diff --git a/infra/traefik/templates/middleware.yaml b/infra/traefik/templates/middleware.yaml new file mode 100644 index 0000000..453ca61 --- /dev/null +++ b/infra/traefik/templates/middleware.yaml @@ -0,0 +1,35 @@ +apiVersion: traefik.containo.us/v1alpha1 +kind: Middleware +metadata: + name: authentik-proxy-provider + namespace: traefik +spec: + forwardAuth: + address: http://ak-outpost-authentik-embedded-outpost.authentik.svc.cluster.local:9000/outpost.goauthentik.io/auth/traefik + trustForwardHeader: true + authResponseHeaders: + - X-authentik-username + - X-authentik-groups + - X-authentik-email + - X-authentik-name + - X-authentik-uid + - X-authentik-jwt + - X-authentik-meta-jwks + - X-authentik-meta-outpost + - X-authentik-meta-provider + - X-authentik-meta-app + - X-authentik-meta-version + +--- + +apiVersion: traefik.containo.us/v1alpha1 +kind: Middleware +metadata: + name: whitelist + namespace: traefik +spec: + ipWhiteList: + sourceRange: + - 192.168.0.0/16 + - 172.16.0.0/12 + - 10.0.0.0/8