Compare commits
6 Commits
01a7f5a821
...
f/oidc-tes
Author | SHA1 | Date | |
---|---|---|---|
7dedf3f7e5 | |||
0ea5fd9141 | |||
c97266c272 | |||
4df11ead1e | |||
99056b875e | |||
ee0349e9df |
@ -16,6 +16,7 @@ configMapGenerator:
|
|||||||
- WERTHER_LDAP_ENDPOINTS="ldap.test.fr:636"
|
- WERTHER_LDAP_ENDPOINTS="ldap.test.fr:636"
|
||||||
- WERTHER_LDAP_IS_TLS=true
|
- WERTHER_LDAP_IS_TLS=true
|
||||||
- WERTHER_LDAP_BASEDN="o=test,c=fr"
|
- WERTHER_LDAP_BASEDN="o=test,c=fr"
|
||||||
|
- WERTHER_LDAP_ATTR_CLAIMS="name:name,sn:family_name,givenName:given_name,mail:email"
|
||||||
- WERTHER_LDAP_ROLE_BASEDN="ou=groups,o=test,c=fr"
|
- WERTHER_LDAP_ROLE_BASEDN="ou=groups,o=test,c=fr"
|
||||||
- WERTHER_LDAP_CONNECTION_TIMEOUT="10s"
|
- WERTHER_LDAP_CONNECTION_TIMEOUT="10s"
|
||||||
|
|
||||||
|
@ -19,7 +19,7 @@ spec:
|
|||||||
containers:
|
containers:
|
||||||
- name: hydra-oidc-php-fpm
|
- name: hydra-oidc-php-fpm
|
||||||
image: reg.cadoles.com/cadoles/hydra-oidc-base:2024.4.2-develop.1349.c4711f6
|
image: reg.cadoles.com/cadoles/hydra-oidc-base:2024.4.2-develop.1349.c4711f6
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: IfNotPresent
|
||||||
args: ["/usr/sbin/php-fpm81", "-F", "-e"]
|
args: ["/usr/sbin/php-fpm81", "-F", "-e"]
|
||||||
readinessProbe:
|
readinessProbe:
|
||||||
exec:
|
exec:
|
||||||
@ -53,7 +53,7 @@ spec:
|
|||||||
|
|
||||||
- name: hydra-oidc-caddy
|
- name: hydra-oidc-caddy
|
||||||
image: reg.cadoles.com/cadoles/hydra-oidc-base:2024.4.2-develop.1349.c4711f6
|
image: reg.cadoles.com/cadoles/hydra-oidc-base:2024.4.2-develop.1349.c4711f6
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: IfNotPresent
|
||||||
args:
|
args:
|
||||||
[
|
[
|
||||||
"/usr/sbin/caddy",
|
"/usr/sbin/caddy",
|
||||||
|
7
components/hydra-sql/files/sql_login.yaml
Normal file
7
components/hydra-sql/files/sql_login.yaml
Normal file
@ -0,0 +1,7 @@
|
|||||||
|
sql_login:
|
||||||
|
login_column_name: mail
|
||||||
|
password_column_name: password
|
||||||
|
salt_column_name: salt
|
||||||
|
table_name: user
|
||||||
|
data_to_fetch:
|
||||||
|
- mail
|
@ -24,6 +24,9 @@ configMapGenerator:
|
|||||||
- DB_PASSWORD="makeMeASecret"
|
- DB_PASSWORD="makeMeASecret"
|
||||||
- REDIS_DSN="redis://redis:6379"
|
- REDIS_DSN="redis://redis:6379"
|
||||||
- PEPPER="MakeMeABigSecret"
|
- PEPPER="MakeMeABigSecret"
|
||||||
|
- name: sql-login-config
|
||||||
|
files:
|
||||||
|
- ./files/sql_login.yaml
|
||||||
- name: hydra-sql-php-ini
|
- name: hydra-sql-php-ini
|
||||||
files:
|
files:
|
||||||
- ./files/03_base.ini
|
- ./files/03_base.ini
|
||||||
|
@ -21,8 +21,8 @@ spec:
|
|||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- name: hydra-sql-fpm
|
- name: hydra-sql-fpm
|
||||||
