oauth2-proxy carries the authorization request in a signed cookie, so the callback can land on a different replica and still succeed, which is the opposite of the BFF failure in B-0. Sharing is therefore just sharing one Secret. Rotating it is all-or-nothing: --cookie-secret is singular, so there is no second key to read old tickets with, and the log shows both the validation failure and Error removing session, leaving the Redis session orphaned because the key cannot be derived from a ticket that will not decode. Getting there required two diagnoses: the callback 502 came from the full session riding in Set-Cookie past nginx's buffer, and every earlier attempt to read nginx config returned nothing because sudo on the host asks for a password while the guests do not. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
14 lines
492 B
Plaintext
14 lines
492 B
Plaintext
=== Grafana ingress 를 잠시 내린다 (app2 를 빌린다) ===
|
|
grafana ingress 삭제
|
|
secret/oauth2-proxy-secrets created
|
|
deployment.apps/oauth2-proxy created
|
|
service/oauth2-proxy created
|
|
ingress.networking.k8s.io/oauth2-proxy created
|
|
deployment "oauth2-proxy" successfully rolled out
|
|
oauth2-proxy-c76b49c59-8p5hl true kc-lab-1
|
|
oauth2-proxy-c76b49c59-b9928 true kc-lab-2
|
|
|
|
=== 진입점 확인 ===
|
|
https://app2.hyeonworks.com/ HTTP 302
|
|
/ping HTTP 200
|