Completes the Authentik-side plumbing for Jellyfin SSO across both media
instances -- fafflix (adults, jellyfin.k8s.syd1.au.unkin.net) and cheeztv
(kids, cheeztv.unkin.net + cheeztv.k8s.syd1.au.unkin.net) -- and adds an
LDAP outpost so native clients can authenticate with app passwords.
Why: the previously-merged jellyfin OIDC provider only covered the fafflix
host and gated on the generic jellyfin permission groups. cheeztv needs SSO
too, access should be limited to media users, and native (non-browser)
clients need a password-based path.
How:
- providers_oauth2/jellyfin.yaml: one shared confidential client now lists
strict redirect URIs for all three hosts using the verified
jellyfin-plugin-sso callback path /sso/OID/redirect/authentik. Client
secret moved to kv kubernetes/namespace/fafflix/default/oauth-credentials.
- Access is gated to media users only: akP-media-fafflix and akP-media-cheeztv
now carry `application: jellyfin` and bind to the app; akP-jellyfin-admin /
akP-jellyfin-user are demoted to pure role-claim groups (no app binding),
still mapped by the plugin for admin/user rights. Per-instance authz
(adults -> both, kids -> cheeztv only) stays with the media proxy.
- providers_ldap/jellyfin-ldap.yaml: new LDAP provider (base_dn
DC=ldap,DC=goauthentik,DC=io, direct bind/search) + application
(jellyfin-ldap) + outpost (jellyfin-ldap-outpost) via the existing module.
- modules/authentik/main.tf: resolve LDAP bind/unbind flow slugs to ids via
data.authentik_flow, matching the oauth2/saml convention.
Jellyfin moves to Authentik SSO via jellyfin-plugin-sso (OIDC), keeping
native clients on Jellyfin local/API auth. Adds the oauth2 provider and
application for jellyfin.k8s.syd1.au.unkin.net plus the akP permission
groups gating access, wired into the standard-user and global-admin
roles per the two-tier RBAC model.
- Adds providers_oauth2/jellyfin.yaml: confidential client, secret read
from kv/kubernetes/namespace/jellyfin/default/oauth-credentials,
redirect URIs for the SSO plugin callback paths
- Adds akP-jellyfin-admin and akP-jellyfin-user bound to the app
- Nests akP-jellyfin-user under akR-standard-user and
akP-jellyfin-admin under akR-global-admin