• Joined on 2025-03-24
bstein created branch feature/mailu in bstein/titan-iac 2025-12-12 02:54:51 +00:00
bstein pushed to feature/mailu at bstein/titan-iac 2025-12-12 02:54:51 +00:00
5ef0b4edf6 mailu: capture helm release and cert
bstein pushed to main at bstein/titan-iac 2025-12-11 20:43:37 +00:00
9f226c1584 Merge pull request 'feature/sso' (#4) from feature/sso into main
319b515882 zot: restore main branch config
cb2b2ec1cd zot: revert to unauthenticated registry
20cd185c0b vault: drop traefik basicauth
2f368f6975 zot,vault: remove oauth2-proxy sso
Compare 31 commits »
bstein merged pull request bstein/titan-iac#4 2025-12-11 20:43:36 +00:00
feature/sso
bstein created pull request bstein/titan-iac#4 2025-12-11 20:43:18 +00:00
feature/sso
bstein pushed to feature/sso at bstein/titan-iac 2025-12-11 20:26:24 +00:00
319b515882 zot: restore main branch config
bstein pushed to feature/sso at bstein/titan-iac 2025-12-11 20:22:27 +00:00
cb2b2ec1cd zot: revert to unauthenticated registry
bstein pushed to feature/sso at bstein/titan-iac 2025-12-11 20:09:13 +00:00
20cd185c0b vault: drop traefik basicauth
bstein pushed to feature/sso at bstein/titan-iac 2025-12-11 20:04:28 +00:00
2f368f6975 zot,vault: remove oauth2-proxy sso
bstein pushed to feature/sso at bstein/titan-iac 2025-12-11 17:17:15 +00:00
bstein pushed to feature/sso at bstein/titan-iac 2025-12-11 04:53:46 +00:00
6e26807f21 zot: remove oidc auth to allow anonymous access
bstein pushed to feature/sso at bstein/titan-iac 2025-12-11 04:50:34 +00:00
d5273a3555 zot: temporarily bypass sso and allow open access
bstein pushed to feature/sso at bstein/titan-iac 2025-12-11 04:41:53 +00:00
7f57b286c1 vault: fix middleware reference
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 14:17:19 +00:00
b39db83702 sso: tighten zot and vault oidc flow
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 06:06:29 +00:00
b8817ef0af keycloak: rerun audience scope bootstrap
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 06:03:58 +00:00
f9ec7ab3ae keycloak: add audience scope for oauth2-proxy clients
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 05:56:35 +00:00
1ec2c55e17 vault: ingress via oauth2-proxy with redirect
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 02:18:07 +00:00
9dc3be6cde zot: forward Authorization header to upstream
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 01:35:34 +00:00
6093297b5d vault: route ingress via oauth2-proxy
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 01:32:49 +00:00
d2ee171a70 vault: correct middleware/serverstransport refs