Onboard repospawner UI to Authentik OIDC
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/plan Pipeline failed

Add an OAuth2/OIDC provider + application for the repospawner operator tool,
fronted by oauth2-proxy, and gate it on a new akP-repospawner-admin permission
group nested under akR-global-admin (mirrors the watchstate precedent).
This commit is contained in:
2026-08-30 15:09:47 +10:00
parent 5ecd03cdd5
commit 2f80c4a536
3 changed files with 29 additions and 0 deletions
+1
View File
@@ -8,6 +8,7 @@ permissions:
- akP-traefik-admin
- akP-logviewer-admin
- akP-watchstate-admin
- akP-repospawner-admin
# arrstack has no admin tier (it is a proxy front door); grant global admins
# the front door plus every per-app entitlement so they reach all media apps.
- akP-arrstack-user