3396b399ce3a4e7c003237a3a5f5ecc0747db12b
Completes the Authentik-side plumbing for Jellyfin SSO across both media instances -- fafflix (adults, jellyfin.k8s.syd1.au.unkin.net) and cheeztv (kids, cheeztv.unkin.net + cheeztv.k8s.syd1.au.unkin.net) -- and adds an LDAP outpost so native clients can authenticate with app passwords. Why: the previously-merged jellyfin OIDC provider only covered the fafflix host and gated on the generic jellyfin permission groups. cheeztv needs SSO too, access should be limited to media users, and native (non-browser) clients need a password-based path. How: - providers_oauth2/jellyfin.yaml: one shared confidential client now lists strict redirect URIs for all three hosts using the verified jellyfin-plugin-sso callback path /sso/OID/redirect/authentik. Client secret moved to kv kubernetes/namespace/fafflix/default/oauth-credentials. - Access is gated to media users only: akP-media-fafflix and akP-media-cheeztv now carry `application: jellyfin` and bind to the app; akP-jellyfin-admin / akP-jellyfin-user are demoted to pure role-claim groups (no app binding), still mapped by the plugin for admin/user rights. Per-instance authz (adults -> both, kids -> cheeztv only) stays with the media proxy. - providers_ldap/jellyfin-ldap.yaml: new LDAP provider (base_dn DC=ldap,DC=goauthentik,DC=io, direct bind/search) + application (jellyfin-ldap) + outpost (jellyfin-ldap-outpost) via the existing module. - modules/authentik/main.tf: resolve LDAP bind/unbind flow slugs to ids via data.authentik_flow, matching the oauth2/saml convention.
terraform-authentik
Terraform configuration for managing the Authentik identity provider at identity.unkin.net.
Managed Resources
- Groups — roles and group hierarchy (users are invited manually)
- SAML providers — SAML application integrations
- OAuth2/OIDC providers — OAuth2 and OpenID Connect integrations
- LDAP providers — LDAP provider and outpost configuration
- Applications — application definitions linked to providers
Configuration
Resources are defined as YAML files under config/:
config/
├── groups/ # Group definitions
├── providers_saml/ # SAML provider definitions
├── providers_oauth2/ # OAuth2/OIDC provider definitions
└── providers_ldap/ # LDAP provider definitions
Usage
make plan # init + plan
make apply # init + plan + apply
make format # format all .tf and .hcl files
Authentication
Set VAULT_ROLEID for local AppRole auth, or VAULT_AUTH_METHOD=kubernetes for CI.
Description
Languages
HCL
94.3%
Makefile
5.7%