Wire ArgoCD RBAC to Authentik ak_groups / akP-argocd-admin (#263)

## Why

Consume the two-tier Authentik RBAC from terraform-authentik#7 (user → role → permissions). ArgoCD should grant admin to the `akP-argocd-admin` permission group, which `akR-global-admin` members inherit.

## Change

- **argocd-cm**: request the hierarchical `ak_groups` scope + id-token claim (carries permission groups inherited via role groups; distinct from the default `groups` claim to avoid collision).
- **argocd-rbac-cm**: `scopes: [ak_groups]`; `policy.csv`: `g, akP-argocd-admin, role:admin` (replaces the flat `argocd-admins`). Default stays `role:readonly`.

## Depends on
terraform-authentik#7 (creates `akP-argocd-admin`, the access binding, and the `ak_groups` mapping). Merge/apply that first; then add yourself to `akR-global-admin` in Authentik.

## Validation
`kustomize build` renders the patched configmaps; pre-commit clean. Note: argocd-server picks up argocd-cm/rbac-cm live.

Reviewed-on: #263
Co-authored-by: Ben Vincent <ben@unkin.net>
Co-committed-by: Ben Vincent <ben@unkin.net>
This commit was merged in pull request #263.
This commit is contained in:
2026-07-18 16:23:58 +10:00
committed by BenVincent
parent 19f8055144
commit 9bdb328d99
2 changed files with 10 additions and 5 deletions
@@ -20,6 +20,9 @@ data:
- openid
- profile
- email
# Hierarchical group claim from terraform-authentik (includes permission
# groups inherited via role groups). Read for RBAC below.
- ak_groups
requestedIDTokenClaims:
groups:
ak_groups:
essential: true
@@ -5,10 +5,12 @@ metadata:
name: argocd-rbac-cm
namespace: argocd
data:
# Match RBAC subjects against the `groups` claim from Authentik.
scopes: "[groups]"
# Match RBAC subjects against the hierarchical `ak_groups` claim from Authentik
# (carries permission groups inherited via role groups).
scopes: "[ak_groups]"
# Authenticated users with no matching group get read-only access.
policy.default: role:readonly
# Authentik group -> ArgoCD role.
# Authentik permission group -> ArgoCD role. akP-argocd-admin is granted to
# akR-global-admin members (and direct members) via terraform-authentik.
policy.csv: |
g, argocd-admins, role:admin
g, akP-argocd-admin, role:admin