Add Authentik OIDC SSO as the default human login for OpenBao #147

Merged
benvin merged 3 commits from benvin/auth-oidc into master 2026-08-30 22:38:05 +10:00
Member

Why

Human login to OpenBao is LDAP-only, so operators keep a second credential set outside Authentik and group membership is maintained twice.

How

  • Add auth_oidc_backend module: oidc-type JWT auth mount, Authentik discovery URL, listing_visibility: unauth, credentials from kv/service/authentik/oidc-vault.
  • Add auth_oidc_role module: oidc role with user_claim email, groups_claim ak_groups, scopes openid profile email ak_groups, the registered redirect URIs, bound_audiences [vault].
  • Add auth_oidc_group module: external identity group plus group alias on the OIDC mount accessor, policies from policy_auth_map.
  • Add config under config/auth_oidc_{backend,role,group}/, discovery locals in config/config.hcl, vault_cluster variables and wiring, and terragrunt inputs.
  • Bind akP-vault-admin on the oidc mount to global-root, alongside the existing LDAP vault_admin binding.
  • Pin the mount path to the literal oidc: the registered redirect URIs embed /ui/vault/auth/oidc/oidc/callback.

Requires #146, terraform-authentik #33 and #148 applied first.

## Why Human login to OpenBao is LDAP-only, so operators keep a second credential set outside Authentik and group membership is maintained twice. ## How - Add `auth_oidc_backend` module: `oidc`-type JWT auth mount, Authentik discovery URL, `listing_visibility: unauth`, credentials from `kv/service/authentik/oidc-vault`. - Add `auth_oidc_role` module: oidc role with `user_claim` email, `groups_claim` `ak_groups`, scopes `openid profile email ak_groups`, the registered redirect URIs, `bound_audiences` `[vault]`. - Add `auth_oidc_group` module: external identity group plus group alias on the OIDC mount accessor, policies from `policy_auth_map`. - Add config under `config/auth_oidc_{backend,role,group}/`, discovery locals in `config/config.hcl`, `vault_cluster` variables and wiring, and terragrunt inputs. - Bind `akP-vault-admin` on the `oidc` mount to `global-root`, alongside the existing LDAP `vault_admin` binding. - Pin the mount path to the literal `oidc`: the registered redirect URIs embed `/ui/vault/auth/oidc/oidc/callback`. Requires #146, terraform-authentik #33 and #148 applied first.
unkin-agent added 1 commit 2026-08-30 21:49:43 +10:00
Add Authentik OIDC SSO as the default human login for OpenBao
ci/woodpecker/pr/plan Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful
b225ef6344
Human access to OpenBao is LDAP-only today, so operators carry a second set of
credentials outside Authentik and group membership is maintained twice. This
makes Authentik SSO the offered default on the UI login page and gives
`bao login -method=oidc` a working CLI path, while approle and kubernetes (CI
and agents) plus the break-glass root path are untouched.

Add three modules mirroring the auth_ldap_* structure: auth_oidc_backend mounts
a vault_jwt_auth_backend of type oidc, auth_oidc_role creates the default login
role, and auth_oidc_group creates an external vault_identity_group plus its
group alias so IdP groups map onto policies.

Mount the backend at the literal path "oidc". The Authentik provider registers
strict redirect URIs containing /ui/vault/auth/oidc/oidc/callback, so the path
is load-bearing and must not be renamed.

Read client_id and client_secret from kv/service/authentik/oidc-vault, which
terraform-authentik generates and writes; nothing is seeded by hand.

Match groups on the ak_groups claim rather than groups, because Authentik's
default profile mapping only emits direct memberships and the estate nests
akP-* permission groups under akR-* roles.

Bind akP-vault-admin to global-root, the same policy the LDAP vault_admin group
already carries. Only akP-* permission groups are named in config or policy;
akR-* roles stay grouping-only.

Grant the deployer auth/oidc/* and identity group management, both of which it
currently lacks. AppRole capabilities are fixed at login, so these land in an
apply before the resources that need them.
unkin-agent added 1 commit 2026-08-30 22:01:10 +10:00
Drop the deployer capability policies extracted to #148
ci/woodpecker/pr/plan Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful
7aaafb455d
Review ruled that shipping the auth/oidc and identity-group grants alongside
the resources they authorise violates the never-bundle rule: AppRole
capabilities are fixed at login, so the grants must land in a prior apply.

Remove policies/auth/oidc/admin.yaml and policies/identity/group/admin.yaml;
they now ship unchanged in #148, which merges and applies first.
Author
Member

Per review, the two deployer capability policies are extracted from this PR into #148 (benvin/oidc-deployer-grants), copied verbatim — policies/auth/oidc/admin.yaml and policies/identity/group/admin.yaml. AppRole capabilities are fixed at login, so those grants have to be applied before the apply that creates the resources they authorise; bundling them here violated the never-bundle rule (precedent: #124 closed unmerged and split into #125/#126/#127, and #146's grant-first pattern).

Head is now 7aaafb4, one additive commit doing the git rm. Nothing else changed — policies/global-root.yaml keeps its oidc: akP-vault-admin entry here, since it depends on the OIDC mount this PR creates.

Merge order: #146 + tf-authentik#33 + #148, all applied, then this PR. The plan here stays red by design until those dependencies apply; pre-commit is green.

Per review, the two deployer capability policies are extracted from this PR into #148 (`benvin/oidc-deployer-grants`), copied verbatim — `policies/auth/oidc/admin.yaml` and `policies/identity/group/admin.yaml`. AppRole capabilities are fixed at login, so those grants have to be applied before the apply that creates the resources they authorise; bundling them here violated the never-bundle rule (precedent: #124 closed unmerged and split into #125/#126/#127, and #146's grant-first pattern). Head is now 7aaafb4, one additive commit doing the `git rm`. Nothing else changed — `policies/global-root.yaml` keeps its `oidc: akP-vault-admin` entry here, since it depends on the OIDC mount this PR creates. Merge order: #146 + tf-authentik#33 + #148, all applied, then this PR. The plan here stays red by design until those dependencies apply; pre-commit is green.
benvin added 1 commit 2026-08-30 22:18:30 +10:00
Merge branch 'master' into benvin/auth-oidc
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
7c51605f9a
benvin merged commit a1e7029615 into master 2026-08-30 22:38:05 +10:00
benvin deleted branch benvin/auth-oidc 2026-08-30 22:38:05 +10:00
Sign in to join this conversation.
No Reviewers
No Label
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/terraform-vault#147