Merge pull request 'Read the vlogs client secret from the vlogs namespace path' (#41) from benvin/vlogs-namespace-move into main
ci/woodpecker/push/apply Pipeline was successful
ci/woodpecker/push/apply Pipeline was successful
Reviewed-on: #41
This commit was merged in pull request #41.
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
# OAuth2/OIDC provider + application for vlogs (the VictoriaLogs query UI,
|
||||
# served at https://vlogs.unkin.net in the logging namespace). An oauth2-proxy
|
||||
# served at https://vlogs.unkin.net in the vlogs namespace). An oauth2-proxy
|
||||
# in front of the UI performs the OIDC login; access is gated on the user's
|
||||
# hierarchical ak_groups claim (akP-vlogs-admin).
|
||||
# client_secret is read from Vault (seeded out of band), never committed.
|
||||
@@ -11,7 +11,7 @@ client_id: vlogs
|
||||
launch_url: https://vlogs.unkin.net/
|
||||
client_secret_vault:
|
||||
mount: kv
|
||||
path: kubernetes/namespace/logging/default/vlogs-oauth-credentials
|
||||
path: kubernetes/namespace/vlogs/default/oauth-credentials
|
||||
scope_mappings:
|
||||
- goauthentik.io/providers/oauth2/scope-openid
|
||||
- goauthentik.io/providers/oauth2/scope-email
|
||||
|
||||
Reference in New Issue
Block a user