Critical fixes: - F-01: SatScope array form support (single pointer → slice with polymorphic JSON) - F-02: Add governance-intent@guildhouse.dev as 10th Shellstream extension - F-06: Replace os.Exit(1) stubs with go-plugin Serve() boilerplate in all cmd/ - F-13: Validate SatScope.ResourcePattern is non-empty High priority: - F-03: Add normative Accord policy syntax note to credential-governance.md §8.2 - F-04: Replace OID XXXXX placeholder with explicit PEN reference and IANA TODO - F-05: Document CredentialComposer hook mapping in spec and plugin-types.md - F-07/F-08: Commit CI pipeline (.github/workflows/ci.yaml) - F-09: Add hashicorp/go-plugin v1.6.3 to go.mod Medium priority: - F-10: Wire sample-ssh-cert-extensions.json fixture into shellstream tests - F-11: Cross-reference merkle proof depth limit (256 leaves) in governance spec - F-12: Add YAML format clarification headers to deploy configs - F-14: Expand README with project status, docs links, and quick-start Low priority: - F-15: Standardize "SSH SVID" → "SSH-SVID" terminology across docs - F-16: Add GovernanceEpochSeconds to PluginConfig and deploy configs - F-17: Add troubleshooting section to deployment.md, error handling to OIDC docs Global: Rename all extension keys from @guildhouse.io to @guildhouse.dev Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
41 lines
1.3 KiB
YAML
41 lines
1.3 KiB
YAML
# SPIRE Agent configuration with Guildhouse OIDC Attestor plugin.
|
|
#
|
|
# FORMAT NOTE: This file uses YAML for readability as a reference document.
|
|
# SPIRE natively uses HCL configuration format. To use this with SPIRE, convert
|
|
# to HCL syntax or use a SPIRE version that supports YAML config (v1.9+).
|
|
# See docs/deployment.md for HCL configuration examples.
|
|
#
|
|
# This is a reference configuration — adapt paths and addresses for your cluster.
|
|
# See docs/deployment.md for full deployment instructions.
|
|
|
|
agent:
|
|
data_dir: /var/lib/spire/agent
|
|
log_level: INFO
|
|
server_address: spire-server.spire.svc.cluster.local
|
|
server_port: 8081
|
|
socket_path: /run/spire/sockets/agent.sock
|
|
trust_domain: guildhouse.example.org
|
|
|
|
plugins:
|
|
NodeAttestor:
|
|
k8s_psat:
|
|
plugin_data:
|
|
cluster: guildhouse
|
|
|
|
KeyManager:
|
|
memory:
|
|
plugin_data: {}
|
|
|
|
WorkloadAttestor:
|
|
# Standard Kubernetes workload attestation.
|
|
k8s:
|
|
plugin_data:
|
|
skip_kubelet_verification: false
|
|
|
|
# Guildhouse OIDC attestation — verifies workload OIDC tokens.
|
|
guildhouse_oidc:
|
|
plugin_cmd: /opt/spire/plugins/oidc-attestor
|
|
plugin_data:
|
|
issuer: https://keycloak.guildhouse.example.org/realms/platform
|
|
audience: spire
|
|
token_path: /var/run/secrets/oidc/token
|