Compare commits

...

6 Commits

Author SHA1 Message Date
ace
6e7a28c2ae
update and fix sample vars 2024-05-06 03:00:59 +03:00
ace
d3db3af028
make postgres more tunable 2024-05-06 03:00:42 +03:00
ace
d9dd334988
fix tsig key name 2024-05-06 03:00:27 +03:00
ace
5d57ca8dce
fix core infra dns 2024-05-06 03:00:19 +03:00
ace
7e508f906f
fix core infra dns 2024-05-06 03:00:14 +03:00
ace
3ac1b27b4c
add keycloak 2024-05-06 03:00:10 +03:00
16 changed files with 293 additions and 81 deletions

View File

@ -22,13 +22,13 @@ metallb_bgp_aggregation_length: 24
## Nginx Ingress ## ## Nginx Ingress ##
### Internal ### ### Internal ###
internal_ingress_class: "ghp-internal-nginx" internal_ingress_class: "{{ namespace }}-internal-nginx"
internal_loadbalancer_ip: "192.168.250.0" internal_loadbalancer_ip: "192.168.250.0"
### External ### ### External ###
internal_ingress_class: "ghp-external-nginx" external_ingress_class: "{{ namespace }}-external-nginx"
external_loadbalancer_ip: "192.168.250.10" external_loadbalancer_ip: "192.168.250.10"
### Local ### ### Local ###
internal_ingress_class: "ghp-local-nginx" local_ingress_class: "{{ namespace }}-local-nginx"
local_loadbalancer_ip: "192.168.250.20" local_loadbalancer_ip: "192.168.250.20"
## External-dns ## ## External-dns ##

View File

@ -0,0 +1,46 @@
keycloak_values: {}
keycloak_realms: {}
# - id: myrealm
# realm: myrealm
keycloak_clients: {}
# - client_id: gitea
# realm: myrealm
# public_client: true
# - client_id: gitea
# realm: myrealm
# public_client: false
keycloak_clients_default_protocol_mappings: {}
# - config:
# access.token.claim: true
# claim.name: "groups"
# id.token.claim: true
# jsonType.label: String
# user.attribute: groups
# userinfo.token.claim: true
# name: groups
# protocol: openid-connect
# protocolMapper: oidc-usermodel-attribute-mapper
keycloak_groups: {}
# - name: admins
# realm: myrealm
# - name: devops
# realm: myrealm
keycloak_users: {}
# - username: John Doe
# realm: myrealm
# firstName: John
# lastName: Doe
# credentials:
# - type: password
# value: my_very_strong_password
# temporary: true
# groups:
# - name: admins
# state: present
# - name: devops
# state: present

View File

@ -1,43 +1 @@
nextcloud_values: nextcloud_values: {}
nextcloud:
configs:
mail.fix.config.php: |-
<?php
$CONFIG = array (
"mail_smtptimeout" => 60,
);
fix.config.php: |-
<?php
$CONFIG = array (
'trusted_proxies' => ['{{ web_proxy_internal_ip }}'],
'overwriteprotocol' => 'https',
'overwrite.cli.url' => 'https://nextcloud.{{ domain }}',
'mail_smtpstreamoptions' =>
array (
'ssl' =>
array (
'allow_self_signed' => true,
'verify_peer' => false,
'verify_peer_name' => false,
),
),
);
rgw.config.php: |-
<?php
$CONFIG = array (
'objectstore_multibucket' => array(
'class' => '\\OC\\Files\\ObjectStore\\S3',
'arguments' => array(
'bucket' => 'nextcloud',
'autocreate' => true,
'key' => 'K4PNZLSTLIDQJMZUV27P',
'secret' => 'iPScsni8RS2aT9MFymfQYLPD7W8dVrRqFpafBKDc',
'hostname' => 'sds1-osd1.lan',
'port' => 8080,
'use_ssl' => false,
'num_buckets' => 16,
'region' => 'us-east-1',
'use_path_style' => true
),
),
);

View File

@ -35,7 +35,9 @@
- name: Deploy Internal DNS - name: Deploy Internal DNS
import_role: import_role:
name: internal-dns name: internal-dns
when: internal_dns_enabled | default(true) when:
- internal_dns_enabled | default(true)
- domain is defined
tags: tags:
- internal-dns - internal-dns
- dns - dns
@ -43,7 +45,9 @@
- name: Deploy Local DNS - name: Deploy Local DNS
import_role: import_role:
name: local-dns name: local-dns
when: local_dns_enabled | default(true) when:
- local_dns_enabled | default(true)
- local_domain is defined
tags: tags:
- local-dns - local-dns
- dns - dns
@ -51,7 +55,9 @@
- name: Deploy Service DNS - name: Deploy Service DNS
import_role: import_role:
name: service-dns name: service-dns
when: service_dns_enabled | default(true) when:
- service_dns_enabled | default(true)
- domain is defined
tags: tags:
- service-dns - service-dns
- dns - dns

View File

@ -0,0 +1,5 @@
---
- hosts: k8s
connection: local
roles:
- keycloak

View File

@ -19,3 +19,9 @@
name: minio name: minio
when: minio_enabled | default(true) when: minio_enabled | default(true)
tags: minio tags: minio
- name: Deploy Keycloak
import_role:
name: keycloak
when: keycloak_enabled | default(false)
tags: keycloak

View File

@ -10,7 +10,7 @@ internal_dns_default_values:
zone: "{{ internal_domain | default(domain) }}" zone: "{{ internal_domain | default(domain) }}"
tsigSecret: "{{ k8s_tsig }}" tsigSecret: "{{ k8s_tsig }}"
tsigSecretAlg: "{{ internal_dns_tsigSecretAlg | default('hmac-sha512') }}" tsigSecretAlg: "{{ internal_dns_tsigSecretAlg | default('hmac-sha512') }}"
tsigKeyname: "{{ internal_dns_tsigKeyname | default('k8s') }}" tsigKeyname: "{{ internal_dns_tsigKeyname | default(namespace) }}"
tsigAxfr: true tsigAxfr: true
## Possible units [ns, us, ms, s, m, h], see more https://golang.org/pkg/time/#ParseDuration ## Possible units [ns, us, ms, s, m, h], see more https://golang.org/pkg/time/#ParseDuration
minTTL: "30s" minTTL: "30s"

View File

@ -0,0 +1,63 @@
keycloak_enabled: true
keycloak_publish: false
keycloak_console_publish: false
keycloak_use_external_db: true
keycloak_chart_ref: "codecentric/keycloakx"
keycloak_short_name: "keycloak"
keycloak_console_short_name: "console"
keycloak_default_values:
command:
- /opt/keycloak/bin/kc.sh
- start
- --http-enabled=true
- --http-port=8080
- --hostname={{ keycloak_short_name }}.{{ domain }}
- --hostname-strict=false
- --hostname-strict-https=false
database:
database: "keycloak"
hostname: "{{ postgres_db_team | default(namespace) }}-postgres.{{ postgres_db_namespace | default(namespace) }}"
username: "{{ keycloak_db_username | default(omit) }}"
password: "{{ keycloak_db_password | default(omit) }}"
port: 5432
vendor: postgres
extraEnv: |
- name: KEYCLOAK_ADMIN
value: admin
- name: KEYCLOAK_ADMIN_PASSWORD
value: {{ keycloak_admin_password }}
- name: JAVA_OPTS_APPEND
value: >-
-Djgroups.dns.query={{ keycloak_short_name }}-keycloakx-headless
ingress:
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
enabled: true
ingressClassName: "{{ external_ingress_class if minio_publish else internal_ingress_class }}"
rules:
- host: "{{ keycloak_short_name }}.{{ domain }}"
paths:
- path: /auth/
pathType: Prefix
servicePort: http
tls:
- hosts:
- "{{ keycloak_short_name }}.{{ domain }}"
secretName: "{{ keycloak_short_name }}.{{ domain }}-tls"
keycloak_realms: {}
keycloak_clients: {}
keycloak_clients_default_protocol_mappings: {}
# - config:
# access.token.claim: true
# claim.name: "groups"
# id.token.claim: true
# jsonType.label: String
# user.attribute: groups
# userinfo.token.claim: true
# name: groups
# protocol: openid-connect
# protocolMapper: oidc-usermodel-attribute-mapper
keycloak_users: {}
keycloak_groups: {}

