6515e7f637
The vlselect query UI is only reachable in-cluster, so every log search needs a port-forward. Publish it at vlogs.unkin.net behind oauth2-proxy on the external (DMZ) Traefik. - Add `apps/base/logging/vlogs`: external Gateway, http->https redirect and main HTTPRoute - Terminate TLS with the reflected Let's Encrypt `*.unkin.net` wildcard; reflect it into `logging` - Publish the `vlogs` A record at the DMZ gateway VIP from the bind-operator `unkin.net` zone - Route all traffic through the `vlogs-oauth2` Service, upstreaming to `vlselect-logs:9471` - Gate on the Authentik `vlogs` application, group `akP-vlogs-admin` - Read OIDC credentials from `kv/kubernetes/namespace/logging/default/vlogs-oauth-credentials` Depends on unkin/terraform-authentik#40. Reviewed-on: #498 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
18 lines
386 B
YAML
18 lines
386 B
YAML
---
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: vlogs-oauth-credentials
|
|
namespace: logging
|
|
spec:
|
|
destination:
|
|
create: true
|
|
name: vlogs-oauth-credentials
|
|
overwrite: true
|
|
hmacSecretData: true
|
|
mount: kv
|
|
path: kubernetes/namespace/logging/default/vlogs-oauth-credentials
|
|
refreshAfter: 5m
|
|
type: kv-v2
|
|
vaultAuthRef: default
|