diff --git a/apps/base/artifactapi/oauth2-proxy-configmap.yaml b/apps/base/artifactapi/oauth2-proxy-configmap.yaml index 672b4be..18fbc94 100644 --- a/apps/base/artifactapi/oauth2-proxy-configmap.yaml +++ b/apps/base/artifactapi/oauth2-proxy-configmap.yaml @@ -39,3 +39,8 @@ data: OAUTH2_PROXY_REVERSE_PROXY: "true" OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256" OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true" + # Back-channel discovery/token calls resolve the issuer inside the cluster, + # where it is served under the internal unkin.net CA rather than the publicly + # trusted cert the browser sees. Trust the bundle the combine-certs init + # container assembles, as every other oauth2-proxy in the estate does. + OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt" diff --git a/apps/base/artifactapi/oauth2-proxy-deployment.yaml b/apps/base/artifactapi/oauth2-proxy-deployment.yaml index 765135e..27c7ad4 100644 --- a/apps/base/artifactapi/oauth2-proxy-deployment.yaml +++ b/apps/base/artifactapi/oauth2-proxy-deployment.yaml @@ -6,7 +6,7 @@ metadata: namespace: artifactapi annotations: configmap.reloader.stakater.com/auto: "true" - secret.reloader.stakater.com/reload: "oauth-credentials" + secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert" spec: replicas: 2 selector: @@ -30,6 +30,36 @@ spec: fsGroup: 65532 seccompProfile: type: RuntimeDefault + initContainers: + # The Authentik issuer is served behind the internal unkin.net CA; + # combine the system roots with it so oauth2-proxy's OIDC HTTP client + # trusts the discovery endpoint. + - name: combine-certs + image: docker.io/library/alpine:3 + imagePullPolicy: IfNotPresent + command: + - sh + - -c + - cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt + volumeMounts: + - name: vault-ca-cert + mountPath: /custom-ca + readOnly: true + - name: combined-certs + mountPath: /combined-certs + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + capabilities: + drop: + - ALL + resources: + requests: + cpu: 50m + memory: 32Mi + limits: + cpu: 200m + memory: 64Mi containers: - name: oauth2-proxy image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3 @@ -83,6 +113,10 @@ spec: capabilities: drop: - ALL + volumeMounts: + - name: combined-certs + mountPath: /etc/ssl/combined + readOnly: true resources: requests: cpu: 50m @@ -90,4 +124,13 @@ spec: limits: cpu: 500m memory: 256Mi + volumes: + - name: vault-ca-cert + secret: + secretName: vault-ca-cert + items: + - key: ca.crt + path: ca.crt + - name: combined-certs + emptyDir: {} restartPolicy: Always