e0d47295f2
## Why The future Vault engine needs to machine-mint arrproxy tokens without an interactive Authentik session. arrproxy v0.2.0 adds an admin route (`POST /api/admin/...`) protected by its own bearer token; OpenBao running on the VMs calls it through the arrstack ingress. This deploys that route. ## Changes - Add an `arrproxy-admin-token` VaultStaticSecret (mirrors the `arrproxy-pepper` VSO: same `default` VaultAuth, k8s-auth default-SA pattern) syncing `kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token` into the `arrproxy-admin-token` Secret. The token is seeded in Vault KV as the shared source of truth for the future Vault engine. - Set `ARRPROXY_ADMIN_TOKEN` on the arrproxy-api Deployment via `secretKeyRef` (key `token`), and add `arrproxy-admin-token` to the Reloader `secret.reloader.stakater.com/reload` annotation so the pod rolls on rotation. - Skip-auth the `/api/admin/` route in oauth2-proxy: `OAUTH2_PROXY_SKIP_AUTH_REGEX` becomes `^/[^/]+/api,^/api/admin/`. The admin route is intentionally oauth-skipped because it is protected by arrproxy's OWN bearer token so OpenBao can reach it machine-to-machine. `/api/tokens` and `/api/me` are NOT matched and stay oauth-gated. `/api/admin/*` already routes to the arrproxy-api upstream via the existing catch-all `/api/` upstream, so no upstream change is needed. - Bump arrproxy-api and arrproxy-ui images to `v0.2.0` (kept in lockstep). ## Validation - `kustomize build --enable-helm apps/overlays/au-syd1/arrstack` succeeds. - pre-commit passes, including the plain-Secret guard (only the VSO CRD is used; no plain Secret objects added). Reviewed-on: #384 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
77 lines
2.5 KiB
YAML
77 lines
2.5 KiB
YAML
---
|
|
# Per-deployment token-hash pepper. Seeded (openssl rand) at
|
|
# kv/kubernetes/namespace/arrstack/default/arrproxy-pepper (key: pepper); the
|
|
# default k8s role's templated policy already grants read on
|
|
# kv/data/kubernetes/namespace/{{sa_namespace}}/{{sa_name}}/* for the
|
|
# arrstack/default ServiceAccount, so no terraform-vault change is needed. VSO
|
|
# syncs it into the arrproxy-pepper Secret consumed by arrproxy-api as
|
|
# ARRPROXY_PEPPER.
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: arrproxy-pepper
|
|
namespace: arrstack
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "0"
|
|
spec:
|
|
destination:
|
|
create: true
|
|
name: arrproxy-pepper
|
|
overwrite: true
|
|
hmacSecretData: true
|
|
mount: kv
|
|
path: kubernetes/namespace/arrstack/default/arrproxy-pepper
|
|
refreshAfter: 5m
|
|
type: kv-v2
|
|
vaultAuthRef: default
|
|
---
|
|
# Machine-mint admin bearer token. Seeded (openssl rand) at
|
|
# kv/kubernetes/namespace/arrstack/default/arrproxy-admin-token (key: token) and
|
|
# shared as the source of truth with the future Vault engine. The default k8s
|
|
# role's templated policy already grants read on
|
|
# kv/data/kubernetes/namespace/{{sa_namespace}}/{{sa_name}}/* for the
|
|
# arrstack/default ServiceAccount, so no terraform-vault change is needed. VSO
|
|
# syncs it into the arrproxy-admin-token Secret consumed by arrproxy-api as
|
|
# ARRPROXY_ADMIN_TOKEN to gate the bearer-protected /api/admin/ route.
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: arrproxy-admin-token
|
|
namespace: arrstack
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "0"
|
|
spec:
|
|
destination:
|
|
create: true
|
|
name: arrproxy-admin-token
|
|
overwrite: true
|
|
hmacSecretData: true
|
|
mount: kv
|
|
path: kubernetes/namespace/arrstack/default/arrproxy-admin-token
|
|
refreshAfter: 5m
|
|
type: kv-v2
|
|
vaultAuthRef: default
|
|
---
|
|
# Authentik OIDC client for the arrstack front door (client_id, client_secret,
|
|
# cookie_secret), created by terraform-authentik at
|
|
# kv/kubernetes/namespace/arrstack/default/oauth-credentials. VSO syncs it into
|
|
# the oauth-credentials Secret consumed by the oauth2-proxy Deployment.
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: oauth-credentials
|
|
namespace: arrstack
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "0"
|
|
spec:
|
|
destination:
|
|
create: true
|
|
name: oauth-credentials
|
|
overwrite: true
|
|
hmacSecretData: true
|
|
mount: kv
|
|
path: kubernetes/namespace/arrstack/default/oauth-credentials
|
|
refreshAfter: 5m
|
|
type: kv-v2
|
|
vaultAuthRef: default
|