90a01563dc
Manages Rancher's Keycloak(OIDC) auth provider via the rancher2 provider, pointed at Authentik. Mirrors the terraform-authentik layout (terragrunt + Vault-sourced secrets + Woodpecker plan/apply/pre-commit pipelines). - modules/rancher: rancher2_auth_config_keycloak_oidc, client_secret read from Vault (kv/kubernetes/namespace/cattle-system/default/oauth-credentials); access_mode unrestricted to avoid admin lockout on enable. - config/keycloakoidc.yaml: issuer/auth_endpoint at identity.unkin.net, client_id rancher, /verify-auth redirect, openid/profile/email scopes. - environments/rancher.k8s.syd1.au.unkin.net: consul state at infra/terraform/rancher/, rancher2 provider api_url from the env name. - rancher2 admin token read from kv/service/terraform/rancher (Makefile); to migrate to a dedicated Vault Rancher secrets engine (90-day token cap). Validated with `tofu validate` (config valid against the rancher2 provider). A live `plan` needs the Rancher admin API token seeded in Vault first.
15 lines
667 B
YAML
15 lines
667 B
YAML
# Rancher Keycloak(OIDC) auth provider backed by Authentik.
|
|
# client_secret is read from Vault (the same secret Authentik sets on its
|
|
# provider), not committed. access_mode "unrestricted" avoids admin lockout:
|
|
# any Authentik user can authenticate; Rancher roles are assigned separately.
|
|
rancher_url: https://rancher.k8s.syd1.au.unkin.net/verify-auth
|
|
client_id: rancher
|
|
issuer: https://identity.unkin.net/application/o/rancher/
|
|
auth_endpoint: https://identity.unkin.net/application/o/authorize/
|
|
scopes: openid profile email
|
|
access_mode: unrestricted
|
|
enabled: true
|
|
client_secret_vault:
|
|
mount: kv
|
|
path: kubernetes/namespace/cattle-system/default/oauth-credentials
|