mirror of
https://github.com/dredx/prole.git
synced 2026-09-28 21:24:30 +00:00
Kerberos is now the single source of truth for all knoe-system accounts. In-cluster KDC (PROLE.LOCAL): - Rename in-cluster KDC realm PROLE.ORG → PROLE.LOCAL to avoid collision with the myrddin.prole.org Samba AD DC which owns PROLE.ORG - Add [capaths] cross-realm trust block: PROLE.ORG (Samba AD) ↔ PROLE.LOCAL - Create admin@PROLE.LOCAL on KDC startup (master password) for UI login - Create guest@PROLE.LOCAL on KDC startup (read-only, PROLE_KDC_GUEST_PASSWORD) - Update prole-kdc-secrets.example.yaml with trust_shared_password and guest_password - Update prole-auth-kerberos ConfigMap realm/servicePrincipal to PROLE.LOCAL - Add PROLE_AUTH_ADMIN_PRINCIPALS and PROLE_KDC_GUEST_PASSWORD to prole-auth Deployment Database (knoe-db — k3s and GKE): - Add spec.managed.roles: admin (superuser), guest (login), developer (group) - Enable GSS pg_hba rules for both PROLE.ORG and PROLE.LOCAL realms - Add krb_server_keyfile parameter for postgres service principal keytab - Mount knoe-db-pg-keytab Secret via spec.additionalVolumes - Add demo schema in postInitSQL with guest read-only grants prole-auth (Spring Boot): - SessionUser: add List<String> groups field - AuthProperties: add adminPrincipals list (env: PROLE_AUTH_ADMIN_PRINCIPALS) - LoginController: stamp groups=["admin"] for configured admin principals at login - SessionTokenService: carry groups through TokenPayload; @JsonIgnoreProperties for backward compat with existing 2-field session cookies - VerifyController: emit X-Prole-Groups header on /auth/verify - grafana-proxy nginx: strip inbound X-Prole-Groups; capture and forward from auth Services: - ArgoCD (k3s + GKE): add g, admin, role:admin to argocd-rbac-cm policy.csv etc/init_knoe_users.sh (new): - Orchestrates full user provisioning: KDC principals, postgres keytab export, CNPG managed.roles patch, demo schema SQL, ArgoCD RBAC patch, Gitea and GitLab admin promotion via API - Actions: initialize | status | cleanup - Idempotent; sources prole_cfg.sh; follows existing init_*.sh style Cross-realm trust activation (myrddin side): samba-tool user add krbtgt_PROLELOCAL --random-password samba-tool user setpassword krbtgt_PROLELOCAL --newpassword=<trust_shared_password> samba-tool spn add "krbtgt/PROLE.LOCAL" krbtgt_PROLELOCAL -U administrator samba-tool user setexpiry krbtgt_PROLELOCAL --noexpiry Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
59 lines
1.7 KiB
YAML
59 lines
1.7 KiB
YAML
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: prole-grafana-proxy-nginx
|
|
data:
|
|
nginx.conf: |
|
|
worker_processes 1;
|
|
events { worker_connections 1024; }
|
|
http {
|
|
map $http_upgrade $connection_upgrade {
|
|
default upgrade;
|
|
'' close;
|
|
}
|
|
|
|
server {
|
|
listen 80;
|
|
server_name _;
|
|
|
|
# Never trust inbound auth headers from clients.
|
|
proxy_set_header X-WEBAUTH-USER "";
|
|
proxy_set_header X-Prole-Groups "";
|
|
|
|
location = /_auth_verify {
|
|
internal;
|
|
proxy_pass http://prole-auth:8080/auth/verify;
|
|
proxy_pass_request_body off;
|
|
proxy_set_header Content-Length "";
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto $scheme;
|
|
proxy_set_header X-Forwarded-Host $host;
|
|
}
|
|
|
|
location / {
|
|
auth_request /_auth_verify;
|
|
auth_request_set $prole_user $upstream_http_x_prole_user;
|
|
auth_request_set $prole_groups $upstream_http_x_prole_groups;
|
|
|
|
error_page 401 = @login;
|
|
error_page 403 = @login;
|
|
|
|
proxy_set_header X-WEBAUTH-USER $prole_user;
|
|
proxy_set_header X-Prole-Groups $prole_groups;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto $scheme;
|
|
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Upgrade $http_upgrade;
|
|
proxy_set_header Connection $connection_upgrade;
|
|
|
|
proxy_pass http://kps-grafana.monitoring.svc.cluster.local:80;
|
|
}
|
|
|
|
location @login {
|
|
return 302 https://api.prole.org/auth/login?next=$scheme://$host$request_uri;
|
|
}
|
|
}
|
|
}
|