Merge remote-tracking branch 'origin/main' into benvin/repospawner-oidc
# Conflicts: # config/roles/akR-global-admin.yaml
This commit is contained in:
@@ -0,0 +1,5 @@
|
||||
# Permission group akP-vault-admin (name = filename). Gates the OpenBao
|
||||
# application: without a binding every Authentik user could complete an OIDC
|
||||
# login, so access is restricted to this group. OpenBao's own policy mapping
|
||||
# keys off the same group name in the ak_groups claim.
|
||||
application: vault
|
||||
@@ -0,0 +1,32 @@
|
||||
# OAuth2/OIDC provider + application for OpenBao (the estate's Vault), making
|
||||
# Authentik the default *human* login. Machine auth (approle, k8s, CI) and the
|
||||
# break-glass paths are untouched and stay on the OpenBao side.
|
||||
#
|
||||
# client_secret is generated here and written to kv/service/authentik/oidc-vault
|
||||
# ({client_id, client_secret}); the companion terraform-vault change reads it to
|
||||
# configure the OIDC auth mount. Nothing is seeded by hand.
|
||||
name: OpenBao
|
||||
authorization_flow: default-provider-authorization-implicit-consent
|
||||
invalidation_flow: default-provider-invalidation-flow
|
||||
client_type: confidential
|
||||
client_id: vault
|
||||
client_secret_vault:
|
||||
mount: kv
|
||||
path: service/authentik/oidc-vault
|
||||
generate: true
|
||||
scope_mappings:
|
||||
- goauthentik.io/providers/oauth2/scope-openid
|
||||
- goauthentik.io/providers/oauth2/scope-email
|
||||
- goauthentik.io/providers/oauth2/scope-profile
|
||||
redirect_uris:
|
||||
# `bao login -method=oidc` CLI callback (local listener, fixed port 8250).
|
||||
- matching_mode: strict
|
||||
url: http://localhost:8250/oidc/callback
|
||||
# UI SSO callback, gateway host (traefik-internal -> vault svc :8200).
|
||||
- matching_mode: strict
|
||||
url: https://vault.k8s.syd1.au.unkin.net/ui/vault/auth/oidc/oidc/callback
|
||||
# UI SSO callback, direct Consul service address (the address the estate
|
||||
# documents for Vault access; any node forwards to the active replica).
|
||||
- matching_mode: strict
|
||||
url: https://vault.service.consul:8200/ui/vault/auth/oidc/oidc/callback
|
||||
launch_url: https://vault.k8s.syd1.au.unkin.net/ui/
|
||||
@@ -9,6 +9,7 @@ permissions:
|
||||
- akP-logviewer-admin
|
||||
- akP-watchstate-admin
|
||||
- akP-repospawner-admin
|
||||
- akP-vault-admin
|
||||
# arrstack has no admin tier (it is a proxy front door); grant global admins
|
||||
# the front door plus every per-app entitlement so they reach all media apps.
|
||||
- akP-arrstack-user
|
||||
|
||||
Reference in New Issue
Block a user