stack.basicstack.de/apps/dozzle/README.md

45 lines
1.8 KiB
Markdown
Raw Normal View History

# Dozzle Deployment
Dozzle is a real-time log viewer for Docker containers running in the Kubernetes cluster.
## Components
- **Namespace**: `dozzle`
- **Domain**: `dozzle.basicstack.de`
- **Storage**: 1Gi PVC using `hcloud-volumes-encrypted` storage class
- **Authentication**: Pocket ID OIDC via oauth2-proxy sidecar
## Architecture
Dozzle doesn't support native OIDC authentication, so we use oauth2-proxy as a sidecar container:
1. **oauth2-proxy** (port 4180): Handles OIDC authentication with Pocket ID
2. **Dozzle** (port 8080): Receives authenticated requests from oauth2-proxy with user headers
The oauth2-proxy authenticates users via Pocket ID OIDC and forwards authenticated requests to Dozzle with `X-Forwarded-User`, `X-Forwarded-Email`, and `X-Forwarded-Preferred-Username` headers. Dozzle is configured with `forward-proxy` authentication to trust these headers.
## Files
- `namespace.yaml`: Dozzle namespace
- `service-account.yaml`: Service account with RBAC for accessing pod logs cluster-wide
- `pvc.yaml`: Persistent volume claim for Dozzle settings (1Gi, ReadWriteOnce with Recreate strategy)
- `deployment.yaml`: Dozzle deployment with oauth2-proxy sidecar
- `service.yaml`: Kubernetes service (routes to oauth2-proxy port 4180)
- `ingress.yaml`: Traefik ingress with TLS (routes to oauth2-proxy)
- `dozzle-oidc-sealed.yaml`: Sealed secret with OIDC client credentials and oauth2-proxy cookie secret
## Pocket ID OIDC Client
- **Client ID**: `179c13f2-d251-4e1e-b1a0-c070df350c4e`
- **Client Name**: Dozzle
- **Callback URL**: `https://dozzle.basicstack.de/oauth2/callback`
- **Scopes**: `openid profile email`
## Access
After deployment, access Dozzle at https://dozzle.basicstack.de and authenticate with Pocket ID credentials.
## ArgoCD
The application is managed by ArgoCD via `app-dozzle.yaml` in the parent apps directory.