Files
terraform-authentik/config/users
unkin-agent d848d9ae86
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/plan Pipeline failed
Manage human role membership from config/users/
Add a users/ config kind mapping a human to the akR-* roles they hold.
Look accounts up with data.authentik_user; never declare them. Set
authentik_group.role users only for roles a user file names, leaving
every other role's membership untouched. No assignments yet.
2026-09-19 12:46:58 +10:00
..

users

One file per human, <username>.yaml, listing the akR-* roles they hold:

# Human user jane (username = filename). The account itself is not managed here
# (humans come from LDAP sync / invite); only its role membership is.
roles:
  - akR-media-adult

The account is looked up by username and must already exist — nothing here creates users. A role that has no config/roles/<name>.yaml fails the plan.

Naming a role here makes Terraform authoritative over that role's entire member list: members added by hand in the Authentik UI for that role are removed on the next apply. Roles no user file names are left untouched.