Authentik
Dieser Block installiert Authentik in Kubernetes.
Upgrade auf Block 0.6.1
Repo von OCI auf das Offizielle Repo umgestellt
- https://charts.goauthentik.io/
chart:
auth:
enabled: true
username: *mirror_registry_auth_user
password: *mirror_registry_auth_password
registry: *mirror_registry_url
UPGRADE auf Block 0.2.0
Postgres Backup + Restore
- Worker und Server auf 0 skalieren
- Shell in postgres pod starten
cd /bitnami/postgresql/PGPASSWORD=$POSTGRES_PASSWORD pg_dump -U $POSTGRES_USER $POSTGRES_DB > authentik-backup.sql(passwordsteht imauthentik-postgresqlSecret)-
Backup vom pod lokal sichern. Bspw. mit
kubectl cp -n authentik authentik-postgresql-0:/bitnami/postgresql/authentik-backup.sql authentik-backup.sql -
CloudnativePG Datenbank mit User
authentikund Datenbankauthentikanlegen. - Anschließend das Backup in den CNPG Postgres Pod hochladen
kubectl cp -n authentik authentik-backup.sql authentik-db-1:/var/lib/postgresql/data/authentik-backup.sql - Shell in CNPG postgres starten
cd /var/lib/postgresql/datacat authentik-backup.sql | psql -d authentik -U authentik -h 127.0.0.1echo $?Exit Status sollte0sein. Anschließend das Block Update installieren.- Ggf. muss der redis pod einmal gelöscht werden.
actions
install
blocks:
- name: authentik
from: cargo.ayedo.cloud/ayedo/k8s/authentik
kubeconfig:
from: k8s
config:
secret_key: <random_key_here>
auth:
password: <random_password_here>
token: <random_token_here>
log_level: debug
ingress:
host: id.example.com
enabled: true
tls:
enabled: true
postgresql:
hostname: authentik-db-rw.authentik.svc.cluster.local
password: <cnpg_authentik_password_here>
### Beispiel Datenbank mit CNPG
- name: cnpg-operator
from: cargo.ayedo.cloud/ayedo/k8s/cloudnative-pg
kubeconfig:
from: k8s
config:
namespace: cloudnative-pg
operator:
enabled: true
replicas: 2
- name: authentik-db
from: cargo.ayedo.cloud/ayedo/k8s/cloudnative-pg
kubeconfig:
from: k8s
config:
namespace: authentik
cluster:
enabled: true
resources:
requests:
memory: "1Gi"
cpu: "500m"
limits:
memory: "2Gi"
monitoring:
vmpodscrape:
enabled: true
instances: 1
postgresql:
# image: ghcr.io/cloudnative-pg/postgresql:16.4 # default
parameters:
archive_mode: "on"
wal_keep_size: 1GB
wal_log_hints: "on"
wal_receiver_timeout: 30s
wal_sender_timeout: 30s
wal_compression: "on"
log_min_duration_statement: "5000"
shared_buffers: 1GB # should be 25% of available memory for DB
work_mem: 16MB
maintenance_work_mem: 128MB
max_connections: "1500"
initdb:
database: app
owner: app
databases:
- name: authentik
roles:
- name: authentik
password: <cnpg_authentik_password_here>
ensure: present
comment: Authentik DB User
storage:
size: 10Gi
class: ""
walstorage:
size: 10Gi
class: ""
pooler:
enabled: false
backup:
enabled: true
retention: "30d"
schedule:
enabled: true
cron: "0 15 20 * * *"
s3:
endpoint: https://s3.example.com
bucket: "authentik-backup"
key: "authentik-backup"
secret: "<secret-here>"