feat(keycloak): add forte-cli public device-code client #26
Closed
jorgen.stensrud
wants to merge 1 commits from
fm/launchpad-forte-cli into main
pull from: fm/launchpad-forte-cli
merge into: :main
:main
:renovate/prometheus-29.x
:renovate/traefik-41.x
:renovate/aws-6.x
:renovate/google-8.x
:fm/launchpad-forte-cli
:renovate/grafana-10.x
:renovate/kubernetes-monorepo
:feature/forte-prod
:fix/drop-duplicate-keycloak-secret
:feature/dns01
:feat/forte-drop-infra
:feature/ppusher
:feature/chibisafe
:hotfix/backup
:feature/vault-migration
:feature/hashicorp-vault
:feature/homepage
:feature/argocd-rbac
:feature/argocd-tls
:feature/multi-cloud
:feature/karpor
:feature/backstage
:feature/ai-review
:gitea-pages
:feature/gitea-docs
:feature/multicluster
:feature/secret-syncing
:feature/smtp
1
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
d087472e63 |
Add forte-cli public device-code Keycloak client
Add a shared public client `forte-cli` to the `forte` realm so downloaded skills (forte-drop first) can do RFC 8628 device-code login through the Auth Sidecar. Today no client in the realm has the device grant enabled, so the flow cannot start. Client (inline in forte-realm.json, imported verbatim by keycloak-config-cli): - publicClient: true, standardFlowEnabled: false, directAccessGrantsEnabled: false - attributes: oauth2.device.authorization.grant.enabled=true - no secret, no redirectUris/webOrigins, no k8s.secret.sync It has to go in the realm JSON because the self-service registrar hardcodes publicClient:false/standardFlowEnabled:true and drops attributes. Also add forte-cli to the cleanup CronJob's protected list (belt-and-braces; it does not match the UUID pattern anyway). Additive only: gitea/grafana/argocd and all other realm settings are unchanged. Keycloak is deployed only via the upc-dev overlay, which inherits base values, so this lands on id.forteapps.net. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QciXev3MtCxo3eomcfrDRW |