dfb495d771
Authentik is canonical at https://identity.unkin.net, served by the internal unkin.net CA. Grafana, LiteLLM and NetBox failed OIDC discovery because their images don't trust that CA (x509: unknown authority); NetBox also still pointed at the secondary admin host. - grafana: mount the reflected vault-ca-cert; set generic_oauth `tls_client_ca`. - litellm: `combine-certs` init builds public+internal CA bundle; `SSL_CERT_FILE` + `REQUESTS_CA_BUNDLE` point at it. - netbox: flip OIDC issuer to identity.unkin.net; same combine bundle for python-social-auth (`requests`). - docs: record the Rancher manual runtime step (issuer + CA in the auth config). Validated: kustomize build + kubeconform + pre-commit. https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv Reviewed-on: #314 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
81 lines
2.9 KiB
YAML
81 lines
2.9 KiB
YAML
---
|
|
apiVersion: grafana.integreatly.org/v1beta1
|
|
kind: Grafana
|
|
metadata:
|
|
name: grafana
|
|
namespace: grafana
|
|
labels:
|
|
dashboards: "grafana"
|
|
spec:
|
|
deployment:
|
|
spec:
|
|
template:
|
|
spec:
|
|
containers:
|
|
- name: grafana
|
|
env:
|
|
# DB password + OAuth client secret injected from the
|
|
# Vault-synced secrets (GF_ env overrides grafana.ini).
|
|
- name: GF_DATABASE_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: postgres-credentials
|
|
key: password
|
|
- name: GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: oauth-credentials
|
|
key: client_secret
|
|
# identity.unkin.net is served by the internal unkin.net CA, which
|
|
# the stock Grafana image doesn't trust. Mount the reflected
|
|
# vault-ca-cert and point generic_oauth's tls_client_ca at it.
|
|
volumeMounts:
|
|
- name: vault-ca-cert
|
|
mountPath: /etc/grafana/vault-ca
|
|
readOnly: true
|
|
resources:
|
|
requests:
|
|
cpu: 100m
|
|
memory: 256Mi
|
|
limits:
|
|
cpu: "1"
|
|
memory: 1Gi
|
|
volumes:
|
|
- name: vault-ca-cert
|
|
secret:
|
|
secretName: vault-ca-cert
|
|
items:
|
|
- key: ca.crt
|
|
path: ca.crt
|
|
config:
|
|
server:
|
|
root_url: "https://grafana.k8s.syd1.au.unkin.net"
|
|
database:
|
|
type: "postgres"
|
|
host: "postgres-pooler-rw.grafana.svc.cluster.local:5432"
|
|
name: "grafana"
|
|
user: "grafana"
|
|
ssl_mode: "require"
|
|
auth:
|
|
disable_login_form: "false"
|
|
oauth_auto_login: "false"
|
|
"auth.generic_oauth":
|
|
enabled: "true"
|
|
name: "Authentik"
|
|
allow_sign_up: "true"
|
|
use_pkce: "true"
|
|
client_id: "grafana"
|
|
# ak_groups = hierarchical group claim from terraform-authentik (carries
|
|
# permission groups inherited via role groups).
|
|
scopes: "openid email profile ak_groups"
|
|
auth_url: "https://identity.unkin.net/application/o/authorize/"
|
|
token_url: "https://identity.unkin.net/application/o/token/"
|
|
api_url: "https://identity.unkin.net/application/o/userinfo/"
|
|
# Trust the internal unkin.net CA that signs identity.unkin.net's cert
|
|
# (mounted from the reflected vault-ca-cert Secret).
|
|
tls_client_ca: "/etc/grafana/vault-ca/ca.crt"
|
|
# Authentik permission groups -> Grafana roles. akP-grafana-admin is granted
|
|
# to akR-global-admin members (and direct members) via terraform-authentik.
|
|
role_attribute_path: "contains(ak_groups[*], 'akP-grafana-admin') && 'Admin' || 'Viewer'"
|
|
role_attribute_strict: "false"
|