forked from Azure-Terraform/terraform-helm-linkerd
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathoauth_ingress.tf
65 lines (59 loc) · 1.76 KB
/
oauth_ingress.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
resource "kubectl_manifest" "linkerd_ingress" {
depends_on = [kubernetes_namespace.namespace]
yaml_body = <<YAML
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: web
namespace: linkerd-viz
annotations:
nginx.ingress.kubernetes.io/ingress.class: nginx
nginx.ingress.kubernetes.io/upstream-vhost: $service_name.$namespace.svc.cluster.local:8084
nginx.ingress.kubernetes.io/configuration-snippet: |
proxy_set_header Origin "";
proxy_hide_header l5d-remote-ip;
proxy_hide_header l5d-server-id;
#nginx.ingress.kubernetes.io/auth-url: https://$host/oauth2/auth
#nginx.ingress.kubernetes.io/auth-signin: "https://$host/oauth2/start?rd=$escaped_request_uri"
#nginx.ingress.kubernetes.io/auth-signin: https://$host/oauth2/start?rd=https%3A%2F%2F$host$request_uri
#nginx.ingress.kubernetes.io/auth-url: http://oauth2-proxy.linkerd-viz.svc.cluster.local:4180/oauth2/auth
spec:
ingressClassName: nginx
rules:
- host: linkerd.devopsdemos.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: web
port:
number: 8084
YAML
}
resource "kubectl_manifest" "oauth2_ingress" {
depends_on = [kubernetes_namespace.namespace]
yaml_body = <<YAML
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: oauth2-proxy
namespace: linkerd-viz
annotations:
nginx.ingress.kubernetes.io/ingress.class: nginx
spec:
ingressClassName: nginx
rules:
- host: linkerd.devopsdemos.com
http:
paths:
- path: /oauth2
pathType: Prefix
backend:
service:
name: oauth2-proxy
port:
number: 80
YAML
}