Files
terraform-vault/modules/vault_cluster/modules/auth_oidc_group/variables.tf
T
unkin-agent b225ef6344
ci/woodpecker/pr/plan Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful
Add Authentik OIDC SSO as the default human login for OpenBao
Human access to OpenBao is LDAP-only today, so operators carry a second set of
credentials outside Authentik and group membership is maintained twice. This
makes Authentik SSO the offered default on the UI login page and gives
`bao login -method=oidc` a working CLI path, while approle and kubernetes (CI
and agents) plus the break-glass root path are untouched.

Add three modules mirroring the auth_ldap_* structure: auth_oidc_backend mounts
a vault_jwt_auth_backend of type oidc, auth_oidc_role creates the default login
role, and auth_oidc_group creates an external vault_identity_group plus its
group alias so IdP groups map onto policies.

Mount the backend at the literal path "oidc". The Authentik provider registers
strict redirect URIs containing /ui/vault/auth/oidc/oidc/callback, so the path
is load-bearing and must not be renamed.

Read client_id and client_secret from kv/service/authentik/oidc-vault, which
terraform-authentik generates and writes; nothing is seeded by hand.

Match groups on the ak_groups claim rather than groups, because Authentik's
default profile mapping only emits direct memberships and the estate nests
akP-* permission groups under akR-* roles.

Bind akP-vault-admin to global-root, the same policy the LDAP vault_admin group
already carries. Only akP-* permission groups are named in config or policy;
akR-* roles stay grouping-only.

Grant the deployer auth/oidc/* and identity group management, both of which it
currently lacks. AppRole capabilities are fixed at login, so these land in an
apply before the resources that need them.
2026-08-30 21:49:14 +10:00

15 lines
370 B
Terraform

variable "groupname" {
description = "Name of the IdP group, as it appears in the groups claim"
type = string
}
variable "policies" {
description = "List of policies to assign to the identity group"
type = list(string)
}
variable "mount_accessor" {
description = "Accessor of the OIDC auth mount the alias is bound to"
type = string
}