Update Gitea redirect URIs to canonical + admin route

SSH is dropped and the forge is served on git.unkin.net (canonical) plus
git.k8s.syd1.au.unkin.net (admin/backup); update the OAuth2 redirect URIs to
match (replacing the old git2 validation host).

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
This commit is contained in:
2026-07-31 00:02:03 +10:00
parent 0ba2785eb5
commit 13a85bc088
+4 -4
View File
@@ -17,9 +17,9 @@ scope_mappings:
- goauthentik.io/providers/oauth2/scope-email
- goauthentik.io/providers/oauth2/scope-profile
redirect_uris:
# Temporary validation host.
- matching_mode: strict
url: https://git2.k8s.syd1.au.unkin.net/user/oauth2/authentik/callback
# Final host (active after DNS/cert cutover).
# Canonical/production host (active after the git.unkin.net DNS cutover).
- matching_mode: strict
url: https://git.unkin.net/user/oauth2/authentik/callback
# Admin/backup route (live now via external-dns), used for validation too.
- matching_mode: strict
url: https://git.k8s.syd1.au.unkin.net/user/oauth2/authentik/callback