feat(garage,authentik): console multi-domain + standalone proxy outpost
Two related additions for gating a cross-host service (garage WebUI on a storage host) behind authentik without breaking on TLS or X-Forwarded-Host: garage role: - Add garage_webui_domains (list), mirroring garage_s3_domains. The console router now accepts every entry, so a DMZ reverseproxy can use a backend_host whose cert SAN matches an internal *.int.* name instead of connecting by IP (which fails acme cert verification). Defaults to the single garage_webui_domain so existing inventories are unaffected. authentik_outpost_proxy role (new): - Standalone proxy (ForwardAuth) outpost, modelled on authentik_outpost_ldap. Co-locate it with the protected service so the ForwardAuth subrequest reaches authentik over the local docker network. The embedded outpost only works for services on the authentik host: a cross-host subrequest routed through an extra reverse-proxy hop arrives with a polluted X-Forwarded-Host (port/comma-appended), which the outpost no longer matches against the provider's external_host (404).
This commit is contained in:
parent
a8954f525c
commit
0733d5710f
12 changed files with 195 additions and 2 deletions
58
roles/authentik_outpost_proxy/README.md
Normal file
58
roles/authentik_outpost_proxy/README.md
Normal file
|
|
@ -0,0 +1,58 @@
|
|||
# authentik_outpost_proxy
|
||||
|
||||
Deploys an [authentik](https://goauthentik.io) proxy (ForwardAuth)
|
||||
outpost via Docker Compose. The outpost serves the
|
||||
`/outpost.goauthentik.io/auth/*` endpoints locally, so a Traefik
|
||||
`ForwardAuth` middleware on the same host can gate services behind
|
||||
authentik without routing the auth subrequest through additional reverse
|
||||
proxies.
|
||||
|
||||
Use this when the protected service runs on a **different host** than the
|
||||
authentik server: the embedded outpost only works for services co-located
|
||||
with authentik (the subrequest must reach it without an intermediate proxy
|
||||
mangling `X-Forwarded-Host`). Co-locating a proxy outpost with the service
|
||||
keeps the ForwardAuth subrequest on the local docker network.
|
||||
|
||||
The outpost connects back to an authentik server using an outpost token
|
||||
issued in the authentik admin interface (register the outpost there and
|
||||
assign the proxy providers it should serve). The image version must match
|
||||
the authentik server version.
|
||||
|
||||
## Requirements
|
||||
|
||||
- Docker and Docker Compose on the target host (e.g. via
|
||||
`digitalboard.core.base`)
|
||||
- Ansible collection: `community.docker`
|
||||
- An authentik proxy outpost registered on the server, with the proxy
|
||||
providers for the protected services assigned to it.
|
||||
|
||||
## Role variables
|
||||
|
||||
| Variable | Default | Description |
|
||||
| --- | --- | --- |
|
||||
| `authentik_outpost_proxy_image` | `ghcr.io/goauthentik/proxy:2026.2.2` | Outpost image (match the server version). |
|
||||
| `authentik_outpost_proxy_host` | `https://authentik.local.test` | URL of the authentik server. |
|
||||
| `authentik_outpost_proxy_token` | `changeme` | Outpost token — **override this**. |
|
||||
| `authentik_outpost_proxy_insecure` | `"true"` | Skip TLS verification toward the authentik server. |
|
||||
| `authentik_outpost_proxy_network` | `proxy` | Docker network the local Traefik routers and this outpost share. |
|
||||
| `authentik_outpost_proxy_extra_hosts` | `[]` | Extra `host:ip` entries for in-container DNS. |
|
||||
|
||||
The local ForwardAuth middleware then points at the container over the
|
||||
shared network, e.g.
|
||||
`http://authentik-outpost-proxy-proxy-1:9000/outpost.goauthentik.io/auth/traefik`.
|
||||
|
||||
## Example
|
||||
|
||||
```yaml
|
||||
- hosts: storage
|
||||
become: true
|
||||
roles:
|
||||
- role: digitalboard.core.authentik_outpost_proxy
|
||||
vars:
|
||||
authentik_outpost_proxy_host: "https://auth.example.com"
|
||||
authentik_outpost_proxy_token: "{{ vault_authentik_proxy_outpost_token }}"
|
||||
```
|
||||
|
||||
## License
|
||||
|
||||
MIT-0
|
||||
Loading…
Add table
Add a link
Reference in a new issue