* allow IAM auth for non-password methods Signed-off-by: Hamdan Al-Radaideh <[email protected]> * add example, patch charts' versions and values Signed-off-by: Hamdan Al-Radaideh <[email protected]> * updates Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump test chart dependencies (#647) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump github.com/onsi/ginkgo/v2 from 2.23.4 to 2.24.0 in /tests (#648) Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.23.4 to 2.24.0. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](https://github.com/onsi/ginkgo/compare/v2.23.4...v2.24.0) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.24.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump helm.sh/helm/v3 from 3.18.4 to 3.18.6 in /tests (#650) Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.18.4 to 3.18.6. - [Release notes](https://github.com/helm/helm/releases) - [Commits](https://github.com/helm/helm/compare/v3.18.4...v3.18.6) --- updated-dependencies: - dependency-name: helm.sh/helm/v3 dependency-version: 3.18.6 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump github.com/onsi/ginkgo/v2 from 2.24.0 to 2.25.1 in /tests (#651) Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.24.0 to 2.25.1. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](https://github.com/onsi/ginkgo/compare/v2.24.0...v2.25.1) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.25.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump test chart dependencies (#653) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump github.com/onsi/gomega from 1.38.0 to 1.38.1 in /tests (#652) Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.38.0 to 1.38.1. - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](https://github.com/onsi/gomega/compare/v1.38.0...v1.38.1) --- updated-dependencies: - dependency-name: github.com/onsi/gomega dependency-version: 1.38.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump github.com/onsi/gomega from 1.38.1 to 1.38.2 in /tests (#654) Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.38.1 to 1.38.2. - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](https://github.com/onsi/gomega/compare/v1.38.1...v1.38.2) --- updated-dependencies: - dependency-name: github.com/onsi/gomega dependency-version: 1.38.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump test chart dependencies (#658) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump github.com/onsi/ginkgo/v2 from 2.25.1 to 2.25.3 in /tests (#659) Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.25.1 to 2.25.3. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](https://github.com/onsi/ginkgo/compare/v2.25.1...v2.25.3) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.25.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump test chart dependencies (#660) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Add labels to the spiffe-oidc-discovery-provider values.yaml (#656) * add labels to the spiffe-oidc-discovery-provider values.yaml Signed-off-by: tuxotron <[email protected]> * add labels to readme Signed-off-by: tuxotron <[email protected]> * Bump github.com/onsi/gomega from 1.38.1 to 1.38.2 in /tests (#654) Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.38.1 to 1.38.2. - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](https://github.com/onsi/gomega/compare/v1.38.1...v1.38.2) --- updated-dependencies: - dependency-name: github.com/onsi/gomega dependency-version: 1.38.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: tuxotron <[email protected]> * Bump test chart dependencies (#658) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Signed-off-by: tuxotron <[email protected]> --------- Signed-off-by: tuxotron <[email protected]> Signed-off-by: dependabot[bot] <[email protected]> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: spire-helm-version-checker[bot] <161522935+spire-helm-version-checker[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump helm.sh/helm/v3 from 3.18.6 to 3.19.0 in /tests (#664) Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.18.6 to 3.19.0. - [Release notes](https://github.com/helm/helm/releases) - [Commits](https://github.com/helm/helm/compare/v3.18.6...v3.19.0) --- updated-dependencies: - dependency-name: helm.sh/helm/v3 dependency-version: 3.19.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * blend into same logic in the chart for the new auth method, add the ability to add loadbalancer ip Signed-off-by: Hamdan Al-Radaideh <[email protected]> * remove whitespaces Signed-off-by: Hamdan Al-Radaideh <[email protected]> * update README and values file Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Spire agent helm chart: allow configuring logFormat (#661) * Spire agent helm chart: allow configuring logFormat Signed-off-by: Nikolai Tihhomirov <[email protected]> * Fixup: wrong doc parameter Signed-off-by: Nikolai Tihhomirov <[email protected]> --------- Signed-off-by: Nikolai Tihhomirov <[email protected]> Co-authored-by: kfox1111 <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Add controller manager configs gcInterval, logLevel, and make entryIDPrefix configurable (#662) * Make controller manager gcInterval configurable in spire-server helm chart Signed-off-by: Daniel Schlatter <[email protected]> * Make controller manager logLevel configurable in spire-server helm chart Signed-off-by: Daniel Schlatter <[email protected]> * Make controller manager entryIDPrefix configurable in spire-server helm chart Signed-off-by: Daniel Schlatter <[email protected]> * change configurable entryIDPrefix to a binary option of add the cluster name or not Signed-off-by: Daniel Schlatter <[email protected]> --------- Signed-off-by: Daniel Schlatter <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Bump test chart dependencies (#666) Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> * make spire server's auth_opa_policy_engine configurable in the helm chart (#663) Signed-off-by: Hamdan Al-Radaideh <[email protected]> * Update spire to 1.13.0 (#667) Signed-off-by: Kevin Fox <[email protected]> Signed-off-by: Hamdan Al-Radaideh <[email protected]> --------- Signed-off-by: Hamdan Al-Radaideh <[email protected]> Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Signed-off-by: dependabot[bot] <[email protected]> Signed-off-by: tuxotron <[email protected]> Signed-off-by: Nikolai Tihhomirov <[email protected]> Signed-off-by: Daniel Schlatter <[email protected]> Signed-off-by: Kevin Fox <[email protected]> Co-authored-by: spire-helm-version-checker[bot] <161522935+spire-helm-version-checker[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: tuxotron <[email protected]> Co-authored-by: Nikolai <[email protected]> Co-authored-by: kfox1111 <[email protected]> Co-authored-by: Daniel Schlatter <[email protected]>
46 lines
1.3 KiB
Markdown
46 lines
1.3 KiB
Markdown
# Cloud SQL Proxy with GCP IAM Authentication
|
|
|
|
Use SPIRE Server with Google Cloud SQL using IAM authentication instead of passwords.
|
|
|
|
## Setup
|
|
|
|
### 1. Create Infrastructure
|
|
|
|
**Prerequisites:**
|
|
- GKE cluster with Workload Identity enabled
|
|
- Terraform configured with GCP provider
|
|
|
|
Use Terraform to create the database, service account, and Workload Identity:
|
|
|
|
```bash
|
|
# Edit main.tf and replace placeholders:
|
|
# - YOUR_PROJECT_ID with your GCP project ID
|
|
# - YOUR_REGION with your preferred region (e.g., us-central1)
|
|
|
|
terraform init
|
|
terraform apply
|
|
```
|
|
|
|
**Note:** This creates:
|
|
- Service account with Cloud SQL Client and Instance User roles
|
|
- Cloud SQL instance with IAM authentication enabled
|
|
- Kubernetes service account with Workload Identity annotation
|
|
- IAM binding for Workload Identity
|
|
|
|
### 2. Deploy
|
|
|
|
Edit `values.yaml` with your project details, then:
|
|
|
|
```bash
|
|
helm upgrade --install -n spire spire spire \
|
|
--repo https://spiffe.github.io/helm-charts-hardened/ \
|
|
-f values.yaml
|
|
```
|
|
|
|
## How It Works
|
|
|
|
1. Cloud SQL Proxy runs as an init container with `restartPolicy: Always`
|
|
2. Proxy connects to your database using IAM authentication
|
|
3. SPIRE connects to `127.0.0.1:3306` through the proxy
|
|
4. Uses `gcp_mysql_sa_iam` database type for automatic IAM authentication
|
|
5. No passwords needed - everything uses IAM authentication |