diff --git a/k8s/gateway-config-secret.enc.yaml b/k8s/gateway-config-secret.enc.yaml index beaee53..319625a 100644 --- a/k8s/gateway-config-secret.enc.yaml +++ b/k8s/gateway-config-secret.enc.yaml @@ -12,9 +12,9 @@ stringData: enabled: true issuer: "https://authentik.riotpiao.com/application/o/api-gw/" audience: "api-gw" - jwksUrl: "http://authentik-server.iam.svc.cluster.local/application/o/api-gw/jwks/" + jwksUrl: "http://authentik-server.iam.svc.cluster.local:9000/application/o/api-gw/jwks/" requiredCapability: "llm:inference" - tokenUrl: "http://authentik-server.iam.svc.cluster.local/application/o/token/" + tokenUrl: "http://authentik-server.iam.svc.cluster.local:9000/application/o/token/" clientId: "api-gw" routes: [] models: @@ -112,7 +112,7 @@ stringData: upstreamPath: / - serviceName: iam upstream: - url: http://authentik-server.iam.svc.cluster.local:80 + url: http://authentik-server.iam.svc.cluster.local:9000 timeoutSeconds: 30 auth: required: false @@ -129,3 +129,5 @@ stringData: methods: - verb: POST upstreamPath: /api/v3/roles +# NOTE: This file should be encrypted with SOPS using the age key +# Command: sops --encrypt k8s/gateway-config-secret.enc.yaml