mirror of
https://github.com/rubenhensen/k8scd.git
synced 2026-09-17 02:12:55 +02:00
Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| c995cbfa7b |
@@ -106,9 +106,6 @@ spec:
|
|||||||
- name: blueprint-actualbudget
|
- name: blueprint-actualbudget
|
||||||
configMap:
|
configMap:
|
||||||
name: authentik-blueprint-actualbudget
|
name: authentik-blueprint-actualbudget
|
||||||
- name: blueprint-session
|
|
||||||
configMap:
|
|
||||||
name: authentik-blueprint-session
|
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: blueprint-vault
|
- name: blueprint-vault
|
||||||
mountPath: /blueprints/custom/vault-oidc.yaml
|
mountPath: /blueprints/custom/vault-oidc.yaml
|
||||||
@@ -128,9 +125,6 @@ spec:
|
|||||||
- name: blueprint-actualbudget
|
- name: blueprint-actualbudget
|
||||||
mountPath: /blueprints/custom/actualbudget-proxy.yaml
|
mountPath: /blueprints/custom/actualbudget-proxy.yaml
|
||||||
subPath: actualbudget-proxy.yaml
|
subPath: actualbudget-proxy.yaml
|
||||||
- name: blueprint-session
|
|
||||||
mountPath: /blueprints/custom/session-duration.yaml
|
|
||||||
subPath: session-duration.yaml
|
|
||||||
ingress:
|
ingress:
|
||||||
enabled: true
|
enabled: true
|
||||||
ingressClassName: nginx
|
ingressClassName: nginx
|
||||||
@@ -162,9 +156,6 @@ spec:
|
|||||||
- name: blueprint-actualbudget
|
- name: blueprint-actualbudget
|
||||||
configMap:
|
configMap:
|
||||||
name: authentik-blueprint-actualbudget
|
name: authentik-blueprint-actualbudget
|
||||||
- name: blueprint-session
|
|
||||||
configMap:
|
|
||||||
name: authentik-blueprint-session
|
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: blueprint-vault
|
- name: blueprint-vault
|
||||||
mountPath: /blueprints/custom/vault-oidc.yaml
|
mountPath: /blueprints/custom/vault-oidc.yaml
|
||||||
@@ -184,9 +175,6 @@ spec:
|
|||||||
- name: blueprint-actualbudget
|
- name: blueprint-actualbudget
|
||||||
mountPath: /blueprints/custom/actualbudget-proxy.yaml
|
mountPath: /blueprints/custom/actualbudget-proxy.yaml
|
||||||
subPath: actualbudget-proxy.yaml
|
subPath: actualbudget-proxy.yaml
|
||||||
- name: blueprint-session
|
|
||||||
mountPath: /blueprints/custom/session-duration.yaml
|
|
||||||
subPath: session-duration.yaml
|
|
||||||
postgresql:
|
postgresql:
|
||||||
enabled: false
|
enabled: false
|
||||||
redis:
|
redis:
|
||||||
|
|||||||
@@ -1,21 +0,0 @@
|
|||||||
apiVersion: argoproj.io/v1alpha1
|
|
||||||
kind: Application
|
|
||||||
metadata:
|
|
||||||
name: bolletjestrui
|
|
||||||
namespace: argocd
|
|
||||||
finalizers:
|
|
||||||
- resources-finalizer.argocd.argoproj.io
|
|
||||||
spec:
|
|
||||||
project: default
|
|
||||||
source:
|
|
||||||
repoURL: https://github.com/rubenhensen/k8scd.git
|
|
||||||
targetRevision: HEAD
|
|
||||||
path: bolletjestrui
|
|
||||||
destination:
|
|
||||||
server: https://kubernetes.default.svc
|
|
||||||
namespace: bolletjestrui
|
|
||||||
syncPolicy:
|
|
||||||
syncOptions:
|
|
||||||
- CreateNamespace=true
|
|
||||||
automated:
|
|
||||||
selfHeal: true
|
|
||||||
@@ -11,22 +11,6 @@ Authentik is deployed as the central identity provider, providing OIDC and LDAP
|
|||||||
- `blueprint-ldap.yaml` — LDAP provider (base DN: `DC=ldap,DC=goauthentik,DC=io`)
|
- `blueprint-ldap.yaml` — LDAP provider (base DN: `DC=ldap,DC=goauthentik,DC=io`)
|
||||||
- `blueprint-mail-oidc.yaml` — OAuth2/OIDC provider for Stalwart mail
|
- `blueprint-mail-oidc.yaml` — OAuth2/OIDC provider for Stalwart mail
|
||||||
- `blueprint-vault-oidc.yaml` — OIDC provider for Vault
|
- `blueprint-vault-oidc.yaml` — OIDC provider for Vault
|
||||||
- `blueprint-argocd-oidc.yaml` — OIDC provider for ArgoCD
|
|
||||||
- `blueprint-freshrss-oidc.yaml` — OIDC provider for FreshRSS
|
|
||||||
- `blueprint-actualbudget-proxy.yaml` — Proxy provider for Actual Budget
|
|
||||||
- `blueprint-session-duration.yaml` — Session lifetime of the default authentication flow
|
|
||||||
|
|
||||||
## Session lifetime
|
|
||||||
|
|
||||||
Authentik ships the login stage of `default-authentication-flow` with
|
|
||||||
`session_duration: seconds=0`, i.e. the SSO session dies when the browser closes.
