This commit is contained in:
2023-08-12 12:10:15 +02:00
parent 8ff7906740
commit 1f944617e5
8 changed files with 674 additions and 723 deletions

View File

@@ -6,21 +6,16 @@ metadata:
name: authentik
description: authentik is an open-source Identity Provider focused on flexibility and versatility
options:
loglevel:
default: info
sub-domain:
default: auth
examples:
- info
- auth
type: string
admin:
default:
email: auth-admin
issuer:
default: letsencrypt-prod
examples:
- email: auth-admin
properties:
email:
default: auth-admin
type: string
type: object
- letsencrypt-prod
type: string
email:
default:
port: 587
@@ -46,79 +41,6 @@ options:
default: false
type: boolean
type: object
redis:
default:
exporter:
enabled: true
image: quay.io/opstree/redis-exporter:v1.44.0
image: quay.io/opstree/redis:v7.0.5
storage: 8Gi
examples:
- exporter:
enabled: true
image: quay.io/opstree/redis-exporter:v1.44.0
image: quay.io/opstree/redis:v7.0.5
storage: 8Gi
properties:
exporter:
default:
enabled: true
image: quay.io/opstree/redis-exporter:v1.44.0
properties:
enabled:
default: true
type: boolean
image:
default: quay.io/opstree/redis-exporter:v1.44.0
type: string
type: object
image:
default: quay.io/opstree/redis:v7.0.5
type: string
storage:
default: 8Gi
type: string
type: object
ingress-class:
default: traefik
examples:
- traefik
type: string
domain-name:
default: your_company.com
examples:
- your_company.com
type: string
image:
default:
project: goauthentik
pullPolicy: IfNotPresent
registry: ghcr.io
repository: goauthentik/server
tag: 2023.5.4
examples:
- project: goauthentik
pullPolicy: IfNotPresent
registry: ghcr.io
repository: goauthentik/server
tag: 2023.5.4
properties:
project:
default: goauthentik
type: string
pullPolicy:
default: IfNotPresent
type: string
registry:
default: ghcr.io
type: string
repository:
default: goauthentik/server
type: string
tag:
default: 2023.5.4
type: string
type: object
postgres:
default:
replicas: 1
@@ -139,15 +61,10 @@ options:
default: '14'
type: string
type: object
sub-domain:
default: auth
domain:
default: your-company
examples:
- auth
type: string
issuer:
default: letsencrypt-prod
examples:
- letsencrypt-prod
- your-company
type: string
error_reporting:
default:
@@ -169,6 +86,16 @@ options:
default: false
type: boolean
type: object
loglevel:
default: info
examples:
- info
type: string
geoip:
default: /geoip/GeoLite2-City.mmdb
examples:
- /geoip/GeoLite2-City.mmdb
type: string
backups:
default:
enable: false
@@ -223,16 +150,89 @@ options:
default: backup-settings
type: string
type: object
domain:
default: your-company
ingress-class:
default: traefik
examples:
- your-company
- traefik
type: string
geoip:
default: /geoip/GeoLite2-City.mmdb
image:
default:
project: goauthentik
pullPolicy: IfNotPresent
registry: ghcr.io
repository: goauthentik/server
tag: 2023.5.4
examples:
- /geoip/GeoLite2-City.mmdb
- project: goauthentik
pullPolicy: IfNotPresent
registry: ghcr.io
repository: goauthentik/server
tag: 2023.5.4
properties:
project:
default: goauthentik
type: string
pullPolicy:
default: IfNotPresent
type: string
registry:
default: ghcr.io
type: string
repository:
default: goauthentik/server
type: string
tag:
default: 2023.5.4
type: string
type: object
domain-name:
default: your_company.com
examples:
- your_company.com
type: string
admin:
default:
email: auth-admin
examples:
- email: auth-admin
properties:
email:
default: auth-admin
type: string
type: object
redis:
default:
exporter:
enabled: true
image: quay.io/opstree/redis-exporter:v1.44.0
image: quay.io/opstree/redis:v7.0.5
storage: 8Gi
examples:
- exporter:
enabled: true
image: quay.io/opstree/redis-exporter:v1.44.0
image: quay.io/opstree/redis:v7.0.5
storage: 8Gi
properties:
exporter:
default:
enabled: true
image: quay.io/opstree/redis-exporter:v1.44.0
properties:
enabled:
default: true
type: boolean
image:
default: quay.io/opstree/redis-exporter:v1.44.0
type: string
type: object
image:
default: quay.io/opstree/redis:v7.0.5
type: string
storage:
default: 8Gi
type: string
type: object
dependencies:
- dist: null
category: core

View File

@@ -2,26 +2,6 @@ locals {
pg-labels = merge(local.common-labels, {
"app.kubernetes.io/component" = "pg"
})
pool-labels = merge(local.common-labels, {
"app.kubernetes.io/component" = "pg-pool"
})
backup-def = {
retentionPolicy = var.backups.retention.db
barmanObjectStore = {
destinationPath = "s3://${var.instance}-${var.namespace}/"
endpointURL = "${var.backups.endpoint}/barman"
s3Credentials = {
accessKeyId = {
name = var.backups.secret-name
key = var.backups.key-id-key
}
secretAccessKey = {
name = var.backups.secret-name
key = var.backups.secret-key
}
}
}
}
}
resource "kubectl_manifest" "prj_pg" {
@@ -36,17 +16,28 @@ resource "kubectl_manifest" "prj_pg" {
instances: ${var.postgres.replicas}
storage:
size: "${var.postgres.storage}"
monitoring:
enablePodMonitor: true
bootstrap:
initdb:
database: "${var.component}"
owner: "${var.component}"
backup: ${jsonencode(var.backups.enable?local.backup-def:{})}
monitoring:
enablePodMonitor: true
backup:
barmanObjectStore:
destinationPath: "s3://${var.instance}-${var.namespace}/"
endpointURL: "${var.backups.endpoint}/barman"
s3Credentials:
accessKeyId:
name: "${var.backups.secret-name}"
key: "${var.backups.key-id-key}"
secretAccessKey:
name: "${var.backups.secret-name}"
key: "${var.backups.secret-key}"
EOF
}
resource "kubectl_manifest" "prj_pg_backup" {
count = var.backup.enable ? 1:0
yaml_body = <<-EOF
apiVersion: postgresql.cnpg.io/v1
kind: ScheduledBackup
@@ -61,26 +52,3 @@ resource "kubectl_manifest" "prj_pg_backup" {
name: "${var.instance}-${var.component}-pg"
EOF
}
resource "kubectl_manifest" "prj_pg_pool" {
depends_on = [kubectl_manifest.prj_pg]
yaml_body = <<-EOF
apiVersion: postgresql.cnpg.io/v1
kind: Pooler
metadata:
name: "${var.instance}-${var.component}-pool"
namespace: "${var.namespace}"
labels: ${jsonencode(local.pool-labels)}
spec:
cluster:
name: "${var.instance}-${var.component}-pg"
instances: 1
type: rw
pgbouncer:
poolMode: session
parameters:
max_client_conn: "1000"
default_pool_size: "10"
EOF
}