Compare commits
24 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| fe51aa07be | |||
| cdaab736b5 | |||
| b31517e6d9 | |||
| 5a74b2cec6 | |||
| f14bcc4d2a | |||
| b01e4c3241 | |||
| bbd5bdaa95 | |||
| 4762cf9e03 | |||
| c83a886e74 | |||
| 9a7200636c | |||
| 9535bad9bc | |||
| 34dd70435e | |||
| 6cc752336e | |||
| 47a2ab9152 | |||
| 4748df497a | |||
| ba14f85e51 | |||
| 8a00ddb82c | |||
| d4aed39f6a | |||
| d6a1279efe | |||
| 55af4b2f16 | |||
| 783a3db0fd | |||
| 84f09f89ff | |||
| 5b07157eeb | |||
| 7aec9a9021 |
@@ -39,3 +39,8 @@ data:
|
|||||||
OAUTH2_PROXY_REVERSE_PROXY: "true"
|
OAUTH2_PROXY_REVERSE_PROXY: "true"
|
||||||
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
|
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
|
||||||
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
|
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
|
||||||
|
# Back-channel discovery/token calls resolve the issuer inside the cluster,
|
||||||
|
# where it is served under the internal unkin.net CA rather than the publicly
|
||||||
|
# trusted cert the browser sees. Trust the bundle the combine-certs init
|
||||||
|
# container assembles, as every other oauth2-proxy in the estate does.
|
||||||
|
OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt"
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ metadata:
|
|||||||
namespace: artifactapi
|
namespace: artifactapi
|
||||||
annotations:
|
annotations:
|
||||||
configmap.reloader.stakater.com/auto: "true"
|
configmap.reloader.stakater.com/auto: "true"
|
||||||
secret.reloader.stakater.com/reload: "oauth-credentials"
|
secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert"
|
||||||
spec:
|
spec:
|
||||||
replicas: 2
|
replicas: 2
|
||||||
selector:
|
selector:
|
||||||
@@ -30,6 +30,36 @@ spec:
|
|||||||
fsGroup: 65532
|
fsGroup: 65532
|
||||||
seccompProfile:
|
seccompProfile:
|
||||||
type: RuntimeDefault
|
type: RuntimeDefault
|
||||||
|
initContainers:
|
||||||
|
# The Authentik issuer is served behind the internal unkin.net CA;
|
||||||
|
# combine the system roots with it so oauth2-proxy's OIDC HTTP client
|
||||||
|
# trusts the discovery endpoint.
|
||||||
|
- name: combine-certs
|
||||||
|
image: docker.io/library/alpine:3
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt
|
||||||
|
volumeMounts:
|
||||||
|
- name: vault-ca-cert
|
||||||
|
mountPath: /custom-ca
|
||||||
|
readOnly: true
|
||||||
|
- name: combined-certs
|
||||||
|
mountPath: /combined-certs
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 32Mi
|
||||||
|
limits:
|
||||||
|
cpu: 200m
|
||||||
|
memory: 64Mi
|
||||||
containers:
|
containers:
|
||||||
- name: oauth2-proxy
|
- name: oauth2-proxy
|
||||||
image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3
|
image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3
|
||||||
@@ -83,6 +113,10 @@ spec:
|
|||||||
capabilities:
|
capabilities:
|
||||||
drop:
|
drop:
|
||||||
- ALL
|
- ALL
|
||||||
|
volumeMounts:
|
||||||
|
- name: combined-certs
|
||||||
|
mountPath: /etc/ssl/combined
|
||||||
|
readOnly: true
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: 50m
|
cpu: 50m
|
||||||
@@ -90,4 +124,13 @@ spec:
|
|||||||
limits:
|
limits:
|
||||||
cpu: 500m
|
cpu: 500m
|
||||||
memory: 256Mi
|
memory: 256Mi
|
||||||
|
volumes:
|
||||||
|
- name: vault-ca-cert
|
||||||
|
secret:
|
||||||
|
secretName: vault-ca-cert
|
||||||
|
items:
|
||||||
|
- key: ca.crt
|
||||||
|
path: ca.crt
|
||||||
|
- name: combined-certs
|
||||||
|
emptyDir: {}
|
||||||
restartPolicy: Always
|
restartPolicy: Always
|
||||||
|
|||||||
@@ -64,8 +64,12 @@ spec:
|
|||||||
archive_mode: "on"
|
archive_mode: "on"
|
||||||
archive_timeout: 5min
|
archive_timeout: 5min
|
||||||
dynamic_shared_memory_type: posix
|
dynamic_shared_memory_type: posix
|
||||||
effective_cache_size: 256MB
|
effective_cache_size: 1536MB
|
||||||
full_page_writes: "on"
|
full_page_writes: "on"
