mirror of
https://github.com/dredx/prole.git
synced 2026-09-24 15:04:31 +00:00
knoe-auth (prole.org k3s): - Fix CNPG manifest drift: remove spec.backup.pluginConfiguration (CNPG 1.28 only), switch spec.certificates from serverTLSSecret to serverAltDNSNames - Apply knoe-auth Round 1 schema + GRANTs manually (postInitSQL had never run on live cluster) - Fix OIDC signing key generator: base64(DER) not base64(PEM) — OidcTokenService does Base64.decode() → PKCS8EncodedKeySpec which requires raw DER bytes - Add OIDC controllers: authorize, token, userinfo, jwks, discovery - Add prole Spring profile: cookieDomain, emailDomain, Kerberos config - Add secret example templates: knoe-db-user, knoe-auth-oidc-signing, knoe-auth-google-prole - Kong configmap: scope knoe-auth route to /auth prefix only Tenant onboarding: - Add etc/onboard_tenant.sh: provision/apply/rotate/status workflow backed by 1Password vaults; types: 'enterprise' (own Kerberos + domain) and 'tenant' (hosted, initContainer KDC) - Provision 'Knoe Tenant - prole.org' vault; apply all 7 k8s secrets to knoe-system - init_knoe_auth.sh: add explicit GRANT + ALTER DEFAULT PRIVILEGES for knoe role Cluster stabilisation: - gitea: roll back 14-day stuck rollout (RWO PVC + maxSurge=100% deadlock); patch deployment strategy to Recreate - supabase: create supabase_admin role, _supabase db, _analytics schema, _realtime schema in CNPG — analytics and realtime had never connected since Helm install day 1 - knoe-db barman ObjectStore: add GCS-backed objectstore manifest + scheduled backup Infrastructure: - gandalf host_vars: k3s registry config - pi host_vars: clean up stale entries - knoe-db schemas: ekosystem.sql, ekosystem_objects.sql - init_prole_app.sql: prole app DB initialisation Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
26 lines
948 B
YAML
26 lines
948 B
YAML
apiVersion: v1
|
|
kind: Secret
|
|
metadata:
|
|
name: knoe-auth-oidc-signing
|
|
namespace: knoe-system
|
|
labels:
|
|
app.kubernetes.io/managed-by: knoe-installer
|
|
# OIDC RS256 signing key for knoe-auth acting as OIDC provider (Phase 2).
|
|
# The signing key is a base64-encoded PKCS#8 RSA private key (2048-bit minimum).
|
|
#
|
|
# Generate a fresh key:
|
|
# openssl genrsa -out oidc-signing.pem 2048
|
|
# openssl pkcs8 -topk8 -nocrypt -in oidc-signing.pem -out oidc-signing-pkcs8.pem
|
|
# SIGNING_KEY=$(base64 -w0 < oidc-signing-pkcs8.pem)
|
|
#
|
|
# Store the real value in OpenBao:
|
|
# bao kv put knoe/oauth2/knoe-auth-oidc-signing signing-key="$SIGNING_KEY"
|
|
#
|
|
# Then create the secret from OpenBao:
|
|
# kubectl create secret generic knoe-auth-oidc-signing \
|
|
# --namespace knoe-system \
|
|
# --from-literal=signing-key="$(bao kv get -field=signing-key knoe/oauth2/knoe-auth-oidc-signing)"
|
|
type: Opaque
|
|
stringData:
|
|
signing-key: "CHANGE_ME_BASE64_PKCS8_RSA_PRIVATE_KEY"
|