feat(k8s): add Kubernetes KMS plugin and operator#999
Conversation
c5e3675 to
2317356
Compare
|
@copilot resolve the merge conflicts in this pull request |
Done — merged |
10eef1b to
dc6f4ba
Compare
There was a problem hiding this comment.
Pull request overview
Adds a new Kubernetes KMS v2 provider plugin binary (cosmian-kms-plugin) to let kube-apiserver delegate Encrypt/Decrypt operations to Cosmian KMS (via KMIP), along with documentation, test vectors, and Nix vendor-hash updates.
Changes:
- Introduces
cosmian_kms_k8s_plugincrate (gRPC service, YAML config, build-time proto generation). - Adds integration docs + MkDocs navigation entry for the Kubernetes plugin.
- Adds a KMS test vector runner entry for the plugin flow and updates Nix expected vendor hashes /
Cargo.lock.
Reviewed changes
Copilot reviewed 18 out of 19 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
nix/expected-hashes/ui.vendor.non-fips.sha256 |
Updates UI vendor hash for Nix builds. |
nix/expected-hashes/ui.vendor.fips.sha256 |
Updates UI vendor hash for Nix builds. |
nix/expected-hashes/server.vendor.static.sha256 |
Updates server vendor hash for Nix builds. |
nix/expected-hashes/cli.vendor.linux.sha256 |
Updates CLI vendor hash for Nix builds. |
documentation/mkdocs.yml |
Adds the Kubernetes plugin page to site navigation. |
documentation/docs/integrations/kubernetes_kms_plugin.md |
New integration documentation for the Kubernetes KMS v2 plugin. |
crate/test_kms_server/src/vector_runner.rs |
Registers a new test vector for the plugin wrap/unwrap flow. |
crate/clients/k8s_plugin/src/service.rs |
Implements the KMS v2 gRPC service delegating to KmsClient KMIP Encrypt/Decrypt. |
crate/clients/k8s_plugin/src/main.rs |
Adds CLI entrypoint: loads config, binds Unix socket, serves tonic gRPC. |
crate/clients/k8s_plugin/src/kmsv2.proto |
Adds the Kubernetes KMS v2 proto definition (Apache 2.0 source). |
crate/clients/k8s_plugin/src/integration_tests.rs |
New end-to-end test: spins up test KMS + plugin and checks Status/Encrypt/Decrypt. |
crate/clients/k8s_plugin/src/error.rs |
Introduces plugin error type and maps it to tonic::Status. |
crate/clients/k8s_plugin/src/config.rs |
Adds YAML config schema + loader for the plugin. |
crate/clients/k8s_plugin/Cargo.toml |
New crate manifest (deps: tonic/prost/protox, serde_yaml, etc.). |
crate/clients/k8s_plugin/build.rs |
Generates tonic bindings from the proto at build time (protox-based). |
Cargo.toml |
Adds the new crate to the workspace members list. |
Cargo.lock |
Locks new dependencies pulled in by the plugin (tonic-build/protox/etc.). |
2bbd24f to
10119df
Compare
f8543b9 to
c89a0cf
Compare
Suggestion: extract the E2E job + reuse the new Helm chartNice work on the KMS plugin + operator — the etcd encryption E2E test is thorough. Two suggestions, both non-blocking: 1. Extract
|
Implements a gRPC KMS v2 plugin (cosmian-kms-plugin) that enables kube-apiserver to use Cosmian KMS as the encryption provider for Kubernetes Secrets stored in etcd. - Add crate/clients/k8s/plugin: tonic 0.12 gRPC server on Unix socket implementing the KMS v2 Status/Encrypt/Decrypt service - Add Helm chart (charts/cosmian-kms) for deploying KMS inside a cluster - Add dedicated CI workflow (.github/workflows/k8s_plugin_e2e.yml) with full Minikube E2E test: deploy KMS via Helm, install plugin via systemd, configure etcd encryption, verify secret encrypted at rest, verify decrypt via kubectl - Use kubernetes-version v1.32.0 (adds grpc.WithAuthority(localhost) fixing RST_STREAM PROTOCOL_ERROR from h2 URI authority validation)
1443ba2 to
90453a8
Compare
Follow-up: pin the KMS image tag in the Helm install stepSmall addition to the Helm-based deployment — the helm install my-kms charts/cosmian-kms --namespace kms-plugin-e2e \
--set kms.database.type=sqlite --wait --timeout 120sWithout it, the chart falls back to
Not a functional blocker today (the plugin only needs standard KMIP helm install my-kms charts/cosmian-kms --namespace kms-plugin-e2e \
--set kms.database.type=sqlite \
--set image.tag=latest \
--wait --timeout 120s(or whichever tag corresponds to the image this job is meant to validate against). |
…bited' state IRIS can return <HALTED> with 'Access to database inhibited' during the KMIP server setup if the write-behind cache has not fully flushed when the session starts. Wrap the KMIP_OUTPUT assignment in a retry loop (up to 3 attempts, 15 s apart) that only retries on this specific transient condition; all other errors still fail immediately.
- Add helm lint step to validate chart syntax before cluster tests - Build cosmian_kms_k8s_operator and cosmian_kms_csi_provider in CI - Run unit tests for all 3 k8s crates (plugin, operator, csi_provider) - Add operator inject E2E: fetch KEK from KMS, verify file written to disk - Add CSI provider E2E: install CSI driver, deploy SecretProviderClass + pod, verify secret file mounted inside container - Extend debug section with CSI provider logs and socket state - Increase timeout 45min → 90min for the additional E2E phases - Remove unused test_kms_server dev-dep from csi_provider Cargo.toml - Fix machete false-positive: prost is used, remove ignored annotation
bash printf interprets leading '-' in format string as an option flag, causing 'printf: - : invalid option' (exit code 2) in the Create SecretProviderClass step.
Scope
This PR introduces two new crates under
crate/clients/:1.
k8s_plugin— Kubernetes KMS Provider Plugin (v2)A Unix-domain gRPC server implementing the Kubernetes KMS v2 provider API.
kube-apiserver calls it to encrypt/decrypt Data Encryption Keys (DEKs) stored in etcd.
The plugin delegates all crypto to the Cosmian KMS server.
Key files:
src/main.rs,src/service.rs,src/config.rs,proto/v2.proto2.
k8s_operator— Kubernetes Operator (CRD controller + mutating admission webhook)A full Kubernetes operator that:
KMSSecretCRD — declarative KMS-backed secrets with auto-refreshThis component is security-sensitive: it mutates Pod specs, injects init-containers, and manages long-lived KMS credentials on behalf of workloads.
Key files:
src/webhook.rs,src/controller.rs,src/crd.rs,src/config.rsSecurity notes
valueFrom.secretKeyRef(not as a literal value)0700directory before bind to eliminate the TOCTOU window