Add Gitea OAuth2/OIDC provider #13

Merged
benvin merged 1 commits from benvin/gitea-oidc into main 2026-07-30 21:09:05 +10:00
+25
View File
@@ -0,0 +1,25 @@
# OAuth2/OIDC provider + application for the k8s Gitea forge.
# Redirect URIs cover both the temporary validation host (git2...) and the final
# git.unkin.net cutover host, so SSO keeps working across the migration. The
# path segment "authentik" is the Gitea OAuth2 login-source name — it must match
# the source registered on the Gitea side. client_secret is read from Vault
# (seeded out of band), never committed.
name: Gitea
authorization_flow: default-provider-authorization-implicit-consent
invalidation_flow: default-provider-invalidation-flow
client_type: confidential
client_id: gitea
client_secret_vault:
mount: kv
path: kubernetes/namespace/gitea/default/oauth-credentials
scope_mappings:
- goauthentik.io/providers/oauth2/scope-openid
- goauthentik.io/providers/oauth2/scope-email
- goauthentik.io/providers/oauth2/scope-profile
redirect_uris:
# Temporary validation host.
- matching_mode: strict
url: https://git2.k8s.syd1.au.unkin.net/user/oauth2/authentik/callback
# Final host (active after DNS/cert cutover).
- matching_mode: strict
url: https://git.unkin.net/user/oauth2/authentik/callback