mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-10-03 13:13:15 +02:00
* update to release version v7.15.5 * Merge commit from fork Signed-off-by: Jan Larwig <jan@larwig.com> Co-authored-by: blakeroberts-wk <blake.roberts@workiva.com> * Merge commit from fork Signed-off-by: Jan Larwig <jan@larwig.com> * Merge commit from fork * fix: validate trusted IP proxy headers Respect trusted proxy boundaries before using real-client-IP headers for authentication bypass decisions and safely traverse X-Forwarded-For chains. Signed-off-by: Jan Larwig <jan@larwig.com> * fix: trusted-ip header bypass Signed-off-by: Jan Larwig <jan@larwig.com> * docs: add changelog entry Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz> --------- Signed-off-by: Jan Larwig <jan@larwig.com> Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz> * docs: changelog for v7.15.5 Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz> * docs: update order of owners for prow Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz> * ci: make the linter happy again Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz> --------- Signed-off-by: Jan Larwig <jan@larwig.com> Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Jan Larwig <jan@larwig.com> Co-authored-by: blakeroberts-wk <blake.roberts@workiva.com> Co-authored-by: Jan Larwig <jan.larwig@digits.schwarz>
1.8 KiB
1.8 KiB
id, title
| id | title |
|---|---|
| index | Integrations |
This section provides configuration examples for integrating OAuth2 Proxy with various reverse proxies, ingress controllers, and Kubernetes web UIs.
Reverse Proxies and Ingress Controllers
OAuth2 Proxy can be integrated with popular reverse proxies and ingress controllers to add authentication to your applications:
Kubernetes Web UIs
OAuth2 Proxy can also be used to add authentication to Kubernetes web user interfaces:
- Headlamp ✨ Recommended
- Kubernetes Dashboard ⚠️ Deprecated
:::tip When integrating with Kubernetes web UIs, make sure to:
- Configure the Ingress to pass the Authorization header with the bearer token
- Increase buffer sizes for large OIDC tokens (especially with Azure Entra ID)
- Set up appropriate Kubernetes RBAC permissions for your users or groups :::
General Requirements
Most integrations require the following OAuth2 Proxy configuration:
--reverse-proxy=true: Required to correctly handleX-Forwarded-*headers--trusted-proxy-ip=<proxy CIDR>: Restricts forwarded headers, including client identity used by--trusted-ip, to the reverse proxies' addresses or networks. Include the direct peer and every trusted hop that can appear in XFF. Without this option, all source addresses are trusted for backwards compatibility.- Session storage: For production deployments with large tokens due to a lot of claims like AD groups, use
--session-store-type=redis
For provider-specific configuration, see the OAuth Provider Configuration documentation.
:::note
If you set up your OAuth2 provider to rotate your client secret, you can use the client-secret-file option to reload the secret when it is updated.
:::