From a018a5bf7611122f2a1965bc76dde05f987a113f Mon Sep 17 00:00:00 2001 From: selmankoc Date: Thu, 28 Aug 2025 11:22:57 +0300 Subject: [PATCH 1/3] Update internalAuthServerAuthority to use HTTPS and enable RequireHttpsMetadata --- etc/k8s/helm-chart/eventhub/values.azure.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/etc/k8s/helm-chart/eventhub/values.azure.yaml b/etc/k8s/helm-chart/eventhub/values.azure.yaml index c62cd80..aa96004 100644 --- a/etc/k8s/helm-chart/eventhub/values.azure.yaml +++ b/etc/k8s/helm-chart/eventhub/values.azure.yaml @@ -15,8 +15,8 @@ global: nginxProxyBuffersNumber: "8" defaultConnString: "Host=eh-az-postgresql;Port=5432;Database=EventHub;Username=root;Password=root" redisConfiguration: "eh-az-redis" - internalAuthServerAuthority: "http://account.openeventhub.com" - internalAuthServerRequireHttpsMetadata: "false" + internalAuthServerAuthority: "https://account.openeventhub.com" + internalAuthServerRequireHttpsMetadata: "true" stringEncryptionDefaultPassPhrase: "TxVIZFPxK33czbbv" imagePullPolicy: Always eventHubImageVersion: latest From 2a39e145db22796c510816d93daa777f6d2407de Mon Sep 17 00:00:00 2001 From: selmankoc Date: Thu, 28 Aug 2025 11:27:55 +0300 Subject: [PATCH 2/3] Comment out cert-manager cluster issuer in ingress templates --- .../eventhub/charts/account/templates/account-ingress.yaml | 2 +- .../eventhub/charts/admin-api/templates/admin-api-ingress.yaml | 2 +- .../eventhub/charts/admin/templates/admin-ingress.yaml | 2 +- .../helm-chart/eventhub/charts/api/templates/api-ingress.yaml | 2 +- .../helm-chart/eventhub/charts/www/templates/www-ingress.yaml | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) diff --git a/etc/k8s/helm-chart/eventhub/charts/account/templates/account-ingress.yaml b/etc/k8s/helm-chart/eventhub/charts/account/templates/account-ingress.yaml index e927c6f..038f676 100644 --- a/etc/k8s/helm-chart/eventhub/charts/account/templates/account-ingress.yaml +++ b/etc/k8s/helm-chart/eventhub/charts/account/templates/account-ingress.yaml @@ -7,7 +7,7 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: "{{ .Values.global.nginxProxyBufferSize }}" nginx.ingress.kubernetes.io/proxy-buffers-number: "{{ .Values.global.nginxProxyBuffersNumber }}" - cert-manager.io/cluster-issuer: letsencrypt + # #cert-manager.io/cluster-issuer: letsencrypt # nginx.ingress.kubernetes.io/configuration-snippet: | # more_set_input_headers "from-ingress: true"; spec: diff --git a/etc/k8s/helm-chart/eventhub/charts/admin-api/templates/admin-api-ingress.yaml b/etc/k8s/helm-chart/eventhub/charts/admin-api/templates/admin-api-ingress.yaml index f0f3115..d33800b 100644 --- a/etc/k8s/helm-chart/eventhub/charts/admin-api/templates/admin-api-ingress.yaml +++ b/etc/k8s/helm-chart/eventhub/charts/admin-api/templates/admin-api-ingress.yaml @@ -7,7 +7,7 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: "{{ .Values.global.nginxProxyBufferSize }}" nginx.ingress.kubernetes.io/proxy-buffers-number: "{{ .Values.global.nginxProxyBuffersNumber }}" - cert-manager.io/cluster-issuer: letsencrypt + #cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: diff --git a/etc/k8s/helm-chart/eventhub/charts/admin/templates/admin-ingress.yaml b/etc/k8s/helm-chart/eventhub/charts/admin/templates/admin-ingress.yaml index 0af4e27..bdfd05f 100644 --- a/etc/k8s/helm-chart/eventhub/charts/admin/templates/admin-ingress.yaml +++ b/etc/k8s/helm-chart/eventhub/charts/admin/templates/admin-ingress.yaml @@ -7,7 +7,7 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: "{{ .Values.global.nginxProxyBufferSize }}" nginx.ingress.kubernetes.io/proxy-buffers-number: "{{ .Values.global.nginxProxyBuffersNumber }}" - cert-manager.io/cluster-issuer: letsencrypt + #cert-manager.io/cluster-issuer: letsencrypt # nginx.ingress.kubernetes.io/configuration-snippet: | # more_set_headers "blazor-environment: {{ .Values.global.dotnetEnvironment }}"; spec: diff --git a/etc/k8s/helm-chart/eventhub/charts/api/templates/api-ingress.yaml b/etc/k8s/helm-chart/eventhub/charts/api/templates/api-ingress.yaml index 62d6861..fbaa668 100644 --- a/etc/k8s/helm-chart/eventhub/charts/api/templates/api-ingress.yaml +++ b/etc/k8s/helm-chart/eventhub/charts/api/templates/api-ingress.yaml @@ -7,7 +7,7 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: "{{ .Values.global.nginxProxyBufferSize }}" nginx.ingress.kubernetes.io/proxy-buffers-number: "{{ .Values.global.nginxProxyBuffersNumber }}" - cert-manager.io/cluster-issuer: letsencrypt + #cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: diff --git a/etc/k8s/helm-chart/eventhub/charts/www/templates/www-ingress.yaml b/etc/k8s/helm-chart/eventhub/charts/www/templates/www-ingress.yaml index f72b98e..232f7be 100644 --- a/etc/k8s/helm-chart/eventhub/charts/www/templates/www-ingress.yaml +++ b/etc/k8s/helm-chart/eventhub/charts/www/templates/www-ingress.yaml @@ -10,7 +10,7 @@ metadata: {{- if eq .Release.Name "eh-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} - cert-manager.io/cluster-issuer: letsencrypt + #cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: From 6cc73d0ff42fe236cc12ee6e5ca4e9eb5ef2ca36 Mon Sep 17 00:00:00 2001 From: selmankoc Date: Thu, 28 Aug 2025 11:28:44 +0300 Subject: [PATCH 3/3] Update Ingress templates to use a consistent TLS secret name --- .../eventhub/charts/account/templates/account-ingress.yaml | 2 +- .../eventhub/charts/admin-api/templates/admin-api-ingress.yaml | 2 +- .../eventhub/charts/admin/templates/admin-ingress.yaml | 2 +- .../helm-chart/eventhub/charts/api/templates/api-ingress.yaml | 2 +- .../helm-chart/eventhub/charts/www/templates/www-ingress.yaml | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) diff --git a/etc/k8s/helm-chart/eventhub/charts/account/templates/account-ingress.yaml b/etc/k8s/helm-chart/eventhub/charts/account/templates/account-ingress.yaml index 038f676..cf3b239 100644 --- a/etc/k8s/helm-chart/eventhub/charts/account/templates/account-ingress.yaml +++ b/etc/k8s/helm-chart/eventhub/charts/account/templates/account-ingress.yaml @@ -15,7 +15,7 @@ spec: tls: - hosts: - {{ .Values.global.accountDomain }} - secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls + secretName: oeh-origin-tls rules: - host: "{{ .Values.global.accountDomain }}" http: diff --git a/etc/k8s/helm-chart/eventhub/charts/admin-api/templates/admin-api-ingress.yaml b/etc/k8s/helm-chart/eventhub/charts/admin-api/templates/admin-api-ingress.yaml index d33800b..2b635bd 100644 --- a/etc/k8s/helm-chart/eventhub/charts/admin-api/templates/admin-api-ingress.yaml +++ b/etc/k8s/helm-chart/eventhub/charts/admin-api/templates/admin-api-ingress.yaml @@ -13,7 +13,7 @@ spec: tls: - hosts: - {{ .Values.global.adminApiDomain }} - secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls + secretName: oeh-origin-tls rules: - host: "{{ .Values.global.adminApiDomain }}" http: diff --git a/etc/k8s/helm-chart/eventhub/charts/admin/templates/admin-ingress.yaml b/etc/k8s/helm-chart/eventhub/charts/admin/templates/admin-ingress.yaml index bdfd05f..9ff9af4 100644 --- a/etc/k8s/helm-chart/eventhub/charts/admin/templates/admin-ingress.yaml +++ b/etc/k8s/helm-chart/eventhub/charts/admin/templates/admin-ingress.yaml @@ -15,7 +15,7 @@ spec: tls: - hosts: - {{ .Values.global.adminDomain }} - secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls + secretName: oeh-origin-tls rules: - host: "{{ .Values.global.adminDomain }}" http: diff --git a/etc/k8s/helm-chart/eventhub/charts/api/templates/api-ingress.yaml b/etc/k8s/helm-chart/eventhub/charts/api/templates/api-ingress.yaml index fbaa668..7e74fbf 100644 --- a/etc/k8s/helm-chart/eventhub/charts/api/templates/api-ingress.yaml +++ b/etc/k8s/helm-chart/eventhub/charts/api/templates/api-ingress.yaml @@ -13,7 +13,7 @@ spec: tls: - hosts: - {{ .Values.global.apiDomain }} - secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls + secretName: oeh-origin-tls rules: - host: "{{ .Values.global.apiDomain }}" http: diff --git a/etc/k8s/helm-chart/eventhub/charts/www/templates/www-ingress.yaml b/etc/k8s/helm-chart/eventhub/charts/www/templates/www-ingress.yaml index 232f7be..ec84ff0 100644 --- a/etc/k8s/helm-chart/eventhub/charts/www/templates/www-ingress.yaml +++ b/etc/k8s/helm-chart/eventhub/charts/www/templates/www-ingress.yaml @@ -19,7 +19,7 @@ spec: {{- if eq .Release.Name "eh-az" }} - {{ print "www." .Values.global.wwwDomain }} {{- end }} - secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls + secretName: oeh-origin-tls rules: {{- if eq .Release.Name "eh-az" }} - host: "{{ print "www." .Values.global.wwwDomain }}"