feat(kanidm): declare the forgejo and grafana OAuth2 clients, and generate the entitlements claim #280
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!280
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/275-declare-forgejo-grafana-clients"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Part of #275. All four OAuth2 clients are now declared, so an undeclared client shows up as drift instead of permanent furniture.
The claim maps had drifted from the entitlement model
kanidm_entitlement_claimsent_lfs→lfsent_lfs_large→lfs-largeent_sso_entraent_orgs→orgsmissing from clientent_renovate→renovatemissing from clientThat is the predictable result of "wire the claim-map one-time, see the runbook": the taxonomy moved (#184 removed LFS entitlements; ADR 0029/0036 added groups) and the manual step didn't follow.
So the claim map is now generated from
kanidm_entitlement_claimsrather than restated. Adding an entitlement group can no longer forget its claim, and this drift cannot recur by omission — which matters more than the one-off correction.Checked before changing token contents
forgejo_roleis CONSUMED.roles/forgejo/tasks/oidc-source.yml:74-77creates the auth source with--group-claim-name forgejo_role --admin-group admin. This claim grants Forgejo site-admin, so dropping it would silently demote every admin at next login. Declared explicitly, unchanged.entitlementsis consumed by nothing. Forgejo reads onlyforgejo_role; the portal derives entitlements from Kanidm group SPNs in thegroupsclaim (account-panel.astro:56); the reconciler reads Kanidm over the API. It is write-only in practice — which is precisely what makes adopting the declared model safe rather than a gamble.joinType: array— Kanidm's default and what live carries (the array join renders as;inoauth2 list). Valid values:csv|ssv|array.basicSecretFilestill never emitted.Stated as unverified, deliberately
Whether
removeOrphanedClaimMapsprunes the two stale entries inside the declaredentitlementsclaim. Upstream's orphan logic operates at claim level — it removes claims absent from state — andentitlementsis present, soent_lfs/ent_lfs_largemay survive as group entries.If they do, one command each:
I'm flagging this rather than asserting it because #278 shipped half-fixed on exactly this class of assumption — I took origins' replace-wholesale behaviour as the rule and scope maps turned out additive (#279).
Verification
--syntax-checkandansible-lint roles/kanidm/pass on the production profile.--check --diff --tags kanidmrenders valid JSON withentitlementscarrying all six declared groups andforgejo_roleintact.command, skipped under--check), so the mutations are unverified until applied.Post-apply checks
kanidm system oauth2 get forgejo—forgejo_rolestill mapsforgejo_admins→admin; entitlements list matches the six.ent_lfs/ent_lfs_largesurvived; delete if so.forgejo_rolewere damaged.grafana_admins.