From 8f7b9360ada87185b99b2538e109a7e36f6b7568 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Mon, 7 Sep 2026 14:02:18 +1000 Subject: [PATCH 1/5] Put the artifactapi web UI behind Authentik oauth2-proxy Front /ui with an Authentik-authenticated oauth2-proxy while leaving every package-manager surface unauthenticated. - Add the oauth2-proxy ConfigMap, Deployment, Service and VMPodScrape. - Add the oauth-credentials VaultStaticSecret. - Split httproute: /ui and /oauth2 to oauth2-proxy (HTTPS, plus an HTTP redirect); everything else to the api Service on both listeners. --- apps/base/artifactapi/httproute.yaml | 84 +++++++++-- apps/base/artifactapi/kustomization.yaml | 2 + .../artifactapi/oauth2-proxy-configmap.yaml | 42 ++++++ .../artifactapi/oauth2-proxy-deployment.yaml | 136 ++++++++++++++++++ apps/base/artifactapi/services.yaml | 20 +++ apps/base/artifactapi/vaultstaticsecret.yaml | 23 +++ apps/base/artifactapi/vmpodscrape.yaml | 14 ++ 7 files changed, 311 insertions(+), 10 deletions(-) create mode 100644 apps/base/artifactapi/oauth2-proxy-configmap.yaml create mode 100644 apps/base/artifactapi/oauth2-proxy-deployment.yaml diff --git a/apps/base/artifactapi/httproute.yaml b/apps/base/artifactapi/httproute.yaml index 775e004..9a72dad 100644 --- a/apps/base/artifactapi/httproute.yaml +++ b/apps/base/artifactapi/httproute.yaml @@ -1,4 +1,15 @@ --- +# API SIDE -- NOT AUTHENTICATED. Everything that is not /ui or /oauth2 lands +# here and goes straight to the api Service, exactly as before: +# /api/v1/{remote,local,virtual}/* package proxy reads (yum/dnf, pip, ...) +# /api/v2/remotes|virtuals|locals/* management API + the UI's own XHR calls +# /api/v2/remotes/{name}/files/* CI publish uploads (PUT) and downloads +# /v2/* Docker Registry V2 (containerd, buildah) +# /terraform/v1/providers/* Terraform provider registry +# /.well-known/terraform.json Terraform service discovery +# /health, /version, / probes and the redirect to /ui/ +# These clients cannot complete a browser OIDC flow, so they must never be +# routed through oauth2-proxy. apiVersion: gateway.networking.k8s.io/v1 kind: HTTPRoute metadata: @@ -19,16 +30,6 @@ spec: name: artifactapi sectionName: https rules: - - backendRefs: - - group: "" - kind: Service - name: ui - port: 80 - weight: 1 - matches: - - path: - type: PathPrefix - value: /ui - backendRefs: - group: "" kind: Service @@ -39,3 +40,66 @@ spec: - path: type: PathPrefix value: / +--- +# UI SIDE -- AUTHENTICATED. Only the human-facing SPA and the oauth2-proxy +# endpoints (sign_in / start / callback / sign_out) go through the proxy, which +# requires an Authentik session in akP-artifactapi-admin and forwards to the ui +# Service. Longer path prefixes win over the api-route "/" rule above. +# HTTPS only: the session cookie is Secure, so a plain-HTTP session cannot work. +apiVersion: gateway.networking.k8s.io/v1 +kind: HTTPRoute +metadata: + name: ui-route + namespace: artifactapi +spec: + hostnames: + - artifactapi.k8s.syd1.au.unkin.net + parentRefs: + - group: gateway.networking.k8s.io + kind: Gateway + name: artifactapi + sectionName: https + rules: + - backendRefs: + - group: "" + kind: Service + name: oauth2 + port: 80 + weight: 1 + matches: + - path: + type: PathPrefix + value: /ui + - path: + type: PathPrefix + value: /oauth2 +--- +# Send plain-HTTP browsers hitting the UI to HTTPS so they can obtain the Secure +# session cookie. Scoped to the UI paths only -- api-route keeps serving the +# package-manager surfaces over port 80 unredirected. +apiVersion: gateway.networking.k8s.io/v1 +kind: HTTPRoute +metadata: + name: ui-http-redirect + namespace: artifactapi +spec: + hostnames: + - artifactapi.k8s.syd1.au.unkin.net + parentRefs: + - group: gateway.networking.k8s.io + kind: Gateway + name: artifactapi + sectionName: http + rules: + - filters: + - type: RequestRedirect + requestRedirect: + scheme: https + statusCode: 301 + matches: + - path: + type: PathPrefix + value: /ui + - path: + type: PathPrefix + value: /oauth2 diff --git a/apps/base/artifactapi/kustomization.yaml b/apps/base/artifactapi/kustomization.yaml index 8e5a482..6053989 100644 --- a/apps/base/artifactapi/kustomization.yaml +++ b/apps/base/artifactapi/kustomization.yaml @@ -12,6 +12,8 @@ resources: - gateway.yaml - httproute.yaml - namespace.yaml + - oauth2-proxy-configmap.yaml + - oauth2-proxy-deployment.yaml - redis-deployment.yaml - services.yaml - ui-deployment.yaml diff --git a/apps/base/artifactapi/oauth2-proxy-configmap.yaml b/apps/base/artifactapi/oauth2-proxy-configmap.yaml new file mode 100644 index 0000000..79f525c --- /dev/null +++ b/apps/base/artifactapi/oauth2-proxy-configmap.yaml @@ -0,0 +1,42 @@ +--- +# Non-secret oauth2-proxy configuration (client_id/secret/cookie_secret come +# from the oauth-credentials Secret). +# +# SCOPE: this proxy fronts the artifactapi web UI ONLY. The HTTPRoute sends just +# /ui and /oauth2 here; every machine surface (/api/v1, /api/v2, /v2 docker +# registry, /terraform, /.well-known/terraform.json, /health, /version, /) goes +# straight to the api Service and is NOT authenticated. yum/dnf, containerd +# registry mirrors, docker/buildah, terraform init and Woodpecker publish steps +# cannot complete a browser OIDC flow, so they must never reach this container. +# Its only upstream is the ui Service -- there is deliberately no api upstream. +apiVersion: v1 +kind: ConfigMap +metadata: + name: artifactapi-oauth2-env + namespace: artifactapi +data: + OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180" + OAUTH2_PROXY_METRICS_ADDRESS: "0.0.0.0:44180" + OAUTH2_PROXY_PROVIDER: "oidc" + # Internal-CA-served Authentik host (trusted via PROVIDER_CA_FILES below); + # Authentik issues the discovery document under the requested host, so the + # issuer is self-consistent. Slug from terraform-authentik. + OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.k8s.syd1.au.unkin.net/application/o/artifactapi/" + OAUTH2_PROXY_REDIRECT_URL: "https://artifactapi.k8s.syd1.au.unkin.net/oauth2/callback" + OAUTH2_PROXY_UPSTREAMS: "http://ui.artifactapi.svc.cluster.local:80/" + OAUTH2_PROXY_SCOPE: "openid email profile ak_groups" + # Populate session.Groups from the Authentik hierarchical ak_groups claim. + OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups" + OAUTH2_PROXY_ALLOWED_GROUPS: "akP-artifactapi-admin" + OAUTH2_PROXY_PASS_USER_HEADERS: "true" + OAUTH2_PROXY_EMAIL_DOMAINS: "*" + # Authentik hardcodes email_verified=false in the id_token; authorization is + # enforced via ak_groups, so accepting the unverified email is safe. + OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true" + OAUTH2_PROXY_COOKIE_SECURE: "true" + OAUTH2_PROXY_COOKIE_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net" + OAUTH2_PROXY_WHITELIST_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net" + OAUTH2_PROXY_REVERSE_PROXY: "true" + OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt" + OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256" + OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true" diff --git a/apps/base/artifactapi/oauth2-proxy-deployment.yaml b/apps/base/artifactapi/oauth2-proxy-deployment.yaml new file mode 100644 index 0000000..74644d5 --- /dev/null +++ b/apps/base/artifactapi/oauth2-proxy-deployment.yaml @@ -0,0 +1,136 @@ +--- +apiVersion: apps/v1 +kind: Deployment +metadata: + name: oauth2 + namespace: artifactapi + annotations: + configmap.reloader.stakater.com/auto: "true" + secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert" +spec: + replicas: 2 + selector: + matchLabels: + app: oauth2 + strategy: + rollingUpdate: + maxUnavailable: 1 + type: RollingUpdate + template: + metadata: + labels: + app: oauth2 + spec: + serviceAccountName: default + automountServiceAccountToken: false + securityContext: + runAsNonRoot: true + runAsUser: 65532 + runAsGroup: 65532 + fsGroup: 65532 + seccompProfile: + type: RuntimeDefault + initContainers: + # identity.k8s.syd1.au.unkin.net serves a Vault-PKI cert; combine the + # system roots with the internal CA so oauth2-proxy's OIDC client + # trusts the discovery/token endpoints. + - name: combine-certs + image: alpine:3 + imagePullPolicy: IfNotPresent + command: + - sh + - -c + - cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt + volumeMounts: + - name: vault-ca-cert + mountPath: /custom-ca + readOnly: true + - name: combined-certs + mountPath: /combined-certs + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + capabilities: + drop: + - ALL + resources: + requests: + cpu: 50m + memory: 32Mi + limits: + cpu: 200m + memory: 64Mi + containers: + - name: oauth2-proxy + image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3 + imagePullPolicy: IfNotPresent + ports: + - containerPort: 4180 + name: http + protocol: TCP + - containerPort: 44180 + name: metrics + protocol: TCP + envFrom: + - configMapRef: + name: artifactapi-oauth2-env + optional: false + env: + - name: OAUTH2_PROXY_CLIENT_ID + valueFrom: + secretKeyRef: + name: oauth-credentials + key: client_id + - name: OAUTH2_PROXY_CLIENT_SECRET + valueFrom: + secretKeyRef: + name: oauth-credentials + key: client_secret + - name: OAUTH2_PROXY_COOKIE_SECRET + valueFrom: + secretKeyRef: + name: oauth-credentials + key: cookie_secret + volumeMounts: + - name: combined-certs + mountPath: /etc/ssl/combined + readOnly: true + livenessProbe: + httpGet: + path: /ping + port: http + initialDelaySeconds: 10 + periodSeconds: 30 + timeoutSeconds: 5 + failureThreshold: 3 + readinessProbe: + httpGet: + path: /ready + port: http + initialDelaySeconds: 5 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 3 + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + capabilities: + drop: + - ALL + resources: + requests: + cpu: 50m + memory: 64Mi + limits: + cpu: 500m + memory: 256Mi + volumes: + - name: vault-ca-cert + secret: + secretName: vault-ca-cert + items: + - key: ca.crt + path: ca.crt + - name: combined-certs + emptyDir: {} + restartPolicy: Always diff --git a/apps/base/artifactapi/services.yaml b/apps/base/artifactapi/services.yaml index 13aa628..f42a84e 100644 --- a/apps/base/artifactapi/services.yaml +++ b/apps/base/artifactapi/services.yaml @@ -16,6 +16,26 @@ spec: sessionAffinity: None type: ClusterIP --- +# Authenticated front door for the web UI only: the ui-route HTTPRoute sends +# /ui and /oauth2 here, oauth2-proxy authenticates and forwards to the ui +# Service. The api Service above is reached directly and stays unauthenticated. +apiVersion: v1 +kind: Service +metadata: + name: oauth2 + namespace: artifactapi +spec: + internalTrafficPolicy: Cluster + ports: + - name: http + port: 80 + protocol: TCP + targetPort: http + selector: + app: oauth2 + sessionAffinity: None + type: ClusterIP +--- apiVersion: v1 kind: Service metadata: diff --git a/apps/base/artifactapi/vaultstaticsecret.yaml b/apps/base/artifactapi/vaultstaticsecret.yaml index 6c92999..c4f3e00 100644 --- a/apps/base/artifactapi/vaultstaticsecret.yaml +++ b/apps/base/artifactapi/vaultstaticsecret.yaml @@ -32,3 +32,26 @@ spec: refreshAfter: 5m type: kv-v2 vaultAuthRef: default +--- +# Authentik OIDC client for the artifactapi UI front door (client_id, +# client_secret, cookie_secret). Seeded out of band at +# kv/kubernetes/namespace/artifactapi/default/oauth-credentials; the default +# k8s auth role already grants the artifactapi/default ServiceAccount read on +# kv/data/kubernetes/namespace/{{sa_namespace}}/{{sa_name}}/*, so no +# terraform-vault change is needed. Consumed by the oauth2 Deployment. +apiVersion: secrets.hashicorp.com/v1beta1 +kind: VaultStaticSecret +metadata: + name: oauth-credentials + namespace: artifactapi +spec: + destination: + create: true + name: oauth-credentials + overwrite: true + hmacSecretData: true + mount: kv + path: kubernetes/namespace/artifactapi/default/oauth-credentials + refreshAfter: 5m + type: kv-v2 + vaultAuthRef: default diff --git a/apps/base/artifactapi/vmpodscrape.yaml b/apps/base/artifactapi/vmpodscrape.yaml index 6e26cea..61883ca 100644 --- a/apps/base/artifactapi/vmpodscrape.yaml +++ b/apps/base/artifactapi/vmpodscrape.yaml @@ -14,3 +14,17 @@ spec: podMetricsEndpoints: - port: metrics path: /metrics +--- +# Scrape the UI oauth2-proxy (:44180), which exposes sign-in/authz counters. +apiVersion: operator.victoriametrics.com/v1beta1 +kind: VMPodScrape +metadata: + name: oauth2 + namespace: artifactapi +spec: + selector: + matchLabels: + app: oauth2 + podMetricsEndpoints: + - port: metrics + path: /metrics -- 2.47.3 From 7a9763e51b39c793a0489d4d152aa69d5cb25dce Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Mon, 7 Sep 2026 14:07:44 +1000 Subject: [PATCH 2/5] Keep the artifactapi UI/API split inside one HTTPRoute Cross-route path precedence is untested on this Traefik gateway; the single route already resolves /ui before / today. - Fold the /ui and /oauth2 rules back into api-route on both listeners. - Drop the separate ui-route and ui-http-redirect routes. --- apps/base/artifactapi/httproute.yaml | 73 +++++++--------------------- 1 file changed, 18 insertions(+), 55 deletions(-) diff --git a/apps/base/artifactapi/httproute.yaml b/apps/base/artifactapi/httproute.yaml index 9a72dad..aea1db2 100644 --- a/apps/base/artifactapi/httproute.yaml +++ b/apps/base/artifactapi/httproute.yaml @@ -1,6 +1,12 @@ --- -# API SIDE -- NOT AUTHENTICATED. Everything that is not /ui or /oauth2 lands -# here and goes straight to the api Service, exactly as before: +# Path split between the authenticated UI and the unauthenticated machine API. +# Longest matching prefix wins, so the two UI rules take precedence over "/". +# +# AUTHENTICATED (oauth2 Service -> oauth2-proxy -> ui Service): +# /oauth2 oauth2-proxy sign_in / start / callback / sign_out +# /ui the human-facing SPA +# +# NOT AUTHENTICATED (artifactapi Service, unchanged): # /api/v1/{remote,local,virtual}/* package proxy reads (yum/dnf, pip, ...) # /api/v2/remotes|virtuals|locals/* management API + the UI's own XHR calls # /api/v2/remotes/{name}/files/* CI publish uploads (PUT) and downloads @@ -8,7 +14,7 @@ # /terraform/v1/providers/* Terraform provider registry # /.well-known/terraform.json Terraform service discovery # /health, /version, / probes and the redirect to /ui/ -# These clients cannot complete a browser OIDC flow, so they must never be +# Those clients cannot complete a browser OIDC flow, so they must never be # routed through oauth2-proxy. apiVersion: gateway.networking.k8s.io/v1 kind: HTTPRoute @@ -33,33 +39,13 @@ spec: - backendRefs: - group: "" kind: Service - name: artifactapi + name: oauth2 port: 80 weight: 1 matches: - path: type: PathPrefix - value: / ---- -# UI SIDE -- AUTHENTICATED. Only the human-facing SPA and the oauth2-proxy -# endpoints (sign_in / start / callback / sign_out) go through the proxy, which -# requires an Authentik session in akP-artifactapi-admin and forwards to the ui -# Service. Longer path prefixes win over the api-route "/" rule above. -# HTTPS only: the session cookie is Secure, so a plain-HTTP session cannot work. -apiVersion: gateway.networking.k8s.io/v1 -kind: HTTPRoute -metadata: - name: ui-route - namespace: artifactapi -spec: - hostnames: - - artifactapi.k8s.syd1.au.unkin.net - parentRefs: - - group: gateway.networking.k8s.io - kind: Gateway - name: artifactapi - sectionName: https - rules: + value: /oauth2 - backendRefs: - group: "" kind: Service @@ -70,36 +56,13 @@ spec: - path: type: PathPrefix value: /ui - - path: - type: PathPrefix - value: /oauth2 ---- -# Send plain-HTTP browsers hitting the UI to HTTPS so they can obtain the Secure -# session cookie. Scoped to the UI paths only -- api-route keeps serving the -# package-manager surfaces over port 80 unredirected. -apiVersion: gateway.networking.k8s.io/v1 -kind: HTTPRoute -metadata: - name: ui-http-redirect - namespace: artifactapi -spec: - hostnames: - - artifactapi.k8s.syd1.au.unkin.net - parentRefs: - - group: gateway.networking.k8s.io - kind: Gateway - name: artifactapi - sectionName: http - rules: - - filters: - - type: RequestRedirect - requestRedirect: - scheme: https - statusCode: 301 + - backendRefs: + - group: "" + kind: Service + name: artifactapi + port: 80 + weight: 1 matches: - path: type: PathPrefix - value: /ui - - path: - type: PathPrefix - value: /oauth2 + value: / -- 2.47.3 From 57972e1a9fd7b5681b7ec82ac3d311ff59a7e80a Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Mon, 7 Sep 2026 14:07:58 +1000 Subject: [PATCH 3/5] Correct the oauth2 Service comment to name api-route --- apps/base/artifactapi/services.yaml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/apps/base/artifactapi/services.yaml b/apps/base/artifactapi/services.yaml index f42a84e..446499f 100644 --- a/apps/base/artifactapi/services.yaml +++ b/apps/base/artifactapi/services.yaml @@ -16,9 +16,9 @@ spec: sessionAffinity: None type: ClusterIP --- -# Authenticated front door for the web UI only: the ui-route HTTPRoute sends -# /ui and /oauth2 here, oauth2-proxy authenticates and forwards to the ui -# Service. The api Service above is reached directly and stays unauthenticated. +# Authenticated front door for the web UI only: api-route sends /ui and /oauth2 +# here, oauth2-proxy authenticates and forwards to the ui Service. Every other +# path reaches the api Service above directly and stays unauthenticated. apiVersion: v1 kind: Service metadata: -- 2.47.3 From af1f77618df46b06e2894ced8c24e0a8f029b9e9 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Mon, 7 Sep 2026 14:14:31 +1000 Subject: [PATCH 4/5] Use the browser-trusted Authentik host for the artifactapi OIDC issuer The authorize step is a browser redirect, so the issuer must present a publicly-trusted cert; identity.k8s.syd1.au.unkin.net serves an internal-CA cert that no user's browser trusts. - Point OAUTH2_PROXY_OIDC_ISSUER_URL at identity.unkin.net - Drop the combine-certs initContainer, its volumes/mounts and PROVIDER_CA_FILES: the pod's only other upstream is plain-HTTP in-cluster --- .../artifactapi/oauth2-proxy-configmap.yaml | 9 ++-- .../artifactapi/oauth2-proxy-deployment.yaml | 45 +------------------ 2 files changed, 5 insertions(+), 49 deletions(-) diff --git a/apps/base/artifactapi/oauth2-proxy-configmap.yaml b/apps/base/artifactapi/oauth2-proxy-configmap.yaml index 79f525c..672b4be 100644 --- a/apps/base/artifactapi/oauth2-proxy-configmap.yaml +++ b/apps/base/artifactapi/oauth2-proxy-configmap.yaml @@ -18,10 +18,10 @@ data: OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180" OAUTH2_PROXY_METRICS_ADDRESS: "0.0.0.0:44180" OAUTH2_PROXY_PROVIDER: "oidc" - # Internal-CA-served Authentik host (trusted via PROVIDER_CA_FILES below); - # Authentik issues the discovery document under the requested host, so the - # issuer is self-consistent. Slug from terraform-authentik. - OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.k8s.syd1.au.unkin.net/application/o/artifactapi/" + # Publicly-trusted Authentik host: the authorize step is a browser redirect, + # so the issuer must present a cert every user's browser already trusts (the + # k8s host serves an internal-CA cert). Slug from terraform-authentik. + OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/artifactapi/" OAUTH2_PROXY_REDIRECT_URL: "https://artifactapi.k8s.syd1.au.unkin.net/oauth2/callback" OAUTH2_PROXY_UPSTREAMS: "http://ui.artifactapi.svc.cluster.local:80/" OAUTH2_PROXY_SCOPE: "openid email profile ak_groups" @@ -37,6 +37,5 @@ data: OAUTH2_PROXY_COOKIE_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net" OAUTH2_PROXY_WHITELIST_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net" OAUTH2_PROXY_REVERSE_PROXY: "true" - OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt" OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256" OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true" diff --git a/apps/base/artifactapi/oauth2-proxy-deployment.yaml b/apps/base/artifactapi/oauth2-proxy-deployment.yaml index 74644d5..765135e 100644 --- a/apps/base/artifactapi/oauth2-proxy-deployment.yaml +++ b/apps/base/artifactapi/oauth2-proxy-deployment.yaml @@ -6,7 +6,7 @@ metadata: namespace: artifactapi annotations: configmap.reloader.stakater.com/auto: "true" - secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert" + secret.reloader.stakater.com/reload: "oauth-credentials" spec: replicas: 2 selector: @@ -30,36 +30,6 @@ spec: fsGroup: 65532 seccompProfile: type: RuntimeDefault - initContainers: - # identity.k8s.syd1.au.unkin.net serves a Vault-PKI cert; combine the - # system roots with the internal CA so oauth2-proxy's OIDC client - # trusts the discovery/token endpoints. - - name: combine-certs - image: alpine:3 - imagePullPolicy: IfNotPresent - command: - - sh - - -c - - cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt - volumeMounts: - - name: vault-ca-cert - mountPath: /custom-ca - readOnly: true - - name: combined-certs - mountPath: /combined-certs - securityContext: - allowPrivilegeEscalation: false - readOnlyRootFilesystem: true - capabilities: - drop: - - ALL - resources: - requests: - cpu: 50m - memory: 32Mi - limits: - cpu: 200m - memory: 64Mi containers: - name: oauth2-proxy image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3 @@ -91,10 +61,6 @@ spec: secretKeyRef: name: oauth-credentials key: cookie_secret - volumeMounts: - - name: combined-certs - mountPath: /etc/ssl/combined - readOnly: true livenessProbe: httpGet: path: /ping @@ -124,13 +90,4 @@ spec: limits: cpu: 500m memory: 256Mi - volumes: - - name: vault-ca-cert - secret: - secretName: vault-ca-cert - items: - - key: ca.crt - path: ca.crt - - name: combined-certs - emptyDir: {} restartPolicy: Always -- 2.47.3 From fc41c5778a063c7499aefdc0f49660b393cdd525 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Mon, 7 Sep 2026 14:20:24 +1000 Subject: [PATCH 5/5] Retrigger CI after a transient purelb chart download timeout -- 2.47.3