diff --git a/config/providers_oauth2/gitea.yaml b/config/providers_oauth2/gitea.yaml new file mode 100644 index 0000000..751194e --- /dev/null +++ b/config/providers_oauth2/gitea.yaml @@ -0,0 +1,25 @@ +# OAuth2/OIDC provider + application for the k8s Gitea forge. +# Redirect URIs cover both the temporary validation host (git2...) and the final +# git.unkin.net cutover host, so SSO keeps working across the migration. The +# path segment "authentik" is the Gitea OAuth2 login-source name — it must match +# the source registered on the Gitea side. client_secret is read from Vault +# (seeded out of band), never committed. +name: Gitea +authorization_flow: default-provider-authorization-implicit-consent +invalidation_flow: default-provider-invalidation-flow +client_type: confidential +client_id: gitea +client_secret_vault: + mount: kv + path: kubernetes/namespace/gitea/default/oauth-credentials +scope_mappings: + - goauthentik.io/providers/oauth2/scope-openid + - goauthentik.io/providers/oauth2/scope-email + - goauthentik.io/providers/oauth2/scope-profile +redirect_uris: + # Temporary validation host. + - matching_mode: strict + url: https://git2.k8s.syd1.au.unkin.net/user/oauth2/authentik/callback + # Final host (active after DNS/cert cutover). + - matching_mode: strict + url: https://git.unkin.net/user/oauth2/authentik/callback