• Joined on 2025-03-24
bstein pushed to feature/sso at bstein/titan-iac 2025-12-09 04:16:13 +00:00
cdbad50c02 zot: fix oidc config keys
bstein pushed to feature/sso at bstein/titan-iac 2025-12-09 02:37:05 +00:00
ea4c04ba04 zot: fix oidc provider map shape
bstein pushed to feature/sso at bstein/titan-iac 2025-12-09 02:25:10 +00:00
dba4d270ff sso: fix vault OIDC bootstrap and render zot oidc config
bstein pushed to feature/sso at bstein/titan-iac 2025-12-07 23:28:57 +00:00
c8254d6eec longhorn/vault: zot oauth2-proxy integration
bstein pushed to feature/sso at bstein/titan-iac 2025-12-07 22:44:27 +00:00
6c62d42f7a longhorn/vault: gate via oauth2-proxy
bstein pushed to feature/sso at bstein/titan-iac 2025-12-07 16:20:06 +00:00
a7e9f1f7d8 auth: remove error middleware to allow redirect
bstein pushed to feature/sso at bstein/titan-iac 2025-12-07 16:09:52 +00:00
ceb692f7ee oauth2-proxy: drop groups scope to avoid invalid_scope
bstein pushed to feature/sso at bstein/titan-iac 2025-12-07 16:03:47 +00:00
24fbaad040 auth: forward-auth via external auth host (svc traffic flaky)
bstein pushed to feature/sso at bstein/titan-iac 2025-12-07 15:50:02 +00:00
04aa32a762 oauth2-proxy: schedule on worker rpis
bstein pushed to feature/sso at bstein/titan-iac 2025-12-07 15:03:35 +00:00
25ee698021 oauth2-proxy: ensure error middleware on auth ingress
bstein pushed to feature/sso at bstein/titan-iac 2025-12-07 14:25:49 +00:00
4a089876ba auth: use internal oauth2-proxy svc for forward-auth
bstein pushed to feature/sso at bstein/titan-iac 2025-12-07 14:14:46 +00:00
20bb776625 auth: add 401 redirect middleware to oauth2-proxy
bstein pushed to feature/sso at bstein/titan-iac 2025-12-07 14:09:31 +00:00
5e59f20bc3 auth: point forward-auth to external auth host
bstein pushed to feature/sso at bstein/titan-iac 2025-12-07 13:42:35 +00:00
dbede55ad4 oauth2-proxy: temporarily drop group restriction
bstein pushed to feature/sso at bstein/titan-iac 2025-12-07 13:26:07 +00:00
27e5c9391c auth: add namespace-local forward-auth middlewares
bstein pushed to feature/sso at bstein/titan-iac 2025-12-07 05:01:37 +00:00
8d5e6c267c auth: wire oauth2-proxy and enable grafana oidc
bstein pushed to feature/sso at bstein/titan-iac 2025-12-06 17:42:49 +00:00
a55502fe27 add oauth2-proxy for SSO forward-auth
bstein pushed to feature/sso at bstein/titan-iac 2025-12-06 04:44:38 +00:00
598bdfc727 keycloak: restrict to worker rpis with titan-24 fallback
bstein pushed to feature/sso at bstein/titan-iac 2025-12-06 04:40:41 +00:00
88c7a1c2aa keycloak: require rpi nodes with titan-24 fallback
bstein pushed to feature/sso at bstein/titan-iac 2025-12-06 04:36:48 +00:00
f4da27271e keycloak: prefer rpi nodes, avoid titan-24