k8s/messaging: add kafka kmsvc and temporal workflows
- Kafka 3-broker cluster (RF=3, min-ISR=2) - kmsvc SQS-like API on Kafka - Redis dedup (standalone, can extend to HA) - Temporal workflow orchestration (Cassandra backend)
This commit is contained in:
@@ -0,0 +1,45 @@
|
||||
# OAuth2-Proxy for Temporal UI — protects with Authentik OIDC
|
||||
# Deployed via Helm: oauth2-proxy/oauth2-proxy chart
|
||||
|
||||
config:
|
||||
clientID: temporal
|
||||
clientSecret: "" # injected from temporal-oidc secret
|
||||
cookieSecret: "" # generated; helm --set will override
|
||||
configFile: ""
|
||||
|
||||
auth:
|
||||
enabled: true
|
||||
|
||||
extraArgs:
|
||||
- --provider=oidc
|
||||
- --oidc-issuer-url=https://authentik.riotpiao.homelab.com/application/o/temporal/
|
||||
- --redirect-url=https://temporal.riotpiao.homelab.com/oauth2/callback
|
||||
- --upstream=http://temporal-web:8080
|
||||
- --cookie-secure=true
|
||||
- --cookie-httponly=true
|
||||
- --cookie-samesite=Lax
|
||||
- --email-domain=*
|
||||
- --skip-auth-regex=^/health
|
||||
- --pass-authorization-header=true
|
||||
- --skip-auth-preflight=true
|
||||
|
||||
service:
|
||||
type: ClusterIP
|
||||
port: 4180
|
||||
targetPort: 4180
|
||||
|
||||
ingress:
|
||||
enabled: false # we'll keep temporal's ingress, just route to oauth2-proxy
|
||||
|
||||
replicaCount: 1
|
||||
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 128Mi
|
||||
limits:
|
||||
cpu: 200m
|
||||
memory: 256Mi
|
||||
|
||||
podAnnotations:
|
||||
secret.reloader.stakater.com/reload: "temporal-oidc"
|
||||
Reference in New Issue
Block a user