From f7ae0ae81e0d9e89fdb8f6ef7103547406057e15 Mon Sep 17 00:00:00 2001 From: Jan Larwig Date: Tue, 18 Aug 2026 09:59:05 +0200 Subject: [PATCH] test: update traefik setup and use in-memory for all dex instances instead of etcd Signed-off-by: Jan Larwig --- contrib/local-environment/Makefile | 4 +- contrib/local-environment/dex-traefik.yaml | 25 +++++++++ contrib/local-environment/dex.yaml | 7 +-- .../docker-compose-alpha-config.yaml | 15 +---- .../docker-compose-nginx.yaml | 29 +--------- .../docker-compose-traefik.yaml | 56 +++++++++++++------ contrib/local-environment/docker-compose.yaml | 15 +---- .../oauth2-proxy-traefik.cfg | 8 +-- .../local-environment/traefik/dynamic.yaml | 15 +++-- .../local-environment/traefik/traefik.yaml | 2 + 10 files changed, 89 insertions(+), 87 deletions(-) create mode 100644 contrib/local-environment/dex-traefik.yaml diff --git a/contrib/local-environment/Makefile b/contrib/local-environment/Makefile index 2d7adf24..c6f890b9 100644 --- a/contrib/local-environment/Makefile +++ b/contrib/local-environment/Makefile @@ -49,8 +49,8 @@ kubernetes-down: .PHONY: traefik-up traefik-up: - docker compose -f docker-compose.yaml -f docker-compose-traefik.yaml up -d + docker compose -f docker-compose-traefik.yaml up -d .PHONY: traefik-% traefik-%: - docker compose -f docker-compose.yaml -f docker-compose-traefik.yaml $* + docker compose -f docker-compose-traefik.yaml $* diff --git a/contrib/local-environment/dex-traefik.yaml b/contrib/local-environment/dex-traefik.yaml new file mode 100644 index 00000000..203e863c --- /dev/null +++ b/contrib/local-environment/dex-traefik.yaml @@ -0,0 +1,25 @@ +# This configuration is intended to be used with the Traefik local environment. +# Dex uses in-memory storage because this environment is disposable. +issuer: http://dex.localtest.me/dex +storage: + type: memory +web: + http: 0.0.0.0:5556 +oauth2: + skipApprovalScreen: true +expiry: + signingKeys: "4h" + idTokens: "1h" +staticClients: + - id: oauth2-proxy + redirectURIs: + - "http://oauth2-proxy.localtest.me/oauth2/callback" + name: "OAuth2 Proxy" + secret: b2F1dGgyLXByb3h5LWNsaWVudC1zZWNyZXQK +enablePasswordDB: true +staticPasswords: + - email: "admin@example.com" + # bcrypt hash of the string "password" + hash: "$2a$10$2b2cU8CPhOTaGrs1HRQuAueS7JTT5ZHsHSzYiFPm1leZck7Mc8T4W" + username: "admin" + userID: "08a8684b-db88-4b73-90a9-3cd1661f5466" diff --git a/contrib/local-environment/dex.yaml b/contrib/local-environment/dex.yaml index e3ed0f8f..8872dbed 100644 --- a/contrib/local-environment/dex.yaml +++ b/contrib/local-environment/dex.yaml @@ -3,11 +3,7 @@ # This should configure Dex to run on port 5556 and provides a static login issuer: http://dex.localtest.me:5556/dex storage: - type: etcd - config: - endpoints: - - http://etcd:2379 - namespace: dex/ + type: memory web: http: 0.0.0.0:5556 oauth2: @@ -21,7 +17,6 @@ staticClients: # These redirect URIs point to the `--redirect-url` for OAuth2 proxy. - "http://oauth2-proxy.localtest.me:4180/oauth2/callback" # For basic proxy example. - "http://oauth2-proxy.localtest.me:8080/oauth2/callback" # For nginx example. - - "http://oauth2-proxy.oauth2-proxy.localhost/oauth2/callback" # For traefik example. name: "OAuth2 Proxy" secret: b2F1dGgyLXByb3h5LWNsaWVudC1zZWNyZXQK enablePasswordDB: true diff --git