2021-08-05 03:15:26 +00:00
|
|
|
package pki
|
|
|
|
|
|
|
|
import (
|
|
|
|
"io"
|
|
|
|
"text/template"
|
|
|
|
|
|
|
|
"github.com/pkg/errors"
|
2021-08-06 21:58:03 +00:00
|
|
|
"github.com/smallstep/certificates/authority"
|
2021-08-05 03:15:26 +00:00
|
|
|
authconfig "github.com/smallstep/certificates/authority/config"
|
|
|
|
"github.com/smallstep/certificates/authority/provisioner"
|
2021-10-27 23:11:47 +00:00
|
|
|
"github.com/smallstep/certificates/templates"
|
2021-08-05 03:15:26 +00:00
|
|
|
"go.step.sm/linkedca"
|
|
|
|
)
|
|
|
|
|
|
|
|
type helmVariables struct {
|
2021-08-06 21:58:03 +00:00
|
|
|
*linkedca.Configuration
|
2021-08-26 17:20:16 +00:00
|
|
|
Defaults *linkedca.Defaults
|
|
|
|
Password string
|
|
|
|
EnableSSH bool
|
2022-09-29 13:08:32 +00:00
|
|
|
EnableAdmin bool
|
2021-08-05 03:15:26 +00:00
|
|
|
TLS authconfig.TLSOptions
|
|
|
|
Provisioners []provisioner.Interface
|
|
|
|
}
|
|
|
|
|
2021-10-27 18:50:55 +00:00
|
|
|
// WriteHelmTemplate a helm template to configure the
|
|
|
|
// smallstep/step-certificates helm chart.
|
2021-08-05 03:15:26 +00:00
|
|
|
func (p *PKI) WriteHelmTemplate(w io.Writer) error {
|
2021-10-27 23:11:47 +00:00
|
|
|
tmpl, err := template.New("helm").Funcs(templates.StepFuncMap()).Parse(helmTemplate)
|
2021-08-05 03:15:26 +00:00
|
|
|
if err != nil {
|
|
|
|
return errors.Wrap(err, "error writing helm template")
|
|
|
|
}
|
|
|
|
|
|
|
|
// Delete ssh section if it is not enabled
|
|
|
|
if !p.options.enableSSH {
|
|
|
|
p.Ssh = nil
|
|
|
|
}
|
|
|
|
|
2021-08-06 21:58:03 +00:00
|
|
|
// Convert provisioner to ca.json
|
2022-09-29 13:08:32 +00:00
|
|
|
numberOfProvisioners := len(p.Authority.Provisioners)
|
|
|
|
if p.options.enableACME {
|
|
|
|
numberOfProvisioners++
|
|
|
|
}
|
|
|
|
provisioners := make([]provisioner.Interface, numberOfProvisioners)
|
2021-08-06 21:58:03 +00:00
|
|
|
for i, p := range p.Authority.Provisioners {
|
|
|
|
pp, err := authority.ProvisionerToCertificates(p)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
provisioners[i] = pp
|
|
|
|
}
|
|
|
|
|
2022-09-29 13:08:32 +00:00
|
|
|
// Add default ACME provisioner if enabled. Note that this logic is similar
|
|
|
|
// to what's in p.GenerateConfig(), but that codepath isn't taken when
|
|
|
|
// writing the Helm template. The default JWK provisioner is added earlier in
|
|
|
|
// the process and that's part of the provisioners above.
|
|
|
|
// TODO(hs): consider refactoring the initialization, so that this becomes
|
|
|
|
// easier to reason about and maintain.
|
|
|
|
if p.options.enableACME {
|
|
|
|
provisioners[len(provisioners)-1] = &provisioner.ACME{
|
|
|
|
Type: "ACME",
|
|
|
|
Name: "acme",
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-10-14 11:52:27 +00:00
|
|
|
// TODO(hs): add default SSHPOP provisioner if SSH is configured, similar
|
|
|
|
// as the ACME one above.
