Add KeyCape client registration for coulomb.social
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Idempotent patch of sso/keycape-config with public PKCE client and
redirect URIs for local :8008 and production coulomb.social callbacks.
This commit is contained in:
tegwick 2026-08-09 01:50:52 +02:00
parent 62b1ea3d59
commit 27656916db
2 changed files with 84 additions and 0 deletions

View file

@ -0,0 +1,20 @@
#!/usr/bin/env bash
# Register coulomb.social as a public KeyCape OIDC client (idempotent).
# Never prints Secret values.
set -euo pipefail
NAMESPACE="${KEYCAPE_NAMESPACE:-sso}"
SECRET="${KEYCAPE_CONFIG_SECRET:-keycape-config}"
KUBECTL="${KUBECTL:-kubectl}"
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
"$KUBECTL" get secret "$SECRET" -n "$NAMESPACE" -o json \
| python3 "$SCRIPT_DIR/register-coulomb-social.py" \
| "$KUBECTL" apply -f -
echo "Registered coulomb-social client in $NAMESPACE/$SECRET"
# KeyCape loads config at process start.
"$KUBECTL" -n "$NAMESPACE" rollout restart deploy/keycape
"$KUBECTL" -n "$NAMESPACE" rollout status deploy/keycape --timeout=120s
echo "KeyCape rolled out."