grafana-kanidm-oidc #35
Reference in New Issue
Block a user
Delete Branch "grafana-kanidm-oidc"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Deploy Grafana on monitoring02 with Kanidm OIDC authentication as a test instance (
grafana-test.home.2rjus.net).Changes
New service module (
services/grafana/):adminsgroup → Admin, others → ViewerKanidm OAuth2 client (
services/kanidm/):grafanawith scope maps forusersgroupTerraform:
services/grafana/oauth2-client-secretkanidm01andmonitoring02monitoring02 host:
grafana-testDocumentation updates:
docs/plans/auth-system-replacement.md- OAuth2 client marked complete, key findings documenteddocs/plans/monitoring-migration-victoriametrics.md- Grafana progress noteddocs/user-management.md- OAuth2/OIDC login requirements (email, users group, primary credential)Key Findings
use_pkce = trueemail_attribute_path,login_attribute_path,name_attribute_pathusersgroup membership, email addressTesting
nix develop -c tofu -chdir=terraform/vault apply