stack.basicstack.de/apps/dozzle/README.md
CTO Agent 9e6344fd7c Fix Dozzle authentication with oauth2-proxy sidecar
Switch from direct OIDC (not supported by Dozzle) to forward-proxy authentication using oauth2-proxy as a sidecar container.

Changes:
- Add oauth2-proxy sidecar container for OIDC authentication
- Configure Dozzle to use forward-proxy auth with user headers
- Update service and ingress to route to oauth2-proxy (port 4180)
- Add cookie-secret to sealed secret for oauth2-proxy session management
- Update documentation to reflect oauth2-proxy architecture

The oauth2-proxy authenticates users via Pocket ID and forwards requests to Dozzle with X-Forwarded-User, X-Forwarded-Email, and X-Forwarded-Preferred-Username headers.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-19 13:30:41 +00:00

1.8 KiB

Dozzle Deployment

Dozzle is a real-time log viewer for Docker containers running in the Kubernetes cluster.

Components

  • Namespace: dozzle
  • Domain: dozzle.basicstack.de
  • Storage: 1Gi PVC using hcloud-volumes-encrypted storage class
  • Authentication: Pocket ID OIDC via oauth2-proxy sidecar

Architecture

Dozzle doesn't support native OIDC authentication, so we use oauth2-proxy as a sidecar container:

  1. oauth2-proxy (port 4180): Handles OIDC authentication with Pocket ID
  2. Dozzle (port 8080): Receives authenticated requests from oauth2-proxy with user headers

The oauth2-proxy authenticates users via Pocket ID OIDC and forwards authenticated requests to Dozzle with X-Forwarded-User, X-Forwarded-Email, and X-Forwarded-Preferred-Username headers. Dozzle is configured with forward-proxy authentication to trust these headers.

Files

  • namespace.yaml: Dozzle namespace
  • service-account.yaml: Service account with RBAC for accessing pod logs cluster-wide
  • pvc.yaml: Persistent volume claim for Dozzle settings (1Gi, ReadWriteOnce with Recreate strategy)
  • deployment.yaml: Dozzle deployment with oauth2-proxy sidecar
  • service.yaml: Kubernetes service (routes to oauth2-proxy port 4180)
  • ingress.yaml: Traefik ingress with TLS (routes to oauth2-proxy)
  • dozzle-oidc-sealed.yaml: Sealed secret with OIDC client credentials and oauth2-proxy cookie secret

Pocket ID OIDC Client

  • Client ID: 179c13f2-d251-4e1e-b1a0-c070df350c4e
  • Client Name: Dozzle
  • Callback URL: https://dozzle.basicstack.de/oauth2/callback
  • Scopes: openid profile email

Access

After deployment, access Dozzle at https://dozzle.basicstack.de and authenticate with Pocket ID credentials.

ArgoCD

The application is managed by ArgoCD via app-dozzle.yaml in the parent apps directory.