* allow IAM auth for non-password methods Signed-off-by: Hamdan Al-Radaideh <[email protected]> * add example, patch charts' versions and values Signed-off-by: Hamdan Al-Radaideh <[email protected]> * updates Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump test chart dependencies (#647) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump github.com/onsi/ginkgo/v2 from 2.23.4 to 2.24.0 in /tests (#648) Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.23.4 to 2.24.0. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](https://github.com/onsi/ginkgo/compare/v2.23.4...v2.24.0) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.24.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump helm.sh/helm/v3 from 3.18.4 to 3.18.6 in /tests (#650) Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.18.4 to 3.18.6. - [Release notes](https://github.com/helm/helm/releases) - [Commits](https://github.com/helm/helm/compare/v3.18.4...v3.18.6) --- updated-dependencies: - dependency-name: helm.sh/helm/v3 dependency-version: 3.18.6 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump github.com/onsi/ginkgo/v2 from 2.24.0 to 2.25.1 in /tests (#651) Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.24.0 to 2.25.1. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](https://github.com/onsi/ginkgo/compare/v2.24.0...v2.25.1) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.25.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump test chart dependencies (#653) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump github.com/onsi/gomega from 1.38.0 to 1.38.1 in /tests (#652) Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.38.0 to 1.38.1. - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](https://github.com/onsi/gomega/compare/v1.38.0...v1.38.1) --- updated-dependencies: - dependency-name: github.com/onsi/gomega dependency-version: 1.38.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump github.com/onsi/gomega from 1.38.1 to 1.38.2 in /tests (#654) Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.38.1 to 1.38.2. - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](https://github.com/onsi/gomega/compare/v1.38.1...v1.38.2) --- updated-dependencies: - dependency-name: github.com/onsi/gomega dependency-version: 1.38.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump test chart dependencies (#658) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump github.com/onsi/ginkgo/v2 from 2.25.1 to 2.25.3 in /tests (#659) Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.25.1 to 2.25.3. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](https://github.com/onsi/ginkgo/compare/v2.25.1...v2.25.3) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.25.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump test chart dependencies (#660) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Add labels to the spiffe-oidc-discovery-provider values.yaml (#656) * add labels to the spiffe-oidc-discovery-provider values.yaml Signed-off-by: tuxotron <[email protected]> * add labels to readme Signed-off-by: tuxotron <[email protected]> * Bump github.com/onsi/gomega from 1.38.1 to 1.38.2 in /tests (#654) Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.38.1 to 1.38.2. - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](https://github.com/onsi/gomega/compare/v1.38.1...v1.38.2) --- updated-dependencies: - dependency-name: github.com/onsi/gomega dependency-version: 1.38.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: tuxotron <[email protected]> * Bump test chart dependencies (#658) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Signed-off-by: tuxotron <[email protected]> --------- Signed-off-by: tuxotron <[email protected]> Signed-off-by: dependabot[bot] <[email protected]> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: spire-helm-version-checker[bot] <161522935+spire-helm-version-checker[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump helm.sh/helm/v3 from 3.18.6 to 3.19.0 in /tests (#664) Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.18.6 to 3.19.0. - [Release notes](https://github.com/helm/helm/releases) - [Commits](https://github.com/helm/helm/compare/v3.18.6...v3.19.0) --- updated-dependencies: - dependency-name: helm.sh/helm/v3 dependency-version: 3.19.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * blend into same logic in the chart for the new auth method, add the ability to add loadbalancer ip Signed-off-by: Hamdan Al-Radaideh <[email protected]> * remove whitespaces Signed-off-by: Hamdan Al-Radaideh <[email protected]> * update README and values file Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Spire agent helm chart: allow configuring logFormat (#661) * Spire agent helm chart: allow configuring logFormat Signed-off-by: Nikolai Tihhomirov <[email protected]> * Fixup: wrong doc parameter Signed-off-by: Nikolai Tihhomirov <[email protected]> --------- Signed-off-by: Nikolai Tihhomirov <[email protected]> Co-authored-by: kfox1111 <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Add controller manager configs gcInterval, logLevel, and make entryIDPrefix configurable (#662) * Make controller manager gcInterval configurable in spire-server helm chart Signed-off-by: Daniel Schlatter <[email protected]> * Make controller manager logLevel configurable in spire-server helm chart Signed-off-by: Daniel Schlatter <[email protected]> * Make controller manager entryIDPrefix configurable in spire-server helm chart Signed-off-by: Daniel Schlatter <[email protected]> * change configurable entryIDPrefix to a binary option of add the cluster name or not Signed-off-by: Daniel Schlatter <[email protected]> --------- Signed-off-by: Daniel Schlatter <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump test chart dependencies (#666) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * make spire server's auth_opa_policy_engine configurable in the helm chart (#663) Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Update spire to 1.13.0 (#667) Signed-off-by: Kevin Fox <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> --------- Signed-off-by: Hamdan Al-Radaideh <[email protected]> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Signed-off-by: dependabot[bot] <[email protected]> Signed-off-by: tuxotron <[email protected]> Signed-off-by: Nikolai Tihhomirov <[email protected]> Signed-off-by: Daniel Schlatter <[email protected]> Signed-off-by: Kevin Fox <[email protected]> Co-authored-by: spire-helm-version-checker[bot] <161522935+spire-helm-version-checker[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: tuxotron <[email protected]> Co-authored-by: Nikolai <[email protected]> Co-authored-by: kfox1111 <[email protected]> Co-authored-by: Daniel Schlatter <[email protected]>
71 lines
2.0 KiB
Terraform
71 lines
2.0 KiB
Terraform
# Create service account for SPIRE
|
|
resource "google_service_account" "spire" {
|
|
account_id = "sa-spire"
|
|
display_name = "SPIRE Server Service Account"
|
|
project = "YOUR_PROJECT_ID"
|
|
}
|
|
|
|
# Grant Cloud SQL Client role
|
|
resource "google_project_iam_member" "cloudsql_client" {
|
|
project = "YOUR_PROJECT_ID"
|
|
role = "roles/cloudsql.client"
|
|
member = "serviceAccount:${google_service_account.spire.email}"
|
|
}
|
|
|
|
# Grant Cloud SQL Instance User role for IAM authentication
|
|
resource "google_project_iam_member" "cloudsql_instance_user" {
|
|
project = "YOUR_PROJECT_ID"
|
|
role = "roles/cloudsql.instanceUser"
|
|
member = "serviceAccount:${google_service_account.spire.email}"
|
|
}
|
|
|
|
# Create Cloud SQL database instance
|
|
resource "google_sql_database_instance" "instance" {
|
|
name = "spire-db"
|
|
region = "YOUR_REGION"
|
|
database_version = "MYSQL_8_0"
|
|
project = "YOUR_PROJECT_ID"
|
|
|
|
settings {
|
|
tier = "db-f1-micro"
|
|
database_flags {
|
|
name = "cloudsql_iam_authentication"
|
|
value = "on"
|
|
}
|
|
}
|
|
|
|
deletion_protection = true
|
|
}
|
|
|
|
# Create database
|
|
resource "google_sql_database" "database" {
|
|
name = "spire"
|
|
instance = google_sql_database_instance.instance.name
|
|
project = "YOUR_PROJECT_ID"
|
|
}
|
|
|
|
# Create IAM user for the service account
|
|
resource "google_sql_user" "iam_service_account_user" {
|
|
name = google_service_account.spire.email
|
|
instance = google_sql_database_instance.instance.name
|
|
type = "CLOUD_IAM_SERVICE_ACCOUNT"
|
|
project = "YOUR_PROJECT_ID"
|
|
}
|
|
|
|
# Create Kubernetes service account
|
|
resource "kubernetes_service_account" "spire" {
|
|
metadata {
|
|
name = "sa-spire"
|
|
namespace = "spire"
|
|
annotations = {
|
|
"iam.gke.io/gcp-service-account" = google_service_account.spire.email
|
|
}
|
|
}
|
|
}
|
|
|
|
# Set up Workload Identity binding
|
|
resource "google_service_account_iam_member" "workload_identity_user" {
|
|
service_account_id = google_service_account.spire.name
|
|
role = "roles/iam.workloadIdentityUser"
|
|
member = "serviceAccount:YOUR_PROJECT_ID.svc.id.goog[spire/sa-spire]"
|
|
} |