CI / k8s (push) Successful in 14s
CI / build (push) Successful in 2m2s
CI / lint (push) Successful in 2m32s
CI / unit (push) Successful in 1m36s
CI / frontend (push) Successful in 3m3s
Deploy to Talos / deploy (push) Successful in 3m39s
CI / mutation (push) Successful in 5m31s
CI / verify-stack (push) Failing after 17m26s
## What & why Makes the portals reachable on real hostnames through the Caddy that already fronts `*.labs.respellion.tech`, instead of five SSH port-forwards: | URL | Service | |---|---| | `https://big-register.labs.respellion.tech` | openbaar | | `https://big-mijn.labs.respellion.tech` | self-service | | `https://big-behandel.labs.respellion.tech` | behandel | | `https://big-beheer.labs.respellion.tech` | beheer | | `https://big-auth.labs.respellion.tech` | Keycloak (`/admin` blocked) | Chain: browser → labs Caddy (TLS) → `openssh-server` container → reverse SSH tunnel → Fedora host → Talos NodePorts. The Caddy routes and the tunnel unit are already on `main` in the Infra repo (`infra/development/`). This repo's part: - **Chart:** a `keycloakUrl` value. When set it replaces `host` + Keycloak's NodePort as the pinned issuer (`KC_HOSTNAME`) and the portals' OIDC authority. Both now come from one helper, `big.keycloakUrl`, so they can't drift apart (ADR-0010). Empty = rendered output identical to today. - **Deploy workflow:** passes the `KEYCLOAK_URL` repo variable as `--set keycloakUrl=…`. - **Runbook:** new section "Publishing through the labs Caddy". Refs #177 ## Definition of Done - [x] Linked Gitea issue (above). - [ ] Failing test committed before the implementation. *(Infra/config change, no test added.)* - [x] Implementation makes the test pass; refactor commit if structure improved. - [x] Conventional Commits referencing the issue (`refs #NN`). - [ ] CI green — all Gitea Actions jobs (or `make ci` green while no runner exists). - [x] `docker compose up` from a fresh clone reaches green health checks within 3 minutes. *(Compose untouched.)* - [x] Docs updated if behaviour, contracts, or operations changed. - [ ] ADR added in `docs/architecture/` if a non-obvious decision was made. - [ ] Demo note in `docs/demo-script.md` if user-visible. ## Notes for reviewers - **This takes the option #177 rejects.** #177 proposes an in-cluster Caddy edge (branch `feat/177-public-tls-edge`). This PR uses the existing labs Caddy instead, because it already holds 80/443 and the wildcard certificate. So it only *refs* #177. If we go this way, #177's ADR should record the host-Caddy option instead. - `make k8s-lint` and `infra/check-docs-nav.py` pass. I rendered the chart with and without `keycloakUrl`: empty gives the same output as before; set, it gives `https://big-auth.labs.respellion.tech` for both the issuer and the authority. - Once `KEYCLOAK_URL` is set, the `localhost` port-forward workflow (runbook §5) no longer logs in, because the issuer is a single string. - The portals are public, with no Azure `authorize` in front of them the way `marketing` has one. The test users use `test123`. - Rollout after merge: install `big-portals-tunnel.service` on the Fedora host, run `docker compose up -d caddy` on the labs server, then set the `KEYCLOAK_URL` variable. 🤖 Generated with [Claude Code](https://claude.com/claude-code)Reviewed-on: #179
45 lines
1.7 KiB
YAML
45 lines
1.7 KiB
YAML
{{- /*
|
|
Shared env blocks — the Kubernetes equivalent of the YAML anchors in
|
|
infra/docker-compose.yml (&oz-env, &nrc-env, &objecttypen-env, &objecten-env).
|
|
A workload picks them up with `envFrom`, so the web/celery/init variants of an
|
|
upstream image stay guaranteed-identical, and `kubectl get cm oz-env -o yaml`
|
|
shows what a pod actually got.
|
|
|
|
The *file* inputs (setup_configuration data.yaml, Keycloak realms, BPMN/DMN, the
|
|
seed scripts) are NOT here: they live in the repo and are turned into ConfigMaps
|
|
by infra/helm/seed-configmaps.sh, exactly as infra/seed-config.sh streams them
|
|
into the compose config volumes. Copying them into the chart would fork them.
|
|
*/ -}}
|
|
{{- range $group, $env := .Values.envGroups }}
|
|
---
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: {{ $group }}-env
|
|
labels:
|
|
{{- include "big.labels" (dict "root" $ "name" (printf "%s-env" $group)) | nindent 4 }}
|
|
data:
|
|
{{- range $k, $v := $env }}
|
|
{{ $k }}: {{ tpl (toString $v) $ | quote }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- /*
|
|
Portal OIDC config. The images bake config.json with the compose authority
|
|
(keycloak:8080), which a browser outside the cluster cannot resolve; these
|
|
ConfigMaps mount over it with the node address Keycloak's issuer is pinned to
|
|
(KC_HOSTNAME below), so the token the browser gets and the issuer the BFF
|
|
discovers are the same string. Same mechanism as infra/host-browser.yml.
|
|
*/ -}}
|
|
{{- range $realm := list "digid" "medewerker" }}
|
|
---
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: portal-config-{{ $realm }}
|
|
labels:
|
|
{{- include "big.labels" (dict "root" $ "name" (printf "portal-config-%s" $realm)) | nindent 4 }}
|
|
data:
|
|
config.json: |
|
|
{ "authority": "{{ include "big.keycloakUrl" $ }}/realms/{{ $realm }}" }
|
|
{{- end }}
|