root nested false
tags.nestedChildFull Set the chart mode to a child cluster with its own nested server false
tags.nestedChildSecurity Set the chart mode to a child cluster for use with a security cluster false
tags.haAgentCommon Set the chart mode to deploy the common portion of a spire-ha-agent setup false
tags.bottomTurtleHAA Setup HA side A for use with a Bottom Turtle architecture false
tags.bottomTurtleHAB Setup HA side B for use with a Bottom Turtle architecture false

Spire agent parameters

Name Description Value
downstream-spire-agent-full.nameOverride Overrides the name of Spire agent pods agent-downstream
downstream-spire-agent-full.server.nameOverride The name override setting of the internal SPIRE server internal-server
downstream-spire-agent-full.bundleConfigMap The name of the configmap that contains the downstream bundle spire-bundle-downstream
downstream-spire-agent-full.persistence.hostPath Which path to use on the host when persistence.type = hostPath /var/lib/spire/k8s/downstream-agent

Spire agent parameters

Name Description Value
downstream-spire-agent-security.nameOverride Overrides the name of Spire agent pods agent-downstream
downstream-spire-agent-security.bundleConfigMap The name of the configmap that contains the downstream bundle spire-bundle-upstream
downstream-spire-agent-security.serviceAccount.name The name of the service account to use spire-agent-upstream
downstream-spire-agent-security.persistence.hostPath Which path to use on the host when persistence.type = hostPath /var/lib/spire/k8s/downstream-agent

Upstream Spire agent parameters

Name Description Value
upstream-spire-agent.upstream Flag for enabling upstream Spire agent true
upstream-spire-agent.nameOverride Name override for upstream Spire agent agent-upstream
upstream-spire-agent.bundleConfigMap The configmap name for upstream Spire agent bundle spire-bundle-upstream
upstream-spire-agent.socketPath Socket path where Spire agent socket is mounted /run/spire/agent-sockets-upstream/spire-agent.sock
upstream-spire-agent.serviceAccount.name Service account name for upstream Spire agent spire-agent-upstream
upstream-spire-agent.healthChecks.port Health check port number for upstream Spire agent 9981
upstream-spire-agent.telemetry.prometheus.port The port where prometheus metrics are available 9989
upstream-spire-agent.server.nameOverride The name override setting of the root SPIRE server root-server
upstream-spire-agent.persistence.hostPath Which path to use on the host when persistence.type = hostPath /var/lib/spire/k8s/upstream-agent

SPIFFE CSI Driver parameters

Name Description Value
downstream-spiffe-csi-driver.fullnameOverride Fullname override spiffe-csi-driver-downstream

Upstream SPIFFE CSI Driver parameters

Name Description Value
upstream-spiffe-csi-driver.fullnameOverride Fullname override spiffe-csi-driver-upstream
upstream-spiffe-csi-driver.pluginName The plugin name for configuring upstream Spiffe CSI driver upstream.csi.spiffe.io
upstream-spiffe-csi-driver.agentSocketPath The socket path where Spiffe CSI driver mounts agent socket /run/spire/agent-sockets-upstream/spire-agent.sock
upstream-spiffe-csi-driver.healthChecks.port The port where Spiffe CSI driver health checks are exposed 9810

SPIFFE oidc discovery provider parameters

Name Description Value
spiffe-oidc-discovery-provider.fullnameOverride Fullname override spiffe-oidc-discovery-provider

