Compare commits
15 Commits
v0.6.1
...
Lerentis/i
Author | SHA1 | Date | |
---|---|---|---|
6f099c4bf2
|
|||
aa015cc7ba | |||
2de9bbb0bf | |||
4505f3985c | |||
82b684e460 | |||
8ec698f50e | |||
9b8fe1d8ef | |||
516f2a34cf | |||
361d0866e9
|
|||
9d4ade904e
|
|||
8c3714f7e0
|
|||
36ae5cc602
|
|||
d908419b78
|
|||
2d399ff8ce
|
|||
c753737497
|
2
.github/workflows/release.yml
vendored
2
.github/workflows/release.yml
vendored
@ -36,7 +36,7 @@ jobs:
|
||||
CR_TOKEN: "${{ secrets.GITHUB_TOKEN }}"
|
||||
|
||||
- name: Get app version from chart
|
||||
uses: mikefarah/yq@v4.33.3
|
||||
uses: mikefarah/yq@v4.34.1
|
||||
id: app_version
|
||||
with:
|
||||
cmd: yq '.appVersion' charts/bitwarden-crd-operator/Chart.yaml
|
||||
|
55
.github/workflows/test-and-lint.yml
vendored
Normal file
55
.github/workflows/test-and-lint.yml
vendored
Normal file
@ -0,0 +1,55 @@
|
||||
name: Lint and Test
|
||||
|
||||
on: pull_request
|
||||
|
||||
jobs:
|
||||
lint-test:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v3
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Set up Helm
|
||||
uses: azure/setup-helm@v3
|
||||
with:
|
||||
version: v3.11.2
|
||||
|
||||
- uses: actions/setup-python@v4
|
||||
with:
|
||||
python-version: '3.9'
|
||||
check-latest: true
|
||||
|
||||
- name: Set up chart-testing
|
||||
uses: helm/chart-testing-action@v2.4.0
|
||||
|
||||
- name: Run chart-testing (list-changed)
|
||||
id: list-changed
|
||||
run: |
|
||||
changed=$(ct list-changed --target-branch ${{ github.event.repository.default_branch }})
|
||||
if [[ -n "$changed" ]]; then
|
||||
echo "changed=true" >> "$GITHUB_OUTPUT"
|
||||
fi
|
||||
|
||||
- name: Run chart-testing (lint)
|
||||
if: steps.list-changed.outputs.changed == 'true'
|
||||
run: ct lint --target-branch ${{ github.event.repository.default_branch }}
|
||||
|
||||
pr-build:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v2
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v2
|
||||
|
||||
- name: "GHCR Build"
|
||||
id: docker_build
|
||||
uses: docker/build-push-action@v4
|
||||
with:
|
||||
push: false
|
||||
platforms: linux/amd64,linux/arm64
|
||||
tags: ghcr.io/lerentis/bitwarden-crd-operator:dev
|
||||
|
4
.gitignore
vendored
4
.gitignore
vendored
@ -165,4 +165,6 @@ include
|
||||
lib
|
||||
lib64
|
||||
|
||||
myvalues.yaml
|
||||
myvalues.yaml
|
||||
|
||||
.vscode
|
49
Dockerfile
49
Dockerfile
@ -1,34 +1,45 @@
|
||||
FROM alpine:latest as builder
|
||||
|
||||
ARG BW_VERSION=2023.1.0
|
||||
|
||||
RUN apk add wget unzip
|
||||
|
||||
RUN cd /tmp && wget https://github.com/bitwarden/clients/releases/download/cli-v${BW_VERSION}/bw-linux-${BW_VERSION}.zip && \
|
||||
unzip /tmp/bw-linux-${BW_VERSION}.zip
|
||||
|
||||
FROM alpine:3.17.3
|
||||
FROM alpine:3.18.0
|
||||
|
||||
LABEL org.opencontainers.image.source=https://github.com/Lerentis/bitwarden-crd-operator
|
||||
LABEL org.opencontainers.image.description="Kubernetes Operator to create k8s secrets from bitwarden"
|
||||
LABEL org.opencontainers.image.licenses=MIT
|
||||
|
||||
ARG PYTHON_VERSION=3.10.11-r0
|
||||
ARG PIP_VERSION=22.3.1-r1
|
||||
ARG GCOMPAT_VERSION=1.1.0-r0
|
||||
ARG LIBCRYPTO_VERSION=3.0.8-r4
|
||||
ARG PYTHON_VERSION=3.11.4-r0
|
||||
ARG PIP_VERSION=23.1.2-r0
|
||||
ARG GCOMPAT_VERSION=1.1.0-r1
|
||||
ARG LIBCRYPTO_VERSION=3.1.0-r4
|
||||
ARG BW_VERSION=2023.1.0
|
||||
|
||||
COPY --from=builder /tmp/bw /usr/local/bin/bw
|
||||
COPY requirements.txt requirements.txt
|
||||
COPY requirements.txt /requirements.txt
|
||||
|
||||
RUN set -eux; \
|
||||
apk add --virtual build-dependencies wget unzip; \
|
||||
ARCH="$(apk --print-arch)"; \
|
||||
case "${ARCH}" in \
|
||||
aarch64|arm64) \
|
||||
apk add npm; \
|
||||
npm install -g @bitwarden/cli@${BW_VERSION}; \
|
||||
;; \
|
||||
amd64|x86_64) \
|
||||
cd /tmp; \
|
||||
wget https://github.com/bitwarden/clients/releases/download/cli-v${BW_VERSION}/bw-linux-${BW_VERSION}.zip; \
|
||||
unzip /tmp/bw-linux-${BW_VERSION}.zip; \
|
||||
mv /tmp/bw /usr/local/bin/bw; \
|
||||
chmod +x /usr/local/bin/bw; \
|
