405dede578
The ArgoCD mobile app and CLI are native clients that cannot hold a secret, and Authentik derives the iss claim from the application slug, so they cannot have a client of their own either. Serve all three clients from the one provider. - switch client_type to public - add argocd://auth/callback as a strict redirect URI
34 lines
1.5 KiB
YAML
34 lines
1.5 KiB
YAML
# OAuth2/OIDC provider + application for the in-cluster ArgoCD
|
|
# (argocd.k8s.syd1.au.unkin.net), serving the web UI, the `argocd` CLI and the
|
|
# ArgoCD mobile app.
|
|
#
|
|
# public, not confidential: the native clients cannot hold a secret, and they
|
|
# cannot have their own client either -- Authentik derives the `iss` claim from
|
|
# the application slug, while ArgoCD validates every token against the single
|
|
# issuer in oidc.config, so a second application would issue tokens ArgoCD
|
|
# rejects. One client for all three; the strict redirect URIs below are the
|
|
# control. Authentik ignores the secret for public clients, but the Vault read
|
|
# stays so argocd-cm's `$argocd-oidc:client_secret` keeps resolving.
|
|
name: ArgoCD
|
|
authorization_flow: default-provider-authorization-implicit-consent
|
|
invalidation_flow: default-provider-invalidation-flow
|
|
client_type: public
|
|
client_id: argocd
|
|
client_secret_vault:
|
|
mount: kv
|
|
path: kubernetes/namespace/argocd/default/oauth-credentials
|
|
scope_mappings:
|
|
- goauthentik.io/providers/oauth2/scope-openid
|
|
- goauthentik.io/providers/oauth2/scope-email
|
|
- goauthentik.io/providers/oauth2/scope-profile
|
|
redirect_uris:
|
|
# Web UI SSO callback.
|
|
- matching_mode: strict
|
|
url: https://argocd.k8s.syd1.au.unkin.net/auth/callback
|
|
# `argocd login --sso` CLI callback (local listener).
|
|
- matching_mode: strict
|
|
url: http://localhost:8085/auth/callback
|
|
# Mobile app callback (custom URL scheme, PKCE).
|
|
- matching_mode: strict
|
|
url: argocd://auth/callback
|