|
|
||||||
`blueprint-session-duration.yaml` raises this to 30 days for every app that uses
|
|
||||||
that flow (FreshRSS, ArgoCD, Vault, Actual Budget, mail).
|
|
||||||
|
|
||||||
The expiry is **absolute** — Authentik does not extend a session on activity. A
|
|
||||||
sliding window has to come from the application itself; FreshRSS does this via
|
|
||||||
`OIDC_SESSION_INACTIVITY_TIMEOUT` (see `freshrss/freshrss-deployment.yaml`), which
|
|
||||||
Apache mod_auth_openidc refreshes on every request.
|
|
||||||
|
|
||||||
## LDAP Outpost
|
## LDAP Outpost
|
||||||
|
|
||||||
|
|||||||
@@ -1,27 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: authentik-blueprint-session
|
|
||||||
data:
|
|
||||||
session-duration.yaml: |
|
|
||||||
version: 1
|
|
||||||
metadata:
|
|
||||||
name: Session duration
|
|
||||||
entries:
|
|
||||||
# Overrides the login stage of the built-in `default-authentication-flow`,
|
|
||||||
# which every OIDC/proxy provider in this cluster authenticates against.
|
|
||||||
# authentik ships this stage with `session_duration: seconds=0`, which means
|
|
||||||
# "until the browser is closed" — that is why re-logins were so frequent.
|
|
||||||
#
|
|
||||||
# Note: authentik's session expiry is absolute (counted from login), it does
|
|
||||||
# not slide on activity. The sliding window lives in the applications, e.g.
|
|
||||||
# OIDC_SESSION_INACTIVITY_TIMEOUT in freshrss/freshrss-deployment.yaml.
|
|
||||||
- model: authentik_stages_user_login.userloginstage
|
|
||||||
state: present
|
|
||||||
identifiers:
|
|
||||||
name: default-authentication-login
|
|
||||||
attrs:
|
|
||||||
session_duration: days=30
|
|
||||||
# Uncomment to show a "Remember me on this device" checkbox that adds
|
|
||||||
# this offset on top of session_duration when ticked (0 = hidden).
|
|
||||||
# remember_me_offset: days=60
|
|
||||||
@@ -1,98 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: bolletjestrui
|
|
||||||
name: bolletjestrui
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: bolletjestrui
|
|
||||||
strategy:
|
|
||||||
type: Recreate
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: bolletjestrui
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- image: ghcr.io/rubenhensen/bolletjestrui:main-10268f1
|
|
||||||
name: bolletjestrui
|
|
||||||
ports:
|
|
||||||
- containerPort: 3000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: DATABASE_URL
|
|
||||||
value: /app/data/bolletjestrui.db
|
|
||||||
- name: ORIGIN
|
|
||||||
value: https://vic.rubenhensen.nl
|
|
||||||
- name: PROTOCOL_HEADER
|
|
||||||
value: x-forwarded-proto
|
|
||||||
- name: HOST_HEADER
|
|
||||||
value: x-forwarded-host
|
|
||||||
# GPX routes and profile photos (up to 20 MB); raise adapter-node's 512K default
|
|
||||||
- name: BODY_SIZE_LIMIT
|
|
||||||
value: "25M"
|
|
||||||
- name: TZ
|
|
||||||
value: Europe/Amsterdam
|
|
||||||
- name: SITE_PASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: bolletjestrui-secrets
|
|
||||||
key: site_password
|
|
||||||
- name: ADMIN_PASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: bolletjestrui-secrets
|
|
||||||
key: admin_password
|
|
||||||
- name: KEY_SECRET
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: bolletjestrui-secrets
|
|
||||||
key: key_secret
|
|
||||||
# Push notifications. optional:true is load-bearing: without it a missing
|
|
||||||
# key leaves the pod in CreateContainerConfigError and the site is down,
|
|
||||||
# which would make deploying this depend on the Vault entries landing
|
|
||||||
# first. The app already treats absent VAPID keys as "send nothing".
|
|
||||||
- name: VAPID_PUBLIC_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: bolletjestrui-secrets
|
|
||||||
key: vapid_public_key
|
|
||||||
optional: true
|
|
||||||
- name: VAPID_PRIVATE_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: bolletjestrui-secrets
|
|
||||||
key: vapid_private_key
|
|
||||||
optional: true
|
|
||||||
- name: VAPID_SUBJECT
|
|
||||||
value: mailto:ruben.hensen@protonmail.com
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
memory: "128Mi"
|
|
||||||
cpu: "50m"
|
|
||||||
limits:
|
|
||||||
memory: "512Mi"
|
|
||||||
cpu: "500m"
|
|
||||||
readinessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: /login
|
|
||||||
port: 3000
|
|
||||||
initialDelaySeconds: 5
|
|
||||||
periodSeconds: 10
|
|
||||||
livenessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: /login
|
|
||||||
port: 3000
|
|
||||||
initialDelaySeconds: 15
|
|
||||||
periodSeconds: 20
|
|
||||||
volumeMounts:
|
|
||||||
- mountPath: /app/data
|
|
||||||
name: data
|
|
||||||
restartPolicy: Always
|
|
||||||
volumes:
|
|
||||||
- name: data
|
|
||||||
persistentVolumeClaim:
|
|
||||||
claimName: bolletjestrui-data
|
|
||||||
@@ -1,13 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: bolletjestrui
|
|
||||||
name: bolletjestrui
|
|
||||||
spec:
|
|
||||||
ports:
|
|
||||||
- name: "3000"
|
|
||||||
port: 3000
|
|
||||||
targetPort: 3000
|
|
||||||
selector:
|
|
||||||
app: bolletjestrui
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: bolletjestrui
|
|
||||||
name: bolletjestrui-data
|
|
||||||
spec:
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 2Gi
|
|
||||||
@@ -1,36 +0,0 @@
|
|||||||
apiVersion: external-secrets.io/v1beta1
|
|
||||||
kind: ExternalSecret
|
|
||||||
metadata:
|
|
||||||
name: bolletjestrui-secrets
|
|
||||||
spec:
|
|
||||||
secretStoreRef:
|
|
||||||
name: vault-backend
|
|
||||||
kind: ClusterSecretStore
|
|
||||||
refreshInterval: 15m
|
|
||||||
target:
|
|
||||||
name: bolletjestrui-secrets
|
|
||||||
creationPolicy: Owner
|
|
||||||
data:
|
|
||||||
- secretKey: site_password
|
|
||||||
remoteRef:
|
|
||||||
key: kv/bolletjestrui
|
|
||||||
property: site_password
|
|
||||||
- secretKey: admin_password
|
|
||||||
remoteRef:
|
|
||||||
key: kv/bolletjestrui
|
|
||||||
property: admin_password
|
|
||||||
- secretKey: key_secret
|
|
||||||
remoteRef:
|
|
||||||
key: kv/bolletjestrui
|
|
||||||
property: key_secret
|
|
||||||
# web-push keypair for the "de route is gekozen" notification.
|
|
||||||
# Generate once with `npx web-push generate-vapid-keys` and never rotate it:
|
|
||||||
# a new key invalidates every subscription on everyone's phone.
|
|
||||||
- secretKey: vapid_public_key
|
|
||||||
remoteRef:
|
|
||||||
key: kv/bolletjestrui
|
|
||||||
property: vapid_public_key
|
|
||||||
- secretKey: vapid_private_key
|
|
||||||
remoteRef:
|
|
||||||
key: kv/bolletjestrui
|
|
||||||
property: vapid_private_key
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
apiVersion: networking.k8s.io/v1
|
|
||||||
kind: Ingress
|
|
||||||
metadata:
|
|
||||||
name: bolletjestrui-ingress
|
|
||||||
annotations:
|
|
||||||
cert-manager.io/cluster-issuer: prod-cluster-issuer
|
|
||||||
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
|
|
||||||
nginx.ingress.kubernetes.io/ssl-passthrough: "false"
|
|
||||||
# matches the app's BODY_SIZE_LIMIT: a bulk route import posts every GPX at once
|
|
||||||
nginx.ingress.kubernetes.io/proxy-body-size: "25m"
|
|
||||||
spec:
|
|
||||||
ingressClassName: nginx
|
|
||||||
rules:
|
|
||||||
- host: vic.rubenhensen.nl
|
|
||||||
http:
|
|
||||||
paths:
|
|
||||||
- path: /
|
|
||||||
pathType: Prefix
|
|
||||||
backend:
|
|
||||||
service:
|
|
||||||
name: bolletjestrui
|
|
||||||
port:
|
|
||||||
number: 3000
|
|
||||||
tls:
|
|
||||||
- secretName: letsencrypt-prod
|
|
||||||
hosts:
|
|
||||||
- vic.rubenhensen.nl
|
|
||||||
@@ -59,10 +59,6 @@ records:
|
|||||||
expire: 300
|
expire: 300
|
||||||
type: A
|
type: A
|
||||||
content: "46.224.26.65"
|
content: "46.224.26.65"
|
||||||
- name: "vic"
|
|
||||||
expire: 300
|
|
||||||
type: A
|
|
||||||
content: "46.224.26.65"
|
|
||||||
- name: "@"
|
- name: "@"
|
||||||
expire: 300
|
expire: 300
|
||||||
type: MX
|
type: MX
|
||||||
|
|||||||
@@ -56,20 +56,6 @@ spec:
|
|||||||
value: "openid email profile"
|
value: "openid email profile"
|
||||||
- name: OIDC_X_FORWARDED_HEADERS
|
- name: OIDC_X_FORWARDED_HEADERS
|
||||||
value: X-Forwarded-Port X-Forwarded-Proto X-Forwarded-Host
|
value: X-Forwarded-Port X-Forwarded-Proto X-Forwarded-Host
|
||||||
# Session handling for the Apache mod_auth_openidc layer that guards /i/.
|
|
||||||
# Defaults are 5 min inactivity / ~7.5 h max, which is what caused the
|
|
||||||
# constant bounces back to authentik.
|
|
||||||
# Sliding window: refreshed on every request, so any visit within the
|
|
||||||
# period extends it by another 30 days.
|
|
||||||
- name: OIDC_SESSION_INACTIVITY_TIMEOUT
|
|
||||||
value: "2592000" # 30 days
|
|
||||||
# Hard cap, counted from login and never extended.
|
|
||||||
- name: OIDC_SESSION_MAX_DURATION
|
|
||||||
value: "7776000" # 90 days
|
|
||||||
# ":persistent" makes the session cookie survive a browser restart
|
|
||||||
# (its expiry tracks OIDC_SESSION_INACTIVITY_TIMEOUT).
|
|
||||||
- name: OIDC_SESSION_TYPE
|
|
||||||
value: "server-cache:persistent"
|
|
||||||
- name: TZ
|
- name: TZ
|
||||||
value: Europe/Amsterdam
|
value: Europe/Amsterdam
|
||||||
image: freshrss/freshrss:latest
|
image: freshrss/freshrss:latest
|
||||||
|
|||||||
@@ -20,7 +20,6 @@ let
|
|||||||
"blog.rubenhensen.nl"
|
"blog.rubenhensen.nl"
|
||||||
"serpbear.rubenhensen.nl"
|
"serpbear.rubenhensen.nl"
|
||||||
"git.rubenhensen.nl"
|
"git.rubenhensen.nl"
|
||||||
"vic.rubenhensen.nl"
|
|
||||||
];
|
];
|
||||||
|
|
||||||
sniMapEntries =
|
sniMapEntries =
|
||||||
|
|||||||
+1
-2
@@ -16,8 +16,7 @@
|
|||||||
"kubernetes": {
|
"kubernetes": {
|
||||||
"managerFilePatterns": [
|
"managerFilePatterns": [
|
||||||
"/apps/templates/.+\\.yaml$/",
|
"/apps/templates/.+\\.yaml$/",
|
||||||
"/serpbear/.+\\.yaml$/",
|
"/serpbear/.+\\.yaml$/"
|
||||||
"/bolletjestrui/.+\\.yaml$/"
|
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"customManagers": [
|
"customManagers": [
|
||||||
|
|||||||
Reference in New Issue
Block a user