diff --git a/kisfenyo-system/guacamole.yaml b/kisfenyo-system/guacamole.yaml index d946257..80cd8b3 100644 --- a/kisfenyo-system/guacamole.yaml +++ b/kisfenyo-system/guacamole.yaml @@ -196,15 +196,15 @@ spec: - name: GUACD_PORT value: "4822" # --- PostgreSQL (shared CloudNativePG) --- - - name: POSTGRES_HOSTNAME + - name: POSTGRESQL_HOSTNAME value: postgresql-rw.database-system.svc.cluster.local - - name: POSTGRES_PORT + - name: POSTGRESQL_PORT value: "5432" - - name: POSTGRES_DATABASE + - name: POSTGRESQL_DATABASE value: guacamole_db - - name: POSTGRES_USER + - name: POSTGRESQL_USER value: guacamole - - name: POSTGRES_PASSWORD + - name: POSTGRESQL_PASSWORD valueFrom: secretKeyRef: name: guacamole-secrets @@ -213,31 +213,31 @@ spec: - name: WEBAPP_CONTEXT value: "ROOT" # --- OpenID Connect (Authentik) --- - - name: OPENID_AUTHORIZATION_ENDPOINT - value: "https://authentik.dooplex.hu/application/o/authorize/" - - name: OPENID_JWKS_ENDPOINT - value: "https://authentik.dooplex.hu/application/o/guacamole/jwks/" - - name: OPENID_ISSUER - value: "https://authentik.dooplex.hu/application/o/guacamole/" - - name: OPENID_CLIENT_ID - valueFrom: - secretKeyRef: - name: guacamole-secrets - key: openid-client-id - - name: OPENID_REDIRECT_URI - value: "https://remote.dooplex.hu/" - - name: OPENID_USERNAME_CLAIM_TYPE - value: "preferred_username" - - name: OPENID_GROUPS_CLAIM_TYPE - value: "groups" - - name: OPENID_SCOPE - value: "openid email profile" - # Show both DB login form AND OIDC button on login page - - name: EXTENSION_PRIORITY - value: "*, openid" - # Auto-create Guacamole accounts for OIDC users - - name: POSTGRESQL_AUTO_CREATE_ACCOUNTS - value: "true" + # - name: OPENID_AUTHORIZATION_ENDPOINT + # value: "https://authentik.dooplex.hu/application/o/authorize/" + # - name: OPENID_JWKS_ENDPOINT + # value: "https://authentik.dooplex.hu/application/o/guacamole/jwks/" + # - name: OPENID_ISSUER + # value: "https://authentik.dooplex.hu/application/o/guacamole/" + # - name: OPENID_CLIENT_ID + # valueFrom: + # secretKeyRef: + # name: guacamole-secrets + # key: openid-client-id + # - name: OPENID_REDIRECT_URI + # value: "https://remote.dooplex.hu/" + # - name: OPENID_USERNAME_CLAIM_TYPE + # value: "preferred_username" + # - name: OPENID_GROUPS_CLAIM_TYPE + # value: "groups" + # - name: OPENID_SCOPE + # value: "openid email profile" + # # Show both DB login form AND OIDC button on login page + # - name: EXTENSION_PRIORITY + # value: "*, openid" + # # Auto-create Guacamole accounts for OIDC users + # - name: POSTGRESQL_AUTO_CREATE_ACCOUNTS + # value: "true" ports: - containerPort: 8080 name: http