diff --git a/kubernetes/apps/authentication/dexidp/app/helmrelease.yaml b/kubernetes/apps/authentication/dexidp/app/helmrelease.yaml deleted file mode 100644 index 95b358bb..00000000 --- a/kubernetes/apps/authentication/dexidp/app/helmrelease.yaml +++ /dev/null @@ -1,115 +0,0 @@ ---- -# yaml-language-server: $schema=https://kubernetes-schemas.pages.dev/helm.toolkit.fluxcd.io/helmrelease_v2beta2.json -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: dex - namespace: authentication -spec: - interval: 5m - chart: - spec: - chart: dex - version: 0.23.0 - sourceRef: - kind: HelmRepository - name: dex - namespace: flux-system - interval: 5m - values: - image: - repository: ghcr.io/dexidp/dex - tag: v2.43.1@sha256:0881d3c9359b436d585b2061736ce271c100331e073be9178ef405ce5bf09557 - env: - KUBERNETES_POD_NAMESPACE: authentication - envFrom: - - secretRef: - name: github-oauth-client - - secretRef: - name: grafana-oauth - - secretRef: - name: outline-oauth - ingress: - enabled: true - className: nginx - annotations: - cert-manager.io/cluster-issuer: letsencrypt-production - hosts: - - host: &host auth.immich.cloud - paths: - - path: / - pathType: Prefix - tls: - - hosts: - - *host - secretName: dex-tls - - config: - issuer: &issuer https://auth.immich.cloud - - storage: - type: kubernetes - config: - inCluster: true - - web: - http: 0.0.0.0:5556 - - frontend: - issuer: immich - issuerUrl: *issuer - logoUrl: https://github.com/immich-app/immich/raw/main/design/immich-logo.png - - expiry: - signingKeys: "6h" - idTokens: "168h" - - logger: - level: debug - format: text - - oauth2: - responseTypes: ["code", "token", "id_token"] - skipApprovalScreen: true - alwaysShowLoginScreen: false - - enablePasswordDB: false - - connectors: - # GitHub configure 'OAuth Apps' -> 'New OAuth App', add callback URL - # https://github.com/settings/developers - - type: github - id: github - name: GitHub - config: - clientID: $GITHUB_CLIENT_ID - clientSecret: $GITHUB_CLIENT_SECRET - redirectURI: https://auth.immich.cloud/callback - orgs: - - name: immich-app - - staticClients: - - id: containerssh - name: containerssh - public: true - redirectURIs: - - "/device/callback" - - id: grafana - name: grafana - secretEnv: GRAFANA_OAUTH_CLIENT_SECRET - redirectURIs: - - "https://monitoring.immich.cloud/login/generic_oauth" - - "https://monitoring.dev.immich.cloud/login/generic_oauth" - - "https://grafana.data.immich.cloud/login/generic_oauth" - - id: outline - name: outline - secretEnv: OIDC_CLIENT_SECRET - redirectURIs: - - "https://outline.immich.cloud/auth/oidc.callback" - - resources: - requests: - cpu: 10m - memory: 100Mi - limits: - memory: 100Mi diff --git a/kubernetes/apps/authentication/dexidp/app/secrets.yaml b/kubernetes/apps/authentication/dexidp/app/secrets.yaml deleted file mode 100644 index b4769a36..00000000 --- a/kubernetes/apps/authentication/dexidp/app/secrets.yaml +++ /dev/null @@ -1,23 +0,0 @@ -apiVersion: onepassword.com/v1 -kind: OnePasswordItem -metadata: - name: github-oauth-client - namespace: authentication -spec: - itemPath: "vaults/Kubernetes/items/github-oauth-client" ---- -apiVersion: onepassword.com/v1 -kind: OnePasswordItem -metadata: - name: grafana-oauth - namespace: authentication -spec: - itemPath: "vaults/Kubernetes/items/grafana-oauth-client-secret" ---- -apiVersion: onepassword.com/v1 -kind: OnePasswordItem -metadata: - name: outline-oauth - namespace: authentication -spec: - itemPath: "vaults/Kubernetes/items/outline-secret" diff --git a/kubernetes/apps/authentication/dexidp/ks.yaml b/kubernetes/apps/authentication/dexidp/ks.yaml deleted file mode 100644 index 94dfce78..00000000 --- a/kubernetes/apps/authentication/dexidp/ks.yaml +++ /dev/null @@ -1,23 +0,0 @@ ---- -# yaml-language-server: $schema=https://github.com/fluxcd-community/flux2-schemas/raw/main/kustomization-kustomize-v1.json -apiVersion: kustomize.toolkit.fluxcd.io/v1 -kind: Kustomization -metadata: - name: &app dexidp - namespace: flux-system -spec: - targetNamespace: authentication - commonMetadata: - labels: - app.kubernetes.io/name: *app - dependsOn: - - name: cluster-apps-onepassword - path: ./kubernetes/apps/authentication/dexidp/app - prune: true - sourceRef: - kind: GitRepository - name: immich-kubernetes - wait: true - interval: 30m - retryInterval: 1m - timeout: 5m diff --git a/kubernetes/apps/authentication/kustomization.yaml b/kubernetes/apps/authentication/kustomization.yaml index d6ac8056..f7486bb8 100644 --- a/kubernetes/apps/authentication/kustomization.yaml +++ b/kubernetes/apps/authentication/kustomization.yaml @@ -3,5 +3,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - ./namespace.yaml - - ./dexidp/ks.yaml - ./zitadel/ks.yaml diff --git a/kubernetes/apps/monitoring-dev/grafana/ks.yaml b/kubernetes/apps/monitoring-dev/grafana/ks.yaml index 5733f421..8f59eafc 100644 --- a/kubernetes/apps/monitoring-dev/grafana/ks.yaml +++ b/kubernetes/apps/monitoring-dev/grafana/ks.yaml @@ -17,7 +17,8 @@ spec: retryInterval: 1m timeout: 5m dependsOn: - - name: cluster-apps-onepassword + - name: external-secrets-stores + - name: zitadel --- apiVersion: kustomize.toolkit.fluxcd.io/v1 kind: Kustomization diff --git a/kubernetes/apps/monitoring/grafana/app/grafana.yaml b/kubernetes/apps/monitoring/grafana/app/grafana.yaml index 63102ebe..1b1c1904 100644 --- a/kubernetes/apps/monitoring/grafana/app/grafana.yaml +++ b/kubernetes/apps/monitoring/grafana/app/grafana.yaml @@ -11,13 +11,14 @@ spec: root_url: https://monitoring.immich.cloud/ auth.generic_oauth: enabled: "true" - client_id: grafana - client_secret: ${GRAFANA_OAUTH_CLIENT_SECRET} + client_id: ${quote}${GRAFANA_OAUTH_CLIENT_ID}${quote} + client_secret: '' + use_pkce: "true" scopes: openid email profile groups offline_access - auth_url: https://auth.immich.cloud/auth - token_url: https://auth.immich.cloud/token - api_url: https://auth.immich.cloud/userinfo - role_attribute_path: contains(groups[*], 'immich-app:Admins') && 'GrafanaAdmin' || 'Viewer' + auth_url: https://zitadel.internal.immich.cloud/oauth/v2/authorize + token_url: https://zitadel.internal.immich.cloud/oauth/v2/token + api_url: https://zitadel.internal.immich.cloud/oidc/v1/userinfo + role_attribute_path: role allow_assign_grafana_admin: "true" auto_login: "true" users: diff --git a/kubernetes/apps/monitoring/grafana/ks.yaml b/kubernetes/apps/monitoring/grafana/ks.yaml index e2dbedfc..5aa260af 100644 --- a/kubernetes/apps/monitoring/grafana/ks.yaml +++ b/kubernetes/apps/monitoring/grafana/ks.yaml @@ -17,7 +17,8 @@ spec: retryInterval: 1m timeout: 5m dependsOn: - - name: cluster-apps-onepassword + - name: external-secrets-stores + - name: zitadel --- apiVersion: kustomize.toolkit.fluxcd.io/v1 kind: Kustomization @@ -44,4 +45,6 @@ spec: postBuild: substituteFrom: - kind: Secret - name: grafana-oauth + name: grafana-prod-oauth-clientid + substitute: + quote: '"' diff --git a/kubernetes/apps/monitoring/grafana/secrets/oauth.yaml b/kubernetes/apps/monitoring/grafana/secrets/oauth.yaml index d03d0e34..d31d70af 100644 --- a/kubernetes/apps/monitoring/grafana/secrets/oauth.yaml +++ b/kubernetes/apps/monitoring/grafana/secrets/oauth.yaml @@ -1,7 +1,14 @@ -apiVersion: onepassword.com/v1 -kind: OnePasswordItem +apiVersion: external-secrets.io/v1 +kind: ExternalSecret metadata: - name: grafana-oauth + name: grafana-prod-oauth-clientid namespace: flux-system spec: - itemPath: "vaults/Kubernetes/items/grafana-oauth-client-secret" + secretStoreRef: + kind: ClusterSecretStore + name: 1p-tf + refreshInterval: "20s" + data: + - secretKey: GRAFANA_OAUTH_CLIENT_ID + remoteRef: + key: ZITADEL_OAUTH_CLIENT_ID_GRAFANA_MONITORING_PROD diff --git a/kubernetes/apps/pipelines/data/grafana/app/grafana.yaml b/kubernetes/apps/pipelines/data/grafana/app/grafana.yaml index 2762406b..f32ce789 100644 --- a/kubernetes/apps/pipelines/data/grafana/app/grafana.yaml +++ b/kubernetes/apps/pipelines/data/grafana/app/grafana.yaml @@ -11,13 +11,14 @@ spec: root_url: https://grafana.data.immich.cloud/ auth.generic_oauth: enabled: "true" - client_id: grafana - client_secret: ${GRAFANA_OAUTH_CLIENT_SECRET} + client_id: ${quote}${GRAFANA_OAUTH_CLIENT_ID}${quote} + client_secret: '' + use_pkce: "true" scopes: openid email profile groups offline_access - auth_url: https://auth.immich.cloud/auth - token_url: https://auth.immich.cloud/token - api_url: https://auth.immich.cloud/userinfo - role_attribute_path: contains(groups[*], 'immich-app:Admins') && 'GrafanaAdmin' || 'Viewer' + auth_url: https://zitadel.internal.immich.cloud/oauth/v2/authorize + token_url: https://zitadel.internal.immich.cloud/oauth/v2/token + api_url: https://zitadel.internal.immich.cloud/oidc/v1/userinfo + role_attribute_path: role allow_assign_grafana_admin: "true" auto_login: "true" users: diff --git a/kubernetes/apps/pipelines/data/grafana/ks.yaml b/kubernetes/apps/pipelines/data/grafana/ks.yaml index 5bb36122..85de2e16 100644 --- a/kubernetes/apps/pipelines/data/grafana/ks.yaml +++ b/kubernetes/apps/pipelines/data/grafana/ks.yaml @@ -17,7 +17,8 @@ spec: retryInterval: 1m timeout: 5m dependsOn: - - name: cluster-apps-onepassword + - name: external-secrets-stores + - name: zitadel --- apiVersion: kustomize.toolkit.fluxcd.io/v1 kind: Kustomization @@ -44,4 +45,6 @@ spec: postBuild: substituteFrom: - kind: Secret - name: data-pipeline-grafana-oauth + name: grafana-data-pipeline-oauth-clientid + substitute: + quote: '"' diff --git a/kubernetes/apps/pipelines/data/grafana/secrets/oauth.yaml b/kubernetes/apps/pipelines/data/grafana/secrets/oauth.yaml index f085a1d0..0828e5a7 100644 --- a/kubernetes/apps/pipelines/data/grafana/secrets/oauth.yaml +++ b/kubernetes/apps/pipelines/data/grafana/secrets/oauth.yaml @@ -1,7 +1,14 @@ -apiVersion: onepassword.com/v1 -kind: OnePasswordItem +apiVersion: external-secrets.io/v1 +kind: ExternalSecret metadata: - name: data-pipeline-grafana-oauth + name: grafana-data-pipeline-oauth-clientid namespace: flux-system spec: - itemPath: "vaults/Kubernetes/items/grafana-oauth-client-secret" + secretStoreRef: + kind: ClusterSecretStore + name: 1p-tf + refreshInterval: "20s" + data: + - secretKey: GRAFANA_OAUTH_CLIENT_ID + remoteRef: + key: ZITADEL_OAUTH_CLIENT_ID_GRAFANA_DATA_PROD diff --git a/kubernetes/apps/tools/containerssh/app/config.yaml b/kubernetes/apps/tools/containerssh/app/config.yaml index 537556f1..2845adb3 100644 --- a/kubernetes/apps/tools/containerssh/app/config.yaml +++ b/kubernetes/apps/tools/containerssh/app/config.yaml @@ -14,11 +14,11 @@ data: keyboardInteractive: method: oauth2 oauth2: - clientId: "containerssh" + clientId: ${quote}${OAUTH_CLIENT_ID}${quote} clientSecret: "ignored" provider: oidc oidc: - url: http://dex.authentication:5556/ + url: http://zitadel.authentication:8080/ deviceFlow: true backend: kubernetes kubernetes: diff --git a/kubernetes/apps/tools/containerssh/app/kustomization.yaml b/kubernetes/apps/tools/containerssh/app/kustomization.yaml index ac6be752..031dc4a0 100644 --- a/kubernetes/apps/tools/containerssh/app/kustomization.yaml +++ b/kubernetes/apps/tools/containerssh/app/kustomization.yaml @@ -2,7 +2,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - secrets.yaml - config.yaml - netpol.yaml - rbac.yaml diff --git a/kubernetes/apps/tools/containerssh/ks.yaml b/kubernetes/apps/tools/containerssh/ks.yaml index e26c9d05..617ee660 100644 --- a/kubernetes/apps/tools/containerssh/ks.yaml +++ b/kubernetes/apps/tools/containerssh/ks.yaml @@ -1,5 +1,25 @@ +apiVersion: kustomize.toolkit.fluxcd.io/v1 +kind: Kustomization +metadata: + name: &app containerssh-secrets + namespace: flux-system +spec: + commonMetadata: + labels: + app.kubernetes.io/name: *app + dependsOn: + - name: external-secrets-stores + - name: zitadel + path: ./kubernetes/apps/tools/containerssh/secrets + prune: true + sourceRef: + kind: GitRepository + name: immich-kubernetes + wait: true + interval: 30m + retryInterval: 1m + timeout: 5m --- -# yaml-language-server: $schema=https://github.com/fluxcd-community/flux2-schemas/raw/main/kustomization-kustomize-v1.json apiVersion: kustomize.toolkit.fluxcd.io/v1 kind: Kustomization metadata: @@ -10,8 +30,7 @@ spec: labels: app.kubernetes.io/name: *app dependsOn: - - name: cluster-apps-onepassword - - name: dexidp + - name: containerssh-secrets path: ./kubernetes/apps/tools/containerssh/app prune: true sourceRef: @@ -21,3 +40,9 @@ spec: interval: 30m retryInterval: 1m timeout: 5m + postBuild: + substituteFrom: + - kind: Secret + name: containerssh-oauth-clientid + substitute: + quote: '"' diff --git a/kubernetes/apps/tools/containerssh/app/secrets.yaml b/kubernetes/apps/tools/containerssh/secrets/host-key.yaml similarity index 100% rename from kubernetes/apps/tools/containerssh/app/secrets.yaml rename to kubernetes/apps/tools/containerssh/secrets/host-key.yaml diff --git a/kubernetes/apps/authentication/dexidp/app/kustomization.yaml b/kubernetes/apps/tools/containerssh/secrets/kustomization.yaml similarity index 65% rename from kubernetes/apps/authentication/dexidp/app/kustomization.yaml rename to kubernetes/apps/tools/containerssh/secrets/kustomization.yaml index d0d9f35f..efa234d8 100644 --- a/kubernetes/apps/authentication/dexidp/app/kustomization.yaml +++ b/kubernetes/apps/tools/containerssh/secrets/kustomization.yaml @@ -2,5 +2,5 