Files
panopticons-charts/apps/argocd/apps/authentik.yaml
2026-08-21 15:52:30 -04:00

80 lines
2.3 KiB
YAML

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: authentik
namespace: argocd
spec:
project: default
source:
repoURL: https://charts.goauthentik.io
chart: authentik
targetRevision: 2026.5.6
helm:
valuesObject:
authentik:
existingSecret:
secretName: authentik
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
fsGroup: 1000
seccompProfile:
type: RuntimeDefault
server:
nodeSelector:
node-role.kubernetes.io/core: "true"
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
fsGroup: 1000
containerSecurityContext:
runAsNonRoot: true
allowPrivilegeEscalation: false
readOnlyRootFilesystem: false # Set to true only if you mount emptyDir for temp paths
seccompProfile:
type: RuntimeDefault
capabilities:
drop:
- ALL
ingress:
enabled: true
ingressClassName: traefik
hosts:
- auth.panopticons.org
worker:
nodeSelector:
node-role.kubernetes.io/core: "true"
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
fsGroup: 1000
containerSecurityContext:
runAsNonRoot: true
allowPrivilegeEscalation: false
readOnlyRootFilesystem: false # Set to true only if you mount emptyDir for temp paths
seccompProfile:
type: RuntimeDefault
capabilities:
drop:
- ALL
postgresql:
enabled: true
auth:
existingSecret: authentik-postgresql
primary:
nodeSelector:
node-role.kubernetes.io/core: "true"
containerSecurityContext:
readOnlyRootFilesystem: true
destination:
server: https://kubernetes.default.svc
namespace: authentik
syncPolicy:
syncOptions: [CreateNamespace=True]