a/contrib/local-environment/docker-compose-alpha-config.yaml b/contrib/local-environment/docker-compose-alpha-config.yaml index 3ad3ed0c..060def68 100644 --- a/contrib/local-environment/docker-compose-alpha-config.yaml +++ b/contrib/local-environment/docker-compose-alpha-config.yaml @@ -1,7 +1,7 @@ # This docker-compose file can be used to bring up an example instance of oauth2-proxy # for manual testing and exploration of features. # Alongside OAuth2-Proxy, this file also starts Dex to act as the identity provider, -# etcd for storage for Dex and HTTPBin as an example upstream. +# HTTPBin as an example upstream. # This file also uses alpha configuration when configuring OAuth2 Proxy. # # This file is an extension of the main compose file and must be used with it @@ -43,25 +43,12 @@ services: dex: aliases: - dex.localtest.me - etcd: {} - depends_on: - - etcd httpbin: container_name: httpbin image: kennethreitz/httpbin ports: [] networks: httpbin: {} - etcd: - container_name: etcd - image: gcr.io/etcd-development/etcd:v3.7.1 - entrypoint: /usr/local/bin/etcd - command: - - --listen-client-urls=http://0.0.0.0:2379 - - --advertise-client-urls=http://etcd:2379 - networks: - etcd: {} networks: dex: {} - etcd: {} httpbin: {} diff --git a/contrib/local-environment/docker-compose-nginx.yaml b/contrib/local-environment/docker-compose-nginx.yaml index 3ae5b5fe..21411031 100644 --- a/contrib/local-environment/docker-compose-nginx.yaml +++ b/contrib/local-environment/docker-compose-nginx.yaml @@ -1,24 +1,14 @@ # This docker-compose file can be used to bring up an example instance of oauth2-proxy # for manual testing and exploration of features. # Alongside OAuth2-Proxy, this file also starts Dex to act as the identity provider, -# etcd for storage for Dex, nginx as a reverse proxy and other http services for upstreams +# nginx as a reverse proxy and other HTTP services for upstreams. # # This file is an extension of the main compose file and must be used with it # docker-compose -f docker-compose.yaml -f docker-compose-nginx.yaml # Alternatively: # make nginx- (eg make nginx-up, make nginx-down) # -# Access one of the following URLs to initiate a login flow: -# - http://oauth2-proxy.localhost -# - http://httpbin.oauth2-proxy.localhost -# -# The OAuth2 Proxy itself is hosted at http://oauth2-proxy.oauth2-proxy.localhost -# -# Note, the above URLs should work with Chrome, but you may need to add hosts -# entries for other browsers -# 127.0.0.1 oauth2-proxy.localhost -# 127.0.0.1 httpbin.oauth2-proxy.localhost -# 127.0.0.1 oauth2-proxy.oauth2-proxy.localhost +# Access http://oauth2-proxy.localtest.me:8080 to initiate a login flow. version: "3.0" services: oauth2-proxy: @@ -33,7 +23,6 @@ services: networks: oauth2-proxy: {} dex: {} - etcd: {} httpbin: {} depends_on: - dex @@ -52,7 +41,6 @@ services: networks: oauth2-proxy: {} dex: {} - etcd: {} httpbin: {} dex: container_name: dex @@ -68,26 +56,13 @@ services: dex: aliases: - dex.localtest.me - etcd: {} - depends_on: - - etcd httpbin: container_name: httpbin image: kennethreitz/httpbin ports: [] networks: httpbin: {} - etcd: - container_name: etcd - image: gcr.io/etcd-development/etcd:v3.7.1 - entrypoint: /usr/local/bin/etcd - command: - - --listen-client-urls=http://0.0.0.0:2379 - - --advertise-client-urls=http://etcd:2379 - networks: - etcd: {} networks: dex: {} - etcd: {} httpbin: {} oauth2-proxy: {} diff --git a/contrib/local-environment/docker-compose-traefik.yaml b/contrib/local-environment/docker-compose-traefik.yaml index be35b08b..24728b68 100644 --- a/contrib/local-environment/docker-compose-traefik.yaml +++ b/contrib/local-environment/docker-compose-traefik.yaml @@ -1,7 +1,7 @@ # This docker-compose file can be used to bring up an example instance of oauth2-proxy # for manual testing and exploration of features. -# Alongside OAuth2-Proxy, this file also starts Dex to act as the identity provider, -# HTTPBin as an example upstream. +# Alongside OAuth2-Proxy, this file also starts Dex to act as the identity provider +# and HTTPBin as an example upstream. # # This can either be created using docker-compose # docker-compose -f docker-compose-traefik.yaml @@ -9,27 +9,46 @@ # make traefik- (eg. make traefik-up, make traefik-down) # # Access one of the following URLs to initiate a login flow: -# - http://oauth2-proxy.localhost -# - http://httpbin.oauth2-proxy.localhost +# - http://oauth2-proxy.localtest.me +# - http://httpbin.localtest.me +# - http://dex.localtest.me/dex # -# The OAuth2 Proxy itself is hosted at http://oauth2-proxy.oauth2-proxy.localhost -# -# Note, the above URLs should work with Chrome, but you may need to add hosts -# entries for other browsers -# 127.0.0.1 oauth2-proxy.localhost -# 127.0.0.1 httpbin.oauth2-proxy.localhost -# 127.0.0.1 oauth2-proxy.oauth2-proxy.localhost -version: '3.0' +# The OAuth2 Proxy itself is hosted at http://oauth2-proxy.localtest.me services: oauth2-proxy: + container_name: oauth2-proxy image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3 + command: --config /oauth2-proxy.cfg ports: [] hostname: oauth2-proxy volumes: - "./oauth2-proxy-traefik.cfg:/oauth2-proxy.cfg" + restart: unless-stopped networks: - oauth2-proxy: + oauth2-proxy: {} + dex: {} + depends_on: + - dex + - httpbin + + dex: + container_name: dex + image: ghcr.io/dexidp/dex:v2.45.1 + command: dex serve /dex.yaml + hostname: dex + volumes: + - "./dex-traefik.yaml:/dex.yaml" + restart: unless-stopped + networks: + dex: {} + + httpbin: + container_name: httpbin + image: kennethreitz/httpbin + ports: [] + networks: + httpbin: {} # Reverse proxy gateway: @@ -43,8 +62,13 @@ services: depends_on: - oauth2-proxy networks: - oauth2-proxy: - httpbin: + oauth2-proxy: {} + httpbin: {} + dex: + aliases: + - dex.localtest.me networks: - oauth2-proxy: + dex: {} + httpbin: {} + oauth2-proxy: {} diff --git a/contrib/local-environment/docker-compose.yaml b/contrib/local-environment/docker-compose.yaml index d31e1110..a0e68d20 100644 --- a/contrib/local-environment/docker-compose.yaml +++ b/contrib/local-environment/docker-compose.yaml @@ -1,7 +1,7 @@ # This docker-compose file can be used to bring up an example instance of oauth2-proxy # for manual testing and exploration of features. # Alongside OAuth2-Proxy, this file also starts Dex to act as the identity provider, -# etcd for storage for Dex and HTTPBin as an example upstream. +# HTTPBin as an example upstream. # # This can either be created using docker-compose # docker-compose -f docker-compose.yaml @@ -41,25 +41,12 @@ services: dex: aliases: - dex.localtest.me - etcd: {} - depends_on: - - etcd httpbin: container_name: httpbin image: kennethreitz/httpbin ports: [] networks: httpbin: {} - etcd: - container_name: etcd - image: gcr.io/etcd-development/etcd:v3.7.1 - entrypoint: /usr/local/bin/etcd - command: - - --listen-client-urls=http://0.0.0.0:2379 - - --advertise-client-urls=http://etcd:2379 - networks: - etcd: {} networks: dex: {} - etcd: {} httpbin: {} diff --git a/contrib/local-environment/oauth2-proxy-traefik.cfg b/contrib/local-environment/oauth2-proxy-traefik.cfg index 8dce6752..f326ca57 100644 --- a/contrib/local-environment/oauth2-proxy-traefik.cfg +++ b/contrib/local-environment/oauth2-proxy-traefik.cfg @@ -2,14 +2,14 @@ http_address="0.0.0.0:4180" cookie_secret="OQINaROshtE9TcZkNAm-5Zs2Pv3xaWytBmc5W7sPX7w=" provider="oidc" email_domains=["example.com"] -oidc_issuer_url="http://dex.localhost:5556/dex" +oidc_issuer_url="http://dex.localtest.me/dex" client_secret="b2F1dGgyLXByb3h5LWNsaWVudC1zZWNyZXQK" client_id="oauth2-proxy" cookie_secure="false" -redirect_url="http://oauth2-proxy.oauth2-proxy.localhost/oauth2/callback" -cookie_domains=".oauth2-proxy.localhost" # Required so cookie can be read on all subdomains. -whitelist_domains=".oauth2-proxy.localhost" # Required to allow redirection back to original requested target. +redirect_url="http://oauth2-proxy.localtest.me/oauth2/callback" +cookie_domains=".localtest.me" # Required so cookie can be read on all subdomains. +whitelist_domains=".localtest.me" # Required to allow redirection back to original requested target. # Mandatory option when using oauth2-proxy with traefik reverse_proxy="true" diff --git a/contrib/local-environment/traefik/dynamic.yaml b/contrib/local-environment/traefik/dynamic.yaml index e5d47df3..80529c3b 100644 --- a/contrib/local-environment/traefik/dynamic.yaml +++ b/contrib/local-environment/traefik/dynamic.yaml @@ -1,22 +1,25 @@ http: routers: oauth2-proxy-route: - rule: "Host(`oauth2-proxy.oauth2-proxy.localhost`)" + rule: "Host(`oauth2-proxy.localtest.me`)" middlewares: - auth-headers service: oauth-backend + dex-route: + rule: "Host(`dex.localtest.me`)" + service: dex-service httpbin-route: - rule: "Host(`httpbin.oauth2-proxy.localhost`)" + rule: "Host(`httpbin.localtest.me`)" service: httpbin-service middlewares: - oauth-auth-redirect # redirects all unauthenticated to oauth2 signin httpbin-route-2: - rule: "Host(`httpbin.oauth2-proxy.localhost`) && PathPrefix(`/no-auto-redirect`)" + rule: "Host(`httpbin.localtest.me`) && PathPrefix(`/no-auto-redirect`)" service: httpbin-service middlewares: - oauth-auth-wo-redirect # unauthenticated session will return a 401 services-oauth2-route: - rule: "Host(`httpbin.oauth2-proxy.localhost`) && PathPrefix(`/oauth2/`)" + rule: "Host(`httpbin.localtest.me`) && PathPrefix(`/oauth2/`)" middlewares: - auth-headers service: oauth-backend @@ -30,6 +33,10 @@ http: loadBalancer: servers: - url: http://oauth2-proxy:4180 + dex-service: + loadBalancer: + servers: + - url: http://dex:5556 middlewares: auth-headers: diff --git a/contrib/local-environment/traefik/traefik.yaml b/contrib/local-environment/traefik/traefik.yaml index 3dd00832..a55bde69 100644 --- a/contrib/local-environment/traefik/traefik.yaml +++ b/contrib/local-environment/traefik/traefik.yaml @@ -5,3 +5,5 @@ log: providers: file: filename: /etc/traefik/dynamic.yaml + # Routes are static for this example; disabling watch avoids host inotify limits. + watch: false