NetworkPolicy allows gateway→iam only on ports 9000/9443, but config used port 80 for JWKS fetch and token endpoints. This caused 'operation not permitted' errors and JWKS refresh failures. Affects: - auth.jwksUrl: uses port 9000 (Authentik HTTP) - auth.tokenUrl: uses port 9000 for token exchange - iam adapter upstream: routes to port 9000 Fixes: Gateway unable to validate JWT tokens, all chat/inference requests returned 401 with 'token is unverifiable' error.
This commit is contained in:
+3
-3
@@ -15,9 +15,9 @@ data:
|
||||
enabled: true
|
||||
issuer: "https://authentik.riotpiao.com/application/o/api-gw/"
|
||||
audience: "api-gw"
|
||||
jwksUrl: "http://authentik-server.iam.svc.cluster.local/application/o/api-gw/jwks/"
|
||||
jwksUrl: "http://authentik-server.iam.svc.cluster.local:9000/application/o/api-gw/jwks/"
|
||||
requiredCapability: "llm:inference"
|
||||
tokenUrl: "http://authentik-server.iam.svc.cluster.local/application/o/token/"
|
||||
tokenUrl: "http://authentik-server.iam.svc.cluster.local:9000/application/o/token/"
|
||||
clientId: "api-gw"
|
||||
|
||||
# Routes: standard HTTP proxy routes (not LLM-specific)
|
||||
@@ -137,7 +137,7 @@ data:
|
||||
|
||||
- serviceName: iam
|
||||
upstream:
|
||||
url: http://authentik-server.iam.svc.cluster.local:80
|
||||
url: http://authentik-server.iam.svc.cluster.local:9000
|
||||
timeoutSeconds: 30
|
||||
auth:
|
||||
required: false
|
||||
|
||||
Reference in New Issue
Block a user