1066 Commits

Author SHA1 Message Date
4111fb079f vault: write bound_claims as file 2026-01-14 02:56:29 -03:00
fd2ae6bdd5 vault: wire more services to CSI 2026-01-14 02:54:59 -03:00
8a358832f3 vault: fix oidc scopes parsing 2026-01-14 02:52:51 -03:00
c3541b72c3 vault: run oidc config with sh 2026-01-14 02:28:38 -03:00
55234f8536 vault: align oidc roles with keycloak 2026-01-14 02:24:32 -03:00
50aec198a4 fix: detect vault initialized state correctly 2026-01-14 01:42:28 -03:00
cb5796cb71 fix: make vault k8s auth script posix 2026-01-14 01:38:27 -03:00
5a9ceeab24 fix: run vault k8s auth config with sh 2026-01-14 01:35:06 -03:00
b82195f2d7 feat: start vault consumption for outline and planka 2026-01-14 01:30:41 -03:00
1d894ea80f keycloak: fix harbor oidc job 2026-01-14 01:24:18 -03:00
537d304b36 keycloak: bump harbor oidc job 2026-01-14 01:22:30 -03:00
e776f004c9 keycloak: ensure harbor oidc scope 2026-01-14 01:21:08 -03:00
8fa38268d9 chore: refresh knowledge catalog headers 2026-01-14 01:08:05 -03:00
4a1c4766b8 feat: add harbor/vault oidc automation 2026-01-14 01:07:47 -03:00
bcc15c3e0a monitoring: allow grafana upgrade remediation 2026-01-13 21:18:42 -03:00
0b5dcde3a3 monitoring: align victoria-metrics PVC size 2026-01-13 21:15:10 -03:00
46777f9ec9 comms: restart atlasbot after MAS fixes 2026-01-13 21:09:41 -03:00
98554e5fa4 comms: rerun mas local user seed 2026-01-13 21:06:45 -03:00
b97146f4d1 comms: disable synapse oidc with MAS 2026-01-13 21:04:29 -03:00
928b9379d8 comms: disable synapse password auth with MAS 2026-01-13 21:02:19 -03:00
b710f45e5c comms: fix synapse runtime config injection 2026-01-13 20:59:35 -03:00
e6a3ae5f7b comms: restore MAS and OIDC secrets in synapse 2026-01-13 20:55:36 -03:00
71fd00d845 comms: fix signing key job permissions 2026-01-13 20:49:11 -03:00
fa8ec588a8 comms: add debug logging for signing key job 2026-01-13 20:47:54 -03:00
47f0d1736e comms: retry synapse signing key job 2026-01-13 20:45:14 -03:00
098a06e723 comms: seed synapse signing key for helm 2026-01-13 20:42:30 -03:00
bcef167b50 harbor: enable keycloak oidc settings 2026-01-13 20:42:26 -03:00
fbde129d4c fix(bstein-dev-home): drop invalid image overrides 2026-01-13 20:27:50 -03:00
4332ded0c3 comms: drop legacy synapse configmaps 2026-01-13 20:07:51 -03:00
bbe5ded0a6 comms: bump ensure job names for new images 2026-01-13 20:03:11 -03:00
4602656578 vault: prep helm releases and image pins 2026-01-13 19:29:14 -03:00
07fde43749 platform: move postgres to infrastructure 2026-01-13 17:53:04 -03:00
flux-bot
b09100e787 chore(bstein-dev-home): automated image update 2026-01-13 15:57:24 +00:00
eefaf7df2e merge main into sso-hardening 2026-01-13 12:56:21 -03:00
073b44e0c3 gitea: auto-link oidc accounts 2026-01-13 12:47:41 -03:00
5aeec67bfb postgres: add flux + vault csi 2026-01-13 12:35:59 -03:00
3fc9f7bbdb iac: localize configmap scripts 2026-01-13 12:07:03 -03:00
6da576a707 iac: externalize ConfigMap scripts 2026-01-13 10:00:19 -03:00
flux-bot
17b733c65e chore(bstein-dev-home): automated image update 2026-01-13 12:48:56 +00:00
flux-bot
6d213e5b25 chore(bstein-dev-home): automated image update 2026-01-13 12:47:56 +00:00
flux-bot
b01ac8da25 chore(bstein-dev-home): automated image update 2026-01-13 12:00:52 +00:00
flux-bot
27460f8dc3 chore(bstein-dev-home): automated image update 2026-01-13 11:59:53 +00:00
flux-bot
4d884bfcb1 chore(bstein-dev-home): automated image update 2026-01-13 02:38:08 +00:00
flux-bot
606718459e chore(bstein-dev-home): automated image update 2026-01-13 02:37:08 +00:00
4d6d0b89b2 planka: default users to project owners 2026-01-12 23:24:09 -03:00
35a19a2f7b outline: move to local storage 2026-01-12 23:14:17 -03:00
1a50f51115 planka: enable project owners via oidc 2026-01-12 23:14:17 -03:00
flux-bot
ed9a41bd70 chore(bstein-dev-home): automated image update 2026-01-13 01:58:04 +00:00
flux-bot
e12d020c51 chore(bstein-dev-home): automated image update 2026-01-13 01:57:04 +00:00
5a5766c9b5 planka: avoid mounting over assets 2026-01-12 22:47:23 -03:00