Enable PKCE for ArgoCD OIDC login
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful

The Authentik client is now public (iOS app needs it), so Authentik
no longer enforces client_secret. PKCE replaces that as the
protection against authorization-code interception.
This commit is contained in:
2026-09-19 15:45:01 +10:00
parent 4762cf9e03
commit ee201a5c71
@@ -26,6 +26,10 @@ data:
issuer: https://identity.unkin.net/application/o/argocd/
clientID: argocd
clientSecret: $argocd-oidc:client_secret
# The Authentik client is public (the iOS app can't hold a secret), so
# Authentik no longer enforces clientSecret; PKCE replaces it as the
# protection against authorization-code interception.
enablePKCEAuthentication: true
# identity.unkin.net now serves the LetsEncrypt *.unkin.net wildcard, so the
# stock image trust store validates it; no rootCA pin.
requestedScopes: