mirror of
https://github.com/dredx/prole.git
synced 2026-09-24 15:54:32 +00:00
Bringing the long-running session-feature branch back into main in one deliberate sweep. The branch carried the cluster work that's been live for weeks (cross-cluster CNPG metrics, Grafana w/ Google OAuth, supabase oauth2-proxy, cluster recovery, pg.0.knoe.dev + per-engineer onboarding, GCS-backed CNPG backups via Workload Identity, the env-contamination guard, the Junie brief queue, the cnpg-grafana CSRF + memory-request fixes from today), while main accumulated Junie's parallel knoe-auth Phase 2 OIDC work (full provider surface: discovery, authorize, token, userinfo, JWKS, RS256 signing, code exchange, session services). Key decision: the two branches did COMPETING rebrands off the same starting point (5ba9b63, 2026-04-27): - claude branch (commit b355855, earlier): org.prole.authority.* → dev.knoe.auth.* (artifact renamed to knoe-auth.jar) - main (commit9daa94b, recent): org.prole.authority.* → dev.knoe.authority.* (kept "authority" artifact name) dev.knoe.auth wins: cluster runs from this name, the Maven artifact is already knoe-auth.jar, and the broader rename is the documented namespace direction (per ~/.claude/projects/-Users-chrisfu-dev-knoe-db/ memory/MEMORY.md). All of main's recent Phase 2 OIDC content was ported from authority/src/.../dev/knoe/authority/ into authority/src/.../dev/knoe/auth/ with package declarations rewritten. == File-level resolution summary == Textual conflicts (4): authority/pom.xml - Took our artifactId="auth" - Took our branch's removal of spring-security-kerberos-client (verified: Junie's Phase 2 OIDC code does not import it; the dep was already-dead config) docs/pipeline-phases.md - Took our branch's "Phase 1 not started" status. Main had a misplaced "✅ Complete" with a knoe-auth-Phase-1 commit ref in the autobuild Phase 1 section — different domain. docs/plans/knoe-auth-round-1.md - Took our branch's dev.knoe.auth file table (vs main's dev.knoe.authority listing). Pure rename mismatch. supabase/helm/knoe-supabase/templates/kong/config.yaml - Took our branch's onboard route + plain dashboard wiring. Main had an oauth2proxy.enabled toggle that put oauth2-proxy as a Kong upstream — but the deployed architecture (commit 25f1b2e) has oauth2-proxy in FRONT of Kong, not behind. Main's wrapper reflected an architecture that was never deployed. - Took our branch's removal of basic-auth from dashboard route (queue #15 brief still tracks the matching values.yaml / kong/deployment.yaml cleanup). Java tree reconciliation (44 file-pairs): 20 dual-path source files + 2 dual-path tests Body-identical between main's authority/ and our branch's auth/ after stripping package decls — main's commit9daa94bwas a pure rebrand. Took our branch's auth/ version for all 22. 8 main-only source files (Phase 2 OIDC), ported into auth/: web/JwksController.java web/OidcAuthorizeController.java web/OidcDiscoveryController.java web/OidcTokenController.java web/OidcUserInfoController.java session/OidcCodeService.java session/OidcTokenService.java session/SessionService.java 12 main-only test files, ported into auth/: HealthControllerTest.java enroll/EnrollValueTypesTest.java enroll/EnrollmentControllerTest.java enroll/TotpServiceTest.java kerberos/KadminClientTest.java kerberos/KerberosSpnegoResultTest.java web/LoginControllerTest.java admin/AdminControllerTest.java user/PrincipalNormalizerTest.java regression/IdentityRegressionTest.java session/OidcCodeServiceTest.java session/SessionServiceTest.java Port mechanics: read main:authority/...<file> via git show, then sed rewrite `package dev.knoe.authority` → `package dev.knoe.auth` and `import dev.knoe.authority` → `import dev.knoe.auth`. Body content unchanged. authority/src/main/java/dev/knoe/authority/ — DELETED (duplicate) authority/src/test/java/dev/knoe/authority/ — DELETED (duplicate) == Verification == - grep -rln '<<<<<<<' across .java/.md/.yaml/.yml/.sh/.xml/.tpl: clean - find authority/src -path '*/dev/knoe/authority*': empty (subtree gone) - grep 'package dev.knoe.authority' across repo: clean - bash -n install.sh deploy.sh etc/preflight_kubecontext.sh: clean - git ls-files -u | wc -l: 0 unmerged paths - helm lint supabase/helm/knoe-supabase: pre-existing failure on studioIngress.enabled undefined in values.yaml (introduced by Junie on main; unrelated to this merge — flagging as follow-up). == Followups (carried into TODO ranked queue or noted here) == - helm lint failure: studioIngress block in values.yaml is missing enable flag; templates/studio/{ingress,oauth2proxy-deployment, oauth2proxy-service}.yaml all reference studioIngress.enabled with no default. Pre-existing on main; not introduced by this merge. - The five Junie briefs filed on this branch are now reachable from main at docs/plans/junie/{02,06,07,13,15}-*.md. Junie can pick them up in any order. - knoe-auth Phase 2 OIDC source (now at dev.knoe.auth.*) is not yet deployed to the cluster. Deployment is its own task. - The branch claude/crazy-bose-fec256 stays in place (worktree at .claude/worktrees/crazy-bose-fec256 may have ongoing context for Claude Code sessions). Safe to delete once next session starts cleanly from main. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
328 lines
12 KiB
YAML
328 lines
12 KiB
YAML
{{- if .Values.deployment.kong.enabled -}}
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: {{ include "supabase.kong.fullname" . }}
|
|
labels:
|
|
{{- include "supabase.labels" . | nindent 4 }}
|
|
data:
|
|
wrapper.sh: |
|
|
#!/bin/bash
|
|
|
|
set -euo pipefail
|
|
|
|
echo "Replacing env placeholders of /usr/local/kong/kong.yml"
|
|
|
|
sed \
|
|
-e "s|\${SUPABASE_ANON_KEY}|${SUPABASE_ANON_KEY}|" \
|
|
-e "s|\${SUPABASE_SERVICE_KEY}|${SUPABASE_SERVICE_KEY}|" \
|
|
-e "s|\${DASHBOARD_USERNAME}|${DASHBOARD_USERNAME}|" \
|
|
-e "s|\${DASHBOARD_PASSWORD}|${DASHBOARD_PASSWORD}|" \
|
|
/usr/local/kong/template.yml \
|
|
> /usr/local/kong/kong.yml
|
|
|
|
exec /docker-entrypoint.sh kong docker-start
|
|
template.yml: |
|
|
_format_version: '2.1'
|
|
_transform: true
|
|
|
|
consumers:
|
|
{{- if .Values.secret.dashboard }}
|
|
- username: DASHBOARD
|
|
{{- end }}
|
|
- username: anon
|
|
keyauth_credentials:
|
|
- key: ${SUPABASE_ANON_KEY}
|
|
- username: service_role
|
|
keyauth_credentials:
|
|
- key: ${SUPABASE_SERVICE_KEY}
|
|
acls:
|
|
- consumer: anon
|
|
group: anon
|
|
- consumer: service_role
|
|
group: admin
|
|
{{- if .Values.secret.dashboard }}
|
|
basicauth_credentials:
|
|
- consumer: DASHBOARD
|
|
username: ${DASHBOARD_USERNAME}
|
|
password: ${DASHBOARD_PASSWORD}
|
|
{{- end }}
|
|
services:
|
|
# Dedicated health endpoint used by the GCE LB BackendConfig.
|
|
# request-termination returns 200 synchronously without hitting any
|
|
# upstream, so the probe passes as long as the Kong proxy itself is
|
|
# accepting requests -- same liveness semantics as the TCP check we
|
|
# originally wanted, but using the HTTP protocol that GCE's L7
|
|
# BackendConfig CRD actually accepts (TCP is rejected with
|
|
# `Protocol "TCP" is not valid, must be one of [HTTP,HTTPS,HTTP2]`).
|
|
#
|
|
# URL is a RFC-2606 reserved `.invalid` hostname that never resolves.
|
|
# We originally tried `http://127.0.0.1:8000/` here, which is Kong's
|
|
# own proxy port -- this crashlooped the pod on startup (rollout timed
|
|
# out waiting for new pod to become Ready). Suspected cause: Kong's
|
|
# declarative-config parser rejects the self-reference. Since the
|
|
# request-termination plugin short-circuits before any DNS lookup or
|
|
# upstream connection, using a non-resolvable placeholder URL is
|
|
# equivalent in behavior but avoids the loop detection.
|
|
- name: healthz
|
|
url: http://knoe.healthz.invalid/
|
|
routes:
|
|
- name: healthz
|
|
strip_path: true
|
|
paths:
|
|
- /healthz
|
|
plugins:
|
|
- name: request-termination
|
|
config:
|
|
status_code: 200
|
|
message: ok
|
|
# Stop-gap support endpoint -- 302s to mailto:support@knoe.dev so any user
|
|
# who lands at https://db.0.knoe.dev/support gets a working escape hatch.
|
|
# The in-Studio "Report a problem" / "Send feedback" buttons in upstream
|
|
# Studio are hardcoded to supabase.com endpoints and are not yet rewired
|
|
# (would require forking the Studio image -- tracked in docs/TODO.md).
|
|
# In the meantime we tell users: "for help, go to db.0.knoe.dev/support".
|
|
# request-termination synthesizes a 302 status; response-transformer
|
|
# injects the Location header (request-termination alone can't set it).
|
|
- name: support
|
|
url: http://knoe.support.invalid/
|
|
routes:
|
|
- name: support-redirect
|
|
strip_path: true
|
|
paths:
|
|
- /support
|
|
plugins:
|
|
- name: request-termination
|
|
config:
|
|
status_code: 302
|
|
message: "Redirecting to support@knoe.dev"
|
|
- name: response-transformer
|
|
config:
|
|
add:
|
|
headers:
|
|
- "Location:mailto:support@knoe.dev"
|
|
{{- if .Values.deployment.auth.enabled }}
|
|
- name: auth-v1-open
|
|
url: http://{{ include "supabase.auth.fullname" . }}:{{ .Values.service.auth.port }}/verify
|
|
routes:
|
|
- name: auth-v1-open
|
|
strip_path: true
|
|
paths:
|
|
- /auth/v1/verify
|
|
plugins:
|
|
- name: cors
|
|
- name: auth-v1-open-callback
|
|
url: http://{{ include "supabase.auth.fullname" . }}:{{ .Values.service.auth.port }}/callback
|
|
routes:
|
|
- name: auth-v1-open-callback
|
|
strip_path: true
|
|
paths:
|
|
- /auth/v1/callback
|
|
plugins:
|
|
- name: cors
|
|
- name: auth-v1-open-authorize
|
|
url: http://{{ include "supabase.auth.fullname" . }}:{{ .Values.service.auth.port }}/authorize
|
|
routes:
|
|
- name: auth-v1-open-authorize
|
|
strip_path: true
|
|
paths:
|
|
- /auth/v1/authorize
|
|
plugins:
|
|
- name: cors
|
|
- name: auth-v1
|
|
_comment: "GoTrue: /auth/v1/* -> http://{{ include "supabase.auth.fullname" . }}:{{ .Values.service.auth.port }}/*"
|
|
url: http://{{ include "supabase.auth.fullname" . }}:{{ .Values.service.auth.port }}
|
|
routes:
|
|
- name: auth-v1-all
|
|
strip_path: true
|
|
paths:
|
|
- /auth/v1/
|
|
plugins:
|
|
- name: cors
|
|
- name: key-auth
|
|
config:
|
|
hide_credentials: false
|
|
- name: acl
|
|
config:
|
|
hide_groups_header: true
|
|
allow:
|
|
- admin
|
|
- anon
|
|
{{- end }}
|
|
{{- if .Values.deployment.rest.enabled }}
|
|
- name: rest-v1
|
|
_comment: "PostgREST: /rest/v1/* -> http://{{ include "supabase.rest.fullname" . }}:{{ .Values.service.rest.port }}/*"
|
|
url: http://{{ include "supabase.rest.fullname" . }}:{{ .Values.service.rest.port }}/
|
|
routes:
|
|
- name: rest-v1-all
|
|
strip_path: true
|
|
paths:
|
|
- /rest/v1/
|
|
plugins:
|
|
- name: cors
|
|
- name: key-auth
|
|
config:
|
|
hide_credentials: true
|
|
- name: acl
|
|
config:
|
|
hide_groups_header: true
|
|
allow:
|
|
- admin
|
|
- anon
|
|
- name: graphql-v1
|
|
_comment: 'PostgREST: /graphql/v1/* -> http://{{ include "supabase.rest.fullname" . }}:{{ .Values.service.rest.port }}/rpc/graphql'
|
|
url: http://{{ include "supabase.rest.fullname" . }}:{{ .Values.service.rest.port }}/rpc/graphql
|
|
routes:
|
|
- name: graphql-v1-all
|
|
strip_path: true
|
|
paths:
|
|
- /graphql/v1
|
|
plugins:
|
|
- name: cors
|
|
- name: key-auth
|
|
config:
|
|
hide_credentials: true
|
|
- name: request-transformer
|
|
config:
|
|
add:
|
|
headers:
|
|
- Content-Profile:graphql_public
|
|
- name: acl
|
|
config:
|
|
hide_groups_header: true
|
|
allow:
|
|
- admin
|
|
- anon
|
|
{{- end }}
|
|
{{- if .Values.deployment.realtime.enabled }}
|
|
- name: realtime-v1-ws
|
|
_comment: "Realtime: /realtime/v1/* -> ws://{{ include "supabase.realtime.fullname" . }}:{{ .Values.service.realtime.port }}/socket/*"
|
|
url: http://{{ include "supabase.realtime.fullname" . }}:{{ .Values.service.realtime.port }}/socket
|
|
protocol: ws
|
|
routes:
|
|
- name: realtime-v1-ws
|
|
strip_path: true
|
|
paths:
|
|
- /realtime/v1/
|
|
plugins:
|
|
- name: cors
|
|
- name: key-auth
|
|
config:
|
|
hide_credentials: false
|
|
- name: acl
|
|
config:
|
|
hide_groups_header: true
|
|
allow:
|
|
- admin
|
|
- anon
|
|
- name: realtime-v1-rest
|
|
_comment: 'Realtime: /realtime/v1/* -> http://{{ include "supabase.realtime.fullname" . }}:{{ .Values.service.realtime.port }}/api/*'
|
|
url: http://{{ include "supabase.realtime.fullname" . }}:{{ .Values.service.realtime.port }}/api
|
|
protocol: http
|
|
routes:
|
|
- name: realtime-v1-rest
|
|
strip_path: true
|
|
paths:
|
|
- /realtime/v1/api
|
|
plugins:
|
|
- name: cors
|
|
- name: key-auth
|
|
config:
|
|
hide_credentials: false
|
|
- name: acl
|
|
config:
|
|
hide_groups_header: true
|
|
allow:
|
|
- admin
|
|
- anon
|
|
{{- end }}
|
|
{{- if .Values.deployment.storage.enabled }}
|
|
- name: storage-v1
|
|
_comment: "Storage: /storage/v1/* -> http://{{ include "supabase.storage.fullname" . }}:{{ .Values.service.storage.port }}/*"
|
|
url: http://{{ include "supabase.storage.fullname" . }}:{{ .Values.service.storage.port }}/
|
|
routes:
|
|
- name: storage-v1-all
|
|
strip_path: true
|
|
paths:
|
|
- /storage/v1/
|
|
plugins:
|
|
- name: cors
|
|
{{- end }}
|
|
{{- if .Values.deployment.functions.enabled }}
|
|
- name: functions-v1
|
|
_comment: 'Edge Functions: /functions/v1/* -> http://{{ include "supabase.functions.fullname" . }}:{{ .Values.service.functions.port }}/*'
|
|
url: http://{{ include "supabase.functions.fullname" . }}:{{ .Values.service.functions.port }}/
|
|
routes:
|
|
- name: functions-v1-all
|
|
strip_path: true
|
|
paths:
|
|
- /functions/v1/
|
|
plugins:
