This commit is contained in:
2023-08-27 15:18:52 +02:00
parent c572579aa5
commit 5c7094f866
2 changed files with 156 additions and 145 deletions

View File

@@ -6,135 +6,6 @@ metadata:
name: authentik name: authentik
description: authentik is an open-source Identity Provider focused on flexibility and versatility description: authentik is an open-source Identity Provider focused on flexibility and versatility
options: options:
backups:
default:
enable: false
endpoint: ''
key-id-key: s3-id
retention:
db: 30d
schedule:
db: 0 3 * * *
secret-key: s3-secret
secret-name: backup-settings
examples:
- enable: false
endpoint: ''
key-id-key: s3-id
retention:
db: 30d
schedule:
db: 0 3 * * *
secret-key: s3-secret
secret-name: backup-settings
properties:
enable:
default: false
type: boolean
endpoint:
default: ''
type: string
key-id-key:
default: s3-id
type: string
retention:
default:
db: 30d
properties:
db:
default: 30d
type: string
type: object
schedule:
default:
db: 0 3 * * *
properties:
db:
default: 0 3 * * *
type: string
type: object
secret-key:
default: s3-secret
type: string
secret-name:
default: backup-settings
type: string
type: object
email:
default:
port: 587
timeout: 30
use_ssl: false
use_tls: false
examples:
- port: 587
timeout: 30
use_ssl: false
use_tls: false
properties:
port:
default: 587
type: integer
timeout:
default: 30
type: integer
use_ssl:
default: false
type: boolean
use_tls:
default: false
type: boolean
type: object
error_reporting:
default:
enabled: false
environment: k8s
send_pii: false
examples:
- enabled: false
environment: k8s
send_pii: false
properties:
enabled:
default: false
type: boolean
environment:
default: k8s
type: string
send_pii:
default: false
type: boolean
type: object
sub-domain:
default: auth
examples:
- auth
type: string
domain-name:
default: your_company.com
examples:
- your_company.com
type: string
postgres:
default:
replicas: 1
storage: 8Gi
version: '14'
examples:
- replicas: 1
storage: 8Gi
version: '14'
properties:
replicas:
default: 1
type: integer
storage:
default: 8Gi
type: string
version:
default: '14'
type: string
type: object
redis: redis:
default: default:
exporter: exporter:
@@ -168,41 +39,145 @@ options:
default: 8Gi default: 8Gi
type: string type: string
type: object type: object
issuer:
default: letsencrypt-prod
examples:
- letsencrypt-prod
type: string
email:
default:
port: 587
timeout: 30
use_ssl: false
use_tls: false
examples:
- port: 587
timeout: 30
use_ssl: false
use_tls: false
properties:
port:
default: 587
type: integer
timeout:
default: 30
type: integer
use_ssl:
default: false
type: boolean
use_tls:
default: false
type: boolean
type: object
ingress-class: ingress-class:
default: traefik default: traefik
examples: examples:
- traefik - traefik
type: string type: string
sub-domain:
default: auth
examples:
- auth
type: string
backups:
default:
enable: false
endpoint: ''
key-id-key: s3-id
retention:
db: 30d
schedule:
db: 0 3 * * *
secret-key: s3-secret
secret-name: backup-settings
use-barman: false
examples:
- enable: false
endpoint: ''
key-id-key: s3-id
retention:
db: 30d
schedule:
db: 0 3 * * *
secret-key: s3-secret
secret-name: backup-settings
use-barman: false
properties:
enable:
default: false
type: boolean
endpoint:
default: ''
type: string
key-id-key:
default: s3-id
type: string
retention:
default:
db: 30d
properties:
db:
default: 30d
type: string
type: object
schedule:
default:
db: 0 3 * * *
properties:
db:
default: 0 3 * * *
type: string
type: object
secret-key:
default: s3-secret
type: string
secret-name:
default: backup-settings
type: string
use-barman:
default: false
type: boolean
type: object
loglevel:
default: info
examples:
- info
type: string
geoip: geoip:
default: /geoip/GeoLite2-City.mmdb default: /geoip/GeoLite2-City.mmdb
examples: examples:
- /geoip/GeoLite2-City.mmdb - /geoip/GeoLite2-City.mmdb
type: string type: string
loglevel:
default: info
examples:
- info
type: string
issuer:
default: letsencrypt-prod
examples:
- letsencrypt-prod
type: string
domain: domain:
default: your-company default: your-company
examples: examples:
- your-company - your-company
type: string type: string
admin: error_reporting:
default: default:
email: auth-admin enabled: false
environment: k8s
send_pii: false
examples: examples:
- email: auth-admin - enabled: false
environment: k8s
send_pii: false
properties: properties:
email: enabled:
default: auth-admin default: false
type: boolean
environment:
default: k8s
type: string type: string
send_pii:
default: false
type: boolean
type: object type: object
domain-name:
default: your_company.com
examples:
- your_company.com
type: string
image: image:
default: default:
project: goauthentik project: goauthentik
@@ -233,6 +208,36 @@ options:
default: 2023.5.4 default: 2023.5.4
type: string type: string
type: object type: object
postgres:
default:
replicas: 1
storage: 8Gi
version: '14'
examples:
- replicas: 1
storage: 8Gi
version: '14'
properties:
replicas:
default: 1
type: integer
storage:
default: 8Gi
type: string
version:
default: '14'
type: string
type: object
admin:
default:
email: auth-admin
examples:
- email: auth-admin
properties:
email:
default: auth-admin
type: string
type: object
dependencies: dependencies:
- dist: null - dist: null
category: core category: core

View File

@@ -8,13 +8,16 @@ locals {
} }
resource "kubectl_manifest" "prj_pg" { resource "kubectl_manifest" "prj_pg" {
yaml_body = <<-EOF yaml_body = join("", concat([<<-EOF
apiVersion: postgresql.cnpg.io/v1 apiVersion: postgresql.cnpg.io/v1
kind: Cluster kind: Cluster
metadata: metadata:
name: "${var.instance}-${var.component}-pg" name: "${var.instance}-${var.component}-pg"
namespace: "${var.namespace}" namespace: "${var.namespace}"
labels: ${jsonencode(local.pg-labels)} labels: ${jsonencode(local.pg-labels)}
annotations:
"k8up.io/backupcommand": "pg_dump -U postgres -d ${var.component} --clean"
"k8up.io/file-extension": ".sql"
spec: spec:
instances: ${var.postgres.replicas} instances: ${var.postgres.replicas}
storage: storage:
@@ -25,6 +28,8 @@ resource "kubectl_manifest" "prj_pg" {
owner: "${var.component}" owner: "${var.component}"
monitoring: monitoring:
enablePodMonitor: true enablePodMonitor: true
EOF
], var.backups.enable&&var.backups.use-barman?[<<-EOF
backup: backup:
barmanObjectStore: barmanObjectStore:
destinationPath: "s3://${var.instance}-${var.namespace}/" destinationPath: "s3://${var.instance}-${var.namespace}/"
@@ -37,6 +42,7 @@ resource "kubectl_manifest" "prj_pg" {
name: "${var.backups.secret-name}" name: "${var.backups.secret-name}"
key: "${var.backups.secret-key}" key: "${var.backups.secret-key}"
EOF EOF
]:[""]))
} }
resource "kubectl_manifest" "prj_pg_backup" { resource "kubectl_manifest" "prj_pg_backup" {