Trust internal CA for Authentik SSO; canonical identity.unkin.net for NetBox #314

Merged
benvin merged 1 commits from benvin/authentik-canonical-issuer into main 2026-07-30 22:17:45 +10:00

1 Commits

Author SHA1 Message Date
unkinben 435057b034 Trust internal CA for Authentik SSO; make identity.unkin.net canonical for netbox
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
identity.unkin.net is now the canonical Authentik host. Grafana, LiteLLM and
NetBox reach it over TLS served by the internal unkin.net CA, which their images
don't trust, so OIDC/discovery failed with x509 unknown-authority. NetBox also
still pointed at the secondary admin host.

- grafana: mount the reflected vault-ca-cert and set generic_oauth tls_client_ca.
- litellm: combine-certs init builds a public+internal CA bundle; SSL_CERT_FILE
  and REQUESTS_CA_BUNDLE point at it.
- netbox: flip the OIDC issuer to identity.unkin.net; same combine-certs bundle
  for python-social-auth (requests).
- docs: record the Rancher manual runtime step (issuer + CA in the auth config).

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Signed-off-by: Ben Vincent <ben@unkin.net>
2026-07-30 21:38:46 +10:00