The traefik dashboards (internal + external ingress classes) are being
exposed behind oauth2-proxy; this adds the Authentik side as the
prerequisite.
- Adds config/providers_oauth2/traefik.yaml mirroring arrstack: confidential
client, client_id traefik, secret from Vault kv
kubernetes/namespace/traefik-system/default/oauth-credentials,
openid/email/profile scopes (ak_groups is attached to every oauth2
provider by the module), strict redirect URIs for
traefik-internal/traefik-external oauth2 callbacks.
- Adds config/permissions/akP-traefik-admin.yaml bound to the traefik
application and nests it under akR-global-admin.
Add the Authentik OIDC application that fronts the arrproxy media front door
at arrstack.unkin.net, plus the per-app entitlement groups arrproxy reads from
the user's groups claim to decide which backends (sonarr/radarr/prowlarr) a
user may reach.
- config/providers_oauth2/arrstack.yaml: confidential oauth2 client
client_id=arrstack, litellm-style auth/invalidation flows, client_secret
from Vault kv kubernetes/namespace/arrstack/default/oauth-credentials,
openid/email/profile scopes, redirect https://arrstack.unkin.net/oauth2/callback,
launch https://arrstack.unkin.net/. The module always attaches the estate's
hierarchical ak_groups scope mapping, so the front door emits the groups claim.
- config/permissions/akP-arrstack-user.yaml: front-door gate (application: arrstack).
- config/permissions/akP-arrstack-{sonarr,radarr,prowlarr}.yaml: per-app
entitlements, unbound (no application) so they only surface in the ak_groups
claim for arrproxy to authorize backends.
- config/roles/akR-arrstack-user.yaml: full media role nesting all four.
- akR-global-admin: also nests the arrstack front door + all per-app perms.
Ben (akR-global-admin) does not see the LiteLLM tile on the Authentik user
dashboard, while ArgoCD/Grafana/Rancher appear normally. The live API shows
LiteLLM is configured identically to those apps: the app exists, its access
binding akP-litellm-admin -> litellm is present, and akR-global-admin nests
akP-litellm-admin (bidirectionally, same as the others). A CI-style plan against
live state reports "No changes" -- so this is not terraform-correctable drift,
and a plain re-apply fixes nothing. Yet check_access for Ben returns
passing=false for litellm and passing=true for the rest: a stale cached access
policy result inside Authentik.
Add an optional per-app launch_url to the providers_oauth2 config (default null,
which keeps Authentik's redirect-derived URL) and wire it to the application's
meta_launch_url. Set it for LiteLLM to its UI. This makes the dashboard tile
deterministic and, on apply, re-saves the application -- invalidating the stale
access-policy cache so Ben's (already-correct) access re-evaluates and the tile
appears.
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
OAuth2 providers with no signing_key fall back to HS256, which RS256-only
RP clients (argocd confirmed, and the rest) reject with "unexpected
signature algorithm HS256; expected [RS256]", breaking OIDC login.
- Add data.authentik_certificate_key_pair.signing, resolving the estate's
RSA keypair by name (var.oauth2_signing_key_name, default the built-in
"authentik Self-signed Certificate").
- Default every provider's signing_key to that keypair via coalesce, so all
providers sign with RS256 while keeping the per-yaml signing_key override.
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
The k8s Gitea drops SSH and serves git.unkin.net (canonical) plus
git.k8s.syd1.au.unkin.net (admin/backup route, live now via external-dns).
Replace the old git2 validation host in the OAuth2 redirect URIs to match
argocd-apps#309.
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Register the k8s Gitea forge as an Authentik OIDC app so it can use SSO at
cutover. Redirect URIs cover both the temporary git2 validation host and the
final git.unkin.net host so login works across the migration.
- add config/providers_oauth2/gitea.yaml (confidential OAuth2 provider + app,
client_secret read from kv/kubernetes/namespace/gitea/default/oauth-credentials)
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
## Why
All Authentik OIDC logins (ArgoCD, Grafana, Rancher, LiteLLM, NetBox) fail
with `invalid_request` / "The request is otherwise malformed". Authentik
2026.5 added an explicit `grant_types` allow-list to the OAuth2 provider
(model default = empty list). Our module never set it, so every provider has
`grant_types = []`, and `authorize.py` rejects the authorization_code grant
(`if self.grant_type not in self.provider.grant_types`) before any user auth.
## Change
- modules/authentik: add a `grant_types` field to the `providers_oauth2`
variable, defaulting to `["authorization_code", "refresh_token"]` (the
standard confidential web-app set), and wire it into
`authentik_provider_oauth2`.
## Plan
`0 to add, 5 to change, 0 to destroy` — each existing oauth2 provider's
`grant_types` goes `[] -> ["authorization_code", "refresh_token"]`; no other
attributes change. Baseline plan (pre-change) was clean (no netbox/state drift).
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
NetBox is being deployed to k8s (argocd-apps) with Authentik SSO via
python-social-auth's OpenIdConnectAuth backend. Add the confidential OAuth2
provider/application (client_id netbox, openid/email/profile scopes, strict
redirect to /oauth/complete/oidc/); the client_secret is read from Vault at
kubernetes/namespace/netbox/default/oauth-credentials (the terraform-authentik
runner policy already covers namespace/+/default/oauth-credentials).
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Bring LiteLLM into the two-tier RBAC and map groups to LiteLLM roles.
- akP-litellm-admin / akP-litellm-user permission groups (bound to the litellm
app for access); added to akR-global-admin / akR-standard-user roles.
- Generic per-provider role_mappings: emit an app role claim computed from
effective (hierarchical) group membership. LiteLLM: emits `litellm_role`
(proxy_admin for akP-litellm-admin, internal_user for akP-litellm-user, else
internal_user_view_only); LiteLLM reads it via GENERIC_USER_ROLE_ATTRIBUTE.
Validated: plan 5 to add, 3 to change; generated role expression renders correctly.
Ceph dashboard SSO is SAML 2.0 (no native OIDC), so onboard it via an Authentik
SAML provider + application. Also resolve SAML authorization/invalidation flows
by slug and the signing keypair by name (mirrors the oauth2 handling), since the
SAML path had not been exercised before.
- config/providers_saml/ceph.yaml: SP entity id/ACS derived from the dashboard
base URL (audience .../auth/saml2/metadata, acs .../auth/saml2, HTTP-POST),
signed with the built-in self-signed keypair.
Ceph side (separate, Puppet): ceph dashboard sso setup saml2
https://dashboard.ceph.unkin.net <authentik-idp-metadata-url>
Validated with `terragrunt plan`: 2 to add (provider + application).
- Permission/role group name now comes from the config filename (the map key),
dropping the redundant `name` field from each YAML and the object types.
- The hierarchical mapping emits an `ak_groups` claim (scope `ak_groups`) instead
of `groups`, so it never collides with the direct-groups the default profile
mapping already emits under `groups` (Authentik overrides same-key claims in an
unpredictable order). Apps request the `ak_groups` scope and read that claim.
Introduce a user -> role -> [permissions] model for app access and roles,
managed declaratively.
- Permission groups (akP-<app>-<access>) under config/permissions/: atomic units,
each names the application it grants access to.
- Role groups (akR-<role>) under config/roles/: what users are assigned to;
each nests permission groups via parents (akR-global-admin -> all *-admin,
akR-standard-user -> all *-user). Split into a separate authentik_group
resource so roles can reference permission ids without self-reference.
- Policy bindings gate each application to its permission groups (and, via
child->parent membership propagation, the roles that nest them).
- Hierarchical `groups` scope mapping: walks user groups up through .parents so
the OIDC claim includes inherited permission groups (works around
goauthentik/authentik#15579). Inert until a provider requests the `groups`
scope, so no behaviour change to existing apps until they opt in.
Validated with `tofu validate`.
Extends Authentik SSO to ArgoCD so cluster operators log in with their
Authentik identity and group membership instead of the local admin account.
- Add config/providers_oauth2/argocd.yaml: confidential OAuth2 provider +
application (slug argocd), client_id argocd, openid/email/profile scopes,
web SSO and CLI (localhost:8085) redirect URIs. client_secret is read from
Vault at kv/kubernetes/namespace/argocd/default/oauth-credentials, matching
the existing Grafana pattern.
authentik_provider_oauth2.allowed_redirect_uris is list(map(string)) and the
API always stores a redirect_uri_type key on each entry. The module only set
matching_mode and url, so every plan showed the Grafana provider being updated
in-place (state map had 3 keys, config map had 2) and never converged.
Add redirect_uri_type to the redirect_uris object, defaulting to
"authorization". `terragrunt plan` now reports no changes.
Adding the first managed group (argocd-admins) exposed a dormant bug: the
groups resource resolved `parents` by indexing authentik_group.this itself,
which OpenTofu rejects as a self-referential block. config/groups/ had been
empty, so `tofu plan` never hit it before.
Pass `parents` through as literal group PKs instead (the resource cannot
reference itself, so parent-by-map-key was never viable). Plan is clean:
3 to add (argocd provider, application, argocd-admins group).
The CI VAULT_TOKEN (short-lived k8s-auth role token) can't create child
tokens, so the vault provider failed with 'failed to create limited child
token: permission denied'. Use the token directly.
The authentik provider needs a token but nothing supplied it, so plan
failed with 'No value for required variable authentik_token'. Source it
from Vault in vault_env like the consul creds, from the dedicated
terraform-service path kv/service/terraform/authentik (field: token),
overridable via AUTHENTIK_TOKEN_KV_* vars.
The module's versions.tf and the root.hcl-generated backend.tf both
declared required_providers, which OpenTofu rejects ("A module may have
only one required providers configuration"), so terragrunt init/plan
failed. Keep them in the module's versions.tf (authentik + vault) and
generate only the backend + provider blocks.
Adds an OIDC provider + application so the in-cluster Grafana
(grafana.k8s.syd1.au.unkin.net) can authenticate users against Authentik.
Extends the oauth2 module so provider config stays declarative and
secret-free:
- Resolve authorization/invalidation flows by slug (data.authentik_flow)
and scope mappings by managed identifier
(data.authentik_property_mapping_provider_scope).
- Read client_secret from Vault kv-v2 (data.vault_kv_secret_v2) instead of
committing it; adds the hashicorp/vault provider (auth via VAULT_ADDR/
VAULT_TOKEN from the Makefile).
- Support allowed_redirect_uris on the oauth2 provider.
config/providers_oauth2/grafana.yaml wires client_id `grafana`, the
openid/email/profile scopes, the login/generic_oauth redirect URI, and
points client_secret at kv/kubernetes/namespace/grafana/default/oauth-credentials.
- Terraform module for groups, SAML/OAuth2/LDAP providers, applications, and LDAP outposts
- Data-driven YAML config with Terragrunt config loader
- Environment: identity.unkin.net with Consul backend
- Provider: goauthentik/authentik 2026.5.0
- Woodpecker CI pipelines (pre-commit, plan, apply)
- Makefile with Vault AppRole and K8s auth support