Files
bea3f04bf8 release: v7.15.5 (#3553)
* update to release version v7.15.5

* Merge commit from fork

Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: blakeroberts-wk <blake.roberts@workiva.com>

* Merge commit from fork

Signed-off-by: Jan Larwig <jan@larwig.com>

* Merge commit from fork

* fix: validate trusted IP proxy headers

Respect trusted proxy boundaries before using real-client-IP headers for authentication bypass decisions and safely traverse X-Forwarded-For chains.

Signed-off-by: Jan Larwig <jan@larwig.com>

* fix: trusted-ip header bypass

Signed-off-by: Jan Larwig <jan@larwig.com>

* docs: add changelog entry

Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>

* docs: changelog for v7.15.5

Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>

* docs: update order of owners for prow

Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>

* ci: make the linter happy again

Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
Co-authored-by: blakeroberts-wk <blake.roberts@workiva.com>
Co-authored-by: Jan Larwig <jan.larwig@digits.schwarz>
2026-10-01 11:01:25 +02:00

1.8 KiB

id, title
id title
index Integrations

This section provides configuration examples for integrating OAuth2 Proxy with various reverse proxies, ingress controllers, and Kubernetes web UIs.

Reverse Proxies and Ingress Controllers

OAuth2 Proxy can be integrated with popular reverse proxies and ingress controllers to add authentication to your applications:

Kubernetes Web UIs

OAuth2 Proxy can also be used to add authentication to Kubernetes web user interfaces:

:::tip When integrating with Kubernetes web UIs, make sure to:

  1. Configure the Ingress to pass the Authorization header with the bearer token
  2. Increase buffer sizes for large OIDC tokens (especially with Azure Entra ID)
  3. Set up appropriate Kubernetes RBAC permissions for your users or groups :::

General Requirements

Most integrations require the following OAuth2 Proxy configuration:

  • --reverse-proxy=true: Required to correctly handle X-Forwarded-* headers
  • --trusted-proxy-ip=<proxy CIDR>: Restricts forwarded headers, including client identity used by --trusted-ip, to the reverse proxies' addresses or networks. Include the direct peer and every trusted hop that can appear in XFF. Without this option, all source addresses are trusted for backwards compatibility.
  • Session storage: For production deployments with large tokens due to a lot of claims like AD groups, use --session-store-type=redis

For provider-specific configuration, see the OAuth Provider Configuration documentation.

:::note If you set up your OAuth2 provider to rotate your client secret, you can use the client-secret-file option to reload the secret when it is updated. :::