Tornjak frontend parameters

Name Description Value
tornjak-frontend.enabled Enables deployment of Tornjak frontend/UI (Not for production) false
root-spire-server.nameOverride Name override root-server
root-spire-server.crNameOverride Custom Resource name override root
root-spire-server.controllerManager.enabled Enable controller manager and provision CRD's true
root-spire-server.controllerManager.externalControllerManagers.enabled Flag to enable external controller managers true
root-spire-server.controllerManager.validatingWebhookConfiguration.enabled Disable only when you have another instance on the k8s cluster with webhooks enabled. false
root-spire-server.controllerManager.className specify to use an explicit class name. spire-mgmt-root-server
root-spire-server.controllerManager.identities.clusterSPIFFEIDs.child-servers.enabled Enable child servers true
root-spire-server.controllerManager.identities.clusterSPIFFEIDs.default.enabled Enable the default cluster spiffe id false
root-spire-server.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.enabled Enable the test-keys identity false
root-spire-server.controllerManager.identities.clusterSPIFFEIDs.test-keys.enabled Enable the test-keys identity false
root-spire-server.externalControllerManagers.enabled Flag to enable external controller managers true
root-spire-server.nodeAttestor.k8sPSAT.serviceAccountAllowList Allowed service accounts for PSAT nodeattestor []
root-spire-server.bundleConfigMap The name of the configmap to store the upstream bundle spire-bundle-upstream
external-root-spire-server-full.externalServer Set to true to setup the bundle configmap, rbac rules, and identity documents but doesn't deploy the server locally. Useful for external servers. true
external-root-spire-server-full.nameOverride Name override root-server
external-root-spire-server-full.crNameOverride Custom Resource name override root
external-root-spire-server-full.controllerManager.enabled Enable controller manager and provision CRD's true
external-root-spire-server-full.controllerManager.validatingWebhookConfiguration.enabled Disable only when you have another instance on the k8s cluster with webhooks enabled. false
external-root-spire-server-full.controllerManager.className specify to use an explicit class name. spire-mgmt-external-server
external-root-spire-server-full.controllerManager.identities.clusterSPIFFEIDs.child-servers.enabled Enable child servers true
external-root-spire-server-full.controllerManager.identities.clusterSPIFFEIDs.child-servers.labels Default label spire.spiffe.io/child-server is set to enable label-based informer filtering on the root cluster's external controller manager. {}
external-root-spire-server-full.controllerManager.identities.clusterSPIFFEIDs.default.enabled Enable the default cluster spiffe id false
external-root-spire-server-full.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.enabled Enable the test-keys identity false
external-root-spire-server-full.controllerManager.identities.clusterSPIFFEIDs.test-keys.enabled Enable the test-keys identity false
external-root-spire-server-full.nodeAttestor.k8sPSAT.serviceAccountAllowList Allowed service accounts for PSAT nodeattestor []
external-root-spire-server-full.bundleConfigMap The name of the configmap to store the upstream bundle spire-bundle-upstream
external-root-spire-server-security.externalServer Set to true to setup the bundle configmap, rbac rules, and identity documents but doesn't deploy the server locally. Useful for external servers. true
external-root-spire-server-security.nameOverride Name override root-server
external-root-spire-server-security.crNameOverride Custom Resource name override root
external-root-spire-server-security.controllerManager.enabled Enable controller manager and provision CRD's true
external-root-spire-server-security.controllerManager.validatingWebhookConfiguration.enabled Disable only when you have another instance on the k8s cluster with webhooks enabled. false
external-root-spire-server-security.controllerManager.className specify to use an explicit class name. spire-mgmt-external-server
external-root-spire-server-security.nodeAttestor.k8sPSAT.serviceAccountAllowList Allowed service accounts for PSAT nodeattestor []
external-root-spire-server-security.bundleConfigMap The name of the configmap to store the upstream bundle spire-bundle-upstream

Spire server parameters

Name Description Value
internal-spire-server.nameOverride Overrides the name of Spire server pods internal-server
internal-spire-server.controllerManager.enabled Enable controller manager and provision CRD's true
internal-spire-server.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.autoPopulateDNSNames Auto populate dns entries false
internal-spire-server.externalControllerManagers.enabled Flag to enable external controller managers true
internal-spire-server.upstreamAuthority.spire.enabled Enable upstream SPIRE server true
internal-spire-server.upstreamAuthority.spire.upstreamDriver Use an upstream driver for authentication upstream.csi.spiffe.io
internal-spire-server.upstreamAuthority.spire.server.nameOverride The name override setting of the root SPIRE server root-server
internal-spire-server.bundleConfigMap The name of the configmap to store the downstream bundle spire-bundle-downstream
external-spire-server.nameOverride Overrides the name of Spire server pods external-server
external-spire-server.crNameOverride Custom Resource name override external
external-spire-server.controllerManager.enabled Enable controller manager and provision CRD's true
external-spire-server.controllerManager.validatingWebhookConfiguration.enabled Disable only when you have another instance on the k8s cluster with webhooks enabled. false
external-spire-server.controllerManager.className specify to use an explicit class name. spire-mgmt-external-server
external-spire-server.controllerManager.identities.clusterSPIFFEIDs.default.enabled Enable the default identity false
external-spire-server.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.enabled Enable the oidc-discovery-provider identity false
external-spire-server.controllerManager.identities.clusterSPIFFEIDs.test-keys.enabled Enable the test-keys identity false
external-spire-server.externalControllerManagers.enabled Flag to enable external controller managers true
external-spire-server.upstreamAuthority.spire.enabled Enable upstream SPIRE server true
external-spire-server.upstreamAuthority.spire.upstreamDriver Use an upstream driver for authentication upstream.csi.spiffe.io
external-spire-server.upstreamAuthority.spire.server.nameOverride The name override setting of the root SPIRE server root-server
external-spire-server.bundlePublisher.k8sConfigMap.enabled Enable local k8s bundle uploader false
external-spire-server.nodeAttestor.k8sPSAT.enabled Enable PSAT k8s nodeattestor false
external-spire-server.nodeAttestor.joinToken.enabled Enable the join_token nodeattestor true
spiffe-csi-driver.fullnameOverride Fullname override spiffe-csi-driver
spiffe-csi-driver.agentSocketPath The socket path where Spiffe CSI driver mounts agent socket /var/run/spire/agent-sockets/spire-agent.sock
spiffe-csi-driver.healthChecks.port Health check port number for upstream Spire agent 9814
spire-ha-agent.fullnameOverride Fullname override spire-ha-agent

Upstream SPIFFE CSI Driver for Bottom Turtle HA A parameters

Name Description Value
upstream-spiffe-csi-driver-bottom-turtle-ha-a.fullnameOverride Fullname override spiffe-csi-driver-upstream-a
upstream-spiffe-csi-driver-bottom-turtle-ha-a.pluginName The plugin name for configuring upstream Spiffe CSI driver upstream-a.csi.spiffe.io
upstream-spiffe-csi-driver-bottom-turtle-ha-a.agentSocketPath The socket path where Spiffe CSI driver mounts agent socket /var/run/spiffe/socat/unix/k8s-spire-server-a/public/spire-agent.sock
upstream-spiffe-csi-driver-bottom-turtle-ha-a.healthChecks.port The port where Spiffe CSI driver health checks are exposed 9810
upstream-spiffe-csi-driver-bottom-turtle-ha-a.validatingAdmissionPolicy.enabled Flag to enable validating policy true

Upstream SPIFFE CSI Driver for Bottom Turtle HA B parameters

Name Description Value
upstream-spiffe-csi-driver-bottom-turtle-ha-b.fullnameOverride Fullname override spiffe-csi-driver-upstream-b
upstream-spiffe-csi-driver-bottom-turtle-ha-b.pluginName The plugin name for configuring upstream Spiffe CSI driver upstream-b.csi.spiffe.io
upstream-spiffe-csi-driver-bottom-turtle-ha-b.agentSocketPath The socket path where Spiffe CSI driver mounts agent socket /var/run/spiffe/socat/unix/k8s-spire-server-b/public/spire-agent.sock
upstream-spiffe-csi-driver-bottom-turtle-ha-b.healthChecks.port The port where Spiffe CSI driver health checks are exposed 9812
upstream-spiffe-csi-driver-bottom-turtle-ha-b.validatingAdmissionPolicy.enabled Flag to enable validating policy true

Spire server parameters

Name Description Value
internal-spire-server-bottom-turtle-ha-a.nameOverride Overrides the name of Spire server pods internal-server
internal-spire-server-bottom-turtle-ha-a.caKeyType Key type to use for the ca ec-p256
internal-spire-server-bottom-turtle-ha-a.experimental.enabled enable experimental features true
internal-spire-server-bottom-turtle-ha-a.experimental.agentSPIFFEIDAsSelector enable adding spiffe_id selectors to all agents true
internal-spire-server-bottom-turtle-ha-a.dynamicRegistration.enabled Enable dynamic registration true
internal-spire-server-bottom-turtle-ha-a.dynamicRegistration.allowedIDPrefix The allowed ID prefix spire/agent/x509pop/k8s
internal-spire-server-bottom-turtle-ha-a.dynamicRegistration.serviceAccount The service account to allow in for dynamic registration spire-a-agent
internal-spire-server-bottom-turtle-ha-a.controllerManager.enabled Enable controller manager and provision CRD's true
internal-spire-server-bottom-turtle-ha-a.controllerManager.parentIDTemplate parent id template spiffe://{{ .TrustDomain }}/k8s_psat/{{ .ClusterName }}/{{ .NodeMeta.UID }}
internal-spire-server-bottom-turtle-ha-a.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.autoPopulateDNSNames Auto populate dns entries false
internal-spire-server-bottom-turtle-ha-a.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.type The type of the entry oidc-discovery-provider-common
internal-spire-server-bottom-turtle-ha-a.controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.enabled Enables the spire-ha-agent identity true
internal-spire-server-bottom-turtle-ha-a.controllerManager.identities.spire-identity-exchange-service.federatesWith List of trust domains to federate with []
internal-spire-server-bottom-turtle-ha-a.persistence.type What type to use for peristence emptyDir
internal-spire-server-bottom-turtle-ha-a.nodeAttestor.k8sPSAT.enabled Enable the k8s projected access token node attestor false
internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.enabled Enable the x509 pop node attestor true
internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.spiffePrefix What prefix to use when mode is spiffe /spire-exchange/k8s${HELM_ADD_CLUSTER_NAME}/
internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.agentPathTemplate Override the default agent path template /{{ .PluginName }}/k8s${HELM_ADD_CLUSTER_NAME}/{{ .SVIDPathTrimmed }}
internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.addClusterName.spiffePrefix Suffix the cluster name onto the spiffePrefix true
internal-spire-server-bottom-turtle-ha-a.nodeAttestor.x509POP.addClusterName.agentPathTemplate Suffix the cluster name onto the agentPathTemplate true
internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.enabled Enable upstream SPIRE server true
internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.upstreamDriver Use an upstream driver for authentication upstream-a.csi.spiffe.io
internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.server.nameOverride The name override setting of the root SPIRE server root-server
internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.server.address Address for upstream Spire server spire-server-a
internal-spire-server-bottom-turtle-ha-a.upstreamAuthority.spire.server.port The port setting of the root SPIRE server 8081
internal-spire-server-bottom-turtle-ha-a.bundleConfigMap The name of the configmap to store the downstream bundle spire-server-a-bundle
internal-spire-server-bottom-turtle-ha-a.trustSync.enabled Enable trust syncing true
internal-spire-server-bottom-turtle-ha-a.trustSync.domains the trust domains to sync ["spire-ha"]

