identity.unkin.net is now the canonical Authentik host. Grafana, LiteLLM and NetBox reach it over TLS served by the internal unkin.net CA, which their images don't trust, so OIDC/discovery failed with x509 unknown-authority. NetBox also still pointed at the secondary admin host. - grafana: mount the reflected vault-ca-cert and set generic_oauth tls_client_ca. - litellm: combine-certs init builds a public+internal CA bundle; SSL_CERT_FILE and REQUESTS_CA_BUNDLE point at it. - netbox: flip the OIDC issuer to identity.unkin.net; same combine-certs bundle for python-social-auth (requests). - docs: record the Rancher manual runtime step (issuer + CA in the auth config). Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv Signed-off-by: Ben Vincent <ben@unkin.net>
2.5 KiB
Rancher Authentik SSO — manual runtime step
Rancher's Authentik/OIDC login is a cluster-scoped runtime object
(authconfigs.management.cattle.io, name keycloakoidc). It is enabled through
Rancher's verify-auth flow (see terraform-rancher), not GitOps, and it is not
declaratively reconcilable without risking admin lockout — so the two fields
below must be set by hand in the Rancher UI (or API). This doc is the record of
that step; nothing in this repo applies it.
Why this is needed
-
Canonical issuer. Authentik is canonical at
https://identity.unkin.net. Rancher's OIDC issuer must behttps://identity.unkin.net/application/o/rancher/. -
Internal CA trust.
identity.unkin.netpresents a cert signed by the internalunkin.netCA. Rancher's Go OIDC client does not trust it out of the box, so discovery fails with:Get "https://identity.unkin.net/application/o/rancher/.well-known/openid-configuration": x509: certificate signed by unknown authorityRancher's Keycloak-OIDC auth provider has a Certificate field that seeds an extra trust anchor for exactly this. Paste the
unkin.netCA chain there.
The step
-
Grab the CA chain (root + intermediate PEM — same bundle as the reflected
vault-ca-certSecret / argocd-apps #305):vault read -field=ca_chain pki_int/cert/ca_chain -
In Rancher: ☰ → Users & Authentication → Auth Provider → Keycloak (OIDC) (or
PUT /v3/keycloakOIDCConfigs/keycloakoidcvia the API) and set:Field Value Issuer / issuerhttps://identity.unkin.net/application/o/rancher/Rancher URL / rancherUrlhttps://rancher.k8s.syd1.au.unkin.net/verify-authClient ID rancherCertificate / certificate(paste the full PEM chain from step 1) Leave Client Secret and the
unrestrictedaccess mode as configured byterraform-rancher. -
Save. Rancher re-runs discovery against
identity.unkin.net; with the CA in the Certificate field thex509error clears and a test login succeeds.
Notes
terraform-rancher(rancher2 provider,rancher2_auth_config_keycloak_oidc) can setissuer/certificatedeclaratively. It does not manage the certificate today; addingcertificate = file(...)there and re-applying is the recommended long-term home for this so it survives a re-provision. Until then, this manual step is authoritative.- The Certificate field trusts an extra CA; it does not replace Rancher's system trust, so public TLS is unaffected.