Conversation
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com>
To have an always up to date kubectl image it is probably better to get kubectl from registry.k8s.io Signed-off-by: Marco Franssen <marco.franssen@gmail.com>
This reduces the footprint for this initContainer to just 4.04MB. The cgr.dev/chainguard/bash image is 35.2MB in size. I have used the same tag as the busybox value to ensure no additional versions have to be pulled on the node running spire-server components. Signed-off-by: Marco Franssen <marco.franssen@gmail.com>
Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.18.3 to 3.18.4. - [Release notes](https://github.com/helm/helm/releases) - [Commits](helm/helm@v3.18.3...v3.18.4) --- updated-dependencies: - dependency-name: helm.sh/helm/v3 dependency-version: 3.18.4 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Add Agent TTL Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * Allow unset agentttl Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> --------- Signed-off-by: Eric Cavalcanti <ericcav@amazon.com>
* Add aws_iid Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * Change to awsIid Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * Change to awsIid Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * update helm Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * Change to awsIID Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * Change to awsIID Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * Change to awsIID Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * Change to awsIID Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * Change to awsIID Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * Change to awsIID Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * add signed off Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * Add doc Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * remove not used config Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * remove not used config Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> * add example awsiid Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> --------- Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com>
* Remove spire-server.nodeAttestor.awsIID.region Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Remove spire-server.nodeAttestor.awsIID.region Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Remove spire-server.nodeAttestor.awsIID.region Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Update README.md Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> --------- Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com>
* Add disk based KeyManager Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Change disk to false Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Change disk to false Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Fix per requirement Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Update information Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Detail doc Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Test change comment Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Commnet better before Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> --------- Signed-off-by: Eric Cavalcanti <ericcav@amazon.com> Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> Co-authored-by: kfox1111 <Kevin.Fox@pnnl.gov>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com>
Signed-off-by: Kevin Fox <Kevin.Fox@pnnl.gov>
--- updated-dependencies: - dependency-name: github.com/onsi/gomega dependency-version: 1.38.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com>
* 64b9c40 Bump test chart dependencies (#635) * d516de0 Update spike to 0.4.2 (#632) * 8904b96 Bump test chart dependencies (#633) * 6581b11 Add disk based KeyManager (#627) * d2913ff Remove region from awsiid node attestor (#630) * 3218db7 Bump test chart dependencies (#628) * 57a6143 Add aws_iid to helm chart (#620) * 9a8e5a8 Add Agent TTL to Spire Server (#626) * 093c593 spire-server: Replace chown image with busybox * a7d536c tools: Replace rancher/kubectl with registry.k8s.io/kubectl * fc1791f Bump test chart dependencies (#618) Signed-off-by: Faisal Memon <fymemon@yahoo.com>
Signed-off-by: Faisal Memon <fymemon@yahoo.com> Co-authored-by: kfox1111 <Kevin.Fox@pnnl.gov>
* Bump spiffe-step-ssh Helm Chart version from 0.1.0 to 0.1.1 * a7d536c tools: Replace rancher/kubectl with registry.k8s.io/kubectl Signed-off-by: Faisal Memon <fymemon@yahoo.com> * Update charts/spiffe-step-ssh/Chart.yaml Signed-off-by: kfox1111 <Kevin.Fox@pnnl.gov> --------- Signed-off-by: Faisal Memon <fymemon@yahoo.com> Signed-off-by: kfox1111 <Kevin.Fox@pnnl.gov> Co-authored-by: kfox1111 <Kevin.Fox@pnnl.gov>
* Add Datadog as telemetry option Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Use correct local domain Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Change doc Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Add docs Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * remove .cluster.local Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Remove cluster.local Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Fix doc Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> --------- Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> Co-authored-by: kfox1111 <Kevin.Fox@pnnl.gov>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com> Co-authored-by: kfox1111 <Kevin.Fox@pnnl.gov>
* Change selinux image pullpolicy and tag version Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Change image pullpolicy Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Update readme Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * update examples Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Update image pullpolicy Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Fix readme as well Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Undo pullpolicy readme Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Add selinux Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Revert code block Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> * Change regex Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com> --------- Signed-off-by: Eric Cavalcanti <cajuclc@gmail.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com>
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.23.4 to 2.24.0. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](onsi/ginkgo@v2.23.4...v2.24.0) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.24.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.18.4 to 3.18.6. - [Release notes](https://github.com/helm/helm/releases) - [Commits](helm/helm@v3.18.4...v3.18.6) --- updated-dependencies: - dependency-name: helm.sh/helm/v3 dependency-version: 3.18.6 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.24.0 to 2.25.1. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](onsi/ginkgo@v2.24.0...v2.25.1) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.25.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com>
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.38.0 to 1.38.1. - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](onsi/gomega@v1.38.0...v1.38.1) --- updated-dependencies: - dependency-name: github.com/onsi/gomega dependency-version: 1.38.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.38.1 to 1.38.2. - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](onsi/gomega@v1.38.1...v1.38.2) --- updated-dependencies: - dependency-name: github.com/onsi/gomega dependency-version: 1.38.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com>
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.25.1 to 2.25.3. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](onsi/ginkgo@v2.25.1...v2.25.3) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.25.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com>
* Bump test chart dependencies Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * Fix bitnami chart support Signed-off-by: Kevin Fox <Kevin.Fox@pnnl.gov> --------- Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Signed-off-by: Kevin Fox <Kevin.Fox@pnnl.gov> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com> Co-authored-by: Kevin Fox <Kevin.Fox@pnnl.gov>
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.25.3 to 2.26.0. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](onsi/ginkgo@v2.25.3...v2.26.0) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.26.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: kfox1111 <Kevin.Fox@pnnl.gov>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com>
…#678) Signed-off-by: Daniel Schlatter <djschlatt@gmail.com> Co-authored-by: kfox1111 <Kevin.Fox@pnnl.gov>
Signed-off-by: Monforton <113210196+Monforton@users.noreply.github.com> Co-authored-by: kfox1111 <Kevin.Fox@pnnl.gov>
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.26.0 to 2.27.1. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](onsi/ginkgo@v2.26.0...v2.27.1) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.27.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.27.1 to 2.27.2. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](onsi/ginkgo@v2.27.1...v2.27.2) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.27.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com>
Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.19.0 to 3.19.1. - [Release notes](https://github.com/helm/helm/releases) - [Commits](helm/helm@v3.19.0...v3.19.1) --- updated-dependencies: - dependency-name: helm.sh/helm/v3 dependency-version: 3.19.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.19.1 to 3.19.2. - [Release notes](https://github.com/helm/helm/releases) - [Commits](helm/helm@v3.19.1...v3.19.2) --- updated-dependencies: - dependency-name: helm.sh/helm/v3 dependency-version: 3.19.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com>
… spire-agent init container (#691) * use spire-agent.resources to set resources for associated initContainers, remove specific keys for those initContainers corresponding resources Signed-off-by: Daniel Schlatter <djschlatt@gmail.com> * set resources for spire-agent init containers fingerprint-tpm and init-tpm-direct Signed-off-by: Daniel Schlatter <djschlatt@gmail.com> * use spiffe-csi-driver.resources to set resources for associated initContainers, remove specific keys for those initContainers corresponding resources Signed-off-by: Daniel Schlatter <djschlatt@gmail.com> * set resources for spiffe-csi-driver init container set-context Signed-off-by: Daniel Schlatter <djschlatt@gmail.com> --------- Signed-off-by: Daniel Schlatter <djschlatt@gmail.com>
Signed-off-by: Kevin Fox <Kevin.Fox@pnnl.gov> Co-authored-by: Faisal Memon <fymemon@yahoo.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: marcofranssen <694733+marcofranssen@users.noreply.github.com>
* 18b8144 Bump test chart dependencies (#698) * 31091cf Add oidc server_path_prefix option (#695) * 8dffc8e use spire-agent.hostCert.resources to set resources for corresponding spire-agent init container (#691) * e75e095 Bump test chart dependencies (#696) * aab7c68 Bump test chart dependencies (#692) * ca6e9f3 Bump test chart dependencies * a373924 Bump test chart dependencies * c52edb9 chore: update SPIRE to 1.13.2 (#681) * 41bd5b9 fix socketAlternate names throwing an error if set to an empty list (#678) * 5402473 Bump test chart dependencies (#684) * 8925975 Bump test chart dependencies (#674) * 0f5bb04 Bump test chart dependencies (#672) Signed-off-by: Faisal Memon <fymemon@yahoo.com>
* c52edb9 chore: update SPIRE to 1.13.2 (#681) Signed-off-by: Faisal Memon <fymemon@yahoo.com> Co-authored-by: kfox1111 <Kevin.Fox@pnnl.gov>
Summary of ChangesHello @alec-w, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request merges the latest upstream changes for SPIRE version 0.27.1, bringing a suite of updates across the Helm charts. The primary goal is to ensure compatibility with the newest SPIRE features and security enhancements, while also integrating new cloud-specific node attestors and telemetry options. The changes encompass dependency upgrades, refined configurations for various components, and the addition of new examples to demonstrate advanced integrations. Highlights
🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console. Changelog
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request merges changes from spire 0.27.1, including numerous dependency updates, version bumps, and configuration changes across various Helm charts. It also adds new features such as the AWS IID node attestor, GCP IAM authentication for Cloud SQL, and Datadog telemetry support. A security audit identified several instances of potential YAML injection in Kubernetes templates where values from values.yaml are embedded without proper quoting, which could lead to configuration manipulation or deployment failures. It is recommended to apply suggested quoting to ensure robust and secure manifests. Additionally, a few minor issues related to file formatting were found in the new example files.
Part of https://github.com/cofide/cofide-spire/issues/155
Conflicts resolved:
helm-docs.shto ensure fix was correct.