Compare commits

...
Author SHA1 Message Date
Renovate Botanddanijel.simeunovic 9f678cb853 chore(deps): update terraform azurerm to v5
AI Code Review / ai-review (pull_request) Skipped
scan.yaml / test (pull_request) Successful in 5s
2026-10-03 18:55:15 +00:00
0f0082d54d chore(deps): update helm release fluent-bit to v0.58.3 (#57)
scan.yaml / test (push) Successful in 7s
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [fluent-bit](https://fluentbit.io/) ([source](https://github.com/fluent/helm-charts)) | patch | `0.58.2` → `0.58.3` |

---

### Release Notes

<details>
<summary>fluent/helm-charts (fluent-bit)</summary>

### [`v0.58.3`](https://github.com/fluent/helm-charts/releases/tag/fluent-bit-0.58.3)

[Compare Source](https://github.com/fluent/helm-charts/compare/fluent-bit-0.58.2...fluent-bit-0.58.3)

##### Changed

- Update *Fluent Bit* OCI image to [v5.1.3](https://github.com/fluent/fluent-bit/releases/tag/v5.1.3). ([#&#8203;759](https://github.com/fluent/helm-charts/pull/759)) [@&#8203;stevehipwell](https://github.com/stevehipwell)

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: #57
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-10-03 18:55:02 +00:00
jorgen.stensrudandClaude Opus 5.5 4a4b8e3540 feat(keycloak): forte-cli device-code client + forte-drop-mcp audience mapper (#44)
scan.yaml / test (push) Successful in 5s
Adds the shared public forte-cli client (RFC 8628 device-code only) to the forte realm, with an oidc-audience-mapper that puts https://mcp.drop.forteapps.net/mcp into aud so the forte-drop-mcp sidecar accepts its tokens. Supersedes #26.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 11:25:34 +00:00
7 changed files with 41 additions and 6 deletions
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers {
azurerm = {
source = "hashicorp/azurerm"
version = "~> 4.0"
version = "~> 5.0"
}
}
}
@@ -4,7 +4,7 @@ terraform {
required_providers {
azurerm = {
source = "hashicorp/azurerm"
version = "~> 4.0"
version = "~> 5.0"
}
azuread = {
source = "hashicorp/azuread"
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers {
azurerm = {
source = "hashicorp/azurerm"
version = "~> 4.0"
version = "~> 5.0"
}
}
}
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers {
azurerm = {
source = "hashicorp/azurerm"
version = "~> 4.0"
version = "~> 5.0"
}
random = {
source = "hashicorp/random"
+6
View File
@@ -1469,6 +1469,12 @@ ArgoCD will sync the Keycloak config, and the registrar CronJob will pick up the
| `k8s.secret.client-id-key` | No | `client-id` | Field name for the client ID in the K8s Secret |
| `k8s.secret.client-secret-key` | No | `client-secret` | Field name for the client secret in the K8s Secret |
#### Public CLI Client (Device-Code Login)
`forte-cli` is a shared **public** client (no secret) with the RFC 8628 device-authorization grant enabled (`oauth2.device.authorization.grant.enabled: "true"`, `standardFlowEnabled: false`, `directAccessGrantsEnabled: false`). Downloaded skills and CLI tools that log in through the Auth Sidecar (forte-drop first) use it with `<PREFIX>_CLIENT_ID=forte-cli`; nothing per-tool needs to be registered in Keycloak.
It must be defined in `forte-realm.json` (this legacy path): the self-service registrar hardcodes `publicClient: false` / `standardFlowEnabled: true` and drops `attributes`, so a `client-config` Secret cannot produce a public device-code client. It carries no `k8s.secret.sync` attribute (the registrar's secret sync skips it) and is listed in the cleanup CronJob's protected clients.
### Retrieving Secrets for External Deployments
The registrar always writes a **central copy** of every synced secret to the `secrets` namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster:
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources:
- repoURL: https://fluent.github.io/helm-charts
chart: fluent-bit
targetRevision: 0.58.2
targetRevision: 0.58.3
helm:
releaseName: fluent-bit
valueFiles:
+30 -1
View File
@@ -186,6 +186,35 @@ keycloakConfigCli:
}
}
]
},
{
"clientId": "forte-cli",
"name": "Forte CLI",
"description": "Shared public client for RFC 8628 device-code login from downloaded skills/CLI tools (forte-drop first) against services behind Auth Sidecar. No client secret.",
"enabled": true,
"protocol": "openid-connect",
"standardFlowEnabled": false,
"directAccessGrantsEnabled": false,
"publicClient": true,
"redirectUris": [],
"webOrigins": [],
"attributes": {
"oauth2.device.authorization.grant.enabled": "true"
},
"protocolMappers": [
{
"name": "audience-forte-drop-mcp",
"protocol": "openid-connect",
"protocolMapper": "oidc-audience-mapper",
"consentRequired": false,
"config": {
"included.custom.audience": "https://mcp.drop.forteapps.net/mcp",
"access.token.claim": "true",
"id.token.claim": "false",
"introspection.token.claim": "true"
}
}
]
}
],
"browserFlow": "browser-auto-idp",
@@ -671,7 +700,7 @@ extraDeploy:
MIN_AGE_SEC=$((MIN_AGE_DAYS * 86400))
# Hardcoded protected clients (never delete these)
PROTECTED_JSON='["gitea","grafana","argocd","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]'
PROTECTED_JSON='["gitea","grafana","argocd","forte-cli","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]'
echo "Fetching clients from realm '${REALM}'..."
CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \