Files
terraform-authentik/modules/authentik/main.tf
T
unkinben 8aa2273dcf
ci/woodpecker/pr/plan Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful
Fix provider schema for goauthentik/authentik 2026.5.0
- group: parent → parents (list)
- saml/oauth2: add required invalidation_flow
- oauth2: remove redirect_uris (use allowed_redirect_uris via config)
- ldap: replace authorization_flow/search_group with bind_flow/unbind_flow
- Add versions.tf with required_providers block
- Remove service_connection from outpost (auto-discovered)
2026-06-28 12:04:19 +10:00

84 lines
2.6 KiB
Terraform

resource "authentik_group" "this" {
for_each = var.groups
name = each.value.name
is_superuser = each.value.is_superuser
parents = each.value.parents != null ? [for p in each.value.parents : authentik_group.this[p].id] : []
attributes = jsonencode(each.value.attributes)
}
resource "authentik_provider_saml" "this" {
for_each = var.providers_saml
name = each.value.name
authorization_flow = each.value.authorization_flow
invalidation_flow = each.value.invalidation_flow
acs_url = each.value.acs_url
sp_binding = each.value.sp_binding
audience = each.value.audience
name_id_mapping = each.value.name_id_mapping
signing_kp = each.value.signing_kp
}
resource "authentik_provider_oauth2" "this" {
for_each = var.providers_oauth2
name = each.value.name
authorization_flow = each.value.authorization_flow
invalidation_flow = each.value.invalidation_flow
client_type = each.value.client_type
client_id = each.value.client_id
client_secret = each.value.client_secret
property_mappings = each.value.property_mappings
signing_key = each.value.signing_key
access_token_validity = each.value.access_token_validity
}
resource "authentik_provider_ldap" "this" {
for_each = var.providers_ldap
name = each.value.name
bind_flow = each.value.bind_flow
unbind_flow = each.value.unbind_flow
base_dn = each.value.base_dn
certificate = each.value.certificate
tls_server_name = each.value.tls_server_name
uid_start_number = each.value.uid_start_number
gid_start_number = each.value.gid_start_number
search_mode = each.value.search_mode
bind_mode = each.value.bind_mode
mfa_support = each.value.mfa_support
}
resource "authentik_application" "saml" {
for_each = var.providers_saml
name = each.value.name
slug = each.key
protocol_provider = authentik_provider_saml.this[each.key].id
}
resource "authentik_application" "oauth2" {
for_each = var.providers_oauth2
name = each.value.name
slug = each.key
protocol_provider = authentik_provider_oauth2.this[each.key].id
}
resource "authentik_application" "ldap" {
for_each = var.providers_ldap
name = each.value.name
slug = each.key
protocol_provider = authentik_provider_ldap.this[each.key].id
}
resource "authentik_outpost" "ldap" {
for_each = var.providers_ldap
name = "${each.key}-outpost"
type = "ldap"
protocol_providers = [authentik_provider_ldap.this[each.key].id]
}