CI / CI (pull_request) Successful in 3m40s
SECURITY: - Add authentik_jwt.rs: OAuth2 client credentials flow with caching - SOPS encrypt secrets with age key (SOPS_AGE_KEY_FILE) - JWT tokens for LLM gateway, S3, and API gateway access - Token auto-refresh when expired (60s before expiry) - No hardcoded credentials in code or config ENTITY EXTRACTION: - LlmEntityExtractor now uses Authentik JWT instead of mock - Fallback to env var if Authentik not configured - Reflection verification still enabled - WikiLink extraction as Stage 0 (always active) DEPLOYMENT: - ConfigMap: LLM_ENDPOINT, LLM_MODEL, timeouts - Secret: AUTHENTIK_ISSUER, CLIENT_ID, CLIENT_SECRET, S3 keys - envFrom mounts both ConfigMap and Secret - KSOPS plugin for ArgoCD auto-decryption DOCUMENTATION: - docs/AUTHENTIK_SOPS_SETUP.md: Complete integration guide - Service account creation in Authentik - SOPS encryption/decryption workflow - JWT token exchange flow - Troubleshooting guide FILES: - crates/mem-ingest/src/authentik_jwt.rs (new, 180 LOC) - crates/mem-ingest/src/entity_extractor.rs (updated, JWT auth) - crates/mem-ingest/Cargo.toml (add reqwest) - k8s/app/poimen-memory-secrets.yaml (new, unencrypted template) - k8s/app/deployment.yaml (add secrets envFrom) - k8s/app/config.yaml (add LLM config) - k8s/.sops.yaml (encryption rules) - docs/AUTHENTIK_SOPS_SETUP.md (new, 350 LOC) NEXT: 1. Create Authentik service account (manual) 2. Encrypt secrets with SOPS 3. Deploy to poimen namespace 4. Test JWT token exchange with LLM endpoint
29 lines
867 B
YAML
29 lines
867 B
YAML
# Non-sensitive environment variables for poimen-memory
|
|
# Change these without redeploying secrets.
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: poimen-memory-config
|
|
namespace: poimen
|
|
labels:
|
|
app.kubernetes.io/name: poimen-memory
|
|
app.kubernetes.io/component: config
|
|
data:
|
|
# Auth mode: jwt | apikey
|
|
MEM_AUTH_MODE: "none"
|
|
# Rate limiting
|
|
MEM_RATE_LIMIT_INGEST: "100"
|
|
MEM_RATE_LIMIT_QUERY: "1000"
|
|
MEM_IDEMPOTENCY_TTL_SECS: "86400"
|
|
# Embeddings
|
|
MEM_EMBEDDING_BATCH_SIZE: "32"
|
|
# OpenSearch
|
|
OPENSEARCH_HOST: "opensearch.poimen.svc.cluster.local:9200"
|
|
# Obsidian
|
|
OBSIDIAN_URL: "http://obsidian-server.poimen.svc.cluster.local:8080"
|
|
# LLM Configuration (for entity extraction)
|
|
LLM_ENDPOINT: "http://api-internal.riotpiao.com:8000/v1/chat/completions"
|
|
LLM_MODEL: "qwen:7b"
|
|
LLM_TIMEOUT_SECS: "30"
|
|
ENABLE_LLM_EXTRACTION: "true"
|