3 Commits

Author SHA1 Message Date
renovate[bot] b79e05fea6 chore(deps): update helm chart cert-manager to v1.21.1 2026-09-07 21:57:38 +00:00
Ruben Hensen 20cf119dbd Extend authentik + FreshRSS session lifetimes
Authentik's default-authentication-login stage ships with
session_duration: seconds=0, so the SSO session died with the browser.
New blueprint raises it to 30 days for every app on that flow.

FreshRSS runs OIDC through Apache mod_auth_openidc, whose defaults are a
5 minute inactivity timeout and a ~7.5 hour max duration in a non-persistent
cookie. Bumped to a 30 day sliding inactivity window (refreshed on every
request) with a 90 day hard cap, and made the cookie persistent so it
survives a browser restart.
2026-09-03 15:21:07 +02:00
Ruben Hensen ec5405fc29 bolletjestrui: deploy main-10268f1 (routes, voting, push, ride uploads)
Adds the VAPID keypair for web push and raises the ingress body limit to 25m to
match the app's BODY_SIZE_LIMIT, since a bulk route import posts every GPX in one
request.

The VAPID env refs are optional:true on purpose — a missing key in a secretKeyRef
puts the pod in CreateContainerConfigError, and the app already handles absent
keys by sending no notifications.
2026-08-15 17:55:37 +02:00
8 changed files with 102 additions and 3 deletions
+12
View File
@@ -106,6 +106,9 @@ spec:
- name: blueprint-actualbudget - name: blueprint-actualbudget
configMap: configMap:
name: authentik-blueprint-actualbudget name: authentik-blueprint-actualbudget
- name: blueprint-session
configMap:
name: authentik-blueprint-session
volumeMounts: volumeMounts:
- name: blueprint-vault - name: blueprint-vault
mountPath: /blueprints/custom/vault-oidc.yaml mountPath: /blueprints/custom/vault-oidc.yaml
@@ -125,6 +128,9 @@ spec:
- name: blueprint-actualbudget - name: blueprint-actualbudget
mountPath: /blueprints/custom/actualbudget-proxy.yaml mountPath: /blueprints/custom/actualbudget-proxy.yaml
subPath: actualbudget-proxy.yaml subPath: actualbudget-proxy.yaml
- name: blueprint-session
mountPath: /blueprints/custom/session-duration.yaml
subPath: session-duration.yaml
ingress: ingress:
enabled: true enabled: true
ingressClassName: nginx ingressClassName: nginx
@@ -156,6 +162,9 @@ spec:
- name: blueprint-actualbudget - name: blueprint-actualbudget
configMap: configMap:
name: authentik-blueprint-actualbudget name: authentik-blueprint-actualbudget
- name: blueprint-session
configMap:
name: authentik-blueprint-session
volumeMounts: volumeMounts:
- name: blueprint-vault - name: blueprint-vault
mountPath: /blueprints/custom/vault-oidc.yaml mountPath: /blueprints/custom/vault-oidc.yaml
@@ -175,6 +184,9 @@ spec:
- name: blueprint-actualbudget - name: blueprint-actualbudget
mountPath: /blueprints/custom/actualbudget-proxy.yaml mountPath: /blueprints/custom/actualbudget-proxy.yaml
subPath: actualbudget-proxy.yaml subPath: actualbudget-proxy.yaml
- name: blueprint-session
mountPath: /blueprints/custom/session-duration.yaml
subPath: session-duration.yaml
postgresql: postgresql:
enabled: false enabled: false
redis: redis:
+1 -1
View File
@@ -12,7 +12,7 @@ spec:
project: default project: default
source: source:
repoURL: https://charts.jetstack.io repoURL: https://charts.jetstack.io
targetRevision: v1.15.5 targetRevision: v1.21.1
chart: cert-manager chart: cert-manager
helm: helm:
parameters: parameters:
+16
View File
@@ -11,6 +11,22 @@ Authentik is deployed as the central identity provider, providing OIDC and LDAP
- `blueprint-ldap.yaml` — LDAP provider (base DN: `DC=ldap,DC=goauthentik,DC=io`) - `blueprint-ldap.yaml` — LDAP provider (base DN: `DC=ldap,DC=goauthentik,DC=io`)
- `blueprint-mail-oidc.yaml` — OAuth2/OIDC provider for Stalwart mail - `blueprint-mail-oidc.yaml` — OAuth2/OIDC provider for Stalwart mail
- `blueprint-vault-oidc.yaml` — OIDC provider for Vault - `blueprint-vault-oidc.yaml` — OIDC provider for Vault
- `blueprint-argocd-oidc.yaml` — OIDC provider for ArgoCD
- `blueprint-freshrss-oidc.yaml` — OIDC provider for FreshRSS
- `blueprint-actualbudget-proxy.yaml` — Proxy provider for Actual Budget
- `blueprint-session-duration.yaml` — Session lifetime of the default authentication flow
## Session lifetime
Authentik ships the login stage of `default-authentication-flow` with
`session_duration: seconds=0`, i.e. the SSO session dies when the browser closes.
`blueprint-session-duration.yaml` raises this to 30 days for every app that uses
that flow (FreshRSS, ArgoCD, Vault, Actual Budget, mail).
The expiry is **absolute** — Authentik does not extend a session on activity. A
