OpenShift oAuth-Proxy Container (sidecar) Logs
2024/02/21 12:10:06 provider.go:129: Defaulting client-id to system:serviceaccount:<REDACTED_COMPANY>-grafana:grafana-oauth-sa
2024/02/21 12:10:06 provider.go:134: Defaulting client-secret to service account token /var/run/secrets/kubernetes.io/serviceaccount/token
2024/02/21 12:10:06 oauthproxy.go:203: mapping path "/" => upstream "http://localhost:3000/"
2024/02/21 12:10:06 oauthproxy.go:224: compiled skip-auth-regex => "^/metrics"
2024/02/21 12:10:06 oauthproxy.go:230: OAuthProxy configured for Client ID: system:serviceaccount:<REDACTED_COMPANY>-grafana:grafana-oauth-sa
2024/02/21 12:10:06 oauthproxy.go:240: Cookie settings: name:_oauth_proxy secure(https):true httponly:true expiry:168h0m0s domain:<default> samesite: refresh:disabled
2024/02/21 12:10:06 http.go:107: HTTPS: listening on [::]:9091
I0221 12:10:06.848246 1 dynamic_serving_content.go:130] Starting serving::/etc/tls/private/tls.crt::/etc/tls/private/tls.key
2024/02/21 12:10:39 provider.go:631: Performing OAuth discovery against https://<REDACTED_IP>/.well-known/oauth-authorization-server
2024/02/21 12:10:39 provider.go:671: 200 GET https://<REDACTED_IP>/.well-known/oauth-authorization-server {
"issuer": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com",
"authorization_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/authorize",
"token_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/token",
"scopes_supported": [
"user:check-access",
"user:full",
"user:info",
"user:list-projects",
"user:list-scoped-projects"
],
"response_types_supported": [
"code",
"token"
],
"grant_types_supported": [
"authorization_code",
"implicit"
],
"code_challenge_methods_supported": [
"plain",
"S256"
]
}
2024/02/21 12:10:41 provider.go:631: Performing OAuth discovery against https://<REDACTED_IP>/.well-known/oauth-authorization-server
2024/02/21 12:10:41 provider.go:671: 200 GET https://<REDACTED_IP>/.well-known/oauth-authorization-server {
"issuer": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com",
"authorization_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/authorize",
"token_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/token",
"scopes_supported": [
"user:check-access",
"user:full",
"user:info",
"user:list-projects",
"user:list-scoped-projects"
],
"response_types_supported": [
"code",
"token"
],
"grant_types_supported": [
"authorization_code",
"implicit"
],
"code_challenge_methods_supported": [
"plain",
"S256"
]
}
2024/02/21 12:10:41 provider.go:671: 200 GET https://<REDACTED_IP>/apis/user.openshift.io/v1/users/~ {"kind":"User","apiVersion":"user.openshift.io/v1","metadata":{<REDACTED_USER_OBJECT>}
2024/02/21 12:10:41 oauthproxy.go:684: <REDACTED_IP>:59816 authentication complete Session{<REDACTED_USERNAME>@cluster.local token:true}
2024/02/21 12:10:52 provider.go:631: Performing OAuth discovery against https://<REDACTED_IP>/.well-known/oauth-authorization-server
2024/02/21 12:10:52 provider.go:671: 200 GET https://<REDACTED_IP>/.well-known/oauth-authorization-server {
"issuer": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com",
"authorization_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/authorize",
"token_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/token",
"scopes_supported": [
"user:check-access",
"user:full",
"user:info",
"user:list-projects",
"user:list-scoped-projects"
],
"response_types_supported": [
"code",
"token"
],
"grant_types_supported": [
"authorization_code",
"implicit"
],
"code_challenge_methods_supported": [
"plain",
"S256"
]
}
2024/02/21 12:10:54 provider.go:631: Performing OAuth discovery against https://<REDACTED_IP>/.well-known/oauth-authorization-server
2024/02/21 12:10:54 provider.go:671: 200 GET https://<REDACTED_IP>/.well-known/oauth-authorization-server {
"issuer": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com",
"authorization_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/authorize",
"token_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/token",
"scopes_supported": [
"user:check-access",
"user:full",
"user:info",
"user:list-projects",
"user:list-scoped-projects"
],
"response_types_supported": [
"code",
"token"
],
"grant_types_supported": [
"authorization_code",
"implicit"
],
"code_challenge_methods_supported": [
"plain",
"S256"
]
}
2024/02/21 12:10:54 provider.go:671: 200 GET https://<REDACTED_IP>/apis/user.openshift.io/v1/users/~ {"kind":"User","apiVersion":"user.openshift.io/v1","metadata":{<REDACTED_USER_OBJECT>}
2024/02/21 12:10:54 oauthproxy.go:684: <REDACTED_IP>:53868 authentication complete Session{<REDACTED_USERNAME>@cluster.local token:true}
2024/02/21 12:11:02 provider.go:631: Performing OAuth discovery against https://<REDACTED_IP>/.well-known/oauth-authorization-server
2024/02/21 12:11:02 provider.go:671: 200 GET https://<REDACTED_IP>/.well-known/oauth-authorization-server {
"issuer": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com",
"authorization_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/authorize",
"token_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/token",
"scopes_supported": [
"user:check-access",
"user:full",
"user:info",
"user:list-projects",
"user:list-scoped-projects"
],
"response_types_supported": [
"code",
"token"
],
"grant_types_supported": [
"authorization_code",
"implicit"
],
"code_challenge_methods_supported": [
"plain",
"S256"
]
}
2024/02/21 12:11:18 provider.go:631: Performing OAuth discovery against https://<REDACTED_IP>/.well-known/oauth-authorization-server
2024/02/21 12:11:18 provider.go:671: 200 GET https://<REDACTED_IP>/.well-known/oauth-authorization-server {
"issuer": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com",
"authorization_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/authorize",
"token_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/token",
"scopes_supported": [
"user:check-access",
"user:full",
"user:info",
"user:list-projects",
"user:list-scoped-projects"
],
"response_types_supported": [
"code",
"token"
],
"grant_types_supported": [
"authorization_code",
"implicit"
],
"code_challenge_methods_supported": [
"plain",
"S256"
]
}
2024/02/21 12:11:18 provider.go:671: 200 GET https://<REDACTED_IP>/apis/user.openshift.io/v1/users/~ {"kind":"User","apiVersion":"user.openshift.io/v1","metadata":{<REDACTED_USER_OBJECT>}
2024/02/21 12:11:18 oauthproxy.go:684: <REDACTED_IP>:58898 authentication complete Session{<REDACTED_USERNAME>@cluster.local token:true}
2024/02/21 12:11:55 provider.go:631: Performing OAuth discovery against https://<REDACTED_IP>/.well-known/oauth-authorization-server
2024/02/21 12:11:55 provider.go:671: 200 GET https://<REDACTED_IP>/.well-known/oauth-authorization-server {
"issuer": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com",
"authorization_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/authorize",
"token_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/token",
"scopes_supported": [
"user:check-access",
"user:full",
"user:info",
"user:list-projects",
"user:list-scoped-projects"
],
"response_types_supported": [
"code",
"token"
],
"grant_types_supported": [
"authorization_code",
"implicit"
],
"code_challenge_methods_supported": [
"plain",
"S256"
]
}
2024/02/21 12:12:09 provider.go:631: Performing OAuth discovery against https://<REDACTED_IP>/.well-known/oauth-authorization-server
2024/02/21 12:12:09 provider.go:671: 200 GET https://<REDACTED_IP>/.well-known/oauth-authorization-server {
"issuer": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com",
"authorization_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/authorize",
"token_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/token",
"scopes_supported": [
"user:check-access",
"user:full",
"user:info",
"user:list-projects",
"user:list-scoped-projects"
],
"response_types_supported": [
"code",
"token"
],
"grant_types_supported": [
"authorization_code",
"implicit"
],
"code_challenge_methods_supported": [
"plain",
"S256"
]
}
2024/02/21 12:12:10 provider.go:671: 200 GET https://<REDACTED_IP>/apis/user.openshift.io/v1/users/~ {"kind":"User","apiVersion":"user.openshift.io/v1","metadata":{<REDACTED_USER_OBJECT>}
2024/02/21 12:12:10 oauthproxy.go:684: <REDACTED_IP>:60434 authentication complete Session{<REDACTED_USERNAME>@cluster.local token:true}
2024/02/21 12:12:45 provider.go:631: Performing OAuth discovery against https://<REDACTED_IP>/.well-known/oauth-authorization-server
2024/02/21 12:12:45 provider.go:671: 200 GET https://<REDACTED_IP>/.well-known/oauth-authorization-server {
"issuer": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com",
"authorization_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/authorize",
"token_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/token",
"scopes_supported": [
"user:check-access",
"user:full",
"user:info",
"user:list-projects",
"user:list-scoped-projects"
],
"response_types_supported": [
"code",
"token"
],
"grant_types_supported": [
"authorization_code",
"implicit"
],
"code_challenge_methods_supported": [
"plain",
"S256"
]
}
2024/02/21 12:12:47 provider.go:631: Performing OAuth discovery against https://<REDACTED_IP>/.well-known/oauth-authorization-server
2024/02/21 12:12:47 provider.go:671: 200 GET https://<REDACTED_IP>/.well-known/oauth-authorization-server {
"issuer": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com",
"authorization_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/authorize",
"token_endpoint": "https://oauth-openshift.apps.<REDACTED_CLUSTER>.ocp.<REDACTED_COMPANY>.com/oauth/token",
"scopes_supported": [
"user:check-access",
"user:full",
"user:info",
"user:list-projects",
"user:list-scoped-projects"
],
"response_types_supported": [
"code",
"token"
],
"grant_types_supported": [
"authorization_code",
"implicit"
],
"code_challenge_methods_supported": [
"plain",
"S256"
]
}
2024/02/21 12:12:47 provider.go:671: 200 GET https://<REDACTED_IP>/apis/user.openshift.io/v1/users/~ {"kind":"User","apiVersion":"user.openshift.io/v1","metadata":{<REDACTED_USER_OBJECT>}
2024/02/21 12:12:47 oauthproxy.go:684: <REDACTED_IP>:58790 authentication complete Session{<REDACTED_USERNAME>@cluster.local token:true}
2024/02/21 12:13:29 reverseproxy.go:491: http: proxy error: context canceled
2024/02/21 12:13:35 reverseproxy.go:491: http: proxy error: context canceled
2024/02/21 12:13:39 reverseproxy.go:491: http: proxy error: context canceled
2024/02/21 12:14:01 reverseproxy.go:491: http: proxy error: context canceled
2024/02/21 12:14:09 reverseproxy.go:491: http: proxy error: context canceled
2024/02/21 12:14:09 reverseproxy.go:491: http: proxy error: context canceled
2024/02/21 12:14:09 reverseproxy.go:491: http: proxy error: context canceled
2024/02/21 12:14:15 reverseproxy.go:491: http: proxy error: context canceled
2024/02/21 12:14:25 reverseproxy.go:491: http: proxy error: context canceled
2024/02/21 12:14:25 reverseproxy.go:491: http: proxy error: context canceled
2024/02/21 12:14:25 reverseproxy.go:491: http: proxy error: context canceled
2024/02/21 12:14:25 reverseproxy.go:491: http: proxy error: context canceled
2024/02/21 12:14:25 reverseproxy.go:491: http: proxy error: context canceled