--- # Non-secret oauth2-proxy configuration (client_id/secret/cookie_secret come # from the oauth-credentials Secret). # # SCOPE: this proxy fronts the artifactapi web UI ONLY. The HTTPRoute sends just # /ui and /oauth2 here; every machine surface (/api/v1, /api/v2, /v2 docker # registry, /terraform, /.well-known/terraform.json, /health, /version, /) goes # straight to the api Service and is NOT authenticated. yum/dnf, containerd # registry mirrors, docker/buildah, terraform init and Woodpecker publish steps # cannot complete a browser OIDC flow, so they must never reach this container. # Its only upstream is the ui Service -- there is deliberately no api upstream. apiVersion: v1 kind: ConfigMap metadata: name: artifactapi-oauth2-env namespace: artifactapi data: OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180" OAUTH2_PROXY_METRICS_ADDRESS: "0.0.0.0:44180" OAUTH2_PROXY_PROVIDER: "oidc" # Publicly-trusted Authentik host: the authorize step is a browser redirect, # so the issuer must present a cert every user's browser already trusts (the # k8s host serves an internal-CA cert). Slug from terraform-authentik. OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/artifactapi/" OAUTH2_PROXY_REDIRECT_URL: "https://artifactapi.k8s.syd1.au.unkin.net/oauth2/callback" OAUTH2_PROXY_UPSTREAMS: "http://ui.artifactapi.svc.cluster.local:80/" OAUTH2_PROXY_SCOPE: "openid email profile ak_groups" # Populate session.Groups from the Authentik hierarchical ak_groups claim. OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups" OAUTH2_PROXY_ALLOWED_GROUPS: "akP-artifactapi-admin" OAUTH2_PROXY_PASS_USER_HEADERS: "true" OAUTH2_PROXY_EMAIL_DOMAINS: "*" # Authentik hardcodes email_verified=false in the id_token; authorization is # enforced via ak_groups, so accepting the unverified email is safe. OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true" OAUTH2_PROXY_COOKIE_SECURE: "true" OAUTH2_PROXY_COOKIE_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net" OAUTH2_PROXY_WHITELIST_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net" OAUTH2_PROXY_REVERSE_PROXY: "true" OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256" OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true" # Back-channel discovery/token calls resolve the issuer inside the cluster, # where it is served under the internal unkin.net CA rather than the publicly # trusted cert the browser sees. Trust the bundle the combine-certs init # container assembles, as every other oauth2-proxy in the estate does. OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt"