mirror of
https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git
synced 2026-08-21 11:36:50 +00:00
Remove all nessus references: ArgoCD project destination, Istio ambient enrollment, waypoint gateway, authorization policies, ext-authz policy, TLS certificate, ingress gateway host, Kyverno exclusion, and Authentik forward-auth blueprint. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
82 lines
3.4 KiB
YAML
82 lines
3.4 KiB
YAML
---
|
|
# Forward Auth Proxy Provider Blueprint for Authentik
|
|
#
|
|
# Replaces oauth2-proxy with Authentik's built-in forward-auth capability.
|
|
# Istio's ext_authz filter calls Authentik's /outpost.goauthentik.io/auth/nginx
|
|
# endpoint to authenticate requests to protected services.
|
|
#
|
|
# Services protected by this provider:
|
|
# - Prometheus, Ceph Dashboard, TeslaMate, ESPHome, Frigate, Kiali, Netbird
|
|
#
|
|
# Services with native OIDC are NOT included here (they handle auth themselves):
|
|
# - GitLab, ArgoCD, Grafana, n8n, Home Assistant, Rancher, Nextcloud
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: authentik-blueprints-forward-auth
|
|
namespace: authentik
|
|
labels:
|
|
goauthentik.io/blueprint: "true"
|
|
data:
|
|
forward-auth.yaml: |-
|
|
version: 1
|
|
metadata:
|
|
name: forward-auth-provider
|
|
entries:
|
|
# ================================================================
|
|
# Proxy Provider - Forward Auth (domain mode) for Istio ext_authz
|
|
# ================================================================
|
|
# forward_domain mode handles ALL subdomains of cookie_domain.
|
|
# The embedded outpost matches any *.kube.huskypup.net request.
|
|
# Auth session is shared across subdomains via a single cookie.
|
|
- model: authentik_providers_proxy.proxyprovider
|
|
id: forward-auth-provider
|
|
state: present
|
|
identifiers:
|
|
name: Forward Auth (Istio)
|
|
attrs:
|
|
name: Forward Auth (Istio)
|
|
authorization_flow: !Find [authentik_flows.flow, [slug, default-provider-authorization-implicit-consent]]
|
|
authentication_flow: !Find [authentik_flows.flow, [slug, default-authentication-flow]]
|
|
invalidation_flow: !Find [authentik_flows.flow, [slug, default-provider-invalidation-flow]]
|
|
mode: forward_domain
|
|
external_host: "https://auth.kube.huskypup.net"
|
|
cookie_domain: "kube.huskypup.net"
|
|
access_token_validity: "hours=1"
|
|
refresh_token_validity: "days=30"
|
|
property_mappings:
|
|
- !Find [authentik_providers_oauth2.scopemapping, [scope_name, openid]]
|
|
- !Find [authentik_providers_oauth2.scopemapping, [scope_name, email]]
|
|
- !Find [authentik_providers_oauth2.scopemapping, [scope_name, profile]]
|
|
|
|
# ================================================================
|
|
# Application - Umbrella app for all forward-auth protected services
|
|
# ================================================================
|
|
- model: authentik_core.application
|
|
id: forward-auth-application
|
|
state: present
|
|
identifiers:
|
|
slug: forward-auth
|
|
attrs:
|
|
name: Protected Services (Forward Auth)
|
|
slug: forward-auth
|
|
policy_engine_mode: any
|
|
provider: !KeyOf forward-auth-provider
|
|
|
|
# ================================================================
|
|
# Outpost - Embedded outpost for forward auth
|
|
# Uses Authentik's built-in outpost (no separate deployment needed)
|
|
# ================================================================
|
|
- model: authentik_outposts.outpost
|
|
id: forward-auth-outpost
|
|
state: present
|
|
identifiers:
|
|
name: "authentik Embedded Outpost"
|
|
attrs:
|
|
type: proxy
|
|
providers:
|
|
- !KeyOf forward-auth-provider
|
|
config:
|
|
authentik_host: "https://auth.kube.huskypup.net/"
|
|
authentik_host_insecure: true
|