|
|
|
|
|
2021-08-05 03:15:26 +00:00
|
|
|
if err := tmpl.Execute(w, helmVariables{
|
2021-08-06 21:58:03 +00:00
|
|
|
Configuration: &p.Configuration,
|
|
|
|
Defaults: &p.Defaults,
|
|
|
|
Password: "",
|
2021-08-26 17:20:16 +00:00
|
|
|
EnableSSH: p.options.enableSSH,
|
2022-09-29 13:08:32 +00:00
|
|
|
EnableAdmin: p.options.enableAdmin,
|
2021-08-05 03:15:26 +00:00
|
|
|
TLS: authconfig.DefaultTLSOptions,
|
2021-08-06 21:58:03 +00:00
|
|
|
Provisioners: provisioners,
|
2021-08-05 03:15:26 +00:00
|
|
|
}); err != nil {
|
|
|
|
return errors.Wrap(err, "error executing helm template")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
const helmTemplate = `# Helm template
|
|
|
|
inject:
|
|
|
|
enabled: true
|
|
|
|
# Config contains the configuration files ca.json and defaults.json
|
|
|
|
config:
|
|
|
|
files:
|
|
|
|
ca.json:
|
|
|
|
root: {{ first .Root }}
|
|
|
|
federateRoots: []
|
|
|
|
crt: {{ .Intermediate }}
|
|
|
|
key: {{ .IntermediateKey }}
|
2022-05-04 23:10:59 +00:00
|
|
|
{{- if .Kms }}
|
|
|
|
kms:
|
|
|
|
type: {{ lower (.Kms.Type | toString) }}
|
|
|
|
{{- end }}
|
2021-08-26 17:20:16 +00:00
|
|
|
{{- if .EnableSSH }}
|
2021-08-05 03:15:26 +00:00
|
|
|
ssh:
|
|
|
|
hostKey: {{ .Ssh.HostKey }}
|
|
|
|
userKey: {{ .Ssh.UserKey }}
|
|
|
|
{{- end }}
|
|
|
|
address: {{ .Address }}
|
|
|
|
dnsNames:
|
|
|
|
{{- range .DnsNames }}
|
|
|
|
- {{ . }}
|
|
|
|
{{- end }}
|
|
|
|
logger:
|
|
|
|
format: json
|
|
|
|
db:
|
2021-09-17 19:49:16 +00:00
|
|
|
type: badgerv2
|
2021-08-05 03:15:26 +00:00
|
|
|
dataSource: /home/step/db
|
|
|
|
authority:
|
2022-09-29 13:08:32 +00:00
|
|
|
enableAdmin: {{ .EnableAdmin }}
|
2021-08-05 03:15:26 +00:00
|
|
|
provisioners:
|
|
|
|
{{- range .Provisioners }}
|
|
|
|
- {{ . | toJson }}
|
|
|
|
{{- end }}
|
|
|
|
tls:
|
|
|
|
cipherSuites:
|
|
|
|
{{- range .TLS.CipherSuites }}
|
|
|
|
- {{ . }}
|
|
|
|
{{- end }}
|
|
|
|
minVersion: {{ .TLS.MinVersion }}
|
|
|
|
maxVersion: {{ .TLS.MaxVersion }}
|
|
|
|
renegotiation: {{ .TLS.Renegotiation }}
|
|
|
|
|
|
|
|
defaults.json:
|
|
|
|
ca-url: {{ .Defaults.CaUrl }}
|
|
|
|
ca-config: {{ .Defaults.CaConfig }}
|
|
|
|
fingerprint: {{ .Defaults.Fingerprint }}
|
|
|
|
root: {{ .Defaults.Root }}
|
|
|
|
|
|
|
|
# Certificates contains the root and intermediate certificate and
|
|
|
|
# optionally the SSH host and user public keys
|
|
|
|
certificates:
|
|
|
|
# intermediate_ca contains the text of the intermediate CA Certificate
|
|
|
|
intermediate_ca: |
|
|
|
|
{{- index .Files .Intermediate | toString | nindent 6 }}
|
|
|
|
|
|
|
|
# root_ca contains the text of the root CA Certificate
|
|
|
|
root_ca: |
|
|
|
|
{{- first .Root | index .Files | toString | nindent 6 }}
|
|
|
|
|
|
|
|
{{- if .Ssh }}
|
|
|
|
# ssh_host_ca contains the text of the public ssh key for the SSH root CA
|
|
|
|
ssh_host_ca: {{ index .Files .Ssh.HostPublicKey | toString }}
|
|
|
|
|
|
|
|
# ssh_user_ca contains the text of the public ssh key for the SSH root CA
|
|
|
|
ssh_user_ca: {{ index .Files .Ssh.UserPublicKey | toString }}
|
|
|
|
{{- end }}
|
|
|
|
|
|
|
|
# Secrets contains the root and intermediate keys and optionally the SSH
|
|
|
|
# private keys
|
|
|
|
secrets:
|
|
|
|
# ca_password contains the password used to encrypt x509.intermediate_ca_key, ssh.host_ca_key and ssh.user_ca_key
|
|
|
|
# This value must be base64 encoded.
|
|
|
|
ca_password: {{ .Password | b64enc }}
|
|
|
|
provisioner_password: {{ .Password | b64enc}}
|
|
|
|
|
|
|
|
x509:
|
|
|
|
# intermediate_ca_key contains the contents of your encrypted intermediate CA key
|
|
|
|
intermediate_ca_key: |
|
|
|
|
{{- index .Files .IntermediateKey | toString | nindent 8 }}
|
|
|
|
|
|
|
|
# root_ca_key contains the contents of your encrypted root CA key
|
|
|
|
# Note that this value can be omitted without impacting the functionality of step-certificates
|
|
|
|
# If supplied, this should be encrypted using a unique password that is not used for encrypting
|
|
|
|
# the intermediate_ca_key, ssh.host_ca_key or ssh.user_ca_key.
|
|
|
|
root_ca_key: |
|
|
|
|
{{- first .RootKey | index .Files | toString | nindent 8 }}
|
|
|
|
|
|
|
|
{{- if .Ssh }}
|
|
|
|
ssh:
|
|
|
|
# ssh_host_ca_key contains the contents of your encrypted SSH Host CA key
|
|
|
|
host_ca_key: |
|
|
|
|
{{- index .Files .Ssh.HostKey | toString | nindent 8 }}
|
|
|
|
|
|
|
|
# ssh_user_ca_key contains the contents of your encrypted SSH User CA key
|
|
|
|
user_ca_key: |
|
|
|
|
{{- index .Files .Ssh.UserKey | toString | nindent 8 }}
|
|
|
|
{{- end }}
|
|
|
|
`
|