updated ingresses for homepage and glance

This commit is contained in:
2026-01-22 20:33:47 +01:00
parent 0dfaee6cc7
commit ae599fbbeb
2 changed files with 12 additions and 43 deletions
+8 -39
View File
@@ -1,6 +1,6 @@
# Glance Dashboard for Orsi
# Namespace: glance-system
# Domain: home.dooplex.hu
# Domain: orsi.dooplex.hu
# Version: v0.8.4
#
# Features:
@@ -15,9 +15,9 @@
# - Calendar widget
#
# Authentik Integration:
# 1. Create Application: "Glance Home"
# 2. Create Provider: Proxy Provider with external host https://home.dooplex.hu
# 3. Create Outpost: glance-home-outpost
# 1. Create Application: "Glance Orsi"
# 2. Create Provider: Proxy Provider with external host https://orsi.dooplex.hu
# 3. Create Outpost: glance-outpost
# 4. Update auth-url annotation with actual outpost service name
---
apiVersion: v1
@@ -739,7 +739,7 @@ metadata:
app.kubernetes.io/instance: glance-orsi
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
external-dns.alpha.kubernetes.io/hostname: home.dooplex.hu
external-dns.alpha.kubernetes.io/hostname: orsi.dooplex.hu
nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: "16k"
nginx.ingress.kubernetes.io/proxy-buffers-number: "4"
@@ -747,7 +747,7 @@ metadata:
# Authentik Forward Auth annotations
# TODO: Update 'glance-home-outpost' with your actual outpost name after creating in Authentik
nginx.ingress.kubernetes.io/auth-url: http://ak-outpost-glance-outpost.auth-system.svc.cluster.local:9000/outpost.goauthentik.io/auth/nginx
nginx.ingress.kubernetes.io/auth-signin: https://home.dooplex.hu/outpost.goauthentik.io/start?rd=$escaped_request_uri
nginx.ingress.kubernetes.io/auth-signin: https://orsi.dooplex.hu/outpost.goauthentik.io/start?rd=$escaped_request_uri
nginx.ingress.kubernetes.io/auth-response-headers: Set-Cookie,X-authentik-username,X-authentik-groups,X-authentik-email
nginx.ingress.kubernetes.io/auth-snippet: |
proxy_set_header X-Forwarded-Host $http_host;
@@ -762,7 +762,7 @@ metadata:
spec:
ingressClassName: nginx-internal
rules:
- host: home.dooplex.hu
- host: orsi.dooplex.hu
http:
paths:
- path: /
@@ -774,37 +774,6 @@ spec:
number: 8080
tls:
- hosts:
- home.dooplex.hu
- orsi.dooplex.hu
secretName: glance-tls
---
# Alternative Ingress WITHOUT Authentik (for testing)
# Uncomment this and comment out the above ingress if you want to test without auth first
# apiVersion: networking.k8s.io/v1
# kind: Ingress
# metadata:
# name: glance-noauth
# namespace: glance-system
# labels:
# app.kubernetes.io/name: glance
# app.kubernetes.io/instance: glance-orsi
# annotations:
# cert-manager.io/cluster-issuer: letsencrypt-prod
# external-dns.alpha.kubernetes.io/hostname: home.dooplex.hu
# nginx.ingress.kubernetes.io/ssl-redirect: "true"
# spec:
# ingressClassName: nginx-internal
# rules:
# - host: home.dooplex.hu
# http:
# paths:
# - path: /
# pathType: Prefix
# backend:
# service:
# name: glance
# port:
# number: 8080
# tls:
# - hosts:
# - home.dooplex.hu
# secretName: glance-tls
+4 -4
View File
@@ -518,7 +518,7 @@ metadata:
app.kubernetes.io/instance: homepage-orsi
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
external-dns.alpha.kubernetes.io/hostname: orsi.dooplex.hu
external-dns.alpha.kubernetes.io/hostname: orsihome.dooplex.hu
nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: "16k"
nginx.ingress.kubernetes.io/proxy-buffers-number: "4"
@@ -526,7 +526,7 @@ metadata:
# Authentik Forward Auth annotations
# Update 'homepage-outpost' with your actual outpost name
nginx.ingress.kubernetes.io/auth-url: http://ak-outpost-homepage-orsi-outpost.auth-system.svc.cluster.local:9000/outpost.goauthentik.io/auth/nginx
nginx.ingress.kubernetes.io/auth-signin: https://orsi.dooplex.hu/outpost.goauthentik.io/start?rd=$escaped_request_uri
nginx.ingress.kubernetes.io/auth-signin: https://orsihome.dooplex.hu/outpost.goauthentik.io/start?rd=$escaped_request_uri
nginx.ingress.kubernetes.io/auth-response-headers: Set-Cookie,X-authentik-username,X-authentik-groups,X-authentik-email
nginx.ingress.kubernetes.io/auth-snippet: |
proxy_set_header X-Forwarded-Host $http_host;
@@ -539,7 +539,7 @@ metadata:
spec:
ingressClassName: nginx-internal
rules:
- host: orsi.dooplex.hu
- host: orsihome.dooplex.hu
http:
paths:
- path: /
@@ -551,6 +551,6 @@ spec:
number: 3000
tls:
- hosts:
- orsi.dooplex.hu
- orsihome.dooplex.hu
secretName: homepage-orsi-tls
---