bbd5bdaa95
The Authentik client for ArgoCD is now public (the iOS app can't hold a secret), so Authentik no longer enforces client_secret on token exchange. PKCE replaces that as the protection against authorization-code interception. - Add `enablePKCEAuthentication: true` to the `oidc.config` block in `argocd-cm-patch.yaml` - Note why PKCE is needed now that the client is public Reviewed-on: #477 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
45 lines
1.9 KiB
YAML
45 lines
1.9 KiB
YAML
---
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: argocd-cm
|
|
namespace: argocd
|
|
data:
|
|
kustomize.buildOptions: "--enable-helm"
|
|
# Kubernetes defaults apiVersion/kind onto every StatefulSet
|
|
# volumeClaimTemplates entry, but neither the raw manifests nor the helm
|
|
# charts emit them, so live StatefulSets carry TypeMeta that git lacks.
|
|
# volumeClaimTemplates are immutable on an existing StatefulSet, so ArgoCD
|
|
# can never reconcile the removal and the resource stays perpetually
|
|
# OutOfSync. Ignore the defaulted TypeMeta fleet-wide.
|
|
resource.customizations.ignoreDifferences.apps_StatefulSet: |
|
|
jqPathExpressions:
|
|
- '.spec.volumeClaimTemplates[]?.apiVersion'
|
|
- '.spec.volumeClaimTemplates[]?.kind'
|
|
# External URL ArgoCD serves on (TLS terminated at the traefik-internal gateway).
|
|
url: https://argocd.k8s.syd1.au.unkin.net
|
|
# OIDC login via Authentik. The client secret is seeded in Vault out of band
|
|
# and surfaced as the `argocd-oidc` Secret (labelled part-of=argocd) by VSO;
|
|
# `$argocd-oidc:client_secret` resolves the key from that Secret.
|
|
oidc.config: |
|
|
name: Authentik
|
|
issuer: https://identity.unkin.net/application/o/argocd/
|
|
clientID: argocd
|
|
clientSecret: $argocd-oidc:client_secret
|
|
# The Authentik client is public (the iOS app can't hold a secret), so
|
|
# Authentik no longer enforces clientSecret; PKCE replaces it as the
|
|
# protection against authorization-code interception.
|
|
enablePKCEAuthentication: true
|
|
# identity.unkin.net now serves the LetsEncrypt *.unkin.net wildcard, so the
|
|
# stock image trust store validates it; no rootCA pin.
|
|
requestedScopes:
|
|
- openid
|
|
- profile
|
|
- email
|
|
# Hierarchical group claim from terraform-authentik (includes permission
|
|
# groups inherited via role groups). Read for RBAC below.
|
|
- ak_groups
|
|
requestedIDTokenClaims:
|
|
ak_groups:
|
|
essential: true
|