Identity, Access & Isolation
Defense-in-depth model combining Authentik Forward-Auth SSO at the Ingress perimeter, strict Kubernetes RBAC role isolation, automated TLS certificate rotation, and air-gapping for public portfolios.
1. Authentik SSO Forward-Auth Integration
Private administrative interfaces (such as internal operational consoles, Grafana, and ArgoCD) do not expose individual login forms to the open internet. Instead, Ingress-NGINX validates each incoming HTTP request against Authentik's Embedded Outpost via subrequests. Unauthenticated sessions are instantly redirected to SSO.
# Ingress-NGINX Forward-Auth Configuration
annotations:
nginx.ingress.kubernetes.io/auth-url: "http://authentik-outpost.authentik.svc.cluster.local:80/outpost.goauthentik.io/auth/nginx"
nginx.ingress.kubernetes.io/auth-signin: "https://auth.example.internal/outpost.goauthentik.io/start?rd=$escaped_request_uri"
nginx.ingress.kubernetes.io/auth-response-headers: "Set-Cookie,X-authentik-username,X-authentik-groups,X-authentik-email"
nginx.ingress.kubernetes.io/auth-snippet: |
proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header X-Original-URL $scheme://$http_host$request_uri;2. Strict Air-Gapped Public Architecture
To prevent attack vectors against internal cluster databases and APIs, this showcase website (lab.techarvest.co.zw) is statically compiled using Next.js Static Site Generation (SSG). An automated batch runner pulls a sanitized JSON snapshot from the cluster's internal FastAPI adapter, builds the static HTML, and writes it directly to an NGINX container volume.