Add KeyCape client registration for coulomb.social
Idempotent patch of sso/keycape-config with public PKCE client and redirect URIs for local :8008 and production coulomb.social callbacks.
This commit is contained in:
parent
62b1ea3d59
commit
27656916db
2 changed files with 84 additions and 0 deletions
20
sso-mfa/k8s/keycape/register-coulomb-social.sh
Executable file
20
sso-mfa/k8s/keycape/register-coulomb-social.sh
Executable file
|
|
@ -0,0 +1,20 @@
|
|||
#!/usr/bin/env bash
|
||||
# Register coulomb.social as a public KeyCape OIDC client (idempotent).
|
||||
# Never prints Secret values.
|
||||
set -euo pipefail
|
||||
|
||||
NAMESPACE="${KEYCAPE_NAMESPACE:-sso}"
|
||||
SECRET="${KEYCAPE_CONFIG_SECRET:-keycape-config}"
|
||||
KUBECTL="${KUBECTL:-kubectl}"
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
|
||||
"$KUBECTL" get secret "$SECRET" -n "$NAMESPACE" -o json \
|
||||
| python3 "$SCRIPT_DIR/register-coulomb-social.py" \
|
||||
| "$KUBECTL" apply -f -
|
||||
|
||||
echo "Registered coulomb-social client in $NAMESPACE/$SECRET"
|
||||
|
||||
# KeyCape loads config at process start.
|
||||
"$KUBECTL" -n "$NAMESPACE" rollout restart deploy/keycape
|
||||
"$KUBECTL" -n "$NAMESPACE" rollout status deploy/keycape --timeout=120s
|
||||
echo "KeyCape rolled out."
|
||||
Loading…
Add table
Add a link
Reference in a new issue