Revert "Put the artifactapi web UI behind Authentik oauth2-proxy (#456)"
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful

This reverts commit c98d88c197.

The artifactapi web UI has been down since #456 merged: /ui/ and /oauth2/
both return 503 "no available server", Traefik's response for a Service
with no ready endpoints, so the oauth2-proxy pod is not becoming ready.
The machine API surface (/version, /api/v2/health, /v2/,
/.well-known/terraform.json) is unaffected and still returns 200.

Rolling back restores unauthenticated access to the UI at /ui, served
directly by the ui Service exactly as before.

- Point the api-route /ui rule back at the ui Service and drop the
  /oauth2 rule.
- Remove the oauth2-proxy ConfigMap, Deployment, Service and VMPodScrape.
- Remove the oauth-credentials VaultStaticSecret.

The apps/base/artifactapi tree is byte-identical to 520da44, the commit
immediately before #456. Nothing that landed since is touched.
This commit is contained in:
2026-09-07 22:29:17 +10:00
parent c98d88c197
commit 297168a398
7 changed files with 1 additions and 221 deletions
-20
View File
@@ -16,26 +16,6 @@ spec:
sessionAffinity: None
type: ClusterIP
---
# Authenticated front door for the web UI only: api-route sends /ui and /oauth2
# here, oauth2-proxy authenticates and forwards to the ui Service. Every other
# path reaches the api Service above directly and stays unauthenticated.
apiVersion: v1
kind: Service
metadata:
name: oauth2
namespace: artifactapi
spec:
internalTrafficPolicy: Cluster
ports:
- name: http
port: 80
protocol: TCP
targetPort: http
selector:
app: oauth2
sessionAffinity: None
type: ClusterIP
---
apiVersion: v1
kind: Service
metadata: