Compare commits

..
Author SHA1 Message Date
Renovate Bot 4087159e7b chore(deps): update helm release prometheus to v29
AI Code Review / ai-review (pull_request) Skipped
scan.yaml / test (pull_request) Successful in 5s
renovate/stability-days Updates have met minimum release age requirement
2026-10-03 00:05:59 +00:00
jorgen.stensrudandClaude Opus 5.5 4a4b8e3540 feat(keycloak): forte-cli device-code client + forte-drop-mcp audience mapper (#44)
scan.yaml / test (push) Successful in 5s
Adds the shared public forte-cli client (RFC 8628 device-code only) to the forte realm, with an oidc-audience-mapper that puts https://mcp.drop.forteapps.net/mcp into aud so the forte-drop-mcp sidecar accepts its tokens. Supersedes #26.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 11:25:34 +00:00
2 changed files with 16 additions and 2 deletions
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources: sources:
- repoURL: https://prometheus-community.github.io/helm-charts - repoURL: https://prometheus-community.github.io/helm-charts
chart: prometheus chart: prometheus
targetRevision: "28.16.0" targetRevision: "29.33.1"
helm: helm:
releaseName: prometheus releaseName: prometheus
valueFiles: valueFiles:
+14
View File
@@ -200,8 +200,22 @@ keycloakConfigCli:
"webOrigins": [], "webOrigins": [],
"attributes": { "attributes": {
"oauth2.device.authorization.grant.enabled": "true" "oauth2.device.authorization.grant.enabled": "true"
},
"protocolMappers": [
{
"name": "audience-forte-drop-mcp",
"protocol": "openid-connect",
"protocolMapper": "oidc-audience-mapper",
"consentRequired": false,
"config": {
"included.custom.audience": "https://mcp.drop.forteapps.net/mcp",
"access.token.claim": "true",
"id.token.claim": "false",
"introspection.token.claim": "true"
} }
} }
]
}
], ],
"browserFlow": "browser-auto-idp", "browserFlow": "browser-auto-idp",
"authenticationFlows": [ "authenticationFlows": [