FIX(vault): fix OIDC HMAC secret key name

- Change key name from secret to key
- Fix Vault secret reference
This commit is contained in:
2026-01-02 19:35:00 +09:00
parent e4fb804b3d
commit ef31735060
2 changed files with 14 additions and 3 deletions

View File

@@ -18,11 +18,21 @@ pod:
- name: users-database - name: users-database
configMap: configMap:
name: authelia-config name: authelia-config
- name: oidc-secrets
secret:
secretName: authelia-secrets
items:
- key: HEADLAMP_CLIENT_SECRET
path: HEADLAMP_CLIENT_SECRET
extraVolumeMounts: extraVolumeMounts:
- name: users-database - name: users-database
mountPath: /config/users_database.yml mountPath: /config/users_database.yml
subPath: users_database.yml subPath: users_database.yml
readOnly: true readOnly: true
- name: oidc-secrets
mountPath: /secrets/HEADLAMP_CLIENT_SECRET
subPath: HEADLAMP_CLIENT_SECRET
readOnly: true
# ConfigMap configuration # ConfigMap configuration
configMap: configMap:
@@ -86,7 +96,8 @@ configMap:
clients: clients:
- client_id: headlamp - client_id: headlamp
client_name: Headlamp client_name: Headlamp
client_secret: '$plaintext${{ secret "HEADLAMP_CLIENT_SECRET" }}' client_secret:
path: /secrets/HEADLAMP_CLIENT_SECRET
public: false public: false
authorization_policy: one_factor authorization_policy: one_factor
redirect_uris: redirect_uris:

View File

@@ -32,8 +32,8 @@ spec:
remoteRef: remoteRef:
key: cluster-infrastructure/authelia key: cluster-infrastructure/authelia
property: JWT_HMAC_KEY property: JWT_HMAC_KEY
# OIDC HMAC secret # OIDC HMAC key
- secretKey: identity_providers.oidc.hmac.secret - secretKey: identity_providers.oidc.hmac.key
remoteRef: remoteRef:
key: cluster-infrastructure/authelia key: cluster-infrastructure/authelia
property: OIDC_HMAC_SECRET property: OIDC_HMAC_SECRET