Spire server parameters

Name Description Value
internal-spire-server-bottom-turtle-ha-b.nameOverride Overrides the name of Spire server pods internal-server
internal-spire-server-bottom-turtle-ha-b.caKeyType Key type to use for the ca ec-p256
internal-spire-server-bottom-turtle-ha-b.experimental.enabled enable experimental features true
internal-spire-server-bottom-turtle-ha-b.experimental.agentSPIFFEIDAsSelector enable adding spiffe_id selectors to all agents true
internal-spire-server-bottom-turtle-ha-b.dynamicRegistration.enabled Enable dynamic registration true
internal-spire-server-bottom-turtle-ha-b.dynamicRegistration.allowedIDPrefix The allowed ID prefix spire/agent/x509pop/k8s
internal-spire-server-bottom-turtle-ha-b.dynamicRegistration.serviceAccount The service account to allow in for dynamic registration spire-b-agent
internal-spire-server-bottom-turtle-ha-b.controllerManager.enabled Enable controller manager and provision CRD's true
internal-spire-server-bottom-turtle-ha-b.controllerManager.parentIDTemplate parent id template spiffe://{{ .TrustDomain }}/k8s_psat/{{ .ClusterName }}/{{ .NodeMeta.UID }}
internal-spire-server-bottom-turtle-ha-b.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.autoPopulateDNSNames Auto populate dns entries false
internal-spire-server-bottom-turtle-ha-b.controllerManager.identities.clusterSPIFFEIDs.oidc-discovery-provider.type The type of the entry oidc-discovery-provider-common
internal-spire-server-bottom-turtle-ha-b.controllerManager.identities.clusterSPIFFEIDs.spire-ha-agent.enabled Enables the spire-ha-agent identity true
internal-spire-server-bottom-turtle-ha-b.controllerManager.identities.spire-identity-exchange-service.federatesWith List of trust domains to federate with []
internal-spire-server-bottom-turtle-ha-b.persistence.type What type to use for peristence emptyDir
internal-spire-server-bottom-turtle-ha-b.nodeAttestor.k8sPSAT.enabled Enable the k8s projected access token node attestor false
internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.enabled Enable the x509 pop node attestor true
internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.spiffePrefix What prefix to use when mode is spiffe /spire-exchange/k8s${HELM_ADD_CLUSTER_NAME}/
internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.agentPathTemplate Override the default agent path template /{{ .PluginName }}/k8s${HELM_ADD_CLUSTER_NAME}/{{ .SVIDPathTrimmed }}
internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.addClusterName.spiffePrefix Suffix the cluster name onto the spiffePrefix true
internal-spire-server-bottom-turtle-ha-b.nodeAttestor.x509POP.addClusterName.agentPathTemplate Suffix the cluster name onto the agentPathTemplate true
internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.enabled Enable upstream SPIRE server true
internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.upstreamDriver Use an upstream driver for authentication upstream-b.csi.spiffe.io
internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.server.nameOverride The name override setting of the root SPIRE server root-server
internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.server.address Address for upstream Spire server spire-server-b
internal-spire-server-bottom-turtle-ha-b.upstreamAuthority.spire.server.port The port setting of the root SPIRE server 8081
internal-spire-server-bottom-turtle-ha-b.bundleConfigMap The name of the configmap to store the downstream bundle spire-server-b-bundle
internal-spire-server-bottom-turtle-ha-b.trustSync.enabled Enable trust syncing true
internal-spire-server-bottom-turtle-ha-b.trustSync.domains the trust domains to sync ["spire-ha"]
downstream-spire-agent-bottom-turtle-ha-a.nameOverride Overrides the name of Spire agent pods agent-downstream
downstream-spire-agent-bottom-turtle-ha-a.server.nameOverride The name override setting of the internal SPIRE server internal-server
downstream-spire-agent-bottom-turtle-ha-a.bundleConfigMap The name of the configmap that contains the downstream bundle spire-server-a-bundle
downstream-spire-agent-bottom-turtle-ha-a.persistence.hostPath Which path to use on the host when persistence.type = hostPath /var/lib/spire/k8s/downstream-agent-a
downstream-spire-agent-bottom-turtle-ha-a.dynamicRegistration.enabled Enable dynamic registration true
downstream-spire-agent-bottom-turtle-ha-a.dynamicRegistration.nameOverride The name override to use to contact the server internal-server
downstream-spire-agent-bottom-turtle-ha-a.nodeAttestor.k8sPSAT.enabled Enable the k8s projected access token node attestor false
downstream-spire-agent-bottom-turtle-ha-a.nodeAttestor.x509POP.enabled Enable the x509 pop node attestor true
downstream-spire-agent-bottom-turtle-ha-a.nodeAttestor.x509POP.spiffeEndpointSocket Where the socket is to use for mode spiffe /var/run/spiffe/socat/unix/k8s-spire-agent-a/public/api.sock
downstream-spire-agent-bottom-turtle-ha-a.keyManager.memory.enabled Enable the memory based Key Manager false
downstream-spire-agent-bottom-turtle-ha-a.keyManager.disk.enabled Enable the disk key manager true
downstream-spire-agent-bottom-turtle-ha-a.keyManager.disk.mode Where the disk plugin will write out its data emptyDir
downstream-spire-agent-bottom-turtle-ha-a.healthChecks.port Health check port 9981
