Pinniped

Pinniped
Terraform module for Kubernetes platforms

Pinniped is a authentication solution for Kubernetes API access for identities from upstream OIDC providers. By leveraging Kubernetes impersonation Pinniped does not require access to the Kubernetes api-server flags to unify authentication across AKS, EKS and GKE.

This Terraform module helps platform engineering teams provision Pinniped on Kubernetes. It fully integrates the upstream Kubernetes resources into the Terraform plan/apply lifecycle and allows configuring Pinniped using native Terraform syntax.

The Pinniped module is continuously updated and tested when new upstream versions are released.

Build status for pinniped-v0.27.0-kbst.0

TL;DR:

  • Use kbst add service pinniped to add Pinniped to your platform
  • The kbst CLI scaffolds the Terraform module boilerplate for you
  • Kubestack platform service modules bundle upstream manifests and are fully customizable

Use the module

The kbst CLI helps you scaffold the Terraform code to provision Pinniped on your platform. It takes care of calling the module once per cluster, and sets the correct source and latest version for the module. And it also makes sure the module's configuration and configuration_base_key match your platform.

# add Pinniped service to all platform clusters
kbst add service pinniped
# or optionally only add Pinniped to a single cluster
# 1. list existing platform modules
kbst list
aks_gc0_westeurope
eks_gc0_eu-west-1
gke_gc0_europe-west1
# 2. add Pinniped to a single cluster
kbst add service pinniped --cluster-name aks_gc0_westeurope

Scaffolding the boilerplate is convenient, but platform service modules are fully documented, standard Terraform modules. They can also be used standalone without the Kubestack framework.

Customize resources

All Kubestack platform service modules support the same module attributes and configuration as all Kubestack modules. The module configuration is a Kustomization set in the per environment configuration map following Kubestack's inheritance model.

The example below shows some options to customize the resources provisioned by the Pinniped module.

module "example_pinniped" {
providers = {
kustomization = kustomization.example
}
source = "kbst.xyz/catalog/pinniped/kustomization"
version = "0.27.0-kbst.0"
configuration = {
apps = {
+ # change the namespace of all resources
+ namespace = var.example_pinniped_namespace
+
+ # or add an annotation
+ common_annotations = {
+ "terraform-workspace" = terraform.workspace
+ }
+
+ # use images to pull from an internal proxy
+ # and avoid being rate limited
+ images = [{
+ # refers to the 'pod.spec.container.name' to modify the 'image' attribute of
+ name = "container-name"
+
+ # customize the 'registry/name' part of the image
+ new_name = "reg.example.com/nginx"
+ }]
}
ops = {
+ # scale down replicas in ops
+ replicas = [{
+ # refers to the 'metadata.name' of the resource to scale
+ name = "example"
+
+ # sets the desired number of replicas
+ count = 1
+ }]
}
}
}

In addition to the example attributes shown above, modules also support secret_generator, config_map_generator, patches and many other Kustomization attributes.

Full documentation how to customize a module's Kubernetes resources is available in the platform service module configuration section of the framework documentation.