Change chart directory structure
This commit is contained in:
+28
@@ -0,0 +1,28 @@
|
||||
apiVersion: security.istio.io/v1beta1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: istio-ingressgateway-oauth2-proxy
|
||||
namespace: istio-system
|
||||
spec:
|
||||
action: CUSTOM
|
||||
provider:
|
||||
name: oauth2-proxy
|
||||
selector:
|
||||
matchLabels:
|
||||
app: istio-ingressgateway
|
||||
rules:
|
||||
# We ONLY authenticate requests that DON'T have an `Authorization` header using oauth2-proxy.
|
||||
# This is because we use RequestAuthentication to authenticate requests with an `Authorization` header.
|
||||
- when:
|
||||
- key: request.headers[authorization]
|
||||
notValues: ["*"]
|
||||
to:
|
||||
- operation:
|
||||
notPaths:
|
||||
# Exclude dex paths, otherwise users won't be able to log in.
|
||||
- /dex/*
|
||||
- /dex/**
|
||||
- /oauth2/*
|
||||
- /v1*
|
||||
- /v2*
|
||||
- /openai*
|
||||
+27
@@ -0,0 +1,27 @@
|
||||
apiVersion: security.istio.io/v1beta1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: istio-ingressgateway-require-jwt
|
||||
namespace: istio-system
|
||||
spec:
|
||||
action: DENY
|
||||
selector:
|
||||
matchLabels:
|
||||
app: istio-ingressgateway
|
||||
rules:
|
||||
# Deny requests that don't have a verified JWT (from a RequestAuthentication)
|
||||
# Note, even user requests that have been authenticated by oauth2-proxy will have a JWT,
|
||||
# because oauth2-proxy injects a Dex JWT into the request.
|
||||
- from:
|
||||
- source:
|
||||
notRequestPrincipals: ["*"]
|
||||
to:
|
||||
- operation:
|
||||
notPaths:
|
||||
# Exclude dex paths, otherwise users won't be able to log in.
|
||||
- /dex/*
|
||||
- /dex/**
|
||||
- /oauth2/*
|
||||
- /v1*
|
||||
- /v2*
|
||||
- /openai*
|
||||
+12
@@ -0,0 +1,12 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1alpha1
|
||||
kind: Component
|
||||
|
||||
resources:
|
||||
- authorizationpolicy.istio-ingressgateway-oauth2-proxy.yaml
|
||||
- authorizationpolicy.istio-ingressgateway-require-jwt.yaml
|
||||
- requestauthentication.keycloak-jwt.yaml
|
||||
|
||||
# If want to enable caching for some paths (e.g. when using Cloudflare),
|
||||
# use the following AuthorizationPolicies instead of the default ones.
|
||||
#- authorizationpolicy.istio-ingressgateway-oauth2-proxy.cloudflare.yaml
|
||||
#- authorizationpolicy.istio-ingressgateway-require-jwt.cloudflare.yaml
|
||||
+25
@@ -0,0 +1,25 @@
|
||||
apiVersion: security.istio.io/v1beta1
|
||||
kind: RequestAuthentication
|
||||
metadata:
|
||||
name: keycloak-jwt
|
||||
namespace: istio-system
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: istio-ingressgateway
|
||||
|
||||
jwtRules:
|
||||
- # The `issuer` must be replaced with a Kustomize patch.
