8fa4192cc6
NetBox is being deployed to k8s (argocd-apps) with Authentik SSO via python-social-auth's OpenIdConnectAuth backend. Add the confidential OAuth2 provider/application (client_id netbox, openid/email/profile scopes, strict redirect to /oauth/complete/oidc/); the client_secret is read from Vault at kubernetes/namespace/netbox/default/oauth-credentials (the terraform-authentik runner policy already covers namespace/+/default/oauth-credentials). Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv