Skip to content

Commit

Permalink
feat(deployment): basic http auth for website (#2191)
Browse files Browse the repository at this point in the history
  • Loading branch information
theosanderson authored Jun 28, 2024
1 parent 454d4ca commit 8733880
Show file tree
Hide file tree
Showing 3 changed files with 30 additions and 2 deletions.
20 changes: 18 additions & 2 deletions kubernetes/loculus/templates/ingressroute.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,16 @@ spec:
redirectScheme:
scheme: https
permanent: true
{{ if $.Values.secrets.basicauth }}
---
apiVersion: traefik.containo.us/v1alpha1
kind: Middleware
metadata:
name: basic-auth
spec:
basicAuth:
secret: basicauth
{{ end }}
---
{{- if eq $.Values.environment "server" }}
{{- $backendHost := printf "backend-%s" .Values.host }}
Expand All @@ -22,12 +32,19 @@ spec:
{{- $middlewareList = append $middlewareList (printf "%s-redirect-middleware@kubernetescrd" $.Release.Namespace) }}
{{- end }}

{{ $middleWareListForWebsite := $middlewareList }}

{{ if $.Values.secrets.basicauth }}
{{ $middleWareListForWebsite = append $middleWareListForWebsite (printf "%s-basic-auth@kubernetescrd" $.Release.Namespace) }}
{{ end }}


apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: loculus-website-ingress
annotations:
traefik.ingress.kubernetes.io/router.middlewares: "{{ join "," $middlewareList }}"
traefik.ingress.kubernetes.io/router.middlewares: "{{ join "," $middleWareListForWebsite }}"
spec:
rules:
- host: "{{ .Values.host }}"
Expand Down Expand Up @@ -66,7 +83,6 @@ spec:
- hosts:
- "{{ $backendHost }}"
---

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
Expand Down
7 changes: 7 additions & 0 deletions kubernetes/loculus/templates/secrets.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,13 @@ spec:
encoding: "hex"
length: "18"
{{- end }}
{{- else if eq $secret.type "rawhtpasswd" }}
apiVersion: v1
kind: Secret
metadata:
name: {{ $name }}
data:
users: {{ htpasswd $secret.data.username $secret.data.password | b64enc }}
{{- else }}
apiVersion: v1
kind: Secret
Expand Down
5 changes: 5 additions & 0 deletions kubernetes/loculus/values_preview_server.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,10 @@
createTestAccounts: true
secrets:
basicauth:
type: rawhtpasswd
data:
username: loculus
password: widetailpotato
smtp-password:
type: sealedsecret
clusterWide: "true"
Expand Down

0 comments on commit 8733880

Please sign in to comment.