6f62b7873f
## Why Consume the two-tier Authentik RBAC from terraform-authentik#7. Grafana should grant Admin to the `akP-grafana-admin` permission group, which `akR-global-admin` members inherit. ## Change - **grafana.yaml** (`auth.generic_oauth`): add `ak_groups` to `scopes`; `role_attribute_path` now keys off `ak_groups` and `akP-grafana-admin` (replaces the flat `grafana-admins`). Non-admins who can log in (gated to `akP-grafana-*` by the Authentik access policy) get Viewer; `role_attribute_strict: false` retained. ## Depends on terraform-authentik#7 (creates `akP-grafana-admin`, the access binding, and the `ak_groups` mapping). ## Validation `kustomize build` (base + overlay) renders; pre-commit clean. Reviewed-on: #264 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
64 lines
2.1 KiB
YAML
64 lines
2.1 KiB
YAML
---
|
|
apiVersion: grafana.integreatly.org/v1beta1
|
|
kind: Grafana
|
|
metadata:
|
|
name: grafana
|
|
namespace: grafana
|
|
labels:
|
|
dashboards: "grafana"
|
|
spec:
|
|
deployment:
|
|
spec:
|
|
template:
|
|
spec:
|
|
containers:
|
|
- name: grafana
|
|
env:
|
|
# DB password + OAuth client secret injected from the
|
|
# Vault-synced secrets (GF_ env overrides grafana.ini).
|
|
- name: GF_DATABASE_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: postgres-credentials
|
|
key: password
|
|
- name: GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: oauth-credentials
|
|
key: client_secret
|
|
resources:
|
|
requests:
|
|
cpu: 100m
|
|
memory: 256Mi
|
|
limits:
|
|
cpu: "1"
|
|
memory: 1Gi
|
|
config:
|
|
server:
|
|
root_url: "https://grafana.k8s.syd1.au.unkin.net"
|
|
database:
|
|
type: "postgres"
|
|
host: "postgres-pooler-rw.grafana.svc.cluster.local:5432"
|
|
name: "grafana"
|
|
user: "grafana"
|
|
ssl_mode: "require"
|
|
auth:
|
|
disable_login_form: "false"
|
|
oauth_auto_login: "false"
|
|
"auth.generic_oauth":
|
|
enabled: "true"
|
|
name: "Authentik"
|
|
allow_sign_up: "true"
|
|
use_pkce: "true"
|
|
client_id: "grafana"
|
|
# ak_groups = hierarchical group claim from terraform-authentik (carries
|
|
# permission groups inherited via role groups).
|
|
scopes: "openid email profile ak_groups"
|
|
auth_url: "https://identity.unkin.net/application/o/authorize/"
|
|
token_url: "https://identity.unkin.net/application/o/token/"
|
|
api_url: "https://identity.unkin.net/application/o/userinfo/"
|
|
# Authentik permission groups -> Grafana roles. akP-grafana-admin is granted
|
|
# to akR-global-admin members (and direct members) via terraform-authentik.
|
|
role_attribute_path: "contains(ak_groups[*], 'akP-grafana-admin') && 'Admin' || 'Viewer'"
|
|
role_attribute_strict: "false"
|