Enabling Authentication for an Existing Environment

You can use this procedure to enable authentication when monitoring or Oracle OpenSearch logging is already enabled for an existing Siebel CRM environment. This procedure updates the generated GitOps repository and reconciles the changes through Flux.

Before you begin, you must obtain the environment ID, environment namespace, generated GitOps repository path, and Traefik load balancer IP address.

To enable authentication for an existing environment:

  1. Source the Kubernetes profile:
    sudo podman exec -it cloudmanager bash
    cd /home/opc/siebel/<ENV_ID>/
    source k8sprofile
  2. Suspend Traefik reconciliation:
    flux suspend kustomization traefik-controller traefik-resources -n <env_namespace>
    flux suspend helmrelease traefik -n <env_namespace>
  3. Generate an APR1 password hash for each user. Copy only the generated value that begins with $apr1$.
    • For Prometheus:
      read -rsp 'Prometheus auth password: ' PROM_PASS; echo
      printf '%s\n' "$PROM_PASS" | openssl passwd -apr1 -stdin
      unset PROM_PASS
    • For OpenSearch Dashboards:
      read -rsp 'OpenSearch Dashboard auth password: ' OS_PASS; echo
      printf '%s\n' "$OS_PASS" | openssl passwd -apr1 -stdin
      unset OS_PASS
  4. Update the Traefik Helm Release as follows:
    1. Open <Cloud manager repository name>/traefik/traefik-controller/release.yaml in edit mode.
    2. Under spec.values, add or update the following section:
      spec:
         values:
            observabilityAuth:
               labels:
                  oracle.siebel.namespace-envid: <env_namespace>-<env_id_lower>
               prometheus:
                  enabled: true
                  secretName: siebel-prometheus-basic-auth
                  middlewareName: siebel-prometheus-basic-auth
                  users: |
                     PromMon:$apr1$<hash>
                  opensearchDashboard:
                     enabled: true
                     secretName: siebel-opensearch-basic-auth
                     middlewareName: siebel-opensearch-basic-auth
                     users: |
                        LogMon:$apr1$<hash>
  5. Update the Prometheus IngressRoute as follows:
    1. Open <Cloud manager repository name>/traefik/traefik-resources/siebel-ingress-prometheus.yaml in edit mode.
    2. Add the siebel-prometheus-basic-auth middleware to the Prometheus route:
      routes:
         - match: PathPrefix(`/prometheus`)
            kind: Rule
            middlewares:
            - name: siebel-prometheus-basic-auth
              services:
            - name: prometheus-service
               port: 8080
  6. Update the OpenSearch Dashboards IngressRoute as follows:
    1. Open <Cloud manager repository name>/traefik/traefik-resources/siebel-ingress-opensearch.yaml in edit mode.
    2. Add the siebel-opensearch-basic-auth middleware to the OpenSearch Dashboards route:
      routes:
         - match: PathPrefix(`/opensearch`)
            kind: Rule
            middlewares:
            - name: siebel-opensearch-basic-auth
            services:
            - name: opensearch-dashboards
               port: 5601
  7. Commit and push the changes:
    git status
    git add <Cloud manager repository name>/traefik/traefik-controller/release.yaml
    git add <Cloud manager repository name>/traefik/traefik-resources/siebel-ingress-prometheus.yaml
    git add <Cloud manager repository name>/traefik/traefik-resources/siebel-ingress-opensearch.yaml
    git commit -m "enable observability ingress auth"
    git push
    git status
  8. Resume and reconcile Traefik resources:
    cd /home/opc/siebel/<ENV_ID>/
    	source k8sprofile
    	
    flux resume kustomization traefik-controller traefik-resources -n <env_namespace>
    flux resume helmrelease traefik -n <env_namespace>
    	
    flux reconcile source git siebel-repo -n <env_namespace>
    flux reconcile source git <env_namespace>-repo -n <env_namespace>
    flux reconcile kustomization traefik-controller -n <env_namespace>
    flux reconcile kustomization traefik-resources -n <env_namespace>
    flux reconcile helmrelease traefik -n <env_namespace>
  9. Validate access.

    After Flux reconciliation is complete, you can access the enabled dashboards using the configured Basic Authentication credentials:

    • Use the Prometheus user name and password to access the Prometheus dashboard.
    • Use the OpenSearch Dashboards user name and password to access OpenSearch Dashboards.
    Note: You can add a user after observability authentication is enabled. To add a user:
    1. Open /home/opc/siebel/<ENV_ID>/<Cloud manager repository name>/flux-crm/traefik/traefik-controller/release.yaml in edit mode.
    2. Add a new username:APR1-password-hash entry on a separate line under the applicable users section:
      • spec.values.observabilityAuth.prometheus.users for Prometheus.
      • spec.values.observabilityAuth.opensearchDashboard.users for OpenSearch Dashboards.

      Note: Retain all existing user entries.

    3. Generate an APR1 password hash for the new user.
    4. Commit and push the updated release.yaml file.
    5. Reconcile the traefik-controller Kustomization.

    For information about generating an APR1 password hash, see step 3 “Generate an APR1 password hash for each user.”