Files
argocd-apps/docs/authentik-rancher-sso.md
T
unkinben 435057b034
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
Trust internal CA for Authentik SSO; make identity.unkin.net canonical for netbox
identity.unkin.net is now the canonical Authentik host. Grafana, LiteLLM and
NetBox reach it over TLS served by the internal unkin.net CA, which their images
don't trust, so OIDC/discovery failed with x509 unknown-authority. NetBox also
still pointed at the secondary admin host.

- grafana: mount the reflected vault-ca-cert and set generic_oauth tls_client_ca.
- litellm: combine-certs init builds a public+internal CA bundle; SSL_CERT_FILE
  and REQUESTS_CA_BUNDLE point at it.
- netbox: flip the OIDC issuer to identity.unkin.net; same combine-certs bundle
  for python-social-auth (requests).
- docs: record the Rancher manual runtime step (issuer + CA in the auth config).

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Signed-off-by: Ben Vincent <ben@unkin.net>
2026-07-30 21:38:46 +10:00

2.5 KiB

Rancher Authentik SSO — manual runtime step

Rancher's Authentik/OIDC login is a cluster-scoped runtime object (authconfigs.management.cattle.io, name keycloakoidc). It is enabled through Rancher's verify-auth flow (see terraform-rancher), not GitOps, and it is not declaratively reconcilable without risking admin lockout — so the two fields below must be set by hand in the Rancher UI (or API). This doc is the record of that step; nothing in this repo applies it.

Why this is needed

  • Canonical issuer. Authentik is canonical at https://identity.unkin.net. Rancher's OIDC issuer must be https://identity.unkin.net/application/o/rancher/.

  • Internal CA trust. identity.unkin.net presents a cert signed by the internal unkin.net CA. Rancher's Go OIDC client does not trust it out of the box, so discovery fails with:

    Get "https://identity.unkin.net/application/o/rancher/.well-known/openid-configuration":
    x509: certificate signed by unknown authority
    

    Rancher's Keycloak-OIDC auth provider has a Certificate field that seeds an extra trust anchor for exactly this. Paste the unkin.net CA chain there.

The step

  1. Grab the CA chain (root + intermediate PEM — same bundle as the reflected vault-ca-cert Secret / argocd-apps #305):

    vault read -field=ca_chain pki_int/cert/ca_chain
    
  2. In Rancher: ☰ → Users & Authentication → Auth Provider → Keycloak (OIDC) (or PUT /v3/keycloakOIDCConfigs/keycloakoidc via the API) and set:

    Field Value
    Issuer / issuer https://identity.unkin.net/application/o/rancher/
    Rancher URL / rancherUrl https://rancher.k8s.syd1.au.unkin.net/verify-auth
    Client ID rancher
    Certificate / certificate (paste the full PEM chain from step 1)

    Leave Client Secret and the unrestricted access mode as configured by terraform-rancher.

  3. Save. Rancher re-runs discovery against identity.unkin.net; with the CA in the Certificate field the x509 error clears and a test login succeeds.

Notes

  • terraform-rancher (rancher2 provider, rancher2_auth_config_keycloak_oidc) can set issuer/certificate declaratively. It does not manage the certificate today; adding certificate = file(...) there and re-applying is the recommended long-term home for this so it survives a re-provision. Until then, this manual step is authoritative.
  • The Certificate field trusts an extra CA; it does not replace Rancher's system trust, so public TLS is unaffected.