image: reg.cadoles.com/cadoles/hydra-sql-base:2024.10.14-develop.1040.7032787
|
image: reg.cadoles.com/cadoles/hydra-sql-base:2024.11.6-develop.1113.075be9b
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: IfNotPresent
|
||||||
args: ["/usr/sbin/php-fpm81", "-F", "-e"]
|
args: ["/usr/sbin/php-fpm81", "-F", "-e"]
|
||||||
readinessProbe:
|
readinessProbe:
|
||||||
exec:
|
exec:
|
||||||
@ -60,13 +60,16 @@ spec:
|
|||||||
- name: OPCACHE_REVALIDATE_FREQ
|
- name: OPCACHE_REVALIDATE_FREQ
|
||||||
value: "0"
|
value: "0"
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
|
- name: sql-login-config
|
||||||
|
mountPath: "/app/config/sql_login_configuration/sql_login.yaml"
|
||||||
|
subPath: "sql_login.yaml"
|
||||||
- name: hydra-sql-php-ini
|
- name: hydra-sql-php-ini
|
||||||
mountPath: /etc/php81/conf.d/03_base.ini
|
mountPath: /etc/php81/conf.d/03_base.ini
|
||||||
subPath: 03_base.ini
|
subPath: 03_base.ini
|
||||||
|
|
||||||
- name: hydra-sql-caddy
|
- name: hydra-sql-caddy
|
||||||
image: reg.cadoles.com/cadoles/hydra-sql-base:2024.10.14-develop.1040.7032787
|
image: reg.cadoles.com/cadoles/hydra-sql-base:2024.11.6-develop.1113.075be9b
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: IfNotPresent
|
||||||
args: ["/usr/sbin/caddy", "run", "--adapter", "caddyfile", "--config", "/etc/caddy/Caddyfile"]
|
args: ["/usr/sbin/caddy", "run", "--adapter", "caddyfile", "--config", "/etc/caddy/Caddyfile"]
|
||||||
readinessProbe:
|
readinessProbe:
|
||||||
httpGet:
|
httpGet:
|
||||||
@ -104,7 +107,14 @@ spec:
|
|||||||
ports:
|
ports:
|
||||||
- containerPort: 8080
|
- containerPort: 8080
|
||||||
name: http
|
name: http
|
||||||
|
volumeMounts:
|
||||||
|
- name: sql-login-config
|
||||||
|
mountPath: "/app/config/sql_login_configuration/sql_login.yaml"
|
||||||
|
subPath: "sql_login.yaml"
|
||||||
volumes:
|
volumes:
|
||||||
|
- name: sql-login-config
|
||||||
|
configMap:
|
||||||
|
name: sql-login-config
|
||||||
- name: hydra-sql-php-ini
|
- name: hydra-sql-php-ini
|
||||||
configMap:
|
configMap:
|
||||||
name: hydra-sql-php-ini
|
name: hydra-sql-php-ini
|
||||||
|
@ -17,4 +17,5 @@ configMapGenerator:
|
|||||||
- OIDC_REDIRECT_URL=https://example.net/oauth2/callback
|
- OIDC_REDIRECT_URL=https://example.net/oauth2/callback
|
||||||
- OIDC_POST_LOGOUT_REDIRECT_URL=https://example.net
|
- OIDC_POST_LOGOUT_REDIRECT_URL=https://example.net
|
||||||
- OIDC_SKIP_ISSUER_VERIFICATION="true"
|
- OIDC_SKIP_ISSUER_VERIFICATION="true"
|
||||||
- OIDC_INSECURE_SKIP_VERIFY="true"
|
- OIDC_INSECURE_SKIP_VERIFY="true"
|
||||||
|
- OIDC_SCOPES="openid profile"
|
||||||
|
17
resources/hydra-dispatcher/files/hydra/default.yaml
Normal file
17
resources/hydra-dispatcher/files/hydra/default.yaml
Normal file
@ -0,0 +1,17 @@
