Skip to content

Commit 80c6535

Browse files
committed
docs: add Quick Navigation Map and YouTube Multimedia Series (masterclasses & shorts)
1 parent b2fc6c1 commit 80c6535

1 file changed

Lines changed: 188 additions & 0 deletions

File tree

‎README.md‎

Lines changed: 188 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -70,8 +70,82 @@ axes:
7070
> (OpenShift-only). If you deploy on OpenShift *exclusively*, either works; this
7171
> repo generalises the same design to any distribution.
7272
73+
<a id="quick-navigation-map"></a>
74+
## 🗺️ Quick Navigation Map
75+
76+
This repository provides an enterprise, production-ready umbrella Helm chart that deploys the official **Traefik Ingress Controller (v3.7+)** with a **Keycloak-protected dashboard (oauth2-proxy + ForwardAuth)**, portable across **Red Hat OpenShift**, **Rancher RKE2**, **k3s**, **kubeadm**, and **VMware Tanzu**. Use this map to navigate the repository layout, architectural documentation, and multimedia series:
77+
78+
### 🧭 Repository Architecture Blueprint
79+
```text
80+
traefik-keycloak-portable/ # 🌐 Multi-Distribution Ingress & Keycloak SSO Platform
81+
├── 📁 argocd/ # Declarative GitOps Multi-Source Delivery
82+
│ ├── 📁 apps/ # ArgoCD Applications (traefik-keycloak)
83+
│ ├── 📄 project.yaml # AppProject scoping repos, namespaces, and cluster resources
84+
│ └── 📄 README.md # Multi-source $values GitOps pattern & runbooks
85+
├── 📁 docs/ # Architectural Deep Dives & Distribution Guides
86+
│ ├── 📄 air-gapped.md # Disconnected deployment, vendoring & image mirroring
87+
│ ├── 📄 external-secrets.md # HashiCorp Vault ESO SecretStore & token sync
88+
│ ├── 📄 network-policies.md # Calico & Cilium default-deny NetworkPolicies
89+
│ └── 📄 tls-secret.md # CA trust chains, cert-manager & TLS secret injection
90+
├── 📁 helm/ # Umbrella Helm Chart & Templates
91+
│ └── 📁 traefik-keycloak/ # Portable umbrella chart (Chart v41.0.2 / Traefik v3.7.6)
92+
│ ├── 📁 charts/ # Vendored official Traefik subchart (offline-ready)
93+
│ ├── 📁 templates/ # Core oauth2-proxy, IngressRoute & _validate.tpl
94+
│ └── 📄 values.yaml # Base values & orthogonal feature flag defaults
95+
├── 📁 keycloak/ # Identity Provider Configuration & Setup
96+
│ └── 📄 keycloak-client-setup.md # OIDC client, mapper & traefik-admin role guide
97+
├── 📁 metallb/ # Bare-Metal Layer 2 / BGP Load Balancing
98+
│ └── 📄 ipaddresspool.example.yaml # On-prem IPAddressPool & L2Advertisement definition
99+
├── 📁 secrets/ # Secret Synchronization Templates
100+
│ └── 📄 oauth2-proxy-secret.example.yaml # Sealed/Vault secret reference for cookie & client secrets
101+
├── 📁 sites/ # Distribution-Specific Values Overlays
102+
│ ├── 📄 values-openshift.yaml # Red Hat OpenShift (restricted-v2 SCC, dynamic UIDs)
103+
│ ├── 📄 values-rke2.yaml # Rancher RKE2 (Cilium LB-IPAM, non-root)
104+
│ ├── 📄 values-k3s.yaml # Lightweight edge k3s (MetalLB, Traefik disabled)
105+
│ ├── 📄 values-kubeadm.yaml # Bare-metal kubeadm (MetalLB, local CA ConfigMap)
106+
│ ├── 📄 values-tanzu-nsx.yaml # VMware Tanzu / TKG with NSX ALB (Avi Vantage)
107+
│ └── 📄 values-tanzu-kubevip.yaml # VMware Tanzu / TKG with kube-vip virtual IP
108+
├── 📄 CHANGELOG.md # Release history & version notes
109+
├── 📄 install.sh # Imperative deployment script with pre-flight linting
110+
└── 📄 PORTABILITY.md # Portability matrix across distros & load balancers
111+
```
112+
113+
<a id="ai-multimedia-series"></a>
114+
## 🎬 AI-Generated Multimedia Series (YouTube)
115+
116+
This repository is accompanied by an educational video masterclass series and technical shorts synthesized with **Gemini NotebookLM** based directly on the multi-distribution architecture, ForwardAuth security flows, and air-gapped runbooks from this project. All videos are freely accessible on YouTube on the [**@nubenetes**](https://youtube.com/@nubenetes) channel.
117+
118+
> [!NOTE]
119+
> **Multilingual Learning Experience**:
120+
> Content features sessions with original spoken audio in **English 🇺🇸**, with automated YouTube closed captions (CC) translated into **20+ languages** for global platform engineering and SRE teams.
121+
122+
### 📽️ Full-Length Technical Deep Dives (Architecture Masterclasses)
123+
124+
| # | Video Guide Title | Engineering Domain & Core Architecture | Audio | Duration | Direct Link |
125+
|:---:|:---|:---|:---:|:---:|:---:|
126+
| **01** | [Portable Traefik & Keycloak Helm Chart](https://www.youtube.com/watch?v=3OQhS25KbIk) | **Multi-Distro Architecture & Feature Flags**<br/>Orthogonal axes, fail-fast validation in `_validate.tpl`, vendored offline charts | 🇺🇸 EN | `9:26` | [▶️ Watch](https://www.youtube.com/watch?v=3OQhS25KbIk) |
127+
| **02** | [Multi-Distro Kubernetes Portability](https://www.youtube.com/watch?v=8w0-SJw0jLo) | **Platform Engineering & Distro Quirks**<br/>OpenShift restricted-v2 SCC vs vanilla K8s, dynamic UIDs & CNI NetworkPolicies | 🇺🇸 EN | `9:26` | [▶️ Watch](https://www.youtube.com/watch?v=8w0-SJw0jLo) |
128+
| **03** | [Traefik & Keycloak OIDC Authentication](https://www.youtube.com/watch?v=X4GdtkJrbZo) | **Zero-Trust Ingress & ForwardAuth**<br/>oauth2-proxy token exchange, statusRewrites 401 to 302, role RBAC (`traefik-admin`) | 🇺🇸 EN | `7:04` | [▶️ Watch](https://www.youtube.com/watch?v=X4GdtkJrbZo) |
129+
| **04** | [Portable Kubernetes Networking](https://www.youtube.com/watch?v=Hb4K81jiGrA) | **On-Premises LoadBalancer Backends**<br/>MetalLB (L2/BGP), VMware NSX ALB (Avi), kube-vip virtual IP & Cilium LB-IPAM | 🇺🇸 EN | `7:52` | [▶️ Watch](https://www.youtube.com/watch?v=Hb4K81jiGrA) |
130+
| **05** | [End-to-End Portable Traefik & Keycloak](https://www.youtube.com/watch?v=1AfsoppwT_w) | **Air-Gapped GitOps Masterclass**<br/>Full Day 0 to Day 2 lifecycle, HashiCorp Vault ESO sync, multi-source ArgoCD | 🇺🇸 EN | `9:46` | [▶️ Watch](https://www.youtube.com/watch?v=1AfsoppwT_w) |
131+
132+
### ⚡ Video Shorts Matrix
133+
134+
| # | Short Title | Architectural Domain & Focus | Audio | Duration | Action |
135+
|:---:|:---|:---|:---:|:---:|:---:|
136+
| **01** | [The Ultimate Portable Traefik & Keycloak Helm Chart](https://www.youtube.com/shorts/murHHpH8WHE) | **Unified Ingress & OIDC**<br/>Zero forks, ForwardAuth middleware, status 401 to 302 rewrite & role-gating | 🇺🇸 EN | `1:30` | [▶️ Watch](https://www.youtube.com/shorts/murHHpH8WHE) |
137+
| **02** | [How Air-Gapped Kubernetes Clusters Install Ingress](https://www.youtube.com/shorts/LGdVhOyaVaI) | **Air-Gapped Architecture**<br/>Vendored Helm dependencies & internal OCI mirrors for disconnected datacenters | 🇺🇸 EN | `1:03` | [▶️ Watch](https://www.youtube.com/shorts/LGdVhOyaVaI) |
138+
| **03** | [How External Secrets Operator Connects Vault](https://www.youtube.com/shorts/BUwUb6vpbqs) | **Zero-Trust Secret Sync**<br/>Bridging HashiCorp Vault into Kubernetes secrets without committing passwords | 🇺🇸 EN | `1:02` | [▶️ Watch](https://www.youtube.com/shorts/BUwUb6vpbqs) |
139+
| **04** | [Why OpenShift SCC Breaks Standard Pods](https://www.youtube.com/shorts/Cv5jakkIseE) | **OpenShift Hardening**<br/>restricted-v2 dynamic UID ranges vs hardcoded non-root UIDs (65532) | 🇺🇸 EN | `1:20` | [▶️ Watch](https://www.youtube.com/shorts/Cv5jakkIseE) |
140+
141+
*For complete technical summaries, topic breakdowns, and direct studio links, see [Section 18: Video Walkthroughs & Architecture References](#18-video-walkthroughs--architecture-references-youtube).*
142+
143+
---
144+
73145
## Table of contents
74146

