Files
argocd-apps/apps
unkin-agent efed6c8966
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
artifactapi: restore combine-certs + PROVIDER_CA_FILES on oauth2-proxy
#456 omitted the combine-certs initContainer and
OAUTH2_PROXY_PROVIDER_CA_FILES on the grounds that identity.unkin.net
serves a publicly trusted Let's Encrypt cert and so needs no internal CA.
That reasoning holds for the browser redirect but not for oauth2-proxy's
own back-channel calls: every other oauth2-proxy in the estate needs the
internal bundle, including repospawner, which uses the same public
identity.unkin.net issuer hostname.

artifactapi is the only one of six without it (arrproxy, logviewer,
mediamark, repospawner and watchstate all have it).

This is NOT the current outage. The UI is 503 because the Authentik
application slug artifactapi does not exist -- terraform-authentik's
push/apply on main (4e16401) failed, so discovery 404s and oauth2-proxy
never starts. This change removes the next blocker, which would surface
as an x509 failure once that apply succeeds.

- Add the combine-certs initContainer, byte-identical to repospawner's.
- Mount the combined bundle and set OAUTH2_PROXY_PROVIDER_CA_FILES.
- Reload the Deployment when vault-ca-cert rotates.

Trust-only and strictly additive: it appends the internal CA to the
system roots, so it is harmless if the back channel turns out to reach a
publicly trusted endpoint after all.
2026-09-07 22:32:48 +10:00
..