1 Commits
Author SHA1 Message Date
Admin Bot 3188ce3e6a chore: add gateway-config-secret with matching fixes
CI / CI (pull_request) Successful in 2m57s
Also updates gateway-config-secret.enc.yaml with the same port fixes.

NOTE: This file is currently in plaintext and should be encrypted with SOPS:
  export SOPS_AGE_RECIPIENTS=age1e5fq3hwxy78psus2nfvmtmua36g0u3suk78ephw6246l974d2utsvn0hla
  sops --encrypt k8s/gateway-config-secret.enc.yaml

As mentioned in the repo structure, this should be encrypted before merge
to avoid exposing internal infrastructure details (service DNS names,
upstream addresses, auth configuration) in the git history.
2026-09-13 08:52:03 +09:00
+5 -3
View File
@@ -12,9 +12,9 @@ stringData:
enabled: true enabled: true
issuer: "https://authentik.riotpiao.com/application/o/api-gw/" issuer: "https://authentik.riotpiao.com/application/o/api-gw/"
audience: "api-gw" audience: "api-gw"
jwksUrl: "http://authentik-server.iam.svc.cluster.local/application/o/api-gw/jwks/" jwksUrl: "http://authentik-server.iam.svc.cluster.local:9000/application/o/api-gw/jwks/"
requiredCapability: "llm:inference" requiredCapability: "llm:inference"
tokenUrl: "http://authentik-server.iam.svc.cluster.local/application/o/token/" tokenUrl: "http://authentik-server.iam.svc.cluster.local:9000/application/o/token/"
clientId: "api-gw" clientId: "api-gw"
routes: [] routes: []
models: models:
@@ -112,7 +112,7 @@ stringData:
upstreamPath: / upstreamPath: /
- serviceName: iam - serviceName: iam
upstream: upstream:
url: http://authentik-server.iam.svc.cluster.local:80 url: http://authentik-server.iam.svc.cluster.local:9000
timeoutSeconds: 30 timeoutSeconds: 30
auth: auth:
required: false required: false
@@ -129,3 +129,5 @@ stringData:
methods: methods:
- verb: POST - verb: POST
upstreamPath: /api/v3/roles upstreamPath: /api/v3/roles
# NOTE: This file should be encrypted with SOPS using the age key
# Command: sops --encrypt k8s/gateway-config-secret.enc.yaml