7aec9a9021
**Fix-forward companion to the #457 rollback. This is NOT the current outage fix — see below.** ## The actual outage The UI is 503 because the Authentik application slug `artifactapi` **does not exist**. OIDC discovery 404s, so oauth2-proxy exits at startup, the Service has no ready endpoints, and Traefik answers `no available server`. ``` identity.unkin.net /application/o/artifactapi/… 404 identity.k8s.syd1.au.unkin.net /application/o/artifactapi/… 404 identity.unkin.net /application/o/repospawner/… 200 identity.unkin.net /application/o/argocd/… 200 ``` Root cause is upstream in **terraform-authentik**: `ci/woodpecker/push/apply` on main HEAD `4e16401` **failed**. That apply has to succeed before any argocd-apps change can help. **This PR does not fix that.** ## What this PR does fix #456 dropped the `combine-certs` initContainer and `OAUTH2_PROXY_PROVIDER_CA_FILES`, reasoning that `identity.unkin.net` serves a publicly trusted Let's Encrypt cert and so needs no internal CA. That holds for the browser redirect but not for oauth2-proxy's own back-channel discovery/token calls. artifactapi is the **only one of six** oauth2-proxies in the estate without it: | app | issuer host | `PROVIDER_CA_FILES` | |---|---|---| | arrproxy | identity.unkin.net | yes | | logviewer | identity.unkin.net | yes | | mediamark | identity.unkin.net | yes | | repospawner | identity.unkin.net | yes | | watchstate | identity.k8s… | yes | | **artifactapi** | identity.unkin.net | **no** | repospawner uses the **same public `identity.unkin.net` issuer** and still needs the internal bundle, which falsifies the removal reasoning. The existing comment on that initContainer states it plainly: *"The Authentik issuer is served behind the internal unkin.net CA."* ## Changes - Add the `combine-certs` initContainer — byte-identical to repospawner's. - Mount the combined bundle and set `OAUTH2_PROXY_PROVIDER_CA_FILES`. - Reload the Deployment when `vault-ca-cert` rotates. `vault-ca-cert` already exists in the `artifactapi` namespace (`api-deployment.yaml` uses it). `kustomize build apps/base/artifactapi` succeeds. ## Risk Trust-only and strictly additive — it appends the internal CA to the system roots. Harmless if the back channel turns out to reach a publicly trusted endpoint after all. Expected to remove the *next* blocker, surfacing as x509, once the terraform-authentik apply lands. ## Sequencing 1. Fix and re-run terraform-authentik `push/apply` so the `artifactapi` application exists. 2. Merge this. 3. Confirm `/ui/` returns 200, then close #457 unmerged. Only merge #457 instead if the UI must come back before step 1 can be done. Reviewed-on: #458 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
47 lines
2.5 KiB
YAML
47 lines
2.5 KiB
YAML
---
|
|
# Non-secret oauth2-proxy configuration (client_id/secret/cookie_secret come
|
|
# from the oauth-credentials Secret).
|
|
#
|
|
# SCOPE: this proxy fronts the artifactapi web UI ONLY. The HTTPRoute sends just
|
|
# /ui and /oauth2 here; every machine surface (/api/v1, /api/v2, /v2 docker
|
|
# registry, /terraform, /.well-known/terraform.json, /health, /version, /) goes
|
|
# straight to the api Service and is NOT authenticated. yum/dnf, containerd
|
|
# registry mirrors, docker/buildah, terraform init and Woodpecker publish steps
|
|
# cannot complete a browser OIDC flow, so they must never reach this container.
|
|
# Its only upstream is the ui Service -- there is deliberately no api upstream.
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: artifactapi-oauth2-env
|
|
namespace: artifactapi
|
|
data:
|
|
OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180"
|
|
OAUTH2_PROXY_METRICS_ADDRESS: "0.0.0.0:44180"
|
|
OAUTH2_PROXY_PROVIDER: "oidc"
|
|
# Publicly-trusted Authentik host: the authorize step is a browser redirect,
|
|
# so the issuer must present a cert every user's browser already trusts (the
|
|
# k8s host serves an internal-CA cert). Slug from terraform-authentik.
|
|
OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/artifactapi/"
|
|
OAUTH2_PROXY_REDIRECT_URL: "https://artifactapi.k8s.syd1.au.unkin.net/oauth2/callback"
|
|
OAUTH2_PROXY_UPSTREAMS: "http://ui.artifactapi.svc.cluster.local:80/"
|
|
OAUTH2_PROXY_SCOPE: "openid email profile ak_groups"
|
|
# Populate session.Groups from the Authentik hierarchical ak_groups claim.
|
|
OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups"
|
|
OAUTH2_PROXY_ALLOWED_GROUPS: "akP-artifactapi-admin"
|
|
OAUTH2_PROXY_PASS_USER_HEADERS: "true"
|
|
OAUTH2_PROXY_EMAIL_DOMAINS: "*"
|
|
# Authentik hardcodes email_verified=false in the id_token; authorization is
|
|
# enforced via ak_groups, so accepting the unverified email is safe.
|
|
OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true"
|
|
OAUTH2_PROXY_COOKIE_SECURE: "true"
|
|
OAUTH2_PROXY_COOKIE_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net"
|
|
OAUTH2_PROXY_WHITELIST_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net"
|
|
OAUTH2_PROXY_REVERSE_PROXY: "true"
|
|
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
|
|
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
|
|
# Back-channel discovery/token calls resolve the issuer inside the cluster,
|
|
# where it is served under the internal unkin.net CA rather than the publicly
|
|
# trusted cert the browser sees. Trust the bundle the combine-certs init
|
|
# container assembles, as every other oauth2-proxy in the estate does.
|
|
OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt"
|