image: repository: ghcr.io/italypaleale/traefik-forward-auth pullPolicy: IfNotPresent # Overrides the image tag; defaults to Chart.AppVersion tag: "" # Domains served by this instance. One entry per registrable domain. # # `domain` scopes the session cookie; `authHost` is where this service is # reachable for that domain, and must be it or a sub-domain of it. # # A browser will not send a cookie scoped to one registrable domain to a host # under another, so an app on a second domain needs its own entry here. A second # OAuth2 client alone does not solve it. domains: [] # - domain: example.com # authHost: auth.example.com # - domain: example.org # authHost: auth.example.org # Single-domain shorthand, used when `domains` is empty. Equivalent to one # `domains` entry of {domain: cookieDomain, authHost: hostname}. hostname: "" cookieDomain: "" tokens: sessionLifetime: 24h # Portals. Each is one OAuth2 client, selected by the middleware address # (/portals/) — which is how access is separated: grant one Pocket ID # application to one group of people and the other to another, and each portal # admits only its own. # # Each portal mounts its secret at # /var/run/secrets/traefik-forward-auth//client-secret. portals: [] # - name: main # middlewareName: pocket-id-auth # default: - # existingSecret: tfa-main-secret # must define key `client-secret` # secretKey: client-secret # optional, if the key differs # pocketID: # endpoint: https://id.example.com # clientID: "..." # Single-portal shorthand, used when `portals` is empty. pocketID: endpoint: "" clientID: "" # Secret containing the client secret. Must define key `client-secret`. # Use sealed-secrets to provide this in cluster overlays. existingSecret: "" portal: name: main # Extra YAML appended to config.yaml (advanced use only). extraConfig: "" service: port: 80 resources: requests: cpu: 50m memory: 32Mi limits: cpu: 200m memory: 128Mi nodeSelector: {} tolerations: [] affinity: {} # Traefik Middleware of kind forwardAuth. Referenced by apps as # -@kubernetescrd. middleware: enabled: true name: "" # defaults to "-auth" if empty authResponseHeaders: - X-Forwarded-User - X-Forwarded-Displayname - X-Forwarded-Groups trustForwardHeader: true ingresses: {} # https: # host: auth.example.com # annotations: # traefik.ingress.kubernetes.io/router.entrypoints: web,websecure # traefik.ingress.kubernetes.io/router.tls: "true" # traefik.ingress.kubernetes.io/router.tls.certresolver: letsencrypt # traefik.ingress.kubernetes.io/router.middlewares: traefik-redirect-to-https@kubernetescrd # tls: # - hosts: # - auth.example.com