Files
argocd-apps/clusters/au-syd1/bootstrap/argocd-cm-patch.yaml
T
unkin-agent bbd5bdaa95 Enable PKCE for ArgoCD OIDC login (#477)
The Authentik client for ArgoCD is now public (the iOS app can't hold
a secret), so Authentik no longer enforces client_secret on token
exchange. PKCE replaces that as the protection against
authorization-code interception.

- Add `enablePKCEAuthentication: true` to the `oidc.config` block in
  `argocd-cm-patch.yaml`
- Note why PKCE is needed now that the client is public

Reviewed-on: #477
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-19 16:10:05 +10:00

45 lines
1.9 KiB
YAML

---
apiVersion: v1
kind: ConfigMap
metadata:
name: argocd-cm
namespace: argocd
data:
kustomize.buildOptions: "--enable-helm"
# Kubernetes defaults apiVersion/kind onto every StatefulSet
# volumeClaimTemplates entry, but neither the raw manifests nor the helm
# charts emit them, so live StatefulSets carry TypeMeta that git lacks.
# volumeClaimTemplates are immutable on an existing StatefulSet, so ArgoCD
# can never reconcile the removal and the resource stays perpetually
# OutOfSync. Ignore the defaulted TypeMeta fleet-wide.
resource.customizations.ignoreDifferences.apps_StatefulSet: |
jqPathExpressions:
- '.spec.volumeClaimTemplates[]?.apiVersion'
- '.spec.volumeClaimTemplates[]?.kind'
# External URL ArgoCD serves on (TLS terminated at the traefik-internal gateway).
url: https://argocd.k8s.syd1.au.unkin.net
# OIDC login via Authentik. The client secret is seeded in Vault out of band
# and surfaced as the `argocd-oidc` Secret (labelled part-of=argocd) by VSO;
# `$argocd-oidc:client_secret` resolves the key from that Secret.
oidc.config: |
name: Authentik
issuer: https://identity.unkin.net/application/o/argocd/
clientID: argocd
clientSecret: $argocd-oidc:client_secret
# The Authentik client is public (the iOS app can't hold a secret), so
# Authentik no longer enforces clientSecret; PKCE replaces it as the
# protection against authorization-code interception.
enablePKCEAuthentication: true
# identity.unkin.net now serves the LetsEncrypt *.unkin.net wildcard, so the
# stock image trust store validates it; no rootCA pin.
requestedScopes:
- openid
- profile
- email
# Hierarchical group claim from terraform-authentik (includes permission
# groups inherited via role groups). Read for RBAC below.
- ak_groups
requestedIDTokenClaims:
ak_groups:
essential: true