artifactapi: restore combine-certs + PROVIDER_CA_FILES on oauth2-proxy
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful

#456 omitted the combine-certs initContainer and
OAUTH2_PROXY_PROVIDER_CA_FILES on the grounds that identity.unkin.net
serves a publicly trusted Let's Encrypt cert and so needs no internal CA.
That reasoning holds for the browser redirect but not for oauth2-proxy's
own back-channel calls: every other oauth2-proxy in the estate needs the
internal bundle, including repospawner, which uses the same public
identity.unkin.net issuer hostname.

artifactapi is the only one of six without it (arrproxy, logviewer,
mediamark, repospawner and watchstate all have it).

This is NOT the current outage. The UI is 503 because the Authentik
application slug artifactapi does not exist -- terraform-authentik's
push/apply on main (4e16401) failed, so discovery 404s and oauth2-proxy
never starts. This change removes the next blocker, which would surface
as an x509 failure once that apply succeeds.

- Add the combine-certs initContainer, byte-identical to repospawner's.
- Mount the combined bundle and set OAUTH2_PROXY_PROVIDER_CA_FILES.
- Reload the Deployment when vault-ca-cert rotates.

Trust-only and strictly additive: it appends the internal CA to the
system roots, so it is harmless if the back channel turns out to reach a
publicly trusted endpoint after all.
This commit is contained in:
2026-09-07 22:32:48 +10:00
parent c98d88c197
commit efed6c8966
2 changed files with 49 additions and 1 deletions
@@ -39,3 +39,8 @@ data:
OAUTH2_PROXY_REVERSE_PROXY: "true"
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
# Back-channel discovery/token calls resolve the issuer inside the cluster,
# where it is served under the internal unkin.net CA rather than the publicly
# trusted cert the browser sees. Trust the bundle the combine-certs init
# container assembles, as every other oauth2-proxy in the estate does.
OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt"
@@ -6,7 +6,7 @@ metadata:
namespace: artifactapi
annotations:
configmap.reloader.stakater.com/auto: "true"
secret.reloader.stakater.com/reload: "oauth-credentials"
secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert"
spec:
replicas: 2
selector:
@@ -30,6 +30,36 @@ spec:
fsGroup: 65532
seccompProfile:
type: RuntimeDefault
initContainers:
# The Authentik issuer is served behind the internal unkin.net CA;
# combine the system roots with it so oauth2-proxy's OIDC HTTP client
# trusts the discovery endpoint.
- name: combine-certs
image: docker.io/library/alpine:3
imagePullPolicy: IfNotPresent
command:
- sh
- -c
- cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt
volumeMounts:
- name: vault-ca-cert
mountPath: /custom-ca
readOnly: true
- name: combined-certs
mountPath: /combined-certs
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
resources:
requests:
cpu: 50m
memory: 32Mi
limits:
cpu: 200m
memory: 64Mi
containers:
- name: oauth2-proxy
image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3
@@ -83,6 +113,10 @@ spec:
capabilities:
drop:
- ALL
volumeMounts:
- name: combined-certs
mountPath: /etc/ssl/combined
readOnly: true
resources:
requests:
cpu: 50m
@@ -90,4 +124,13 @@ spec:
limits:
cpu: 500m
memory: 256Mi
volumes:
- name: vault-ca-cert
secret:
secretName: vault-ca-cert
items:
- key: ca.crt
path: ca.crt
- name: combined-certs
emptyDir: {}
restartPolicy: Always