|
||||||
|
# Replicas report their oldest xmin to the primary, so multi-second reads on
|
||||||
|
# a hot standby stop exhausting max_standby_streaming_delay and being
|
||||||
|
# cancelled. Retained-dead-tuple cost is negligible on a ~155MB database.
|
||||||
|
hot_standby_feedback: "on"
|
||||||
log_destination: csvlog
|
log_destination: csvlog
|
||||||
log_directory: /controller/log
|
log_directory: /controller/log
|
||||||
log_filename: postgres
|
log_filename: postgres
|
||||||
@@ -77,7 +81,12 @@ spec:
|
|||||||
max_parallel_workers: "16"
|
max_parallel_workers: "16"
|
||||||
max_replication_slots: "16"
|
max_replication_slots: "16"
|
||||||
max_worker_processes: "16"
|
max_worker_processes: "16"
|
||||||
shared_buffers: 128MB
|
# A pg_stat_statements.* parameter is what makes CNPG treat the extension as
|
||||||
|
# managed and run CREATE EXTENSION in every database; preloading alone does
|
||||||
|
# not create it.
|
||||||
|
pg_stat_statements.max: "10000"
|
||||||
|
pg_stat_statements.track: top
|
||||||
|
shared_buffers: 512MB
|
||||||
shared_memory_type: mmap
|
shared_memory_type: mmap
|
||||||
ssl_max_protocol_version: TLSv1.3
|
ssl_max_protocol_version: TLSv1.3
|
||||||
ssl_min_protocol_version: TLSv1.3
|
ssl_min_protocol_version: TLSv1.3
|
||||||
@@ -86,6 +95,9 @@ spec:
|
|||||||
wal_log_hints: "on"
|
wal_log_hints: "on"
|
||||||
wal_receiver_timeout: 5s
|
wal_receiver_timeout: 5s
|
||||||
wal_sender_timeout: 5s
|
wal_sender_timeout: 5s
|
||||||
|
# CNPG merges this with the libraries it manages itself.
|
||||||
|
shared_preload_libraries:
|
||||||
|
- pg_stat_statements
|
||||||
syncReplicaElectionConstraint:
|
syncReplicaElectionConstraint:
|
||||||
enabled: false
|
enabled: false
|
||||||
primaryUpdateMethod: restart
|
primaryUpdateMethod: restart
|
||||||
@@ -105,13 +117,16 @@ spec:
|
|||||||
updateInterval: 30
|
updateInterval: 30
|
||||||
resources:
|
resources:
|
||||||
limits:
|
limits:
|
||||||
cpu: 500m
|
# 500m is a 50ms CFS quota per 100ms period, exhausted by bursts even at
|
||||||
|
# ~0.01 cores average, so every query pays throttle latency.
|
||||||
|
cpu: "2"
|
||||||
# 512Mi OOMKilled replicas under load (shared_buffers 128MB +
|
# 512Mi OOMKilled replicas under load (shared_buffers 128MB +
|
||||||
# max_connections 200 leave no headroom) — see incident 2026-07-28.
|
# max_connections 200 leave no headroom) — see incident 2026-07-28.
|
||||||
memory: 1Gi
|
# shared_buffers 512MB needs the same headroom multiple, hence 2Gi.
|
||||||
|
memory: 2Gi
|
||||||
requests:
|
requests:
|
||||||
cpu: 50m
|
cpu: 500m
|
||||||
memory: 512Mi
|
memory: 1Gi
|
||||||
smartShutdownTimeout: 180
|
smartShutdownTimeout: 180
|
||||||
startDelay: 3600
|
startDelay: 3600
|
||||||
stopDelay: 1800
|
stopDelay: 1800
|
||||||
|
|||||||
@@ -37,6 +37,22 @@ spec:
|
|||||||
name: authentik
|
name: authentik
|
||||||
sectionName: https
|
sectionName: https
|
||||||
rules:
|
rules:
|
||||||
|
- backendRefs:
|
||||||
|
- group: ""
|
||||||
|
kind: Service
|
||||||
|
name: authentik-server
|
||||||
|
port: 80
|
||||||
|
weight: 1
|
||||||
|
filters:
|
||||||
|
- type: URLRewrite
|
||||||
|
urlRewrite:
|
||||||
|
path:
|
||||||
|
type: ReplaceFullPath
|
||||||
|
replaceFullPath: /application/o/token/
|
||||||
|
matches:
|
||||||
|
- path:
|
||||||
|
type: Exact
|
||||||
|
value: /application/o/token
|
||||||
- backendRefs:
|
- backendRefs:
|
||||||
- group: ""
|
- group: ""
|
||||||
kind: Service
|
kind: Service
|
||||||
@@ -86,6 +102,22 @@ spec:
|
|||||||
name: authentik-internal
|
name: authentik-internal
|
||||||
sectionName: https
|
sectionName: https
|
||||||
rules:
|
rules:
|
||||||
|
- backendRefs:
|
||||||
|
- group: ""
|
||||||
|
kind: Service
|
||||||
|
name: authentik-server
|
||||||
|
port: 80
|
||||||
|
weight: 1
|
||||||
|
filters:
|
||||||
|
- type: URLRewrite
|
||||||
|
urlRewrite:
|
||||||
|
path:
|
||||||
|
type: ReplaceFullPath
|
||||||
|
replaceFullPath: /application/o/token/
|
||||||
|
matches:
|
||||||
|
- path:
|
||||||
|
type: Exact
|
||||||
|
value: /application/o/token
|
||||||
- backendRefs:
|
- backendRefs:
|
||||||
- group: ""
|
- group: ""
|
||||||
kind: Service
|
kind: Service
|
||||||
|
|||||||
@@ -19,6 +19,7 @@ resources:
|
|||||||
- redis-deployment.yaml
|
- redis-deployment.yaml
|
||||||
- redis-pvc.yaml
|
- redis-pvc.yaml
|
||||||
- redis-service.yaml
|
- redis-service.yaml
|
||||||
|
- server-vmpodscrape.yaml
|
||||||
- vaultauth.yaml
|
- vaultauth.yaml
|
||||||
- vaultstaticsecret.yaml
|
- vaultstaticsecret.yaml
|
||||||
- vmpodscrape.yaml
|
- vmpodscrape.yaml
|
||||||
|
|||||||
@@ -0,0 +1,16 @@
|
|||||||
|
---
|
||||||
|
# Scrape the authentik server's django_prometheus endpoint (:9300). Picked up
|
||||||
|
# by the observability VMAgent (selectAllByDefault).
|
||||||
|
apiVersion: operator.victoriametrics.com/v1beta1
|
||||||
|
kind: VMPodScrape
|
||||||
|
metadata:
|
||||||
|
name: authentik-server
|
||||||
|
namespace: authentik
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: authentik
|
||||||
|
app.kubernetes.io/component: server
|
||||||
|
podMetricsEndpoints:
|
||||||
|
- port: metrics
|
||||||
|
path: /metrics
|
||||||
@@ -21,7 +21,7 @@ spec:
|
|||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
containers:
|
containers:
|
||||||
- name: operator
|
- name: operator
|
||||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/bind-operator:v0.2.6
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/bind-operator:v0.2.7
|
||||||
args:
|
args:
|
||||||
- --metrics-bind-address=:8080
|
- --metrics-bind-address=:8080
|
||||||
- --health-probe-bind-address=:8081
|
- --health-probe-bind-address=:8081
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ resources:
|
|||||||
- namespace.yaml
|
- namespace.yaml
|
||||||
# CRDs are pulled from the bind-operator repo at the matching tag rather than
|
# CRDs are pulled from the bind-operator repo at the matching tag rather than
|
||||||
# vendored here, so they never drift from the operator.
|
# vendored here, so they never drift from the operator.
|
||||||
- https://git.unkin.net/unkin/bind-operator/raw/tag/v0.2.6/config/crd/install.yaml
|
- https://git.unkin.net/unkin/bind-operator/raw/tag/v0.2.7/config/crd/install.yaml
|
||||||
- rbac.yaml
|
- rbac.yaml
|
||||||
- agent-dns-rbac.yaml
|
- agent-dns-rbac.yaml
|
||||||
- deployment.yaml
|
- deployment.yaml
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ data:
|
|||||||
</key>
|
</key>
|
||||||
<value>
|
<value>
|
||||||
<PluginConfiguration>
|
<PluginConfiguration>
|
||||||
<OidEndpoint>https://identity.k8s.syd1.au.unkin.net/application/o/jellyfin/</OidEndpoint>
|
<OidEndpoint>https://identity.unkin.net/application/o/jellyfin/</OidEndpoint>
|
||||||
<OidClientId>jellyfin</OidClientId>
|
<OidClientId>jellyfin</OidClientId>
|
||||||
<OidSecret>@@CLIENT_SECRET@@</OidSecret>
|
<OidSecret>@@CLIENT_SECRET@@</OidSecret>
|
||||||
<Enabled>true</Enabled>
|
<Enabled>true</Enabled>
|
||||||
|
|||||||
@@ -13,6 +13,4 @@ spec:
|
|||||||
targetPort: http
|
targetPort: http
|
||||||
selector:
|
selector:
|
||||||
app: cheeztv
|
app: cheeztv
|
||||||
# Pin each client to one replica to reduce transcode-session churn/takeover.
|
|
||||||
sessionAffinity: ClientIP
|
|
||||||
type: ClusterIP
|
type: ClusterIP
|
||||||
|
|||||||
@@ -4,6 +4,8 @@ kind: StatefulSet
|
|||||||
metadata:
|
metadata:
|
||||||
name: cheeztv
|
name: cheeztv
|
||||||
namespace: cheeztv
|
namespace: cheeztv
|
||||||
|
annotations:
|
||||||
|
configmap.reloader.stakater.com/auto: "true"
|
||||||
spec:
|
spec:
|
||||||
# HA: two replicas coordinate transcode session ownership through Valkey and
|
# HA: two replicas coordinate transcode session ownership through Valkey and
|
||||||
# resume each other's HLS segments off the shared RWX transcode PVC. Stable
|
# resume each other's HLS segments off the shared RWX transcode PVC. Stable
|
||||||
@@ -162,7 +164,7 @@ spec:
|
|||||||
readOnly: true
|
readOnly: true
|
||||||
containers:
|
containers:
|
||||||
- name: cheeztv
|
- name: cheeztv
|
||||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.2.0
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.4.0
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
ports:
|
ports:
|
||||||
- name: http
|
- name: http
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ data:
|
|||||||
</key>
|
</key>
|
||||||
<value>
|
<value>
|
||||||
<PluginConfiguration>
|
<PluginConfiguration>
|
||||||
<OidEndpoint>https://identity.k8s.syd1.au.unkin.net/application/o/jellyfin/</OidEndpoint>
|
<OidEndpoint>https://identity.unkin.net/application/o/jellyfin/</OidEndpoint>
|
||||||
<OidClientId>jellyfin</OidClientId>
|
<OidClientId>jellyfin</OidClientId>
|
||||||
<OidSecret>@@CLIENT_SECRET@@</OidSecret>
|
<OidSecret>@@CLIENT_SECRET@@</OidSecret>
|
||||||
<Enabled>true</Enabled>
|
<Enabled>true</Enabled>
|
||||||
|
|||||||
@@ -13,6 +13,4 @@ spec:
|
|||||||
targetPort: http
|
targetPort: http
|
||||||
selector:
|
selector:
|
||||||
app: fafflix
|
app: fafflix
|
||||||
# Pin each client to one replica to reduce transcode-session churn/takeover.
|
|
||||||
sessionAffinity: ClientIP
|
|
||||||
type: ClusterIP
|
type: ClusterIP
|
||||||
|
|||||||
@@ -4,6 +4,8 @@ kind: StatefulSet
|
|||||||
metadata:
|
metadata:
|
||||||
name: fafflix
|
name: fafflix
|
||||||
namespace: fafflix
|
namespace: fafflix
|
||||||
|
annotations:
|
||||||
|
configmap.reloader.stakater.com/auto: "true"
|
||||||
spec:
|
spec:
|
||||||
# HA: two replicas coordinate transcode session ownership through Valkey and
|
# HA: two replicas coordinate transcode session ownership through Valkey and
|
||||||
# resume each other's HLS segments off the shared RWX transcode PVC. Stable
|
# resume each other's HLS segments off the shared RWX transcode PVC. Stable
|
||||||
@@ -162,7 +164,7 @@ spec:
|
|||||||
readOnly: true
|
readOnly: true
|
||||||
containers:
|
containers:
|
||||||
- name: fafflix
|
- name: fafflix
|
||||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.2.0
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.4.0
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
ports:
|
ports:
|
||||||
- name: http
|
- name: http
|
||||||
|
|||||||
@@ -25,7 +25,7 @@ spec:
|
|||||||
- name: pdbmux
|
- name: pdbmux
|
||||||
# Image is published by the pdbmux repo's .woodpecker/docker.yaml on
|
# Image is published by the pdbmux repo's .woodpecker/docker.yaml on
|
||||||
# a v* tag. It only exists after that tag is cut (see PR merge gates).
|
# a v* tag. It only exists after that tag is cut (see PR merge gates).
|
||||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/pdbmux:v0.2.0
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/pdbmux:v0.4.0
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 8080
|
- containerPort: 8080
|
||||||
|
|||||||
@@ -99,6 +99,23 @@ spec:
|
|||||||
- mountPath: /docker-custom-entrypoint.d/post-startup/additional-ruby-gems.sh
|
- mountPath: /docker-custom-entrypoint.d/post-startup/additional-ruby-gems.sh
|
||||||
name: additional-ruby-gems
|
name: additional-ruby-gems
|
||||||
subPath: additional-ruby-gems.sh
|
subPath: additional-ruby-gems.sh
|
||||||
|
- mountPath: /configmaps/auth.conf
|
||||||
|
name: compiler-auth-conf
|
||||||
|
subPath: auth.conf
|
||||||
|
- mountPath: /docker-custom-entrypoint.d/pre-default/10-auth-conf.sh
|
||||||
|
name: compiler-auth-conf-seed
|
||||||
|
subPath: 10-auth-conf.sh
|
||||||
|
- mountPath: /docker-custom-entrypoint.d/pre-default/20-vault-helpers.sh
|
||||||
|
name: compiler-vault-helpers-seed
|
||||||
|
subPath: 20-vault-helpers.sh
|
||||||
|
- mountPath: /opt/certmanager/config.yaml
|
||||||
|
name: certmanager-config
|
||||||
|
subPath: certmanager.yaml
|
||||||
|
readOnly: true
|
||||||
|
- mountPath: /opt/sshsignhost/config.yaml
|
||||||
|
name: sshsignhost-config
|
||||||
|
subPath: sshsignhost.yaml
|
||||||
|
readOnly: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- name: copy-configmaps
|
- name: copy-configmaps
|
||||||
image: busybox:1.35
|
image: busybox:1.35
|
||||||
@@ -196,7 +213,38 @@ spec:
|
|||||||
echo "$EXPECTED encapic" | sha256sum -c -
|
echo "$EXPECTED encapic" | sha256sum -c -
|
||||||
install -m 0755 encapic /opt/bin/encapic
|
install -m 0755 encapic /opt/bin/encapic
|
||||||
|
|
||||||
|
# Puppet shells out to these two from generate() during catalog
|
||||||
|
# compilation: profiles::pki::vault runs certmanager and
|
||||||
|
# profiles::ssh::sign runs sshsignhost.
|
||||||
|
install_release() {
|
||||||
|
name=$1
|
||||||
|
version=$2
|
||||||
|
asset="$name-linux-amd64"
|
||||||
|
base="https://git.unkin.net/unkin/$name/releases/download/$version"
|
||||||
|
curl -fsSL -o "$name" "$base/$asset"
|
||||||
|
curl -fsSL -o "$name.checksums" "$base/checksums.txt"
|
||||||
|
# checksums.txt covers every release asset; pick the line for the
|
||||||
|
# one we downloaded and verify it under our local filename.
|
||||||
|
expected=$(awk -v a="$asset" '$NF == a || $NF == "*"a {print $1}' "$name.checksums")
|
||||||
|
if [ -z "$expected" ]; then
|
||||||
|
echo "no checksum for $asset in $version checksums.txt" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo "$expected $name" | sha256sum -c -
|
||||||
|
install -m 0755 "$name" "/opt/bin/$name"
|
||||||
|
}
|
||||||
|
|
||||||
|
install_release certmanager v0.2.0
|
||||||
|
install_release sshsignhost v0.1.0
|
||||||
|
|
||||||
echo "Shared binaries setup completed"
|
echo "Shared binaries setup completed"
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: 300m
|
||||||
|
memory: 256Mi
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 64Mi
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- mountPath: /opt/bin/
|
- mountPath: /opt/bin/
|
||||||
name: puppet-shared-bins
|
name: puppet-shared-bins
|
||||||
@@ -234,5 +282,22 @@ spec:
|
|||||||
configMap:
|
configMap:
|
||||||
name: additional-ruby-gems
|
name: additional-ruby-gems
|
||||||
defaultMode: 0755
|
defaultMode: 0755
|
||||||
|
- name: compiler-auth-conf
|
||||||
|
configMap:
|
||||||
|
name: compiler-auth.conf
|
||||||
|
- name: compiler-auth-conf-seed
|
||||||
|
configMap:
|
||||||
|
name: compiler-auth-conf-seed
|
||||||
|
defaultMode: 0755
|
||||||
|
- name: compiler-vault-helpers-seed
|
||||||
|
configMap:
|
||||||
|
name: compiler-vault-helpers-seed
|
||||||
|
defaultMode: 0755
|
||||||
|
- name: certmanager-config
|
||||||
|
configMap:
|
||||||
|
name: certmanager-config
|
||||||
|
- name: sshsignhost-config
|
||||||
|
configMap:
|
||||||
|
name: sshsignhost-config
|
||||||
strategy:
|
strategy:
|
||||||
type: RollingUpdate
|
type: RollingUpdate
|
||||||
|
|||||||
@@ -54,6 +54,31 @@ configMapGenerator:
|
|||||||
- resources/compiler/puppetdb.conf
|
- resources/compiler/puppetdb.conf
|
||||||
options:
|
options:
|
||||||
disableNameSuffixHash: true
|
disableNameSuffixHash: true
|
||||||
|
- name: compiler-auth.conf
|
||||||
|
files:
|
||||||
|
- resources/compiler/auth.conf
|
||||||
|
options:
|
||||||
|
disableNameSuffixHash: true
|
||||||
|
- name: compiler-auth-conf-seed
|
||||||
|
files:
|
||||||
|
- resources/compiler/10-auth-conf.sh
|
||||||
|
options:
|
||||||
|
disableNameSuffixHash: true
|
||||||
|
- name: compiler-vault-helpers-seed
|
||||||
|
files:
|
||||||
|
- resources/compiler/20-vault-helpers.sh
|
||||||
|
options:
|
||||||
|
disableNameSuffixHash: true
|
||||||
|
- name: certmanager-config
|
||||||
|
files:
|
||||||
|
- resources/compiler/certmanager.yaml
|
||||||
|
options:
|
||||||
|
disableNameSuffixHash: true
|
||||||
|
- name: sshsignhost-config
|
||||||
|
files:
|
||||||
|
- resources/compiler/sshsignhost.yaml
|
||||||
|
options:
|
||||||
|
disableNameSuffixHash: true
|
||||||
- name: additional-ruby-gems
|
- name: additional-ruby-gems
|
||||||
files:
|
files:
|
||||||
- resources/additional-ruby-gems.sh
|
- resources/additional-ruby-gems.sh
|
||||||
|
|||||||
@@ -6,4 +6,6 @@ echo "Installing additional Ruby gems..."
|
|||||||
/opt/puppetlabs/puppet/bin/gem install ipaddr
|
/opt/puppetlabs/puppet/bin/gem install ipaddr
|
||||||
/opt/puppetlabs/puppet/bin/gem install hiera-eyaml
|
/opt/puppetlabs/puppet/bin/gem install hiera-eyaml
|
||||||
/opt/puppetlabs/puppet/bin/gem install toml
|
/opt/puppetlabs/puppet/bin/gem install toml
|
||||||
|
# Under set -e a failed install kills the entrypoint post-startup hooks, taking down an already-serving compiler.
|
||||||
|
/opt/puppetlabs/bin/puppetserver gem install toml
|
||||||
echo "Additional Ruby gems installed successfully"
|
echo "Additional Ruby gems installed successfully"
|
||||||
|
|||||||
+14
@@ -0,0 +1,14 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
SRC=/configmaps/auth.conf
|
||||||
|
DST=/etc/puppetlabs/puppetserver/conf.d/auth.conf
|
||||||
|
|
||||||
|
# Copied rather than mounted: the entrypoint chowns conf.d and rewrites auth.conf,
|
||||||
|
# both of which fail on a read-only configmap mount and abort container startup.
|
||||||
|
if [ ! -s "$SRC" ]; then
|
||||||
|
echo "FATAL: $SRC missing or empty; refusing to start on the image default auth.conf" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
cp "$SRC" "$DST"
|
||||||
+29
@@ -0,0 +1,29 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
BIN_DIR=/opt/bin
|
||||||
|
CA=/opt/vault-ca-cert.crt
|
||||||
|
|
||||||
|
if [ ! -s "$CA" ]; then
|
||||||
|
echo "FATAL: $CA missing or empty; certmanager and sshsignhost cannot verify Vault" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# profiles::pki::vault and profiles::ssh::sign shell out to fixed /usr/local/bin
|
||||||
|
# paths from generate(); the binaries ship on the shared PVC, and /usr/local/bin
|
||||||
|
# lives in the image. Wrappers rather than symlinks because neither binary reads
|
||||||
|
# a CA path from its config: SSL_CERT_FILE scopes the internal CA to these two
|
||||||
|
# processes instead of the puppetserver JVM's own trust store.
|
||||||
|
for bin in certmanager sshsignhost; do
|
||||||
|
if [ ! -x "$BIN_DIR/$bin" ]; then
|
||||||
|
echo "FATAL: $BIN_DIR/$bin missing; generate() would abort every catalog compile" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
cat > "/usr/local/bin/$bin" <<WRAPPER
|
||||||
|
#!/bin/sh
|
||||||
|
SSL_CERT_FILE=$CA
|
||||||
|
export SSL_CERT_FILE
|
||||||
|
exec $BIN_DIR/$bin "\$@"
|
||||||
|
WRAPPER
|
||||||
|
chmod 0755 "/usr/local/bin/$bin"
|
||||||
|
done
|
||||||
@@ -0,0 +1,320 @@
|
|||||||
|
# Copied into conf.d at startup by 10-auth-conf.sh; the entrypoint then appends the
|
||||||
|
# admin API cache rule and re-renders the result, so the running file is not byte-identical.
|
||||||
|
authorization: {
|
||||||
|
version: 1
|
||||||
|
rules: [
|
||||||
|
{
|
||||||
|
# Allow nodes to retrieve their own catalog
|
||||||
|
match-request: {
|
||||||
|
path: "^/puppet/v3/catalog/([^/]+)$"
|
||||||
|
type: regex
|
||||||
|
method: [get, post]
|
||||||
|
}
|
||||||
|
allow: "$1"
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs v3 catalog from agents"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow catalog-diff to retrieve catalogs on behalf of others.
|
||||||
|
# sort-order 400 must stay lower than the puppetlabs deny that follows: rules
|
||||||
|
# sort by [sort-order, name] and the first match wins.
|
||||||
|
match-request: {
|
||||||
|
path: "^/puppet/v4/catalog/?$"
|
||||||
|
type: regex
|
||||||
|
method: post
|
||||||
|
}
|
||||||
|
allow: "catalog-diff.main.unkin.net"
|
||||||
|
sort-order: 400
|
||||||
|
name: "unkin v4 catalog for catalog-diff"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow services to retrieve catalogs on behalf of others
|
||||||
|
match-request: {
|
||||||
|
path: "^/puppet/v4/catalog/?$"
|
||||||
|
type: regex
|
||||||
|
method: post
|
||||||
|
}
|
||||||
|
deny: "*"
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs v4 catalog for services"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow nodes to retrieve the certificate they requested earlier
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet-ca/v1/certificate/"
|
||||||
|
type: path
|
||||||
|
method: get
|
||||||
|
}
|
||||||
|
allow-unauthenticated: true
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs certificate"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow all nodes to access the certificate revocation list
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet-ca/v1/certificate_revocation_list/ca"
|
||||||
|
type: path
|
||||||
|
method: get
|
||||||
|
}
|
||||||
|
allow-unauthenticated: true
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs crl"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow nodes to request a new certificate
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet-ca/v1/certificate_request"
|
||||||
|
type: path
|
||||||
|
method: [get, put]
|
||||||
|
}
|
||||||
|
allow-unauthenticated: true
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs csr"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow nodes to renew their certificate
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet-ca/v1/certificate_renewal"
|
||||||
|
type: path
|
||||||
|
method: post
|
||||||
|
}
|
||||||
|
# this endpoint should never be unauthenticated, as it requires the cert to be provided.
|
||||||
|
allow: "*"
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs certificate renewal"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow the CA CLI to access the certificate_status endpoint
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet-ca/v1/certificate_status"
|
||||||
|
type: path
|
||||||
|
method: [get, put, delete]
|
||||||
|
}
|
||||||
|
allow: {
|
||||||
|
extensions: {
|
||||||
|
pp_cli_auth: "true"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs cert status"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
match-request: {
|
||||||
|
path: "^/puppet-ca/v1/certificate_revocation_list$"
|
||||||
|
type: regex
|
||||||
|
method: put
|
||||||
|
}
|
||||||
|
allow: {
|
||||||
|
extensions: {
|
||||||
|
pp_cli_auth: "true"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs CRL update"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow the CA CLI to access the certificate_statuses endpoint
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet-ca/v1/certificate_statuses"
|
||||||
|
type: path
|
||||||
|
method: get
|
||||||
|
}
|
||||||
|
allow: {
|
||||||
|
extensions: {
|
||||||
|
pp_cli_auth: "true"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs cert statuses"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow authenticated access to the CA expirations endpoint
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet-ca/v1/expirations"
|
||||||
|
type: path
|
||||||
|
method: get
|
||||||
|
}
|
||||||
|
allow: "*"
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs CA cert and CRL expirations"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow the CA CLI to access the certificate clean endpoint
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet-ca/v1/clean"
|
||||||
|
type: path
|
||||||
|
method: put
|
||||||
|
}
|
||||||
|
allow: {
|
||||||
|
extensions: {
|
||||||
|
pp_cli_auth: "true"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs cert clean"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow the CA CLI to access the certificate sign endpoint
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet-ca/v1/sign"
|
||||||
|
type: path
|
||||||
|
method: post
|
||||||
|
}
|
||||||
|
allow: {
|
||||||
|
extensions: {
|
||||||
|
pp_cli_auth: "true"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs cert sign"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow the CA CLI to access the certificate sign all endpoint
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet-ca/v1/sign/all"
|
||||||
|
type: path
|
||||||
|
method: post
|
||||||
|
}
|
||||||
|
allow: {
|
||||||
|
extensions: {
|
||||||
|
pp_cli_auth: "true"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs cert sign all"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow unauthenticated access to the status service endpoint
|
||||||
|
match-request: {
|
||||||
|
path: "/status/v1/services"
|
||||||
|
type: path
|
||||||
|
method: get
|
||||||
|
}
|
||||||
|
allow-unauthenticated: true
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs status service - full"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
match-request: {
|
||||||
|
path: "/status/v1/simple"
|
||||||
|
type: path
|
||||||
|
method: get
|
||||||
|
}
|
||||||
|
allow-unauthenticated: true
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs status service - simple"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet/v3/environments"
|
||||||
|
type: path
|
||||||
|
method: get
|
||||||
|
}
|
||||||
|
allow: "*"
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs environments"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow nodes to access all file_bucket_files. Note that access for
|
||||||
|
# the 'delete' method is forbidden by Puppet regardless of the
|
||||||
|
# configuration of this rule.
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet/v3/file_bucket_file"
|
||||||
|
type: path
|
||||||
|
method: [get, head, post, put]
|
||||||
|
}
|
||||||
|
allow: "*"
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs file bucket file"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow nodes to access all file_content. Note that access for the
|
||||||
|
# 'delete' method is forbidden by Puppet regardless of the
|
||||||
|
# configuration of this rule.
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet/v3/file_content"
|
||||||
|
type: path
|
||||||
|
method: [get, post]
|
||||||
|
}
|
||||||
|
allow: "*"
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs file content"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow nodes to access all file_metadata. Note that access for the