View File

@ -0,0 +1,96 @@
- name: Import secret.yaml to obtain secrets
include_tasks: secrets.yaml
when:
- keycloak_use_external_db
- postgres_enabled is defined and postgres_enabled
- set_fact:
keycloak_combined_values: "{{ keycloak_default_values | combine(keycloak_values, recursive=true) }}"
- name: Deploy Keycloak
kubernetes.core.helm:
release_namespace: "{{ keycloak_namespace | default(namespace) }}"
release_name: "{{ keycloak_name | default('keycloak') }}"
chart_ref: "{{ keycloak_chart_ref }}"
chart_version: "{{ keycloak_version | default(omit) }}"
release_values: "{{ keycloak_combined_values | from_yaml }}"
- name: Wait Keycloak until HTTP status is 200
uri:
url: "https://{{ keycloak_short_name }}.{{ domain }}/auth"
return_content: yes
validate_certs: no
status_code:
- 200
until: uri_output.status == 200
retries: 24 # Retries for 24 * 5 seconds = 120 seconds = 2 minutes
delay: 5 # Every 5 seconds
register: uri_output
- name: Create or update Keycloak client, authentication with credentials
community.general.keycloak_client:
client_id: admin-cli
auth_keycloak_url: "https://{{ keycloak_short_name }}.{{ domain }}/auth"
auth_realm: master
auth_username: admin
auth_password: "{{ keycloak_admin_password }}"
state: present
- name: Create or update Keycloak realms
community.general.keycloak_realm:
auth_client_id: admin-cli
auth_keycloak_url: "https://{{ keycloak_short_name }}.{{ domain }}/auth"
auth_realm: master
auth_username: admin
auth_password: "{{ keycloak_admin_password }}"
id: "{{ item.id }}"
realm: "{{ item.realm }}"
state: "{{ item.state | default('present') }}"
enabled: "{{ item.enabled | default(true) }}"
loop: "{{ keycloak_realms }}"
- name: Create or update Keycloak clients
community.general.keycloak_client:
auth_client_id: admin-cli
auth_keycloak_url: "https://{{ keycloak_short_name }}.{{ domain }}/auth"
auth_realm: master
auth_username: admin
auth_password: "{{ keycloak_admin_password }}"
client_id: "{{ item.client_id + '-public' if item.public_client else item.client_id }}"
realm: "{{ item.realm }}"
name: "{{ \"'${client_\" + item.client_id + \"'\" if item.public_client else \"'${client_\" + item.client_id + \"_public'\" }}"
protocol: openid-connect
public_client: "{{ item.public_client | default(false) }}"
standard_flow_enabled: "{{ item.standard_flow_enabled | default(true) }}"
implicit_flow_enabled: "{{ item.implicit_flow_enabled | default(true) }}"
direct_access_grants_enabled: "{{ item.direct_access_grants_enabled | default(true) }}"
state: "{{ item.state | default('present') }}"
protocol_mappers: "{{ keycloak_clients_default_protocol_mappings }}"
loop: "{{ keycloak_clients }}"
- name: Create Keycloak groups
community.general.keycloak_group:
auth_client_id: admin-cli
auth_keycloak_url: "https://{{ keycloak_short_name }}.{{ domain }}/auth"
auth_realm: master
auth_username: admin
auth_password: "{{ keycloak_admin_password }}"
realm: "{{ item.realm }}"
name: "{{ item.name }}"
state: "{{ item.state | default('present') }}"
loop: "{{ keycloak_groups }}"
- name: Create Keycloak users
community.general.keycloak_user:
auth_client_id: admin-cli
auth_keycloak_url: "https://{{ keycloak_short_name }}.{{ domain }}/auth"
auth_realm: master
auth_username: admin
auth_password: "{{ keycloak_admin_password }}"
realm: "{{ item.realm }}"
state: "{{ item.state | default('present') }}"
username: "{{ item.username }}"
firstName: "{{ item.firstName }}"
lastName: "{{ item.lastName }}"
email: "{{ item.email | default( item.username + '@' + domain) }}"
enabled: "{{ item.enabled | default(true) }}"
emailVerified: "{{ item.emailVerified | default(true) }}"
credentials: "{{ item.credentials }}"
groups: "{{ item.groups }}"
loop: "{{ keycloak_users }}"

