Wire LiteLLM SSO to Authentik (generic OIDC)
App-side of the LiteLLM Authentik onboarding (terraform-authentik#8). Configures LiteLLM's generic OIDC SSO against Authentik. - VaultStaticSecret oauth-credentials: surfaces the OIDC client secret (same secret Authentik sets on the provider) as a k8s Secret. - Deployment: GENERIC_CLIENT_SECRET from that Secret. - litellm-env: GENERIC_CLIENT_ID, authorization/token/userinfo endpoints, scope, and PROXY_BASE_URL (required for SSO). reloader restarts on secret/config change.
This commit is contained in:
@@ -25,5 +25,14 @@ configMapGenerator:
|
||||
- name: litellm-env
|
||||
literals:
|
||||
- STORE_MODEL_IN_DB=True
|
||||
# Authentik OIDC SSO (generic). Client secret is injected from the
|
||||
# oauth-credentials Secret in the Deployment; endpoints match the other
|
||||
# apps (identity.unkin.net). PROXY_BASE_URL is required for SSO.
|
||||
- GENERIC_CLIENT_ID=litellm
|
||||
- GENERIC_AUTHORIZATION_ENDPOINT=https://identity.unkin.net/application/o/authorize/
|
||||
- GENERIC_TOKEN_ENDPOINT=https://identity.unkin.net/application/o/token/
|
||||
- GENERIC_USERINFO_ENDPOINT=https://identity.unkin.net/application/o/userinfo/
|
||||
- GENERIC_SCOPE=openid email profile
|
||||
- PROXY_BASE_URL=https://litellm.k8s.syd1.au.unkin.net
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
|
||||
Reference in New Issue
Block a user