Files
terraform-authentik/config/permissions/akP-watchstate-admin.yaml
T
unkin-agent db5bf753b5
ci/woodpecker/pr/plan Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful
Onboard watchstate into Authentik for oauth2-proxy
watchstate is an internal media watch-state sync admin tool deployed at
watchstate.k8s.syd1.au.unkin.net behind oauth2-proxy (OIDC against
Authentik). Add the OAuth2/OIDC provider + application mirroring the
logviewer/traefik in-cluster admin pattern, gate it with the
akP-watchstate-admin permission group bound to the app, and nest that
permission into the akR-global-admin role so only the admin team can
authorize.
2026-08-25 20:11:38 +10:00

4 lines
172 B
YAML

# Permission group akP-watchstate-admin (name = filename). Grants admin
# access to watchstate: bound to the watchstate application, gating the UI.
application: watchstate