kfox1111andFaisal Memon ec7259699f spiffe-step-ssh server (#198)
* Initial prototype of spire-step-ssh integration

Signed-off-by: Kevin Fox <[email protected]>

* Ingress work, image cleanup and misc cleanup

Signed-off-by: Kevin Fox <[email protected]>

* More values rework

Signed-off-by: Kevin Fox <[email protected]>

* Rename chart spiffe-step-ssh

Signed-off-by: Kevin Fox <[email protected]>

* Update to use shared lib

Signed-off-by: Kevin Fox <[email protected]>

* Update spiffe-helper

Signed-off-by: Kevin Fox <[email protected]>

* Use URLSAN rather then CN

Signed-off-by: Kevin Fox <[email protected]>

* Lookup the sans.

Signed-off-by: Kevin Fox <[email protected]>

* Make trust domain configurable

Signed-off-by: Kevin Fox <[email protected]>

* Add flag

Signed-off-by: Kevin Fox <[email protected]>

* Make driver configurable

Signed-off-by: Kevin Fox <[email protected]>

* Add more configurables. Fix up docs to pass test.

Signed-off-by: Kevin Fox <[email protected]>

* Add some metadata

Signed-off-by: Kevin Fox <[email protected]>

* Fix metadata

Signed-off-by: Kevin Fox <[email protected]>

* Add default values for lint

Signed-off-by: Kevin Fox <[email protected]>

* Forgot values updates

Signed-off-by: Kevin Fox <[email protected]>

* Fix metadata

Signed-off-by: Kevin Fox <[email protected]>

* Start working on integration test

Signed-off-by: Kevin Fox <[email protected]>

* Test

Signed-off-by: Kevin Fox <[email protected]>

* Test

Signed-off-by: Kevin Fox <[email protected]>

* Fix names

Signed-off-by: Kevin Fox <[email protected]>

* More test bits

Signed-off-by: Kevin Fox <[email protected]>

* More test bits

Signed-off-by: Kevin Fox <[email protected]>

* More test bits

Signed-off-by: Kevin Fox <[email protected]>

* More test bits

Signed-off-by: Kevin Fox <[email protected]>

* More test bits

Signed-off-by: Kevin Fox <[email protected]>

* More test bits

Signed-off-by: Kevin Fox <[email protected]>

* More fixes

Signed-off-by: Kevin Fox <[email protected]>

* More fixes

Signed-off-by: Kevin Fox <[email protected]>

* More fixes

Signed-off-by: Kevin Fox <[email protected]>

* Fix name conflict. Align naming

Signed-off-by: Kevin Fox <[email protected]>

* Fix name

Signed-off-by: Kevin Fox <[email protected]>

* Add more logging

Signed-off-by: Kevin Fox <[email protected]>

* Disable unneeded test. Add missing file.

Signed-off-by: Kevin Fox <[email protected]>

* Setup more things

Signed-off-by: Kevin Fox <[email protected]>

* Add missing conf file

Signed-off-by: Kevin Fox <[email protected]>

* Fix multiple svids

Signed-off-by: Kevin Fox <[email protected]>

* Fix ci defaults

Signed-off-by: Kevin Fox <[email protected]>

* Fix filename

Signed-off-by: Kevin Fox <[email protected]>

* Try and get the linter to stop complaining...

Signed-off-by: Kevin Fox <[email protected]>

* Fix perms

Signed-off-by: Kevin Fox <[email protected]>

* More logs

Signed-off-by: Kevin Fox <[email protected]>

* More setup

Signed-off-by: Kevin Fox <[email protected]>

* Fixes

Signed-off-by: Kevin Fox <[email protected]>

* Fixes

Signed-off-by: Kevin Fox <[email protected]>

* Add wait

Signed-off-by: Kevin Fox <[email protected]>

* More logging

Signed-off-by: Kevin Fox <[email protected]>

* Test ssh

Signed-off-by: Kevin Fox <[email protected]>

* Restart fetchca on updates too

Signed-off-by: Kevin Fox <[email protected]>

* Fix formating

Signed-off-by: Kevin Fox <[email protected]>

* Add missing file flag

Signed-off-by: Kevin Fox <[email protected]>

* Increase timeout

Signed-off-by: Kevin Fox <[email protected]>

* More flags

Signed-off-by: Kevin Fox <[email protected]>

* Fix name

Signed-off-by: Kevin Fox <[email protected]>

* Finish end to end test

Signed-off-by: Kevin Fox <[email protected]>

* Fix ingress setting

Signed-off-by: Kevin Fox <[email protected]>

* More logging/tests

Signed-off-by: Kevin Fox <[email protected]>

* More testing

Signed-off-by: Kevin Fox <[email protected]>

* Fix namespace

Signed-off-by: Kevin Fox <[email protected]>

* Fetch correct bundle

Signed-off-by: Kevin Fox <[email protected]>

* Chart testing will fail as it depends on spire to be preinstalled. Weird dependency loop.