147+
- [Quick Navigation Map](#quick-navigation-map)
148+
- [AI-Generated Multimedia Series (YouTube)](#ai-multimedia-series)
75149
1. [Architecture](#1-architecture)
76150
2. [How portability works (orthogonal axes)](#2-how-portability-works-orthogonal-axes)
77151
3. [Deployment topology](#3-deployment-topology)
@@ -89,6 +163,7 @@ axes:
89163
15. [Operations & troubleshooting](#15-operations--troubleshooting)
90164
16. [GitOps with ArgoCD](#16-gitops-with-argocd)
91165
17. [Contributing & license](#17-contributing--license)
166+
18. [Video Walkthroughs & Architecture References (YouTube)](#18-video-walkthroughs--architecture-references-youtube)
92167

93168
---
94169

@@ -661,3 +736,116 @@ Licensed under the [MIT License](LICENSE).
661736

662737
> **Status:** untested on a live cluster — all validation is `helm lint` /
663738
> `helm template` / kubeconform / mermaid parsing, not runtime.
739+
740+
---
741+
742+
## 18. Video Walkthroughs & Architecture References (YouTube)
743+
744+
Architectural deep dives, video walkthroughs, and technical shorts for `traefik-keycloak-portable`, multi-distribution Kubernetes deployments, Traefik Ingress, and Keycloak SSO are hosted on the **[Nubenetes YouTube Channel (@nubenetes)](https://www.youtube.com/@nubenetes)**.
745+
746+
<details open>
747+
<summary>📂 <strong>Full-Length Technical Deep Dives (Architecture Masterclasses)</strong></summary>
748+
749+
<br/>
750+
751+
##### 1. Portable Traefik & Keycloak Helm Chart: Multi-Distro Kubernetes Architecture
752+
- 🔗 **Direct Link**: [https://www.youtube.com/watch?v=3OQhS25KbIk](https://www.youtube.com/watch?v=3OQhS25KbIk)
753+
- 🌐 **Origin Language**: English 🇺🇸 (Subtitles in 20+ languages)
754+
- ⏱️ **Duration**: 9:26
755+
- 🏷️ **Engineering Domain**: Multi-Distribution Architecture, Orthogonal Feature Flags & Helm Design
756+
- 📝 **Technical Overview**:
757+
Detailed exploration of a single, highly portable umbrella Helm chart deploying Traefik v3 and a Keycloak-protected dashboard across OpenShift, RKE2, k3s, kubeadm, and VMware Tanzu. Explains why a single core with orthogonal feature flags outperforms per-distribution forks, how `_validate.tpl` catches invalid configurations during `helm template` rendering, and how vendored subcharts enable true air-gapped deployments.
758+
- 🛠️ **Direct Links**: [Watch on YouTube](https://www.youtube.com/watch?v=3OQhS25KbIk) | [Edit in YouTube Studio](https://studio.youtube.com/video/3OQhS25KbIk/edit)
759+
760+
##### 2. Multi-Distro Kubernetes Portability: OpenShift, RKE2, K3s, Kubeadm & Tanzu
761+
- 🔗 **Direct Link**: [https://www.youtube.com/watch?v=8w0-SJw0jLo](https://www.youtube.com/watch?v=8w0-SJw0jLo)
762+
- 🌐 **Origin Language**: English 🇺🇸 (Subtitles in 20+ languages)
763+
- ⏱️ **Duration**: 9:26
764+
- 🏷️ **Engineering Domain**: Platform Engineering, Distribution Quirks & Security Hardening
765+
- 📝 **Technical Overview**:
766+
Architectural analysis of multi-distribution Kubernetes portability. Explores how platform-specific security models—specifically Red Hat OpenShift's `restricted-v2` SecurityContextConstraints rejecting hardcoded UIDs like 65532—differ from standard Kubernetes PodSecurityStandards. Demonstrates how the portable chart adapts UID allocation dynamically, configures CNI NetworkPolicies for Calico and Cilium, and eliminates environment drift.
767+
- 🛠️ **Direct Links**: [Watch on YouTube](https://www.youtube.com/watch?v=8w0-SJw0jLo) | [Edit in YouTube Studio](https://studio.youtube.com/video/8w0-SJw0jLo/edit)
768+
769+
##### 3. Traefik & Keycloak OIDC Authentication: ForwardAuth & Role RBAC Masterclass
770+
- 🔗 **Direct Link**: [https://www.youtube.com/watch?v=X4GdtkJrbZo](https://www.youtube.com/watch?v=X4GdtkJrbZo)
771+
- 🌐 **Origin Language**: English 🇺🇸 (Subtitles in 20+ languages)
772+
- ⏱️ **Duration**: 7:04
773+
- 🏷️ **Engineering Domain**: Zero-Trust Ingress, Keycloak OIDC, oauth2-proxy & ForwardAuth Middleware
774+
- 📝 **Technical Overview**:
775+
Comprehensive guide to securing the internal Traefik dashboard with OpenID Connect when Traefik OSS lacks native OIDC. Details the exact mechanics of `oauth2-proxy`, Traefik's `ForwardAuth` middleware (`/oauth2/auth`), the Traefik v3.4+ `errors` middleware status rewrite (`statusRewrites: "401": 302`), and enforcing strict role-based access control with `traefik-dashboard:traefik-admin`.
776+
- 🛠️ **Direct Links**: [Watch on YouTube](https://www.youtube.com/watch?v=X4GdtkJrbZo) | [Edit in YouTube Studio](https://studio.youtube.com/video/X4GdtkJrbZo/edit)
777+
778+
##### 4. Portable Kubernetes Networking: MetalLB, NSX ALB, Kube-Vip & Cilium LB-IPAM
779+
- 🔗 **Direct Link**: [https://www.youtube.com/watch?v=Hb4K81jiGrA](https://www.youtube.com/watch?v=Hb4K81jiGrA)
780+
- 🌐 **Origin Language**: English 🇺🇸 (Subtitles in 20+ languages)
781+
- ⏱️ **Duration**: 7:52
782+
- 🏷️ **Engineering Domain**: On-Premises Load Balancing, Ingress Networking & CNI Isolation
783+
- 📝 **Technical Overview**:
784+
Deep dive into decoupling Kubernetes ingress networking from specific cloud providers. Compares on-premises LoadBalancer backends supported by the chart: MetalLB (Layer 2 ARP and BGP pools), VMware NSX Advanced Load Balancer (Avi Vantage with AKO), kube-vip virtual IP failover, and modern eBPF-native Cilium LB-IPAM. Also reviews ingress NetworkPolicy hardening for zero-trust datacenters.
785+
- 🛠️ **Direct Links**: [Watch on YouTube](https://www.youtube.com/watch?v=Hb4K81jiGrA) | [Edit in YouTube Studio](https://studio.youtube.com/video/Hb4K81jiGrA/edit)
786+
787+
##### 5. End-to-End Portable Traefik & Keycloak: Air-Gapped GitOps Masterclass
788+
- 🔗 **Direct Link**: [https://www.youtube.com/watch?v=1AfsoppwT_w](https://www.youtube.com/watch?v=1AfsoppwT_w)
789+
- 🌐 **Origin Language**: English 🇺🇸 (Subtitles in 20+ languages)
790+
- ⏱️ **Duration**: 9:46
791+
- 🏷️ **Engineering Domain**: End-to-End Production Lifecycle, Air-Gapped GitOps & Secrets Management
792+
- 📝 **Technical Overview**:
793+
The complete production walkthrough covering Day 0 setup through Day 2 operations. Explains disconnected air-gapped image mirroring and chart vendoring, synchronizing secrets and private CA certificates from HashiCorp Vault via External Secrets Operator, declarative multi-source GitOps delivery with ArgoCD, and zero-downtime Helm upgrades.
794+
- 🛠️ **Direct Links**: [Watch on YouTube](https://www.youtube.com/watch?v=1AfsoppwT_w) | [Edit in YouTube Studio](https://studio.youtube.com/video/1AfsoppwT_w/edit)
795+
796+
</details>
797+
798+
<details open>
799+
<summary>📂 <strong>Technical Shorts Matrix & Architecture Breakdowns</strong></summary>
800+
801+
<br/>
802+
803+
### ⚡ Video Shorts Matrix
804+
805+
| # | Short Title | Architectural Domain & Focus | Audio | Duration | Action |
806+
|:---:|:---|:---|:---:|:---:|:---:|
807+
| **01** | [The Ultimate Portable Traefik & Keycloak Helm Chart](https://www.youtube.com/shorts/murHHpH8WHE) | **Unified Ingress & OIDC**<br/>Zero forks, ForwardAuth middleware, status 401 to 302 rewrite & role-gating | 🇺🇸 EN | `1:30` | [▶️ Watch](https://www.youtube.com/shorts/murHHpH8WHE) |
808+
| **02** | [How Air-Gapped Kubernetes Clusters Install Ingress](https://www.youtube.com/shorts/LGdVhOyaVaI) | **Air-Gapped Architecture**<br/>Vendored Helm dependencies & internal OCI mirrors for disconnected datacenters | 🇺🇸 EN | `1:03` | [▶️ Watch](https://www.youtube.com/shorts/LGdVhOyaVaI) |
809+
| **03** | [How External Secrets Operator Connects Vault](https://www.youtube.com/shorts/BUwUb6vpbqs) | **Zero-Trust Secret Sync**<br/>Bridging HashiCorp Vault into Kubernetes secrets without committing passwords | 🇺🇸 EN | `1:02` | [▶️ Watch](https://www.youtube.com/shorts/BUwUb6vpbqs) |
810+
| **04** | [Why OpenShift SCC Breaks Standard Pods](https://www.youtube.com/shorts/Cv5jakkIseE) | **OpenShift Hardening**<br/>restricted-v2 dynamic UID ranges vs hardcoded non-root UIDs (65532) | 🇺🇸 EN | `1:20` | [▶️ Watch](https://www.youtube.com/shorts/Cv5jakkIseE) |
811+
812+
<br/>
813+
814+
##### 1. The Ultimate Portable Traefik & Keycloak Helm Chart Explained
815+
- 🔗 **Direct Link**: [https://www.youtube.com/shorts/murHHpH8WHE](https://www.youtube.com/shorts/murHHpH8WHE)
816+
- 🌐 **Origin Language**: English 🇺🇸 (Subtitles in 20+ languages)
817+
- ⏱️ **Duration**: 1:30
818+
- 🏷️ **Engineering Domain**: Unified Ingress, OIDC Authentication & Helm Architecture
819+
- 📝 **Technical Overview**:
820+
Why managing separate Helm chart forks per distribution is an anti-pattern. Demonstrates how a single portable chart handles Traefik ingress and Keycloak dashboard protection across any Kubernetes cluster, using oauth2-proxy, ForwardAuth, status 401 to 302 redirect rewriting, and role-based gating.
821+
- 🛠️ **Direct Links**: [Watch Short](https://www.youtube.com/shorts/murHHpH8WHE) | [Edit in YouTube Studio](https://studio.youtube.com/video/murHHpH8WHE/edit)
822+
823+
##### 2. How Air-Gapped Kubernetes Clusters Install Ingress & Helm Charts
824+
- 🔗 **Direct Link**: [https://www.youtube.com/shorts/LGdVhOyaVaI](https://www.youtube.com/shorts/LGdVhOyaVaI)
825+
- 🌐 **Origin Language**: English 🇺🇸 (Subtitles in 20+ languages)
826+
- ⏱️ **Duration**: 1:03
827+
- 🏷️ **Engineering Domain**: Air-Gapped Kubernetes, Disconnected Mirroring & Offline Charts
828+
- 📝 **Technical Overview**:
829+
How to deploy ingress controllers and complex microservices in strictly isolated datacenters with zero internet egress. Explains storing vendored Helm charts in Git and redirecting image repositories to internal OCI registries.
830+
- 🛠️ **Direct Links**: [Watch Short](https://www.youtube.com/shorts/LGdVhOyaVaI) | [Edit in YouTube Studio](https://studio.youtube.com/video/LGdVhOyaVaI/edit)
831+
832+
##### 3. How External Secrets Operator Connects HashiCorp Vault to Kubernetes
833+
- 🔗 **Direct Link**: [https://www.youtube.com/shorts/BUwUb6vpbqs](https://www.youtube.com/shorts/BUwUb6vpbqs)
834+
- 🌐 **Origin Language**: English 🇺🇸 (Subtitles in 20+ languages)
835+
- ⏱️ **Duration**: 1:02
836+
- 🏷️ **Engineering Domain**: Zero-Trust Secret Management, External Secrets Operator & Vault
837+
- 📝 **Technical Overview**:
838+
Eliminating plaintext secrets from Git repositories. Shows how External Secrets Operator continuously polls HashiCorp Vault to synchronize client secrets, cookie encryption keys, and internal TLS certs into standard Kubernetes Secrets.
839+
- 🛠️ **Direct Links**: [Watch Short](https://www.youtube.com/shorts/BUwUb6vpbqs) | [Edit in YouTube Studio](https://studio.youtube.com/video/BUwUb6vpbqs/edit)
840+
841+
##### 4. Why OpenShift Security Context Constraints Break Standard Kubernetes Pods
842+
- 🔗 **Direct Link**: [https://www.youtube.com/shorts/Cv5jakkIseE](https://www.youtube.com/shorts/Cv5jakkIseE)
843+
- 🌐 **Origin Language**: English 🇺🇸 (Subtitles in 20+ languages)
844+
- ⏱️ **Duration**: 1:20
845+
- 🏷️ **Engineering Domain**: OpenShift Security, restricted-v2 SCC & Dynamic UID Ranges
846+
- 📝 **Technical Overview**:
847+
Why pods that run fine on k3s or kubeadm get blocked on Red Hat OpenShift. Explains how OpenShift's `restricted-v2` SCC allocates dynamic UIDs and why hardcoding `runAsUser: 65532` causes admission failures, plus how the portable chart adapts seamlessly.
848+
- 🛠️ **Direct Links**: [Watch Short](https://www.youtube.com/shorts/Cv5jakkIseE) | [Edit in YouTube Studio](https://studio.youtube.com/video/Cv5jakkIseE/edit)
849+
850+
</details>
851+

0 commit comments

Comments
 (0)