NetworkPolicy allows gateway→iam only on ports 9000/9443, but config used port 80 for JWKS fetch and token endpoints. This caused 'operation not permitted' errors and JWKS refresh failures. Affects: - auth.jwksUrl: uses port 9000 (Authentik HTTP) - auth.tokenUrl: uses port 9000 for token exchange - iam adapter upstream: routes to port 9000 Fixes: Gateway unable to validate JWT tokens, all chat/inference requests returned 401 with 'token is unverifiable' error.
This commit is contained in:
+3
-3
@@ -15,9 +15,9 @@ data:
|
|||||||
enabled: true
|
enabled: true
|
||||||
issuer: "https://authentik.riotpiao.com/application/o/api-gw/"
|
issuer: "https://authentik.riotpiao.com/application/o/api-gw/"
|
||||||
audience: "api-gw"
|
audience: "api-gw"
|
||||||
jwksUrl: "http://authentik-server.iam.svc.cluster.local/application/o/api-gw/jwks/"
|
jwksUrl: "http://authentik-server.iam.svc.cluster.local:9000/application/o/api-gw/jwks/"
|
||||||
requiredCapability: "llm:inference"
|
requiredCapability: "llm:inference"
|
||||||
tokenUrl: "http://authentik-server.iam.svc.cluster.local/application/o/token/"
|
tokenUrl: "http://authentik-server.iam.svc.cluster.local:9000/application/o/token/"
|
||||||
clientId: "api-gw"
|
clientId: "api-gw"
|
||||||
|
|
||||||
# Routes: standard HTTP proxy routes (not LLM-specific)
|
# Routes: standard HTTP proxy routes (not LLM-specific)
|
||||||
@@ -137,7 +137,7 @@ data:
|
|||||||
|
|
||||||
- serviceName: iam
|
- serviceName: iam
|
||||||
upstream:
|
upstream:
|
||||||
url: http://authentik-server.iam.svc.cluster.local:80
|
url: http://authentik-server.iam.svc.cluster.local:9000
|
||||||
timeoutSeconds: 30
|
timeoutSeconds: 30
|
||||||
auth:
|
auth:
|
||||||
required: false
|
required: false
|
||||||
|
|||||||
Reference in New Issue
Block a user