Trust internal CA for Authentik SSO; make identity.unkin.net canonical for netbox
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful

identity.unkin.net is now the canonical Authentik host. Grafana, LiteLLM and
NetBox reach it over TLS served by the internal unkin.net CA, which their images
don't trust, so OIDC/discovery failed with x509 unknown-authority. NetBox also
still pointed at the secondary admin host.

- grafana: mount the reflected vault-ca-cert and set generic_oauth tls_client_ca.
- litellm: combine-certs init builds a public+internal CA bundle; SSL_CERT_FILE
  and REQUESTS_CA_BUNDLE point at it.
- netbox: flip the OIDC issuer to identity.unkin.net; same combine-certs bundle
  for python-social-auth (requests).
- docs: record the Rancher manual runtime step (issuer + CA in the auth config).

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Signed-off-by: Ben Vincent <ben@unkin.net>
This commit is contained in:
2026-07-30 21:38:46 +10:00
parent 23c26e8cc2
commit 435057b034
6 changed files with 149 additions and 2 deletions
+1
View File
@@ -6,3 +6,4 @@ Operational notes for the manifests in this repo.
| --- | --- |
| [cnpg-backups.md](cnpg-backups.md) | How CNPG Postgres backups (WAL archiving + nightly base backups) to Ceph RGW are configured. |
| [cnpg-restore.md](cnpg-restore.md) | Restoring a CNPG cluster: full recovery, point-in-time recovery, cutover, and gotchas. |
| [authentik-rancher-sso.md](authentik-rancher-sso.md) | Manual runtime step to point Rancher's OIDC auth at the canonical `identity.unkin.net` issuer and trust the internal CA. |
+59
View File
@@ -0,0 +1,59 @@
# Rancher Authentik SSO — manual runtime step
Rancher's Authentik/OIDC login is a cluster-scoped **runtime** object
(`authconfigs.management.cattle.io`, name `keycloakoidc`). It is enabled through
Rancher's verify-auth flow (see `terraform-rancher`), not GitOps, and it is not
declaratively reconcilable without risking admin lockout — so the two fields
below must be set by hand in the Rancher UI (or API). This doc is the record of
that step; nothing in this repo applies it.
## Why this is needed
- **Canonical issuer.** Authentik is canonical at `https://identity.unkin.net`.
Rancher's OIDC issuer must be `https://identity.unkin.net/application/o/rancher/`.
- **Internal CA trust.** `identity.unkin.net` presents a cert signed by the
internal `unkin.net` CA. Rancher's Go OIDC client does not trust it out of the
box, so discovery fails with:
```
Get "https://identity.unkin.net/application/o/rancher/.well-known/openid-configuration":
x509: certificate signed by unknown authority
```
Rancher's Keycloak-OIDC auth provider has a **Certificate** field that seeds an
extra trust anchor for exactly this. Paste the `unkin.net` CA chain there.
## The step
1. Grab the CA chain (root + intermediate PEM — same bundle as the reflected
`vault-ca-cert` Secret / argocd-apps #305):
```sh
vault read -field=ca_chain pki_int/cert/ca_chain
```
2. In Rancher: **☰ → Users & Authentication → Auth Provider → Keycloak (OIDC)**
(or `PUT /v3/keycloakOIDCConfigs/keycloakoidc` via the API) and set:
| Field | Value |
| --- | --- |
| Issuer / `issuer` | `https://identity.unkin.net/application/o/rancher/` |
| Rancher URL / `rancherUrl` | `https://rancher.k8s.syd1.au.unkin.net/verify-auth` |
| Client ID | `rancher` |
| Certificate / `certificate` | *(paste the full PEM chain from step 1)* |
Leave Client Secret and the `unrestricted` access mode as configured by
`terraform-rancher`.
3. Save. Rancher re-runs discovery against `identity.unkin.net`; with the CA in
the Certificate field the `x509` error clears and a test login succeeds.
## Notes
- `terraform-rancher` (rancher2 provider, `rancher2_auth_config_keycloak_oidc`)
*can* set `issuer`/`certificate` declaratively. It does not manage the
certificate today; adding `certificate = file(...)` there and re-applying is the
recommended long-term home for this so it survives a re-provision. Until then,
this manual step is authoritative.
- The Certificate field trusts an extra CA; it does not replace Rancher's system
trust, so public TLS is unaffected.