d848d9ae86
Add a users/ config kind mapping a human to the akR-* roles they hold. Look accounts up with data.authentik_user; never declare them. Set authentik_group.role users only for roles a user file names, leaving every other role's membership untouched. No assignments yet.
40 lines
1.4 KiB
Markdown
40 lines
1.4 KiB
Markdown
# terraform-authentik
|
|
|
|
Terraform configuration for managing the Authentik identity provider at identity.unkin.net.
|
|
|
|
## Managed Resources
|
|
|
|
- **Groups** — roles and group hierarchy (accounts themselves are created elsewhere)
|
|
- **User role membership** — which `akR-*` roles a human holds (see `config/users/`)
|
|
- **SAML providers** — SAML application integrations
|
|
- **OAuth2/OIDC providers** — OAuth2 and OpenID Connect integrations
|
|
- **LDAP providers** — LDAP provider and outpost configuration
|
|
- **Applications** — application definitions linked to providers
|
|
- **Service accounts** — machine identities with RBAC roles and API tokens (keys published to Vault kv)
|
|
|
|
## Configuration
|
|
|
|
Resources are defined as YAML files under `config/`:
|
|
|
|
```
|
|
config/
|
|
├── groups/ # Group definitions
|
|
├── providers_saml/ # SAML provider definitions
|
|
├── providers_oauth2/ # OAuth2/OIDC provider definitions
|
|
├── providers_ldap/ # LDAP provider definitions
|
|
├── service_accounts/ # Automation service accounts + API tokens
|
|
└── users/ # Human role membership (authoritative per named role)
|
|
```
|
|
|
|
## Usage
|
|
|
|
```sh
|
|
make plan # init + plan
|
|
make apply # init + plan + apply
|
|
make format # format all .tf and .hcl files
|
|
```
|
|
|
|
### Authentication
|
|
|
|
Set `VAULT_ROLEID` for local AppRole auth, or `VAULT_AUTH_METHOD=kubernetes` for CI.
|