dfb495d771
Authentik is canonical at https://identity.unkin.net, served by the internal unkin.net CA. Grafana, LiteLLM and NetBox failed OIDC discovery because their images don't trust that CA (x509: unknown authority); NetBox also still pointed at the secondary admin host. - grafana: mount the reflected vault-ca-cert; set generic_oauth `tls_client_ca`. - litellm: `combine-certs` init builds public+internal CA bundle; `SSL_CERT_FILE` + `REQUESTS_CA_BUNDLE` point at it. - netbox: flip OIDC issuer to identity.unkin.net; same combine bundle for python-social-auth (`requests`). - docs: record the Rancher manual runtime step (issuer + CA in the auth config). Validated: kustomize build + kubeconform + pre-commit. https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv Reviewed-on: #314 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
48 lines
1.7 KiB
YAML
48 lines
1.7 KiB
YAML
---
|
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
kind: Kustomization
|
|
|
|
resources:
|
|
- cnpg_cluster.yaml
|
|
- cnpg_backup.yaml
|
|
- cnpg_pooler.yaml
|
|
- deployment.yaml
|
|
- hpa.yaml
|
|
- gateway.yaml
|
|
- httproute.yaml
|
|
- namespace.yaml
|
|
- redis-deployment.yaml
|
|
- redis-pvc.yaml
|
|
- services.yaml
|
|
- vaultauth.yaml
|
|
- vaultstaticsecret.yaml
|
|
- vpa.yaml
|
|
|
|
configMapGenerator:
|
|
- name: litellm-config
|
|
files:
|
|
- config.yaml=resources/config.yaml
|
|
options:
|
|
disableNameSuffixHash: true
|
|
- name: litellm-env
|
|
literals:
|
|
- STORE_MODEL_IN_DB=True
|
|
# Authentik OIDC SSO (generic). Client secret is injected from the
|
|
# oauth-credentials Secret in the Deployment; endpoints match the other
|
|
# apps (identity.unkin.net). PROXY_BASE_URL is required for SSO.
|
|
- GENERIC_CLIENT_ID=litellm
|
|
- GENERIC_AUTHORIZATION_ENDPOINT=https://identity.unkin.net/application/o/authorize/
|
|
- GENERIC_TOKEN_ENDPOINT=https://identity.unkin.net/application/o/token/
|
|
- GENERIC_USERINFO_ENDPOINT=https://identity.unkin.net/application/o/userinfo/
|
|
# litellm_role scope carries the Authentik-computed role claim; LiteLLM
|
|
# reads it via GENERIC_USER_ROLE_ATTRIBUTE and maps to proxy_admin/etc.
|
|
- GENERIC_SCOPE=openid email profile litellm_role
|
|
- GENERIC_USER_ROLE_ATTRIBUTE=litellm_role
|
|
- PROXY_BASE_URL=https://litellm.k8s.syd1.au.unkin.net
|
|
# Trust the internal unkin.net CA (identity.unkin.net) via the combined
|
|
# bundle assembled by the combine-certs init container.
|
|
- SSL_CERT_FILE=/etc/ssl/combined/ca-certificates.crt
|
|
- REQUESTS_CA_BUNDLE=/etc/ssl/combined/ca-certificates.crt
|
|
options:
|
|
disableNameSuffixHash: true
|