apiVersion: apps/v1 kind: Deployment metadata: name: authentik-server namespace: security labels: app: authentik-server spec: replicas: 0 selector: matchLabels: app: authentik-server template: metadata: labels: app: authentik-server app.kubernetes.io/name: authentik-server spec: automountServiceAccountToken: false securityContext: runAsUser: 1000 runAsGroup: 988 containers: - name: server image: ghcr.io/goauthentik/server:2026.2 imagePullPolicy: IfNotPresent args: - server ports: - name: http containerPort: 9000 - name: https containerPort: 9443 env: - name: AUTHENTIK_LISTEN__HTTP value: 0.0.0.0:9000 - name: AUTHENTIK_LISTEN__HTTPS value: 0.0.0.0:9443 - name: AUTHENTIK_POSTGRESQL__HOST value: shared-postgres-rw.data.svc.cluster.local - name: AUTHENTIK_POSTGRESQL__NAME value: authentik - name: AUTHENTIK_POSTGRESQL__USER value: authentik - name: AUTHENTIK_POSTGRESQL__PORT value: "5432" - name: AUTHENTIK_POSTGRESQL__SSLMODE value: disable - name: AUTHENTIK_POSTGRESQL__PASSWORD value: file:///run/secrets/db_password - name: AUTHENTIK_SECRET_KEY value: file:///run/secrets/secret_key - name: AUTHENTIK_ERROR_REPORTING__ENABLED value: "false" volumeMounts: - name: secrets mountPath: /run/secrets/db_password readOnly: true subPath: db_password - name: secrets mountPath: /run/secrets/secret_key readOnly: true subPath: secret_key - name: authentik-data mountPath: /data readinessProbe: httpGet: path: /-/health/ready/ port: http initialDelaySeconds: 15 periodSeconds: 10 startupProbe: httpGet: path: /-/health/live/ port: http failureThreshold: 30 periodSeconds: 10 livenessProbe: httpGet: path: /-/health/live/ port: http initialDelaySeconds: 30 periodSeconds: 30 volumes: - name: secrets secret: secretName: authentik-secrets - name: authentik-data persistentVolumeClaim: claimName: authentik-data