From bbd5bdaa95d264e7526d72a383d5d5b64564e2f6 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sat, 19 Sep 2026 16:10:05 +1000 Subject: [PATCH] Enable PKCE for ArgoCD OIDC login (#477) The Authentik client for ArgoCD is now public (the iOS app can't hold a secret), so Authentik no longer enforces client_secret on token exchange. PKCE replaces that as the protection against authorization-code interception. - Add `enablePKCEAuthentication: true` to the `oidc.config` block in `argocd-cm-patch.yaml` - Note why PKCE is needed now that the client is public Reviewed-on: https://git.unkin.net/unkin/argocd-apps/pulls/477 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- clusters/au-syd1/bootstrap/argocd-cm-patch.yaml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/clusters/au-syd1/bootstrap/argocd-cm-patch.yaml b/clusters/au-syd1/bootstrap/argocd-cm-patch.yaml index fe2f258..cfc7dc8 100644 --- a/clusters/au-syd1/bootstrap/argocd-cm-patch.yaml +++ b/clusters/au-syd1/bootstrap/argocd-cm-patch.yaml @@ -26,6 +26,10 @@ data: issuer: https://identity.unkin.net/application/o/argocd/ clientID: argocd clientSecret: $argocd-oidc:client_secret + # The Authentik client is public (the iOS app can't hold a secret), so + # Authentik no longer enforces clientSecret; PKCE replaces it as the + # protection against authorization-code interception. + enablePKCEAuthentication: true # identity.unkin.net now serves the LetsEncrypt *.unkin.net wildcard, so the # stock image trust store validates it; no rootCA pin. requestedScopes: