Compare commits
1
Commits
main
..
a4dbe88b30
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a4dbe88b30 |
@@ -23,15 +23,14 @@ jobs:
|
|||||||
REVIEW__INLINE_COMMENT_FALLBACK: "false"
|
REVIEW__INLINE_COMMENT_FALLBACK: "false"
|
||||||
# LLM configuration
|
# LLM configuration
|
||||||
LLM__PROVIDER: CLAUDE
|
LLM__PROVIDER: CLAUDE
|
||||||
LLM__META__MODEL: claude-sonnet-5-5
|
LLM__META__MODEL: claude-3-opus
|
||||||
LLM__META__REASONING__EFFORT: high
|
|
||||||
LLM__META__MAX_TOKENS: "4096"
|
LLM__META__MAX_TOKENS: "4096"
|
||||||
LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com
|
LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com
|
||||||
LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }}
|
LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
uses: actions/checkout@v7
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
submodules: true
|
submodules: true
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
@@ -41,11 +40,11 @@ jobs:
|
|||||||
run: git submodule update --remote --merge
|
run: git submodule update --remote --merge
|
||||||
|
|
||||||
- name: Run inline review
|
- name: Run inline review
|
||||||
uses: docker://nikitafilonov/ai-review:v1.1.0
|
uses: docker://nikitafilonov/ai-review:v0.77.0
|
||||||
with:
|
with:
|
||||||
args: ai-review run-inline
|
args: ai-review run-inline
|
||||||
|
|
||||||
- name: Run summary review
|
- name: Run summary review
|
||||||
uses: docker://nikitafilonov/ai-review:v1.1.0
|
uses: docker://nikitafilonov/ai-review:v0.77.0
|
||||||
with:
|
with:
|
||||||
args: ai-review run-summary
|
args: ai-review run-summary
|
||||||
|
|||||||
@@ -9,7 +9,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v7
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
- name: Install TruffleHog
|
- name: Install TruffleHog
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ terraform {
|
|||||||
required_providers {
|
required_providers {
|
||||||
azurerm = {
|
azurerm = {
|
||||||
source = "hashicorp/azurerm"
|
source = "hashicorp/azurerm"
|
||||||
version = "~> 5.0"
|
version = "~> 4.0"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ terraform {
|
|||||||
required_providers {
|
required_providers {
|
||||||
azurerm = {
|
azurerm = {
|
||||||
source = "hashicorp/azurerm"
|
source = "hashicorp/azurerm"
|
||||||
version = "~> 5.0"
|
version = "~> 4.0"
|
||||||
}
|
}
|
||||||
azuread = {
|
azuread = {
|
||||||
source = "hashicorp/azuread"
|
source = "hashicorp/azuread"
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ terraform {
|
|||||||
required_providers {
|
required_providers {
|
||||||
azurerm = {
|
azurerm = {
|
||||||
source = "hashicorp/azurerm"
|
source = "hashicorp/azurerm"
|
||||||
version = "~> 5.0"
|
version = "~> 4.0"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ terraform {
|
|||||||
required_providers {
|
required_providers {
|
||||||
azurerm = {
|
azurerm = {
|
||||||
source = "hashicorp/azurerm"
|
source = "hashicorp/azurerm"
|
||||||
version = "~> 5.0"
|
version = "~> 4.0"
|
||||||
}
|
}
|
||||||
random = {
|
random = {
|
||||||
source = "hashicorp/random"
|
source = "hashicorp/random"
|
||||||
|
|||||||
@@ -29,7 +29,7 @@ spec:
|
|||||||
topologyKey: kubernetes.io/hostname
|
topologyKey: kubernetes.io/hostname
|
||||||
initContainers:
|
initContainers:
|
||||||
- name: gitea-dump
|
- name: gitea-dump
|
||||||
image: gitea/gitea:28.0.0
|
image: gitea/gitea:1.27.3
|
||||||
command:
|
command:
|
||||||
- sh
|
- sh
|
||||||
- -c
|
- -c
|
||||||
|
|||||||
+3
-3
@@ -2,7 +2,7 @@
|
|||||||
"$schema": "https://raw.githubusercontent.com/jetify-com/devbox/0.16.0/.schema/devbox.schema.json",
|
"$schema": "https://raw.githubusercontent.com/jetify-com/devbox/0.16.0/.schema/devbox.schema.json",
|
||||||
"packages": [
|
"packages": [
|
||||||
"kubectl@1.36.3",
|
"kubectl@1.36.3",
|
||||||
"kubernetes-helm@4.2.4",
|
"kubernetes-helm@3.20.2",
|
||||||
"k9s@0.51.0",
|
"k9s@0.51.0",
|
||||||
"kubeseal@0.38.4",
|
"kubeseal@0.38.4",
|
||||||
"argocd@3.4.6",
|
"argocd@3.4.6",
|
||||||
@@ -14,12 +14,12 @@
|
|||||||
"syft@1.51.0",
|
"syft@1.51.0",
|
||||||
"grype@0.118.0",
|
"grype@0.118.0",
|
||||||
"traefik@3.7.10",
|
"traefik@3.7.10",
|
||||||
"claude-code@2.1.245",
|
"claude-code@0.2.122",
|
||||||
"go@latest",
|
"go@latest",
|
||||||
"dotnet-sdk@8.0.424",
|
"dotnet-sdk@8.0.424",
|
||||||
"opentofu@1.12.5",
|
"opentofu@1.12.5",
|
||||||
"_1password@2.30.0",
|
"_1password@2.30.0",
|
||||||
"github-cli@2.23.0",
|
"github-cli@0.12.0",
|
||||||
"upcloud-cli@3.36.0",
|
"upcloud-cli@3.36.0",
|
||||||
"awscli2@2.35.11"
|
"awscli2@2.35.11"
|
||||||
],
|
],
|
||||||
|
|||||||
@@ -1469,12 +1469,6 @@ ArgoCD will sync the Keycloak config, and the registrar CronJob will pick up the
|
|||||||
| `k8s.secret.client-id-key` | No | `client-id` | Field name for the client ID in the K8s Secret |
|
| `k8s.secret.client-id-key` | No | `client-id` | Field name for the client ID in the K8s Secret |
|
||||||
| `k8s.secret.client-secret-key` | No | `client-secret` | Field name for the client secret in the K8s Secret |
|
| `k8s.secret.client-secret-key` | No | `client-secret` | Field name for the client secret in the K8s Secret |
|
||||||
|
|
||||||
#### Public CLI Client (Device-Code Login)
|
|
||||||
|
|
||||||
`forte-cli` is a shared **public** client (no secret) with the RFC 8628 device-authorization grant enabled (`oauth2.device.authorization.grant.enabled: "true"`, `standardFlowEnabled: false`, `directAccessGrantsEnabled: false`). Downloaded skills and CLI tools that log in through the Auth Sidecar (forte-drop first) use it with `<PREFIX>_CLIENT_ID=forte-cli`; nothing per-tool needs to be registered in Keycloak.
