Add kubeflow/v1.10.0

This commit is contained in:
wbsong111
2025-06-24 12:03:10 +09:00
parent 0132496142
commit 6e8dd89e48
1531 changed files with 120984 additions and 262120 deletions
@@ -0,0 +1,25 @@
apiVersion: security.istio.io/v1beta1
kind: AuthorizationPolicy
metadata:
name: istio-ingressgateway-oauth2-proxy
namespace: istio-system
spec:
action: CUSTOM
provider:
name: oauth2-proxy
selector:
matchLabels:
app: istio-ingressgateway
rules:
# We ONLY authenticate requests that DON'T have an `Authorization` header using oauth2-proxy.
# This is because we use RequestAuthentication to authenticate requests with an `Authorization` header.
- when:
- key: request.headers[authorization]
notValues: ["*"]
to:
- operation:
notPaths:
# Exclude dex paths, otherwise users won't be able to log in.
- /dex/*
- /dex/**
- /oauth2/*
@@ -0,0 +1,24 @@
apiVersion: security.istio.io/v1beta1
kind: AuthorizationPolicy
metadata:
name: istio-ingressgateway-require-jwt
namespace: istio-system
spec:
action: DENY
selector:
matchLabels:
app: istio-ingressgateway
rules:
# Deny requests that don't have a verified JWT (from a RequestAuthentication)
# Note, even user requests that have been authenticated by oauth2-proxy will have a JWT,
# because oauth2-proxy injects a Dex JWT into the request.
- from:
- source:
notRequestPrincipals: ["*"]
to:
- operation:
notPaths:
# Exclude dex paths, otherwise users won't be able to log in.
- /dex/*
- /dex/**
- /oauth2/*
@@ -0,0 +1,12 @@
apiVersion: kustomize.config.k8s.io/v1alpha1
kind: Component
resources:
- authorizationpolicy.istio-ingressgateway-oauth2-proxy.yaml
- authorizationpolicy.istio-ingressgateway-require-jwt.yaml
- requestauthentication.keycloak-jwt.yaml
# If want to enable caching for some paths (e.g. when using Cloudflare),
# use the following AuthorizationPolicies instead of the default ones.
#- authorizationpolicy.istio-ingressgateway-oauth2-proxy.cloudflare.yaml
#- authorizationpolicy.istio-ingressgateway-require-jwt.cloudflare.yaml
@@ -0,0 +1,25 @@
apiVersion: security.istio.io/v1beta1
kind: RequestAuthentication
metadata:
name: keycloak-jwt
namespace: istio-system
spec:
selector:
matchLabels:
app: istio-ingressgateway
jwtRules:
- # The `issuer` must be replaced with a Kustomize patch.
issuer: PATCH_ME
jwksUri: PATCH_ME
forwardOriginalToken: true
outputClaimToHeaders:
- header: kubeflow-userid
claim: email
- header: kubeflow-groups
claim: groups
- header: x-auth-request-user
claim: sub
fromHeaders:
- name: Authorization
prefix: "Bearer "