db5bf753b5
watchstate is an internal media watch-state sync admin tool deployed at watchstate.k8s.syd1.au.unkin.net behind oauth2-proxy (OIDC against Authentik). Add the OAuth2/OIDC provider + application mirroring the logviewer/traefik in-cluster admin pattern, gate it with the akP-watchstate-admin permission group bound to the app, and nest that permission into the akR-global-admin role so only the admin team can authorize.
4 lines
172 B
YAML
4 lines
172 B
YAML
# Permission group akP-watchstate-admin (name = filename). Grants admin
|
|
# access to watchstate: bound to the watchstate application, gating the UI.
|
|
application: watchstate
|