artifactapi: restore combine-certs + PROVIDER_CA_FILES on oauth2-proxy #458

Merged
benvin merged 1 commits from benvin/artifactapi-oauth2-provider-ca into main 2026-09-07 23:05:40 +10:00
Member

Fix-forward companion to the #457 rollback. This is NOT the current outage fix — see below.

The actual outage

The UI is 503 because the Authentik application slug artifactapi does not exist. OIDC discovery 404s, so oauth2-proxy exits at startup, the Service has no ready endpoints, and Traefik answers no available server.

identity.unkin.net              /application/o/artifactapi/…  404
identity.k8s.syd1.au.unkin.net  /application/o/artifactapi/…  404
identity.unkin.net              /application/o/repospawner/…  200
identity.unkin.net              /application/o/argocd/…       200

Root cause is upstream in terraform-authentik: ci/woodpecker/push/apply on main HEAD 4e16401 failed. That apply has to succeed before any argocd-apps change can help. This PR does not fix that.

What this PR does fix

#456 dropped the combine-certs initContainer and OAUTH2_PROXY_PROVIDER_CA_FILES, reasoning that identity.unkin.net serves a publicly trusted Let's Encrypt cert and so needs no internal CA. That holds for the browser redirect but not for oauth2-proxy's own back-channel discovery/token calls.

artifactapi is the only one of six oauth2-proxies in the estate without it:

app issuer host PROVIDER_CA_FILES
arrproxy identity.unkin.net yes
logviewer identity.unkin.net yes
mediamark identity.unkin.net yes
repospawner identity.unkin.net yes
watchstate identity.k8s… yes
artifactapi identity.unkin.net no

repospawner uses the same public identity.unkin.net issuer and still needs the internal bundle, which falsifies the removal reasoning. The existing comment on that initContainer states it plainly: "The Authentik issuer is served behind the internal unkin.net CA."

Changes

  • Add the combine-certs initContainer — byte-identical to repospawner's.
  • Mount the combined bundle and set OAUTH2_PROXY_PROVIDER_CA_FILES.
  • Reload the Deployment when vault-ca-cert rotates.

vault-ca-cert already exists in the artifactapi namespace (api-deployment.yaml uses it). kustomize build apps/base/artifactapi succeeds.

Risk

Trust-only and strictly additive — it appends the internal CA to the system roots. Harmless if the back channel turns out to reach a publicly trusted endpoint after all. Expected to remove the next blocker, surfacing as x509, once the terraform-authentik apply lands.

Sequencing

  1. Fix and re-run terraform-authentik push/apply so the artifactapi application exists.
  2. Merge this.
  3. Confirm /ui/ returns 200, then close #457 unmerged.

Only merge #457 instead if the UI must come back before step 1 can be done.

**Fix-forward companion to the #457 rollback. This is NOT the current outage fix — see below.** ## The actual outage The UI is 503 because the Authentik application slug `artifactapi` **does not exist**. OIDC discovery 404s, so oauth2-proxy exits at startup, the Service has no ready endpoints, and Traefik answers `no available server`. ``` identity.unkin.net /application/o/artifactapi/… 404 identity.k8s.syd1.au.unkin.net /application/o/artifactapi/… 404 identity.unkin.net /application/o/repospawner/… 200 identity.unkin.net /application/o/argocd/… 200 ``` Root cause is upstream in **terraform-authentik**: `ci/woodpecker/push/apply` on main HEAD `4e16401` **failed**. That apply has to succeed before any argocd-apps change can help. **This PR does not fix that.** ## What this PR does fix #456 dropped the `combine-certs` initContainer and `OAUTH2_PROXY_PROVIDER_CA_FILES`, reasoning that `identity.unkin.net` serves a publicly trusted Let's Encrypt cert and so needs no internal CA. That holds for the browser redirect but not for oauth2-proxy's own back-channel discovery/token calls. artifactapi is the **only one of six** oauth2-proxies in the estate without it: | app | issuer host | `PROVIDER_CA_FILES` | |---|---|---| | arrproxy | identity.unkin.net | yes | | logviewer | identity.unkin.net | yes | | mediamark | identity.unkin.net | yes | | repospawner | identity.unkin.net | yes | | watchstate | identity.k8s… | yes | | **artifactapi** | identity.unkin.net | **no** | repospawner uses the **same public `identity.unkin.net` issuer** and still needs the internal bundle, which falsifies the removal reasoning. The existing comment on that initContainer states it plainly: *"The Authentik issuer is served behind the internal unkin.net CA."* ## Changes - Add the `combine-certs` initContainer — byte-identical to repospawner's. - Mount the combined bundle and set `OAUTH2_PROXY_PROVIDER_CA_FILES`. - Reload the Deployment when `vault-ca-cert` rotates. `vault-ca-cert` already exists in the `artifactapi` namespace (`api-deployment.yaml` uses it). `kustomize build apps/base/artifactapi` succeeds. ## Risk Trust-only and strictly additive — it appends the internal CA to the system roots. Harmless if the back channel turns out to reach a publicly trusted endpoint after all. Expected to remove the *next* blocker, surfacing as x509, once the terraform-authentik apply lands. ## Sequencing 1. Fix and re-run terraform-authentik `push/apply` so the `artifactapi` application exists. 2. Merge this. 3. Confirm `/ui/` returns 200, then close #457 unmerged. Only merge #457 instead if the UI must come back before step 1 can be done.
unkin-agent added 1 commit 2026-09-07 22:33:08 +10:00
artifactapi: restore combine-certs + PROVIDER_CA_FILES on oauth2-proxy
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
efed6c8966
#456 omitted the combine-certs initContainer and
OAUTH2_PROXY_PROVIDER_CA_FILES on the grounds that identity.unkin.net
serves a publicly trusted Let's Encrypt cert and so needs no internal CA.
That reasoning holds for the browser redirect but not for oauth2-proxy's
own back-channel calls: every other oauth2-proxy in the estate needs the
internal bundle, including repospawner, which uses the same public
identity.unkin.net issuer hostname.

artifactapi is the only one of six without it (arrproxy, logviewer,
mediamark, repospawner and watchstate all have it).

This is NOT the current outage. The UI is 503 because the Authentik
application slug artifactapi does not exist -- terraform-authentik's
push/apply on main (4e16401) failed, so discovery 404s and oauth2-proxy
never starts. This change removes the next blocker, which would surface
as an x509 failure once that apply succeeds.

- Add the combine-certs initContainer, byte-identical to repospawner's.
- Mount the combined bundle and set OAUTH2_PROXY_PROVIDER_CA_FILES.
- Reload the Deployment when vault-ca-cert rotates.

Trust-only and strictly additive: it appends the internal CA to the
system roots, so it is harmless if the back channel turns out to reach a
publicly trusted endpoint after all.
benvin merged commit 7aec9a9021 into main 2026-09-07 23:05:40 +10:00
benvin deleted branch benvin/artifactapi-oauth2-provider-ca 2026-09-07 23:05:40 +10:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/argocd-apps#458