diff --git a/charts/incubator/authentik/Chart.yaml b/charts/incubator/authentik/Chart.yaml index 1b9659e4929..a6d8de2b7f4 100644 --- a/charts/incubator/authentik/Chart.yaml +++ b/charts/incubator/authentik/Chart.yaml @@ -1,5 +1,5 @@ apiVersion: v2 -appVersion: "2023.4.1" +appVersion: "2023.5.3" dependencies: - name: common repository: https://library-charts.truecharts.org @@ -8,7 +8,7 @@ dependencies: name: redis repository: https://deps.truecharts.org version: 6.0.58 -description: authentik is an open-source Identity Provider focused on flexibility and versatility. +description: Authentik is an open-source Identity Provider focused on flexibility and versatility. home: https://truecharts.org/charts/incubator/authentik icon: https://truecharts.org/img/hotlink-ok/chart-icons/authentik.png keywords: @@ -23,9 +23,8 @@ sources: - https://github.com/truecharts/charts/tree/master/charts/incubator/authentik - https://github.com/goauthentik/authentik - https://goauthentik.io/docs/ -version: 12.0.2 +version: 13.0.0 annotations: truecharts.org/catagories: | - authentication truecharts.org/SCALE-support: "true" - truecharts.org/grade: U diff --git a/charts/incubator/authentik/docs/installation_notes.md b/charts/incubator/authentik/docs/installation_notes.md index bbab5b73606..79f2d3d2771 100644 --- a/charts/incubator/authentik/docs/installation_notes.md +++ b/charts/incubator/authentik/docs/installation_notes.md @@ -6,23 +6,5 @@ Default username: `akadmin` ## Outposts -Enable each outpost by simple setting `enabled` to `true`. -Scale users, just have to check the checkbox - -> You have to create an outpost in the GUI first. -> And afterwards enable it. -> Applications > Outposts - -### Host - -`host` should not need to be overridden. Defaults to `https://localhost:9443` - -### Host Browser - -`host_browser` by default is set to the first ingress host you set - -### Token - -`token` is only needed if you accidentally deleted the bootstrap token within the UI. - -> You can get one from Applications > Outposts > View Deployment Info +You need to create an outpost in the GUI first. +Generate a token and then enable it. diff --git a/charts/incubator/authentik/questions.yaml b/charts/incubator/authentik/questions.yaml index df29aef736e..4136156a7d8 100644 --- a/charts/incubator/authentik/questions.yaml +++ b/charts/incubator/authentik/questions.yaml @@ -6,7 +6,6 @@ questions: # Include{global} # Include{workload} # Include{workloadDeployment} - # Include{replicas1} # Include{podSpec} # Include{containerMain} @@ -25,13 +24,26 @@ questions: additional_attrs: true type: dict attrs: + - variable: email + label: Email + description: | + Set the default email address for the akadmin user.
+ Only read on initial install, changing this will have no effect. + schema: + type: string + required: true + immutable: true + default: "" - variable: password - label: Password (Initial install only) - description: Password for user. Can be used for any flow executor + label: Password + description: | + Set the default password for the akadmin user.
+ Only read on initial install, changing this will have no effect. schema: type: string private: true required: true + immutable: true default: "" - variable: general label: General @@ -39,42 +51,49 @@ questions: additional_attrs: true type: dict attrs: - - variable: disable_update_check + - variable: disableUpdateCheck label: Disable Update Check description: Disable the inbuilt update-checker schema: type: boolean default: false - - variable: disable_startup_analytics + - variable: disableUpdateCheck label: Disable Startup Analytics description: Disable startup analytics schema: type: boolean default: true - - variable: allow_user_name_change - label: Allow User Name Change + - variable: allowUserChangeName + label: Allow User Change Name description: Enable the ability for users to change their Name schema: type: boolean default: true - - variable: allow_user_mail_change - label: Allow User Mail Change + - variable: allowUserChangeEmail + label: Allow User Change Mail description: Enable the ability for users to change their Email address schema: type: boolean default: true - - variable: allow_user_username_change - label: Allow User Username Change + - variable: allowUserChangeUsername + label: Allow User Change Username description: Enable the ability for users to change their Usernames schema: type: boolean default: true - - variable: gdpr_compliance + - variable: gdprCompliance label: GDPR Compliance description: When enabled, all the events caused by a user will be deleted upon the user's deletion schema: type: boolean default: true + - variable: tokenLength + label: Token Length + description: Configure the length of generated tokens + schema: + type: int + min: 60 + default: 128 - variable: impersonation label: Impersonation description: Globally enable / disable impersonation @@ -85,22 +104,49 @@ questions: label: Avatars description: Configure how authentik should show avatars for users schema: - type: string - default: gravatar,initials - - variable: token_length - label: Token Length - description: Configure the length of generated tokens - schema: - type: int - default: 128 - - variable: footer_links + type: list + default: + - gravatar + - initials + items: + - variable: avatar + label: Avatar + description: Avatar type + schema: + type: string + default: "" + required: true + - variable: footerLinks label: Footer Links description: This option configures the footer links on the flow executor pages schema: - type: string - default: "" - - variable: mail - label: e-Mail + type: list + default: + - name: Authentik + href: https://goauthentik.io + items: + - variable: footerLink + label: Footer Link + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: Name + description: Name of the link + schema: + type: string + default: "" + required: true + - variable: href + label: Href + description: URL of the link + schema: + type: string + default: "" + required: true + - variable: email + label: Email schema: additional_attrs: true type: dict @@ -116,16 +162,29 @@ questions: description: Sets port of mail server schema: type: int - default: 25 - - variable: tls + default: 587 + - variable: username + label: Username + description: Sets username of mail server + schema: + type: string + default: "" + - variable: password + label: Password + description: Sets password of mail server + schema: + type: string + private: true + default: "" + - variable: useTLS label: Use TLS for authentication - description: Sets tls for mail server authentication + description: Sets TLS for mail server authentication schema: type: boolean - default: false - - variable: ssl + default: true + - variable: useSSL label: Use SSL for authentication - description: Sets ssl for mail server authentication + description: Sets SSL for mail server authentication schema: type: boolean default: false @@ -135,51 +194,32 @@ questions: schema: type: int default: 10 - - variable: user - label: Username - description: Sets username of mail server - schema: - type: string - default: "" - - variable: pass - label: Password - description: Sets password of mail server - schema: - type: string - private: true - default: "" - variable: from label: From Address description: Email address authentik will send from schema: type: string default: "" - - variable: error_reporting - label: Error Reporting + - variable: ldap + label: LDAP schema: additional_attrs: true type: dict attrs: - - variable: enabled - label: Enable Reporting - description: Enables error reporting + - variable: tls_ciphers + label: TLS Ciphers + description: | + Allows configuration of TLS Ciphers for LDAP connections used by LDAP sources.
+ Setting applies to all sources schema: - type: boolean - default: false - show_subquestions_if: - subquestions: - - variable: send_pii - label: Send Personal Data - description: Whether or not to send personal data, like usernames - schema: - type: boolean - default: false - - variable: environment - label: Environment - description: Unique environment that is attached to your error reports, should be set to your email address for example. - schema: - type: string - default: customer + type: string + default: "null" + - variable: taskTimeoutHours + label: Task Timeout Hours + description: Timeout in hours for LDAP synchronization tasks + schema: + type: int + default: 2 - variable: logging label: Logging schema: @@ -203,235 +243,142 @@ questions: description: warning - value: error description: error - - variable: ldap - label: LDAP - schema: - additional_attrs: true - type: dict - attrs: - - variable: tls_ciphers - label: TLS Ciphers - description: Allows configuration of TLS Ciphers for LDAP connections used by LDAP sources. Setting applies to all sources - schema: - type: string - default: "null" - - variable: outposts - group: App Configuration - label: Outpost Configuration - schema: - additional_attrs: true - type: dict - attrs: - - variable: ldap - label: LDAP + - variable: error_reporting + label: Error Reporting schema: additional_attrs: true type: dict attrs: - variable: enabled - label: Enable LDAP outpost + label: Enable Reporting + description: Enables error reporting schema: type: boolean default: false - show_subquestions_if: true + show_subquestions_if: subquestions: - - variable: overrideHost - label: Override Host + - variable: sendPII + label: Send Personal Data + description: Whether or not to send personal data, like usernames schema: type: boolean default: false - show_subquestions_if: true - subquestions: - - variable: host - label: Authentik Host - description: "URL of your Authentik server. (e.g. https://auth.domain.com)" - schema: - type: string - # TODO: Make them required again once Scale stable supports nested subquestions - # required: true - default: "" - - variable: insecure - label: Insecure - description: Check only if you accessing Authentik in an unsecure way - schema: - type: boolean - default: false - - variable: overrideToken - label: Override Token - description: Overrides the random generated token to provide your own + - variable: environment + label: Environment + description: The environment tag associated with all data sent to Sentry schema: - type: boolean - default: false - show_subquestions_if: true - subquestions: - - variable: token - label: API Token - description: You can get this from Applications > Outposts > View Deployment Info - schema: - type: string - private: true - # TODO: Make them required again once Scale stable supports nested subquestions - # required: true - default: "" - - variable: overrideBrowserHost - label: Override Host Browser - description: Overrides the Browser Host, by default the first ingress host is used + type: string + default: customer + - variable: sentryDSN + label: Sentry DSN + description: Sets the DSN for the Sentry API endpoint. schema: - type: boolean - default: false - show_subquestions_if: true - subquestions: - - variable: host_browser - label: Host Browser - description: URL to use in the browser, when it differs from << host >> - schema: - type: string - # TODO: Make them required again once Scale stable supports nested subquestions - # required: true - default: "" - - variable: proxy - label: Proxy + type: string + private: true + default: "" + - variable: geoip + label: GeoIP schema: additional_attrs: true type: dict attrs: - variable: enabled - label: Enable Proxy outpost + label: Enabled + description: | + Enables and configures the GeoIP container.
