diff --git a/Chart.yaml b/Chart.yaml index b1ee17a..c99131c 100644 --- a/Chart.yaml +++ b/Chart.yaml @@ -2,5 +2,5 @@ apiVersion: v2 name: pgdog-control description: PgDog Control type: application -version: 0.3.3 -appVersion: "80895477" +version: 0.3.4 +appVersion: "main-ent" diff --git a/README.md b/README.md index 98f9eed..84347f7 100644 --- a/README.md +++ b/README.md @@ -71,7 +71,7 @@ redis: | Option | Description | | ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- | | `redis.enabled` | Deploy the chart-managed Redis resources (bool, default `true`). | -| `redis.pdb.enabled` | Create the Redis PodDisruptionBudget with `minAvailable: 1` (bool, default `true`). | +| `redis.pdb.enabled` | Create the Redis PodDisruptionBudget with `minAvailable: 1` (bool, default `true`). | | `redis.url` | Redis connection string written to `[redis].url` in `control.toml`. When empty, defaults to the chart-managed Redis Service (string, default `""`). | | `redis.image.repository` | Redis image repository (string, default `redis`). | | `redis.image.tag` | Redis image tag (string, default `7-alpine`). | @@ -588,6 +588,17 @@ If `allowed_cidrs` is omitted, the control plane defaults to private IPv4 ranges ### Authentication +Set `control.config.auth.tokens` to restrict requests to the PgDog API to the listed Bearer tokens: + +```yaml +control: + config: + auth: + tokens: ["token-1", "token-2"] +``` + +See [Secrets](#secrets) on how to configure these using a Kube `Secret`. + `control.config.auth` wires up the OAuth-backed login flow for the dashboard. GitHub and Google are supported and can be enabled side by side. At least one needs to be configured, or the dashboard will be **accessible by anyone with the URL**: ```yaml @@ -623,16 +634,17 @@ control: Secrets are injected as environment variables. Leave corresponding inline values unset, since they take precedence. -| Environment variable | Description | -| --- | --- | -| `GITHUB_CLIENT_ID` | GitHub OAuth application ID. | -| `GITHUB_CLIENT_SECRET` | GitHub OAuth application secret. | -| `GOOGLE_CLIENT_ID` | Google OAuth application ID. | -| `GOOGLE_CLIENT_SECRET` | Google OAuth application secret. | -| `COOKIE_SECRET` | Key used to sign session and CSRF cookies. | -| `INCIDENT_IO_API_KEY` | incident.io API key for creating incidents. | -| `RAFT_TOKEN` | Shared token authenticating Raft peers. | -| `REDIS_URL` | Redis connection URL, including credentials if required. | +| Environment variable | Description | +| ---------------------- | ------------------------------------------------------------------------------------------------------------- | +| `AUTH_TOKENS` | Comma-separated Bearer token allowlist for `/api/v2`, sourced through `control.config.auth.secret.tokensKey`. | +| `GITHUB_CLIENT_ID` | GitHub OAuth application ID. | +| `GITHUB_CLIENT_SECRET` | GitHub OAuth application secret. | +| `GOOGLE_CLIENT_ID` | Google OAuth application ID. | +| `GOOGLE_CLIENT_SECRET` | Google OAuth application secret. | +| `COOKIE_SECRET` | Key used to sign session and CSRF cookies. | +| `INCIDENT_IO_API_KEY` | incident.io API key for creating incidents. | +| `RAFT_TOKEN` | Shared token authenticating Raft peers. | +| `REDIS_URL` | Redis connection URL, including credentials if required. | Create `secrets.yaml` separately from the Helm release, replacing the example values: @@ -643,6 +655,7 @@ metadata: name: control-secrets type: Opaque stringData: + auth-tokens: "token-1,token-2" github-client-id: "your-github-client-id" github-client-secret: "your-github-client-secret" google-client-id: "your-google-client-id" @@ -661,6 +674,7 @@ control: auth: secret: name: control-secrets + tokensKey: auth-tokens cookieSecretKey: cookie-secret github: secret: diff --git a/templates/configmap.yaml b/templates/configmap.yaml index ea92d6d..7a9c17d 100644 --- a/templates/configmap.yaml +++ b/templates/configmap.yaml @@ -150,6 +150,9 @@ data: {{- if or $cookieSecret (gt (len $auth) 0) }} [auth] + {{- if hasKey $auth "tokens" }} + tokens = [{{ range $i, $token := $auth.tokens }}{{ if $i }}, {{ end }}{{ $token | quote }}{{ end }}] + {{- end }} {{- if $cookieSecret }} cookie_secret = {{ $cookieSecret | quote }} {{- end }} diff --git a/templates/deployment.yaml b/templates/deployment.yaml index c5ffcf3..5883b5c 100644 --- a/templates/deployment.yaml +++ b/templates/deployment.yaml @@ -152,6 +152,13 @@ spec: {{- end }} {{- $auth := (.Values.control.config | default dict).auth | default dict }} {{- with $auth.secret }} + {{- if .tokensKey }} + - name: AUTH_TOKENS + valueFrom: + secretKeyRef: + name: {{ required "control.config.auth.secret.name is required when tokensKey is set" .name | quote }} + key: {{ .tokensKey | quote }} + {{- end }} {{- if .cookieSecretKey }} - name: COOKIE_SECRET valueFrom: diff --git a/test/values-full.yaml b/test/values-full.yaml index 1928a64..0263047 100644 --- a/test/values-full.yaml +++ b/test/values-full.yaml @@ -43,6 +43,7 @@ control: repo: pgdogdev repo_url: https://helm.pgdog.dev auth: + tokens: [token-1, token-2] cookie_secret: test-cookie-secret redirect_base_url: https://control.example.com cookie_secure: true diff --git a/test/values-secrets.yaml b/test/values-secrets.yaml index b7e87c9..85a2aa9 100644 --- a/test/values-secrets.yaml +++ b/test/values-secrets.yaml @@ -3,6 +3,7 @@ control: auth: secret: name: control-secrets + tokensKey: auth-tokens cookieSecretKey: cookie-secret github: secret: diff --git a/values.yaml b/values.yaml index eb05c43..e514402 100644 --- a/values.yaml +++ b/values.yaml @@ -140,9 +140,11 @@ control: # repo: pgdogdev # repo_url: https://helm.pgdog.dev auth: {} + # tokens: ["token-1", "token-2"] # /api/v2 Bearer token allowlist; [] disables validation # cookie_secret: "" # optional; random key generated at boot when absent # secret: # name: "" # existing Secret in the release namespace + # tokensKey: "" # comma-separated list -> AUTH_TOKENS; leave tokens unset # cookieSecretKey: "" # key -> COOKIE_SECRET; leave cookie_secret unset # redirect_base_url: "" # e.g. https://control.example.com # cookie_secure: true