Zurück zum Hub

cargo.ayedo.cloud/ayedo/k8s/authentik

Registry-Block

polycrate block pull cargo.ayedo.cloud/ayedo/k8s/authentik:0.6.4

Authentik

Dieser Block installiert Authentik in Kubernetes.


Upgrade auf Block 0.6.1

Repo von OCI auf das Offizielle Repo umgestellt

  • https://charts.goauthentik.io/

      chart:
        auth:
          enabled: true
          username: *mirror_registry_auth_user
          password: *mirror_registry_auth_password
          registry: *mirror_registry_url
wurde aus dem Beispiel Block entfernt

UPGRADE auf Block 0.2.0

Postgres Backup + Restore

  • Worker und Server auf 0 skalieren
  • Shell in postgres pod starten
  • cd /bitnami/postgresql/
  • PGPASSWORD=$POSTGRES_PASSWORD pg_dump -U $POSTGRES_USER $POSTGRES_DB > authentik-backup.sql (password steht im authentik-postgresql Secret)
  • Backup vom pod lokal sichern. Bspw. mit kubectl cp -n authentik authentik-postgresql-0:/bitnami/postgresql/authentik-backup.sql authentik-backup.sql

  • CloudnativePG Datenbank mit User authentik und Datenbank authentik anlegen.

  • Anschließend das Backup in den CNPG Postgres Pod hochladen kubectl cp -n authentik authentik-backup.sql authentik-db-1:/var/lib/postgresql/data/authentik-backup.sql
  • Shell in CNPG postgres starten
  • cd /var/lib/postgresql/data
  • cat authentik-backup.sql | psql -d authentik -U authentik -h 127.0.0.1
  • echo $? Exit Status sollte 0 sein. Anschließend das Block Update installieren.
  • Ggf. muss der redis pod einmal gelöscht werden.

actions

install

blocks:
  - name: authentik
    from: cargo.ayedo.cloud/ayedo/k8s/authentik
    kubeconfig:
      from: k8s
    config:
      secret_key: <random_key_here>
      auth:
        password: <random_password_here>
        token: <random_token_here>
      log_level: debug
      ingress:
        host: id.example.com
        enabled: true
        tls:
          enabled: true
      postgresql:
        hostname: authentik-db-rw.authentik.svc.cluster.local
        password: <cnpg_authentik_password_here>

### Beispiel Datenbank mit CNPG
  - name: cnpg-operator
    from: cargo.ayedo.cloud/ayedo/k8s/cloudnative-pg
    kubeconfig:
      from: k8s
    config:
      namespace: cloudnative-pg
      operator:
        enabled: true
        replicas: 2

  - name: authentik-db
    from: cargo.ayedo.cloud/ayedo/k8s/cloudnative-pg
    kubeconfig:
      from: k8s
    config:
      namespace: authentik
      cluster:
        enabled: true
        resources:
          requests:
            memory: "1Gi"
            cpu: "500m"
          limits:
            memory: "2Gi"
        monitoring:
          vmpodscrape:
            enabled: true
        instances: 1
        postgresql:
          # image: ghcr.io/cloudnative-pg/postgresql:16.4 # default
          parameters:
            archive_mode: "on"
            wal_keep_size: 1GB
            wal_log_hints: "on"
            wal_receiver_timeout: 30s
            wal_sender_timeout: 30s
            wal_compression: "on"
            log_min_duration_statement: "5000"
            shared_buffers: 1GB # should be 25% of available memory for DB
            work_mem: 16MB
            maintenance_work_mem: 128MB
            max_connections: "1500"
        initdb:
          database: app
          owner: app
        databases:
          - name: authentik
        roles:
          - name: authentik
            password: <cnpg_authentik_password_here>
            ensure: present
            comment: Authentik DB User
        storage:
          size: 10Gi
          class: ""
        walstorage:
          size: 10Gi
          class: ""
        pooler:
          enabled: false
        backup:
          enabled: true
          retention: "30d"
          schedule:
            enabled: true
            cron: "0 15 20 * * *"
          s3:
            endpoint: https://s3.example.com
            bucket: "authentik-backup"
            key: "authentik-backup"
            secret: "<secret-here>"