Signed-off-by: Kevin Fox <[email protected]>

* Dont skip tls for testing

Signed-off-by: Kevin Fox <[email protected]>

* More logging

Signed-off-by: Kevin Fox <[email protected]>

* More debug

Signed-off-by: Kevin Fox <[email protected]>

* More debug

Signed-off-by: Kevin Fox <[email protected]>

* Pass intermediates

Signed-off-by: Kevin Fox <[email protected]>

* Fix trustdomain

Signed-off-by: Kevin Fox <[email protected]>

* Add ca authority prefix

Signed-off-by: Kevin Fox <[email protected]>

* fix

Signed-off-by: Kevin Fox <[email protected]>

* fix

Signed-off-by: Kevin Fox <[email protected]>

* fix

Signed-off-by: Kevin Fox <[email protected]>

* ci test is just broken. Revert trying to fix it.

Signed-off-by: Kevin Fox <[email protected]>

* Update charts/spiffe-step-ssh/files/ssh_x5c.tpl

Signed-off-by: kfox1111 <[email protected]>

* Self review feedback

Signed-off-by: Kevin Fox <[email protected]>

* Switch ingress to our more functional/easy type

Signed-off-by: Kevin Fox <[email protected]>

* Simplify the template

Signed-off-by: Kevin Fox <[email protected]>

* Add cast

Signed-off-by: Kevin Fox <[email protected]>

* Add install notes

Signed-off-by: Kevin Fox <[email protected]>

* Fix test

Signed-off-by: Kevin Fox <[email protected]>

* Update tests for updated client

Signed-off-by: Kevin Fox <[email protected]>

* Fix logging and entry

Signed-off-by: Kevin Fox <[email protected]>

* Add missing dir

Signed-off-by: Kevin Fox <[email protected]>

* Fix file location

Signed-off-by: Kevin Fox <[email protected]>

* Update timeout

Signed-off-by: Kevin Fox <[email protected]>

* More logging

Signed-off-by: Kevin Fox <[email protected]>

* Fix filename

Signed-off-by: Kevin Fox <[email protected]>

* Fix perms

Signed-off-by: Kevin Fox <[email protected]>

* Update charts/spiffe-step-ssh/README.md

Signed-off-by: kfox1111 <[email protected]>

* Apply suggestions from code review

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: kfox1111 <[email protected]>

---------

Signed-off-by: Kevin Fox <[email protected]>
Signed-off-by: kfox1111 <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
2024-11-07 23:43:26 -08:00
2024-11-07 23:43:26 -08:00
2024-11-07 23:43:26 -08:00
2024-11-07 23:43:26 -08:00
2023-02-21 15:47:06 +01:00
2023-11-08 13:11:58 +01:00
2023-09-18 17:52:01 +02:00
2023-11-08 13:11:58 +01:00
2023-11-08 13:11:58 +01:00
2022-11-30 10:16:57 -06:00
2023-11-13 14:14:24 -08:00
2024-01-23 08:05:49 -08:00

Note

Things to consider:

  1. We do not support running out of the git main branch. This is where development happens. Please use released versions via the published repo or git tags.
  2. All the helm charts in this repo are beta. We encourage you to try them out and contribute. The API may change as we move towards a production ready release.

SPIFFE Helm Charts

Apache 2.0 License Development Phase Artifact Hub

A suite of Helm Charts for standardized installations of SPIRE components in Kubernetes environments.

How to install or upgrade

You most likely want to do an integrated setup based on the spire chart. See the Instructions.

Contributing

Before contributing ensure to check our CONTRIBUTING guidelines.

LICENSE

This project is licensed under Apache License, Version 2.0.

Reporting a Vulnerability

Vulnerabilities can be reported by sending an email to [email protected]. A confirmation email will be sent to acknowledge the report within 72 hours. A second acknowledgement will be sent within 7 days when the vulnerability has been positively or negatively confirmed.

S
Description
SPIFFE hardened Helm charts fork,基于当前 homelab 部署版本维护必要补丁
Readme Apache-2.0
3.9 MiB
Languages
Go Template 49.2%
Shell 23.7%
Go 16.2%
Python 7.9%
Makefile 1.6%
Other 1.4%