refactor(k8s): Reorganize into 5-layer structure with production kustomizations
This commit is contained in:
@@ -0,0 +1,52 @@
|
||||
# Rotates the Authentik OIDC signing key quarterly for all homelab providers.
|
||||
#
|
||||
# Prerequisites (run once):
|
||||
# # 1. ConfigMap from the Rust source file
|
||||
# kubectl create configmap key-rotation-script \
|
||||
# --from-file=rotate_key.rs=key_rotate.rs \
|
||||
# -n iam --dry-run=client -o yaml | kubectl apply -f -
|
||||
#
|
||||
# # 2. Token secret — fill in your value, never commit it
|
||||
# kubectl create secret generic authentik-key-rotation-token \
|
||||
# --from-literal=AUTHENTIK_BOOTSTRAP_TOKEN="${AUTHENTIK_BOOTSTRAP_TOKEN}" \
|
||||
# -n iam --dry-run=client -o yaml | kubectl apply -f -
|
||||
#
|
||||
# Apply: kubectl apply -f key-rotation-cronjob.yaml
|
||||
# Test: kubectl create job --from=cronjob/authentik-key-rotation test-rotation -n iam
|
||||
# Logs: kubectl logs -n iam -l job-name=test-rotation -f
|
||||
|
||||
apiVersion: batch/v1
|
||||
kind: CronJob
|
||||
metadata:
|
||||
name: authentik-key-rotation
|
||||
namespace: iam
|
||||
spec:
|
||||
schedule: "0 0 1 */3 *" # 00:00 UTC on the 1st of Jan, Apr, Jul, Oct
|
||||
concurrencyPolicy: Forbid # skip if a previous job is still running
|
||||
jobTemplate:
|
||||
spec:
|
||||
template:
|
||||
spec:
|
||||
restartPolicy: OnFailure
|
||||
volumes:
|
||||
- name: script
|
||||
configMap:
|
||||
name: key-rotation-script
|
||||
containers:
|
||||
- name: rotate
|
||||
image: rust:1.82-slim
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- rustc /scripts/rotate_key.rs -o /tmp/rotate_key && /tmp/rotate_key
|
||||
volumeMounts:
|
||||
- name: script
|
||||
mountPath: /scripts
|
||||
env:
|
||||
- name: AUTHENTIK_BASE_URL
|
||||
value: "http://authentik-server.iam.svc.cluster.local"
|
||||
- name: AUTHENTIK_BOOTSTRAP_TOKEN
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: authentik-key-rotation-token
|
||||
key: AUTHENTIK_BOOTSTRAP_TOKEN
|
||||
Reference in New Issue
Block a user