mirror of
https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git
synced 2026-08-21 05:26:49 +00:00
Initial commit
This commit is contained in:
@@ -0,0 +1,139 @@
|
||||
# ==========================================================================
|
||||
# Istio ext_authz Policies - Forward Auth via Authentik
|
||||
# ==========================================================================
|
||||
#
|
||||
# These policies protect services that don't have native OIDC integration.
|
||||
# Istio's ext_authz filter calls Authentik's forward-auth endpoint before
|
||||
# allowing traffic through.
|
||||
#
|
||||
# Services with native OIDC (GitLab, ArgoCD, Grafana, n8n, Home Assistant,
|
||||
# Rancher, Nextcloud) do NOT need ext_authz - they handle auth themselves.
|
||||
#
|
||||
# IMPORTANT: CUSTOM action does NOT support 'from' or source-based matching.
|
||||
# We use 'to.operation.hosts' to restrict to external hostnames only.
|
||||
# Internal service-to-service traffic uses k8s DNS names (*.svc.cluster.local)
|
||||
# which won't match, so it bypasses ext_authz and hits ALLOW policies instead.
|
||||
# ==========================================================================
|
||||
|
||||
# --- Prometheus: Require Authentik auth for browser access ---
|
||||
apiVersion: security.istio.io/v1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: ext-authz-prometheus
|
||||
namespace: prometheus
|
||||
spec:
|
||||
action: CUSTOM
|
||||
provider:
|
||||
name: authentik-ext-authz
|
||||
rules:
|
||||
- to:
|
||||
- operation:
|
||||
hosts:
|
||||
- prometheus.kube.huskypup.net
|
||||
paths:
|
||||
- /*
|
||||
---
|
||||
# --- TeslaMate: Require Authentik auth ---
|
||||
apiVersion: security.istio.io/v1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: ext-authz-teslamate
|
||||
namespace: teslamate
|
||||
spec:
|
||||
action: CUSTOM
|
||||
provider:
|
||||
name: authentik-ext-authz
|
||||
rules:
|
||||
- to:
|
||||
- operation:
|
||||
hosts:
|
||||
- teslamate.kube.huskypup.net
|
||||
---
|
||||
# --- ESPHome: Require Authentik auth ---
|
||||
apiVersion: security.istio.io/v1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: ext-authz-esphome
|
||||
namespace: home-assistant
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/name: esphome
|
||||
action: CUSTOM
|
||||
provider:
|
||||
name: authentik-ext-authz
|
||||
rules:
|
||||
- to:
|
||||
- operation:
|
||||
hosts:
|
||||
- esphome.kube.huskypup.net
|
||||
---
|
||||
# --- Kiali: Require Authentik auth ---
|
||||
apiVersion: security.istio.io/v1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: ext-authz-kiali
|
||||
namespace: istio-system
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/name: kiali
|
||||
action: CUSTOM
|
||||
provider:
|
||||
name: authentik-ext-authz
|
||||
rules:
|
||||
- to:
|
||||
- operation:
|
||||
hosts:
|
||||
- kiali.kube.huskypup.net
|
||||
---
|
||||
# --- Frigate: Require Authentik auth ---
|
||||
apiVersion: security.istio.io/v1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: ext-authz-frigate
|
||||
namespace: frigate
|
||||
spec:
|
||||
action: CUSTOM
|
||||
provider:
|
||||
name: authentik-ext-authz
|
||||
rules:
|
||||
- to:
|
||||
- operation:
|
||||
hosts:
|
||||
- frigate.kube.huskypup.net
|
||||
---
|
||||
# --- Scylla Manager: Require Authentik auth ---
|
||||
# NOTE: Namespace 'scylla-manager' must exist before applying this policy.
|
||||
apiVersion: security.istio.io/v1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: ext-authz-scylla-manager
|
||||
namespace: scylla-manager
|
||||
spec:
|
||||
action: CUSTOM
|
||||
provider:
|
||||
name: authentik-ext-authz
|
||||
rules:
|
||||
- to:
|
||||
- operation:
|
||||
hosts:
|
||||
- scylla-manager.kube.huskypup.net
|
||||
---
|
||||
# --- Nessus: Require Authentik auth ---
|
||||
# NOTE: Namespace 'nessus' must exist before applying this policy.
|
||||
# This policy will be skipped if the namespace doesn't exist yet.
|
||||
apiVersion: security.istio.io/v1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: ext-authz-nessus
|
||||
namespace: nessus
|
||||
spec:
|
||||
action: CUSTOM
|
||||
provider:
|
||||
name: authentik-ext-authz
|
||||
rules:
|
||||
- to:
|
||||
- operation:
|
||||
hosts:
|
||||
- nessus.kube.huskypup.net
|
||||
Reference in New Issue
Block a user