skillhub/deploy/k8s/base/configmap.yaml
XiaoSeS a35bdce3c6 feat(auth): add LDAP and Active Directory adapter
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-31 19:13:32 +08:00

113 lines
4.1 KiB
YAML
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

apiVersion: v1
kind: ConfigMap
metadata:
name: skillhub-config
data:
# Redis 配置
# 使用外部 Redis:修改为外部主机地址
# 使用内置 Redis(overlays/with-infra):保持 redis
redis-host: redis
redis-port: "6379"
# 连接外部 Redis Cluster 时取消下面几行注释。Cluster 节点存在时,
# Spring Boot 会自动忽略上面的单机 host/port。
# redis-cluster-nodes: "redis-0.example.com:6379,redis-1.example.com:6379,redis-2.example.com:6379"
# redis-cluster-max-redirects: "5"
# redis-username: "skillhub"
# redis-ssl-enabled: "true"
# redis-connect-timeout: "5s"
# redis-timeout: "3s"
# redis-client-name: "skillhub"
# 连接外部 Redis Sentinel 时取消下面几行注释。Sentinel 配置优先于
# Cluster 和单机 host/port。
# redis-sentinel-master: "mymaster"
# redis-sentinel-nodes: "sentinel-0.example.com:26379,sentinel-1.example.com:26379,sentinel-2.example.com:26379"
# redis-sentinel-username: "sentinel-user"
# redis-sentinel-check-list: "true"
# 技能存储路径
storage-base-path: /var/lib/skillhub/storage
# 存储配置
# local: 本地存储(默认), s3: S3/OSS 对象存储
skillhub-storage-provider: local
# 技能扫描器配置
skill-scanner-enabled: "true"
skill-scanner-url: http://skillhub-scanner:8000
skill-scanner-mode: upload
# Bootstrap 管理员配置(非敏感)
bootstrap-admin-enabled: "true"
bootstrap-admin-user-id: docker-admin
bootstrap-admin-username: admin
bootstrap-admin-display-name: Platform Admin
bootstrap-admin-email: admin@example.com
# Session 配置
# HTTP 环境设为 false,HTTPS 环境设为 true
session-cookie-secure: "false"
# 账号合并依赖按稳定 userId 建立的 Spring Session principal index。
session-redis-namespace: skillhub:session:indexed-v1
session-repository-type: indexed
session-redis-configure-action: notify-keyspace-events
# 首次升级先保持关闭;完成 Session 索引过渡后再启用。
auth-account-merge-enabled: "false"
auth-account-merge-session-cutover-complete: "false"
# LDAP/Active Directory 登录(默认关闭)
# 生产环境只使用 LDAPS,或 ldap:// 配合 start-tls=true。provider code、
# authority 和稳定 subject 映射在产生身份绑定后不得随意修改。
auth-ldap-enabled: "false"
auth-ldap-provider-code: ldap-main
auth-ldap-display-name: Corporate Directory
auth-ldap-authority: corp-directory
auth-ldap-url: ldaps://ldap.example.com:636
auth-ldap-start-tls: "false"
auth-ldap-directory-type: OPENLDAP
auth-ldap-base-dn: dc=example,dc=com
auth-ldap-user-search-base: ou=people
auth-ldap-user-search-filter: "(uid={0})"
auth-ldap-bind-dn: cn=skillhub,ou=services,dc=example,dc=com
auth-ldap-subject-attribute: ""
auth-ldap-subject-type: ""
auth-ldap-username-attribute: uid
auth-ldap-display-name-attribute: displayName
auth-ldap-email-attribute: mail
auth-ldap-avatar-url-attribute: ""
auth-ldap-email-authoritative: "false"
auth-ldap-connect-timeout: PT5S
auth-ldap-read-timeout: PT10S
auth-ldap-pool-wait-timeout: PT2S
auth-ldap-max-concurrent-requests: "16"
auth-ldap-max-attribute-values: "16"
# CAS 2.0/3.0 登录(默认关闭)
# service-url 必须是浏览器可访问的精确回调地址,且 provider code
# 必须与路径中的值一致。
auth-cas-enabled: "false"
auth-cas-provider-code: cas-main
auth-cas-display-name: Corporate CAS
auth-cas-authority: corp-cas
auth-cas-server-url: https://cas.example.com/cas
auth-cas-service-url: https://skillhub.example.com/api/v1/auth/cas/cas-main/callback
auth-cas-protocol-version: "3.0"
auth-cas-subject-type: cas_principal
auth-cas-connect-timeout: PT5S
auth-cas-read-timeout: PT10S
auth-cas-state-ttl: PT5M
auth-cas-max-response-bytes: "1048576"
auth-cas-attribute-subject: ""
auth-cas-attribute-display-name: displayName
auth-cas-attribute-email: mail
auth-cas-attribute-avatar-url: ""
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: skillhub-storage-pvc
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 10Gi