# Rancher Authentik SSO — manual runtime step Rancher's Authentik/OIDC login is a cluster-scoped **runtime** object (`authconfigs.management.cattle.io`, name `keycloakoidc`). It is enabled through Rancher's verify-auth flow (see `terraform-rancher`), not GitOps, and it is not declaratively reconcilable without risking admin lockout — so the two fields below must be set by hand in the Rancher UI (or API). This doc is the record of that step; nothing in this repo applies it. ## Why this is needed - **Canonical issuer.** Authentik is canonical at `https://identity.unkin.net`. Rancher's OIDC issuer must be `https://identity.unkin.net/application/o/rancher/`. - **Internal CA trust.** `identity.unkin.net` presents a cert signed by the internal `unkin.net` CA. Rancher's Go OIDC client does not trust it out of the box, so discovery fails with: ``` Get "https://identity.unkin.net/application/o/rancher/.well-known/openid-configuration": x509: certificate signed by unknown authority ``` Rancher's Keycloak-OIDC auth provider has a **Certificate** field that seeds an extra trust anchor for exactly this. Paste the `unkin.net` CA chain there. ## The step 1. Grab the CA chain (root + intermediate PEM — same bundle as the reflected `vault-ca-cert` Secret / argocd-apps #305): ```sh vault read -field=ca_chain pki_int/cert/ca_chain ``` 2. In Rancher: **☰ → Users & Authentication → Auth Provider → Keycloak (OIDC)** (or `PUT /v3/keycloakOIDCConfigs/keycloakoidc` via the API) and set: | Field | Value | | --- | --- | | Issuer / `issuer` | `https://identity.unkin.net/application/o/rancher/` | | Rancher URL / `rancherUrl` | `https://rancher.k8s.syd1.au.unkin.net/verify-auth` | | Client ID | `rancher` | | Certificate / `certificate` | *(paste the full PEM chain from step 1)* | Leave Client Secret and the `unrestricted` access mode as configured by `terraform-rancher`. 3. Save. Rancher re-runs discovery against `identity.unkin.net`; with the CA in the Certificate field the `x509` error clears and a test login succeeds. ## Notes - `terraform-rancher` (rancher2 provider, `rancher2_auth_config_keycloak_oidc`) *can* set `issuer`/`certificate` declaratively. It does not manage the certificate today; adding `certificate = file(...)` there and re-applying is the recommended long-term home for this so it survives a re-provision. Until then, this manual step is authoritative. - The Certificate field trusts an extra CA; it does not replace Rancher's system trust, so public TLS is unaffected.