8c929e44ee
The vlselect query UI is only reachable in-cluster, so log searches need a port-forward. Front it with the same oauth2-proxy pattern logviewer uses. - Add apps/base/logging/vlogs: vlogs Gateway (vault-issuer TLS, traefik-internal) plus http->https redirect and main HTTPRoute - Route all traffic through the vlogs-oauth2 Service into oauth2-proxy, which upstreams to vlselect-logs:9471 - Gate access on the Authentik vlogs application, group akP-vlogs-admin - Source OIDC credentials from kv/kubernetes/namespace/logging/default/vlogs-oauth-credentials
20 lines
402 B
YAML
20 lines
402 B
YAML
---
|
|
# Front-door entry Service: the HTTPRoute for vlogs.unkin.net targets this, so
|
|
# all traffic enters via oauth2-proxy.
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: vlogs-oauth2
|
|
namespace: logging
|
|
spec:
|
|
internalTrafficPolicy: Cluster
|
|
ports:
|
|
- name: http
|
|
port: 80
|
|
protocol: TCP
|
|
targetPort: http
|
|
selector:
|
|
app: vlogs-oauth2
|
|
sessionAffinity: None
|
|
type: ClusterIP
|