From 72ab9c5933bd578dd1d104e0a9379a3ae9e8a1d1 Mon Sep 17 00:00:00 2001 From: Matthias Linhuber Date: Thu, 27 Aug 2026 00:00:10 +0200 Subject: [PATCH] chore: remove the Gitea/generic-OIDC auth provider The Gitea integration is no longer needed, so remove the Gitea auth-provider option added in #22 (now living in charts/eduide after the chart split): - values: drop the gitea.* block. - oauth2-proxy configmap: remove the gitea provider branch, the gitea secret guards, the keycloak/gitea mutual-exclusion guard, and the gitea host/issuer wiring; back to keycloak-only. - operator: drop the --gitea argument. - landing-page config: drop useGiteaOidc/giteaIssuerUrl/giteaClientId. - preflight: the keycloak placeholder check now always runs (was skipped when gitea was enabled). - README: drop the generated gitea.* rows. Kept oauth2Proxy.sslInsecureSkipVerify: it is a provider-agnostic setting (applies to keycloak) that enforces TLS certificate validation by default; removing it would revert to the previous hardcoded insecure default. Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_012iEasFrsCzFTCkRh5SP1KY --- charts/eduide/README.md | 6 ---- charts/eduide/templates/_preflight.tpl | 2 -- .../templates/landing-page-config-map.yaml | 8 ----- ...oauth2-configmap-oauth2proxy-keycloak.yaml | 30 +------------------ charts/eduide/templates/operator.yaml | 3 -- charts/eduide/values.yaml | 25 ---------------- 6 files changed, 1 insertion(+), 73 deletions(-) diff --git a/charts/eduide/README.md b/charts/eduide/README.md index 3493279..9640e91 100644 --- a/charts/eduide/README.md +++ b/charts/eduide/README.md @@ -50,12 +50,6 @@ environment. Requires eduide-cluster to be installed on the cluster first. | gateway.routes.enabled | bool | `true` | Whether to render HTTPRoute resources. | | gateway.serviceRouteRequestTimeout | string | `"60s"` | HTTPRoute request timeout for service-route (Envoy default can be 15s) | | gateway.tls | bool | `true` | Does Theia Cloud expect TLS connections (true) or is TLS terminated outside of Theia Cloud (false) | -| gitea | object | (see details below) | Values related to Gitea / generic OIDC authentication. Mutually exclusive with keycloak (a single oauth2-proxy provider is supported per session). | -| gitea.clientId | string | `"theia-cloud"` | The client-id. Only has to be specified when enable: true | -| gitea.clientSecret | string | `""` | The client secret configured for the OIDC application in Gitea. Must be provided (rendering fails when gitea.enable is true and this is empty). | -| gitea.cookieSecret | string | `""` | The cookie secret. This should not be public! Must be provided when enable: true (rendering fails when gitea.enable is true and this is empty). See https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/overview/#generating-a-cookie-secret for how to generate a strong cookie secret. | -| gitea.enable | bool | `false` | Whether Gitea / generic OIDC authentication shall be used | -| gitea.issuerUrl | string | `"https://gitea.example.com"` | The Gitea base URL used as the OIDC issuer. Only has to be specified when enable: true. This must be the issuer base URL without a trailing slash and without a realms path, e.g. "https://gitea.example.com". | | hosts | object | (see details below) | You may adjust the hostname below. | | hosts.allWildcardInstances | list | `[]` | all additional wildcard hostnames that may be required in the launched Theia-applications, e.g. "*.webview." which leads to "*.webview.ws.192.168.39.173.nip.io" to expose webviews. Please note that this means that this usually means that all "ingressHostnamePrefixes" patterns from all app definitions need to be added. IMPORTANT: If this gets updated, the helm chart needs to be re-installed because helm upgrade will not properly update this at the moment. These