e6e882abfc
The Vault KV layout is kubernetes/namespace/<ns>/<sa>/<secret>, so vlogs and logviewer both running as SA default in the shared logging namespace would collide on one oauth-credentials entry. Splitting vlogs out resolves it without widening any Vault policy. - Move apps/base/logging/vlogs to apps/base/vlogs, namespace vlogs - Add namespace.yaml and a vlogs-scoped VaultAuth (role default) - Point the VaultStaticSecret at kubernetes/namespace/vlogs/default/oauth-credentials - Add the au-syd1 overlay, platform ApplicationSet path and project destination - Move the wildcard-unkin-net-tls reflection from logging to vlogs; vlogs was its only consumer there Secret is already seeded at the new Vault path. Reviewed-on: #507 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
29 lines
1.2 KiB
YAML
29 lines
1.2 KiB
YAML
---
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: vlogs-oauth2-env
|
|
namespace: vlogs
|
|
data:
|
|
OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180"
|
|
OAUTH2_PROXY_PROVIDER: "oidc"
|
|
OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/vlogs/"
|
|
OAUTH2_PROXY_REDIRECT_URL: "https://vlogs.unkin.net/oauth2/callback"
|
|
OAUTH2_PROXY_UPSTREAMS: "http://vlselect-logs.logging.svc.cluster.local:9471/"
|
|
OAUTH2_PROXY_SCOPE: "openid email profile ak_groups"
|
|
# Populate session.Groups from the Authentik ak_groups claim.
|
|
OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups"
|
|
OAUTH2_PROXY_ALLOWED_GROUPS: "akP-vlogs-admin"
|
|
OAUTH2_PROXY_PASS_USER_HEADERS: "true"
|
|
OAUTH2_PROXY_EMAIL_DOMAINS: "*"
|
|
# Authentik hardcodes email_verified=false in the id_token; authorization is
|
|
# enforced via ak_groups, so accepting the unverified email is safe.
|
|
OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true"
|
|
OAUTH2_PROXY_COOKIE_SECURE: "true"
|
|
OAUTH2_PROXY_COOKIE_DOMAINS: "vlogs.unkin.net"
|
|
OAUTH2_PROXY_WHITELIST_DOMAINS: "vlogs.unkin.net"
|
|
OAUTH2_PROXY_REVERSE_PROXY: "true"
|
|
OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt"
|
|
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
|
|
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
|