--- # Non-secret oauth2-proxy configuration (client_id/secret/cookie_secret come # from the watchstate-oauth-credentials Secret). Single auth front for the # WatchState UI + API: every path requires a valid Authentik session. Access is # authorized Authentik-side (the watchstate application binds akR-global-admin # only), so no oauth2-proxy group allowlist is set here. apiVersion: v1 kind: ConfigMap metadata: name: watchstate-oauth2-env namespace: watchstate data: OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180" OAUTH2_PROXY_PROVIDER: "oidc" OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.k8s.syd1.au.unkin.net/application/o/watchstate/" OAUTH2_PROXY_REDIRECT_URL: "https://watchstate.k8s.syd1.au.unkin.net/oauth2/callback" OAUTH2_PROXY_UPSTREAMS: "http://watchstate.watchstate.svc.cluster.local:8080/" OAUTH2_PROXY_SCOPE: "openid email profile ak_groups" OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups" OAUTH2_PROXY_PASS_USER_HEADERS: "true" OAUTH2_PROXY_EMAIL_DOMAINS: "*" # Authentik hardcodes email_verified=false in the id_token; authorization is # enforced Authentik-side, so accepting the unverified email is safe. OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true" OAUTH2_PROXY_COOKIE_SECURE: "true" OAUTH2_PROXY_COOKIE_DOMAINS: "watchstate.k8s.syd1.au.unkin.net" OAUTH2_PROXY_WHITELIST_DOMAINS: "watchstate.k8s.syd1.au.unkin.net" OAUTH2_PROXY_REVERSE_PROXY: "true" OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt" OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256" OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"