From 643c484deaad0f2dc43e42e4d2689e58dbd0f422 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Tue, 25 Aug 2026 21:42:26 +1000 Subject: [PATCH] watchstate: add external watchstate.unkin.net redirect URI watchstate is being exposed externally at watchstate.unkin.net; oauth2-proxy needs the external callback registered. --- config/providers_oauth2/watchstate.yaml | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/config/providers_oauth2/watchstate.yaml b/config/providers_oauth2/watchstate.yaml index 850372d..6b4dac4 100644 --- a/config/providers_oauth2/watchstate.yaml +++ b/config/providers_oauth2/watchstate.yaml @@ -1,7 +1,8 @@ # OAuth2/OIDC provider + application for watchstate (the internal media # watch-state sync admin tool, served at -# https://watchstate.k8s.syd1.au.unkin.net in the watchstate namespace). An -# oauth2-proxy in front of the UI performs the OIDC login; access is gated on +# https://watchstate.k8s.syd1.au.unkin.net (cluster hostname) and +# https://watchstate.unkin.net (external hostname) in the watchstate namespace). +# An oauth2-proxy in front of the UI performs the OIDC login; access is gated on # the user's hierarchical ak_groups claim (akP-watchstate-admin). # client_secret is read from Vault (seeded out of band), never committed. name: watchstate @@ -9,7 +10,7 @@ authorization_flow: default-provider-authorization-implicit-consent invalidation_flow: default-provider-invalidation-flow client_type: confidential client_id: watchstate -launch_url: https://watchstate.k8s.syd1.au.unkin.net/ +launch_url: https://watchstate.unkin.net/ client_secret_vault: mount: kv path: kubernetes/namespace/watchstate/default/oauth-credentials @@ -20,3 +21,5 @@ scope_mappings: redirect_uris: - matching_mode: strict url: https://watchstate.k8s.syd1.au.unkin.net/oauth2/callback + - matching_mode: strict + url: https://watchstate.unkin.net/oauth2/callback -- 2.47.3