Add forte-cli public device-code Keycloak client
Add a shared public client `forte-cli` to the `forte` realm so downloaded skills (forte-drop first) can do RFC 8628 device-code login through the Auth Sidecar. Today no client in the realm has the device grant enabled, so the flow cannot start. Client (inline in forte-realm.json, imported verbatim by keycloak-config-cli): - publicClient: true, standardFlowEnabled: false, directAccessGrantsEnabled: false - attributes: oauth2.device.authorization.grant.enabled=true - no secret, no redirectUris/webOrigins, no k8s.secret.sync It has to go in the realm JSON because the self-service registrar hardcodes publicClient:false/standardFlowEnabled:true and drops attributes. Also add forte-cli to the cleanup CronJob's protected list (belt-and-braces; it does not match the UUID pattern anyway). Additive only: gitea/grafana/argocd and all other realm settings are unchanged. Keycloak is deployed only via the upc-dev overlay, which inherits base values, so this lands on id.forteapps.net. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QciXev3MtCxo3eomcfrDRW
This commit is contained in:
co-authored by
Claude Fable 5.1
parent
60b8fa657a
commit
0bf8c3988e
@@ -186,6 +186,21 @@ keycloakConfigCli:
|
||||
}
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"clientId": "forte-cli",
|
||||
"name": "Forte CLI",
|
||||
"description": "Shared public client for RFC 8628 device-code login from downloaded skills/CLI tools (forte-drop first) against services behind Auth Sidecar. No client secret.",
|
||||
"enabled": true,
|
||||
"protocol": "openid-connect",
|
||||
"standardFlowEnabled": false,
|
||||
"directAccessGrantsEnabled": false,
|
||||
"publicClient": true,
|
||||
"redirectUris": [],
|
||||
"webOrigins": [],
|
||||
"attributes": {
|
||||
"oauth2.device.authorization.grant.enabled": "true"
|
||||
}
|
||||
}
|
||||
],
|
||||
"browserFlow": "browser-auto-idp",
|
||||
@@ -671,7 +686,7 @@ extraDeploy:
|
||||
MIN_AGE_SEC=$((MIN_AGE_DAYS * 86400))
|
||||
|
||||
# Hardcoded protected clients (never delete these)
|
||||
PROTECTED_JSON='["gitea","grafana","argocd","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]'
|
||||
PROTECTED_JSON='["gitea","grafana","argocd","forte-cli","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]'
|
||||
|
||||
echo "Fetching clients from realm '${REALM}'..."
|
||||
CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \
|
||||
|
||||
Reference in New Issue
Block a user