Register the k8s Gitea forge as an Authentik OIDC app so it can use SSO at
cutover. Redirect URIs cover both the temporary git2 validation host and the
final git.unkin.net host so login works across the migration.
- add config/providers_oauth2/gitea.yaml (confidential OAuth2 provider + app,
client_secret read from kv/kubernetes/namespace/gitea/default/oauth-credentials)
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
NetBox is being deployed to k8s (argocd-apps) with Authentik SSO via
python-social-auth's OpenIdConnectAuth backend. Add the confidential OAuth2
provider/application (client_id netbox, openid/email/profile scopes, strict
redirect to /oauth/complete/oidc/); the client_secret is read from Vault at
kubernetes/namespace/netbox/default/oauth-credentials (the terraform-authentik
runner policy already covers namespace/+/default/oauth-credentials).
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Bring LiteLLM into the two-tier RBAC and map groups to LiteLLM roles.
- akP-litellm-admin / akP-litellm-user permission groups (bound to the litellm
app for access); added to akR-global-admin / akR-standard-user roles.
- Generic per-provider role_mappings: emit an app role claim computed from
effective (hierarchical) group membership. LiteLLM: emits `litellm_role`
(proxy_admin for akP-litellm-admin, internal_user for akP-litellm-user, else
internal_user_view_only); LiteLLM reads it via GENERIC_USER_ROLE_ATTRIBUTE.
Validated: plan 5 to add, 3 to change; generated role expression renders correctly.
Ceph dashboard SSO is SAML 2.0 (no native OIDC), so onboard it via an Authentik
SAML provider + application. Also resolve SAML authorization/invalidation flows
by slug and the signing keypair by name (mirrors the oauth2 handling), since the
SAML path had not been exercised before.
- config/providers_saml/ceph.yaml: SP entity id/ACS derived from the dashboard
base URL (audience .../auth/saml2/metadata, acs .../auth/saml2, HTTP-POST),
signed with the built-in self-signed keypair.
Ceph side (separate, Puppet): ceph dashboard sso setup saml2
https://dashboard.ceph.unkin.net <authentik-idp-metadata-url>
Validated with `terragrunt plan`: 2 to add (provider + application).
- Permission/role group name now comes from the config filename (the map key),
dropping the redundant `name` field from each YAML and the object types.
- The hierarchical mapping emits an `ak_groups` claim (scope `ak_groups`) instead
of `groups`, so it never collides with the direct-groups the default profile
mapping already emits under `groups` (Authentik overrides same-key claims in an
unpredictable order). Apps request the `ak_groups` scope and read that claim.
Introduce a user -> role -> [permissions] model for app access and roles,
managed declaratively.
- Permission groups (akP-<app>-<access>) under config/permissions/: atomic units,
each names the application it grants access to.
- Role groups (akR-<role>) under config/roles/: what users are assigned to;
each nests permission groups via parents (akR-global-admin -> all *-admin,
akR-standard-user -> all *-user). Split into a separate authentik_group
resource so roles can reference permission ids without self-reference.
- Policy bindings gate each application to its permission groups (and, via
child->parent membership propagation, the roles that nest them).
- Hierarchical `groups` scope mapping: walks user groups up through .parents so
the OIDC claim includes inherited permission groups (works around
goauthentik/authentik#15579). Inert until a provider requests the `groups`
scope, so no behaviour change to existing apps until they opt in.
Validated with `tofu validate`.
Extends Authentik SSO to ArgoCD so cluster operators log in with their
Authentik identity and group membership instead of the local admin account.
- Add config/providers_oauth2/argocd.yaml: confidential OAuth2 provider +
application (slug argocd), client_id argocd, openid/email/profile scopes,
web SSO and CLI (localhost:8085) redirect URIs. client_secret is read from
Vault at kv/kubernetes/namespace/argocd/default/oauth-credentials, matching
the existing Grafana pattern.
Adds an OIDC provider + application so the in-cluster Grafana
(grafana.k8s.syd1.au.unkin.net) can authenticate users against Authentik.
Extends the oauth2 module so provider config stays declarative and
secret-free:
- Resolve authorization/invalidation flows by slug (data.authentik_flow)
and scope mappings by managed identifier
(data.authentik_property_mapping_provider_scope).
- Read client_secret from Vault kv-v2 (data.vault_kv_secret_v2) instead of
committing it; adds the hashicorp/vault provider (auth via VAULT_ADDR/
VAULT_TOKEN from the Makefile).
- Support allowed_redirect_uris on the oauth2 provider.
config/providers_oauth2/grafana.yaml wires client_id `grafana`, the
openid/email/profile scopes, the login/generic_oauth redirect URI, and
points client_secret at kv/kubernetes/namespace/grafana/default/oauth-credentials.
- Terraform module for groups, SAML/OAuth2/LDAP providers, applications, and LDAP outposts
- Data-driven YAML config with Terragrunt config loader
- Environment: identity.unkin.net with Consul backend
- Provider: goauthentik/authentik 2026.5.0
- Woodpecker CI pipelines (pre-commit, plan, apply)
- Makefile with Vault AppRole and K8s auth support