downstream-spire-agent-bottom-turtle-ha-a.telemetry.prometheus.port Prometheus port to use 9989
downstream-spire-agent-bottom-turtle-ha-a.socketPath Socket path to use /var/run/spire/agent/sockets/a/csi.spiffe.io/public/spire-agent.sock
downstream-spire-agent-bottom-turtle-ha-a.sockets.hostBasePath Path on the host to place sockets /var/run/spire/agent/sockets/a
downstream-spire-agent-bottom-turtle-ha-a.sockets.admin.enabled Enable admin socket true
downstream-spire-agent-bottom-turtle-ha-a.sockets.admin.mountOnHost Mount admin socket on host true
downstream-spire-agent-bottom-turtle-ha-a.authorizedDelegates List of workloads able to use the delegation api ["/spire-ha-agent"]
downstream-spire-agent-bottom-turtle-ha-b.nameOverride Overrides the name of Spire agent pods agent-downstream
downstream-spire-agent-bottom-turtle-ha-b.server.nameOverride The name override setting of the internal SPIRE server internal-server
downstream-spire-agent-bottom-turtle-ha-b.bundleConfigMap The name of the configmap that contains the downstream bundle spire-server-b-bundle
downstream-spire-agent-bottom-turtle-ha-b.persistence.hostPath Which path to use on the host when persistence.type = hostPath /var/lib/spire/k8s/downstream-agent-b
downstream-spire-agent-bottom-turtle-ha-b.dynamicRegistration.enabled Enable dynamic registration true
downstream-spire-agent-bottom-turtle-ha-b.dynamicRegistration.nameOverride The name override to use to contact the server internal-server
downstream-spire-agent-bottom-turtle-ha-b.nodeAttestor.k8sPSAT.enabled Enable the k8s projected access token node attestor false
downstream-spire-agent-bottom-turtle-ha-b.nodeAttestor.x509POP.enabled Enable the x509 pop node attestor true
downstream-spire-agent-bottom-turtle-ha-b.nodeAttestor.x509POP.spiffeEndpointSocket Where the socket is to use for mode spiffe /var/run/spiffe/socat/unix/k8s-spire-agent-b/public/api.sock
downstream-spire-agent-bottom-turtle-ha-b.keyManager.memory.enabled Enable the memory based Key Manager false
downstream-spire-agent-bottom-turtle-ha-b.keyManager.disk.enabled Enable the disk key manager true
downstream-spire-agent-bottom-turtle-ha-b.keyManager.disk.mode Where the disk plugin will write out its data emptyDir
downstream-spire-agent-bottom-turtle-ha-b.healthChecks.port Health check port 9982
downstream-spire-agent-bottom-turtle-ha-b.telemetry.prometheus.port Prometheus port to use 9990
downstream-spire-agent-bottom-turtle-ha-b.socketPath Socket path to use /var/run/spire/agent/sockets/b/csi.spiffe.io/public/spire-agent.sock
downstream-spire-agent-bottom-turtle-ha-b.sockets.hostBasePath Path on the host to place sockets /var/run/spire/agent/sockets/b
downstream-spire-agent-bottom-turtle-ha-b.sockets.admin.enabled Enable admin socket true
downstream-spire-agent-bottom-turtle-ha-b.sockets.admin.mountOnHost Mount admin socket on host true
downstream-spire-agent-bottom-turtle-ha-b.authorizedDelegates List of workloads able to use the delegation api ["/spire-ha-agent"]
downstream-spiffe-csi-driver-bottom-turtle-ha-a.fullnameOverride Fullname override spiffe-csi-driver-downstream-a
downstream-spiffe-csi-driver-bottom-turtle-ha-a.agentSocketPath path to agent socket /var/run/spire/agent/sockets/a/csi.spiffe.io/public/spire-agent.sock
downstream-spiffe-csi-driver-bottom-turtle-ha-a.pluginName The name of the plugin instance a.csi.spiffe.io
downstream-spiffe-csi-driver-bottom-turtle-ha-a.healthChecks.port The health check port 9814
downstream-spiffe-csi-driver-bottom-turtle-ha-b.fullnameOverride Fullname override spiffe-csi-driver-downstream-b
downstream-spiffe-csi-driver-bottom-turtle-ha-b.agentSocketPath path to agent socket /var/run/spire/agent/sockets/b/csi.spiffe.io/public/spire-agent.sock
downstream-spiffe-csi-driver-bottom-turtle-ha-b.pluginName The name of the plugin instance b.csi.spiffe.io
downstream-spiffe-csi-driver-bottom-turtle-ha-b.healthChecks.port The health check port 9816
spire-identity-exchange-bottom-turtle-ha-a.enabled Enable the spire-identity-exchange false
spire-identity-exchange-bottom-turtle-ha-a.nameOverride name override identity-exchange
spire-identity-exchange-bottom-turtle-ha-a.csiDriverName CSI driver name to use a.csi.spiffe.io
spire-identity-exchange-bottom-turtle-ha-a.rest.ingress.host Hostname override for the rest ingress service spire-identity-exchange-a-rest
spire-identity-exchange-bottom-turtle-ha-a.grpc.ingress.host Hostname override for the rest ingress service spire-identity-exchange-a-grpc
spire-identity-exchange-bottom-turtle-ha-a.server.nameOverride The name override setting of the internal SPIRE server internal-server
spire-identity-exchange-bottom-turtle-ha-b.enabled Enable the spire-identity-exchange false
spire-identity-exchange-bottom-turtle-ha-b.nameOverride name override identity-exchange
spire-identity-exchange-bottom-turtle-ha-b.csiDriverName CSI driver name to use b.csi.spiffe.io
spire-identity-exchange-bottom-turtle-ha-b.server.nameOverride The name override setting of the internal SPIRE server internal-server
spire-identity-exchange-bottom-turtle-ha-b.rest.ingress.host Hostname override for the rest ingress service spire-identity-exchange-b-rest
spire-identity-exchange-bottom-turtle-ha-b.grpc.ingress.host Hostname override for the rest ingress service spire-identity-exchange-b-grpc