Files
devops-infra-helm-charts-gcp/helm-overrides/k8s-admin-prd-ase1/elastic-cluster/eck-observability/ingress-kibana.yaml
T
2026-08-26 03:39:42 +05:30

51 lines
2.5 KiB
YAML

# Kibana — nginx-internal with Google OAuth via oauth2-proxy.
# Ref: https://medium.com/@hrlimaye/google-oauth2-with-kubernetes-nginx-controller-d7a0a3e62e1b
#
# nginx auth_request flow:
# 1. Request hits this ingress for path /
# 2. nginx makes internal subrequest to auth-url (cluster-internal DNS, always resolvable from nginx pod)
# 3. oauth2-proxy returns 202 (valid cookie) -> request passes to Kibana
# oauth2-proxy returns 401 (no/bad cookie) -> nginx redirects browser to auth-signin
# 4. auth-signin uses $host (browser redirect, not internal subrequest - $host is fine here)
# -> oauth2-proxy starts Google login flow -> /oauth2/callback -> sets cookie -> back to Kibana
#
# Why auth-url uses cluster DNS (not $host):
# auth-url is an nginx internal subrequest - nginx tries to resolve it from inside the pod.
# External hostnames like prd.meesho.int may not resolve from within the nginx controller pod.
# auth-signin is a browser redirect, so $host works fine there.
#
# Requires:
# - Secret oauth2-proxy-google applied (oauth2-proxy-secret.example.yaml)
# - oauth2-proxy Deployment + Service (oauth2-proxy.yaml)
# - /oauth2 Ingress on same host (ingress-oauth2-proxy.yaml)
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: kibana-prd-observability-nginx
namespace: eck-observability-prd
annotations:
kubernetes.io/ingress.class: nginx-internal
nginx.ingress.kubernetes.io/ssl-redirect: "false"
nginx.ingress.kubernetes.io/proxy-read-timeout: "300"
nginx.ingress.kubernetes.io/proxy-send-timeout: "300"
nginx.ingress.kubernetes.io/proxy-body-size: "0"
nginx.ingress.kubernetes.io/proxy-buffer-size: "16k"
# auth-url: cluster-internal DNS so nginx can always reach oauth2-proxy for the subrequest.
nginx.ingress.kubernetes.io/auth-url: "http://oauth2-proxy-kibana.eck-observability-prd.svc.cluster.local:4180/oauth2/auth"
# auth-signin: browser redirect — $host resolves to the request Host header in the browser.
nginx.ingress.kubernetes.io/auth-signin: "http://$host/oauth2/start?rd=$escaped_request_uri"
nginx.ingress.kubernetes.io/auth-response-headers: "X-Auth-Request-Email, X-Auth-Request-User"
spec:
ingressClassName: nginx-internal
rules:
- host: kibana-prd-observability.prd.meesho.int
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: kibana-eck-observability-prd-kb-http
port:
number: 5601