artifactapi: restore combine-certs + PROVIDER_CA_FILES on oauth2-proxy #458
@@ -39,3 +39,8 @@ data:
|
|||||||
OAUTH2_PROXY_REVERSE_PROXY: "true"
|
OAUTH2_PROXY_REVERSE_PROXY: "true"
|
||||||
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
|
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
|
||||||
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
|
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
|
||||||
|
# Back-channel discovery/token calls resolve the issuer inside the cluster,
|
||||||
|
# where it is served under the internal unkin.net CA rather than the publicly
|
||||||
|
# trusted cert the browser sees. Trust the bundle the combine-certs init
|
||||||
|
# container assembles, as every other oauth2-proxy in the estate does.
|
||||||
|
OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt"
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ metadata:
|
|||||||
namespace: artifactapi
|
namespace: artifactapi
|
||||||
annotations:
|
annotations:
|
||||||
configmap.reloader.stakater.com/auto: "true"
|
configmap.reloader.stakater.com/auto: "true"
|
||||||
secret.reloader.stakater.com/reload: "oauth-credentials"
|
secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert"
|
||||||
spec:
|
spec:
|
||||||
replicas: 2
|
replicas: 2
|
||||||
selector:
|
selector:
|
||||||
@@ -30,6 +30,36 @@ spec:
|
|||||||
fsGroup: 65532
|
fsGroup: 65532
|
||||||
seccompProfile:
|
seccompProfile:
|
||||||
type: RuntimeDefault
|
type: RuntimeDefault
|
||||||
|
initContainers:
|
||||||
|
# The Authentik issuer is served behind the internal unkin.net CA;
|
||||||
|
# combine the system roots with it so oauth2-proxy's OIDC HTTP client
|
||||||
|
# trusts the discovery endpoint.
|
||||||
|
- name: combine-certs
|
||||||
|
image: docker.io/library/alpine:3
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt
|
||||||
|
volumeMounts:
|
||||||
|
- name: vault-ca-cert
|
||||||
|
mountPath: /custom-ca
|
||||||
|
readOnly: true
|
||||||
|
- name: combined-certs
|
||||||
|
mountPath: /combined-certs
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 32Mi
|
||||||
|
limits:
|
||||||
|
cpu: 200m
|
||||||
|
memory: 64Mi
|
||||||
containers:
|
containers:
|
||||||
- name: oauth2-proxy
|
- name: oauth2-proxy
|
||||||
image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3
|
image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3
|
||||||
@@ -83,6 +113,10 @@ spec:
|
|||||||
capabilities:
|
capabilities:
|
||||||
drop:
|
drop:
|
||||||
- ALL
|
- ALL
|
||||||
|
volumeMounts:
|
||||||
|
- name: combined-certs
|
||||||
|
mountPath: /etc/ssl/combined
|
||||||
|
readOnly: true
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: 50m
|
cpu: 50m
|
||||||
@@ -90,4 +124,13 @@ spec:
|
|||||||
limits:
|
limits:
|
||||||
cpu: 500m
|
cpu: 500m
|
||||||
memory: 256Mi
|
memory: 256Mi
|
||||||
|
volumes:
|
||||||
|
- name: vault-ca-cert
|
||||||
|
secret:
|
||||||
|
secretName: vault-ca-cert
|
||||||
|
items:
|
||||||
|
- key: ca.crt
|
||||||
|
path: ca.crt
|
||||||
|
- name: combined-certs
|
||||||
|
emptyDir: {}
|
||||||
restartPolicy: Always
|
restartPolicy: Always
|
||||||
|
|||||||
Reference in New Issue
Block a user