# OAuth2/OIDC provider + application for repospawner (the internal repository # provisioning admin tool, served at # https://repospawner.k8s.syd1.au.unkin.net (cluster hostname) and # https://repospawner.unkin.net (external hostname) in the repospawner namespace). # An oauth2-proxy in front of the UI performs the OIDC login; access is gated on # the user's hierarchical ak_groups claim (akP-repospawner-admin). # client_secret is read from Vault (seeded out of band), never committed. name: repospawner authorization_flow: default-provider-authorization-implicit-consent invalidation_flow: default-provider-invalidation-flow client_type: confidential client_id: repospawner launch_url: https://repospawner.unkin.net/ client_secret_vault: mount: kv path: kubernetes/namespace/repospawner/default/oauth-credentials scope_mappings: - goauthentik.io/providers/oauth2/scope-openid - goauthentik.io/providers/oauth2/scope-email - goauthentik.io/providers/oauth2/scope-profile redirect_uris: - matching_mode: strict url: https://repospawner.k8s.syd1.au.unkin.net/oauth2/callback - matching_mode: strict url: https://repospawner.unkin.net/oauth2/callback