Wire ArgoCD RBAC to Authentik ak_groups / akP-argocd-admin #263
@@ -20,6 +20,9 @@ data:
|
|||||||
- openid
|
- openid
|
||||||
- profile
|
- profile
|
||||||
- email
|
- email
|
||||||
|
# Hierarchical group claim from terraform-authentik (includes permission
|
||||||
|
# groups inherited via role groups). Read for RBAC below.
|
||||||
|
- ak_groups
|
||||||
requestedIDTokenClaims:
|
requestedIDTokenClaims:
|
||||||
groups:
|
ak_groups:
|
||||||
essential: true
|
essential: true
|
||||||
|
|||||||
@@ -5,10 +5,12 @@ metadata:
|
|||||||
name: argocd-rbac-cm
|
name: argocd-rbac-cm
|
||||||
namespace: argocd
|
namespace: argocd
|
||||||
data:
|
data:
|
||||||
# Match RBAC subjects against the `groups` claim from Authentik.
|
# Match RBAC subjects against the hierarchical `ak_groups` claim from Authentik
|
||||||
scopes: "[groups]"
|
# (carries permission groups inherited via role groups).
|
||||||
|
scopes: "[ak_groups]"
|
||||||
# Authenticated users with no matching group get read-only access.
|
# Authenticated users with no matching group get read-only access.
|
||||||
policy.default: role:readonly
|
policy.default: role:readonly
|
||||||
# Authentik group -> ArgoCD role.
|
# Authentik permission group -> ArgoCD role. akP-argocd-admin is granted to
|
||||||
|
# akR-global-admin members (and direct members) via terraform-authentik.
|
||||||
policy.csv: |
|
policy.csv: |
|
||||||
g, argocd-admins, role:admin
|
g, akP-argocd-admin, role:admin
|
||||||
|
|||||||
Reference in New Issue
Block a user