diff --git a/k8s/oidc-vault/k8s/ingress.yaml b/k8s/oidc-vault/k8s/ingress.yaml deleted file mode 100644 index 1f17a9d..0000000 --- a/k8s/oidc-vault/k8s/ingress.yaml +++ /dev/null @@ -1,30 +0,0 @@ -apiVersion: networking.k8s.io/v1 -kind: Ingress -metadata: - name: spire-ingress - namespace: spire -spec: - tls: - - hosts: - # TODO: Replace MY_DISCOVERY_DOMAIN with the FQDN of the Discovery Provider that you will configure in DNS - - MY_DISCOVERY_DOMAIN - secretName: oidc-secret - rules: - # TODO: Replace MY_DISCOVERY_DOMAIN with the FQDN of the Discovery Provider that you will configure in DNS - - host: MY_DISCOVERY_DOMAIN - http: - paths: - - path: /.well-known/openid-configuration - pathType: Prefix - backend: - service: - name: spire-oidc - port: - number: 443 - - path: /keys - pathType: Prefix - backend: - service: - name: spire-oidc - port: - number: 443 diff --git a/k8s/oidc-vault/k8s/oidc-dp-configmap.yaml b/k8s/oidc-vault/k8s/oidc-dp-configmap.yaml index 17c590f..16c204d 100644 --- a/k8s/oidc-vault/k8s/oidc-dp-configmap.yaml +++ b/k8s/oidc-vault/k8s/oidc-dp-configmap.yaml @@ -7,7 +7,7 @@ data: oidc-discovery-provider.conf: | log_level = "INFO" # TODO: Replace MY_DISCOVERY_DOMAIN with the FQDN of the Discovery Provider that you will configure in DNS - domain = "MY_DISCOVERY_DOMAIN" + domains = ["MY_DISCOVERY_DOMAIN"] acme { directory_url = "https://acme-v02.api.letsencrypt.org/directory" cache_dir = "/run/spire" diff --git a/k8s/oidc-vault/k8s/server-statefulset.yaml b/k8s/oidc-vault/k8s/server-statefulset.yaml index d9b11ee..cd646cb 100644 --- a/k8s/oidc-vault/k8s/server-statefulset.yaml +++ b/k8s/oidc-vault/k8s/server-statefulset.yaml @@ -52,7 +52,7 @@ spec: initialDelaySeconds: 5 periodSeconds: 5 - name: spire-oidc - image: ghcr.io/spiffe/oidc-discovery-provider:1.5.1 + image: ghcr.io/spiffe/oidc-discovery-provider:1.5.3 args: - -config - /run/spire/oidc/config/oidc-discovery-provider.conf @@ -71,7 +71,7 @@ spec: readOnly: false readinessProbe: httpGet: - path: /keys # TODO: Change this to /ready when using 1.5.2+ + path: /ready port: 8008 failureThreshold: 5 initialDelaySeconds: 5