are required to configure TLS (if enabled via gateway.tls == true) I.e. custom certificates or a cert-manager provider that can handle wildcard certificates need to be configured. | | hosts.configuration | object | (see details below) | Configuration for the hostnames. Contains the baseHost and afixes for all services | diff --git a/charts/eduide/templates/_preflight.tpl b/charts/eduide/templates/_preflight.tpl index 9eaa165..99b4dc4 100644 --- a/charts/eduide/templates/_preflight.tpl +++ b/charts/eduide/templates/_preflight.tpl @@ -43,12 +43,10 @@ */}} {{- define "eduide.preflightKeycloak" -}} {{- $kc := .Values.keycloak -}} -{{- if not .Values.gitea.enable }} {{- $placeholder := or (eq ($kc.authUrl | toString) "https://keycloak.url/auth/") (eq ($kc.realm | toString) "TheiaCloud") (eq ($kc.clientId | toString) "theia-cloud") -}} {{- if and $placeholder (not $kc.allowUnauthenticated) }} {{- fail (printf "keycloak is left at the chart's placeholder values (authUrl=%s realm=%s clientId=%s). Configure them, or set keycloak.allowUnauthenticated=true to install without a working identity provider." $kc.authUrl $kc.realm $kc.clientId) }} {{- end }} -{{- end }} {{- end -}} diff --git a/charts/eduide/templates/landing-page-config-map.yaml b/charts/eduide/templates/landing-page-config-map.yaml index 740cd0a..4d12713 100644 --- a/charts/eduide/templates/landing-page-config-map.yaml +++ b/charts/eduide/templates/landing-page-config-map.yaml @@ -15,14 +15,6 @@ data: keycloakAuthUrl: "{{ tpl (.Values.keycloak.authUrl | toString) . }}", keycloakRealm: "{{ tpl (.Values.keycloak.realm | toString) . }}", keycloakClientId: "{{ tpl (.Values.keycloak.clientId | toString) . }}", - useGiteaOidc: {{ tpl (.Values.gitea.enable | toString) . }}, - {{- if .Values.gitea.enable }} - giteaIssuerUrl: "{{ tpl (.Values.gitea.issuerUrl | toString) . }}", - giteaClientId: "{{ tpl (.Values.gitea.clientId | toString) . }}", - {{- else }} - giteaIssuerUrl: "", - giteaClientId: "", - {{- end }} serviceUrl: "{{ include "theia-cloud.url.service" . }}", appDefinition: "{{ tpl (.Values.landingPage.appDefinition | toString) . }}", {{- /* diff --git a/charts/eduide/templates/oauth2-configmap-oauth2proxy-keycloak.yaml b/charts/eduide/templates/oauth2-configmap-oauth2proxy-keycloak.yaml index 11a9a2c..fb7ec7e 100644 --- a/charts/eduide/templates/oauth2-configmap-oauth2proxy-keycloak.yaml +++ b/charts/eduide/templates/oauth2-configmap-oauth2proxy-keycloak.yaml @@ -1,22 +1,9 @@ -{{- /* keycloak and gitea use the same single oauth2-proxy provider, so only one may be enabled. */ -}} -{{- if and .Values.keycloak.enable .Values.gitea.enable }}{{- fail "keycloak.enable and gitea.enable are mutually exclusive (single oauth2-proxy provider)" }}{{- end }} -{{- /* Gitea OIDC applications issue real credentials, so require them explicitly instead of shipping insecure defaults. */ -}} -{{- if .Values.gitea.enable }} -{{- if not (tpl (.Values.gitea.clientSecret | toString) .) }}{{- fail "gitea.clientSecret must be set when gitea.enable is true" }}{{- end }} -{{- if not (tpl (.Values.gitea.cookieSecret | toString) .) }}{{- fail "gitea.cookieSecret must be set when gitea.enable is true" }}{{- end }} -{{- end }} {{- /* Extract the host where the Keycloak runs by extracting it from the auth URL via regex. */ -}} {{- $keycloakUrl := tpl (.Values.keycloak.authUrl | toString) . -}} {{- /* Regex to match a URL that matches the host in group 1: ([^/]+) */ -}} {{- $hostRegex := `^https?://([^/]+)(/.*)?