Add auth option for Tornjak (#259)

* Added auth option, specifically keycloak for tornjak production use

Signed-off-by: Mohammed Abdi <[email protected]>

* Added auth values for tornjak

Signed-off-by: Mohammed Abdi <[email protected]>

* Update charts/spire/charts/tornjak-frontend/values.yaml

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* Update examples/tornjak/keycloak/README.md

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* Update examples/tornjak/keycloak/README.md

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* Update examples/tornjak/keycloak/README.md

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* Update examples/tornjak/keycloak/README.md

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* Update examples/tornjak/keycloak/README.md

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* Update examples/tornjak/keycloak/README.md

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* nit

Signed-off-by: Mohammed Abdi <[email protected]>

* nit

Signed-off-by: Mohammed Abdi <[email protected]>

* nit

Signed-off-by: Mohammed Abdi <[email protected]>

* Update examples/tornjak/keycloak/README.md

Co-authored-by: Mariusz Sabath <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* nit

Signed-off-by: Mohammed Abdi <[email protected]>

* install keycloak first

Signed-off-by: Mohammed Abdi <[email protected]>

* add logs volume back

Signed-off-by: Mohammed Abdi <[email protected]>

* Fixed NPM init error

Signed-off-by: Mariusz Sabath <[email protected]>

* Fixed the values documentation errors

Signed-off-by: Mariusz Sabath <[email protected]>

* Post-review suggestion fixes

Signed-off-by: Mariusz Sabath <[email protected]>

* Fixed typo

Signed-off-by: Mariusz Sabath <[email protected]>

* Updating Keyclaok examples README

Signed-off-by: Mariusz Sabath <[email protected]>

* Fixed the parameter reference

Signed-off-by: Mariusz Sabath <[email protected]>

* Fix typo

Signed-off-by: Mariusz Sabath <[email protected]>

* use keycloak-config-cli to simplify tornjak realm import

Signed-off-by: MohammedAbdi <[email protected]>

* edit client id

Signed-off-by: MohammedAbdi <[email protected]>

* reverse client id

Signed-off-by: MohammedAbdi <[email protected]>

* fix the doc

Signed-off-by: Mariusz Sabath <[email protected]>

* update tornjak version and backend auth

Signed-off-by: MohammedAbdi <[email protected]>

* update client id

Signed-off-by: MohammedAbdi <[email protected]>

* updates values yaml

Signed-off-by: MohammedAbdi <[email protected]>

* update documentation

Signed-off-by: MohammedAbdi <[email protected]>

* nit

Signed-off-by: MohammedAbdi <[email protected]>

* update doc

Signed-off-by: MohammedAbdi <[email protected]>

* add audience check tornjak

Signed-off-by: MohammedAbdi <[email protected]>

* remove unused file

Signed-off-by: MohammedAbdi <[email protected]>

* update doc

Signed-off-by: MohammedAbdi <[email protected]>

* nit and add auth not enabled warning back

Signed-off-by: MohammedAbdi <[email protected]>

* adjust liveness probe until tornjak handles liveendpoint for auth and direct connection to discovery

Signed-off-by: MohammedAbdi <[email protected]>

* update doc and add keycloak proxy

Signed-off-by: MohammedAbdi <[email protected]>

---------

Signed-off-by: Mohammed Abdi <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>
Signed-off-by: Mariusz Sabath <[email protected]>
Signed-off-by: MohammedAbdi <[email protected]>
Co-authored-by: Mohammed Abdi <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
Co-authored-by: Mariusz Sabath <[email protected]>
This commit is contained in:
Mohammed Abdi
2024-04-25 15:49:20 -07:00
committed by GitHub
co-authored by Faisal Memon Mariusz Sabath Mohammed Abdi
parent f679a0dab6
commit a2494ee45e
15 changed files with 360 additions and 71 deletions
+47 -44
View File
@@ -55,47 +55,50 @@ port forwarding. See the chart NOTES output for more details.
### Chart parameters
| Name | Description | Value |
| ---------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- |
| `image.registry` | The OCI registry to pull the image from | `ghcr.io` |
| `image.repository` | The repository within the registry | `spiffe/tornjak-frontend` |
| `image.pullPolicy` | The image pull policy | `IfNotPresent` |
| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
| `imagePullSecrets` | Pull secrets for images | `[]` |
| `nameOverride` | Name override | `""` |
| `namespaceOverride` | Namespace override | `""` |
| `fullnameOverride` | Fullname override | `""` |
| `serviceAccount.create` | Specifies whether a service account should be created | `true` |
| `serviceAccount.annotations` | Annotations to add to the service account | `{}` |
| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` |
| `labels` | Labels for tornjak frontend pods | `{}` |
| `podSecurityContext` | Pod security context | `{}` |
| `securityContext` | Security context | `{}` |
| `service.type` | Service type | `ClusterIP` |
| `service.port` | Service port | `3000` |
| `service.annotations` | Annotations for service resource | `{}` |
| `nodeSelector` | Select specific nodes to run on (currently only amd64 is supported by Tornjak) | |
| `affinity` | Affinity rules | `{}` |
| `tolerations` | List of tolerations | `[]` |
| `topologySpreadConstraints` | List of topology spread constraints for resilience | `[]` |
| `apiServerURL` | URL of the Tornjak APIs (backend). Since Tornjak Frontend runs in the browser, this URL must be accessible from the machine running a browser. If unset, autodetection is atempted. | `""` |
| `spireHealthCheck.enabled` | Enables the SPIRE Healthchecker indicator | `true` |
| `startupProbe.enabled` | Enable startupProbe on Tornjak frontend container | `true` |
| `startupProbe.initialDelaySeconds` | Initial delay seconds for startupProbe | `5` |
| `startupProbe.periodSeconds` | Period seconds for startupProbe | `10` |
| `startupProbe.timeoutSeconds` | Timeout seconds for startupProbe | `5` |
| `startupProbe.failureThreshold` | Failure threshold count for startupProbe | `6` |
| `startupProbe.successThreshold` | Success threshold count for startupProbe | `1` |
| `workingDir` | Set to override the default path containing the Tornjak frontend within the image | `""` |
| `ingress.enabled` | Flag to enable ingress for Tornjak frontend service | `false` |
| `ingress.className` | Ingress class name for Tornjak frontend service | `""` |
| `ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, autodetection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` |
| `ingress.annotations` | Annotations for Tornjak frontend service | `{}` |
| `ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `tornjak-frontend` |
| `ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` |
| `ingress.hosts` | Host paths for ingress object. If emtpy, rules will be built based on the host var. | `[]` |
| `ingress.tls` | Secrets containing TLS certs to enable https on ingress. If emtpy, rules will be built based on the host and tlsSecret vars. | `[]` |
| `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
| `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` |
| `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` |
| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:a0383e176104e7840387deb9fda1782660e903654f39acf62931e2c9a60b7fe1` |
| Name | Description | Value |
| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- |
| `image.registry` | The OCI registry to pull the image from | `ghcr.io` |
| `image.repository` | The repository within the registry | `spiffe/tornjak-frontend` |
| `image.pullPolicy` | The image pull policy | `IfNotPresent` |
| `image.tag` | Overrides the image tag whose default is the chart appVersion | `""` |
| `imagePullSecrets` | Pull secrets for images | `[]` |
| `nameOverride` | Name override | `""` |
| `namespaceOverride` | Namespace override | `""` |
| `fullnameOverride` | Fullname override | `""` |
| `serviceAccount.create` | Specifies whether a service account should be created | `true` |
| `serviceAccount.annotations` | Annotations to add to the service account | `{}` |
| `serviceAccount.name` | The name of the service account to use. If not set and create is true, a name is generated. | `""` |
| `labels` | Labels for tornjak frontend pods | `{}` |
| `podSecurityContext` | Pod security context | `{}` |
| `securityContext` | Security context | `{}` |
| `service.type` | Service type | `ClusterIP` |
| `service.port` | Service port | `3000` |
| `service.annotations` | Annotations for service resource | `{}` |
| `nodeSelector` | (Optional) Select specific nodes to run on. Tornjak currently supports amd64 and arm64 architectures | `{}` |
| `affinity` | Affinity rules | `{}` |
| `tolerations` | List of tolerations | `[]` |
| `topologySpreadConstraints` | List of topology spread constraints for resilience | `[]` |
| `apiServerURL` | URL of the Tornjak APIs (backend). Since Tornjak Frontend runs in the browser, this URL must be accessible from the machine running a browser. If not provided, auto-detection is attempted. | `""` |
| `spireHealthCheck.enabled` | Enables the SPIRE Healthchecker indicator | `true` |
| `auth.enabled` | Enables auth for Tornjak | `false` |
| `auth.serverURL` | URL of the Auth service. Tornjak Frontend will redirect to this URL to authenticate the user | `""` |
| `startupProbe.enabled` | Enable startupProbe on Tornjak frontend container | `true` |
| `startupProbe.initialDelaySeconds` | Initial delay seconds for startupProbe | `5` |
| `startupProbe.periodSeconds` | Period seconds for startupProbe | `10` |
| `startupProbe.timeoutSeconds` | Timeout seconds for startupProbe | `5` |
| `startupProbe.failureThreshold` | Failure threshold count for startupProbe | `6` |
| `startupProbe.successThreshold` | Success threshold count for startupProbe | `1` |
| `workingDir` | Set to override the default path containing the Tornjak frontend within the image | `""` |
| `logsDir` | Directory path for NPM logs | `/home/node/` |
| `ingress.enabled` | Flag to enable ingress for Tornjak frontend service | `false` |
| `ingress.className` | Ingress class name for Tornjak frontend service | `""` |
| `ingress.controllerType` | Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, auto-detection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. | `""` |
| `ingress.annotations` | Annotations for Tornjak frontend service | `{}` |
| `ingress.host` | Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. | `tornjak-frontend` |
| `ingress.tlsSecret` | Secret that has the certs. If blank will use default certs. Used with host var. | `""` |
| `ingress.hosts` | Host paths for ingress object. If empty, rules will be built based on the host var. | `[]` |
| `ingress.tls` | Secrets containing TLS certs to enable https on ingress. If empty, rules will be built based on the host and tlsSecret vars. | `[]` |
| `tests.bash.image.registry` | The OCI registry to pull the image from | `cgr.dev` |
| `tests.bash.image.repository` | The repository within the registry | `chainguard/bash` |
| `tests.bash.image.pullPolicy` | The image pull policy | `IfNotPresent` |
| `tests.bash.image.tag` | Overrides the image tag whose default is the chart appVersion | `latest@sha256:a0383e176104e7840387deb9fda1782660e903654f39acf62931e2c9a60b7fe1` |