mirror of
https://github.com/dredx/prole.git
synced 2026-09-24 15:54:32 +00:00
knoe-auth (Spring Boot OIDC provider): - AuthProperties: add google.workspaceDomain and kerberos.servicePrincipal fields - GoogleOAuthService: validate hd (hosted domain) claim; restrict to configured workspace - LoginController: /login/google endpoint + SPNEGO negotiation entry point - PrincipalNormalizer: map Kerberos principal (user@REALM) to knoe-auth user - application.yml: add spring.security.kerberos and oauth2.client stubs (values injected at runtime from env / Kubernetes Secrets) - knoe-auth-deployment.yaml: mount HTTP keytab Secret; add GOOGLE_PROLE_CLIENT_ID / GOOGLE_PROLE_CLIENT_SECRET env from oauth2-proxy-prole-secret - knoe-auth-http-keytab-secret.example.yaml: example Secret for HTTP/<host> keytab Kong (init_kong.sh): - Add db.prole.org route in k3s mode block via oauth2-proxy upstream - Mode-gate: only registered for k3s, excluded for k3d/k8s Supabase / oauth2-proxy: - New supabase/helm/oauth2-proxy Helm chart: gates Supabase Studio at db.prole.org with Google OAuth (email-domain=prole.org) + cookie settings for .prole.org domain - values-k3s.yaml: k3s-specific overrides (upstream service, TLS, cookie domain) - secret-example.yaml: placeholder for oauth2-proxy-prole-secret Ansible: - infrastructure/playbooks/kerberos_trust_setup.yml: automates samba-tool domain trust create on myrddin.prole.org for PROLE.LOCAL ↔ PROLE.ORG cross-realm trust Test: - GoogleLoginProleOrgTest: verifies hd=prole.org tokens are accepted; hd=other.com rejected Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| argocd | ||
| manifests | ||
| main.tf | ||
| opentofu.auto.tfvars | ||
| README.md | ||
| variables.tf | ||
OpenTofu k3s Pipeline
This pipeline re-deploys the Knoe environment into a k3s cluster using OpenTofu.
Usage
- Ensure
opentofu.auto.tfvarsis populated (install.py will generate it). - Sync manifests into
deploy/opentofu/k3s/manifests. - Run:
tofu init
tofu plan
tofu apply
Files
main.tf: Applies Kubernetes manifests with the configured namespace.variables.tf: Pipeline inputs (server URL, token, namespace).opentofu.auto.tfvars: Auto-generated values from Knoe install/config.manifests/: Copy ofk8s/manifests to re-deploy.