|
|||||||
|
parameters:
|
||||||
|
env(HYDRA_DISPATCHER_WEBHOOK_ENABLED): false
|
||||||
|
env(HYDRA_DISPATCHER_WEBHOOK_API_URL): ""
|
||||||
|
env(HYDRA_DISPATCHER_WEBHOOK_API_KEY): ""
|
||||||
|
env(HYDRA_DISPATCHER_WEBHOOK_API_METHOD): POST
|
||||||
|
env(HYDRA_DISPATCHER_FIREWALL_ADDITIONAL_PROPERTIES): true
|
||||||
|
|
||||||
|
hydra:
|
||||||
|
apps: []
|
||||||
|
webhook:
|
||||||
|
enabled: "%env(bool:HYDRA_DISPATCHER_WEBHOOK_ENABLED)%"
|
||||||
|
api_url: "%env(string:HYDRA_DISPATCHER_WEBHOOK_API_URL)%"
|
||||||
|
api_key: "%env(string:HYDRA_DISPATCHER_WEBHOOK_API_KEY)%"
|
||||||
|
api_method: "%env(string:HYDRA_DISPATCHER_WEBHOOK_API_METHOD)%"
|
||||||
|
firewall:
|
||||||
|
additional_properties: "%env(bool:HYDRA_DISPATCHER_FIREWALL_ADDITIONAL_PROPERTIES)%"
|
||||||
|
rules: {}
|
@ -26,6 +26,9 @@ configMapGenerator:
|
|||||||
- DEFAULT_LOCALE=fr
|
- DEFAULT_LOCALE=fr
|
||||||
- APP_LOCALES=fr,en
|
- APP_LOCALES=fr,en
|
||||||
- REDIS_DSN="redis://redis:6379"
|
- REDIS_DSN="redis://redis:6379"
|
||||||
|
- name: hydra-dispatcher-apps
|
||||||
|
files:
|
||||||
|
- apps.yaml=./files/hydra/default.yaml
|
||||||
- name: hydra-dispatcher-php-ini
|
- name: hydra-dispatcher-php-ini
|
||||||
files:
|
files:
|
||||||
- ./files/03_base.ini
|
- ./files/03_base.ini
|
@ -49,6 +49,8 @@ spec:
|
|||||||
- configMapRef:
|
- configMapRef:
|
||||||
name: hydra-dispatcher-env
|
name: hydra-dispatcher-env
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
|
- mountPath: /app/config/hydra
|
||||||
|
name: hydra-dispatcher-apps
|
||||||
- name: hydra-dispatcher-php-ini
|
- name: hydra-dispatcher-php-ini
|
||||||
mountPath: /etc/php81/conf.d/03_base.ini
|
mountPath: /etc/php81/conf.d/03_base.ini
|
||||||
subPath: 03_base.ini
|
subPath: 03_base.ini
|
||||||
@ -59,7 +61,7 @@ spec:
|
|||||||
runAsUser: 1000
|
runAsUser: 1000
|
||||||
- name: hydra-dispatcher-caddy
|
- name: hydra-dispatcher-caddy
|
||||||
image: reg.cadoles.com/cadoles/hydra-dispatcher-base:2024.9.24-develop.1122.f88a5eb
|
image: reg.cadoles.com/cadoles/hydra-dispatcher-base:2024.9.24-develop.1122.f88a5eb
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: IfNotPresent
|
||||||
args:
|
args:
|
||||||
[
|
[
|
||||||
"/usr/sbin/caddy",
|
"/usr/sbin/caddy",
|
||||||
@ -107,6 +109,9 @@ spec:
|
|||||||
runAsUser: 1000
|
runAsUser: 1000
|
||||||
restartPolicy: Always
|
restartPolicy: Always
|
||||||
volumes:
|
volumes:
|
||||||
|
- name: hydra-dispatcher-apps
|
||||||
|
configMap:
|
||||||
|
name: hydra-dispatcher-apps
|
||||||
- name: hydra-dispatcher-php-ini
|
- name: hydra-dispatcher-php-ini
|
||||||
configMap:
|
configMap:
|
||||||
name: hydra-dispatcher-php-ini
|
name: hydra-dispatcher-php-ini
|
||||||
|
Reference in New Issue
Block a user