View File

@ -0,0 +1,25 @@
- block:
- name: Set DB namespace for secret lookup
set_fact:
db_namespace: "{{ keycloak_db_namespace | default(postgres_db_namespace) | default(postgres_namespace) | default(postgres_operator_namespace) | default(namespace) }}"
- name: Set DB secret name for lookup
set_fact:
db_secret_name: "keycloak.{{ postgres_db_team | default(namespace) }}-postgres.credentials.postgresql.acid.zalan.do"
- name: Lookup Keycloak DB secret
set_fact:
keycloak_db_secret: "{{ lookup('k8s', kind='Secret', namespace=db_namespace, resource_name=db_secret_name) }}"
- debug:
msg: "{{ keycloak_db_secret }}"
verbosity: 2
- name: Set Keycloak DB username
set_fact:
keycloak_db_username: "{{ keycloak_db_secret.data.username | b64decode }}"
- name: Set Keycloak DB password
set_fact:
keycloak_db_password: "{{ keycloak_db_secret.data.password | b64decode }}"

View File

@ -10,7 +10,7 @@ local_dns_default_values:
zone: "{{ local_domain }}" zone: "{{ local_domain }}"
tsigSecret: "{{ k8s_tsig }}" tsigSecret: "{{ k8s_tsig }}"
tsigSecretAlg: "{{ local_dns_tsigSecretAlg | default('hmac-sha512') }}" tsigSecretAlg: "{{ local_dns_tsigSecretAlg | default('hmac-sha512') }}"
tsigKeyname: "{{ local_dns_tsigKeyname | default('k8s') }}" tsigKeyname: "{{ local_dns_tsigKeyname | default(namespace) }}"
tsigAxfr: true tsigAxfr: true
## Possible units [ns, us, ms, s, m, h], see more https://golang.org/pkg/time/#ParseDuration ## Possible units [ns, us, ms, s, m, h], see more https://golang.org/pkg/time/#ParseDuration
minTTL: "30s" minTTL: "30s"

View File

@ -1,3 +1,6 @@
postgres_enabled: true
postgres_operator_enabled: true
postgres_operator_ui_enabled: true
postgres_operator_chart_ref: "ghp/postgres-operator" postgres_operator_chart_ref: "ghp/postgres-operator"
postgres_operator_ui_chart_ref: "ghp/postgres-operator-ui" postgres_operator_ui_chart_ref: "ghp/postgres-operator-ui"
postgres_operator_ui_short_name: "postgres-operator-ui" postgres_operator_ui_short_name: "postgres-operator-ui"
@ -64,6 +67,7 @@ postgres_db_definitions:
roundcube: [] roundcube: []
harbor: [] harbor: []
mastodon: [] mastodon: []
keycloak: []
databases: databases:
gitea: gitea gitea: gitea
bitwarden: bitwarden bitwarden: bitwarden
@ -75,6 +79,7 @@ postgres_db_definitions:
harbor_notary_server: harbor harbor_notary_server: harbor
harbor_notary_signer: harbor harbor_notary_signer: harbor
mastodon: mastodon mastodon: mastodon
keycloak: keycloak
preparedDatabases: preparedDatabases:
peertube: peertube:
defaultUsers: true defaultUsers: true

View File

@ -44,6 +44,7 @@
- set_fact: - set_fact:
postgres_operator_combined_values: "{{ postgres_operator_default_values | combine(postgres_operator_values, recursive=true) }}" postgres_operator_combined_values: "{{ postgres_operator_default_values | combine(postgres_operator_values, recursive=true) }}"
when: postgres_operator_enabled
- name: Deploy Postgres Operator - name: Deploy Postgres Operator
kubernetes.core.helm: kubernetes.core.helm:
@ -54,9 +55,11 @@
chart_version: "{{ postgres_operator_version | default(omit) }}" chart_version: "{{ postgres_operator_version | default(omit) }}"
release_values: "{{ postgres_operator_combined_values | from_yaml }}" release_values: "{{ postgres_operator_combined_values | from_yaml }}"
wait: true wait: true
when: postgres_operator_enabled
- set_fact: - set_fact:
postgres_operator_ui_combined_values: "{{ postgres_operator_ui_default_values | combine(postgres_operator_ui_values, recursive=true) }}" postgres_operator_ui_combined_values: "{{ postgres_operator_ui_default_values | combine(postgres_operator_ui_values, recursive=true) }}"
when: postgres_operator_ui_enabled
- name: Deploy Postgres Operator UI - name: Deploy Postgres Operator UI
kubernetes.core.helm: kubernetes.core.helm:
@ -67,6 +70,7 @@
chart_version: "{{ postgres_operator_ui_version | default(omit) }}" chart_version: "{{ postgres_operator_ui_version | default(omit) }}"
release_values: "{{ postgres_operator_ui_combined_values | from_yaml }}" release_values: "{{ postgres_operator_ui_combined_values | from_yaml }}"
wait: true wait: true
when: postgres_operator_ui_enabled
- name: Create Postgres databases - name: Create Postgres databases
k8s: k8s:

View File

@ -15,6 +15,7 @@ default_accounts:
- { name: harbor_admin } - { name: harbor_admin }
- { name: systemuser } - { name: systemuser }
- { name: minio_admin } - { name: minio_admin }
- { name: keycloak_admin }
secret_keys: secret_keys:
- { name: peertube } - { name: peertube }

View File

@ -21,13 +21,10 @@
cleanup: true cleanup: true
detach: false detach: false
container_default_behavior: no_defaults container_default_behavior: no_defaults
command: "keymgr -t k8s hmac-sha512" command: "keymgr -t {{ namespace }} hmac-sha512"
register: knot_container_output register: knot_container_output
when: k8s_tsig_test_grep.stdout == '0' when: k8s_tsig_test_grep.stdout == '0'
- debug:
msg: "{{ knot_container_output }}"
- name: Set k8s_key - name: Set k8s_key
set_fact: set_fact:
k8s_key: "{{ knot_container_output.container.Output | from_yaml }}" k8s_key: "{{ knot_container_output.container.Output | from_yaml }}"

View File

@ -10,7 +10,7 @@ service_dns_default_values:
zone: "{{ service_domain | default(domain) }}" zone: "{{ service_domain | default(domain) }}"
tsigSecret: "{{ k8s_tsig }}" tsigSecret: "{{ k8s_tsig }}"
tsigSecretAlg: "{{ service_dns_tsigSecretAlg | default('hmac-sha512') }}" tsigSecretAlg: "{{ service_dns_tsigSecretAlg | default('hmac-sha512') }}"
tsigKeyname: "{{ service_dns_tsigKeyname | default('k8s') }}" tsigKeyname: "{{ service_dns_tsigKeyname | default(namespace) }}"
tsigAxfr: true tsigAxfr: true
## Possible units [ns, us, ms, s, m, h], see more https://golang.org/pkg/time/#ParseDuration ## Possible units [ns, us, ms, s, m, h], see more https://golang.org/pkg/time/#ParseDuration
minTTL: "30s" minTTL: "30s"