Compare commits
1
Commits
main
..
89a137674c
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
89a137674c |
@@ -41,11 +41,11 @@ jobs:
|
||||
run: git submodule update --remote --merge
|
||||
|
||||
- name: Run inline review
|
||||
uses: docker://nikitafilonov/ai-review:v1.4.0
|
||||
uses: docker://nikitafilonov/ai-review:v0.77.0
|
||||
with:
|
||||
args: ai-review run-inline
|
||||
|
||||
- name: Run summary review
|
||||
uses: docker://nikitafilonov/ai-review:v1.4.0
|
||||
uses: docker://nikitafilonov/ai-review:v0.77.0
|
||||
with:
|
||||
args: ai-review run-summary
|
||||
|
||||
@@ -4,7 +4,7 @@ terraform {
|
||||
required_providers {
|
||||
azurerm = {
|
||||
source = "hashicorp/azurerm"
|
||||
version = "~> 5.0"
|
||||
version = "~> 4.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,7 +4,7 @@ terraform {
|
||||
required_providers {
|
||||
azurerm = {
|
||||
source = "hashicorp/azurerm"
|
||||
version = "~> 5.0"
|
||||
version = "~> 4.0"
|
||||
}
|
||||
azuread = {
|
||||
source = "hashicorp/azuread"
|
||||
|
||||
@@ -4,7 +4,7 @@ terraform {
|
||||
required_providers {
|
||||
azurerm = {
|
||||
source = "hashicorp/azurerm"
|
||||
version = "~> 5.0"
|
||||
version = "~> 4.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,7 +4,7 @@ terraform {
|
||||
required_providers {
|
||||
azurerm = {
|
||||
source = "hashicorp/azurerm"
|
||||
version = "~> 5.0"
|
||||
version = "~> 4.0"
|
||||
}
|
||||
random = {
|
||||
source = "hashicorp/random"
|
||||
|
||||
@@ -2,7 +2,7 @@ terraform {
|
||||
required_providers {
|
||||
aws = {
|
||||
source = "hashicorp/aws"
|
||||
version = "~> 6.0"
|
||||
version = "~> 5.0"
|
||||
}
|
||||
tls = {
|
||||
source = "hashicorp/tls"
|
||||
|
||||
@@ -2,7 +2,7 @@ terraform {
|
||||
required_providers {
|
||||
aws = {
|
||||
source = "hashicorp/aws"
|
||||
version = "~> 6.0"
|
||||
version = "~> 5.0"
|
||||
}
|
||||
tls = {
|
||||
source = "hashicorp/tls"
|
||||
|
||||
@@ -2,7 +2,7 @@ terraform {
|
||||
required_providers {
|
||||
aws = {
|
||||
source = "hashicorp/aws"
|
||||
version = "~> 6.0"
|
||||
version = "~> 5.0"
|
||||
}
|
||||
tls = {
|
||||
source = "hashicorp/tls"
|
||||
|
||||
@@ -2,7 +2,7 @@ terraform {
|
||||
required_providers {
|
||||
aws = {
|
||||
source = "hashicorp/aws"
|
||||
version = "~> 6.0"
|
||||
version = "~> 5.0"
|
||||
}
|
||||
tls = {
|
||||
source = "hashicorp/tls"
|
||||
|
||||
@@ -29,7 +29,7 @@ spec:
|
||||
topologyKey: kubernetes.io/hostname
|
||||
initContainers:
|
||||
- name: gitea-dump
|
||||
image: gitea/gitea:28.0.0
|
||||
image: gitea/gitea:1.27.3
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
|
||||
@@ -1469,12 +1469,6 @@ ArgoCD will sync the Keycloak config, and the registrar CronJob will pick up the
|
||||
| `k8s.secret.client-id-key` | No | `client-id` | Field name for the client ID in the K8s Secret |
|
||||
| `k8s.secret.client-secret-key` | No | `client-secret` | Field name for the client secret in the K8s Secret |
|
||||
|
||||
#### Public CLI Client (Device-Code Login)
|
||||
|
||||
`forte-cli` is a shared **public** client (no secret) with the RFC 8628 device-authorization grant enabled (`oauth2.device.authorization.grant.enabled: "true"`, `standardFlowEnabled: false`, `directAccessGrantsEnabled: false`). Downloaded skills and CLI tools that log in through the Auth Sidecar (forte-drop first) use it with `<PREFIX>_CLIENT_ID=forte-cli`; nothing per-tool needs to be registered in Keycloak.
|
||||
|
||||
It must be defined in `forte-realm.json` (this legacy path): the self-service registrar hardcodes `publicClient: false` / `standardFlowEnabled: true` and drops `attributes`, so a `client-config` Secret cannot produce a public device-code client. It carries no `k8s.secret.sync` attribute (the registrar's secret sync skips it) and is listed in the cleanup CronJob's protected clients.
