d848d9ae86
Add a users/ config kind mapping a human to the akR-* roles they hold. Look accounts up with data.authentik_user; never declare them. Set authentik_group.role users only for roles a user file names, leaving every other role's membership untouched. No assignments yet.
18 lines
653 B
Markdown
18 lines
653 B
Markdown
# users
|
|
|
|
One file per human, `<username>.yaml`, listing the `akR-*` roles they hold:
|
|
|
|
```yaml
|
|
# Human user jane (username = filename). The account itself is not managed here
|
|
# (humans come from LDAP sync / invite); only its role membership is.
|
|
roles:
|
|
- akR-media-adult
|
|
```
|
|
|
|
The account is looked up by username and must already exist — nothing here
|
|
creates users. A role that has no `config/roles/<name>.yaml` fails the plan.
|
|
|
|
**Naming a role here makes Terraform authoritative over that role's entire
|
|
member list**: members added by hand in the Authentik UI for that role are
|
|
removed on the next apply. Roles no user file names are left untouched.
|