Compare commits

..

7 Commits

Author SHA1 Message Date
jorgen.stensrud 53cd44d6a2 feat(auth-sidecar): inject AUTH_OIDC_COOKIE_DOMAIN from annotation
/ test (pull_request) Successful in 31s
Empty when the annotation is unset = host-only = unchanged for every app.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 13:04:50 +02:00
jorgen.stensrud 3a23451802 feat(forte-drop): issuer dnsZones for *.drop.forteapps.net (subdomain-per-drop) (#22)
/ test (push) Successful in 12s
2026-06-26 11:38:30 +00:00
danijel.simeunovic 9297398d56 gitea update
/ test (push) Successful in 8s
2026-06-11 13:03:59 +02:00
danijel.simeunovic b0804e1e6a scan
/ test (push) Successful in 11s
2026-06-11 10:34:11 +02:00
danijel.simeunovic 8216399155 trufflehog
/ test (push) Failing after 33s
2026-06-11 10:14:25 +02:00
danijel.simeunovic a70f078bbb drop drop 2026-06-05 19:38:30 +02:00
danijel.simeunovic a24e61d538 disable slack notifications for forte-drop
Signed-off-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
2026-06-05 13:41:42 +00:00
8 changed files with 78 additions and 12 deletions
+20
View File
@@ -0,0 +1,20 @@
on:
push:
branches:
- main
pull_request:
jobs:
test:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Install TruffleHog
run: |
curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/scripts/install.sh \
| sh -s -- -b /usr/local/bin
- name: Secret Scanning
run: trufflehog git file://. --fail --no-update --results=verified,unknown
@@ -5,9 +5,9 @@ metadata:
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "1"
notifications.argoproj.io/subscribe.on-sync-succeeded.slack: ""
notifications.argoproj.io/subscribe.on-sync-failed.slack: ""
notifications.argoproj.io/subscribe.on-degraded.slack: ""
# notifications.argoproj.io/subscribe.on-sync-succeeded.slack: ""
# notifications.argoproj.io/subscribe.on-sync-failed.slack: ""
# notifications.argoproj.io/subscribe.on-degraded.slack: ""
labels:
app.kubernetes.io/name: forte-drop
app.kubernetes.io/part-of: apps
@@ -0,0 +1,33 @@
apiVersion: v1
kind: Secret
metadata:
name: keycloak-client-forte-drop
namespace: forte-drop
labels:
keycloak.forteapps.net/client-config: "true"
annotations:
keycloak.forteapps.net/source-namespace: "forte-drop"
stringData:
client.json: |
{
"clientId": "forte-drop",
"name": "Forte Drop (web)",
"enabled": true,
"protocol": "openid-connect",
"clientAuthenticatorType": "client-secret",
"standardFlowEnabled": true,
"directAccessGrantsEnabled": false,
"serviceAccountsEnabled": false,
"publicClient": false,
"redirectUris": ["https://drop.forteapps.net/auth/callback"],
"webOrigins": ["https://drop.forteapps.net"],
"defaultClientScopes": ["openid","email","profile"],
"secret": {
"namespace": "forte-drop",
"name": "forte-drop-oidc-credentials",
"keys": {
"clientId": "client-id",
"clientSecret": "client-secret"
}
}
}
@@ -2,5 +2,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- forte-drop.yaml
- keycloak-client-forte-drop.yaml
- forte-drop-pdb.yaml
- forte-drop-secrets-sealed.yaml
+18 -4
View File
@@ -24,8 +24,15 @@ spec:
name: azuredns-config
key: client-secret
selector:
dnsNames:
- '*.forteapps.net'
# NOTE: cert-manager solver selectors are NOT TLS-style wildcards. selector.dnsNames
# matches by exact FQDN, so '*.forteapps.net' here would match only a cert literally
# named '*.forteapps.net' — it would NOT cover 'drop.forteapps.net'. selector.dnsZones
# instead suffix-matches the zone apex AND every subdomain at any depth, so this single
# entry routes all forteapps.net ACME challenges (forteapps.net, *.forteapps.net,
# drop.forteapps.net, *.drop.forteapps.net, mcp.drop.forteapps.net, ...) through this
# Azure dns01 solver. Wildcard names require dns01; non-wildcard names that ever fail
# to match fall through to the http01 solver below.
dnsZones:
- 'forteapps.net'
# HTTP-01 fallback for non-wildcard certificates
- http01:
@@ -58,8 +65,15 @@ spec:
name: azuredns-config
key: client-secret
selector:
dnsNames:
- '*.forteapps.net'
# NOTE: cert-manager solver selectors are NOT TLS-style wildcards. selector.dnsNames
# matches by exact FQDN, so '*.forteapps.net' here would match only a cert literally
# named '*.forteapps.net' — it would NOT cover 'drop.forteapps.net'. selector.dnsZones
# instead suffix-matches the zone apex AND every subdomain at any depth, so this single
# entry routes all forteapps.net ACME challenges (forteapps.net, *.forteapps.net,
# drop.forteapps.net, *.drop.forteapps.net, mcp.drop.forteapps.net, ...) through this
# Azure dns01 solver. Wildcard names require dns01; non-wildcard names that ever fail
# to match fall through to the http01 solver below.
dnsZones:
- 'forteapps.net'
# HTTP-01 fallback for non-wildcard certificates
- http01:
@@ -233,6 +233,8 @@ spec:
value: "{{ regex_replace_all('https?://[^/]*', request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-callback-path\", '') }}"
- name: AUTH_OIDC_SCOPES
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-scopes\" || 'openid,profile,email' }}"
- name: AUTH_OIDC_COOKIE_DOMAIN
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-cookie-domain\" || '' }}"
- name: AUTH_PUBLIC_PATHS
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-public-paths\" || '/healthz' }}"
- name: AUTH_OIDC_COOKIE_SECRET
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources:
- repoURL: https://dl.gitea.com/charts
chart: gitea
targetRevision: "12.5.0"
targetRevision: "12.6.0"
helm:
releaseName: gitea
valueFiles:
@@ -59,10 +59,6 @@ config:
href: https://benken.hackathon.forteapps.net
description: Teknisk kompetanse fra offentlige anbud
icon: forte
- Forte Drop:
href: https://drop.forteapps.net
description: Self-hosted HTML-drops + MCP for Claude
icon: forte
- Forte Feedback:
href: https://feedback.forteapps.net
description: Fortes internal feedback app