prole/supabase/helm/prole-supabase/values-gke.yaml
chrisfu 620bdd25eb feat: GKE production deployment — CNPG + GCS backups + Google Workspace SSO
Add complete GKE deployment stack:
- deploy/gcp/gke/: namespace, CloudNativePG cluster (premium-rwo, 100Gi),
  GCS barman-cloud backup with Workload Identity SA, ArgoCD OIDC ConfigMap,
  GitLab OmniAuth secret template, knoe-auth Google OIDC secret template
- etc/init_cnpg_gke.sh: provision GCS buckets, GCP SA, WI binding, CNPG operator
- etc/init_argocd.sh: apply argocd-oidc-cm.yaml when PLATFORM_DOMAIN/FRONTDOOR_HOST set
- etc/init_gitlab.sh: inject OmniAuth openid_connect block when FRONTDOOR_HOST set
- prole-auth-deployment.yaml: add GOOGLE_OIDC_ENABLED env vars (all optional)
- supabase/helm/prole-supabase/values-gke.yaml: GoTrue Google OAuth overlay
- knoe/core/prod_config.py: add backupProvider, workloadIdentitySA, googleClientId/Secret/HostedDomain

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-01 10:41:55 -07:00

47 lines
2.3 KiB
YAML

# GKE production values overlay for prole-supabase Helm chart.
#
# Apply on top of values.yaml:
# helm upgrade --install prole-supabase ./supabase/helm/prole-supabase \
# --values supabase/helm/prole-supabase/values.yaml \
# --values supabase/helm/prole-supabase/values-gke.yaml \
# --set environment.auth.GOTRUE_EXTERNAL_GOOGLE_CLIENT_ID="$CLIENT_ID" \
# --set environment.auth.GOTRUE_EXTERNAL_GOOGLE_SECRET="$CLIENT_SECRET" \
# --set environment.auth.GOTRUE_SITE_URL="https://$FRONTDOOR_HOST" \
# --set environment.auth.GOTRUE_EXTERNAL_GOOGLE_REDIRECT_URI="https://$FRONTDOOR_HOST/auth/v1/callback" \
# --set environment.auth.GOTRUE_URI_ALLOW_LIST="https://$FRONTDOOR_HOST/**"
#
# Or set FRONTDOOR_HOST, GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET in environment
# and let init_supabase.sh --mode k8s substitute them automatically.
# ── Storage: use GCS instead of bundled MinIO ───────────────────────────────
# When CNPG Workload Identity is active the pod SA already has storage access;
# set storage driver to gcs and disable minio.
deployment:
minio:
enabled: false
# ── GoTrue: enable Google OAuth via knoe-auth OIDC broker ───────────────────
environment:
auth:
# Override base URL to the GKE frontdoor
API_EXTERNAL_URL: "" # set to https://<frontdoor-host>/auth/v1 at deploy time
GOTRUE_SITE_URL: "" # set to https://<frontdoor-host>
GOTRUE_URI_ALLOW_LIST: "" # set to https://<frontdoor-host>/**
# Google OAuth2 — client ID and secret from knoe-auth-google-oidc secret
GOTRUE_EXTERNAL_GOOGLE_ENABLED: "true"
GOTRUE_EXTERNAL_GOOGLE_CLIENT_ID: "" # injected at deploy time
GOTRUE_EXTERNAL_GOOGLE_SECRET: "" # injected at deploy time
GOTRUE_EXTERNAL_GOOGLE_REDIRECT_URI: "" # set to https://<frontdoor-host>/auth/v1/callback
# Disable anonymous sign-in in production
GOTRUE_EXTERNAL_ANONYMOUS_USERS_ENABLED: "false"
# Auto-confirm email (Google accounts are pre-verified)
GOTRUE_MAILER_AUTOCONFIRM: "true"
# ── Ingress: use GKE-managed ingress class ──────────────────────────────────
ingress:
studio:
className: "gce" # GKE L7 load balancer; override with "kong" if Kong is installed