Compare commits
7
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f44d4349a7 | ||
|
|
9368ac559e | ||
|
|
fef75ad34f
|
||
|
|
0c7728fe0b
|
||
|
|
a4e2c60346 | ||
|
|
746d326292 | ||
|
|
4a6b5c8a1d
|
@@ -8,8 +8,15 @@ metadata:
|
||||
backstage.io/kubernetes-id: homelab-backstage
|
||||
spec:
|
||||
replicas: 1
|
||||
# Backstage is multi-instance safe (scheduler locks, event bus, and auth keys
|
||||
# live in PostgreSQL), so surge one new pod and keep the old one serving
|
||||
# until it is ready. Migrations run on the new pod while the old one still
|
||||
# serves; revisit if an upgrade ships a backward-incompatible migration.
|
||||
strategy:
|
||||
type: Recreate
|
||||
type: RollingUpdate
|
||||
rollingUpdate:
|
||||
maxSurge: 1
|
||||
maxUnavailable: 0
|
||||
selector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/name: backstage
|
||||
@@ -27,7 +34,7 @@ spec:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: backstage
|
||||
image: zot.ad.ddupan.top/panxiao81/backstage:latest@sha256:da55be5c2f5c8b33de2d87ee0ef02edeacf52a349c8b19a5fac9be4152b2723d # {"$imagepolicy": "flux-system:backstage"}
|
||||
image: zot.ad.ddupan.top/panxiao81/backstage:latest@sha256:476b40ea5cdf7301edb4f5dab5a012686a0009d1b0f1fce21fab34b969543ebb # {"$imagepolicy": "flux-system:backstage"}
|
||||
imagePullPolicy: IfNotPresent
|
||||
env:
|
||||
- name: BACKSTAGE_BASE_URL
|
||||
|
||||
@@ -27,9 +27,10 @@ Hydra 回调为 `/oauth2/start`、`/oauth2/consent`、`/oauth2/logout`;默认
|
||||
|
||||
### 客户端管理 `/console`
|
||||
|
||||
iam-login 的客户端管理 API 只接受 Hydra 签发、带 `iam.clients.manage` scope 的 access token;
|
||||
`/console` 是调用该 API 的前端,在 Hydra 中登记为普通 **public** 客户端 `iam-admin-ui`。
|
||||
该 scope 只在 consent 时发给 `iam-admin-ui` 且直接属于管理组的用户,规则在 iam-login。
|
||||
iam-login 的客户端管理 API 是普通 resource server:只接受 Hydra 签发、`aud` 含 `iam-login`
|
||||
且 `groups` 含管理组的 access token。`/console` 是调用该 API 的前端,在 Hydra 中登记为普通
|
||||
**public** 客户端 `iam-admin-ui`;只有它被允许申请 audience `iam-login`(Hydra 按客户端登记的
|
||||
audience 白名单执行),所以其他应用拿到的管理员 token 不能调用该 API。
|
||||
|
||||
浏览器直接向 Hydra 换取 token,因此 `hydra.yaml` 为 public 端口开启 CORS,只允许开发实例
|
||||
origin;不放行 cookie 凭据。Gitea 等服务端客户端不受影响。
|
||||
@@ -42,11 +43,11 @@ curl -fsS -X POST http://127.0.0.1:18445/admin/clients -H 'Content-Type: applica
|
||||
"client_id": "iam-admin-ui", "client_name": "IAM 管理",
|
||||
"redirect_uris": ["https://laptop.tail7e769.ts.net:18082/console/callback"],
|
||||
"grant_types": ["authorization_code"], "response_types": ["code"],
|
||||
"scope": "openid iam.clients.manage", "token_endpoint_auth_method": "none",
|
||||
"scope": "openid groups", "audience": ["iam-login"], "token_endpoint_auth_method": "none",
|
||||
"subject_type": "public", "metadata": {"iam_login_enabled": true}}'
|
||||
```
|
||||
|
||||
开发实例另需 `iam.clients.admin-ui-client-id=iam-admin-ui`;未配置时 `/console` 不提供,API
|
||||
开发实例另需 `iam.clients.admin-ui-client-id=iam-admin-ui` 与 `iam.clients.admin-groups`(组名);未配置时 `/console` 不提供,API
|
||||
无法获得可用 token(fail closed)。
|
||||
|
||||
从 Gitea `/user/oauth2/hydra` 发起,应进入新密码/Passkey 页,确认授权后返回原账号,核对
|
||||
|
||||
+5
-2
@@ -26,8 +26,11 @@ SPIRE 认证链路已经验证,但当前没有常驻 publisher 或删除授权
|
||||
`/var/lib/registry` 是 `emptyDir`,仅用于运行时本地工作数据。
|
||||
|
||||
两个单副本实例共用同一 bucket 和前缀:`zot` 负责鉴权写入,`zot-reader` 负责匿名
|
||||
读取。关闭跨仓库 dedupe,不额外部署 Redis/DynamoDB 缓存。只有写入实例启用 GC,
|
||||
暂不配置自动删除已发布版本的 retention policy。增加副本、启用 dedupe 或搜索等
|
||||
读取。关闭跨仓库 dedupe,不额外部署 Redis/DynamoDB 缓存。只有写入实例启用 GC。
|
||||
retention policy 只针对 `panxiao81/backstage`:仅保留 `latest`,历史 sha tag 与失去
|
||||
tag 的 digest 在 24h 后回收(dev 镜像由 Flux 跟踪 `latest` 的 digest)。其余仓库由
|
||||
`**` 兜底策略保留全部 tag,行为与未配置 retention 时一致;新增按仓库的清理规则时,
|
||||
必须放在兜底策略之前,否则不会生效。增加副本、启用 dedupe 或搜索等
|
||||
扩展前,需要重新检查共享元数据与缓存的持久化要求。
|
||||
|
||||
凭据链路:
|
||||
|
||||
@@ -27,6 +27,21 @@ configFiles:
|
||||
"gc": true,
|
||||
"gcDelay": "24h",
|
||||
"gcInterval": "24h",
|
||||
"retention": {
|
||||
"delay": "24h",
|
||||
"policies": [
|
||||
{
|
||||
"repositories": ["panxiao81/backstage"],
|
||||
"deleteUntagged": true,
|
||||
"keepTags": [{ "patterns": ["^latest$"] }]
|
||||
},
|
||||
{
|
||||
"repositories": ["**"],
|
||||
"deleteUntagged": true,
|
||||
"keepTags": [{ "patterns": [".*"] }]
|
||||
}
|
||||
]
|
||||
},
|
||||
"storageDriver": {
|
||||
"name": "s3",
|
||||
"region": "us-east-1",
|
||||
|
||||
Reference in New Issue
Block a user