Fix keycloack url

This commit is contained in:
dvirlabs 2025-05-09 18:51:50 +03:00
parent c1e1b67f10
commit 1633cd8a24

View File

@ -44,6 +44,12 @@ server:
oidc_client_secret="8GWiUqwUZimb4xXHqFNTYCrTkKyc9hrY" \ oidc_client_secret="8GWiUqwUZimb4xXHqFNTYCrTkKyc9hrY" \
default_role="vault-role" default_role="vault-role"
vault policy write oidc-ui-access - <<EOF
path "auth/oidc/role/vault-role" {
capabilities = ["read"]
}
EOF
vault write auth/oidc/role/vault-role \ vault write auth/oidc/role/vault-role \
bound_audiences="vault" \ bound_audiences="vault" \
allowed_redirect_uris="https://vault.dvirlabs.com/ui/vault/auth/oidc/oidc/callback" \ allowed_redirect_uris="https://vault.dvirlabs.com/ui/vault/auth/oidc/oidc/callback" \
@ -51,8 +57,10 @@ server:
groups_claim="groups" \ groups_claim="groups" \
oidc_scopes="profile email groups" \ oidc_scopes="profile email groups" \
policies="default" \ policies="default" \
token_policies="oidc-ui-access" \
ttl="1h" ttl="1h"
env: env:
- name: VAULT_TOKEN - name: VAULT_TOKEN
valueFrom: valueFrom: