147 lines
4.4 KiB
YAML
147 lines
4.4 KiB
YAML
# oauth2-proxy: Google OAuth at the nginx ingress layer.
|
|
# Ref: https://medium.com/@hrlimaye/google-oauth2-with-kubernetes-nginx-controller-d7a0a3e62e1b
|
|
#
|
|
# Flow:
|
|
# 1. Request hits nginx ingress for Kibana (ingress-kibana.yaml).
|
|
# 2. nginx calls auth-url -> oauth2-proxy /oauth2/auth (200 = pass, 401 = redirect to signin).
|
|
# 3. On 401, nginx redirects to auth-signin (oauth2-proxy /oauth2/start) -> Google login.
|
|
# 4. Google redirects back to /oauth2/callback (served by ingress-oauth2-proxy.yaml).
|
|
# 5. Authenticated request proceeds to Kibana.
|
|
#
|
|
# Requires Secret "oauth2-proxy-google" (see oauth2-proxy-secret.example.yaml).
|
|
# Google OAuth app: Authorized redirect URI must be set to:
|
|
# http://kibana-prd-observability.prd.meesho.int/oauth2/callback
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: oauth2-proxy-kibana
|
|
namespace: eck-observability-prd
|
|
labels:
|
|
app: oauth2-proxy-kibana
|
|
spec:
|
|
type: ClusterIP
|
|
ports:
|
|
- name: http
|
|
port: 4180
|
|
targetPort: 4180
|
|
selector:
|
|
app: oauth2-proxy-kibana
|
|
---
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: oauth2-proxy-kibana
|
|
namespace: eck-observability-prd
|
|
labels:
|
|
app: oauth2-proxy-kibana
|
|
spec:
|
|
replicas: 1
|
|
selector:
|
|
matchLabels:
|
|
app: oauth2-proxy-kibana
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app: oauth2-proxy-kibana
|
|
annotations:
|
|
cluster-autoscaler.kubernetes.io/safe-to-evict: "false"
|
|
spec:
|
|
tolerations:
|
|
- effect: NoSchedule
|
|
key: elastic-observability-common-nodes
|
|
operator: Equal
|
|
value: "true"
|
|
nodeSelector:
|
|
elastic-observability-common-nodes: "true"
|
|
containers:
|
|
- name: oauth2-proxy
|
|
image: quay.io/oauth2-proxy/oauth2-proxy:v7.6.0
|
|
args:
|
|
- --provider=google
|
|
- --http-address=0.0.0.0:4180
|
|
# upstream=static://200 means oauth2-proxy only handles /oauth2/* paths;
|
|
# actual proxying to Kibana is done by nginx, not oauth2-proxy.
|
|
- --upstream=static://200
|
|
- --skip-provider-button=true
|
|
# Allow any Google-authenticated user; restrict by setting --email-domain=meesho.com
|
|
- --email-domain=*
|
|
- --cookie-secure=false
|
|
- --set-xauthrequest=true
|
|
- --pass-access-token=false
|
|
- --redirect-url=http://kibana-prd-observability.prd.meesho.int/oauth2/callback
|
|
envFrom:
|
|
- secretRef:
|
|
name: oauth2-proxy-google
|
|
ports:
|
|
- name: http
|
|
containerPort: 4180
|
|
readinessProbe:
|
|
httpGet:
|
|
path: /ping
|
|
port: 4180
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 10
|
|
resources:
|
|
requests:
|
|
cpu: 9
|
|
memory: 25Gi
|
|
limits:
|
|
cpu: 13
|
|
memory: 25Gi
|
|
---
|
|
# HorizontalPodAutoscaler for oauth2-proxy-kibana Deployment
|
|
apiVersion: autoscaling/v2
|
|
kind: HorizontalPodAutoscaler
|
|
metadata:
|
|
name: oauth2-proxy-kibana-hpa
|
|
namespace: eck-observability-prd
|
|
spec:
|
|
scaleTargetRef:
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
name: oauth2-proxy-kibana
|
|
minReplicas: 1
|
|
maxReplicas: 10
|
|
metrics:
|
|
# CPU-based scaling: target 70% CPU utilization
|
|
- type: Resource
|
|
resource:
|
|
name: cpu
|
|
target:
|
|
type: Utilization
|
|
averageUtilization: 70
|
|
# Memory-based scaling: target 80% memory utilization
|
|
- type: Resource
|
|
resource:
|
|
name: memory
|
|
target:
|
|
type: Utilization
|
|
averageUtilization: 80
|
|
behavior:
|
|
scaleDown:
|
|
stabilizationWindowSeconds: 300
|
|
policies:
|
|
- type: Percent
|
|
value: 50
|
|
periodSeconds: 60
|
|
scaleUp:
|
|
stabilizationWindowSeconds: 30
|
|
policies:
|
|
- type: Percent
|
|
value: 100
|
|
periodSeconds: 30
|
|
- type: Pods
|
|
value: 2
|
|
periodSeconds: 60
|
|
|
|
|
|
# kubectl exec -it eck-observability-prd-es-hot-0 -n eck-observability-prd \
|
|
# -- curl -s -u "elastic:$(kubectl get secret eck-observability-prd-es-elastic-user -n eck-observability-prd -o jsonpath='{.data.elastic}' | base64 -d)" \
|
|
# -X POST "http://localhost:9200/_security/user/kibana-anonymous-viewer" \
|
|
# -H "Content-Type: application/json" \
|
|
# -d '{
|
|
# "password": "ViewerPass@2026",
|
|
# "roles": ["viewer"],
|
|
# "full_name": "Kibana Anonymous Viewer",
|
|
# "enabled": true
|
|
# }' |