Story Crater Bot
|
8b4a5ad129
|
fix(forgejo): register Authentik OAuth source via CLI
Root cause: Forgejo OAuth env vars (CLIENT_ID, CLIENT_SECRET, etc.) only
configure the OAuth2 *server*-side settings. The authentication source must
be separately registered in Forgejo's database for the SSO button to appear.
Fixed via gitea CLI:
gitea admin auth add-oauth --name authentik --provider openidConnect \
--key forgejo --secret <from forgejo-oidc secret> \
--auto-discover-url https://authentik.riotpiao.com/application/o/forgejo/.well-known/openid-configuration
Verified: login_source table now has id=1, type=6 (OAuth2), name=authentik
SSO Status across all 4 services:
- ✓ Forgejo: OAuth source registered (this commit)
- ✓ Grafana: auth.generic_oauth enabled + grafana-oidc secret exists
- ✗ MinIO: OIDC env committed but not deployed (needs git push)
- ✓ ArgoCD: oidc.config in argocd-cm ConfigMap
User: rock / Password: ea6b6e161318351933bfd3593914fed7
|
2026-08-18 15:08:03 -07:00 |
|