Files
k8scd/authentik/blueprint-vault-oidc.yaml
T
2026-03-15 10:50:18 +01:00

46 lines
1.7 KiB
YAML

apiVersion: v1
kind: ConfigMap
metadata:
name: authentik-blueprint-vault
data:
vault-oidc.yaml: |
version: 1
metadata:
name: Vault OIDC
entries:
- model: authentik_crypto.certificatekeypair
id: vault-signing-key
state: present
attrs:
name: vault-signing-key
generate: true
- model: authentik_providers_oauth2.oauth2provider
id: vault-provider
state: present
identifiers:
name: Vault
attrs:
name: Vault
authorization_flow: !Find [authentik_flows.flow, [slug, default-provider-authorization-implicit-consent]]
authentication_flow: !Find [authentik_flows.flow, [slug, default-authentication-flow]]
client_type: confidential
client_id: vault
client_secret: !Env [VAULT_OIDC_CLIENT_SECRET]
redirect_uris: |-
https://vault.hensen.io/ui/vault/auth/oidc/oidc/callback
http://localhost:8250/oidc/callback
signing_key: !KeyOf vault-signing-key
property_mappings:
- !Find [authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-openid]]
- !Find [authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-email]]
- !Find [authentik_providers_oauth2.scopemapping, [managed, goauthentik.io/providers/oauth2/scope-profile]]
- model: authentik_core.application
id: vault-app
state: present
identifiers:
slug: vault
attrs:
name: Vault
provider: !KeyOf vault-provider
meta_launch_url: https://vault.hensen.io