Commit Graph

7 Commits

Author SHA1 Message Date
benvin 08fbc9b8ab Merge pull request 'Fix global role binding name to be RFC 1123 compliant' (#3) from benvin/rancher-grb-name into main
ci/woodpecker/push/apply Pipeline was successful
Reviewed-on: #3
2026-07-18 22:59:02 +10:00
unkinben f2f41fc1c0 Fix global role binding name to be RFC 1123 compliant
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/plan Pipeline was successful
rancher2_global_role_binding.name must be a lowercase RFC 1123 label, but the
akP-* group keys are mixed-case, so apply failed with InvalidFormat 422.
Lowercase the name; keep the group principal id in original case to match the
Authentik group.
2026-07-18 22:55:38 +10:00
benvin 1dc43580f6 Merge pull request 'Wire Rancher to Authentik ak_groups + akP-rancher global roles' (#2) from benvin/rancher-akgroups into main
ci/woodpecker/push/apply Pipeline failed
Reviewed-on: #2
2026-07-18 20:53:18 +10:00
unkinben 80fa1b2844 Wire Rancher to Authentik ak_groups + akP-rancher global roles
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/plan Pipeline was successful
Consume the two-tier Authentik RBAC (terraform-authentik): read the hierarchical
`ak_groups` claim and grant Rancher global roles to the akP-rancher permission
groups. Members of akR-global-admin/akR-standard-user inherit these.

- keycloakoidc: scopes += ak_groups; groups_field = ak_groups
- global_role_bindings: akP-rancher-admin -> admin, akP-rancher-user -> user
  (group principal keycloakoidc_group://<name>)
2026-07-18 16:25:18 +10:00
benvin 5b6a0527ee Merge pull request 'Scaffold terraform-rancher: Authentik OIDC auth config' (#1) from benvin/scaffold into main
ci/woodpecker/push/apply Pipeline was successful
Reviewed-on: #1
2026-07-16 22:26:13 +10:00
unkinben 90a01563dc Scaffold terraform-rancher: Authentik OIDC auth config
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/plan Pipeline was successful
Manages Rancher's Keycloak(OIDC) auth provider via the rancher2 provider,
pointed at Authentik. Mirrors the terraform-authentik layout (terragrunt +
Vault-sourced secrets + Woodpecker plan/apply/pre-commit pipelines).

- modules/rancher: rancher2_auth_config_keycloak_oidc, client_secret read from
  Vault (kv/kubernetes/namespace/cattle-system/default/oauth-credentials);
  access_mode unrestricted to avoid admin lockout on enable.
- config/keycloakoidc.yaml: issuer/auth_endpoint at identity.unkin.net,
  client_id rancher, /verify-auth redirect, openid/profile/email scopes.
- environments/rancher.k8s.syd1.au.unkin.net: consul state at
  infra/terraform/rancher/, rancher2 provider api_url from the env name.
- rancher2 admin token read from kv/service/terraform/rancher (Makefile);
  to migrate to a dedicated Vault Rancher secrets engine (90-day token cap).

Validated with `tofu validate` (config valid against the rancher2 provider).
A live `plan` needs the Rancher admin API token seeded in Vault first.
2026-07-16 22:21:00 +10:00
gitadmin e21699ede9 Initial commit 2026-07-15 21:24:52 +10:00