Add Authentik OIDC SSO as the default human login for OpenBao #147

Merged
benvin merged 3 commits from benvin/auth-oidc into master 2026-08-30 22:38:05 +10:00

3 Commits

Author SHA1 Message Date
benvin 7c51605f9a Merge branch 'master' into benvin/auth-oidc
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-08-30 22:18:28 +10:00
unkin-agent 7aaafb455d Drop the deployer capability policies extracted to #148
ci/woodpecker/pr/plan Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful
Review ruled that shipping the auth/oidc and identity-group grants alongside
the resources they authorise violates the never-bundle rule: AppRole
capabilities are fixed at login, so the grants must land in a prior apply.

Remove policies/auth/oidc/admin.yaml and policies/identity/group/admin.yaml;
they now ship unchanged in #148, which merges and applies first.
2026-08-30 22:01:07 +10:00
unkin-agent b225ef6344 Add Authentik OIDC SSO as the default human login for OpenBao
ci/woodpecker/pr/plan Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful
Human access to OpenBao is LDAP-only today, so operators carry a second set of
credentials outside Authentik and group membership is maintained twice. This
makes Authentik SSO the offered default on the UI login page and gives
`bao login -method=oidc` a working CLI path, while approle and kubernetes (CI
and agents) plus the break-glass root path are untouched.

Add three modules mirroring the auth_ldap_* structure: auth_oidc_backend mounts
a vault_jwt_auth_backend of type oidc, auth_oidc_role creates the default login
role, and auth_oidc_group creates an external vault_identity_group plus its
group alias so IdP groups map onto policies.

Mount the backend at the literal path "oidc". The Authentik provider registers
strict redirect URIs containing /ui/vault/auth/oidc/oidc/callback, so the path
is load-bearing and must not be renamed.

Read client_id and client_secret from kv/service/authentik/oidc-vault, which
terraform-authentik generates and writes; nothing is seeded by hand.

Match groups on the ak_groups claim rather than groups, because Authentik's
default profile mapping only emits direct memberships and the estate nests
akP-* permission groups under akR-* roles.

Bind akP-vault-admin to global-root, the same policy the LDAP vault_admin group
already carries. Only akP-* permission groups are named in config or policy;
akR-* roles stay grouping-only.

Grant the deployer auth/oidc/* and identity group management, both of which it
currently lacks. AppRole capabilities are fixed at login, so these land in an
apply before the resources that need them.
2026-08-30 21:49:14 +10:00