||||
;; \
|
||||
*) \
|
||||
echo "Unsupported arch: ${ARCH}"; \
|
||||
exit 1; \
|
||||
;; \
|
||||
esac; \
|
||||
apk del --purge build-dependencies; \
|
||||
addgroup -S -g 1000 bw-operator; \
|
||||
adduser -S -D -u 1000 -G bw-operator bw-operator; \
|
||||
mkdir -p /home/bw-operator; \
|
||||
chown -R bw-operator /home/bw-operator; \
|
||||
chmod +x /usr/local/bin/bw; \
|
||||
apk add gcc musl-dev libstdc++ gcompat=${GCOMPAT_VERSION} python3=${PYTHON_VERSION} py3-pip=${PIP_VERSION} libcrypto3=${LIBCRYPTO_VERSION} libssl3=${LIBCRYPTO_VERSION}; \
|
||||
pip install -r requirements.txt --no-warn-script-location; \
|
||||
apk add gcc musl-dev libstdc++ gcompat=${GCOMPAT_VERSION} python3=${PYTHON_VERSION} py3-pip=${PIP_VERSION} libcrypto3=${LIBCRYPTO_VERSION}; \
|
||||
pip install -r /requirements.txt --no-warn-script-location; \
|
||||
rm /requirements.txt; \
|
||||
apk del --purge gcc musl-dev libstdc++;
|
||||
|
||||
COPY --chown=bw-operator:bw-operator src /home/bw-operator
|
||||
|
@ -4,9 +4,9 @@ description: Deploy the Bitwarden CRD Operator
|
||||
|
||||
type: application
|
||||
|
||||
version: "v0.7.1"
|
||||
version: "v0.7.4"
|
||||
|
||||
appVersion: "0.6.1"
|
||||
appVersion: "0.6.4"
|
||||
|
||||
keywords:
|
||||
- operator
|
||||
@ -20,7 +20,7 @@ home: https://lerentis.github.io/bitwarden-crd-operator/
|
||||
sources:
|
||||
- https://github.com/Lerentis/bitwarden-crd-operator
|
||||
|
||||
kubeVersion: '>= 1.23.0-0'
|
||||
kubeVersion: ">= 1.23.0-0"
|
||||
|
||||
maintainers:
|
||||
- name: lerentis
|
||||
@ -55,10 +55,10 @@ annotations:
|
||||
content:
|
||||
- element:
|
||||
secretName: username
|
||||
secretRef: nameofUser
|
||||
secretRef: nameofUser
|
||||
- element:
|
||||
secretName: password
|
||||
secretRef: passwordOfUser
|
||||
secretRef: passwordOfUser
|
||||
id: "aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee"
|
||||
name: "test-secret"
|
||||
namespace: "default"
|
||||
@ -90,15 +90,13 @@ annotations:
|
||||
apps:
|
||||
"some.app.identifier:some_version":
|
||||
pubkey: {{ bitwarden_lookup("aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee", "fields", "public_key") }}
|
||||
enabled: true
|
||||
enabled: true
|
||||
artifacthub.io/license: MIT
|
||||
artifacthub.io/operator: "true"
|
||||
artifacthub.io/containsSecurityUpdates: "true"
|
||||
artifacthub.io/operator: "true"
|
||||
artifacthub.io/containsSecurityUpdates: "false"
|
||||
artifacthub.io/changes: |
|
||||
- kind: fixed
|
||||
description: "Fixed fields lookup"
|
||||
- kind: fixed
|
||||
description: "Fixed CVE-2023-1255 in base image"
|
||||
description: "Fixed bitwarden installation"
|
||||
artifacthub.io/images: |
|
||||
- name: bitwarden-crd-operator
|
||||
image: ghcr.io/lerentis/bitwarden-crd-operator:0.6.1
|
||||
image: ghcr.io/lerentis/bitwarden-crd-operator:0.6.4
|
||||
|
@ -14,15 +14,15 @@ imagePullSecrets: []
|
||||
nameOverride: ""
|
||||
fullnameOverride: ""
|
||||
|
||||
#env:
|
||||
# - name: BW_HOST
|
||||
# value: "define_it"
|
||||
# - name: BW_CLIENTID
|
||||
# value: "define_it"
|
||||
# - name: BW_CLIENTSECRET
|
||||
# value: "define_it"
|
||||
# - name: BW_PASSWORD
|
||||
# value: "define_id"
|
||||
# env:
|
||||
# - name: BW_HOST
|
||||
# value: "define_it"
|
||||
# - name: BW_CLIENTID
|
||||
# value: "define_it"
|
||||
# - name: BW_CLIENTSECRET
|
||||
# value: "define_it"
|
||||
# - name: BW_PASSWORD
|
||||
# value: "define_id"
|
||||
|
||||
externalConfigSecret:
|
||||
enabled: false
|
||||
|
@ -32,9 +32,9 @@ def command_wrapper(logger, command, use_success: bool = True):
|
||||
shell=True,
|
||||
env=system_env)
|
||||
out, err = sp.communicate()
|
||||
resp = json.loads(out.decode(encoding='UTF-8'))
|
||||
if "DEBUG" in system_env:
|
||||
logger.info(resp)
|
||||
logger.info(out.decode(encoding='UTF-8'))
|
||||
resp = json.loads(out.decode(encoding='UTF-8'))
|
||||
if resp["success"] != None and (not use_success or (use_success and resp["success"] == True)):
|
||||
return resp
|
||||
logger.warn(resp)
|
||||
|
Reference in New Issue
Block a user