|
||||
issuer: PATCH_ME
|
||||
jwksUri: PATCH_ME
|
||||
forwardOriginalToken: true
|
||||
outputClaimToHeaders:
|
||||
- header: kubeflow-userid
|
||||
claim: email
|
||||
- header: kubeflow-groups
|
||||
claim: groups
|
||||
- header: x-auth-request-user
|
||||
claim: sub
|
||||
fromHeaders:
|
||||
- name: Authorization
|
||||
prefix: "Bearer "
|
||||
@@ -0,0 +1,63 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- ../../base
|
||||
|
||||
components:
|
||||
- ./istio-keycloak-auth
|
||||
|
||||
configMapGenerator:
|
||||
- name: oauth2-proxy-parameters
|
||||
behavior: merge
|
||||
literals:
|
||||
# Configs for oauth2-proxy
|
||||
- ALLOW_SELF_SIGNED_ISSUER=true
|
||||
- name: istio-m2m-params
|
||||
envs:
|
||||
- m2m.env
|
||||
|
||||
replacements:
|
||||
- source:
|
||||
kind: ConfigMap
|
||||
version: v1
|
||||
name: istio-m2m-params
|
||||
fieldPath: data.M2M_ISSUER
|
||||
targets:
|
||||
- select:
|
||||
group: security.istio.io
|
||||
version: v1beta1
|
||||
kind: RequestAuthentication
|
||||
name: keycloak-jwt
|
||||
namespace: istio-system
|
||||
fieldPaths:
|
||||
- spec.jwtRules.0.issuer
|
||||
|
||||
- source:
|
||||
kind: ConfigMap
|
||||
version: v1
|
||||
name: istio-m2m-params
|
||||
fieldPath: data.M2M_JWKS
|
||||
targets:
|
||||
- select:
|
||||
group: security.istio.io
|
||||
version: v1beta1
|
||||
kind: RequestAuthentication
|
||||
name: keycloak-jwt
|
||||
namespace: istio-system
|
||||
fieldPaths:
|
||||
- spec.jwtRules.0.jwksUri
|
||||
|
||||
|
||||
secretGenerator:
|
||||
- name: oauth2-proxy
|
||||
behavior: merge
|
||||
type: Opaque
|
||||
envs:
|
||||
- secrets.env
|
||||
|
||||
patches:
|
||||
- target:
|
||||
kind: ConfigMap
|
||||
name: oauth2-proxy
|
||||
path: patch-oauth2-proxy-config.yaml
|
||||
@@ -0,0 +1,2 @@
|
||||
M2M_ISSUER=$OIDC_ISSUER_URL
|
||||
M2M_JWKS=$OIDC_JWKS_URL
|
||||
+56
@@ -0,0 +1,56 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: oauth2-proxy
|
||||
labels:
|
||||
app: oauth2-proxy
|
||||
data:
|
||||
oauth2_proxy.cfg: |
|
||||
provider = "keycloak-oidc"
|
||||
oidc_issuer_url = "$OIDC_ISSUER_URL"
|
||||
scope = "profile email roles openid"
|
||||
upstreams = "static://200"
|
||||
email_domains = [ "*" ]
|
||||
insecure_oidc_allow_unverified_email = "true"
|
||||
# ---
|
||||
# OIDC Discovery has to be skipped and login url has to be provided directly
|
||||
# in order to enable relative auth redirect.
|
||||
# Turning On OIDC Discovery would set the auth redirect location as the dex
|
||||
# Issuer URL which is http://dex.auth.svc.cluster.local:5556 in the default,
|
||||
# example installation. This address is usuallynot available through the Web
|
||||
# Browser. If you have a setup where dex has it's url as other than the
|
||||
# in-cluster service, this is optional.
|
||||
# ---
|
||||
# Go to dex login page directly instead of showing the oauth2-proxy login
|
||||
# page.
|
||||
skip_provider_button = true
|
||||
# ---
|
||||
# Set Authorization Bearer response header. This is needed in order to
|
||||
# forward the Authorization Bearer token to Istio and enable authorization
|
||||
# based on JWT.
|
||||
set_authorization_header = true
|
||||
pass_access_token = true
|
||||
pass_authorization_header = true
|
||||
|
||||
# ---
|
||||
# set X-Auth-Request-User, X-Auth-Request-Groups, X-Auth-Request-Email and
|
||||
# X-Auth-Request-Preferred-Username. This is optional for Kubeflow but you
|
||||
# may have other services that use standard auth headers.
|
||||
set_xauthrequest = true
|
||||
# ---
|
||||
cookie_name = "oauth2_proxy_kubeflow"
|
||||
# ---
|
||||
# Dex default cookie expiration is 24h. If set to 168h (default oauth2-proxy),
|
||||
# Istio will not be able to use the JWT after 24h but oauth2-proxy will still
|
||||
# consider the cookie valid.
|
||||
# It's possible to configure the JWT Refresh Token to enable longer login
|
||||
# session.
|
||||
cookie_expire = "24h"
|
||||
cookie_refresh = "5m"
|
||||
# ---
|
||||
code_challenge_method = "S256"
|
||||
# ---
|
||||
redirect_url = "$REDIRECT_URL"
|
||||
relative_redirect_url = true
|
||||
|
||||
binaryData: {}
|
||||
@@ -0,0 +1,3 @@
|
||||
client-id=$CLIENT-ID
|
||||
client-secret=$CLIENT-SECRET
|
||||
cookie-secret=$COOKIE-SECRET
|
||||
Reference in New Issue
Block a user