Switch from direct OIDC (not supported by Dozzle) to forward-proxy authentication using oauth2-proxy as a sidecar container. Changes: - Add oauth2-proxy sidecar container for OIDC authentication - Configure Dozzle to use forward-proxy auth with user headers - Update service and ingress to route to oauth2-proxy (port 4180) - Add cookie-secret to sealed secret for oauth2-proxy session management - Update documentation to reflect oauth2-proxy architecture The oauth2-proxy authenticates users via Pocket ID and forwards requests to Dozzle with X-Forwarded-User, X-Forwarded-Email, and X-Forwarded-Preferred-Username headers. Co-Authored-By: Paperclip <noreply@paperclip.ing>
44 lines
1.8 KiB
Markdown
44 lines
1.8 KiB
Markdown
# Dozzle Deployment
|
|
|
|
Dozzle is a real-time log viewer for Docker containers running in the Kubernetes cluster.
|
|
|
|
## Components
|
|
|
|
- **Namespace**: `dozzle`
|
|
- **Domain**: `dozzle.basicstack.de`
|
|
- **Storage**: 1Gi PVC using `hcloud-volumes-encrypted` storage class
|
|
- **Authentication**: Pocket ID OIDC via oauth2-proxy sidecar
|
|
|
|
## Architecture
|
|
|
|
Dozzle doesn't support native OIDC authentication, so we use oauth2-proxy as a sidecar container:
|
|
|
|
1. **oauth2-proxy** (port 4180): Handles OIDC authentication with Pocket ID
|
|
2. **Dozzle** (port 8080): Receives authenticated requests from oauth2-proxy with user headers
|
|
|
|
The oauth2-proxy authenticates users via Pocket ID OIDC and forwards authenticated requests to Dozzle with `X-Forwarded-User`, `X-Forwarded-Email`, and `X-Forwarded-Preferred-Username` headers. Dozzle is configured with `forward-proxy` authentication to trust these headers.
|
|
|
|
## Files
|
|
|
|
- `namespace.yaml`: Dozzle namespace
|
|
- `service-account.yaml`: Service account with RBAC for accessing pod logs cluster-wide
|
|
- `pvc.yaml`: Persistent volume claim for Dozzle settings (1Gi, ReadWriteOnce with Recreate strategy)
|
|
- `deployment.yaml`: Dozzle deployment with oauth2-proxy sidecar
|
|
- `service.yaml`: Kubernetes service (routes to oauth2-proxy port 4180)
|
|
- `ingress.yaml`: Traefik ingress with TLS (routes to oauth2-proxy)
|
|
- `dozzle-oidc-sealed.yaml`: Sealed secret with OIDC client credentials and oauth2-proxy cookie secret
|
|
|
|
## Pocket ID OIDC Client
|
|
|
|
- **Client ID**: `179c13f2-d251-4e1e-b1a0-c070df350c4e`
|
|
- **Client Name**: Dozzle
|
|
- **Callback URL**: `https://dozzle.basicstack.de/oauth2/callback`
|
|
- **Scopes**: `openid profile email`
|
|
|
|
## Access
|
|
|
|
After deployment, access Dozzle at https://dozzle.basicstack.de and authenticate with Pocket ID credentials.
|
|
|
|
## ArgoCD
|
|
|
|
The application is managed by ArgoCD via `app-dozzle.yaml` in the parent apps directory.
|