1169d796e7
## Why `identity.unkin.net` moved from an internal `unkin.net` CA-issued cert to the LetsEncrypt `*.unkin.net` wildcard. `auth.generic_oauth`'s `tls_client_ca` pointed Grafana at the internal root only, so the OAuth handshake to the LE-issued cert now fails. Grafana's image trust store already contains the public roots. ## Changes - Remove `tls_client_ca: /etc/grafana/vault-ca/ca.crt` (and its stale comment) from `auth.generic_oauth`. - Remove the now-unused `vault-ca-cert` volume and volumeMount from the Grafana pod spec — nothing else in the pod referenced it (the CNPG `endpointCA` reference to `vault-ca-cert` for `s3.ceph.unkin.net` is a separate resource and stays). - Leave the auth/token/api URLs, scopes and `role_attribute_path` untouched. Reviewed-on: #440 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
64 lines
2.1 KiB
YAML
64 lines
2.1 KiB
YAML
---
|
|
apiVersion: grafana.integreatly.org/v1beta1
|
|
kind: Grafana
|
|
metadata:
|
|
name: grafana
|
|
namespace: grafana
|
|
labels:
|
|
dashboards: "grafana"
|
|
spec:
|
|
deployment:
|
|
spec:
|
|
template:
|
|
spec:
|
|
containers:
|
|
- name: grafana
|
|
env:
|
|
# DB password + OAuth client secret injected from the
|
|
# Vault-synced secrets (GF_ env overrides grafana.ini).
|
|
- name: GF_DATABASE_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: postgres-credentials
|
|
key: password
|
|
- name: GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: oauth-credentials
|
|
key: client_secret
|
|
resources:
|
|
requests:
|
|
cpu: 100m
|
|
memory: 256Mi
|
|
limits:
|
|
cpu: "1"
|
|
memory: 1Gi
|
|
config:
|
|
server:
|
|
root_url: "https://grafana.k8s.syd1.au.unkin.net"
|
|
database:
|
|
type: "postgres"
|
|
host: "postgres-pooler-rw.grafana.svc.cluster.local:5432"
|
|
name: "grafana"
|
|
user: "grafana"
|
|
ssl_mode: "require"
|
|
auth:
|
|
disable_login_form: "false"
|
|
oauth_auto_login: "false"
|
|
"auth.generic_oauth":
|
|
enabled: "true"
|
|
name: "Authentik"
|
|
allow_sign_up: "true"
|
|
use_pkce: "true"
|
|
client_id: "grafana"
|
|
# ak_groups = hierarchical group claim from terraform-authentik (carries
|
|
# permission groups inherited via role groups).
|
|
scopes: "openid email profile ak_groups"
|
|
auth_url: "https://identity.unkin.net/application/o/authorize/"
|
|
token_url: "https://identity.unkin.net/application/o/token/"
|
|
api_url: "https://identity.unkin.net/application/o/userinfo/"
|
|
# Authentik permission groups -> Grafana roles. akP-grafana-admin is granted
|
|
# to akR-global-admin members (and direct members) via terraform-authentik.
|
|
role_attribute_path: "contains(ak_groups[*], 'akP-grafana-admin') && 'Admin' || 'Viewer'"
|
|
role_attribute_strict: "false"
|