|
|
- name: cors
|
|
{{- end }}
|
|
|
|
{{/*
|
|
## Not used - Studio and Vector talk directly to analytics via Docker networking.
|
|
## If external access is needed, add routes with key-auth matching Logflare's x-api-key auth.
|
|
*/}}
|
|
|
|
{{/*
|
|
{{- if .Values.deployment.analytics.enabled }}
|
|
- name: analytics-v1
|
|
_comment: 'Analytics: /analytics/v1/* -> http://{{ include "supabase.analytics.fullname" . }}:{{ .Values.service.analytics.port }}/*'
|
|
url: http://{{ include "supabase.analytics.fullname" . }}:{{ .Values.service.analytics.port }}/
|
|
routes:
|
|
- name: analytics-v1-all
|
|
strip_path: true
|
|
paths:
|
|
- /analytics/v1/
|
|
{{- end }}
|
|
*/}}
|
|
|
|
{{- if .Values.deployment.meta.enabled }}
|
|
- name: meta
|
|
_comment: "pg-meta: /pg/* -> http://{{ include "supabase.meta.fullname" . }}:{{ .Values.service.meta.port }}/*"
|
|
url: http://{{ include "supabase.meta.fullname" . }}:{{ .Values.service.meta.port }}/
|
|
routes:
|
|
- name: meta-all
|
|
strip_path: true
|
|
paths:
|
|
- /pg/
|
|
plugins:
|
|
- name: key-auth
|
|
config:
|
|
hide_credentials: false
|
|
- name: acl
|
|
config:
|
|
hide_groups_header: true
|
|
allow:
|
|
- admin
|
|
{{- end }}
|
|
# Onboarding reveal page (knoe-onboard nginx pod). Listed BEFORE the
|
|
# /-wildcard dashboard route so Kong's longest-prefix match picks
|
|
# /onboard.html over the dashboard. The page itself is also exempted
|
|
# from oauth2-proxy gating (`--skip-auth-route=^/onboard\.html$`) since
|
|
# URL fragments don't survive an OAuth redirect; URL secrecy + 24h
|
|
# expiry + immediate-rotation is the security envelope.
|
|
- name: onboard
|
|
_comment: 'Onboarding reveal: /onboard.html -> knoe-onboard nginx pod'
|
|
url: http://knoe-onboard:80/
|
|
routes:
|
|
- name: onboard-html
|
|
strip_path: false
|
|
paths:
|
|
- /onboard.html
|
|
plugins:
|
|
- name: cors
|
|
- name: dashboard
|
|
_comment: 'Studio: /* -> http://{{ include "supabase.studio.fullname" . }}:{{ .Values.service.studio.port }}/*'
|
|
url: http://{{ include "supabase.studio.fullname" . }}:{{ .Values.service.studio.port }}/
|
|
routes:
|
|
- name: dashboard-all
|
|
strip_path: true
|
|
paths:
|
|
- /
|
|
plugins:
|
|
- name: cors
|
|
{{- end }}
|