Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,5 +2,5 @@ apiVersion: v2
name: pgdog-control
description: PgDog Control
type: application
version: 0.3.3
appVersion: "80895477"
version: 0.3.4
appVersion: "main-ent"
36 changes: 25 additions & 11 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -71,7 +71,7 @@ redis:
| Option | Description |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
| `redis.enabled` | Deploy the chart-managed Redis resources (bool, default `true`). |
| `redis.pdb.enabled` | Create the Redis PodDisruptionBudget with `minAvailable: 1` (bool, default `true`). |
| `redis.pdb.enabled` | Create the Redis PodDisruptionBudget with `minAvailable: 1` (bool, default `true`). |
| `redis.url` | Redis connection string written to `[redis].url` in `control.toml`. When empty, defaults to the chart-managed Redis Service (string, default `""`). |
| `redis.image.repository` | Redis image repository (string, default `redis`). |
| `redis.image.tag` | Redis image tag (string, default `7-alpine`). |
Expand Down Expand Up @@ -588,6 +588,17 @@ If `allowed_cidrs` is omitted, the control plane defaults to private IPv4 ranges

### Authentication

Set `control.config.auth.tokens` to restrict requests to the PgDog API to the listed Bearer tokens:

```yaml
control:
config:
auth:
tokens: ["token-1", "token-2"]
```

See [Secrets](#secrets) on how to configure these using a Kube `Secret`.

`control.config.auth` wires up the OAuth-backed login flow for the dashboard. GitHub and Google are supported and can be enabled side by side. At least one needs to be configured, or the dashboard will be **accessible by anyone with the URL**:

```yaml
Expand Down Expand Up @@ -623,16 +634,17 @@ control:

Secrets are injected as environment variables. Leave corresponding inline values unset, since they take precedence.

| Environment variable | Description |
| --- | --- |
| `GITHUB_CLIENT_ID` | GitHub OAuth application ID. |
| `GITHUB_CLIENT_SECRET` | GitHub OAuth application secret. |
| `GOOGLE_CLIENT_ID` | Google OAuth application ID. |
| `GOOGLE_CLIENT_SECRET` | Google OAuth application secret. |
| `COOKIE_SECRET` | Key used to sign session and CSRF cookies. |
| `INCIDENT_IO_API_KEY` | incident.io API key for creating incidents. |
| `RAFT_TOKEN` | Shared token authenticating Raft peers. |
| `REDIS_URL` | Redis connection URL, including credentials if required. |
| Environment variable | Description |
| ---------------------- | ------------------------------------------------------------------------------------------------------------- |
| `AUTH_TOKENS` | Comma-separated Bearer token allowlist for `/api/v2`, sourced through `control.config.auth.secret.tokensKey`. |
| `GITHUB_CLIENT_ID` | GitHub OAuth application ID. |
| `GITHUB_CLIENT_SECRET` | GitHub OAuth application secret. |
| `GOOGLE_CLIENT_ID` | Google OAuth application ID. |
| `GOOGLE_CLIENT_SECRET` | Google OAuth application secret. |
| `COOKIE_SECRET` | Key used to sign session and CSRF cookies. |
| `INCIDENT_IO_API_KEY` | incident.io API key for creating incidents. |
| `RAFT_TOKEN` | Shared token authenticating Raft peers. |
| `REDIS_URL` | Redis connection URL, including credentials if required. |

Create `secrets.yaml` separately from the Helm release, replacing the example values:

Expand All @@ -643,6 +655,7 @@ metadata:
name: control-secrets
type: Opaque
stringData:
auth-tokens: "token-1,token-2"
github-client-id: "your-github-client-id"
github-client-secret: "your-github-client-secret"
google-client-id: "your-google-client-id"
Expand All @@ -661,6 +674,7 @@ control:
auth:
secret:
name: control-secrets
tokensKey: auth-tokens
cookieSecretKey: cookie-secret
github:
secret:
Expand Down
3 changes: 3 additions & 0 deletions templates/configmap.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -150,6 +150,9 @@ data:
{{- if or $cookieSecret (gt (len $auth) 0) }}

[auth]
{{- if hasKey $auth "tokens" }}
tokens = [{{ range $i, $token := $auth.tokens }}{{ if $i }}, {{ end }}{{ $token | quote }}{{ end }}]
{{- end }}
{{- if $cookieSecret }}
cookie_secret = {{ $cookieSecret | quote }}
{{- end }}
Expand Down
7 changes: 7 additions & 0 deletions templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -152,6 +152,13 @@ spec:
{{- end }}
{{- $auth := (.Values.control.config | default dict).auth | default dict }}
{{- with $auth.secret }}
{{- if .tokensKey }}
- name: AUTH_TOKENS
valueFrom:
secretKeyRef:
name: {{ required "control.config.auth.secret.name is required when tokensKey is set" .name | quote }}
key: {{ .tokensKey | quote }}
{{- end }}
{{- if .cookieSecretKey }}
- name: COOKIE_SECRET
valueFrom:
Expand Down
1 change: 1 addition & 0 deletions test/values-full.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,7 @@ control:
repo: pgdogdev
repo_url: https://helm.pgdog.dev
auth:
tokens: [token-1, token-2]
cookie_secret: test-cookie-secret
redirect_base_url: https://control.example.com
cookie_secure: true
Expand Down
1 change: 1 addition & 0 deletions test/values-secrets.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ control:
auth:
secret:
name: control-secrets
tokensKey: auth-tokens
cookieSecretKey: cookie-secret
github:
secret:
Expand Down
2 changes: 2 additions & 0 deletions values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -140,9 +140,11 @@ control:
# repo: pgdogdev
# repo_url: https://helm.pgdog.dev
auth: {}
# tokens: ["token-1", "token-2"] # /api/v2 Bearer token allowlist; [] disables validation
# cookie_secret: "" # optional; random key generated at boot when absent
# secret:
# name: "" # existing Secret in the release namespace
# tokensKey: "" # comma-separated list -> AUTH_TOKENS; leave tokens unset
# cookieSecretKey: "" # key -> COOKIE_SECRET; leave cookie_secret unset
# redirect_base_url: "" # e.g. https://control.example.com
# cookie_secure: true
Expand Down
Loading