This commit is contained in:
2022-11-17 16:01:44 -06:00
parent 12b7f118f9
commit 807136e35a

View File

@@ -4,22 +4,30 @@ metadata:
annotations: annotations:
kubernetes.io/ingress.class: nginx kubernetes.io/ingress.class: nginx
cert-manager.io/cluster-issuer: letsencrypt-production cert-manager.io/cluster-issuer: letsencrypt-production
nginx.ingress.kubernetes.io/proxy-read-timeout: "3600" #nginx.ingress.kubernetes.io/proxy-read-timeout: "3600"
nginx.ingress.kubernetes.io/proxy-send-timeout: "3600" #nginx.ingress.kubernetes.io/proxy-send-timeout: "3600"
nginx.ingress.kubernetes.io/server-snippets: | nginx.ingress.kubernetes.io/auth-url: |-
location / { http://ak-outpost-authentik-embedded-outpost.authentik.svc.cluster.local:9000/outpost.goauthentik.io/auth/nginx
proxy_set_header Upgrade $http_upgrade; nginx.ingress.kubernetes.io/auth-signin: |-
proxy_http_version 1.1; https://whoogle.durp.info/outpost.goauthentik.io/start?rd=$escaped_request_uri
nginx.ingress.kubernetes.io/auth-response-headers: |-
Set-Cookie,X-authentik-username,X-authentik-groups,X-authentik-email,X-authentik-name,X-authentik-uid
nginx.ingress.kubernetes.io/auth-snippet: |
proxy_set_header X-Forwarded-Host $http_host; proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header X-Forwarded-Proto $scheme; # nginx.ingress.kubernetes.io/server-snippets: |
proxy_set_header X-Forwarded-For $remote_addr; # location / {
proxy_set_header Host $host; # proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade"; # proxy_http_version 1.1;
proxy_set_header X-Real-IP $remote_addr; # proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; # proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Upgrade $http_upgrade; # proxy_set_header X-Forwarded-For $remote_addr;
proxy_cache_bypass $http_upgrade; # proxy_set_header Host $host;
} # proxy_set_header Connection "upgrade";
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# proxy_set_header Upgrade $http_upgrade;
# proxy_cache_bypass $http_upgrade;
# }
name: ingress name: ingress
spec: spec:
tls: tls: