Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 0 additions & 6 deletions charts/eduide/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,12 +50,6 @@ environment. Requires eduide-cluster to be installed on the cluster first.
| gateway.routes.enabled | bool | `true` | Whether to render HTTPRoute resources. |
| gateway.serviceRouteRequestTimeout | string | `"60s"` | HTTPRoute request timeout for service-route (Envoy default can be 15s) |
| gateway.tls | bool | `true` | Does Theia Cloud expect TLS connections (true) or is TLS terminated outside of Theia Cloud (false) |
| gitea | object | (see details below) | Values related to Gitea / generic OIDC authentication. Mutually exclusive with keycloak (a single oauth2-proxy provider is supported per session). |
| gitea.clientId | string | `"theia-cloud"` | The client-id. Only has to be specified when enable: true |
| gitea.clientSecret | string | `""` | The client secret configured for the OIDC application in Gitea. Must be provided (rendering fails when gitea.enable is true and this is empty). |
| gitea.cookieSecret | string | `""` | The cookie secret. This should not be public! Must be provided when enable: true (rendering fails when gitea.enable is true and this is empty). See https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/overview/#generating-a-cookie-secret for how to generate a strong cookie secret. |
| gitea.enable | bool | `false` | Whether Gitea / generic OIDC authentication shall be used |
| gitea.issuerUrl | string | `"https://gitea.example.com"` | The Gitea base URL used as the OIDC issuer. Only has to be specified when enable: true. This must be the issuer base URL without a trailing slash and without a realms path, e.g. "https://gitea.example.com". |
| hosts | object | (see details below) | You may adjust the hostname below. |
| hosts.allWildcardInstances | list | `[]` | all additional wildcard hostnames that may be required in the launched Theia-applications, e.g. "*.webview." which leads to "*.webview.ws.192.168.39.173.nip.io" to expose webviews. Please note that this means that this usually means that all "ingressHostnamePrefixes" patterns from all app definitions need to be added. IMPORTANT: If this gets updated, the helm chart needs to be re-installed because helm upgrade will not properly update this at the moment. These are required to configure TLS (if enabled via gateway.tls == true) I.e. custom certificates or a cert-manager provider that can handle wildcard certificates need to be configured. |
| hosts.configuration | object | (see details below) | Configuration for the hostnames. Contains the baseHost and afixes for all services |
Expand Down
2 changes: 0 additions & 2 deletions charts/eduide/templates/_preflight.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -43,12 +43,10 @@
*/}}
{{- define "eduide.preflightKeycloak" -}}
{{- $kc := .Values.keycloak -}}
{{- if not .Values.gitea.enable }}
{{- $placeholder := or (eq ($kc.authUrl | toString) "https://keycloak.url/auth/")
(eq ($kc.realm | toString) "TheiaCloud")
(eq ($kc.clientId | toString) "theia-cloud") -}}
{{- if and $placeholder (not $kc.allowUnauthenticated) }}
{{- fail (printf "keycloak is left at the chart's placeholder values (authUrl=%s realm=%s clientId=%s). Configure them, or set keycloak.allowUnauthenticated=true to install without a working identity provider." $kc.authUrl $kc.realm $kc.clientId) }}
{{- end }}
{{- end }}
{{- end -}}
8 changes: 0 additions & 8 deletions charts/eduide/templates/landing-page-config-map.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -15,14 +15,6 @@ data:
keycloakAuthUrl: "{{ tpl (.Values.keycloak.authUrl | toString) . }}",
keycloakRealm: "{{ tpl (.Values.keycloak.realm | toString) . }}",
keycloakClientId: "{{ tpl (.Values.keycloak.clientId | toString) . }}",
useGiteaOidc: {{ tpl (.Values.gitea.enable | toString) . }},
{{- if .Values.gitea.enable }}
giteaIssuerUrl: "{{ tpl (.Values.gitea.issuerUrl | toString) . }}",
giteaClientId: "{{ tpl (.Values.gitea.clientId | toString) . }}",
{{- else }}
giteaIssuerUrl: "",
giteaClientId: "",
{{- end }}
serviceUrl: "{{ include "theia-cloud.url.service" . }}",
appDefinition: "{{ tpl (.Values.landingPage.appDefinition | toString) . }}",
{{- /*
Expand Down
Original file line number Diff line number Diff line change
@@ -1,22 +1,9 @@
{{- /* keycloak and gitea use the same single oauth2-proxy provider, so only one may be enabled. */ -}}
{{- if and .Values.keycloak.enable .Values.gitea.enable }}{{- fail "keycloak.enable and gitea.enable are mutually exclusive (single oauth2-proxy provider)" }}{{- end }}
{{- /* Gitea OIDC applications issue real credentials, so require them explicitly instead of shipping insecure defaults. */ -}}
{{- if .Values.gitea.enable }}
{{- if not (tpl (.Values.gitea.clientSecret | toString) .) }}{{- fail "gitea.clientSecret must be set when gitea.enable is true" }}{{- end }}
{{- if not (tpl (.Values.gitea.cookieSecret | toString) .) }}{{- fail "gitea.cookieSecret must be set when gitea.enable is true" }}{{- end }}
{{- end }}
{{- /* Extract the host where the Keycloak runs by extracting it from the auth URL via regex. */ -}}
{{- $keycloakUrl := tpl (.Values.keycloak.authUrl | toString) . -}}
{{- /* Regex to match a URL that matches the host in group 1: ([^/]+) */ -}}
{{- $hostRegex := `^https?://([^/]+)(/.*)?$` -}}
{{- /* Replace the URL with only the first group which is only the host. */ -}}
{{- $keycloakHost:= regexReplaceAll $hostRegex $keycloakUrl `$1` -}}
{{- /* Extract the host where Gitea runs the same way from the issuer URL. */ -}}
{{- $giteaUrl := tpl (.Values.gitea.issuerUrl | toString) . -}}
{{- $giteaHost := regexReplaceAll $hostRegex $giteaUrl `$1` -}}
{{- /* Host of the currently enabled OIDC provider, used for the whitelist defaults. */ -}}
{{- $oauthHost := $keycloakHost -}}
{{- if .Values.gitea.enable }}{{- $oauthHost = $giteaHost -}}{{- end }}

apiVersion: v1
kind: ConfigMap
Expand All @@ -26,29 +13,14 @@ metadata:
data:
oauth2-proxy.cfg: |+
# Provider config
{{- if .Values.gitea.enable }}
provider="oidc"
{{- else }}
provider="keycloak-oidc"
{{- end }}
redirect_url="https://placeholder/oauth2/callback"
{{- if .Values.gitea.enable }}
oidc_issuer_url="{{ $giteaUrl }}"
{{- else }}
oidc_issuer_url="{{ $keycloakUrl }}realms/{{ tpl (.Values.keycloak.realm | toString) . }}"
{{- end }}
ssl_insecure_skip_verify={{ .Values.oauth2Proxy.sslInsecureSkipVerify }}
# Client config
{{- if .Values.gitea.enable }}
client_id="{{ tpl (.Values.gitea.clientId | toString) . }}"
client_secret="{{ tpl (.Values.gitea.clientSecret | toString) . }}"
cookie_secret="{{ tpl (.Values.gitea.cookieSecret | toString) . }}"
pass_access_token=true
{{- else }}
client_id="{{ tpl (.Values.keycloak.clientId | toString) . }}"
client_secret="{{ tpl (.Values.keycloak.clientSecret | toString) . }}"
cookie_secret="{{ tpl (.Values.keycloak.cookieSecret | toString) . }}"
{{- end }}
cookie_secure="false"
#proxy_prefix=""
# Upstream config
Expand All @@ -70,6 +42,6 @@ data:
{{- if gt (len $whitelistDomains) 0 }}
whitelist_domains={{ toJson $whitelistDomains }}
{{- else }}
whitelist_domains=["{{ tpl (.Values.hosts.configuration.instance | toString) . }}:*","{{ $oauthHost }}:*"]
whitelist_domains=["{{ tpl (.Values.hosts.configuration.instance | toString) . }}:*","{{ $keycloakHost }}:*"]
{{- end }}
custom_templates_dir="/templates"
3 changes: 0 additions & 3 deletions charts/eduide/templates/operator.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -45,9 +45,6 @@ spec:
- "--keycloakClientId"
- "{{ tpl (.Values.keycloak.clientId | toString) . }}"
{{- end }}
{{- if .Values.gitea.enable }}
- "--gitea"
{{- end }}
{{ if .Values.operator.eagerStart }}- "--eagerStart"{{ end }}
- "--cloudProvider"
- {{ tpl (.Values.operator.cloudProvider | toString) . }}
Expand Down
25 changes: 0 additions & 25 deletions charts/eduide/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -229,31 +229,6 @@ keycloak:
# for how to generate a strong cookie secret.
cookieSecret: "OQINaROshtE9TcZkNAm5Zs2Pv3xaWytBmc5W7sPX7ws="

# -- Values related to Gitea / generic OIDC authentication.
# Mutually exclusive with keycloak (a single oauth2-proxy provider is supported per session).
# @default -- (see details below)
gitea:
# -- Whether Gitea / generic OIDC authentication shall be used
enable: false

# -- The Gitea base URL used as the OIDC issuer. Only has to be specified when enable: true.
# This must be the issuer base URL without a trailing slash and without a realms path,
# e.g. "https://gitea.example.com".
issuerUrl: "https://gitea.example.com"

# -- The client-id. Only has to be specified when enable: true
clientId: "theia-cloud"

# -- The client secret configured for the OIDC application in Gitea.
# Must be provided (rendering fails when gitea.enable is true and this is empty).
clientSecret: ""

# -- The cookie secret. This should not be public! Must be provided when enable: true
# (rendering fails when gitea.enable is true and this is empty).
# See https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/overview/#generating-a-cookie-secret
# for how to generate a strong cookie secret.
cookieSecret: ""

# -- Values related to OAuth2 Proxy configuration
oauth2Proxy:
# -- Whether OAuth2 Proxy skips TLS certificate verification of the OIDC provider
Expand Down
Loading