Add Authentik OIDC SSO as the default human login for OpenBao (#147)
ci/woodpecker/push/apply Pipeline failed
ci/woodpecker/push/apply Pipeline failed
## Why
Human login to OpenBao is LDAP-only, so operators keep a second credential set outside Authentik and group membership is maintained twice.
## How
- Add `auth_oidc_backend` module: `oidc`-type JWT auth mount, Authentik discovery URL, `listing_visibility: unauth`, credentials from `kv/service/authentik/oidc-vault`.
- Add `auth_oidc_role` module: oidc role with `user_claim` email, `groups_claim` `ak_groups`, scopes `openid profile email ak_groups`, the registered redirect URIs, `bound_audiences` `[vault]`.
- Add `auth_oidc_group` module: external identity group plus group alias on the OIDC mount accessor, policies from `policy_auth_map`.
- Add config under `config/auth_oidc_{backend,role,group}/`, discovery locals in `config/config.hcl`, `vault_cluster` variables and wiring, and terragrunt inputs.
- Bind `akP-vault-admin` on the `oidc` mount to `global-root`, alongside the existing LDAP `vault_admin` binding.
- Pin the mount path to the literal `oidc`: the registered redirect URIs embed `/ui/vault/auth/oidc/oidc/callback`.
Requires #146, terraform-authentik #33 and #148 applied first.
---------
Co-authored-by: BenVincent <benvin@main.unkin.net>
Reviewed-on: #147
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #147.
This commit is contained in:
@@ -62,6 +62,46 @@ variable "auth_ldap_group" {
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "auth_oidc_backend" {
|
||||
description = "Map of OIDC (JWT) auth backends to create"
|
||||
type = map(object({
|
||||
oidc_discovery_url = string
|
||||
description = optional(string)
|
||||
client_secret_mount = optional(string, "kv")
|
||||
client_secret_path = optional(string, "service/authentik/oidc-vault")
|
||||
default_role = optional(string, "default")
|
||||
listing_visibility = optional(string)
|
||||
default_lease_ttl = optional(string)
|
||||
max_lease_ttl = optional(string)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "auth_oidc_role" {
|
||||
description = "Map of OIDC auth roles to create"
|
||||
type = map(object({
|
||||
role_name = string
|
||||
backend = string
|
||||
allowed_redirect_uris = list(string)
|
||||
user_claim = optional(string, "email")
|
||||
groups_claim = optional(string, "ak_groups")
|
||||
oidc_scopes = optional(list(string), [])
|
||||
bound_audiences = optional(list(string), [])
|
||||
token_ttl = optional(number, 3600)
|
||||
token_max_ttl = optional(number, 28800)
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "auth_oidc_group" {
|
||||
description = "Map of external identity groups bound to an OIDC auth mount"
|
||||
type = map(object({
|
||||
groupname = string
|
||||
backend = string
|
||||
}))
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "auth_kubernetes_backend" {
|
||||
description = "Map of Kubernetes auth backends to create"
|
||||
type = map(object({
|
||||
|
||||
Reference in New Issue
Block a user