mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
docs: update external auth to better explain process (#16027)
- adds to @ChristopherJTrent's PR #15970 > Adds more information on how to add external auth, including docker-compose and docker CLI examples and terraform code for template integration. - general edits and improvements to the external-auth doc [preview](https://coder.com/docs/@15970-external-auth-update/admin/external-auth) --------- Co-authored-by: Christopher Trent <ChristopherJTrent@outlook.com> Co-authored-by: Muhammad Atif Ali <me@matifali.dev>
This commit is contained in:
co-authored by
Christopher Trent
Muhammad Atif Ali
parent
8fb7832b27
commit
ee1829ba71
+25
-27
@@ -52,7 +52,7 @@ a wildcard subdomain that resolves to Coder (e.g. `*.coder.example.com`).
|
||||
If you are providing TLS certificates directly to the Coder server, either
|
||||
|
||||
1. Use a single certificate and key for both the root and wildcard domains.
|
||||
2. Configure multiple certificates and keys via
|
||||
1. Configure multiple certificates and keys via
|
||||
[`coder.tls.secretNames`](https://github.com/coder/coder/blob/main/helm/coder/values.yaml)
|
||||
in the Helm Chart, or
|
||||
[`--tls-cert-file`](../../reference/cli/server.md#--tls-cert-file) and
|
||||
@@ -78,29 +78,27 @@ working directory prior to step 1.
|
||||
|
||||
1. Create the TLS secret in your Kubernetes cluster
|
||||
|
||||
```shell
|
||||
kubectl create secret tls coder-tls -n <coder-namespace> --key="tls.key" --cert="tls.crt"
|
||||
```
|
||||
```shell
|
||||
kubectl create secret tls coder-tls -n <coder-namespace> --key="tls.key" --cert="tls.crt"
|
||||
```
|
||||
|
||||
> You can use a single certificate for the both the access URL and wildcard
|
||||
> access URL. The certificate CN must match the wildcard domain, such as
|
||||
> `*.example.coder.com`.
|
||||
You can use a single certificate for the both the access URL and wildcard access URL. The certificate CN must match the wildcard domain, such as `*.example.coder.com`.
|
||||
|
||||
1. Reference the TLS secret in your Coder Helm chart values
|
||||
|
||||
```yaml
|
||||
coder:
|
||||
tls:
|
||||
secretName:
|
||||
- coder-tls
|
||||
```yaml
|
||||
coder:
|
||||
tls:
|
||||
secretName:
|
||||
- coder-tls
|
||||
|
||||
# Alternatively, if you use an Ingress controller to terminate TLS,
|
||||
# set the following values:
|
||||
ingress:
|
||||
enable: true
|
||||
secretName: coder-tls
|
||||
wildcardSecretName: coder-tls
|
||||
```
|
||||
# Alternatively, if you use an Ingress controller to terminate TLS,
|
||||
# set the following values:
|
||||
ingress:
|
||||
enable: true
|
||||
secretName: coder-tls
|
||||
wildcardSecretName: coder-tls
|
||||
```
|
||||
|
||||
## PostgreSQL Database
|
||||
|
||||
@@ -116,7 +114,7 @@ the PostgreSQL interactive terminal), output the connection URL with the
|
||||
following command:
|
||||
|
||||
```console
|
||||
coder server postgres-builtin-url
|
||||
$ coder server postgres-builtin-url
|
||||
psql "postgres://coder@localhost:49627/coder?sslmode=disable&password=feU...yI1"
|
||||
```
|
||||
|
||||
@@ -126,13 +124,13 @@ To migrate from the built-in database to an external database, follow these
|
||||
steps:
|
||||
|
||||
1. Stop your Coder deployment.
|
||||
2. Run `coder server postgres-builtin-serve` in a background terminal.
|
||||
3. Run `coder server postgres-builtin-url` and copy its output command.
|
||||
4. Run `pg_dump <built-in-connection-string> > coder.sql` to dump the internal
|
||||
1. Run `coder server postgres-builtin-serve` in a background terminal.
|
||||
1. Run `coder server postgres-builtin-url` and copy its output command.
|
||||
1. Run `pg_dump <built-in-connection-string> > coder.sql` to dump the internal
|
||||
database to a file.
|
||||
5. Restore that content to an external database with
|
||||
1. Restore that content to an external database with
|
||||
`psql <external-connection-string> < coder.sql`.
|
||||
6. Start your Coder deployment with
|
||||
1. Start your Coder deployment with
|
||||
`CODER_PG_CONNECTION_URL=<external-connection-string>`.
|
||||
|
||||
## Configuring Coder behind a proxy
|
||||
@@ -144,7 +142,7 @@ To configure Coder behind a corporate proxy, set the environment variables
|
||||
## External Authentication
|
||||
|
||||
Coder supports external authentication via OAuth2.0. This allows enabling
|
||||
integrations with git providers, such as GitHub, GitLab, and Bitbucket etc.
|
||||
integrations with Git providers, such as GitHub, GitLab, and Bitbucket.
|
||||
|
||||
External authentication can also be used to integrate with external services
|
||||
like JFrog Artifactory and others.
|
||||
@@ -154,5 +152,5 @@ more information.
|
||||
|
||||
## Up Next
|
||||
|
||||
- [Learn how to setup and manage templates](../templates/index.md)
|
||||
- [Setup and manage templates](../templates/index.md)
|
||||
- [Setup external provisioners](../provisioners.md)
|
||||
|
||||
Reference in New Issue
Block a user