$` -}} {{- /* Replace the URL with only the first group which is only the host. */ -}} {{- $keycloakHost:= regexReplaceAll $hostRegex $keycloakUrl `$1` -}} -{{- /* Extract the host where Gitea runs the same way from the issuer URL. */ -}} -{{- $giteaUrl := tpl (.Values.gitea.issuerUrl | toString) . -}} -{{- $giteaHost := regexReplaceAll $hostRegex $giteaUrl `$1` -}} -{{- /* Host of the currently enabled OIDC provider, used for the whitelist defaults. */ -}} -{{- $oauthHost := $keycloakHost -}} -{{- if .Values.gitea.enable }}{{- $oauthHost = $giteaHost -}}{{- end }} apiVersion: v1 kind: ConfigMap @@ -26,29 +13,14 @@ metadata: data: oauth2-proxy.cfg: |+ # Provider config - {{- if .Values.gitea.enable }} - provider="oidc" - {{- else }} provider="keycloak-oidc" - {{- end }} redirect_url="https://placeholder/oauth2/callback" - {{- if .Values.gitea.enable }} - oidc_issuer_url="{{ $giteaUrl }}" - {{- else }} oidc_issuer_url="{{ $keycloakUrl }}realms/{{ tpl (.Values.keycloak.realm | toString) . }}" - {{- end }} ssl_insecure_skip_verify={{ .Values.oauth2Proxy.sslInsecureSkipVerify }} # Client config - {{- if .Values.gitea.enable }} - client_id="{{ tpl (.Values.gitea.clientId | toString) . }}" - client_secret="{{ tpl (.Values.gitea.clientSecret | toString) . }}" - cookie_secret="{{ tpl (.Values.gitea.cookieSecret | toString) . }}" - pass_access_token=true - {{- else }} client_id="{{ tpl (.Values.keycloak.clientId | toString) . }}" client_secret="{{ tpl (.Values.keycloak.clientSecret | toString) . }}" cookie_secret="{{ tpl (.Values.keycloak.cookieSecret | toString) . }}" - {{- end }} cookie_secure="false" #proxy_prefix="" # Upstream config @@ -70,6 +42,6 @@ data: {{- if gt (len $whitelistDomains) 0 }} whitelist_domains={{ toJson $whitelistDomains }} {{- else }} - whitelist_domains=["{{ tpl (.Values.hosts.configuration.instance | toString) . }}:*","{{ $oauthHost }}:*"] + whitelist_domains=["{{ tpl (.Values.hosts.configuration.instance | toString) . }}:*","{{ $keycloakHost }}:*"] {{- end }} custom_templates_dir="/templates" diff --git a/charts/eduide/templates/operator.yaml b/charts/eduide/templates/operator.yaml index af64749..f095b83 100644 --- a/charts/eduide/templates/operator.yaml +++ b/charts/eduide/templates/operator.yaml @@ -45,9 +45,6 @@ spec: - "--keycloakClientId" - "{{ tpl (.Values.keycloak.clientId | toString) . }}" {{- end }} - {{- if .Values.gitea.enable }} - - "--gitea" - {{- end }} {{ if .Values.operator.eagerStart }}- "--eagerStart"{{ end }} - "--cloudProvider" - {{ tpl (.Values.operator.cloudProvider | toString) . }} diff --git a/charts/eduide/values.yaml b/charts/eduide/values.yaml index eb98195..ae2327b 100644 --- a/charts/eduide/values.yaml +++ b/charts/eduide/values.yaml @@ -229,31 +229,6 @@ keycloak: # for how to generate a strong cookie secret. cookieSecret: "OQINaROshtE9TcZkNAm5Zs2Pv3xaWytBmc5W7sPX7ws=" -# -- Values related to Gitea / generic OIDC authentication. -# Mutually exclusive with keycloak (a single oauth2-proxy provider is supported per session). -# @default -- (see details below) -gitea: - # -- Whether Gitea / generic OIDC authentication shall be used - enable: false - - # -- The Gitea base URL used as the OIDC issuer. Only has to be specified when enable: true. - # This must be the issuer base URL without a trailing slash and without a realms path, - # e.g. "https://gitea.example.com". - issuerUrl: "https://gitea.example.com" - - # -- The client-id. Only has to be specified when enable: true - clientId: "theia-cloud" - - # -- The client secret configured for the OIDC application in Gitea. - # Must be provided (rendering fails when gitea.enable is true and this is empty). - clientSecret: "" - - # -- The cookie secret. This should not be public! Must be provided when enable: true - # (rendering fails when gitea.enable is true and this is empty). - # See https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/overview/#generating-a-cookie-secret - # for how to generate a strong cookie secret. - cookieSecret: "" - # -- Values related to OAuth2 Proxy configuration oauth2Proxy: # -- Whether OAuth2 Proxy skips TLS certificate verification of the OIDC provider