|
|
||||||
|
|
||||||
It must be defined in `forte-realm.json` (this legacy path): the self-service registrar hardcodes `publicClient: false` / `standardFlowEnabled: true` and drops `attributes`, so a `client-config` Secret cannot produce a public device-code client. It carries no `k8s.secret.sync` attribute (the registrar's secret sync skips it) and is listed in the cleanup CronJob's protected clients.
|
|
||||||
|
|
||||||
### Retrieving Secrets for External Deployments
|
### Retrieving Secrets for External Deployments
|
||||||
|
|
||||||
The registrar always writes a **central copy** of every synced secret to the `secrets` namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster:
|
The registrar always writes a **central copy** of every synced secret to the `secrets` namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster:
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ spec:
|
|||||||
sources:
|
sources:
|
||||||
- repoURL: https://fluent.github.io/helm-charts
|
- repoURL: https://fluent.github.io/helm-charts
|
||||||
chart: fluent-bit
|
chart: fluent-bit
|
||||||
targetRevision: 0.58.3
|
targetRevision: 0.58.2
|
||||||
helm:
|
helm:
|
||||||
releaseName: fluent-bit
|
releaseName: fluent-bit
|
||||||
valueFiles:
|
valueFiles:
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ spec:
|
|||||||
sources:
|
sources:
|
||||||
- repoURL: https://opencost.github.io/opencost-helm-chart
|
- repoURL: https://opencost.github.io/opencost-helm-chart
|
||||||
chart: opencost
|
chart: opencost
|
||||||
targetRevision: "2.5.32"
|
targetRevision: "1.43.2"
|
||||||
helm:
|
helm:
|
||||||
releaseName: opencost
|
releaseName: opencost
|
||||||
valueFiles:
|
valueFiles:
|
||||||
|
|||||||
@@ -186,35 +186,6 @@ keycloakConfigCli:
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
|
||||||
{
|
|
||||||
"clientId": "forte-cli",
|
|
||||||
"name": "Forte CLI",
|
|
||||||
"description": "Shared public client for RFC 8628 device-code login from downloaded skills/CLI tools (forte-drop first) against services behind Auth Sidecar. No client secret.",
|
|
||||||
"enabled": true,
|
|
||||||
"protocol": "openid-connect",
|
|
||||||
"standardFlowEnabled": false,
|
|
||||||
"directAccessGrantsEnabled": false,
|
|
||||||
"publicClient": true,
|
|
||||||
"redirectUris": [],
|
|
||||||
"webOrigins": [],
|
|
||||||
"attributes": {
|
|
||||||
"oauth2.device.authorization.grant.enabled": "true"
|
|
||||||
},
|
|
||||||
"protocolMappers": [
|
|
||||||
{
|
|
||||||
"name": "audience-forte-drop-mcp",
|
|
||||||
"protocol": "openid-connect",
|
|
||||||
"protocolMapper": "oidc-audience-mapper",
|
|
||||||
"consentRequired": false,
|
|
||||||
"config": {
|
|
||||||
"included.custom.audience": "https://mcp.drop.forteapps.net/mcp",
|
|
||||||
"access.token.claim": "true",
|
|
||||||
"id.token.claim": "false",
|
|
||||||
"introspection.token.claim": "true"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"browserFlow": "browser-auto-idp",
|
"browserFlow": "browser-auto-idp",
|
||||||
@@ -700,7 +671,7 @@ extraDeploy:
|
|||||||
MIN_AGE_SEC=$((MIN_AGE_DAYS * 86400))
|
MIN_AGE_SEC=$((MIN_AGE_DAYS * 86400))
|
||||||
|
|
||||||
# Hardcoded protected clients (never delete these)
|
# Hardcoded protected clients (never delete these)
|
||||||
PROTECTED_JSON='["gitea","grafana","argocd","forte-cli","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]'
|
PROTECTED_JSON='["gitea","grafana","argocd","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]'
|
||||||
|
|
||||||
echo "Fetching clients from realm '${REALM}'..."
|
echo "Fetching clients from realm '${REALM}'..."
|
||||||
CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \
|
CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \
|
||||||
|
|||||||
+1
-1
Submodule shared-prompts updated: 97057a4436...b79858d73c
Reference in New Issue
Block a user