Add kubeflow/v1.10.0
This commit is contained in:
+34
@@ -0,0 +1,34 @@
|
||||
apiVersion: security.istio.io/v1beta1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: istio-ingressgateway-oauth2-proxy
|
||||
namespace: istio-system
|
||||
spec:
|
||||
action: CUSTOM
|
||||
provider:
|
||||
name: oauth2-proxy
|
||||
selector:
|
||||
matchLabels:
|
||||
app: istio-ingressgateway
|
||||
rules:
|
||||
# We ONLY authenticate requests that DON'T have an `Authorization` header using oauth2-proxy.
|
||||
# This is because we use RequestAuthentication to authenticate requests with an `Authorization` header.
|
||||
- when:
|
||||
- key: request.headers[authorization]
|
||||
notValues: ["*"]
|
||||
to:
|
||||
- operation:
|
||||
notPaths:
|
||||
# Exclude dex paths, otherwise users won't be able to log in.
|
||||
- /dex/*
|
||||
- /dex/**
|
||||
- /oauth2/*
|
||||
|
||||
# Exclude paths which are safe to cache by Cloudflare.
|
||||
- /favicon*
|
||||
- /webcomponentsjs*
|
||||
- /vendor.bundle.js
|
||||
- /app.bundle.js
|
||||
- /dashboard_lib.bundle.js
|
||||
- /assets*
|
||||
- /app.css
|
||||
+25
@@ -0,0 +1,25 @@
|
||||
apiVersion: security.istio.io/v1beta1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: istio-ingressgateway-oauth2-proxy
|
||||
namespace: istio-system
|
||||
spec:
|
||||
action: CUSTOM
|
||||
provider:
|
||||
name: oauth2-proxy
|
||||
selector:
|
||||
matchLabels:
|
||||
app: istio-ingressgateway
|
||||
rules:
|
||||
# We ONLY authenticate requests that DON'T have an `Authorization` header using oauth2-proxy.
|
||||
# This is because we use RequestAuthentication to authenticate requests with an `Authorization` header.
|
||||
- when:
|
||||
- key: request.headers[authorization]
|
||||
notValues: ["*"]
|
||||
to:
|
||||
- operation:
|
||||
notPaths:
|
||||
# Exclude dex paths, otherwise users won't be able to log in.
|
||||
- /dex/*
|
||||
- /dex/**
|
||||
- /oauth2/*
|
||||
+33
@@ -0,0 +1,33 @@
|
||||
apiVersion: security.istio.io/v1beta1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: istio-ingressgateway-require-jwt
|
||||
namespace: istio-system
|
||||
spec:
|
||||
action: DENY
|
||||
selector:
|
||||
matchLabels:
|
||||
app: istio-ingressgateway
|
||||
rules:
|
||||
# Deny requests that don't have a verified JWT (from a RequestAuthentication)
|
||||
# Note, even user requests that have been authenticated by oauth2-proxy will have a JWT,
|
||||
# because oauth2-proxy injects a Dex JWT into the request.
|
||||
- from:
|
||||
- source:
|
||||
notRequestPrincipals: ["*"]
|
||||
to:
|
||||
- operation:
|
||||
notPaths:
|
||||
# Exclude dex paths, otherwise users won't be able to log in.
|
||||
- /dex/*
|
||||
- /dex/**
|
||||
- /oauth2/*
|
||||
|
||||
# Exclude paths which are safe to cache by Cloudflare.
|
||||
- /favicon*
|
||||
- /webcomponentsjs*
|
||||
- /vendor.bundle.js
|
||||
- /app.bundle.js
|
||||
- /dashboard_lib.bundle.js
|
||||
- /assets*
|
||||
- /app.css
|
||||
+24
@@ -0,0 +1,24 @@
|
||||
apiVersion: security.istio.io/v1beta1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: istio-ingressgateway-require-jwt
|
||||
namespace: istio-system
|
||||
spec:
|
||||
action: DENY
|
||||
selector:
|
||||
matchLabels:
|
||||
app: istio-ingressgateway
|
||||
rules:
|
||||
# Deny requests that don't have a verified JWT (from a RequestAuthentication)
|
||||
# Note, even user requests that have been authenticated by oauth2-proxy will have a JWT,
|
||||
# because oauth2-proxy injects a Dex JWT into the request.
|
||||
- from:
|
||||
- source:
|
||||
notRequestPrincipals: ["*"]
|
||||
to:
|
||||
- operation:
|
||||
notPaths:
|
||||
# Exclude dex paths, otherwise users won't be able to log in.
|
||||
- /dex/*
|
||||
- /dex/**
|
||||
- /oauth2/*
|
||||
@@ -0,0 +1,12 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1alpha1
|
||||
kind: Component
|
||||
|
||||
resources:
|
||||
- authorizationpolicy.istio-ingressgateway-oauth2-proxy.yaml
|
||||
- authorizationpolicy.istio-ingressgateway-require-jwt.yaml
|
||||
- requestauthentication.dex-jwt.yaml
|
||||
|
||||
# If want to enable caching for some paths (e.g. when using Cloudflare),
|
||||
# use the following AuthorizationPolicies instead of the default ones.
|
||||
#- authorizationpolicy.istio-ingressgateway-oauth2-proxy.cloudflare.yaml
|
||||
#- authorizationpolicy.istio-ingressgateway-require-jwt.cloudflare.yaml
|
||||
+44
@@ -0,0 +1,44 @@
|
||||
apiVersion: security.istio.io/v1beta1
|
||||
kind: RequestAuthentication
|
||||
metadata:
|
||||
name: dex-jwt
|
||||
namespace: istio-system
|
||||
spec:
|
||||
# we only apply to the ingress-gateway because:
|
||||
# - there is no need to verify the same tokens at each sidecar
|
||||
# - having no selector will apply to the RequestAuthentication to ALL
|
||||
# Pods in the mesh, even ones which are not part of Kubeflow
|
||||
# - some Kubeflow services accept direct connections with Kubernetes JWTs,
|
||||
# and we don't want to require that users configure Istio to verify Kubernetes JWTs
|
||||
# as there is no method to do this which works on all distributions.
|
||||
selector:
|
||||
matchLabels:
|
||||
app: istio-ingressgateway
|
||||
|
||||
jwtRules:
|
||||
- issuer: http://dex.auth.svc.cluster.local:5556/dex
|
||||
|
||||
# `forwardOriginalToken` is not strictly required to be true.
|
||||
# there are pros and cons to each value:
|
||||
# - true: the original token is forwarded to the destination service
|
||||
# which raises the risk of the token leaking
|
||||
# - false: the original token is stripped from the request
|
||||
# which will prevent the destination service from
|
||||
# verifying the token (possibly with its own RequestAuthentication)
|
||||
forwardOriginalToken: true
|
||||
|
||||
# This will unpack the JWTs issued by dex into the expected headers.
|
||||
# It is applied to BOTH the m2m tokens from outside the cluster (which skip
|
||||
# oauth2-proxy because they already have a dex JWT), AND user requests which were
|
||||
# authenticated by oauth2-proxy (which injected a dex JWT).
|
||||
outputClaimToHeaders:
|
||||
- header: kubeflow-userid
|
||||
claim: email
|
||||
- header: kubeflow-groups
|
||||
claim: groups
|
||||
|
||||
# We explicitly set `fromHeaders` to ensure that the JWT is only extracted from the `Authorization` header.
|
||||
# This is because we exclude requests that have an `Authorization` header from oauth2-proxy.
|
||||
fromHeaders:
|
||||
- name: Authorization
|
||||
prefix: "Bearer "
|
||||
Reference in New Issue
Block a user