Commit Graph
462 Commits
Author SHA1 Message Date
Periklis Tsirakidis a1f63b953d Use vault api and sdk modules instead of tagged repo
Signed-off-by: Periklis Tsirakidis <periklis@nefeli.eu>
2020-01-20 12:27:09 +01:00
jetstack-botandGitHub 5ee9e6c7aa Merge pull request #2452 from munnerz/kubernetes-1.17.0
Bump Kubernetes dependencies to v0.17.0
2020-01-14 14:19:57 +00:00
Daniel 6a775423c3 Use upstream Pebble v2.3.0 for E2E tests.
This is a follow-up from 0f196a5 which temporarily switched the Pebble
image to a fork. The required functionality landed in the upstream
v2.3.0 release and so the E2E tests can be switched back to the
upstream repo.

Signed-off-by: Daniel McCarney <cpu@letsencrypt.org>
2019-12-18 15:05:02 -05:00
James Munnelly b50f0a983a Fix issue using new apiserver lib with older Kubernetes
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-17 17:14:42 +00:00
James Munnelly 4930a0e8d8 Add end-to-end tests using EAB
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-11 12:28:49 +00:00
James Munnelly 0f196a57dc Use forked pebble with support for EABs
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-11 12:28:49 +00:00
James Munnelly dc95d9597d Upgrade to Pebble containing letsencrypt/pebble#294
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-05 12:22:50 +00:00
jetstack-botandGitHub 1581bf2796 Merge pull request #2400 from JoshVanL/secret-annotation-fallback
Allow secrets with legacy annotations for issuer name and kind to match
2019-11-27 15:39:22 +00:00
JoshVanL 0d9d0eeb22 Allow secrets with legacy annotations for issuer name and kind to match
existing certificates

Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-26 12:13:58 +00:00
Matevz Mihalic b5972a379f Add API token auth option to Cloudflare issuer
Signed-off-by: Matevz Mihalic <matevz.mihalic@gmail.com>
2019-11-18 17:51:43 +01:00
JoshVanL b72e8341df Correctly wait for issue on e2e tests
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-13 14:36:31 +00:00
JoshVanL 0645bb6769 Use cloud flare service account in cluster namespace when using cluster
issuer

Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-13 11:03:12 +00:00
JoshVanL f03cf45a9e Generate Name on e2e secret names and clean up
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-13 11:03:12 +00:00
JoshVanL d57cd5a6c7 Sets all conformance issuers to have generate name
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-13 11:02:43 +00:00
JoshVanL 854c67d718 Ensure ClusterIssuer is deleted after tests
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-13 11:02:43 +00:00
JoshVanL 56a40ddba7 Adds cluster issuer tests for all conformance issuer suites
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-13 11:02:43 +00:00
JoshVanL dfaf2f20c2 Initialise e2e vault issuer secret namespace before each
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-13 11:02:43 +00:00
JoshVanL d6248d20bd Make vault issuer to point to resource namespace over certificaterequest
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-13 11:02:43 +00:00
jetstack-botandGitHub 4bc4844f27 Merge pull request #2355 from JoshVanL/disable-api-service-ca-injector
Disables API Service cainjector.go e2e test
2019-11-13 10:22:26 +00:00
jetstack-botandGitHub 1bfec37482 Merge pull request #2349 from JoshVanL/2205-kubernetes-auth-path
Changes the vault issuer Kubernetes auth path to require the full *mount* path
2019-11-13 09:58:26 +00:00
JoshVanL ee196a4578 Disables API Service cainjector.go e2e test
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-12 20:55:00 +00:00
JoshVanL 0e739bdde9 Mount path now hard codes /login endpoint in code
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-12 18:37:54 +00:00
JoshVanL 836800d1e7 Correctly de-duplicate ext key usages in e2e tests
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-11 14:34:45 +00:00
JoshVanL b3c301dfd4 De-duplicate ext key usages is e2e tests getting defaults
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-11 13:18:30 +00:00
JoshVanL 7ec3103eb4 Changes the vault issuer Kubernetes auth path to require the full path
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-11 12:49:02 +00:00
jetstack-botandGitHub d3254e3843 Merge pull request #2260 from JoshVanL/2247-cert-key-usages
Ensure key usages are set on CertificateRequests created by the Certificate controller
2019-11-07 17:14:34 +00:00
JoshVanL 2f91506565 Move vault issuer cleanup to JsutAfterEach
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-05 19:08:35 +00:00
JoshVanL b4e62d0fce Increase vault health timeout try
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-05 17:59:38 +00:00
JoshVanL 50d9b1f038 Ignore key encipherment of e2e tests when key is EC
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-05 15:23:51 +00:00
JoshVanL b2337cdf9e Creates a proper wrapper for vault port-forwarding to keep it alive and
healthy

Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-05 14:23:23 +00:00
JoshVanL 206c4a3909 Ensure no ECDSA keys have key enrichment expected for e2e
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-05 14:22:25 +00:00
JoshVanL 9c2a37fbfd Remove key encipherment for DNS01 ACME ECDSA certs
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-05 14:22:25 +00:00
JoshVanL 2bb8bfe07a Adds server auth to Venafi default key usages
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-05 14:22:25 +00:00
JoshVanL 48afefbeb4 Adds key usage exceptions for vault in e2e tests
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-05 14:22:25 +00:00
JoshVanL 78196cffe5 If certificate uses Vault or ACME issuer then add server/client auth key
usages as expected

Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-05 14:22:25 +00:00
JoshVanL 192566d789 Adds conversion for key usage int to string
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-05 14:22:25 +00:00
JoshVanL fca395bb4d Expose non-matching key-usages with string
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-05 14:22:25 +00:00
JoshVanL a03560b93a Updates tests to ensure that key usages are correctly checked
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-05 14:22:25 +00:00
JoshVanL bca6ebc520 Ensure key usages are set on CertificateRequests created by the
Certificate controller

Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-11-05 14:22:25 +00:00
James Munnelly df30a1fc6d Bump Helm and Tiller to 2.15.1
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-10-24 12:54:24 +01:00
James Munnelly 2138dde7c3 Run a single instance of Pebble during the e2e suite
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-10-16 21:48:58 +01:00
James Munnelly 0472ac4f09 Print 'kubectl apply' output during e2e tests
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-10-11 11:05:26 +01:00
James Munnelly 6138f0c3c4 Fix e2e jobs on Kubernetes 1.14 and below
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-10-10 18:36:19 +01:00
jetstack-botandGitHub d9043e512f Merge pull request #2179 from JoshVanL/fix-e2e-cnf-test-name
Fix name of a conformance test
2019-10-09 16:32:35 +01:00
JoshVanL 0865c9cd02 Fix name of a conformance test
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-10-09 14:30:44 +01:00
James Munnelly 5ec4bd1b09 Skip Venafi conformance tests
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-10-09 12:52:47 +01:00
JoshVanL 7965be9b41 Adds from comments
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-10-02 17:48:37 +01:00
JoshVanL b6bce10b2f Adds CommonName e2e tests for new behaviour
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-10-02 17:48:37 +01:00
JoshVanL e64d0a26be Add allowed URI names to e2e test vault server
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-10-02 17:48:37 +01:00
JoshVanL 15fccf9ebb Adds describe CertificateRequest in tests when waiting for valid
certificate fails and enable no CommonName for vault server

Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com>
2019-10-02 17:48:37 +01:00