17 lines
557 B
YAML
17 lines
557 B
YAML
# Traefik ForwardAuth → oauth2-proxy (OIDC with Authentik). Reference from Ingress:
|
|
# traefik.ingress.kubernetes.io/router.middlewares: oauth2-proxy-forward-auth@kubernetescrd
|
|
apiVersion: traefik.io/v1alpha1
|
|
kind: Middleware
|
|
metadata:
|
|
name: forward-auth
|
|
namespace: oauth2-proxy
|
|
spec:
|
|
forwardAuth:
|
|
address: http://oauth2-proxy.oauth2-proxy.svc.cluster.local:4180/oauth2/auth
|
|
trustForwardHeader: true
|
|
authResponseHeaders:
|
|
- X-Forwarded-User
|
|
- X-Forwarded-Email
|
|
- X-Forwarded-Preferred-Username
|
|
- X-Forwarded-Groups
|