sliding window has to come from the application itself; FreshRSS does this via
`OIDC_SESSION_INACTIVITY_TIMEOUT` (see `freshrss/freshrss-deployment.yaml`), which
Apache mod_auth_openidc refreshes on every request.
## LDAP Outpost ## LDAP Outpost
+27
View File
@@ -0,0 +1,27 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: authentik-blueprint-session
data:
session-duration.yaml: |
version: 1
metadata:
name: Session duration
entries:
# Overrides the login stage of the built-in `default-authentication-flow`,
# which every OIDC/proxy provider in this cluster authenticates against.
# authentik ships this stage with `session_duration: seconds=0`, which means
# "until the browser is closed" — that is why re-logins were so frequent.
#
# Note: authentik's session expiry is absolute (counted from login), it does
# not slide on activity. The sliding window lives in the applications, e.g.
# OIDC_SESSION_INACTIVITY_TIMEOUT in freshrss/freshrss-deployment.yaml.
- model: authentik_stages_user_login.userloginstage
state: present
identifiers:
name: default-authentication-login
attrs:
session_duration: days=30
# Uncomment to show a "Remember me on this device" checkbox that adds
# this offset on top of session_duration when ticked (0 = hidden).
# remember_me_offset: days=60
+19 -1
View File
@@ -17,7 +17,7 @@ spec:
app: bolletjestrui app: bolletjestrui
spec: spec:
containers: containers:
- image: ghcr.io/rubenhensen/bolletjestrui:main-8f17b5d - image: ghcr.io/rubenhensen/bolletjestrui:main-10268f1
name: bolletjestrui name: bolletjestrui
ports: ports:
- containerPort: 3000 - containerPort: 3000
@@ -51,6 +51,24 @@ spec:
secretKeyRef: secretKeyRef:
name: bolletjestrui-secrets name: bolletjestrui-secrets
key: key_secret key: key_secret
# Push notifications. optional:true is load-bearing: without it a missing
# key leaves the pod in CreateContainerConfigError and the site is down,
# which would make deploying this depend on the Vault entries landing
# first. The app already treats absent VAPID keys as "send nothing".
- name: VAPID_PUBLIC_KEY
valueFrom:
secretKeyRef:
name: bolletjestrui-secrets
key: vapid_public_key
optional: true
- name: VAPID_PRIVATE_KEY
valueFrom:
secretKeyRef:
name: bolletjestrui-secrets
key: vapid_private_key
optional: true
- name: VAPID_SUBJECT
value: mailto:ruben.hensen@protonmail.com
resources: resources:
requests: requests:
memory: "128Mi" memory: "128Mi"
+11
View File
@@ -23,3 +23,14 @@ spec:
remoteRef: remoteRef:
key: kv/bolletjestrui key: kv/bolletjestrui
property: key_secret property: key_secret
# web-push keypair for the "de route is gekozen" notification.
# Generate once with `npx web-push generate-vapid-keys` and never rotate it:
# a new key invalidates every subscription on everyone's phone.
- secretKey: vapid_public_key
remoteRef:
key: kv/bolletjestrui
property: vapid_public_key
- secretKey: vapid_private_key
remoteRef:
key: kv/bolletjestrui
property: vapid_private_key
+2 -1
View File
@@ -6,7 +6,8 @@ metadata:
cert-manager.io/cluster-issuer: prod-cluster-issuer cert-manager.io/cluster-issuer: prod-cluster-issuer
nginx.ingress.kubernetes.io/backend-protocol: "HTTP" nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
nginx.ingress.kubernetes.io/ssl-passthrough: "false" nginx.ingress.kubernetes.io/ssl-passthrough: "false"
nginx.ingress.kubernetes.io/proxy-body-size: "10m" # matches the app's BODY_SIZE_LIMIT: a bulk route import posts every GPX at once
nginx.ingress.kubernetes.io/proxy-body-size: "25m"
spec: spec:
ingressClassName: nginx ingressClassName: nginx
rules: rules:
+14
View File
@@ -56,6 +56,20 @@ spec:
value: "openid email profile" value: "openid email profile"
- name: OIDC_X_FORWARDED_HEADERS - name: OIDC_X_FORWARDED_HEADERS
value: X-Forwarded-Port X-Forwarded-Proto X-Forwarded-Host value: X-Forwarded-Port X-Forwarded-Proto X-Forwarded-Host
# Session handling for the Apache mod_auth_openidc layer that guards /i/.
# Defaults are 5 min inactivity / ~7.5 h max, which is what caused the
# constant bounces back to authentik.
# Sliding window: refreshed on every request, so any visit within the
# period extends it by another 30 days.
- name: OIDC_SESSION_INACTIVITY_TIMEOUT
value: "2592000" # 30 days
# Hard cap, counted from login and never extended.
- name: OIDC_SESSION_MAX_DURATION
value: "7776000" # 90 days
# ":persistent" makes the session cookie survive a browser restart
# (its expiry tracks OIDC_SESSION_INACTIVITY_TIMEOUT).
- name: OIDC_SESSION_TYPE
value: "server-cache:persistent"
- name: TZ - name: TZ
value: Europe/Amsterdam value: Europe/Amsterdam
image: freshrss/freshrss:latest image: freshrss/freshrss:latest