a1e7029615
ci/woodpecker/push/apply Pipeline failed
## Why
Human login to OpenBao is LDAP-only, so operators keep a second credential set outside Authentik and group membership is maintained twice.
## How
- Add `auth_oidc_backend` module: `oidc`-type JWT auth mount, Authentik discovery URL, `listing_visibility: unauth`, credentials from `kv/service/authentik/oidc-vault`.
- Add `auth_oidc_role` module: oidc role with `user_claim` email, `groups_claim` `ak_groups`, scopes `openid profile email ak_groups`, the registered redirect URIs, `bound_audiences` `[vault]`.
- Add `auth_oidc_group` module: external identity group plus group alias on the OIDC mount accessor, policies from `policy_auth_map`.
- Add config under `config/auth_oidc_{backend,role,group}/`, discovery locals in `config/config.hcl`, `vault_cluster` variables and wiring, and terragrunt inputs.
- Bind `akP-vault-admin` on the `oidc` mount to `global-root`, alongside the existing LDAP `vault_admin` binding.
- Pin the mount path to the literal `oidc`: the registered redirect URIs embed `/ui/vault/auth/oidc/oidc/callback`.
Requires #146, terraform-authentik #33 and #148 applied first.
---------
Co-authored-by: BenVincent <benvin@main.unkin.net>
Reviewed-on: #147
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
22 lines
560 B
YAML
22 lines
560 B
YAML
# Global root policy with full access to all paths
|
|
---
|
|
rules:
|
|
- path: "*"
|
|
capabilities:
|
|
- create
|
|
- read
|
|
- update
|
|
- delete
|
|
- list
|
|
- sudo
|
|
|
|
# The oidc entry is an Authentik akP-* permission group, not an LDAP group name:
|
|
# it names the external identity group under config/auth_oidc_group, so a human
|
|
# who logs in via Authentik SSO lands on exactly the policy the LDAP vault_admin
|
|
# group already carries. akR-* roles are grouping-only and never named here.
|
|
auth:
|
|
ldap:
|
|
- vault_admin
|
|
oidc:
|
|
- akP-vault-admin
|