concourse cfssl resources for pki management
969
this project provides a set of concourse-ci custom resources designed to wrap the cfssl cli
the baseline image provides a common core of system packages, reducing duplication
each individual resource image contains a copy of the library files and a set of scripts which invoke the appropriate library function (check/in/out)
the root ca resource will create a root-ca.pem certificate and root-ca-key.pem private key file under the designated s3 path
the intermediate ca resource will create an intermediate-ca.pem certificate and intermediate-ca-key.pem private key file under the designated s3 path
the intermediate ca keypair will be created using the root ca found in the same s3 path
the intermediate ca certificate can be renewed using the existing certificate and private key
the intermediate ca certificate expiration can be changed upon renewal
the leaf resource will create a {leaf_name}.pem certificate and {leaf_name}-key.pem private key file under the designated s3 path
the leaf keypair will be created using the intermediate ca found in the same s3 path
the leaf certificate can be renewed using the existing certificate and private key
the leaf certificate expiration, key usages, and subject alternative names can be changed upon renewal
tested with concourse 4.x
baseline for each concourse cfssl resource
includes:
also includes pip packages in requirements.txt
creates and gets root ca using cfssl
bucket_name: required. the name of the bucket.
access_key_id: required. the aws access key id to use when accessing the bucket
secret_access_key: required. the aws secret access key to use when accessing the bucket
region_name: required. the region the bucket is in.
role_arn: optional. the aws role arn to assume using the provided credentials.
session_name: optional. the session name to use when assuming the role in role_arn. default: concourse-cfssl-resource
session_duration: optional. the duration in seconds for the lease on credentials obtained from role_arn. default: 900
prefix: optional. the prefix path to prepend to the cfssl files. e.g. prefix: my/prefix/path will result in a root ca cert file path of {bucket}/my/prefix/path/root-ca.pem default: null
endpoint: optional. custom endpoint for using S3 compatible provider.
disable_ssl: optional. disable SSL for the endpoint, useful for S3 compatible providers without SSL.
check: check for root cain: fetch root ca certificate and private keyfetches the certificate and/or private key file for a root ca
the following files will be places in the destination, based on parameters:
/root-ca.pem: the root ca certificate file
/root-ca-key.pem: the root ca private key file
parameters
save_certificate: optional. save the certificate file to disk. default: true
save_private_key: optional. save the private key file to disk. default: false
out: create or renew root cacreates a new root ca certificate and private key
note: parameters are mostly 1:1 analogous to their cfssl counterparts
see cfssl documentation for best practices and examples
common parameters
action: optional. the operation to perform, either create or renew. default: createcreate parameters
CN: required. the certificate common name
key: optional. the key parameters
algo: optional. algorithm. default: rsa
size: optional. size. default: 2048
ca: optional. the ca parameters
expiry: optional. the expiration length to use for the ca (a time duration in the form understood by go's time package). default: 87600hnames: optional. array containing single dict with fields used when signing
C: optional. country code
L: optional. city / locality
O: optional. organization
OU: optional. organizational unit
ST: optional. state
---
resource_types:
- name: cfssl-root-ca
type: docker-image
source:
repository: snapkitchen/concourse-cfssl-root-ca-resource
tag: latest
resources:
- name: my-root-ca
type: cfssl-root-ca
source:
bucket_name: ((bucket_name))
access_key_id: ((access_key_id))
secret_access_key: ((secret_access_key))
region_name: ((region_name))
prefix: ((prefix))
jobs:
- name: get-root-ca-keypair
plan:
- get: my-root-ca
params:
save_certificate: true
save_private_key: true
jobs:
- name: create-root-ca-keypair
plan:
- put: my-root-ca
params:
CN: RootCA
names:
- C: US
L: Austin
O: EXAMPLE
OU: DevOps
ST: Texas
jobs:
- name: renew-root-ca-certificate
plan:
- put: my-root-ca
params:
action: renew
creates and gets intermediate ca using cfssl
bucket_name: required. the name of the bucket.
access_key_id: required. the aws access key id to use when accessing the bucket
secret_access_key: required. the aws secret access key to use when accessing the bucket
region_name: required. the region the bucket is in.
role_arn: optional. the aws role arn to assume using the provided credentials.
session_name: optional. the session name to use when assuming the role in role_arn. default: concourse-cfssl-resource
session_duration: optional. the duration in seconds for the lease on credentials obtained from role_arn. default: 900
prefix: optional. the prefix path to prepend to the cfssl files. e.g. prefix: my/prefix/path will result in an intermediate ca cert file path of {bucket}/my/prefix/path/intermediate-ca.pem default: null
note: this path must also contain the root ca certificate and private key under root-ca.pem and root-ca-key.pem, respectively
endpoint: optional. custom endpoint for using S3 compatible provider.
disable_ssl: optional. disable SSL for the endpoint, useful for S3 compatible providers without SSL.
check: check for intermediate cain: fetch intermediate ca certificate and private keyfetches the certificate and/or private key file for a root ca
the following files will be places in the destination, based on parameters:
/intermediate-ca.pem: the intermediate ca certificate file
/intermediate-ca-key.pem: the intermediate ca private key file
parameters
save_certificate: optional. save the certificate file to disk. default: true
save_private_key: optional. save the private key file to disk. default: false
out: create or renew intermediate cacreates a new intermediate ca certificate and private key and signs it using the root ca
note: parameters are mostly 1:1 analogous to their cfssl counterparts
see cfssl documentation for best practices and examples
common parameters
action: optional. the operation to perform, either create or renew. default: create
ca: optional. the ca parameters
expiry: optional. the expiration length to use for the ca (a time duration in the form understood by go's time package). default: 43800hcreate parameters
CN: required. the certificate common name
key: optional. the key parameters
algo: optional. algorithm. default: rsa
size: optional. size. default: 2048
names: optional. array containing single dict with fields used when signing
C: optional. country code
L: optional. city / locality
O: optional. organization
OU: optional. organizational unit
ST: optional. state
---
resource_types:
- name: cfssl-intermediate-ca
type: docker-image
source:
repository: snapkitchen/concourse-cfssl-intermediate-ca-resource
tag: latest
resources:
- name: my-intermediate-ca
type: cfssl-intermediate-ca
source:
bucket_name: ((bucket_name))
access_key_id: ((access_key_id))
secret_access_key: ((secret_access_key))
region_name: ((region_name))
prefix: ((prefix))
jobs:
- name: get-intermediate-ca-keypair
plan:
- get: my-intermediate-ca
params:
save_certificate: true
save_private_key: true
jobs:
- name: create-intermediate-ca-keypair
plan:
- put: my-intermediate-ca
params:
CN: IntermediateCA
names:
- C: US
L: Austin
O: EXAMPLE
OU: DevOps
ST: Texas
jobs:
- name: renew-intermediate-ca-certificate
plan:
- put: my-intermediate-ca
params:
action: renew
creates and gets leaf using cfssl
leaf_name: required. the leaf name (used for file names, e.g.: {leaf-name}.pem)
bucket_name: required. the name of the bucket.
access_key_id: required. the aws access key id to use when accessing the bucket
secret_access_key: required. the aws secret access key to use when accessing the bucket
region_name: required. the region the bucket is in.
role_arn: optional. the aws role arn to assume using the provided credentials.
session_name: optional. the session name to use when assuming the role in role_arn. default: concourse-cfssl-resource
session_duration: optional. the duration in seconds for the lease on credentials obtained from role_arn. default: 900
prefix: optional. the prefix path to prepend to the cfssl files. e.g. prefix: my/prefix/path will result in a leaf cert file path of {bucket}/my/prefix/path/{leaf-name}.pem default: null
note: this path must also contain the intermediate ca certificate and private key under intermediate-ca.pem and intermediate-ca-key.pem, respectively
endpoint: optional. custom endpoint for using S3 compatible provider.
disable_ssl: optional. disable SSL for the endpoint, useful for S3 compatible providers without SSL.
check: check for leafin: fetch leaf certificate, private key, and parent certificatesfetches the leaf certificate, leaf private key, root ca certificate, and intermediate ca certificate
the following files will be places in the destination, based on parameters:
/{leaf_name}.pem: the leaf certificate file
/{leaf_name}-key.pem: the leaf private key file
/{ca/}root-ca.pem: the root ca certificate file
/{ca/}intermediate-ca.pem: the intermediate ca certificate file
/{ca/}ca-chain.pem: the intermediate ca certificate file
parameters
save_certificate: optional. save the certificate file to disk. default: true
save_private_key: optional. save the private key file to disk. default: false
save_root_ca_certificate: optional. save the root ca certificate file to disk. default: false
save_intermediate_ca_certificate: optional. save the intermediate ca certificate file to disk. default: false
save_ca_chain: optional. combine the ca certificates and save them as the ca chain certificate file. default: false
save_to_ca_subdir: optional. save the ca certificates into a ca/ subdirectory. default: false
out: create or renew leafcreates a new leaf certificate and private key and signs it using the intermediate ca
note: parameters are mostly 1:1 analogous to their cfssl counterparts
see cfssl documentation for best practices and examples
common parameters
action: optional. the operation to perform, either create or renew. default: create
leaf: optional. the leaf parameters
expiry: optional. the expiration length to use for the leaf (a time duration in the form understood by go's time package). default: 8760h
usages: optional. array of key usages.
default:
["signing",
"key encipherment",
"server auth",
"client auth"]
hosts: optional. array of SANs. default: null
create parameters
CN: required. the certificate common name
key: optional. the key parameters
algo: optional. algorithm. default: rsa
size: optional. size. default: 2048
names: optional. array containing single dict with fields used when signing
C: optional. country code
L: optional. city / locality
O: optional. organization
OU: optional. organizational unit
ST: optional. state
---
resource_types:
- name: cfssl-leaf
type: docker-image
source:
repository: snapkitchen/concourse-cfssl-leaf-resource
tag: latest
resources:
- name: server-leaf
type: cfssl-leaf
source:
leaf_name: server
bucket_name: ((bucket_name))
access_key_id: ((access_key_id))
secret_access_key: ((secret_access_key))
region_name: ((region_name))
prefix: ((prefix))
jobs:
- name: get-server-leaf-keypair
plan:
- get: server-leaf
params:
save_certificate: true
save_private_key: true
jobs:
- name: get-server-leaf-keypair-and-parents
plan:
- get: server-leaf
params:
save_certificate: true
save_private_key: true
save_root_ca_certificate: true
save_intermediate_ca_certificate: true
jobs:
- name: create-server-leaf-keypair
plan:
- put: server-leaf
params:
CN: server
leaf:
expiry: 26280h
hosts:
- server.node.local.consul
- localhost
- 127.0.0.1
usages:
- signing
- key encipherment
- server auth
names:
- C: US
L: Austin
O: EXAMPLE
OU: DevOps
ST: Texas
jobs:
- name: renew-server-leaf-certificate
plan:
- put: server-leaf
params:
action: renew
install python 3.7 and requirements from requirements-dev.txt
install cfssl
.vscode/settings.json will enable linters in vscode
builds are handled automatically by docker hub
the baseline image is built upon every commit to master
once that is built, the resource images are automatically triggered and built
see LICENSE
Content type
Image
Digest
Size
200.9 MB
Last updated
over 7 years ago
docker pull snapkitchen/concourse-cfssl-baseline