From efed6c8966c827a11b90c5f2feb710e4b45218ed Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Mon, 7 Sep 2026 22:32:48 +1000 Subject: [PATCH] artifactapi: restore combine-certs + PROVIDER_CA_FILES on oauth2-proxy #456 omitted the combine-certs initContainer and OAUTH2_PROXY_PROVIDER_CA_FILES on the grounds that identity.unkin.net serves a publicly trusted Let's Encrypt cert and so needs no internal CA. That reasoning holds for the browser redirect but not for oauth2-proxy's own back-channel calls: every other oauth2-proxy in the estate needs the internal bundle, including repospawner, which uses the same public identity.unkin.net issuer hostname. artifactapi is the only one of six without it (arrproxy, logviewer, mediamark, repospawner and watchstate all have it). This is NOT the current outage. The UI is 503 because the Authentik application slug artifactapi does not exist -- terraform-authentik's push/apply on main (4e16401) failed, so discovery 404s and oauth2-proxy never starts. This change removes the next blocker, which would surface as an x509 failure once that apply succeeds. - Add the combine-certs initContainer, byte-identical to repospawner's. - Mount the combined bundle and set OAUTH2_PROXY_PROVIDER_CA_FILES. - Reload the Deployment when vault-ca-cert rotates. Trust-only and strictly additive: it appends the internal CA to the system roots, so it is harmless if the back channel turns out to reach a publicly trusted endpoint after all. --- .../artifactapi/oauth2-proxy-configmap.yaml | 5 +++ .../artifactapi/oauth2-proxy-deployment.yaml | 45 ++++++++++++++++++- 2 files changed, 49 insertions(+), 1 deletion(-) diff --git a/apps/base/artifactapi/oauth2-proxy-configmap.yaml b/apps/base/artifactapi/oauth2-proxy-configmap.yaml index 672b4be..18fbc94 100644 --- a/apps/base/artifactapi/oauth2-proxy-configmap.yaml +++ b/apps/base/artifactapi/oauth2-proxy-configmap.yaml @@ -39,3 +39,8 @@ data: OAUTH2_PROXY_REVERSE_PROXY: "true" OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256" OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true" + # Back-channel discovery/token calls resolve the issuer inside the cluster, + # where it is served under the internal unkin.net CA rather than the publicly + # trusted cert the browser sees. Trust the bundle the combine-certs init + # container assembles, as every other oauth2-proxy in the estate does. + OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt" diff --git a/apps/base/artifactapi/oauth2-proxy-deployment.yaml b/apps/base/artifactapi/oauth2-proxy-deployment.yaml index 765135e..27c7ad4 100644 --- a/apps/base/artifactapi/oauth2-proxy-deployment.yaml +++ b/apps/base/artifactapi/oauth2-proxy-deployment.yaml @@ -6,7 +6,7 @@ metadata: namespace: artifactapi annotations: configmap.reloader.stakater.com/auto: "true" - secret.reloader.stakater.com/reload: "oauth-credentials" + secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert" spec: replicas: 2 selector: @@ -30,6 +30,36 @@ spec: fsGroup: 65532 seccompProfile: type: RuntimeDefault + initContainers: + # The Authentik issuer is served behind the internal unkin.net CA; + # combine the system roots with it so oauth2-proxy's OIDC HTTP client + # trusts the discovery endpoint. + - name: combine-certs + image: docker.io/library/alpine:3 + imagePullPolicy: IfNotPresent + command: + - sh + - -c + - cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt + volumeMounts: + - name: vault-ca-cert + mountPath: /custom-ca + readOnly: true + - name: combined-certs + mountPath: /combined-certs + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + capabilities: + drop: + - ALL + resources: + requests: + cpu: 50m + memory: 32Mi + limits: + cpu: 200m + memory: 64Mi containers: - name: oauth2-proxy image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3 @@ -83,6 +113,10 @@ spec: capabilities: drop: - ALL + volumeMounts: + - name: combined-certs + mountPath: /etc/ssl/combined + readOnly: true resources: requests: cpu: 50m @@ -90,4 +124,13 @@ spec: limits: cpu: 500m memory: 256Mi + volumes: + - name: vault-ca-cert + secret: + secretName: vault-ca-cert + items: + - key: ca.crt + path: ca.crt + - name: combined-certs + emptyDir: {} restartPolicy: Always -- 2.47.3