+ This will deploy the GeoIP container. schema: type: boolean default: false show_subquestions_if: true subquestions: - - variable: overrideHost - label: Override Host + - variable: editionID + label: Edition ID + description: | + The edition ID of the database to download.
+ Only one seems to be supported by Authentik. + schema: + type: string + default: GeoLite2-City + - variable: frequency + label: Frequency + description: The number of hours between geoipupdate runs. + schema: + type: int + min: 1 + default: 8 + - variable: accountID + label: Account ID + description: Your MaxMind account ID + schema: + type: string + private: true + required: true + default: "" + - variable: licenseKey + label: License Key + description: Your MaxMind license key + schema: + type: string + private: true + required: true + default: "" + - variable: outposts + label: Outposts + schema: + additional_attrs: true + type: dict + attrs: + - variable: radius + label: Radius + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: Enabled + description: | + Enables and configures the Radius container.
+ This will deploy the Radius container. schema: type: boolean default: false show_subquestions_if: true subquestions: - - variable: host - label: Authentik Host - description: "URL of your Authentik server. (e.g. https://auth.domain.com)" + - variable: token + label: Token + description: | + The token used to authenticate with the authentik server. schema: type: string - # TODO: Make them required again once Scale stable supports nested subquestions - # required: true + private: true + required: true default: "" - - variable: insecure - label: Insecure - description: Check only if you accessing Authentik in an unsecure way + - variable: ldap + label: LDAP + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: Enabled + description: | + Enables and configures the LDAP container.
+ This will deploy the LDAP container. + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: token + label: Token + description: | + The token used to authenticate with the authentik server. schema: - type: boolean - default: false - - variable: overrideToken - label: Override Token - description: Overrides the random generated token to provide your own - schema: - type: boolean - default: false - show_subquestions_if: true - subquestions: - - variable: token - label: API Token - description: You can get this from Applications > Outposts > View Deployment Info - schema: - type: string - private: true - # TODO: Make them required again once Scale stable supports nested subquestions - # required: true - default: "" - - variable: overrideBrowserHost - label: Override Host Browser - description: Overrides the Browser Host, by default the first ingress host is used - schema: - type: boolean - default: false - show_subquestions_if: true - subquestions: - - variable: host_browser - label: Host Browser - description: URL to use in the browser, when it differs from << host >> - schema: - type: string - # TODO: Make them required again once Scale stable supports nested subquestions - # required: true - default: "" - - variable: geoip - group: App Configuration - label: GeoIP Configuration - schema: - additional_attrs: true - type: dict - attrs: - - variable: enabled - label: Enable GeoIP Container - description: Enables GeoIP container - schema: - type: boolean - default: false - show_subquestions_if: true - subquestions: - - variable: account_id - label: Account ID - description: Your MaxMind account ID - schema: - type: string - private: true - required: true - default: "" - - variable: license_key - label: License Key - description: Your case-sensitive MaxMind license key - schema: - type: string - private: true - required: true - default: "" - - variable: edition_ids - label: Edition IDs - description: List of space-separated database edition IDs. Edition IDs may consist of letters, digits, and dashes - schema: - type: string - required: true - default: GeoLite2-City - - variable: frequency - label: Frequency - description: The number of hours between geoipupdate runs - schema: - type: int - min: 1 - default: 8 - - variable: host_server - label: Host Server - description: The host name of the server to use - schema: - type: string - default: updates.maxmind.com - - variable: preserve_file_times - label: Preserve File Times - description: Whether to preserve modification times of files downloaded from the server - schema: - type: boolean - default: false - - variable: verbose - label: Verbose - description: Enable verbose mode. Prints out the steps that geoipupdate takes - schema: - type: boolean - default: false - - variable: proxy - label: Proxy - description: The proxy host name or IP address - schema: - type: string - default: "" - - variable: proxy_user_pass - label: Proxy Pass - description: The proxy user name and password, separated by a colon - schema: - type: string - private: true - default: "" + type: string + private: true + required: true + default: "" # Include{containerConfig} # Include{podOptions} # Include{serviceRoot} @@ -457,17 +404,17 @@ questions: type: int default: 10229 required: true - - variable: ldapldaps - label: LDAPS Service - description: The LDAPS service. + - variable: radius + label: RADIUS Service + description: The RADIUS service. schema: additional_attrs: true type: dict attrs: # Include{serviceSelectorLoadBalancer} # Include{serviceSelectorExtras} - - variable: ldapldaps - label: LDAPS Service Port Configuration + - variable: radius + label: RADIUS Service Port Configuration schema: additional_attrs: true type: dict @@ -477,18 +424,18 @@ questions: description: This port exposes the container port on the service schema: type: int - default: 636 + default: 1812 required: true - - variable: ldapldap + - variable: ldap label: LDAP Service - description: The LDAPS service. + description: The LDAP service. schema: additional_attrs: true type: dict attrs: # Include{serviceSelectorLoadBalancer} # Include{serviceSelectorExtras} - - variable: ldapldap + - variable: ldap label: LDAP Service Port Configuration schema: additional_attrs: true @@ -501,17 +448,17 @@ questions: type: int default: 389 required: true - - variable: proxyhttps - label: Proxy HTTPS Service - description: The Proxy HTTPS service. + - variable: ldaps + label: LDAPS Service + description: The LDAPS service. schema: additional_attrs: true type: dict attrs: # Include{serviceSelectorLoadBalancer} # Include{serviceSelectorExtras} - - variable: proxyhttps - label: Proxy HTTPS Service Port Configuration + - variable: ldaps + label: LDAPS Service Port Configuration schema: additional_attrs: true type: dict @@ -521,7 +468,7 @@ questions: description: This port exposes the container port on the service schema: type: int - default: 10233 + default: 636 required: true # Include{serviceExpertRoot} # Include{serviceExpert} @@ -542,6 +489,14 @@ questions: additional_attrs: true type: dict attrs: +# Include{persistenceBasic} + - variable: blueprints + label: App Blueprints Storage + description: Stores the Application Blueprints. + schema: + additional_attrs: true + type: dict + attrs: # Include{persistenceBasic} - variable: certs label: App Certs Storage @@ -570,29 +525,18 @@ questions: # Include{ingressDefault} # Include{ingressTLS} # Include{ingressTraefik} -# Include{ingressAdvanced} - - variable: proxyhttps - label: Proxy HTTPS Ingress - schema: - additional_attrs: true - type: dict - attrs: -# Include{ingressDefault} -# Include{ingressTLS} -# Include{ingressTraefik} # Include{ingressAdvanced} # Include{ingressList} # Include{securityContextRoot} - - variable: runAsUser - label: "runAsUser" - description: "The UserID of the user running the application" + label: runAsUser + description: The UserID of the user running the application schema: type: int default: 1000 - variable: runAsGroup - label: "runAsGroup" - description: "The groupID of the user running the application" + label: runAsGroup + description: The groupID of the user running the application schema: type: int default: 1000 @@ -600,12 +544,11 @@ questions: # Include{securityContextAdvanced} # Include{securityContextPod} - variable: fsGroup - label: "fsGroup" - description: "The group that should own ALL storage." + label: fsGroup + description: The group that should own ALL storage. schema: type: int default: 568 - # Include{resources} # Include{metrics} # Include{prometheusRule} diff --git a/charts/incubator/authentik/templates/_config.tpl b/charts/incubator/authentik/templates/_config.tpl index 04b8874a8f3..ee064a093c0 100644 --- a/charts/incubator/authentik/templates/_config.tpl +++ b/charts/incubator/authentik/templates/_config.tpl @@ -1,118 +1,109 @@ {{/* Define the configmaps */}} {{- define "authentik.configmaps" -}} -{{- $authServerWorkerConfigName := printf "%s-authentik-config" (include "tc.v1.common.lib.chart.names.fullname" .) }} -{{- $authServerConfigName := printf "%s-authentik-server-config" (include "tc.v1.common.lib.chart.names.fullname" .) }} -{{- $geoipConfigName := printf "%s-geoip-config" (include "tc.v1.common.lib.chart.names.fullname" .) }} -{{- $ldapConfigName := printf "%s-ldap-config" (include "tc.v1.common.lib.chart.names.fullname" .) }} -{{- $proxyConfigName := printf "%s-proxy-config" (include "tc.v1.common.lib.chart.names.fullname" .) }} + {{- $fullname := include "tc.v1.common.lib.chart.names.fullname" $ -}} + {{- $host := .Values.chartContext.APPURL }} +server: + enabled: true + data: + AUTHENTIK_LISTEN__HTTPS: {{ printf "0.0.0.0:%v" .Values.service.main.ports.main.port | quote }} + AUTHENTIK_LISTEN__HTTP: {{ printf "0.0.0.0:%v" .Values.service.http.ports.http.port | quote }} + AUTHENTIK_LISTEN__METRICS: {{ printf "0.0.0.0:%v" .Values.service.servermetrics.ports.servermetrics.port | quote }} -{{ $host := printf "https://localhost:%v" .Values.service.main.ports.main.targetPort }} -{{- if .Values.ingress.main.enabled }} - {{ $first := (first .Values.ingress.main.hosts) }} - {{- if $first }} - {{ $host = printf "https://%s" $first.host }} - {{- end }} -{{- end }} - -{{/* This configmap is loaded in both the main authentik container and worker */}} -{{ $authServerWorkerConfigName }}: +server-worker: enabled: true data: {{/* Dependencies */}} - AUTHENTIK_REDIS__HOST: {{ .Values.redis.creds.plain }} - {{- with $redis := .Values.redisProvider }} - AUTHENTIK_REDIS__PORT: {{ default 6379 $redis.port | quote }} - {{- end }} AUTHENTIK_POSTGRESQL__NAME: {{ .Values.cnpg.main.database }} AUTHENTIK_POSTGRESQL__USER: {{ .Values.cnpg.main.user }} AUTHENTIK_POSTGRESQL__HOST: {{ .Values.cnpg.main.creds.host }} - {{- with $cnpg := .Values.cnpgProvider }} - AUTHENTIK_POSTGRESQL__PORT: {{ default 5432 $cnpg.port | quote }} - {{- end }} - {{/* Mail */}} - {{- with .Values.authentik.mail.port }} - AUTHENTIK_EMAIL__PORT: {{ . | quote }} - {{- end }} - AUTHENTIK_EMAIL__USE_TLS: {{ .Values.authentik.mail.tls | quote }} - AUTHENTIK_EMAIL__USE_SSL: {{ .Values.authentik.mail.ssl | quote }} - {{- with .Values.authentik.mail.timeout }} - AUTHENTIK_EMAIL__TIMEOUT: {{ . | quote }} - {{- end }} - {{/* Logging */}} - {{- with .Values.authentik.logging.log_level }} - AUTHENTIK_LOG_LEVEL: {{ . }} - {{- end }} - {{/* General */}} - AUTHENTIK_DISABLE_STARTUP_ANALYTICS: {{ .Values.authentik.general.disable_startup_analytics | quote }} - AUTHENTIK_DISABLE_UPDATE_CHECK: {{ .Values.authentik.general.disable_update_check | quote }} - {{- with .Values.authentik.general.avatars }} - AUTHENTIK_AVATARS: {{ . }} - {{- end }} - AUTHENTIK_DEFAULT_USER_CHANGE_NAME: {{ .Values.authentik.general.allow_user_name_change | quote }} - AUTHENTIK_DEFAULT_USER_CHANGE_EMAIL: {{ .Values.authentik.general.allow_user_mail_change | quote }} - AUTHENTIK_DEFAULT_USER_CHANGE_USERNAME: {{ .Values.authentik.general.allow_user_username_change | quote }} - AUTHENTIK_GDPR_COMPLIANCE: {{ .Values.authentik.general.gdpr_compliance | quote }} - AUTHENTIK_IMPERSONATION: {{ .Values.authentik.general.impersonation | quote }} - AUTHENTIK_DEFAULT_TOKEN_LENGTH: {{ .Values.authentik.general.token_length | quote }} - {{- with .Values.authentik.general.footer_links }} - AUTHENTIK_FOOTER_LINKS: {{ . | squote }} - {{- end }} - {{/* Error Reporting */}} - AUTHENTIK_ERROR_REPORTING__ENABLED: {{ .Values.authentik.error_reporting.enabled | quote }} - AUTHENTIK_ERROR_REPORTING__SEND_PII: {{ .Values.authentik.error_reporting.send_pii | quote }} - {{- with .Values.authentik.error_reporting.environment }} - AUTHENTIK_ERROR_REPORTING__ENVIRONMENT: {{ . }} - {{- end }} - {{/* LDAP */}} - {{- with .Values.authentik.ldap.tls_ciphers }} - AUTHENTIK_LDAP__TLS__CIPHERS: {{ . | quote }} - {{- end }} - {{/* Outposts */}} - AUTHENTIK_OUTPOSTS__DISCOVER: {{ "false" | quote }} + AUTHENTIK_POSTGRESQL__PORT: "5432" + AUTHENTIK_REDIS__HOST: {{ .Values.redis.creds.plain }} + AUTHENTIK_REDIS__PORT: "6379" -{{/* This configmap is loaded in both the main authentik container and worker */}} -{{ $authServerConfigName }}: + {{/* Outposts */}} + AUTHENTIK_OUTPOSTS__DISCOVER: "false" + + {{/* GeoIP */}} + {{- $geoipPath := (printf "/geoip/%v.mmdb" .Values.authentik.geoip.editionID) -}} + {{- if not .Values.authentik.geoip.enabled -}} + {{- $geoipPath = "/tmp/non-existent-file" -}} + {{- end }} + AUTHENTIK_GEOIP: {{ $geoipPath }} + + {{/* Mail */}} + AUTHENTIK_EMAIL__USE_TLS: {{ .Values.authentik.email.useTLS | quote }} + AUTHENTIK_EMAIL__USE_SSL: {{ .Values.authentik.email.useSSL | quote }} + {{- with .Values.authentik.email.port }} + AUTHENTIK_EMAIL__PORT: {{ . | quote }} + {{- end -}} + {{- with .Values.authentik.email.timeout }} + AUTHENTIK_EMAIL__TIMEOUT: {{ . | quote }} + {{- end -}} + + {{/* LDAP */}} + AUTHENTIK_LDAP__TASK_TIMEOUT_HOURS: {{ .Values.authentik.ldap.taskTimeoutHours | quote }} + AUTHENTIK_LDAP__TLS__CIPHERS: {{ .Values.authentik.ldap.tlsCiphers | quote }} + + {{/* Logging */}} + AUTHENTIK_LOG_LEVEL: {{ .Values.authentik.logging.logLevel }} + + {{/* Error Reporting */}} + AUTHENTIK_ERROR_REPORTING__ENABLED: {{ .Values.authentik.errorReporting.enabled | quote }} + AUTHENTIK_ERROR_REPORTING__SEND_PII: {{ .Values.authentik.errorReporting.sendPII | quote }} + {{- with .Values.authentik.errorReporting.environment }} + AUTHENTIK_ERROR_REPORTING__ENVIRONMENT: {{ . | quote }} + {{- end -}} + {{- with .Values.authentik.errorReporting.sentryDSN }} + AUTHENTIK_ERROR_REPORTING__SENTRY_DSN: {{ . | quote }} + {{- end -}} + {{- with .Values.authentik.general.avatars }} + AUTHENTIK_AVATARS: {{ join "," . }} + {{- end -}} + {{- with .Values.authentik.general.footerLinks }} + AUTHENTIK_FOOTER_LINKS: {{ toJson . | squote }} + {{- end -}} + + {{/* General */}} + AUTHENTIK_DISABLE_UPDATE_CHECK: {{ .Values.authentik.general.disableUpdateCheck | quote }} + AUTHENTIK_DISABLE_STARTUP_ANALYTICS: {{ .Values.authentik.general.disableStartupAnalytics | quote }} + AUTHENTIK_DEFAULT_USER_CHANGE_NAME: {{ .Values.authentik.general.allowUserChangeName | quote }} + AUTHENTIK_DEFAULT_USER_CHANGE_EMAIL: {{ .Values.authentik.general.allowUserChangeEmail | quote }} + AUTHENTIK_DEFAULT_USER_CHANGE_USERNAME: {{ .Values.authentik.general.allowUserChangeUsername | quote }} + AUTHENTIK_GDPR_COMPLIANCE: {{ .Values.authentik.general.gdprCompliance | quote }} + AUTHENTIK_DEFAULT_TOKEN_LENGTH: {{ .Values.authentik.general.tokenLength | quote }} + AUTHENTIK_IMPERSONATION: {{ .Values.authentik.general.impersonation | quote }} + +{{- if .Values.authentik.outposts.radius.enabled }} +radius: enabled: true data: - {{/* Listen */}} - AUTHENTIK_LISTEN__HTTPS: 0.0.0.0:{{ .Values.service.main.ports.main.targetPort | default 9443 }} - AUTHENTIK_LISTEN__HTTP: 0.0.0.0:{{ .Values.service.http.ports.http.targetPort | default 9000 }} - AUTHENTIK_LISTEN__METRICS: 0.0.0.0:{{ .Values.service.metrics.ports.metrics.targetPort | default 9301 }} - -{{/* This configmap is loaded in the geoip container */}} -{{ $geoipConfigName }}: - enabled: {{ .Values.geoip.enabled }} - data: - {{- with .Values.geoip.edition_ids }} - GEOIPUPDATE_EDITION_IDS: {{ . }} - {{- end }} - GEOIPUPDATE_FREQUENCY: {{ .Values.geoip.frequency | quote }} - {{- with .Values.geoip.host_server }} - GEOIPUPDATE_HOST: {{ . }} - {{- end }} - GEOIPUPDATE_PRESERVE_FILE_TIMES: {{ ternary "1" "0" .Values.geoip.preserve_file_times | quote }} - GEOIPUPDATE_VERBOSE: {{ ternary "1" "0" .Values.geoip.verbose | quote }} - -{{/* This configmap is loaded in the ldap container */}} -{{ $ldapConfigName }}: - enabled: {{ .Values.outposts.ldap.enabled }} - data: - AUTHENTIK_INSECURE: {{ .Values.outposts.ldap.insecure | default "true" | quote }} - AUTHENTIK_HOST: {{ .Values.outposts.ldap.host | default (printf "https://localhost:%v" .Values.service.main.ports.main.targetPort) }} - AUTHENTIK_HOST_BROWSER: {{ .Values.outposts.ldap.host_browser | default $host }} - AUTHENTIK_LISTEN__LDAPS: 0.0.0.0:{{ .Values.service.ldapldaps.ports.ldapldaps.targetPort | default 6636 }} - AUTHENTIK_LISTEN__LDAP: 0.0.0.0:{{ .Values.service.ldapldap.ports.ldapldap.targetPort | default 3389 }} - AUTHENTIK_LISTEN__METRICS: 0.0.0.0:{{ .Values.service.ldapmetrics.ports.ldapmetrics.targetPort | default 9302 }} - -{{/* This configmap is loaded in the proxy container */}} -{{ $proxyConfigName }}: - enabled: {{ .Values.outposts.proxy.enabled }} - data: - AUTHENTIK_INSECURE: {{ .Values.outposts.proxy.insecure | default "true" | quote }} - AUTHENTIK_HOST: {{ .Values.outposts.proxy.host | default (printf "https://localhost:%v" .Values.service.main.ports.main.targetPort) }} - AUTHENTIK_HOST_BROWSER: {{ .Values.outposts.proxy.host_browser | default $host }} - AUTHENTIK_LISTEN__HTTPS: 0.0.0.0:{{ .Values.service.proxyhttps.ports.proxyhttps.targetPort | default 9444 }} - AUTHENTIK_LISTEN__HTTP: 0.0.0.0:{{ .Values.service.proxyhttp.ports.proxyhttp.targetPort | default 9001 }} - AUTHENTIK_LISTEN__METRICS: 0.0.0.0:{{ .Values.service.proxymetrics.ports.proxymetrics.targetPort | default 9303 }} + AUTHENTIK_LISTEN__RADIUS: {{ printf "0.0.0.0:%v" .Values.service.radius.ports.radius.port | quote }} + AUTHENTIK_LISTEN__METRICS: {{ printf "0.0.0.0:%v" .Values.service.radiusmetrics.ports.radiusmetrics.port | quote }} + AUTHENTIK_HOST: {{ printf "https://%v:%v" $fullname .Values.service.main.ports.main.port }} + AUTHENTIK_INSECURE: "true" + # TODO: node ip or ingress host + AUTHENTIK_HOST_BROWSER: {{ $host }} +{{- end -}} + +{{- if .Values.authentik.outposts.ldap.enabled }} +ldap: + enabled: true + data: + AUTHENTIK_LISTEN__LDAP: {{ printf "0.0.0.0:%v" .Values.service.ldap.ports.ldap.port | quote }} + AUTHENTIK_LISTEN__LDAPS: {{ printf "0.0.0.0:%v" .Values.service.ldaps.ports.ldaps.port | quote }} + AUTHENTIK_LISTEN__METRICS: {{ printf "0.0.0.0:%v" .Values.service.ldapmetrics.ports.ldapmetrics.port | quote }} + AUTHENTIK_HOST: {{ printf "https://%v:%v" $fullname .Values.service.main.ports.main.port }} + AUTHENTIK_INSECURE: "true" + # TODO: node ip or ingress host + AUTHENTIK_HOST_BROWSER: {{ $host }} +{{- end -}} + +{{- if .Values.authentik.geoip.enabled }} +geoip: + enabled: true + data: + GEOIPUPDATE_EDITION_IDS: {{ .Values.authentik.geoip.editionID }} + GEOIPUPDATE_FREQUENCY: {{ .Values.authentik.geoip.frequency | quote }} +{{- end -}} {{- end -}} diff --git a/charts/incubator/authentik/templates/_geoip.tpl b/charts/incubator/authentik/templates/_geoip.tpl deleted file mode 100644 index aa7032d9e38..00000000000 --- a/charts/incubator/authentik/templates/_geoip.tpl +++ /dev/null @@ -1,23 +0,0 @@ -{{/* Define the geoip container */}} -{{- define "authentik.geoip.container" -}} -enabled: true -primary: false -imageSelector: geoipImage -securityContext: - runAsUser: 0 - runAsGroup: 0 -envFrom: - - secretRef: - name: '{{ include "tc.v1.common.lib.chart.names.fullname" . }}-geoip-secret' - - configMapRef: - name: '{{ include "tc.v1.common.lib.chart.names.fullname" . }}-geoip-config' -{{/* TODO: Add healthchecks */}} -{{/* TODO: https://github.com/maxmind/geoipupdate/issues/105 */}} -probes: - readiness: - enabled: false - liveness: - enabled: false - startup: - enabled: false -{{- end -}} diff --git a/charts/incubator/authentik/templates/_ldap.tpl b/charts/incubator/authentik/templates/_ldap.tpl deleted file mode 100644 index b54a71c7674..00000000000 --- a/charts/incubator/authentik/templates/_ldap.tpl +++ /dev/null @@ -1,39 +0,0 @@ -{{/* Define the ldap container */}} -{{- define "authentik.ldap.container" -}} -enabled: true -primary: false -imageSelector: ldapImage -securityContext: - readOnlyRootFilesystem: true - runAsNonRoot: true -envFrom: - - secretRef: - name: '{{ include "tc.v1.common.lib.chart.names.fullname" . }}-ldap-secret' - - configMapRef: - name: '{{ include "tc.v1.common.lib.chart.names.fullname" . }}-ldap-config' -ports: - - containerPort: {{ .Values.service.ldapldaps.ports.ldapldaps.targetPort }} - name: ldapldaps - - containerPort: {{ .Values.service.ldapldap.ports.ldapldap.targetPort }} - name: ldapldap -{{- if .Values.metrics.enabled }} - - containerPort: {{ .Values.service.ldapmetrics.ports.ldapmetrics.targetPort }} - name: ldapmetrics -{{- end }} -probes: - readiness: - enabled: true - type: {{ .Values.service.ldapmetrics.ports.ldapmetrics.protocol }} - path: /outpost.goauthentik.io/ping - port: {{ .Values.service.ldapmetrics.ports.ldapmetrics.targetPort }} - liveness: - enabled: true - type: {{ .Values.service.ldapmetrics.ports.ldapmetrics.protocol }} - path: /outpost.goauthentik.io/ping - port: {{ .Values.service.ldapmetrics.ports.ldapmetrics.targetPort }} - startup: - enabled: true - type: {{ .Values.service.ldapmetrics.ports.ldapmetrics.protocol }} - path: /outpost.goauthentik.io/ping - port: {{ .Values.service.ldapmetrics.ports.ldapmetrics.targetPort }} -{{- end -}} diff --git a/charts/incubator/authentik/templates/_proxy.tpl b/charts/incubator/authentik/templates/_proxy.tpl deleted file mode 100644 index 911c571403a..00000000000 --- a/charts/incubator/authentik/templates/_proxy.tpl +++ /dev/null @@ -1,39 +0,0 @@ -{{/* Define the proxy container */}} -{{- define "authentik.proxy.container" -}} -enabled: true -primary: false -imageSelector: proxyImage -securityContext: - readOnlyRootFilesystem: true - runAsNonRoot: true -envFrom: - - secretRef: - name: '{{ include "tc.v1.common.lib.chart.names.fullname" . }}-proxy-secret' - - configMapRef: - name: '{{ include "tc.v1.common.lib.chart.names.fullname" . }}-proxy-config' -ports: - - containerPort: {{ .Values.service.proxyhttps.ports.proxyhttps.targetPort }} - name: proxyhttps - - containerPort: {{ .Values.service.proxyhttp.ports.proxyhttp.targetPort }} - name: proxyhttp -{{- if .Values.metrics.enabled }} - - containerPort: {{ .Values.service.proxymetrics.ports.proxymetrics.targetPort }} - name: proxymetrics -{{- end }} -probes: - readiness: - enabled: true - type: {{ .Values.service.proxymetrics.ports.proxymetrics.protocol }} - path: /outpost.goauthentik.io/ping - port: {{ .Values.service.proxymetrics.ports.proxymetrics.targetPort }} - liveness: - enabled: true - type: {{ .Values.service.proxymetrics.ports.proxymetrics.protocol }} - path: /outpost.goauthentik.io/ping - port: {{ .Values.service.proxymetrics.ports.proxymetrics.targetPort }} - startup: - enabled: true - type: {{ .Values.service.proxymetrics.ports.proxymetrics.protocol }} - path: /outpost.goauthentik.io/ping - port: {{ .Values.service.proxymetrics.ports.proxymetrics.targetPort }} -{{- end -}} diff --git a/charts/incubator/authentik/templates/_secret.tpl b/charts/incubator/authentik/templates/_secret.tpl index 3f4b1957b86..5d9a90763ec 100644 --- a/charts/incubator/authentik/templates/_secret.tpl +++ b/charts/incubator/authentik/templates/_secret.tpl @@ -1,81 +1,63 @@ {{/* Define the secrets */}} {{- define "authentik.secrets" -}} -{{- $authentikSecretName := printf "%s-authentik-secret" (include "tc.v1.common.lib.chart.names.fullname" .) }} -{{- $geoipSecretName := printf "%s-geoip-secret" (include "tc.v1.common.lib.chart.names.fullname" .) }} -{{- $ldapSecretName := printf "%s-ldap-secret" (include "tc.v1.common.lib.chart.names.fullname" .) }} -{{- $proxySecretName := printf "%s-proxy-secret" (include "tc.v1.common.lib.chart.names.fullname" .) }} -{{- $token := randAlphaNum 128 }} + {{- $fullname := include "tc.v1.common.lib.chart.names.fullname" $ -}} + {{- $fetchname := printf "%v-server-worker" $fullname -}} -{{/* This secret is loaded in both the main authentik container and worker */}} -{{ $authentikSecretName }}: + {{- $secretKey := randAlphaNum 32 -}} + {{- with (lookup "v1" "Secret" .Release.Namespace $fetchname) -}} + {{ $secretKey = index .data "AUTHENTIK_SECRET_KEY" }} + {{- end }} + +server-worker: enabled: true data: - {{/* Secret Key */}} - {{- with (lookup "v1" "Secret" .Release.Namespace $authentikSecretName) }} - AUTHENTIK_SECRET_KEY: {{ index .data "AUTHENTIK_SECRET_KEY" }} - {{ $token = index .data "AUTHENTIK_BOOTSTRAP_TOKEN" }} - {{- else }} - AUTHENTIK_SECRET_KEY: {{ randAlphaNum 32 }} - {{- end }} - AUTHENTIK_BOOTSTRAP_TOKEN: {{ $token }} {{/* Dependencies */}} AUTHENTIK_POSTGRESQL__PASSWORD: {{ .Values.cnpg.main.creds.password | trimAll "\"" }} AUTHENTIK_REDIS__PASSWORD: {{ .Values.redis.creds.redisPassword | trimAll "\"" }} - {{/* Credentials */}} - {{- with .Values.authentik.credentials.password }} - AUTHENTIK_BOOTSTRAP_PASSWORD: {{ . }} - {{- end }} + + {{/* Secret Key */}} + AUTHENTIK_SECRET_KEY: {{ $secretKey }} + + {{/* Initial credentials */}} + AUTHENTIK_BOOTSTRAP_EMAIL: {{ .Values.authentik.credentials.email | quote }} + AUTHENTIK_BOOTSTRAP_PASSWORD: {{ .Values.authentik.credentials.password | quote }} + {{/* Mail */}} - {{- with .Values.authentik.mail.host }} + {{- with .Values.authentik.email.host }} AUTHENTIK_EMAIL__HOST: {{ . }} - {{- end }} - {{- with .Values.authentik.mail.user }} + {{- end -}} + {{- with .Values.authentik.email.user }} AUTHENTIK_EMAIL__USERNAME: {{ . }} - {{- end }} - {{- with .Values.authentik.mail.pass }} + {{- end -}} + {{- with .Values.authentik.email.pass }} AUTHENTIK_EMAIL__PASSWORD: {{ . }} - {{- end }} - {{- with .Values.authentik.mail.from }} + {{- end -}} + {{- with .Values.authentik.email.from }} AUTHENTIK_EMAIL__FROM: {{ . }} {{- end }} -{{/* This secret is loaded in the geoip container */}} -{{ $geoipSecretName }}: - enabled: {{ .Values.geoip.enabled }} +{{- if .Values.authentik.geoip.enabled }} +geoip: + enabled: true data: - {{/* Credentials */}} - {{- with .Values.geoip.account_id }} - GEOIPUPDATE_ACCOUNT_ID: {{ . }} - {{- end }} - {{- with .Values.geoip.license_key }} - GEOIPUPDATE_LICENSE_KEY: {{ . }} - {{- end }} - {{/* Proxy */}} - {{- with .Values.geoip.proxy }} - GEOIPUPDATE_PROXY: {{ . }} - {{- end }} - {{- with .Values.geoip.proxy_user_pass }} - GEOIPUPDATE_PROXY_USER_PASSWORD: {{ . }} - {{- end }} + GEOIPUPDATE_VERBOSE: "0" + GEOIPUPDATE_PRESERVE_FILE_TIMES: "1" + GEOIPUPDATE_ACCOUNT_ID: {{ .Values.authentik.geoip.accountID | quote }} + GEOIPUPDATE_LICENSE_KEY: {{ .Values.authentik.geoip.licenseKey | quote }} +{{- end -}} -{{/* This secret is loaded in the ldap container */}} -{{ $ldapSecretName }}: - enabled: {{ .Values.outposts.ldap.enabled }} +{{- if .Values.authentik.outposts.radius.enabled }} +radius: + enabled: true data: - {{- with .Values.outposts.ldap.token }} - AUTHENTIK_TOKEN: {{ . }} - {{- else }} - AUTHENTIK_TOKEN: {{ $token }} - {{- end }} + AUTHENTIK_TOKEN: {{ .Values.authentik.outposts.radius.token | quote }} +{{- end -}} -{{/* This secret is loaded in the proxy container */}} -{{ $proxySecretName }}: - enabled: {{ .Values.outposts.proxy.enabled }} +{{- if .Values.authentik.outposts.ldap.enabled }} +ldap: + enabled: true data: - {{- with .Values.outposts.proxy.token }} - AUTHENTIK_TOKEN: {{ . }} - {{- else }} - AUTHENTIK_TOKEN: {{ $token }} - {{- end }} -{{- end }} + AUTHENTIK_TOKEN: {{ .Values.authentik.outposts.ldap.token | quote }} +{{- end -}} +{{- end -}} diff --git a/charts/incubator/authentik/templates/_validation.tpl b/charts/incubator/authentik/templates/_validation.tpl new file mode 100644 index 00000000000..28cf1ba2780 --- /dev/null +++ b/charts/incubator/authentik/templates/_validation.tpl @@ -0,0 +1,21 @@ +{{- define "authentik.validation" -}} + {{- range $outpost, $values := .Values.authentik.outposts -}} + {{- if and $values.enabled (not $values.token) -}} + {{- fail (printf "Authentik - Outpost [%v] is enabled, but [token] was not provided" ($outpost | upper)) -}} + {{- end -}} + {{- end -}} + + {{- if .Values.authentik.geoip.enabled -}} + {{- if not .Values.authentik.geoip.accountID -}} + {{- fail "Authentik - GeoIP is enabled but [accountID] was not provided" -}} + {{- end -}} + + {{- if not .Values.authentik.geoip.licenseKey -}} + {{- fail "Authentik - GeoIP is enabled but [licenseKey] was not provided" -}} + {{- end -}} + + {{- if contains " " .Values.authentik.geoip.editionID -}} + {{- fail "Authentik - GeoIP is enabled but [editionID] cannot contain spaces" -}} + {{- end -}} + {{- end -}} +{{- end -}} diff --git a/charts/incubator/authentik/templates/_worker.tpl b/charts/incubator/authentik/templates/_worker.tpl deleted file mode 100644 index 28457cb2b33..00000000000 --- a/charts/incubator/authentik/templates/_worker.tpl +++ /dev/null @@ -1,31 +0,0 @@ -{{/* Define the worker container */}} -{{- define "authentik.worker.container" -}} -enabled: true -primary: false -imageSelector: image -args: ["worker"] -envFrom: - - secretRef: - name: '{{ include "tc.v1.common.lib.chart.names.fullname" . }}-authentik-secret' - - configMapRef: - name: '{{ include "tc.v1.common.lib.chart.names.fullname" . }}-authentik-config' -probes: - readiness: - enabled: true - type: exec - command: - - /lifecycle/ak - - healthcheck - liveness: - enabled: true - type: exec - command: - - /lifecycle/ak - - healthcheck - startup: - enabled: true - type: exec - command: - - /lifecycle/ak - - healthcheck -{{- end -}} diff --git a/charts/incubator/authentik/templates/common.yaml b/charts/incubator/authentik/templates/common.yaml index 6e93d973082..6a7dcff49ce 100644 --- a/charts/incubator/authentik/templates/common.yaml +++ b/charts/incubator/authentik/templates/common.yaml @@ -1,46 +1,62 @@ {{/* Make sure all variables are set properly */}} {{- include "tc.v1.common.loader.init" . }} +{{- include "authentik.validation" $ -}} + {{/* Render secrets for authentik and friends */}} -{{- $authentikSecrets := include "authentik.secrets" . | fromYaml -}} -{{- if $authentikSecrets -}} - {{ $secrets := (mustMerge $.Values.secret $authentikSecrets) }} +{{- $secrets := include "authentik.secrets" . | fromYaml -}} +{{- if $secrets -}} + {{ $secrets := (mustMergeOverwrite .Values.secret $secrets) }} {{- $_ := set .Values "secret" $secrets -}} {{- end -}} {{/* Render configmaps for authentik and friends */}} -{{- $authentikConfigmaps := include "authentik.configmaps" . | fromYaml -}} -{{- if $authentikConfigmaps -}} - {{ $configmaps := (mustMerge $.Values.configmap $authentikConfigmaps) }} +{{- $configmaps := include "authentik.configmaps" . | fromYaml -}} +{{- if $configmaps -}} + {{ $configmaps := (mustMergeOverwrite .Values.configmap $configmaps) }} {{- $_ := set .Values "configmap" $configmaps -}} {{- end -}} - -{{- if .Values.workerContainer.enabled -}} -{{- $_ := set .Values.workload.main.podSpec.containers "worker" (include "authentik.worker.container" . | fromYaml) -}} +{{- if .Values.authentik.geoip.enabled -}} + {{- $_ := set .Values.workload.geoip "enabled" true -}} +{{- else -}} + {{- $_ := set .Values.workload.geoip "enabled" false -}} {{- end -}} -{{- if .Values.geoip.enabled -}} -{{- $_ := set .Values.workload.main.podSpec.containers "geoip" (include "authentik.geoip.container" . | fromYaml) -}} +{{- if .Values.authentik.outposts.radius.enabled -}} + {{- $_ := set .Values.workload.radius "enabled" true -}} + {{- $_ := set .Values.service.radius "enabled" true -}} + {{- $_ := set .Values.service.radiusmetrics "enabled" true -}} + {{- $_ := set .Values.metrics.radiusmetrics "enabled" true -}} +{{- else -}} + {{- $_ := set .Values.workload.radius "enabled" false -}} + {{- $_ := set .Values.service.radius "enabled" false -}} + {{- $_ := set .Values.service.radiusmetrics "enabled" false -}} + {{- $_ := set .Values.metrics.radiusmetrics "enabled" false -}} {{- end -}} -{{- if .Values.outposts.ldap.enabled -}} -{{- $_ := set .Values.workload.main.podSpec.containers "ldap-outpost" (include "authentik.ldap.container" . | fromYaml) -}} -{{/* - if .Values.metrics.enabled - */}} -{{/* https://github.com/prometheus/prometheus/issues/3756 */}} -{{/* TODO: Figure how the pipe works to connect it to prometheus operator */}} -{{/* We can't define multiple ports/endpoints with annotations */}} -{{/* - end - */}} +{{- if .Values.authentik.outposts.ldap.enabled -}} + {{- $_ := set .Values.workload.ldap "enabled" true -}} + {{- $_ := set .Values.service.ldap "enabled" true -}} + {{- $_ := set .Values.service.ldaps "enabled" true -}} + {{- $_ := set .Values.service.ldapmetrics "enabled" true -}} + {{- $_ := set .Values.metrics.ldapmetrics "enabled" true -}} +{{- else -}} + {{- $_ := set .Values.workload.ldap "enabled" false -}} + {{- $_ := set .Values.service.ldap "enabled" false -}} + {{- $_ := set .Values.service.ldaps "enabled" false -}} + {{- $_ := set .Values.service.ldapmetrics "enabled" false -}} + {{- $_ := set .Values.metrics.ldapmetrics "enabled" false -}} {{- end -}} -{{- if .Values.outposts.proxy.enabled -}} -{{- $_ := set .Values.workload.main.podSpec.containers "proxy-outpost" (include "authentik.proxy.container" . | fromYaml) -}} -{{/* - if .Values.metrics.enabled - */}} -{{/* https://github.com/prometheus/prometheus/issues/3756 */}} -{{/* TODO: Figure how the pipe works to connect it to prometheus operator */}} -{{/* We can't define multiple ports/endpoints with annotations */}} -{{/* - end - */}} -{{- end -}} +{{/* FIXME: See values.yaml */}} +{{- $_ := set .Values.service.servermetrics "enabled" false -}} +{{- $_ := set .Values.service.radiusmetrics "enabled" false -}} +{{- $_ := set .Values.service.ldapmetrics "enabled" false -}} + +{{- $_ := set .Values.metrics.servermetrics "enabled" false -}} +{{- $_ := set .Values.metrics.radiusmetrics "enabled" false -}} +{{- $_ := set .Values.metrics.ldapmetrics "enabled" false -}} {{/* Render the templates */}} {{ include "tc.v1.common.loader.apply" . }} diff --git a/charts/incubator/authentik/templates/prometheusrules.yaml b/charts/incubator/authentik/templates/prometheusrules.yaml deleted file mode 100644 index db0c56cd213..00000000000 --- a/charts/incubator/authentik/templates/prometheusrules.yaml +++ /dev/null @@ -1,160 +0,0 @@ -{{- if hasKey .Values "metrics" }} -{{- if and .Values.metrics.enabled .Values.metrics.prometheusRule.enabled }} -apiVersion: monitoring.coreos.com/v1 -kind: PrometheusRule -metadata: - name: {{ include "tc.v1.common.lib.chart.names.fullname" . }} - labels: - {{- include "tc.common.labels" . | nindent 4 }} - {{- with .Values.metrics.prometheusRule.labels }} - {{- toYaml . | nindent 4 }} - {{- end }} -spec: - groups: - - name: {{ include "tc.v1.common.lib.chart.names.fullname" . }} - rules: - {{- with .Values.metrics.prometheusRule.rules }} - {{- toYaml . | nindent 8 }} - {{- end }} - {{- if .Values.metrics.prometheusRule.useDefault }} - - name: authentik Aggregate request counters - rules: - - record: job:django_http_requests_before_middlewares_total:sum_rate30s - expr: sum(rate(django_http_requests_before_middlewares_total[30s])) by (job) - - record: job:django_http_requests_unknown_latency_total:sum_rate30s - expr: sum(rate(django_http_requests_unknown_latency_total[30s])) by (job) - - record: job:django_http_ajax_requests_total:sum_rate30s - expr: sum(rate(django_http_ajax_requests_total[30s])) by (job) - - record: job:django_http_responses_before_middlewares_total:sum_rate30s - expr: sum(rate(django_http_responses_before_middlewares_total[30s])) by (job) - - record: job:django_http_requests_unknown_latency_including_middlewares_total:sum_rate30s - expr: sum(rate(django_http_requests_unknown_latency_including_middlewares_total[30s])) by (job) - - record: job:django_http_requests_body_total_bytes:sum_rate30s - expr: sum(rate(django_http_requests_body_total_bytes[30s])) by (job) - - record: job:django_http_responses_streaming_total:sum_rate30s - expr: sum(rate(django_http_responses_streaming_total[30s])) by (job) - - record: job:django_http_responses_body_total_bytes:sum_rate30s - expr: sum(rate(django_http_responses_body_total_bytes[30s])) by (job) - - record: job:django_http_requests_total:sum_rate30s - expr: sum(rate(django_http_requests_total_by_method[30s])) by (job) - - record: job:django_http_requests_total_by_method:sum_rate30s - expr: sum(rate(django_http_requests_total_by_method[30s])) by (job,method) - - record: job:django_http_requests_total_by_transport:sum_rate30s - expr: sum(rate(django_http_requests_total_by_transport[30s])) by (job,transport) - - record: job:django_http_requests_total_by_view:sum_rate30s - expr: sum(rate(django_http_requests_total_by_view_transport_method[30s])) by (job,view) - - record: job:django_http_requests_total_by_view_transport_method:sum_rate30s - expr: sum(rate(django_http_requests_total_by_view_transport_method[30s])) by (job,view,transport,method) - - record: job:django_http_responses_total_by_templatename:sum_rate30s - expr: sum(rate(django_http_responses_total_by_templatename[30s])) by (job,templatename) - - record: job:django_http_responses_total_by_status:sum_rate30s - expr: sum(rate(django_http_responses_total_by_status[30s])) by (job,status) - - record: job:django_http_responses_total_by_status_name_method:sum_rate30s - expr: sum(rate(django_http_responses_total_by_status_name_method[30s])) by (job,status,name,method) - - record: job:django_http_responses_total_by_charset:sum_rate30s - expr: sum(rate(django_http_responses_total_by_charset[30s])) by (job,charset) - - record: job:django_http_exceptions_total_by_type:sum_rate30s - expr: sum(rate(django_http_exceptions_total_by_type[30s])) by (job,type) - - record: job:django_http_exceptions_total_by_view:sum_rate30s - expr: sum(rate(django_http_exceptions_total_by_view[30s])) by (job,view) - - name: authentik Aggregate latency histograms - rules: - - record: job:django_http_requests_latency_including_middlewares_seconds:quantile_rate30s - expr: histogram_quantile(0.50, sum(rate(django_http_requests_latency_including_middlewares_seconds_bucket[30s])) by (job, le)) - labels: - quantile: "50" - - record: job:django_http_requests_latency_including_middlewares_seconds:quantile_rate30s - expr: histogram_quantile(0.95, sum(rate(django_http_requests_latency_including_middlewares_seconds_bucket[30s])) by (job, le)) - labels: - quantile: "95" - - record: job:django_http_requests_latency_including_middlewares_seconds:quantile_rate30s - expr: histogram_quantile(0.99, sum(rate(django_http_requests_latency_including_middlewares_seconds_bucket[30s])) by (job, le)) - labels: - quantile: "99" - - record: job:django_http_requests_latency_including_middlewares_seconds:quantile_rate30s - expr: histogram_quantile(0.999, sum(rate(django_http_requests_latency_including_middlewares_seconds_bucket[30s])) by (job, le)) - labels: - quantile: "99.9" - - record: job:django_http_requests_latency_seconds:quantile_rate30s - expr: histogram_quantile(0.50, sum(rate(django_http_requests_latency_seconds_bucket[30s])) by (job, le)) - labels: - quantile: "50" - - record: job:django_http_requests_latency_seconds:quantile_rate30s - expr: histogram_quantile(0.95, sum(rate(django_http_requests_latency_seconds_bucket[30s])) by (job, le)) - labels: - quantile: "95" - - record: job:django_http_requests_latency_seconds:quantile_rate30s - expr: histogram_quantile(0.99, sum(rate(django_http_requests_latency_seconds_bucket[30s])) by (job, le)) - labels: - quantile: "99" - - record: job:django_http_requests_latency_seconds:quantile_rate30s - expr: histogram_quantile(0.999, sum(rate(django_http_requests_latency_seconds_bucket[30s])) by (job, le)) - labels: - quantile: "99.9" - - name: authentik Aggregate model operations - rules: - - record: job:django_model_inserts_total:sum_rate1m - expr: sum(rate(django_model_inserts_total[1m])) by (job, model) - - record: job:django_model_updates_total:sum_rate1m - expr: sum(rate(django_model_updates_total[1m])) by (job, model) - - record: job:django_model_deletes_total:sum_rate1m - expr: sum(rate(django_model_deletes_total[1m])) by (job, model) - - name: authentik Aggregate database operations - rules: - - record: job:django_db_new_connections_total:sum_rate30s - expr: sum(rate(django_db_new_connections_total[30s])) by (alias, vendor) - - record: job:django_db_new_connection_errors_total:sum_rate30s - expr: sum(rate(django_db_new_connection_errors_total[30s])) by (alias, vendor) - - record: job:django_db_execute_total:sum_rate30s - expr: sum(rate(django_db_execute_total[30s])) by (alias, vendor) - - record: job:django_db_execute_many_total:sum_rate30s - expr: sum(rate(django_db_execute_many_total[30s])) by (alias, vendor) - - record: job:django_db_errors_total:sum_rate30s - expr: sum(rate(django_db_errors_total[30s])) by (alias, vendor, type) - - name: authentik Aggregate migrations - rules: - - record: job:django_migrations_applied_total:max - expr: max(django_migrations_applied_total) by (job, connection) - - record: job:django_migrations_unapplied_total:max - expr: max(django_migrations_unapplied_total) by (job, connection) - - name: authentik Alerts - rules: - - alert: NoWorkersConnected - expr: max without (pid) (authentik_admin_workers) < 1 - annotations: - message: | - authentik instance {{ printf "{{ $labels.instance }}" }}'s worker are either not running or not connected. - summary: No workers connected - for: 10m - labels: - severity: critical - - alert: PendingMigrations - expr: max without (pid) (django_migrations_unapplied_total) > 0 - annotations: - message: | - authentik instance {{ printf "{{ $labels.instance }}" }} has pending database migrations - summary: Pending database migrations - for: 10m - labels: - severity: critical - - alert: FailedSystemTasks - expr: sum(increase(authentik_system_tasks{status="TaskResultStatus.ERROR"}[2h])) > 0 - annotations: - message: | - System task {{ printf "{{ $labels.task_name }}" }} has failed - summary: Failed system tasks - for: 2h - labels: - severity: critical - - alert: DisconnectedOutposts - expr: sum by (outpost) (max without (pid) (authentik_outposts_connected{uid!~"specific.*"})) < 1 - annotations: - message: | - Outpost {{ printf "{{ $labels.outpost }}" }} has at least 1 disconnected instance - summary: Disconnected outpost - for: 30m - labels: - severity: critical - {{- end }} -{{- end }} -{{- end }} diff --git a/charts/incubator/authentik/templates/servicemonitor.yaml b/charts/incubator/authentik/templates/servicemonitor.yaml deleted file mode 100644 index 231f1eb5229..00000000000 --- a/charts/incubator/authentik/templates/servicemonitor.yaml +++ /dev/null @@ -1,44 +0,0 @@ -{{- if hasKey .Values "metrics" }} -{{- if .Values.metrics.enabled }} -apiVersion: monitoring.coreos.com/v1 -kind: ServiceMonitor -metadata: - name: {{ include "tc.v1.common.lib.chart.names.fullname" . }} - labels: - {{- include "tc.common.labels" . | nindent 4 }} - {{- with .Values.metrics.serviceMonitor.labels }} - {{- toYaml . | nindent 4 }} - {{- end }} -spec: - selector: - matchLabels: - {{- include "tc.common.labels.selectorLabels" . | nindent 6 }} - endpoints: - - port: metrics - {{- with .Values.metrics.serviceMonitor.interval }} - interval: {{ . }} - {{- end }} - {{- with .Values.metrics.serviceMonitor.scrapeTimeout }} - scrapeTimeout: {{ . }} - {{- end }} - path: /metrics - - - port: ldapmetrics - {{- with .Values.metrics.serviceMonitor.interval }} - interval: {{ . }} - {{- end }} - {{- with .Values.metrics.serviceMonitor.scrapeTimeout }} - scrapeTimeout: {{ . }} - {{- end }} - path: /metrics - - - port: proxymetrics - {{- with .Values.metrics.serviceMonitor.interval }} - interval: {{ . }} - {{- end }} - {{- with .Values.metrics.serviceMonitor.scrapeTimeout }} - scrapeTimeout: {{ . }} - {{- end }} - path: /metrics -{{- end }} -{{- end }} diff --git a/charts/incubator/authentik/values.yaml b/charts/incubator/authentik/values.yaml index f30ddc863e0..5f89eac2459 100644 --- a/charts/incubator/authentik/values.yaml +++ b/charts/incubator/authentik/values.yaml @@ -1,65 +1,275 @@ image: repository: tccr.io/truecharts/authentik - tag: 2023.4.1@sha256:7d60414d9d5f2395b703228193e8b03c616d7fed6c3cee620940845dd0b725cb + tag: v2023.5.3@sha256:55c6eea8ce8d936379b34a05c0d0558a0ca737e71a72d27600d27ce23bc369e3 pullPolicy: IfNotPresent geoipImage: repository: tccr.io/truecharts/geoipupdate - tag: v4.9@sha256:ce42b4252c8cd4a9e39275fd7c3312e5df7bda0d7034df565af4362d7e0d26ce + tag: v5.1.0@sha256:9397c7e4d99ab79d620bd7c6ecbad3558ac581dfc2c9432d98dd066ae7d55c71 pullPolicy: IfNotPresent ldapImage: repository: tccr.io/truecharts/authentik-ldap - tag: 2023.4.1@sha256:f737b534c6f3a022b002bb5d635ef491273fd40f8c0b6dd64efa7f5f6265d8cf + tag: v2023.5.3@sha256:7ac0f5c4ad334c9480548cf2d5978fe0f6105809c9deeb8d40c450486863526f pullPolicy: IfNotPresent -proxyImage: - repository: tccr.io/truecharts/authentik-proxy - tag: 2023.4.1@sha256:b6e40435836333bdc53afde38f4c4bfb342005b0636d769c641c79348ce1aae4 +radiusImage: + repository: tccr.io/truecharts/authentik-radius + tag: v2023.5.3@sha256:d46f4dbc727d5d6f6c91df0f6a2bf98d2c941de908fdc15193552413331e375b pullPolicy: IfNotPresent -securityContext: - container: - runAsUser: 1000 - runAsGroup: 1000 - readOnlyRootFilesystem: false +authentik: + credentials: + # Only works on initial install + email: my-mail@example.com + password: my-password + general: + disableUpdateCheck: false + disableStartupAnalytics: true + allowUserChangeName: true + allowUserChangeEmail: true + allowUserChangeUsername: true + gdprCompliance: true + tokenLength: 128 + impersonation: true + avatars: + - gravatar + - initials + footerLinks: + - name: Authentik + href: https://goauthentik.io + email: + host: "" + port: 587 + username: + password: + useTLS: true + useSSL: false + timeout: 10 + from: "" + ldap: + tlsCiphers: "null" + taskTimeoutHours: 2 + logging: + # info, debug, warning, error, trace + logLevel: info + errorReporting: + enabled: false + sendPII: false + environment: customer + sentryDSN: "" + geoip: + enabled: false + editionID: GeoLite2-City + frequency: 8 + accountID: "" + licenseKey: "" + outposts: + radius: + enabled: false + token: "" + ldap: + enabled: false + token: "" +# ===== DO NOT EDIT BELOW THIS LINE ===== workload: + # ===== Server ===== main: - replicas: 1 - strategy: RollingUpdate + enabled: true + type: Deployment podSpec: containers: main: - args: ["server"] + enabled: true + primary: true + imageSelector: image + securityContext: + runAsUser: 1000 + runAsGroup: 1000 + # readOnlyRootFilesystem: false envFrom: + - configMapRef: + name: server - secretRef: - name: '{{ include "tc.v1.common.lib.chart.names.fullname" . }}-authentik-secret' + name: server-worker - configMapRef: - name: '{{ include "tc.v1.common.lib.chart.names.fullname" . }}-authentik-config' - - configMapRef: - name: '{{ include "tc.v1.common.lib.chart.names.fullname" . }}-authentik-server-config' + name: server-worker + args: + - server probes: liveness: - type: https - path: /-/health/live/ - port: "{{ .Values.service.main.ports.main.targetPort }}" + enabled: true + type: exec + command: + - /lifecycle/ak + - healthcheck readiness: - type: https - path: /-/health/ready/ - port: "{{ .Values.service.main.ports.main.targetPort }}" + enabled: true + type: exec + command: + - /lifecycle/ak + - healthcheck startup: - type: https - path: /-/health/ready/ - port: "{{ .Values.service.main.ports.main.targetPort }}" + enabled: true + type: exec + command: + - /lifecycle/ak + - healthcheck + + # ===== Worker ===== + worker: + enabled: true + type: Deployment + podSpec: + containers: + worker: + enabled: true + primary: true + imageSelector: image + securityContext: + runAsUser: 1000 + runAsGroup: 1000 + # readOnlyRootFilesystem: false + envFrom: + - secretRef: + name: server-worker + - configMapRef: + name: server-worker + args: + - worker + probes: + liveness: + enabled: true + type: exec + command: + - /lifecycle/ak + - healthcheck + readiness: + enabled: true + type: exec + command: + - /lifecycle/ak + - healthcheck + startup: + enabled: true + type: exec + command: + - /lifecycle/ak + - healthcheck + + # ===== RADIUS ===== + radius: + enabled: true + type: Deployment + podSpec: + containers: + radius: + enabled: true + primary: true + imageSelector: radiusImage + securityContext: + runAsUser: 1000 + runAsGroup: 1000 + envFrom: + - configMapRef: + name: radius + - secretRef: + name: radius + probes: + liveness: + enabled: true + type: exec + command: + - /radius + - healthcheck + readiness: + enabled: true + type: exec + command: + - /radius + - healthcheck + startup: + enabled: true + type: exec + command: + - /radius + - healthcheck + + # ===== LDAP ===== + ldap: + enabled: true + type: Deployment + podSpec: + containers: + ldap: + enabled: true + primary: true + imageSelector: ldapImage + securityContext: + runAsUser: 1000 + runAsGroup: 1000 + envFrom: + - configMapRef: + name: ldap + - secretRef: + name: ldap + probes: + liveness: + enabled: true + type: exec + command: + - /ldap + - healthcheck + readiness: + enabled: true + type: exec + command: + - /ldap + - healthcheck + startup: + enabled: true + type: exec + command: + - /ldap + - healthcheck + + # ===== GeoIP Updater ===== + geoip: + enabled: true + type: Deployment + podSpec: + containers: + geoip: + enabled: true + primary: true + imageSelector: geoipImage + securityContext: + runAsUser: 0 + runAsGroup: 0 + capabilities: + disableS6Caps: true + envFrom: + - configMapRef: + name: geoip + - secretRef: + name: geoip + probes: + liveness: + enabled: false + readiness: + enabled: false + startup: + enabled: false service: + # Server HTTPS main: ports: main: protocol: https port: 10229 - targetPort: 9443 + # Server HTTP http: enabled: true type: ClusterIP @@ -68,133 +278,100 @@ service: enabled: true protocol: http port: 10230 - targetPort: 9000 - # LDAP Outpost Services - ldapldaps: + # Radius + radius: enabled: true ports: - ldapldaps: + radius: enabled: true - port: 636 - targetPort: 6636 - ldapldap: + protocol: udp + port: 1812 + # LDAP + ldap: enabled: true ports: - ldapldap: + ldap: enabled: true port: 389 - targetPort: 3389 - # Proxy Outpost Services - proxyhttps: + # LDAPS + ldaps: enabled: true ports: - proxyhttps: + ldaps: enabled: true - port: 10233 - protocol: https - targetPort: 9444 - proxyhttp: + port: 636 + # Server Metrics + servermetrics: enabled: true type: ClusterIP ports: - proxyhttp: - enabled: true - port: 10234 - protocol: http - targetPort: 9001 - # Metrics Services - metrics: - enabled: true - type: ClusterIP - ports: - metrics: + servermetrics: enabled: true protocol: http port: 10231 - targetPort: 9301 + # Radius Metrics + radiusmetrics: + enabled: true + type: ClusterIP + ports: + radiusmetrics: + enabled: true + protocol: http + port: 10232 + # LDAP Metrics ldapmetrics: enabled: true type: ClusterIP ports: ldapmetrics: enabled: true - port: 10232 protocol: http - targetPort: 9302 - proxymetrics: - enabled: true - type: ClusterIP - ports: - proxymetrics: - enabled: true - port: 10235 - protocol: http - targetPort: 9303 + port: 10233 -metrics: - # TODO - main: - # -- Enable and configure a Prometheus serviceMonitor for the chart under this key. - # @default -- See values.yaml - enabled: false - type: "servicemonitor" - endpoints: - - port: main - path: /metrics - interval: 1m - scrapeTimeout: 30s - # -- Enable and configure Prometheus Rules for the chart under this key. - # @default -- See values.yaml - prometheusRule: - enabled: false - labels: {} - # -- Configure additionial rules for the chart under this key. - # @default -- See prometheusrules.yaml - rules: - [] - # - alert: UnifiPollerAbsent - # annotations: - # description: Unifi Poller has disappeared from Prometheus service discovery. - # summary: Unifi Poller is down. - # expr: | - # absent(up{job=~".*unifi-poller.*"} == 1) - # for: 5m - # labels: - # severity: critical - -ingress: - proxyhttps: - autoLink: true - -# Target selectors taken from authentik's compose file: -# See https://github.com/goauthentik/authentik/blob/main/docker-compose.yml persistence: media: enabled: true - mountPath: "/media" targetSelector: main: - main: {} - worker: {} + main: + mountPath: /media + worker: + worker: + mountPath: /media templates: enabled: true - mountPath: "/templates" targetSelector: main: - main: {} - worker: {} + main: + mountPath: /templates + worker: + worker: + mountPath: /templates + blueprints: + enabled: true + targetSelector: + worker: + worker: + mountPath: /blueprints certs: enabled: true - mountPath: "/certs" + mountPath: /certs targetSelector: - main: - worker: {} + worker: + worker: + mountPath: /certs geoip: enabled: true - mountPath: "/usr/share/GeoIP" targetSelector: main: - geoip: {} + main: + mountPath: /geoip + worker: + worker: + mountPath: /geoip + geoip: + geoip: + mountPath: /usr/share/GeoIP cnpg: main: @@ -202,89 +379,36 @@ cnpg: user: authentik database: authentik -cnpgProvider: - port: 5432 - -# Enabled redis -# ... for more options see https://github.com/tccr.io/truecharts/charts/tree/master/tccr.io/truecharts/redis redis: enabled: true -redisProvider: - port: 6379 - -workerContainer: - enabled: true - -authentik: - credentials: - password: "supersecret" - general: - disable_update_check: false - disable_startup_analytics: true - allow_user_name_change: true - allow_user_mail_change: true - allow_user_username_change: true - gdpr_compliance: true - impersonation: true - avatars: "gravatar,initials" - token_length: 128 - # Use single quotes for footer_links - footer_links: '[{"name": "Link Name", "href": "https://mylink.com"}]' - mail: - host: "" - port: 25 - tls: false - ssl: false - timeout: 10 - user: "" - pass: "" - from: "" - error_reporting: - enabled: false - send_pii: false - environment: "customer" - logging: - log_level: "info" - ldap: - tls_ciphers: "null" - -geoip: - enabled: false - account_id: "" - license_key: "" - proxy: "" - proxy_user_pass: "" - edition_ids: "GeoLite2-City" - frequency: 8 - host_server: "updates.maxmind.com" - preserve_file_times: false - verbose: false - -outposts: - ldap: - # -- First you have to create an Outpost in the GUI. Applications > Outposts - enabled: false - # -- Host Browser by default is set to the first ingress host you set - # host_browser: "" - # -- Host should not need to be overridden. Defaults to https://localhost:9443 - # host: "" - # -- As we use https://localhost:9443 it's an unsecure connection - # insecure: false - # -- Token is only needed if you accidentally deleted the token within the UI - # token: "" - proxy: - # -- First you have to create an Outpost in the GUI. Applications > Outposts - enabled: false - # -- Host Browser by default is set to the first ingress host you set - # host_browser: "" - # -- As we use https://localhost:9443 it's an unsecure connection - # insecure: false - # -- Host should not need to be overridden. Defaults to https://localhost:9443 - # host: "" - # -- Token is only needed if you accidentally deleted the token within the UI - # token: "" - portal: open: enabled: true + +metrics: + # FIXME: Metris do not work yet + servermetrics: + enabled: true + type: servicemonitor + endpoints: + - port: "{{ .Values.service.servermetrics.ports.servermetrics.port }}" + path: /metrics + prometheusRule: + enabled: false + radiusmetrics: + enabled: true + type: servicemonitor + endpoints: + - port: "{{ .Values.service.radiusmetrics.ports.radiusmetrics.port }}" + path: /metrics + prometheusRule: + enabled: false + ldapmetrics: + enabled: true + type: servicemonitor + endpoints: + - port: "{{ .Values.service.ldapmetrics.ports.ldapmetrics.port }}" + path: /metrics + prometheusRule: + enabled: false