Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add systemd example #64

Merged
merged 13 commits into from
Jul 17, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,12 @@ Examples showing how to deploy SPIRE on Amazon EKS.
+ [EKS-based SAT with SPIRE 1.5.1](examples/k8s/eks_sat) - This slightly modifies the **Kubernetes Simple SAT** configuration to
make it compatible with EKS platform.

## SystemD

Examples showing how to start up SPIRE services using SystemD

* [SystemD](examples/systemd) SPIRE services managed by SystemD

## Getting Help

If you have any questions on the above examples, or anything else related to deploying or maintaining SPIRE, please feel free to either [open an issue](https://github.com/spiffe/spire-examples/issues/new) or ask in #help on our [Slack](https://slack.spiffe.io/).
9 changes: 9 additions & 0 deletions examples/systemd/Makefile
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
default:
@echo Targets:
@echo " install"

install:
mkdir -p $(DESTDIR)/usr/lib/systemd/system/
install system/* $(DESTDIR)/usr/lib/systemd/system/
([ ! -f $(DESTDIR)/etc/spire/agent/main.conf ] && mkdir -p $(DESTDIR)/etc/spire/agent && install conf/agent/main.conf $(DESTDIR)/etc/spire/agent/main.conf) || true
([ ! -f $(DESTDIR)/etc/spire/server/main.conf ] && mkdir -p $(DESTDIR)/etc/spire/server && install conf/server/main.conf $(DESTDIR)/etc/spire/server/main.conf) || true
48 changes: 48 additions & 0 deletions examples/systemd/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
# SPIRE services managed by SystemD

To install, download the newest spire-server and spire-agent binaries from the SPIRE website and place in /bin
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think that it would be nice to have a title for this document.


Run:
```
make install
```

Edit /etc/spire/server/main.conf and update with settings as needed.

Enable the main server:

```
systemctl enable spire-server@main
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Does the "@main" have any benefit here? I'd keep it simple and not have these parameterized

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah. It lets you have multiple servers/agents. Either for nesting or redundancy. I do plan on using both.

```

Start the main server:

```
systemctl start spire-server@main
```


# Create a join token
```
spire-server token generate -spiffeID spiffe://example.org/changeme -socketPath /run/spire/server/sockets/main/private/api.sock
```

Edit /etc/spire/agent/main.conf and update with settings as needed, in particular the join token.

Enable the main agent:
Comment on lines +31 to +32
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should also specify how to fetch the join token and how to pass it to the service.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated.


```
systemctl enable spire-agent@main
```

Start the main agent:

```
systemctl start spire-agent@main
```


# Show Entries from the main server
```
spire-server entry show -socketPath /run/spire/server/sockets/main/private/api.sock
```
28 changes: 28 additions & 0 deletions examples/systemd/conf/agent/main.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
agent {
log_level = "DEBUG"
trust_domain = "example.org"
server_address = "localhost"
server_port = 8081

# Insecure bootstrap is NOT appropriate for production use but is ok for
# simple testing/evaluation purposes.
insecure_bootstrap = true

join_token = "cdf1885a-1db8-4a83-aa16-ad8c84761fa8"
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is not the best, but I imagine you want to wait for something like that dns/http pop attestor being available, right?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah, that would be a better default once its available.

This is just an example config file really. Its expected an end user will need to update it to use it properly.

}

plugins {
KeyManager "disk" {
plugin_data {
directory = "./"
}
}

NodeAttestor "join_token" {
plugin_data {}
}

WorkloadAttestor "systemd" {
plugin_data {}
}
Comment on lines +25 to +27
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: could also use the unix attestore here.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, but I think systemd is a better plugin then unix as a default suggestion. Many different services run as root (ssh, apache, kubelet, etc). But each would probably want its own identity. The systemd attestor can tell them apart.

