8c929e44ee
The vlselect query UI is only reachable in-cluster, so log searches need a port-forward. Front it with the same oauth2-proxy pattern logviewer uses. - Add apps/base/logging/vlogs: vlogs Gateway (vault-issuer TLS, traefik-internal) plus http->https redirect and main HTTPRoute - Route all traffic through the vlogs-oauth2 Service into oauth2-proxy, which upstreams to vlselect-logs:9471 - Gate access on the Authentik vlogs application, group akP-vlogs-admin - Source OIDC credentials from kv/kubernetes/namespace/logging/default/vlogs-oauth-credentials
12 lines
225 B
YAML
12 lines
225 B
YAML
---
|
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
kind: Kustomization
|
|
|
|
resources:
|
|
- vaultstaticsecret.yaml
|
|
- oauth2-proxy-configmap.yaml
|
|
- oauth2-proxy-deployment.yaml
|
|
- service.yaml
|
|
- gateway.yaml
|
|
- httproute.yaml
|