fix: pin Jenkins OIDC realm via JCasC

This commit is contained in:
Brad Stein 2025-12-16 20:04:21 -03:00
parent fc858fc8df
commit 162fe3339f

View File

@ -130,6 +130,23 @@ spec:
}
JCasC:
configScripts:
security.yaml: |
jenkins:
securityRealm:
oic:
clientId: "${OIDC_CLIENT_ID}"
clientSecret: "${OIDC_CLIENT_SECRET}"
wellKnownOpenIDConfigurationUrl: "${OIDC_ISSUER}/.well-known/openid-configuration"
scopes: "openid profile email"
userNameField: "preferred_username"
fullNameFieldName: "name"
emailFieldName: "email"
groupsFieldName: "groups"
logoutFromOpenidProvider: true
rootURLFromRequest: true
authorizationStrategy:
loggedInUsersCanDoAnything:
allowAnonymousRead: false
creds.yaml: |
credentials:
system: