From 297168a3989467ec029a118040af962eeeebaa3d Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Mon, 7 Sep 2026 22:29:17 +1000 Subject: [PATCH] Revert "Put the artifactapi web UI behind Authentik oauth2-proxy (#456)" This reverts commit c98d88c1978c63b15d42583af65f6ef9af45f727. The artifactapi web UI has been down since #456 merged: /ui/ and /oauth2/ both return 503 "no available server", Traefik's response for a Service with no ready endpoints, so the oauth2-proxy pod is not becoming ready. The machine API surface (/version, /api/v2/health, /v2/, /.well-known/terraform.json) is unaffected and still returns 200. Rolling back restores unauthenticated access to the UI at /ui, served directly by the ui Service exactly as before. - Point the api-route /ui rule back at the ui Service and drop the /oauth2 rule. - Remove the oauth2-proxy ConfigMap, Deployment, Service and VMPodScrape. - Remove the oauth-credentials VaultStaticSecret. The apps/base/artifactapi tree is byte-identical to 520da44, the commit immediately before #456. Nothing that landed since is touched. --- apps/base/artifactapi/httproute.yaml | 29 +----- apps/base/artifactapi/kustomization.yaml | 2 - .../artifactapi/oauth2-proxy-configmap.yaml | 41 -------- .../artifactapi/oauth2-proxy-deployment.yaml | 93 ------------------- apps/base/artifactapi/services.yaml | 20 ---- apps/base/artifactapi/vaultstaticsecret.yaml | 23 ----- apps/base/artifactapi/vmpodscrape.yaml | 14 --- 7 files changed, 1 insertion(+), 221 deletions(-) delete mode 100644 apps/base/artifactapi/oauth2-proxy-configmap.yaml delete mode 100644 apps/base/artifactapi/oauth2-proxy-deployment.yaml diff --git a/apps/base/artifactapi/httproute.yaml b/apps/base/artifactapi/httproute.yaml index aea1db2..775e004 100644 --- a/apps/base/artifactapi/httproute.yaml +++ b/apps/base/artifactapi/httproute.yaml @@ -1,21 +1,4 @@ --- -# Path split between the authenticated UI and the unauthenticated machine API. -# Longest matching prefix wins, so the two UI rules take precedence over "/". -# -# AUTHENTICATED (oauth2 Service -> oauth2-proxy -> ui Service): -# /oauth2 oauth2-proxy sign_in / start / callback / sign_out -# /ui the human-facing SPA -# -# NOT AUTHENTICATED (artifactapi Service, unchanged): -# /api/v1/{remote,local,virtual}/* package proxy reads (yum/dnf, pip, ...) -# /api/v2/remotes|virtuals|locals/* management API + the UI's own XHR calls -# /api/v2/remotes/{name}/files/* CI publish uploads (PUT) and downloads -# /v2/* Docker Registry V2 (containerd, buildah) -# /terraform/v1/providers/* Terraform provider registry -# /.well-known/terraform.json Terraform service discovery -# /health, /version, / probes and the redirect to /ui/ -# Those clients cannot complete a browser OIDC flow, so they must never be -# routed through oauth2-proxy. apiVersion: gateway.networking.k8s.io/v1 kind: HTTPRoute metadata: @@ -39,17 +22,7 @@ spec: - backendRefs: - group: "" kind: Service - name: oauth2 - port: 80 - weight: 1 - matches: - - path: - type: PathPrefix - value: /oauth2 - - backendRefs: - - group: "" - kind: Service - name: oauth2 + name: ui port: 80 weight: 1 matches: diff --git a/apps/base/artifactapi/kustomization.yaml b/apps/base/artifactapi/kustomization.yaml index 6053989..8e5a482 100644 --- a/apps/base/artifactapi/kustomization.yaml +++ b/apps/base/artifactapi/kustomization.yaml @@ -12,8 +12,6 @@ resources: - gateway.yaml - httproute.yaml - namespace.yaml - - oauth2-proxy-configmap.yaml - - oauth2-proxy-deployment.yaml - redis-deployment.yaml - services.yaml - ui-deployment.yaml