|
||||
|
||||
### Retrieving Secrets for External Deployments
|
||||
|
||||
The registrar always writes a **central copy** of every synced secret to the `secrets` namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster:
|
||||
|
||||
@@ -17,7 +17,7 @@ spec:
|
||||
sources:
|
||||
- repoURL: https://fluent.github.io/helm-charts
|
||||
chart: fluent-bit
|
||||
targetRevision: 0.58.3
|
||||
targetRevision: 0.58.2
|
||||
helm:
|
||||
releaseName: fluent-bit
|
||||
valueFiles:
|
||||
|
||||
@@ -24,7 +24,7 @@ spec:
|
||||
sources:
|
||||
- repoURL: https://traefik.github.io/charts
|
||||
chart: traefik
|
||||
targetRevision: "41.6.0"
|
||||
targetRevision: "28.3.0"
|
||||
helm:
|
||||
releaseName: traefik
|
||||
valueFiles:
|
||||
|
||||
@@ -186,35 +186,6 @@ keycloakConfigCli:
|
||||
}
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"clientId": "forte-cli",
|
||||
"name": "Forte CLI",
|
||||
"description": "Shared public client for RFC 8628 device-code login from downloaded skills/CLI tools (forte-drop first) against services behind Auth Sidecar. No client secret.",
|
||||
"enabled": true,
|
||||
"protocol": "openid-connect",
|
||||
"standardFlowEnabled": false,
|
||||
"directAccessGrantsEnabled": false,
|
||||
"publicClient": true,
|
||||
"redirectUris": [],
|
||||
"webOrigins": [],
|
||||
"attributes": {
|
||||
"oauth2.device.authorization.grant.enabled": "true"
|
||||
},
|
||||
"protocolMappers": [
|
||||
{
|
||||
"name": "audience-forte-drop-mcp",
|
||||
"protocol": "openid-connect",
|
||||
"protocolMapper": "oidc-audience-mapper",
|
||||
"consentRequired": false,
|
||||
"config": {
|
||||
"included.custom.audience": "https://mcp.drop.forteapps.net/mcp",
|
||||
"access.token.claim": "true",
|
||||
"id.token.claim": "false",
|
||||
"introspection.token.claim": "true"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
],
|
||||
"browserFlow": "browser-auto-idp",
|
||||
@@ -700,7 +671,7 @@ extraDeploy:
|
||||
MIN_AGE_SEC=$((MIN_AGE_DAYS * 86400))
|
||||
|
||||
# Hardcoded protected clients (never delete these)
|
||||
PROTECTED_JSON='["gitea","grafana","argocd","forte-cli","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]'
|
||||
PROTECTED_JSON='["gitea","grafana","argocd","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]'
|
||||
|
||||
echo "Fetching clients from realm '${REALM}'..."
|
||||
CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \
|
||||
|
||||
@@ -4,12 +4,6 @@ server:
|
||||
service:
|
||||
servicePort: 80
|
||||
|
||||
strategy:
|
||||
type: Recreate
|
||||
|
||||
retention: 7d
|
||||
retentionSize: 6GB
|
||||
|
||||
resources:
|
||||
requests:
|
||||
cpu: 150m
|
||||
@@ -24,7 +18,7 @@ server:
|
||||
|
||||
extraScrapeConfigs: |
|
||||
- job_name: kyverno
|
||||
scrape_interval: 60s
|
||||
scrape_interval: 15s
|
||||
metrics_path: /metrics
|
||||
kubernetes_sd_configs:
|
||||
- role: endpoints
|
||||
@@ -41,16 +35,9 @@ extraScrapeConfigs: |
|
||||
target_label: pod
|
||||
- source_labels: [__meta_kubernetes_namespace]
|
||||
target_label: namespace
|
||||
metric_relabel_configs:
|
||||
- source_labels: [__name__]
|
||||
regex: 'kyverno_(http_requests_duration_seconds|controller_.+_duration_seconds|admission_review_duration_seconds)_bucket'
|
||||
action: drop
|
||||
- source_labels: [__name__]
|
||||
regex: 'go_.*|process_.*'
|
||||
action: drop
|
||||
|
||||
- job_name: traefik
|
||||
scrape_interval: 60s
|
||||
scrape_interval: 15s
|
||||
metrics_path: /metrics
|
||||
kubernetes_sd_configs:
|
||||
- role: endpoints
|
||||
@@ -67,13 +54,6 @@ extraScrapeConfigs: |
|
||||
target_label: pod
|
||||
- source_labels: [__meta_kubernetes_namespace]
|
||||
target_label: namespace
|
||||
metric_relabel_configs:
|
||||
- source_labels: [__name__]
|
||||
regex: 'traefik_(router|service|entrypoint)_request_duration_seconds_bucket'
|
||||
action: drop
|
||||
- source_labels: [__name__]
|
||||
regex: 'go_.*|process_.*'
|
||||
action: drop
|
||||
|
||||
alertmanager:
|
||||
enabled: false
|
||||
|
||||
Reference in New Issue
Block a user