Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions deploy/helm/openshell/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -350,6 +350,8 @@ discovery endpoint or its TLS CA.
| openshiftRoute.host | string | `""` | Hostname for the Route. Must match a SAN on the gateway's server cert. |
| pkiInitJob.enabled | bool | `true` | Run a pre-install/pre-upgrade Job that creates gateway and client mTLS Secrets. When certManager.enabled=true, cert-manager owns TLS and this same hook runs in JWT-only mode even if pkiInitJob.enabled remains true. |
| pkiInitJob.failOnTimeout | bool | `true` | Fail the helm install/upgrade if cert-manager does not issue the certificate within the polling timeout. When true (default), the install fails immediately if the timeout is reached, providing clear feedback that BackendTLSPolicy is non-functional. When false, the hook succeeds with a warning and you can run `helm upgrade` after cert-manager issues the certificate to create the backend CA ConfigMap. If you set this to false and see "TLS error: Secret is not supplied by SDS" when connecting to the gateway, check if the TLS secret exists and run `helm upgrade` to create the ConfigMap. |
| pkiInitJob.podSecurityContext | object | `{"seccompProfile":{"type":"RuntimeDefault"}}` | Pod-level securityContext for the certgen hook Jobs. Defaults satisfy the Kubernetes Restricted Pod Security Standard. |
| pkiInitJob.securityContext | object | `{"allowPrivilegeEscalation":false,"capabilities":{"drop":["ALL"]},"runAsNonRoot":true,"runAsUser":1000}` | Container-level securityContext for the certgen hook Jobs. Defaults satisfy the Kubernetes Restricted Pod Security Standard. |
| pkiInitJob.serverDnsNames | list | `[]` | Extra DNS SANs to append to the server certificate. |
| pkiInitJob.serverIpAddresses | list | `[]` | Extra IP SANs to append to the server certificate. |
| pkiInitJob.timeoutSeconds | int | `120` | Maximum time in seconds for the certgen hook to poll for cert-manager certificates. When using cert-manager with BackendTLSPolicy, the hook polls for this many seconds waiting for the certificate to be issued, then creates the backend CA ConfigMap. The Job deadline is set to (timeoutSeconds + 30) to allow time for ConfigMap creation and cleanup. Increase this if cert-manager takes longer than 120 seconds to issue certificates. |
Expand Down
18 changes: 10 additions & 8 deletions deploy/helm/openshell/templates/certgen.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -83,15 +83,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.pkiInitJob.podSecurityContext }}
securityContext:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: certgen
image: {{ include "openshell.image" . | quote }}
imagePullPolicy: {{ .Values.gateway.image.pullPolicy | default .Values.global.image.pullPolicy }}
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
{{- toYaml .Values.pkiInitJob.securityContext | nindent 12 }}
env:
- name: POD_NAMESPACE
valueFrom:
Expand Down Expand Up @@ -154,15 +155,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.pkiInitJob.podSecurityContext }}
securityContext:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: certgen
image: {{ include "openshell.image" . | quote }}
imagePullPolicy: {{ .Values.gateway.image.pullPolicy | default .Values.global.image.pullPolicy }}
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
{{- toYaml .Values.pkiInitJob.securityContext | nindent 12 }}
env:
- name: POD_NAMESPACE
valueFrom:
Expand Down
44 changes: 44 additions & 0 deletions deploy/helm/openshell/tests/certgen_test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,50 @@ tests:
content: "--jwt-secret-name=custom-jwt-keys"
documentIndex: 3

- it: satisfies the Restricted Pod Security Standard by default
template: templates/certgen.yaml
asserts:
- equal:
path: spec.template.spec.securityContext.seccompProfile.type
value: RuntimeDefault
documentIndex: 3
- equal:
path: spec.template.spec.containers[0].securityContext.runAsNonRoot
value: true
documentIndex: 3
- equal:
path: spec.template.spec.containers[0].securityContext.allowPrivilegeEscalation
value: false
documentIndex: 3
- equal:
path: spec.template.spec.containers[0].securityContext.capabilities.drop
value: ["ALL"]
documentIndex: 3

- it: allows overriding the certgen hook security context
template: templates/certgen.yaml
set:
pkiInitJob.podSecurityContext:
seccompProfile:
type: Localhost
localhostProfile: profiles/certgen.json
pkiInitJob.securityContext:
runAsNonRoot: true
runAsUser: 2000
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
asserts:
- equal:
path: spec.template.spec.securityContext.seccompProfile.type
value: Localhost
documentIndex: 3
- equal:
path: spec.template.spec.containers[0].securityContext.runAsUser
value: 2000
documentIndex: 3

- it: renders JWT-only hook when cert-manager is enabled even if pkiInitJob remains enabled
template: templates/certgen.yaml
set:
Expand Down
14 changes: 14 additions & 0 deletions deploy/helm/openshell/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -552,6 +552,20 @@ pkiInitJob:
# see "TLS error: Secret is not supplied by SDS" when connecting to the gateway,
# check if the TLS secret exists and run `helm upgrade` to create the ConfigMap.
failOnTimeout: true
# -- Pod-level securityContext for the certgen hook Jobs. Defaults satisfy the
# Kubernetes Restricted Pod Security Standard.
podSecurityContext:
seccompProfile:
type: RuntimeDefault
# -- Container-level securityContext for the certgen hook Jobs. Defaults
# satisfy the Kubernetes Restricted Pod Security Standard.
securityContext:
runAsNonRoot: true
runAsUser: 1000
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL

# cert-manager Certificate/Issuer resources (requires cert-manager CRDs in-cluster).
# Does not install cert-manager itself.
Expand Down
Loading