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - ./secrets.yaml - - ./helmrelease.yaml \ No newline at end of file + - ./host-key.yaml + - ./oauth.yaml diff --git a/kubernetes/apps/tools/containerssh/secrets/oauth.yaml b/kubernetes/apps/tools/containerssh/secrets/oauth.yaml new file mode 100644 index 00000000..a407fe06 --- /dev/null +++ b/kubernetes/apps/tools/containerssh/secrets/oauth.yaml @@ -0,0 +1,14 @@ +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: containerssh-oauth-clientid + namespace: flux-system +spec: + secretStoreRef: + kind: ClusterSecretStore + name: 1p-tf + refreshInterval: "20s" + data: + - secretKey: OAUTH_CLIENT_ID + remoteRef: + key: ZITADEL_OAUTH_CLIENT_ID_CONTAINERSSH diff --git a/kubernetes/apps/tools/outline/app/helmrelease.yaml b/kubernetes/apps/tools/outline/app/helmrelease.yaml index e7a8e2c8..697cebb1 100644 --- a/kubernetes/apps/tools/outline/app/helmrelease.yaml +++ b/kubernetes/apps/tools/outline/app/helmrelease.yaml @@ -40,11 +40,10 @@ spec: FILE_STORAGE_LOCAL_ROOT_DIR: /data FILE_STORAGE_UPLOAD_MAX_SIZE: &upload-limit "26214400" FILE_STORAGE_IMPORT_MAX_SIZE: *upload-limit - OIDC_CLIENT_ID: outline OIDC_SCOPES: "openid profile email" - OIDC_AUTH_URI: "https://auth.immich.cloud/auth" - OIDC_TOKEN_URI: "https://auth.immich.cloud/token" - OIDC_USERINFO_URI: "https://auth.immich.cloud/userinfo" + OIDC_AUTH_URI: "https://zitadel.internal.immich.cloud/oauth/v2/authorize" + OIDC_TOKEN_URI: "https://zitadel.internal.immich.cloud/oauth/v2/token" + OIDC_USERINFO_URI: "https://zitadel.internal.immich.cloud/oidc/v1/userinfo" WEB_CONCURRENCY: 10 DATABASE_URL: valueFrom: @@ -53,7 +52,9 @@ spec: key: uri envFrom: - secretRef: - name: outline-secret + name: outline-secret-keys + - secretRef: + name: outline-oauth-client securityContext: fsGroup: 1001 valkey: diff --git a/kubernetes/apps/tools/outline/ks.yaml b/kubernetes/apps/tools/outline/ks.yaml index d4d1d7cd..7b36dcce 100644 --- a/kubernetes/apps/tools/outline/ks.yaml +++ b/kubernetes/apps/tools/outline/ks.yaml @@ -8,7 +8,8 @@ spec: labels: app.kubernetes.io/name: *app dependsOn: - - name: cluster-apps-onepassword + - name: external-secrets-stores + - name: zitadel path: ./kubernetes/apps/tools/outline/secrets prune: true sourceRef: @@ -30,7 +31,6 @@ spec: labels: app.kubernetes.io/name: *app dependsOn: - - name: dexidp - name: outline-secrets path: ./kubernetes/apps/tools/outline/app prune: true diff --git a/kubernetes/apps/tools/outline/secrets/kustomization.yaml b/kubernetes/apps/tools/outline/secrets/kustomization.yaml index 534a33ec..b7f6eaff 100644 --- a/kubernetes/apps/tools/outline/secrets/kustomization.yaml +++ b/kubernetes/apps/tools/outline/secrets/kustomization.yaml @@ -5,3 +5,4 @@ resources: - ./secret.yaml - ./db-backup-secret.yaml - ./db-backup-bucket.yaml + - ./oauth.yaml diff --git a/kubernetes/apps/tools/outline/secrets/oauth.yaml b/kubernetes/apps/tools/outline/secrets/oauth.yaml new file mode 100644 index 00000000..c74b2832 --- /dev/null +++ b/kubernetes/apps/tools/outline/secrets/oauth.yaml @@ -0,0 +1,17 @@ +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: outline-oauth-client + namespace: tools +spec: + secretStoreRef: + kind: ClusterSecretStore + name: 1p-tf + refreshInterval: "20s" + data: + - secretKey: OIDC_CLIENT_ID + remoteRef: + key: ZITADEL_OAUTH_CLIENT_ID_OUTLINE + - secretKey: OIDC_CLIENT_SECRET + remoteRef: + key: ZITADEL_OAUTH_CLIENT_SECRET_OUTLINE diff --git a/kubernetes/apps/tools/outline/secrets/secret.yaml b/kubernetes/apps/tools/outline/secrets/secret.yaml index f7348aaa..a11a6ded 100644 --- a/kubernetes/apps/tools/outline/secrets/secret.yaml +++ b/kubernetes/apps/tools/outline/secrets/secret.yaml @@ -1,7 +1,17 @@ -apiVersion: onepassword.com/v1 -kind: OnePasswordItem +apiVersion: external-secrets.io/v1 +kind: ExternalSecret metadata: - name: outline-secret + name: outline-secret-keys namespace: tools spec: - itemPath: "vaults/Kubernetes/items/outline-secret" + secretStoreRef: + kind: ClusterSecretStore + name: 1p-tf + refreshInterval: "20s" + data: + - secretKey: SECRET_KEY + remoteRef: + key: OUTLINE_SECRET_KEY + - secretKey: UTILS_SECRET + remoteRef: + key: OUTLINE_UTILS_SECRET diff --git a/tf/deployment/modules/shared/1password/account/k8s-secrets.tf b/tf/deployment/modules/shared/1password/account/k8s-secrets.tf index c3e3996f..b4f772ab 100644 --- a/tf/deployment/modules/shared/1password/account/k8s-secrets.tf +++ b/tf/deployment/modules/shared/1password/account/k8s-secrets.tf @@ -191,69 +191,6 @@ removed { from = onepassword_item.bot_fourthwall_webhook_slug } -resource "random_password" "grafana_oauth_client_secret" { - length = 40 - special = false -} - -resource "onepassword_item" "grafana_oauth_client_secret" { - vault = data.onepassword_vault.kubernetes.uuid - title = "grafana-oauth-client-secret" - category = "secure_note" - - section { - label = "OAuth secret for grafana" - - field { - label = "GRAFANA_OAUTH_CLIENT_SECRET" - type = "CONCEALED" - value = random_password.grafana_oauth_client_secret.result - } - } -} - -resource "random_bytes" "outline_secret_key" { - length = 32 -} - -resource "random_password" "outline_utils_secret" { - length = 40 - special = false -} - -resource "random_password" "outline_oauth_client_secret" { - length = 40 - special = false -} - -resource "onepassword_item" "outline_secret" { - vault = data.onepassword_vault.kubernetes.uuid - title = "outline-secret" - category = "secure_note" - - section { - label = "Outline secret" - - field { - label = "SECRET_KEY" - type = "CONCEALED" - value = random_bytes.outline_secret_key.hex - } - - field { - label = "UTILS_SECRET" - type = "CONCEALED" - value = random_password.outline_utils_secret.result - } - - field { - label = "OIDC_CLIENT_SECRET" - type = "CONCEALED" - value = random_password.outline_oauth_client_secret.result - } - } -} - data "onepassword_item" "zitadel_profile_json" { vault = data.onepassword_vault.kubernetes.uuid title = "PUSHED_ZITADEL_IAC_ADMIN_SA" diff --git a/tf/deployment/modules/shared/1password/account/secrets.tf b/tf/deployment/modules/shared/1password/account/secrets.tf index 9f82d0d7..1e9baf26 100644 --- a/tf/deployment/modules/shared/1password/account/secrets.tf +++ b/tf/deployment/modules/shared/1password/account/secrets.tf @@ -44,7 +44,9 @@ module "generated-secrets" { { name = "IMMICH_DISCORD_BOT_FOURTHWALL_WEBHOOK_SLUG" }, { name = "FLUXCD_GITHUB_WEBHOOK_SECRET" }, { name = "PREVIEWS_GITHUB_WEBHOOK_SECRET" }, - { name = "AUTH_ZITADEL_MASTER_KEY", length = 32 } + { name = "AUTH_ZITADEL_MASTER_KEY", length = 32 }, + { name = "OUTLINE_SECRET_KEY", length = 32 }, + { name = "OUTLINE_UTILS_SECRET" } ] } }