diff --git a/apps/base/authentik/gateway.yaml b/apps/base/authentik/gateway.yaml index aa8892f..ef05aac 100644 --- a/apps/base/authentik/gateway.yaml +++ b/apps/base/authentik/gateway.yaml @@ -1,19 +1,18 @@ --- -# The public identity.unkin.net listener terminates TLS with the real Let's -# Encrypt *.unkin.net wildcard (Certificate wildcard-unkin-net in cert-manager, -# reflected here as wildcard-unkin-net-tls). The cluster-hostname listeners -# (identity.k8s.syd1.au.unkin.net) keep the Vault-PKI authentik-tls, whose -# cert-manager annotations below now key the common-name off that cluster host. +# Public identity.unkin.net listener. external-dns publishes the A record at the +# internal LB VIP (198.18.200.4). Public TLS is terminated with the real Let's +# Encrypt *.unkin.net wildcard, centrally minted once in the cert-manager +# namespace (Certificate wildcard-unkin-net) and reflected into this namespace +# by the emberstack reflector as the secret wildcard-unkin-net-tls. No +# cert-manager annotations here so the gateway-shim does not mint a competing +# Vault-PKI Certificate for the reflected secret. apiVersion: gateway.networking.k8s.io/v1 kind: Gateway metadata: labels: traefik.io/instance: internal annotations: - cert-manager.io/cluster-issuer: vault-issuer - cert-manager.io/common-name: identity.k8s.syd1.au.unkin.net - cert-manager.io/private-key-size: "4096" - external-dns.alpha.kubernetes.io/hostname: identity.unkin.net,identity.k8s.syd1.au.unkin.net + external-dns.alpha.kubernetes.io/hostname: identity.unkin.net external-dns.alpha.kubernetes.io/target: 198.18.200.4 name: authentik namespace: authentik @@ -40,18 +39,38 @@ spec: kind: Secret name: wildcard-unkin-net-tls mode: Terminate +--- +# Cluster hostname variant, identity.k8s.syd1.au.unkin.net. Internal Traefik, +# external-dns at 198.18.200.4. Own leaf from the Vault PKI issuer via the +# cert-manager gateway-shim; the common-name keys off this cluster host. +apiVersion: gateway.networking.k8s.io/v1 +kind: Gateway +metadata: + labels: + traefik.io/instance: internal + annotations: + cert-manager.io/cluster-issuer: vault-issuer + cert-manager.io/common-name: identity.k8s.syd1.au.unkin.net + cert-manager.io/private-key-size: "4096" + external-dns.alpha.kubernetes.io/hostname: identity.k8s.syd1.au.unkin.net + external-dns.alpha.kubernetes.io/target: 198.18.200.4 + name: authentik-internal + namespace: authentik +spec: + gatewayClassName: traefik-internal + listeners: - allowedRoutes: namespaces: from: Same hostname: identity.k8s.syd1.au.unkin.net - name: http-internal + name: http port: 80 protocol: HTTP - allowedRoutes: namespaces: from: Same hostname: identity.k8s.syd1.au.unkin.net - name: https-internal + name: https port: 443 protocol: HTTPS tls: diff --git a/apps/base/authentik/httproute.yaml b/apps/base/authentik/httproute.yaml index bd4892e..3e85185 100644 --- a/apps/base/authentik/httproute.yaml +++ b/apps/base/authentik/httproute.yaml @@ -7,16 +7,11 @@ metadata: spec: hostnames: - identity.unkin.net - - identity.k8s.syd1.au.unkin.net parentRefs: - group: gateway.networking.k8s.io kind: Gateway name: authentik sectionName: http - - group: gateway.networking.k8s.io - kind: Gateway - name: authentik - sectionName: http-internal rules: - filters: - type: RequestRedirect @@ -36,16 +31,60 @@ metadata: spec: hostnames: - identity.unkin.net - - identity.k8s.syd1.au.unkin.net parentRefs: - group: gateway.networking.k8s.io kind: Gateway name: authentik sectionName: https - - group: gateway.networking.k8s.io - kind: Gateway - name: authentik - sectionName: https-internal + rules: + - backendRefs: + - group: "" + kind: Service + name: authentik-server + port: 80 + weight: 1 + matches: + - path: + type: PathPrefix + value: / +--- +apiVersion: gateway.networking.k8s.io/v1 +kind: HTTPRoute +metadata: + name: authentik-http-redirect-internal + namespace: authentik +spec: + hostnames: + - identity.k8s.syd1.au.unkin.net + parentRefs: + - group: gateway.networking.k8s.io + kind: Gateway + name: authentik-internal + sectionName: http + rules: + - filters: + - type: RequestRedirect + requestRedirect: + scheme: https + statusCode: 301 + matches: + - path: + type: PathPrefix + value: / +--- +apiVersion: gateway.networking.k8s.io/v1 +kind: HTTPRoute +metadata: + name: authentik-internal + namespace: authentik +spec: + hostnames: + - identity.k8s.syd1.au.unkin.net + parentRefs: + - group: gateway.networking.k8s.io + kind: Gateway + name: authentik-internal + sectionName: https rules: - backendRefs: - group: ""