chore: add gateway-config-secret with matching fixes
CI / CI (pull_request) Successful in 2m57s

Also updates gateway-config-secret.enc.yaml with the same port fixes.

NOTE: This file is currently in plaintext and should be encrypted with SOPS:
  export SOPS_AGE_RECIPIENTS=age1e5fq3hwxy78psus2nfvmtmua36g0u3suk78ephw6246l974d2utsvn0hla
  sops --encrypt k8s/gateway-config-secret.enc.yaml

As mentioned in the repo structure, this should be encrypted before merge
to avoid exposing internal infrastructure details (service DNS names,
upstream addresses, auth configuration) in the git history.
This commit is contained in:
Admin Bot
2026-09-13 08:52:03 +09:00
parent 45254a48b0
commit 3188ce3e6a
+5 -3
View File
@@ -12,9 +12,9 @@ stringData:
enabled: true
issuer: "https://authentik.riotpiao.com/application/o/api-gw/"
audience: "api-gw"
jwksUrl: "http://authentik-server.iam.svc.cluster.local/application/o/api-gw/jwks/"
jwksUrl: "http://authentik-server.iam.svc.cluster.local:9000/application/o/api-gw/jwks/"
requiredCapability: "llm:inference"
tokenUrl: "http://authentik-server.iam.svc.cluster.local/application/o/token/"
tokenUrl: "http://authentik-server.iam.svc.cluster.local:9000/application/o/token/"
clientId: "api-gw"
routes: []
models:
@@ -112,7 +112,7 @@ stringData:
upstreamPath: /
- serviceName: iam
upstream:
url: http://authentik-server.iam.svc.cluster.local:80
url: http://authentik-server.iam.svc.cluster.local:9000
timeoutSeconds: 30
auth:
required: false
@@ -129,3 +129,5 @@ stringData:
methods:
- verb: POST
upstreamPath: /api/v3/roles
# NOTE: This file should be encrypted with SOPS using the age key
# Command: sops --encrypt k8s/gateway-config-secret.enc.yaml