|
||||||
|
# 'delete' method is forbidden by Puppet regardless of the
|
||||||
|
# configuration of this rule.
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet/v3/file_metadata"
|
||||||
|
type: path
|
||||||
|
method: [get, post]
|
||||||
|
}
|
||||||
|
allow: "*"
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs file metadata"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow nodes to retrieve only their own node definition
|
||||||
|
match-request: {
|
||||||
|
path: "^/puppet/v3/node/([^/]+)$"
|
||||||
|
type: regex
|
||||||
|
method: get
|
||||||
|
}
|
||||||
|
allow: "$1"
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs node"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow nodes to store only their own reports
|
||||||
|
match-request: {
|
||||||
|
path: "^/puppet/v3/report/([^/]+)$"
|
||||||
|
type: regex
|
||||||
|
method: put
|
||||||
|
}
|
||||||
|
allow: "$1"
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs report"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Allow nodes to update their own facts
|
||||||
|
match-request: {
|
||||||
|
path: "^/puppet/v3/facts/([^/]+)$"
|
||||||
|
type: regex
|
||||||
|
method: put
|
||||||
|
}
|
||||||
|
allow: "$1"
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs facts"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet/v3/static_file_content"
|
||||||
|
type: path
|
||||||
|
method: get
|
||||||
|
}
|
||||||
|
allow: "*"
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppetlabs static file content"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
match-request: {
|
||||||
|
path: "/puppet/v3/tasks"
|
||||||
|
type: path
|
||||||
|
}
|
||||||
|
allow: "*"
|
||||||
|
sort-order: 500
|
||||||
|
name: "puppet tasks information"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
# Deny everything else. This ACL is not strictly
|
||||||
|
# necessary, but illustrates the default policy
|
||||||
|
match-request: {
|
||||||
|
path: "/"
|
||||||
|
type: path
|
||||||
|
}
|
||||||
|
deny: "*"
|
||||||
|
sort-order: 999
|
||||||
|
name: "puppetlabs deny all"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
---
|
||||||
|
vault:
|
||||||
|
addr: https://vault.service.consul:8200
|
||||||
|
auth_method: kubernetes
|
||||||
|
k8s_mount: k8s/au/syd1
|
||||||
|
k8s_role: puppet_certmanager
|
||||||
|
jwt_path: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
mount_point: pki_int
|
||||||
|
role_name: servers_default
|
||||||
|
output_path: /tmp/certmanager
|
||||||
|
tls_skip_verify: false
|
||||||
|
timeout: 30s
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
vault:
|
||||||
|
addr: https://vault.service.consul:8200
|
||||||
|
auth_method: kubernetes
|
||||||
|
k8s_mount: k8s/au/syd1
|
||||||
|
k8s_role: puppet_sshsigner
|
||||||
|
jwt_path: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
mount_point: sshca
|
||||||
|
role_name: signhost
|
||||||
|
tls_skip_verify: false
|
||||||
|
timeout: 30s
|
||||||
@@ -15,6 +15,7 @@ resources:
|
|||||||
- serviceaccount_mediamark_ci.yaml
|
- serviceaccount_mediamark_ci.yaml
|
||||||
- serviceaccount_plugin_docker_buildx.yaml
|
- serviceaccount_plugin_docker_buildx.yaml
|
||||||
- serviceaccount_jellyfin_ha_src.yaml
|
- serviceaccount_jellyfin_ha_src.yaml
|
||||||
|
- serviceaccount_jellyfin_plugin_sso.yaml
|
||||||
- serviceaccount_repospawner_ci.yaml
|
- serviceaccount_repospawner_ci.yaml
|
||||||
- serviceaccount_terraform_artifactapi.yaml
|
- serviceaccount_terraform_artifactapi.yaml
|
||||||
- serviceaccount_terraform_authentik.yaml
|
- serviceaccount_terraform_authentik.yaml
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: jellyfin-plugin-sso
|
||||||
|
namespace: woodpecker
|
||||||
@@ -4,7 +4,7 @@ agent:
|
|||||||
WOODPECKER_MAX_WORKFLOWS: "8"
|
WOODPECKER_MAX_WORKFLOWS: "8"
|
||||||
WOODPECKER_BACKEND_K8S_PRIORITY_CLASS: power
|
WOODPECKER_BACKEND_K8S_PRIORITY_CLASS: power
|
||||||
WOODPECKER_BACKEND_K8S_STORAGE_CLASS: cephrbd-fast-delete
|
WOODPECKER_BACKEND_K8S_STORAGE_CLASS: cephrbd-fast-delete
|
||||||
WOODPECKER_BACKEND_K8S_VOLUME_SIZE: 10G
|
WOODPECKER_BACKEND_K8S_VOLUME_SIZE: 20Gi
|
||||||
WOODPECKER_BACKEND_K8S_STORAGE_RWX: false
|
WOODPECKER_BACKEND_K8S_STORAGE_RWX: false
|
||||||
# Required from woodpecker 3.16.0 (GHSA-qf34-295c-26v8): step-level
|
# Required from woodpecker 3.16.0 (GHSA-qf34-295c-26v8): step-level
|
||||||
# serviceAccountName is gated behind this agent flag (default false).
|
# serviceAccountName is gated behind this agent flag (default false).
|
||||||
|
|||||||
@@ -26,6 +26,10 @@ data:
|
|||||||
issuer: https://identity.unkin.net/application/o/argocd/
|
issuer: https://identity.unkin.net/application/o/argocd/
|
||||||
clientID: argocd
|
clientID: argocd
|
||||||
clientSecret: $argocd-oidc:client_secret
|
clientSecret: $argocd-oidc:client_secret
|
||||||
|
# The Authentik client is public (the iOS app can't hold a secret), so
|
||||||
|
# Authentik no longer enforces clientSecret; PKCE replaces it as the
|
||||||
|
# protection against authorization-code interception.
|
||||||
|
enablePKCEAuthentication: true
|
||||||
# identity.unkin.net now serves the LetsEncrypt *.unkin.net wildcard, so the
|
# identity.unkin.net now serves the LetsEncrypt *.unkin.net wildcard, so the
|
||||||
# stock image trust store validates it; no rootCA pin.
|
# stock image trust store validates it; no rootCA pin.
|
||||||
requestedScopes:
|
requestedScopes:
|
||||||
|
|||||||
Reference in New Issue
Block a user