91080c1504
Pairs with terraform-authentik#10: request the litellm_role scope (Authentik emits the computed role claim) and read it via GENERIC_USER_ROLE_ATTRIBUTE so akP-litellm-admin -> proxy_admin, akP-litellm-user -> internal_user.
42 lines
1.4 KiB
YAML
42 lines
1.4 KiB
YAML
---
|
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
kind: Kustomization
|
|
|
|
resources:
|
|
- cnpg_cluster.yaml
|
|
- cnpg_pooler.yaml
|
|
- deployment.yaml
|
|
- hpa.yaml
|
|
- gateway.yaml
|
|
- httproute.yaml
|
|
- namespace.yaml
|
|
- redis-deployment.yaml
|
|
- redis-pvc.yaml
|
|
- services.yaml
|
|
- vaultauth.yaml
|
|
- vaultstaticsecret.yaml
|
|
|
|
configMapGenerator:
|
|
- name: litellm-config
|
|
files:
|
|
- config.yaml=resources/config.yaml
|
|
options:
|
|
disableNameSuffixHash: true
|
|
- name: litellm-env
|
|
literals:
|
|
- STORE_MODEL_IN_DB=True
|
|
# Authentik OIDC SSO (generic). Client secret is injected from the
|
|
# oauth-credentials Secret in the Deployment; endpoints match the other
|
|
# apps (identity.unkin.net). PROXY_BASE_URL is required for SSO.
|
|
- GENERIC_CLIENT_ID=litellm
|
|
- GENERIC_AUTHORIZATION_ENDPOINT=https://identity.unkin.net/application/o/authorize/
|
|
- GENERIC_TOKEN_ENDPOINT=https://identity.unkin.net/application/o/token/
|
|
- GENERIC_USERINFO_ENDPOINT=https://identity.unkin.net/application/o/userinfo/
|
|
# litellm_role scope carries the Authentik-computed role claim; LiteLLM
|
|
# reads it via GENERIC_USER_ROLE_ATTRIBUTE and maps to proxy_admin/etc.
|
|
- GENERIC_SCOPE=openid email profile litellm_role
|
|
- GENERIC_USER_ROLE_ATTRIBUTE=litellm_role
|
|
- PROXY_BASE_URL=https://litellm.k8s.syd1.au.unkin.net
|
|
options:
|
|
disableNameSuffixHash: true
|