Adds multi-user-basic authentication mode to the helm chart alongside
existing basic (single-user) and oauth modes.
Multi-user BasicAuth mode enables:
- Pass-through authentication (credentials in request headers)
- Optional background operations using app passwords via Astrolabe
- Optional OAuth client credentials (uses DCR if not provided)
- Token encryption and persistent storage for background sync
Changes:
- values.yaml: Add auth.multiUserBasic configuration section
- deployment.yaml: Add ENABLE_MULTI_USER_BASIC_AUTH and related env vars
- secret.yaml: Add secret template for token encryption key and OAuth credentials
- pvc.yaml: Add PVC template for token database persistence
- _helpers.tpl: Add helper functions for secret/PVC names
Tested with:
helm template --set auth.mode=multi-user-basic \
--set auth.multiUserBasic.enableOfflineAccess=true \
--set auth.multiUserBasic.tokenEncryptionKey=... \
--set vectorSync.enabled=true
Related: Multi-user deployment support (ADR-020)
48 lines
1.8 KiB
YAML
48 lines
1.8 KiB
YAML
{{- if eq .Values.auth.mode "basic" }}
|
|
{{- if not .Values.auth.basic.existingSecret }}
|
|
apiVersion: v1
|
|
kind: Secret
|
|
metadata:
|
|
name: {{ include "nextcloud-mcp-server.fullname" . }}-basic-auth
|
|
labels:
|
|
{{- include "nextcloud-mcp-server.labels" . | nindent 4 }}
|
|
type: Opaque
|
|
data:
|
|
{{ .Values.auth.basic.usernameKey }}: {{ .Values.auth.basic.username | b64enc | quote }}
|
|
{{ .Values.auth.basic.passwordKey }}: {{ .Values.auth.basic.password | b64enc | quote }}
|
|
{{- end }}
|
|
{{- end }}
|
|
---
|
|
{{- if eq .Values.auth.mode "multi-user-basic" }}
|
|
{{- if and .Values.auth.multiUserBasic.enableOfflineAccess (not .Values.auth.multiUserBasic.existingSecret) }}
|
|
apiVersion: v1
|
|
kind: Secret
|
|
metadata:
|
|
name: {{ include "nextcloud-mcp-server.fullname" . }}-multi-user-basic
|
|
labels:
|
|
{{- include "nextcloud-mcp-server.labels" . | nindent 4 }}
|
|
type: Opaque
|
|
data:
|
|
{{ .Values.auth.multiUserBasic.tokenEncryptionKeyKey }}: {{ .Values.auth.multiUserBasic.tokenEncryptionKey | b64enc | quote }}
|
|
{{- if .Values.auth.multiUserBasic.clientId }}
|
|
{{ .Values.auth.multiUserBasic.clientIdKey }}: {{ .Values.auth.multiUserBasic.clientId | b64enc | quote }}
|
|
{{ .Values.auth.multiUserBasic.clientSecretKey }}: {{ .Values.auth.multiUserBasic.clientSecret | b64enc | quote }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- end }}
|
|
---
|
|
{{- if eq .Values.auth.mode "oauth" }}
|
|
{{- if and .Values.auth.oauth.clientId (not .Values.auth.oauth.existingSecret) }}
|
|
apiVersion: v1
|
|
kind: Secret
|
|
metadata:
|
|
name: {{ include "nextcloud-mcp-server.fullname" . }}-oauth
|
|
labels:
|
|
{{- include "nextcloud-mcp-server.labels" . | nindent 4 }}
|
|
type: Opaque
|
|
data:
|
|
{{ .Values.auth.oauth.clientIdKey }}: {{ .Values.auth.oauth.clientId | b64enc | quote }}
|
|
{{ .Values.auth.oauth.clientSecretKey }}: {{ .Values.auth.oauth.clientSecret | b64enc | quote }}
|
|
{{- end }}
|
|
{{- end }}
|