Authentik is canonical at https://identity.unkin.net, served by the internal unkin.net CA. Grafana, LiteLLM and NetBox failed OIDC discovery because their images don't trust that CA (x509: unknown authority); NetBox also still pointed at the secondary admin host. - grafana: mount the reflected vault-ca-cert; set generic_oauth `tls_client_ca`. - litellm: `combine-certs` init builds public+internal CA bundle; `SSL_CERT_FILE` + `REQUESTS_CA_BUNDLE` point at it. - netbox: flip OIDC issuer to identity.unkin.net; same combine bundle for python-social-auth (`requests`). - docs: record the Rancher manual runtime step (issuer + CA in the auth config). Validated: kustomize build + kubeconform + pre-commit. https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv Reviewed-on: #314 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
2.5 KiB
Rancher Authentik SSO — manual runtime step
Rancher's Authentik/OIDC login is a cluster-scoped runtime object
(authconfigs.management.cattle.io, name keycloakoidc). It is enabled through
Rancher's verify-auth flow (see terraform-rancher), not GitOps, and it is not
declaratively reconcilable without risking admin lockout — so the two fields
below must be set by hand in the Rancher UI (or API). This doc is the record of
that step; nothing in this repo applies it.
Why this is needed
-
Canonical issuer. Authentik is canonical at
https://identity.unkin.net. Rancher's OIDC issuer must behttps://identity.unkin.net/application/o/rancher/. -
Internal CA trust.
identity.unkin.netpresents a cert signed by the internalunkin.netCA. Rancher's Go OIDC client does not trust it out of the box, so discovery fails with:Get "https://identity.unkin.net/application/o/rancher/.well-known/openid-configuration": x509: certificate signed by unknown authorityRancher's Keycloak-OIDC auth provider has a Certificate field that seeds an extra trust anchor for exactly this. Paste the
unkin.netCA chain there.
The step
-
Grab the CA chain (root + intermediate PEM — same bundle as the reflected
vault-ca-certSecret / argocd-apps #305):vault read -field=ca_chain pki_int/cert/ca_chain -
In Rancher: ☰ → Users & Authentication → Auth Provider → Keycloak (OIDC) (or
PUT /v3/keycloakOIDCConfigs/keycloakoidcvia the API) and set:Field Value Issuer / issuerhttps://identity.unkin.net/application/o/rancher/Rancher URL / rancherUrlhttps://rancher.k8s.syd1.au.unkin.net/verify-authClient ID rancherCertificate / certificate(paste the full PEM chain from step 1) Leave Client Secret and the
unrestrictedaccess mode as configured byterraform-rancher. -
Save. Rancher re-runs discovery against
identity.unkin.net; with the CA in the Certificate field thex509error clears and a test login succeeds.
Notes
terraform-rancher(rancher2 provider,rancher2_auth_config_keycloak_oidc) can setissuer/certificatedeclaratively. It does not manage the certificate today; addingcertificate = file(...)there and re-applying is the recommended long-term home for this so it survives a re-provision. Until then, this manual step is authoritative.- The Certificate field trusts an extra CA; it does not replace Rancher's system trust, so public TLS is unaffected.