161 lines
4.8 KiB
YAML
161 lines
4.8 KiB
YAML
# services/hermes/oauth2-proxy.yaml
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: hermes-operator-allowlist
|
|
namespace: hermes
|
|
data:
|
|
allowed-emails: |
|
|
brad@bstein.dev
|
|
---
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: oauth2-proxy-hermes
|
|
namespace: hermes
|
|
labels:
|
|
app: oauth2-proxy-hermes
|
|
spec:
|
|
selector:
|
|
app: oauth2-proxy-hermes
|
|
ports:
|
|
- name: http
|
|
port: 80
|
|
targetPort: http
|
|
---
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: oauth2-proxy-hermes
|
|
namespace: hermes
|
|
labels:
|
|
app: oauth2-proxy-hermes
|
|
spec:
|
|
replicas: 1
|
|
revisionHistoryLimit: 2
|
|
selector:
|
|
matchLabels:
|
|
app: oauth2-proxy-hermes
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app: oauth2-proxy-hermes
|
|
annotations:
|
|
vault.hashicorp.com/agent-inject: "true"
|
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
vault.hashicorp.com/role: hermes
|
|
vault.hashicorp.com/agent-inject-secret-oidc-config: kv/data/atlas/hermes/operator-oidc
|
|
vault.hashicorp.com/agent-inject-template-oidc-config: |
|
|
{{- with secret "kv/data/atlas/hermes/operator-oidc" -}}
|
|
client_id = "{{ .Data.data.client_id }}"
|
|
client_secret = "{{ .Data.data.client_secret }}"
|
|
cookie_secret = "{{ .Data.data.cookie_secret }}"
|
|
{{- end -}}
|
|
spec:
|
|
serviceAccountName: hermes-vault
|
|
automountServiceAccountToken: true
|
|
affinity:
|
|
nodeAffinity:
|
|
requiredDuringSchedulingIgnoredDuringExecution:
|
|
nodeSelectorTerms:
|
|
- matchExpressions:
|
|
- key: kubernetes.io/arch
|
|
operator: In
|
|
values:
|
|
- arm64
|
|
- key: node-role.kubernetes.io/worker
|
|
operator: In
|
|
values:
|
|
- "true"
|
|
- key: kubernetes.io/hostname
|
|
operator: NotIn
|
|
values:
|
|
- titan-13
|
|
- titan-15
|
|
- titan-17
|
|
- titan-19
|
|
preferredDuringSchedulingIgnoredDuringExecution:
|
|
- weight: 90
|
|
preference:
|
|
matchExpressions:
|
|
- key: hardware
|
|
operator: In
|
|
values:
|
|
- rpi5
|
|
- weight: 50
|
|
preference:
|
|
matchExpressions:
|
|
- key: hardware
|
|
operator: In
|
|
values:
|
|
- rpi4
|
|
containers:
|
|
- name: oauth2-proxy
|
|
image: quay.io/oauth2-proxy/oauth2-proxy:v7.6.0@sha256:dcb6ff8dd21bf3058f6a22c6fa385fa5b897a9cd3914c88a2cc2bb0a85f8065d
|
|
imagePullPolicy: IfNotPresent
|
|
args:
|
|
- --provider=oidc
|
|
- --config=/vault/secrets/oidc-config
|
|
- --redirect-url=https://agent.bstein.dev/oauth2/callback
|
|
- --oidc-issuer-url=https://sso.bstein.dev/realms/atlas
|
|
- --scope=openid profile email
|
|
- --email-domain=*
|
|
- --authenticated-emails-file=/etc/oauth2-proxy/allowed-emails
|
|
- --set-xauthrequest=true
|
|
- --pass-access-token=true
|
|
- --set-authorization-header=true
|
|
- --cookie-secure=true
|
|
- --cookie-samesite=lax
|
|
- --cookie-refresh=20m
|
|
- --cookie-expire=24h
|
|
- --upstream=http://hermes.hermes.svc.cluster.local:9119
|
|
- --http-address=0.0.0.0:4180
|
|
- --skip-provider-button=true
|
|
- --skip-jwt-bearer-tokens=true
|
|
- --cookie-domain=agent.bstein.dev
|
|
- --reverse-proxy=true
|
|
ports:
|
|
- name: http
|
|
containerPort: 4180
|
|
readinessProbe:
|
|
httpGet:
|
|
path: /ping
|
|
port: http
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 10
|
|
livenessProbe:
|
|
httpGet:
|
|
path: /ping
|
|
port: http
|
|
initialDelaySeconds: 20
|
|
periodSeconds: 20
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
readOnlyRootFilesystem: true
|
|
runAsNonRoot: true
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
resources:
|
|
requests:
|
|
cpu: 25m
|
|
memory: 64Mi
|
|
limits:
|
|
cpu: 250m
|
|
memory: 256Mi
|
|
volumeMounts:
|
|
- name: allowlist
|
|
mountPath: /etc/oauth2-proxy
|
|
readOnly: true
|
|
- name: tmp
|
|
mountPath: /tmp
|
|
volumes:
|
|
- name: allowlist
|
|
configMap:
|
|
name: hermes-operator-allowlist
|
|
- name: tmp
|
|
emptyDir:
|
|
sizeLimit: 64Mi
|