Add oidc to Vault

This commit is contained in:
Ruben Hensen
2026-03-15 10:50:18 +01:00
parent 50f38912bc
commit 66d1ba9d13
3 changed files with 138 additions and 0 deletions
+45
View File
@@ -0,0 +1,45 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: authentik-blueprint-vault
data:
vault-oidc.yaml: |
version: 1
metadata:
name: Vault OIDC
entries:
- model: authentik_crypto.certificatekeypair
id: vault-signing-key
state: present
attrs:
name: vault-signing-key
generate: true
- model: authentik_providers_oauth2.oauth2provider
id: vault-provider
state: present
identifiers:
name: Vault
attrs:
name: Vault
authorization_flow: !Find [authentik_flows.flow, [slug, default-provider-authorization-implicit-consent]]
authentication_flow: !Find [authentik_flows.flow, [slug, default-authentication-flow]]
client_type: confidential
client_id: vault
client_secret: !Env [VAULT_OIDC_CLIENT_SECRET]
redirect_uris: |-
https://vault.hensen.io/ui/vault/auth/oidc/oidc/callback
http://localhost:8250/oidc/callback
signing_key: !KeyOf vault-signing-key
property_mappings:
- !Find [authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-openid]]
- !Find [authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-email]]
- !Find [authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-profile]]
- model: authentik_core.application
id: vault-app
state: present
identifiers:
slug: vault
attrs:
name: Vault
provider: !KeyOf vault-provider
meta_launch_url: https://vault.hensen.io
+18
View File
@@ -45,3 +45,21 @@ spec:
remoteRef: remoteRef:
key: kv/authentik key: kv/authentik
property: postgres_password property: postgres_password
---
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: vault-oidc-client-secret
spec:
secretStoreRef:
name: vault-backend
kind: ClusterSecretStore
refreshInterval: 15m
target:
name: vault-oidc-client-secret
creationPolicy: Owner
data:
- secretKey: client_secret
remoteRef:
key: kv/vault-oidc
property: client_secret
+75
View File
@@ -0,0 +1,75 @@
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: vault-oidc-config
spec:
secretStoreRef:
name: vault-backend
kind: ClusterSecretStore
refreshInterval: 15m
target:
name: vault-oidc-config
creationPolicy: Owner
data:
- secretKey: client_secret
remoteRef:
key: kv/vault-oidc
property: client_secret
- secretKey: admin_token
remoteRef:
key: kv/vault-oidc
property: admin_token
---
apiVersion: batch/v1
kind: Job
metadata:
name: vault-configure-oidc
annotations:
argocd.argoproj.io/hook: PostSync
argocd.argoproj.io/hook-delete-policy: BeforeHookCreation
spec:
backoffLimit: 3
template:
spec:
containers:
- name: configure
image: hashicorp/vault:1.15
env:
- name: VAULT_ADDR
value: "https://vault-active.vault.svc:8200"
- name: VAULT_CACERT
value: "/vault-tls/vault.ca"
- name: VAULT_TOKEN
valueFrom:
secretKeyRef:
name: vault-oidc-config
key: admin_token
- name: OIDC_CLIENT_SECRET
valueFrom:
secretKeyRef:
name: vault-oidc-config
key: client_secret
volumeMounts:
- name: vault-tls
mountPath: /vault-tls
readOnly: true
command: ["/bin/sh", "-c"]
args:
- |
vault auth enable oidc 2>/dev/null || true
vault write auth/oidc/config \
oidc_discovery_url="https://authentik.rubenhensen.nl/application/o/vault/" \
oidc_client_id="vault" \
oidc_client_secret="$OIDC_CLIENT_SECRET" \
default_role="default"
vault write auth/oidc/role/default \
allowed_redirect_uris="https://vault.hensen.io/ui/vault/auth/oidc/oidc/callback" \
allowed_redirect_uris="http://localhost:8250/oidc/callback" \
user_claim="preferred_username" \
groups_claim="groups" \
policies="default"
volumes:
- name: vault-tls
secret:
secretName: vault-ha-tls
restartPolicy: OnFailure