• Joined on 2025-03-24
bstein pushed to feature/sso at bstein/titan-iac 2025-12-11 04:53:46 +00:00
6e26807f21 zot: remove oidc auth to allow anonymous access
bstein pushed to feature/sso at bstein/titan-iac 2025-12-11 04:50:34 +00:00
d5273a3555 zot: temporarily bypass sso and allow open access
bstein pushed to feature/sso at bstein/titan-iac 2025-12-11 04:41:53 +00:00
7f57b286c1 vault: fix middleware reference
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 14:17:19 +00:00
b39db83702 sso: tighten zot and vault oidc flow
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 06:06:29 +00:00
b8817ef0af keycloak: rerun audience scope bootstrap
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 06:03:58 +00:00
f9ec7ab3ae keycloak: add audience scope for oauth2-proxy clients
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 05:56:35 +00:00
1ec2c55e17 vault: ingress via oauth2-proxy with redirect
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 02:18:07 +00:00
9dc3be6cde zot: forward Authorization header to upstream
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 01:35:34 +00:00
6093297b5d vault: route ingress via oauth2-proxy
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 01:32:49 +00:00
d2ee171a70 vault: correct middleware/serverstransport refs
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 00:19:43 +00:00
bc9abd38f0 vault: reference namespace-qualified middleware
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 00:17:53 +00:00
190e452869 vault: tighten redirect regex
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 00:16:24 +00:00
a360f9ce83 vault: use local middleware reference
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 00:14:37 +00:00
a4da1c1abb vault: fix traefik middleware references
bstein pushed to feature/sso at bstein/titan-iac 2025-12-10 00:07:24 +00:00
8b22c707fb vault: send ingress directly to vault with oidc redirect
bstein pushed to feature/sso at bstein/titan-iac 2025-12-09 23:49:36 +00:00
9d6881725a zot: align oidc client to oauth2-proxy; add vault redirect
bstein pushed to feature/sso at bstein/titan-iac 2025-12-09 22:07:31 +00:00
8f9f6dd5b3 vault: route ingress through oauth2-proxy
bstein pushed to feature/sso at bstein/titan-iac 2025-12-09 22:04:36 +00:00
129f5d6415 vault: fix traefik namespace prefixes
bstein pushed to feature/sso at bstein/titan-iac 2025-12-09 22:01:00 +00:00
fdd275c446 keycloak: fix oauth2-proxy redirect bootstrap job
bstein pushed to feature/sso at bstein/titan-iac 2025-12-09 21:53:31 +00:00
59ee37a3b5 keycloak: bootstrap oauth2-proxy redirect URIs