Add Ceph dashboard SAML provider
Ceph dashboard SSO is SAML 2.0 (no native OIDC), so onboard it via an Authentik SAML provider + application. Also resolve SAML authorization/invalidation flows by slug and the signing keypair by name (mirrors the oauth2 handling), since the SAML path had not been exercised before. - config/providers_saml/ceph.yaml: SP entity id/ACS derived from the dashboard base URL (audience .../auth/saml2/metadata, acs .../auth/saml2, HTTP-POST), signed with the built-in self-signed keypair. Ceph side (separate, Puppet): ceph dashboard sso setup saml2 https://dashboard.ceph.unkin.net <authentik-idp-metadata-url> Validated with `terragrunt plan`: 2 to add (provider + application).
This commit is contained in:
@@ -52,17 +52,34 @@ resource "authentik_property_mapping_provider_scope" "groups_hierarchical" {
|
||||
EOT
|
||||
}
|
||||
|
||||
# Resolve SAML flows by slug and the signing keypair by name, so configs use
|
||||
# human-readable names instead of Authentik UUIDs (mirrors the oauth2 handling).
|
||||
data "authentik_flow" "saml_authorization" {
|
||||
for_each = var.providers_saml
|
||||
slug = each.value.authorization_flow
|
||||
}
|
||||
|
||||
data "authentik_flow" "saml_invalidation" {
|
||||
for_each = var.providers_saml
|
||||
slug = each.value.invalidation_flow
|
||||
}
|
||||
|
||||
data "authentik_certificate_key_pair" "saml_signing" {
|
||||
for_each = { for k, v in var.providers_saml : k => v if v.signing_kp != null }
|
||||
name = each.value.signing_kp
|
||||
}
|
||||
|
||||
resource "authentik_provider_saml" "this" {
|
||||
for_each = var.providers_saml
|
||||
|
||||
name = each.value.name
|
||||
authorization_flow = each.value.authorization_flow
|
||||
invalidation_flow = each.value.invalidation_flow
|
||||
authorization_flow = data.authentik_flow.saml_authorization[each.key].id
|
||||
invalidation_flow = data.authentik_flow.saml_invalidation[each.key].id
|
||||
acs_url = each.value.acs_url
|
||||
sp_binding = each.value.sp_binding
|
||||
audience = each.value.audience
|
||||
name_id_mapping = each.value.name_id_mapping
|
||||
signing_kp = each.value.signing_kp
|
||||
signing_kp = each.value.signing_kp != null ? data.authentik_certificate_key_pair.saml_signing[each.key].id : null
|
||||
}
|
||||
|
||||
# Resolve oauth2 flows by slug and scope mappings by managed identifier, and
|
||||
|
||||
Reference in New Issue
Block a user