Files
terraform-authentik/README.md
T
unkin-agent d848d9ae86
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/plan Pipeline failed
Manage human role membership from config/users/
Add a users/ config kind mapping a human to the akR-* roles they hold.
Look accounts up with data.authentik_user; never declare them. Set
authentik_group.role users only for roles a user file names, leaving
every other role's membership untouched. No assignments yet.
2026-09-19 12:46:58 +10:00

40 lines
1.4 KiB
Markdown

# terraform-authentik
Terraform configuration for managing the Authentik identity provider at identity.unkin.net.
## Managed Resources
- **Groups** — roles and group hierarchy (accounts themselves are created elsewhere)
- **User role membership** — which `akR-*` roles a human holds (see `config/users/`)
- **SAML providers** — SAML application integrations
- **OAuth2/OIDC providers** — OAuth2 and OpenID Connect integrations
- **LDAP providers** — LDAP provider and outpost configuration
- **Applications** — application definitions linked to providers
- **Service accounts** — machine identities with RBAC roles and API tokens (keys published to Vault kv)
## Configuration
Resources are defined as YAML files under `config/`:
```
config/
├── groups/ # Group definitions
├── providers_saml/ # SAML provider definitions
├── providers_oauth2/ # OAuth2/OIDC provider definitions
├── providers_ldap/ # LDAP provider definitions
├── service_accounts/ # Automation service accounts + API tokens
└── users/ # Human role membership (authoritative per named role)
```
## Usage
```sh
make plan # init + plan
make apply # init + plan + apply
make format # format all .tf and .hcl files
```
### Authentication
Set `VAULT_ROLEID` for local AppRole auth, or `VAULT_AUTH_METHOD=kubernetes` for CI.