# OAuth2/OIDC provider + application for mediamark (the Go web UI for marking # media as kids content, served at https://mediamark.unkin.net (external # hostname) and https://mediamark.k8s.syd1.au.unkin.net (cluster hostname) in # its own mediamark namespace). An oauth2-proxy in front of the UI performs the # OIDC login with a relative redirect, so both hostnames must be registered; # access is gated on the user's hierarchical ak_groups claim # (akP-mediamark-user). # client_secret is read from Vault (seeded out of band), never committed. name: mediamark authorization_flow: default-provider-authorization-implicit-consent invalidation_flow: default-provider-invalidation-flow client_type: confidential client_id: mediamark launch_url: https://mediamark.unkin.net/ client_secret_vault: mount: kv path: kubernetes/namespace/mediamark/default/oauth-credentials scope_mappings: - goauthentik.io/providers/oauth2/scope-openid - goauthentik.io/providers/oauth2/scope-email - goauthentik.io/providers/oauth2/scope-profile redirect_uris: - matching_mode: strict url: https://mediamark.k8s.syd1.au.unkin.net/oauth2/callback - matching_mode: strict url: https://mediamark.unkin.net/oauth2/callback