Compare commits

..
Author SHA1 Message Date
d087472e63 Add forte-cli public device-code Keycloak client
AI Code Review / ai-review (pull_request) Skipped
scan.yaml / test (pull_request) Successful in 27s
Add a shared public client `forte-cli` to the `forte` realm so downloaded
skills (forte-drop first) can do RFC 8628 device-code login through the
Auth Sidecar. Today no client in the realm has the device grant enabled,
so the flow cannot start.

Client (inline in forte-realm.json, imported verbatim by keycloak-config-cli):
- publicClient: true, standardFlowEnabled: false,
  directAccessGrantsEnabled: false
- attributes: oauth2.device.authorization.grant.enabled=true
- no secret, no redirectUris/webOrigins, no k8s.secret.sync

It has to go in the realm JSON because the self-service registrar
hardcodes publicClient:false/standardFlowEnabled:true and drops
attributes. Also add forte-cli to the cleanup CronJob's protected list
(belt-and-braces; it does not match the UUID pattern anyway).

Additive only: gitea/grafana/argocd and all other realm settings are
unchanged. Keycloak is deployed only via the upc-dev overlay, which
inherits base values, so this lands on id.forteapps.net.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QciXev3MtCxo3eomcfrDRW
2026-10-01 10:37:49 +00:00
7 changed files with 7 additions and 21 deletions
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers {
azurerm = {
source = "hashicorp/azurerm"
version = "~> 5.0"
version = "~> 4.0"
}
}
}
@@ -4,7 +4,7 @@ terraform {
required_providers {
azurerm = {
source = "hashicorp/azurerm"
version = "~> 5.0"
version = "~> 4.0"
}
azuread = {
source = "hashicorp/azuread"
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers {
azurerm = {
source = "hashicorp/azurerm"
version = "~> 5.0"
version = "~> 4.0"
}
}
}
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers {
azurerm = {
source = "hashicorp/azurerm"
version = "~> 5.0"
version = "~> 4.0"
}
random = {
source = "hashicorp/random"
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources:
- repoURL: https://fluent.github.io/helm-charts
chart: fluent-bit
targetRevision: 0.58.3
targetRevision: 0.58.2
helm:
releaseName: fluent-bit
valueFiles:
@@ -24,7 +24,7 @@ spec:
sources:
- repoURL: https://traefik.github.io/charts
chart: traefik
targetRevision: "41.6.0"
targetRevision: "28.3.0"
helm:
releaseName: traefik
valueFiles:
+1 -15
View File
@@ -200,21 +200,7 @@ keycloakConfigCli:
"webOrigins": [],
"attributes": {
"oauth2.device.authorization.grant.enabled": "true"
},
"protocolMappers": [
{
"name": "audience-forte-drop-mcp",
"protocol": "openid-connect",
"protocolMapper": "oidc-audience-mapper",
"consentRequired": false,
"config": {
"included.custom.audience": "https://mcp.drop.forteapps.net/mcp",
"access.token.claim": "true",
"id.token.claim": "false",
"introspection.token.claim": "true"
}
}
]
}
}
],
"browserFlow": "browser-auto-idp",