}
27 changes: 27 additions & 0 deletions examples/systemd/conf/server/main.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
server {
bind_address = "127.0.0.1"
bind_port = "8081"
trust_domain = "example.org"
log_level = "DEBUG"
ca_ttl = "168h"
default_x509_svid_ttl = "48h"
}

plugins {
DataStore "sql" {
plugin_data {
database_type = "sqlite3"
connection_string = "./datastore.sqlite3"
}
}

KeyManager "disk" {
plugin_data {
keys_path = "./keys.json"
}
}

NodeAttestor "join_token" {
plugin_data {}
}
}
8 changes: 8 additions & 0 deletions examples/systemd/system/spire-agent.target
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
[Unit]
Description=SPIRE Agent target allowing to start/stop all spire-agent@.service instances at once
PartOf=spire.target
Before=spire.target
Wants=spire.target

[Install]
WantedBy=multi-user.target spire.target
43 changes: 43 additions & 0 deletions examples/systemd/system/spire-agent@.service
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
[Unit]
Description=SPIRE Agent Daemon %i
PartOf=spire-agent.target
After=network-online.target local-fs.target time-sync.target
Before=remote-fs-pre.target spire-agent.target
Wants=network-online.target local-fs.target time-sync.target remote-fs-pre.target spire-agent.target

[Service]
WorkingDirectory=/var/lib/spire/agent/%i
StateDirectory=spire/agent/%i
RuntimeDirectory=spire/agent/sockets/%i
RuntimeDirectoryPreserve=true
ConfigurationDirectory=spire/agent
ExecStart=/bin/spire-agent run -config /etc/spire/agent/%i.conf -dataDir /var/lib/spire/agent/%i -socketPath /run/spire/agent/sockets/%i/public/api.sock -expandEnv
ExecStartPre=mkdir -p /var/lib/spire/agent/%i /run/spire/agent/%i/public
# https://gist.github.com/ageis/f5595e59b1cddb1513d1b425a323db04
LockPersonality=true
MemoryDenyWriteExecute=true
NoNewPrivileges=true
PrivateDevices=false
# Needed by plugins
PrivateTmp=false
ProtectControlGroups=true
ProtectHome=true
ProtectHostname=true
ProtectKernelLogs=true
ProtectKernelModules=true
ProtectKernelTunables=true
ProtectSystem=strict
ReadOnlyPaths=/
ReadWritePaths=/var/lib/spire/agent /run/spire/agent
Restart=on-failure
RestartSec=15
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
RestrictNamespaces=true
RestrictRealtime=yes
RestrictSUIDSGID=yes
StartLimitBurst=3
StartLimitInterval=30min
TasksMax=infinity

[Install]
WantedBy=spire-agent.target
8 changes: 8 additions & 0 deletions examples/systemd/system/spire-server.target
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
[Unit]
Description=SPIRE Server target allowing to start/stop all spire-server@.service instances at once
PartOf=spire.target
Before=spire.target
Wants=spire.target

[Install]
WantedBy=multi-user.target spire.target
43 changes: 43 additions & 0 deletions examples/systemd/system/spire-server@.service
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
[Unit]
Description=SPIRE Server Daemon %i
PartOf=spire-server.target
After=network-online.target local-fs.target time-sync.target
Before=remote-fs-pre.target spire-server.target
Wants=network-online.target local-fs.target time-sync.target remote-fs-pre.target spire-server.target

[Service]
WorkingDirectory=/var/lib/spire/server/%i
StateDirectory=spire/server/%i
RuntimeDirectory=spire/server/sockets/%i
RuntimeDirectoryPreserve=true
ConfigurationDirectory=spire/server
ExecStart=/bin/spire-server run -config /etc/spire/server/%i.conf -dataDir /var/lib/spire/server/%i -socketPath /run/spire/server/sockets/%i/private/api.sock -expandEnv
ExecStartPre=mkdir -p /var/lib/spire/server/%i /run/spire/server/%i/private
# https://gist.github.com/ageis/f5595e59b1cddb1513d1b425a323db04
LockPersonality=true
MemoryDenyWriteExecute=true
NoNewPrivileges=true
PrivateDevices=false
# Needed by plugins
PrivateTmp=false
ProtectControlGroups=true
ProtectHome=true
ProtectHostname=true
ProtectKernelLogs=true
ProtectKernelModules=true
ProtectKernelTunables=true
ProtectSystem=strict
ReadOnlyPaths=/
ReadWritePaths=/var/lib/spire/server /run/spire/server
Restart=on-failure
RestartSec=15
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
RestrictNamespaces=true
RestrictRealtime=yes
RestrictSUIDSGID=yes
StartLimitBurst=3
StartLimitInterval=30min
TasksMax=infinity

[Install]
WantedBy=spire-server.target
5 changes: 5 additions & 0 deletions examples/systemd/system/spire.target
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
[Unit]
Description=SPIRE target allowing to start/stop all spire*@.service instances at once

[Install]
WantedBy=multi-user.target
Loading