unkin-agent b3c08369fd
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/plan Pipeline was successful
Add vlogs OIDC application and provider
Onboard the VictoriaLogs query UI at https://vlogs.unkin.net behind
oauth2-proxy, gated on akP-vlogs-admin.

- add config/providers_oauth2/vlogs.yaml reading its client_secret from
  kv/kubernetes/namespace/logging/default/vlogs-oauth-credentials
- add permission group akP-vlogs-admin bound to the vlogs application
- nest akP-vlogs-admin under akR-global-admin
2026-09-27 10:13:18 +10:00
2026-06-28 11:55:26 +10:00
2026-06-28 11:55:26 +10:00

terraform-authentik

Terraform configuration for managing the Authentik identity provider at identity.unkin.net.

Managed Resources

  • Groups — roles and group hierarchy (accounts themselves are created elsewhere)
  • User role membership — which akR-* roles a human holds (see config/users/)
  • SAML providers — SAML application integrations
  • OAuth2/OIDC providers — OAuth2 and OpenID Connect integrations
  • LDAP providers — LDAP provider and outpost configuration
  • Applications — application definitions linked to providers
  • Service accounts — machine identities with RBAC roles and API tokens (keys published to Vault kv)

Configuration

Resources are defined as YAML files under config/:

config/
├── groups/              # Group definitions
├── providers_saml/      # SAML provider definitions
├── providers_oauth2/    # OAuth2/OIDC provider definitions
├── providers_ldap/      # LDAP provider definitions
├── service_accounts/    # Automation service accounts + API tokens
└── users/               # Human role membership (authoritative per named role)

Usage

make plan     # init + plan
make apply    # init + plan + apply
make format   # format all .tf and .hcl files

Authentication

Set VAULT_ROLEID for local AppRole auth, or VAULT_AUTH_METHOD=kubernetes for CI.

S
Description
Terraform configuration for managing Authentik identity provider
Readme 264 KiB
Languages
HCL 94.8%
Makefile 5.2%