diff --git a/apps/templates/authentik-helm.yaml b/apps/templates/authentik-helm.yaml index 16ced28..96da680 100644 --- a/apps/templates/authentik-helm.yaml +++ b/apps/templates/authentik-helm.yaml @@ -76,6 +76,11 @@ spec: secretKeyRef: name: argocd-oidc-client-secret key: client_secret + - name: FRESHRSS_OIDC_CLIENT_SECRET + valueFrom: + secretKeyRef: + name: freshrss-oidc-client-secret + key: client_secret server: volumes: - name: blueprint-vault @@ -90,6 +95,9 @@ spec: - name: blueprint-argocd configMap: name: authentik-blueprint-argocd + - name: blueprint-freshrss + configMap: + name: authentik-blueprint-freshrss volumeMounts: - name: blueprint-vault mountPath: /blueprints/custom/vault-oidc.yaml @@ -103,6 +111,9 @@ spec: - name: blueprint-argocd mountPath: /blueprints/custom/argocd-oidc.yaml subPath: argocd-oidc.yaml + - name: blueprint-freshrss + mountPath: /blueprints/custom/freshrss-oidc.yaml + subPath: freshrss-oidc.yaml ingress: enabled: true ingressClassName: nginx @@ -128,6 +139,9 @@ spec: - name: blueprint-argocd configMap: name: authentik-blueprint-argocd + - name: blueprint-freshrss + configMap: + name: authentik-blueprint-freshrss volumeMounts: - name: blueprint-vault mountPath: /blueprints/custom/vault-oidc.yaml @@ -141,6 +155,9 @@ spec: - name: blueprint-argocd mountPath: /blueprints/custom/argocd-oidc.yaml subPath: argocd-oidc.yaml + - name: blueprint-freshrss + mountPath: /blueprints/custom/freshrss-oidc.yaml + subPath: freshrss-oidc.yaml postgresql: enabled: false redis: diff --git a/authentik/blueprint-freshrss-oidc.yaml b/authentik/blueprint-freshrss-oidc.yaml new file mode 100644 index 0000000..10444e4 --- /dev/null +++ b/authentik/blueprint-freshrss-oidc.yaml @@ -0,0 +1,40 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: authentik-blueprint-freshrss +data: + freshrss-oidc.yaml: | + version: 1 + metadata: + name: FreshRSS OIDC + entries: + - model: authentik_providers_oauth2.oauth2provider + id: freshrss-provider + state: present + identifiers: + name: FreshRSS + attrs: + name: FreshRSS + authorization_flow: !Find [authentik_flows.flow, [slug, default-provider-authorization-implicit-consent]] + authentication_flow: !Find [authentik_flows.flow, [slug, default-authentication-flow]] + invalidation_flow: !Find [authentik_flows.flow, [slug, default-provider-invalidation-flow]] + client_type: confidential + client_id: freshrss + client_secret: !Env [FRESHRSS_OIDC_CLIENT_SECRET, ""] + redirect_uris: + - matching_mode: strict + url: https://rss.rubenhensen.nl/i/oidc/ + signing_key: !Find [authentik_crypto.certificatekeypair, [name, "authentik Self-signed Certificate"]] + property_mappings: + - !Find [authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-openid]] + - !Find [authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-email]] + - !Find [authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-profile]] + - model: authentik_core.application + id: freshrss-app + state: present + identifiers: + slug: freshrss + attrs: + name: FreshRSS + provider: !KeyOf freshrss-provider + meta_launch_url: https://rss.rubenhensen.nl diff --git a/authentik/external-secret.yaml b/authentik/external-secret.yaml index 143f05e..9bfaf96 100644 --- a/authentik/external-secret.yaml +++ b/authentik/external-secret.yaml @@ -99,3 +99,21 @@ spec: remoteRef: key: kv/argocd-oidc property: client_secret +--- +apiVersion: external-secrets.io/v1beta1 +kind: ExternalSecret +metadata: + name: freshrss-oidc-client-secret +spec: + secretStoreRef: + name: vault-backend + kind: ClusterSecretStore + refreshInterval: 15m + target: + name: freshrss-oidc-client-secret + creationPolicy: Owner + data: + - secretKey: client_secret + remoteRef: + key: kv/freshrss-oidc + property: client_secret diff --git a/freshrss/external-secret.yaml b/freshrss/external-secret.yaml new file mode 100644 index 0000000..d1d0057 --- /dev/null +++ b/freshrss/external-secret.yaml @@ -0,0 +1,17 @@ +apiVersion: external-secrets.io/v1beta1 +kind: ExternalSecret +metadata: + name: freshrss-oidc-client-secret +spec: + secretStoreRef: + name: vault-backend + kind: ClusterSecretStore + refreshInterval: 15m + target: + name: freshrss-oidc-client-secret + creationPolicy: Owner + data: + - secretKey: client_secret + remoteRef: + key: kv/freshrss-oidc + property: client_secret diff --git a/freshrss/freshrss-deployment.yaml b/freshrss/freshrss-deployment.yaml index 67dff97..6750388 100644 --- a/freshrss/freshrss-deployment.yaml +++ b/freshrss/freshrss-deployment.yaml @@ -42,7 +42,20 @@ spec: - name: CRON_MIN value: "13,43" - name: OIDC_ENABLED - value: "0" + value: "1" + - name: OIDC_PROVIDER_METADATA_URL + value: https://authentik.rubenhensen.nl/application/o/freshrss/.well-known/openid-configuration + - name: OIDC_CLIENT_ID + value: freshrss + - name: OIDC_CLIENT_SECRET + valueFrom: + secretKeyRef: + name: freshrss-oidc-client-secret + key: client_secret + - name: OIDC_SCOPES + value: "openid email profile" + - name: OIDC_X_FORWARDED_HEADERS + value: X-Forwarded-Port X-Forwarded-Proto X-Forwarded-Host - name: TZ value: Europe/Amsterdam image: freshrss/freshrss:latest