Put the artifactapi web UI behind Authentik oauth2-proxy (#456)
The artifactapi web UI is open to anyone who can reach the host. Front it with Authentik SSO gated on akP-artifactapi-admin, while leaving the package-manager surfaces (/api/v1, /api/v2, /v2 docker registry, /terraform, /.well-known) untouched — dnf, containerd mirrors, buildah, terraform and CI publish steps cannot do a browser flow. - Add the oauth2-proxy ConfigMap, Deployment, Service and VMPodScrape. - Add the oauth-credentials VaultStaticSecret. - Point the api-route /ui rule at oauth2-proxy and add a /oauth2 rule; the catch-all / rule still goes straight to the api Service on both listeners. Requires terraform-authentik #34 applied and the Vault kv seed first. Reviewed-on: #456 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #456.
This commit is contained in:
@@ -0,0 +1,41 @@
|
||||
---
|
||||
# Non-secret oauth2-proxy configuration (client_id/secret/cookie_secret come
|
||||
# from the oauth-credentials Secret).
|
||||
#
|
||||
# SCOPE: this proxy fronts the artifactapi web UI ONLY. The HTTPRoute sends just
|
||||
# /ui and /oauth2 here; every machine surface (/api/v1, /api/v2, /v2 docker
|
||||
# registry, /terraform, /.well-known/terraform.json, /health, /version, /) goes
|
||||
# straight to the api Service and is NOT authenticated. yum/dnf, containerd
|
||||
# registry mirrors, docker/buildah, terraform init and Woodpecker publish steps
|
||||
# cannot complete a browser OIDC flow, so they must never reach this container.
|
||||
# Its only upstream is the ui Service -- there is deliberately no api upstream.
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: artifactapi-oauth2-env
|
||||
namespace: artifactapi
|
||||
data:
|
||||
OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180"
|
||||
OAUTH2_PROXY_METRICS_ADDRESS: "0.0.0.0:44180"
|
||||
OAUTH2_PROXY_PROVIDER: "oidc"
|
||||
# Publicly-trusted Authentik host: the authorize step is a browser redirect,
|
||||
# so the issuer must present a cert every user's browser already trusts (the
|
||||
# k8s host serves an internal-CA cert). Slug from terraform-authentik.
|
||||
OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/artifactapi/"
|
||||
OAUTH2_PROXY_REDIRECT_URL: "https://artifactapi.k8s.syd1.au.unkin.net/oauth2/callback"
|
||||
OAUTH2_PROXY_UPSTREAMS: "http://ui.artifactapi.svc.cluster.local:80/"
|
||||
OAUTH2_PROXY_SCOPE: "openid email profile ak_groups"
|
||||
# Populate session.Groups from the Authentik hierarchical ak_groups claim.
|
||||
OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups"
|
||||
OAUTH2_PROXY_ALLOWED_GROUPS: "akP-artifactapi-admin"
|
||||
OAUTH2_PROXY_PASS_USER_HEADERS: "true"
|
||||
OAUTH2_PROXY_EMAIL_DOMAINS: "*"
|
||||
# Authentik hardcodes email_verified=false in the id_token; authorization is
|
||||
# enforced via ak_groups, so accepting the unverified email is safe.
|
||||
OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true"
|
||||
OAUTH2_PROXY_COOKIE_SECURE: "true"
|
||||
OAUTH2_PROXY_COOKIE_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net"
|
||||
OAUTH2_PROXY_WHITELIST_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net"
|
||||
OAUTH2_PROXY_REVERSE_PROXY: "true"
|
||||
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
|
||||
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
|
||||
Reference in New Issue
Block a user