diff --git a/apps/base/artifactapi/oauth2-proxy-configmap.yaml b/apps/base/artifactapi/oauth2-proxy-configmap.yaml deleted file mode 100644 index 672b4be..0000000 --- a/apps/base/artifactapi/oauth2-proxy-configmap.yaml +++ /dev/null @@ -1,41 +0,0 @@ ---- -# Non-secret oauth2-proxy configuration (client_id/secret/cookie_secret come -# from the oauth-credentials Secret). -# -# SCOPE: this proxy fronts the artifactapi web UI ONLY. The HTTPRoute sends just -# /ui and /oauth2 here; every machine surface (/api/v1, /api/v2, /v2 docker -# registry, /terraform, /.well-known/terraform.json, /health, /version, /) goes -# straight to the api Service and is NOT authenticated. yum/dnf, containerd -# registry mirrors, docker/buildah, terraform init and Woodpecker publish steps -# cannot complete a browser OIDC flow, so they must never reach this container. -# Its only upstream is the ui Service -- there is deliberately no api upstream. -apiVersion: v1 -kind: ConfigMap -metadata: - name: artifactapi-oauth2-env - namespace: artifactapi -data: - OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180" - OAUTH2_PROXY_METRICS_ADDRESS: "0.0.0.0:44180" - OAUTH2_PROXY_PROVIDER: "oidc" - # Publicly-trusted Authentik host: the authorize step is a browser redirect, - # so the issuer must present a cert every user's browser already trusts (the - # k8s host serves an internal-CA cert). Slug from terraform-authentik. - OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/artifactapi/" - OAUTH2_PROXY_REDIRECT_URL: "https://artifactapi.k8s.syd1.au.unkin.net/oauth2/callback" - OAUTH2_PROXY_UPSTREAMS: "http://ui.artifactapi.svc.cluster.local:80/" - OAUTH2_PROXY_SCOPE: "openid email profile ak_groups" - # Populate session.Groups from the Authentik hierarchical ak_groups claim. - OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups" - OAUTH2_PROXY_ALLOWED_GROUPS: "akP-artifactapi-admin" - OAUTH2_PROXY_PASS_USER_HEADERS: "true" - OAUTH2_PROXY_EMAIL_DOMAINS: "*" - # Authentik hardcodes email_verified=false in the id_token; authorization is - # enforced via ak_groups, so accepting the unverified email is safe. - OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true" - OAUTH2_PROXY_COOKIE_SECURE: "true" - OAUTH2_PROXY_COOKIE_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net" - OAUTH2_PROXY_WHITELIST_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net" - OAUTH2_PROXY_REVERSE_PROXY: "true" - OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256" - OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true" diff --git a/apps/base/artifactapi/oauth2-proxy-deployment.yaml b/apps/base/artifactapi/oauth2-proxy-deployment.yaml deleted file mode 100644 index 765135e..0000000 --- a/apps/base/artifactapi/oauth2-proxy-deployment.yaml +++ /dev/null @@ -1,93 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: oauth2 - namespace: artifactapi - annotations: - configmap.reloader.stakater.com/auto: "true" - secret.reloader.stakater.com/reload: "oauth-credentials" -spec: - replicas: 2 - selector: - matchLabels: - app: oauth2 - strategy: - rollingUpdate: - maxUnavailable: 1 - type: RollingUpdate - template: - metadata: - labels: - app: oauth2 - spec: - serviceAccountName: default - automountServiceAccountToken: false - securityContext: - runAsNonRoot: true - runAsUser: 65532 - runAsGroup: 65532 - fsGroup: 65532 - seccompProfile: - type: RuntimeDefault - containers: - - name: oauth2-proxy - image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3 - imagePullPolicy: IfNotPresent - ports: - - containerPort: 