d848d9ae86
Add a users/ config kind mapping a human to the akR-* roles they hold. Look accounts up with data.authentik_user; never declare them. Set authentik_group.role users only for roles a user file names, leaving every other role's membership untouched. No assignments yet.
653 B
653 B
users
One file per human, <username>.yaml, listing the akR-* roles they hold:
# Human user jane (username = filename). The account itself is not managed here
# (humans come from LDAP sync / invite); only its role membership is.
roles:
- akR-media-adult
The account is looked up by username and must already exist — nothing here
creates users. A role that has no config/roles/<name>.yaml fails the plan.
Naming a role here makes Terraform authoritative over that role's entire member list: members added by hand in the Authentik UI for that role are removed on the next apply. Roles no user file names are left untouched.