Give teams access to the dashboard and API
Let your teams open the Konfidence dashboard in a browser and sign in with their company account. The same setup lets the kden CLI and CI pipelines reach the API. Publish the API server under a public URL with TLS, then configure login through your OpenID Connect (OIDC) provider.
This configures the installation's endpoint and login. Create a project and grant teams access to it to make project resources available after sign-in.
Prerequisites
- Konfidence installed with the release name
konfidenceinkonfidence-system. See Install Konfidence. - Helm and
kubectlaccess to upgrade the release and configure Secrets and routing in its namespace. - An Ingress controller in the cluster, or a Gateway API implementation such as Envoy Gateway. Check:
kubectl get ingressclassorkubectl get gatewayclasslists at least one class. - A DNS name for the API that resolves to that controller, for example
konfidence.example.com. - A TLS certificate for that name as a Secret in
konfidence-system. An issuer such as cert-manager can create it from Ingress annotations instead. - An OIDC client at your identity provider with the redirect URL
https://konfidence.example.com/api/v1/auth/callback. Note its issuer URL, client ID, and client secret.
The session cookie is marked secure, so browsers send it over HTTPS only. Plain HTTP works for curl but not for the dashboard login.
Set the values used below:
export KONFIDENCE_VERSION=0.0.1-alpha.1
export KONFIDENCE_HOST=konfidence.example.comStore the client secret
The chart reads the client secret from a Secret in the release namespace:
kubectl create secret generic konfidence-oidc-client \
--namespace konfidence-system \
--from-literal=client-secret='<CLIENT_SECRET>'Write the values file
Choose the tab for your controller. Save the file as konfidence-values.yaml and replace the issuer URL and client ID with the values from your provider. For an Ingress, replace <INGRESS_CLASS> with the name from kubectl get ingressclass.
api:
oidc:
enabled: true
issuerURL: https://id.example.com
clientId: konfidence
clientSecretRef:
name: konfidence-oidc-client
key: client-secret
redirectURL: https://konfidence.example.com/api/v1/auth/callback
scopes: openid,profile,email,groups
ingress:
enabled: true
className: <INGRESS_CLASS>
hosts:
- host: konfidence.example.com
paths:
- path: /
pathType: Prefix
tls:
- secretName: konfidence-tls
hosts:
- konfidence.example.comapi:
oidc:
enabled: true
issuerURL: https://id.example.com
clientId: konfidence
clientSecretRef:
name: konfidence-oidc-client
key: client-secret
redirectURL: https://konfidence.example.com/api/v1/auth/callback
scopes: openid,profile,email,groups
ingress:
enabled: falseRole bindings match users by group, so the token must carry group membership. Add the scope your provider uses for that, groups in the example. Leave redirectURL identical to the redirect URL registered at the provider.
Upgrade the release
Apply the values to the existing release:
helm upgrade konfidence oci://ghcr.io/konfidence-project/charts/konfidence \
--version "$KONFIDENCE_VERSION" \
--namespace konfidence-system \
--set image.repository=ghcr.io/konfidence-project/konfidence-operator \
--set image.tag="$KONFIDENCE_VERSION" \
--set webhook.enabled=false \
--values konfidence-values.yaml \
--waitHelm restarts the API deployment.
Publish the endpoint
kubectl get ingress konfidence-api --namespace konfidence-systemapiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: konfidence-api
namespace: konfidence-system
spec:
parentRefs:
- name: <GATEWAY_NAME>
namespace: <GATEWAY_NAMESPACE>
hostnames:
- konfidence.example.com
rules:
- backendRefs:
- name: konfidence-api
port: 8090With an Ingress, Helm already created it during the upgrade. The command lists konfidence-api with your host and an address.
With Gateway API, save the route as konfidence-route.yaml and apply it with kubectl apply -f konfidence-route.yaml. It points at the konfidence-api Service. TLS terminates at the Gateway's HTTPS listener, so the certificate is configured on the Gateway, not on the route. The Gateway must allow routes from konfidence-system in its listener's allowedRoutes.
Verify the endpoint
Check the health endpoint through your Ingress or Gateway:
curl --fail "https://$KONFIDENCE_HOST/healthz"The command exits with status 0. Open https://konfidence.example.com in a browser. The sign-in page appears, and after signing in you see the dashboard with the projects your groups grant you.
Log in with the CLI
Point kden at the public endpoint and sign in:
kden config set api-endpoint "https://$KONFIDENCE_HOST/api"
kden loginA browser window opens for the identity provider. After sign-in, kden project list prints the projects your groups grant you.
Troubleshooting
- The API pod restarts with
oidc-issuer-url must not be empty:api.oidc.issuerURLis missing from the values file. - The provider rejects the login with a redirect URI error:
redirectURLdiffers from the URL registered at the provider. - Sign-in succeeds but
kden project listis empty: the token carries no group that a project binds. Check the scope and Grant teams access to a project. curlreports a certificate error: the TLS Secret named iningress.tlsdoes not exist or covers a different host.
Next steps
- Choose a deployer selects the deployment capabilities to install.
- Create a project establishes a project, and Grant teams access to a project binds identity provider groups to its roles.
- Grant CI pipelines access lets pipelines call the exposed API.