4180 - name: http - protocol: TCP - - containerPort: 44180 - name: metrics - protocol: TCP - envFrom: - - configMapRef: - name: artifactapi-oauth2-env - optional: false - env: - - name: OAUTH2_PROXY_CLIENT_ID - valueFrom: - secretKeyRef: - name: oauth-credentials - key: client_id - - name: OAUTH2_PROXY_CLIENT_SECRET - valueFrom: - secretKeyRef: - name: oauth-credentials - key: client_secret - - name: OAUTH2_PROXY_COOKIE_SECRET - valueFrom: - secretKeyRef: - name: oauth-credentials - key: cookie_secret - livenessProbe: - httpGet: - path: /ping - port: http - initialDelaySeconds: 10 - periodSeconds: 30 - timeoutSeconds: 5 - failureThreshold: 3 - readinessProbe: - httpGet: - path: /ready - port: http - initialDelaySeconds: 5 - periodSeconds: 10 - timeoutSeconds: 5 - failureThreshold: 3 - securityContext: - allowPrivilegeEscalation: false - readOnlyRootFilesystem: true - capabilities: - drop: - - ALL - resources: - requests: - cpu: 50m - memory: 64Mi - limits: - cpu: 500m - memory: 256Mi - restartPolicy: Always diff --git a/apps/base/artifactapi/services.yaml b/apps/base/artifactapi/services.yaml index 446499f..13aa628 100644 --- a/apps/base/artifactapi/services.yaml +++ b/apps/base/artifactapi/services.yaml @@ -16,26 +16,6 @@ spec: sessionAffinity: None type: ClusterIP --- -# Authenticated front door for the web UI only: api-route sends /ui and /oauth2 -# here, oauth2-proxy authenticates and forwards to the ui Service. Every other -# path reaches the api Service above directly and stays unauthenticated. -apiVersion: v1 -kind: Service -metadata: - name: oauth2 - namespace: artifactapi -spec: - internalTrafficPolicy: Cluster - ports: - - name: http - port: 80 - protocol: TCP - targetPort: http - selector: - app: oauth2 - sessionAffinity: None - type: ClusterIP ---- apiVersion: v1 kind: Service metadata: diff --git a/apps/base/artifactapi/vaultstaticsecret.yaml b/apps/base/artifactapi/vaultstaticsecret.yaml index c4f3e00..6c92999 100644 --- a/apps/base/artifactapi/vaultstaticsecret.yaml +++ b/apps/base/artifactapi/vaultstaticsecret.yaml @@ -32,26 +32,3 @@ spec: refreshAfter: 5m type: kv-v2 vaultAuthRef: default ---- -# Authentik OIDC client for the artifactapi UI front door (client_id, -# client_secret, cookie_secret). Seeded out of band at -# kv/kubernetes/namespace/artifactapi/default/oauth-credentials; the default -# k8s auth role already grants the artifactapi/default ServiceAccount read on -# kv/data/kubernetes/namespace/{{sa_namespace}}/{{sa_name}}/*, so no -# terraform-vault change is needed. Consumed by the oauth2 Deployment. -apiVersion: secrets.hashicorp.com/v1beta1 -kind: VaultStaticSecret -metadata: - name: oauth-credentials - namespace: artifactapi -spec: - destination: - create: true - name: oauth-credentials - overwrite: true - hmacSecretData: true - mount: kv - path: kubernetes/namespace/artifactapi/default/oauth-credentials - refreshAfter: 5m - type: kv-v2 - vaultAuthRef: default diff --git a/apps/base/artifactapi/vmpodscrape.yaml b/apps/base/artifactapi/vmpodscrape.yaml index 61883ca..6e26cea 100644 --- a/apps/base/artifactapi/vmpodscrape.yaml +++ b/apps/base/artifactapi/vmpodscrape.yaml @@ -14,17 +14,3 @@ spec: podMetricsEndpoints: - port: metrics path: /metrics ---- -# Scrape the UI oauth2-proxy (:44180), which exposes sign-in/authz counters. -apiVersion: operator.victoriametrics.com/v1beta1 -kind: VMPodScrape -metadata: - name: oauth2 - namespace: artifactapi -spec: - selector: - matchLabels: - app: oauth2 - podMetricsEndpoints: - - port: metrics - path: /metrics -- 2.47.3