apiVersion: v1 kind: ConfigMap metadata: name: authentik-blueprint-freshrss data: freshrss-oidc.yaml: | version: 1 metadata: name: FreshRSS OIDC entries: - model: authentik_providers_oauth2.oauth2provider id: freshrss-provider state: present identifiers: name: FreshRSS attrs: name: FreshRSS authorization_flow: !Find [authentik_flows.flow, [slug, default-provider-authorization-implicit-consent]] authentication_flow: !Find [authentik_flows.flow, [slug, default-authentication-flow]] invalidation_flow: !Find [authentik_flows.flow, [slug, default-provider-invalidation-flow]] client_type: confidential client_id: freshrss client_secret: !Env [FRESHRSS_OIDC_CLIENT_SECRET, ""] redirect_uris: - matching_mode: strict url: https://rss.rubenhensen.nl/i/oidc/ signing_key: !Find [authentik_crypto.certificatekeypair, [name, "authentik Self-signed Certificate"]] property_mappings: - !Find [authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-openid]] - !Find [authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-email]] - !Find [authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-profile]] - model: authentik_core.application id: freshrss-app state: present identifiers: slug: freshrss attrs: name: FreshRSS provider: !KeyOf freshrss-provider meta_launch_url: https://rss.rubenhensen.nl