Initial authentik gitops app
Validate manifests / validate (push) Failing after 8s

This commit is contained in:
2026-04-20 01:03:25 +01:00
commit c85556e327
27 changed files with 1129 additions and 0 deletions
+84
View File
@@ -0,0 +1,84 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: authentik-server
namespace: security
labels:
app: authentik-server
spec:
replicas: 1
selector:
matchLabels:
app: authentik-server
template:
metadata:
labels:
app: authentik-server
app.kubernetes.io/name: authentik-server
spec:
automountServiceAccountToken: false
securityContext:
runAsUser: 1000
runAsGroup: 988
containers:
- name: server
image: ghcr.io/goauthentik/server:2026.2
imagePullPolicy: IfNotPresent
args:
- server
ports:
- name: http
containerPort: 9000
- name: https
containerPort: 9443
env:
- name: AUTHENTIK_LISTEN__HTTP
value: 0.0.0.0:9000
- name: AUTHENTIK_LISTEN__HTTPS
value: 0.0.0.0:9443
- name: AUTHENTIK_POSTGRESQL__HOST
value: shared-postgres-rw.data.svc.cluster.local
- name: AUTHENTIK_POSTGRESQL__NAME
value: authentik
- name: AUTHENTIK_POSTGRESQL__USER
value: authentik
- name: AUTHENTIK_POSTGRESQL__PORT
value: "5432"
- name: AUTHENTIK_POSTGRESQL__SSLMODE
value: disable
- name: AUTHENTIK_POSTGRESQL__PASSWORD
value: file:///run/secrets/db_password
- name: AUTHENTIK_SECRET_KEY
value: file:///run/secrets/secret_key
- name: AUTHENTIK_ERROR_REPORTING__ENABLED
value: "false"
volumeMounts:
- name: secrets
mountPath: /run/secrets/db_password
readOnly: true
subPath: db_password
- name: secrets
mountPath: /run/secrets/secret_key
readOnly: true
subPath: secret_key
- name: authentik-data
mountPath: /data
readinessProbe:
httpGet:
path: /-/health/ready/
port: http
initialDelaySeconds: 15
periodSeconds: 10
livenessProbe:
httpGet:
path: /-/health/live/
port: http
initialDelaySeconds: 30
periodSeconds: 30
volumes:
- name: secrets
secret:
secretName: authentik-secrets
- name: authentik-data
persistentVolumeClaim:
claimName: authentik-data
+10
View File
@@ -0,0 +1,10 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: security
resources:
- serviceaccount.yaml
- deployment.yaml
- worker-deployment.yaml
- service.yaml
+17
View File
@@ -0,0 +1,17 @@
apiVersion: v1
kind: Service
metadata:
name: authentik
namespace: security
labels:
app: authentik-server
spec:
selector:
app: authentik-server
ports:
- name: http
port: 9000
targetPort: http
- name: https
port: 9443
targetPort: https
+5
View File
@@ -0,0 +1,5 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: authentik-worker
namespace: security
+64
View File
@@ -0,0 +1,64 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: authentik-worker
namespace: security
labels:
app: authentik-worker
spec:
replicas: 1
selector:
matchLabels:
app: authentik-worker
template:
metadata:
labels:
app: authentik-worker
spec:
serviceAccountName: authentik-worker
securityContext:
runAsUser: 1000
runAsGroup: 988
containers:
- name: worker
image: ghcr.io/goauthentik/server:2026.2
imagePullPolicy: IfNotPresent
args:
- worker
env:
- name: AUTHENTIK_POSTGRESQL__HOST
value: shared-postgres-rw.data.svc.cluster.local
- name: AUTHENTIK_POSTGRESQL__NAME
value: authentik
- name: AUTHENTIK_POSTGRESQL__USER
value: authentik
- name: AUTHENTIK_POSTGRESQL__PORT
value: "5432"
- name: AUTHENTIK_POSTGRESQL__SSLMODE
value: disable
- name: AUTHENTIK_POSTGRESQL__PASSWORD
value: file:///run/secrets/db_password
- name: AUTHENTIK_SECRET_KEY
value: file:///run/secrets/secret_key
- name: AUTHENTIK_ERROR_REPORTING__ENABLED
value: "false"
- name: AUTHENTIK_WORKER__THREADS
value: "2"
volumeMounts:
- name: secrets
mountPath: /run/secrets/db_password
readOnly: true
subPath: db_password
- name: secrets
mountPath: /run/secrets/secret_key
readOnly: true
subPath: secret_key
- name: authentik-data
mountPath: /data
volumes:
- name: secrets
secret:
secretName: authentik-secrets
- name: authentik-data
persistentVolumeClaim:
claimName: authentik-data