Enabling Authentication for an Existing Environment
You can use this procedure to enable authentication when monitoring or Oracle OpenSearch logging is already enabled for an existing Siebel CRM environment. This procedure updates the generated GitOps repository and reconciles the changes through Flux.
Before you begin, you must obtain the environment ID, environment namespace, generated GitOps repository path, and Traefik load balancer IP address.
To enable authentication for an existing environment:
- Source the Kubernetes
profile:
sudo podman exec -it cloudmanager bash cd /home/opc/siebel/<ENV_ID>/ source k8sprofile - Suspend Traefik
reconciliation:
flux suspend kustomization traefik-controller traefik-resources -n <env_namespace> flux suspend helmrelease traefik -n <env_namespace> - Generate an APR1 password hash for each user. Copy only the generated value that
begins with
$apr1$.- For
Prometheus:
read -rsp 'Prometheus auth password: ' PROM_PASS; echo printf '%s\n' "$PROM_PASS" | openssl passwd -apr1 -stdin unset PROM_PASS - For OpenSearch
Dashboards:
read -rsp 'OpenSearch Dashboard auth password: ' OS_PASS; echo printf '%s\n' "$OS_PASS" | openssl passwd -apr1 -stdin unset OS_PASS
- For
Prometheus:
- Update the Traefik Helm Release as follows:
- Open
<Cloud manager repository name>/traefik/traefik-controller/release.yamlin edit mode. - Under
spec.values, add or update the following section:spec: values: observabilityAuth: labels: oracle.siebel.namespace-envid: <env_namespace>-<env_id_lower> prometheus: enabled: true secretName: siebel-prometheus-basic-auth middlewareName: siebel-prometheus-basic-auth users: | PromMon:$apr1$<hash> opensearchDashboard: enabled: true secretName: siebel-opensearch-basic-auth middlewareName: siebel-opensearch-basic-auth users: | LogMon:$apr1$<hash>
- Open
- Update the Prometheus IngressRoute as follows:
- Open
<Cloud manager repository name>/traefik/traefik-resources/siebel-ingress-prometheus.yamlin edit mode. - Add the
siebel-prometheus-basic-authmiddleware to the Prometheus route:routes: - match: PathPrefix(`/prometheus`) kind: Rule middlewares: - name: siebel-prometheus-basic-auth services: - name: prometheus-service port: 8080
- Open
- Update the OpenSearch Dashboards IngressRoute as follows:
- Open
<Cloud manager repository name>/traefik/traefik-resources/siebel-ingress-opensearch.yamlin edit mode. - Add the
siebel-opensearch-basic-authmiddleware to the OpenSearch Dashboards route:routes: - match: PathPrefix(`/opensearch`) kind: Rule middlewares: - name: siebel-opensearch-basic-auth services: - name: opensearch-dashboards port: 5601
- Open
- Commit and push the changes:
git status git add <Cloud manager repository name>/traefik/traefik-controller/release.yaml git add <Cloud manager repository name>/traefik/traefik-resources/siebel-ingress-prometheus.yaml git add <Cloud manager repository name>/traefik/traefik-resources/siebel-ingress-opensearch.yaml git commit -m "enable observability ingress auth" git push git status - Resume and reconcile Traefik
resources:
cd /home/opc/siebel/<ENV_ID>/ source k8sprofile flux resume kustomization traefik-controller traefik-resources -n <env_namespace> flux resume helmrelease traefik -n <env_namespace> flux reconcile source git siebel-repo -n <env_namespace> flux reconcile source git <env_namespace>-repo -n <env_namespace> flux reconcile kustomization traefik-controller -n <env_namespace> flux reconcile kustomization traefik-resources -n <env_namespace> flux reconcile helmrelease traefik -n <env_namespace> - Validate access.
After Flux reconciliation is complete, you can access the enabled dashboards using the configured Basic Authentication credentials:
- Use the Prometheus user name and password to access the Prometheus dashboard.
- Use the OpenSearch Dashboards user name and password to access OpenSearch Dashboards.
Note: You can add a user after observability authentication is enabled. To add a user:- Open
/home/opc/siebel/<ENV_ID>/<Cloud manager repository name>/flux-crm/traefik/traefik-controller/release.yamlin edit mode. - Add a new
username:APR1-password-hashentry on a separate line under the applicableuserssection:spec.values.observabilityAuth.prometheus.usersfor Prometheus.spec.values.observabilityAuth.opensearchDashboard.usersfor OpenSearch Dashboards.
Note: Retain all existing user entries.
- Generate an APR1 password hash for the new user.
- Commit and push the updated
release.yamlfile. - Reconcile the
traefik-controllerKustomization.
For information about generating an APR1 password hash, see step 3 “Generate an APR1 password hash for each user.”