--- apiVersion: apps/v1 kind: Deployment metadata: name: arrproxy-oauth2 namespace: arrstack annotations: argocd.argoproj.io/sync-wave: "2" configmap.reloader.stakater.com/auto: "true" secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert" spec: replicas: 2 selector: matchLabels: app: arrproxy-oauth2 strategy: rollingUpdate: maxUnavailable: 1 type: RollingUpdate template: metadata: labels: app: arrproxy-oauth2 spec: serviceAccountName: default automountServiceAccountToken: false securityContext: runAsNonRoot: true runAsUser: 65532 runAsGroup: 65532 fsGroup: 65532 seccompProfile: type: RuntimeDefault initContainers: # identity.unkin.net serves a Vault-PKI cert; combine the system roots # with the internal CA so oauth2-proxy's OIDC HTTP client trusts it. - name: combine-certs image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/alpine:3 imagePullPolicy: IfNotPresent command: - sh - -c - cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt volumeMounts: - name: vault-ca-cert mountPath: /custom-ca readOnly: true - name: combined-certs mountPath: /combined-certs securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true capabilities: drop: - ALL resources: requests: cpu: 50m memory: 32Mi limits: cpu: 200m memory: 64Mi containers: - name: oauth2-proxy image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3 imagePullPolicy: IfNotPresent ports: - containerPort: 4180 name: http protocol: TCP envFrom: - configMapRef: name: arrproxy-oauth2-env optional: false env: - name: OAUTH2_PROXY_CLIENT_ID valueFrom: secretKeyRef: name: oauth-credentials key: client_id - name: OAUTH2_PROXY_CLIENT_SECRET valueFrom: secretKeyRef: name: oauth-credentials key: client_secret - name: OAUTH2_PROXY_COOKIE_SECRET valueFrom: secretKeyRef: name: oauth-credentials key: cookie_secret volumeMounts: - name: combined-certs mountPath: /etc/ssl/combined readOnly: true livenessProbe: httpGet: path: /ping port: http initialDelaySeconds: 10 periodSeconds: 30 timeoutSeconds: 5 failureThreshold: 3 readinessProbe: httpGet: path: /ready port: http initialDelaySeconds: 5 periodSeconds: 10 timeoutSeconds: 5 failureThreshold: 3 securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true capabilities: drop: - ALL resources: requests: cpu: 50m memory: 64Mi limits: cpu: 500m memory: 256Mi volumes: - name: vault-ca-cert secret: secretName: vault-ca-cert items: - key: ca.crt path: ca.crt - name: combined-certs emptyDir: {} restartPolicy: Always