Upgrade Passmower to 2.3.0 and migrate client compatibility

This commit is contained in:
Erki Aas
2026-09-18 12:29:05 +03:00
parent 4634d25320
commit 3ab70fedae
13 changed files with 186 additions and 161 deletions
+2
View File
@@ -18,8 +18,10 @@ spec:
responseTypes: responseTypes:
- code - code
availableScopes: availableScopes:
- email
- openid - openid
- profile - profile
- groups
pkce: false pkce: false
secretMetadata: secretMetadata:
labels: labels:
+67 -65
View File
@@ -33,75 +33,77 @@ spec:
- refresh_token - refresh_token
responseTypes: responseTypes:
- code - code
# Preserve 1.x email claims for clients whose requests only include profile.
overrideIncomingScopes: true
availableScopes: availableScopes:
- email
- openid - openid
- profile - profile
pkce: false pkce: false
secretRefreshPod: secretRefreshJobSpec:
apiVersion: v1 template:
kind: Pod spec:
spec: volumes:
volumes: - name: tmp
- name: tmp emptyDir: {}
emptyDir: {} initContainers:
initContainers: - name: jq
- name: jq image: mirror.gcr.io/alpine/k8s:1.31.76@sha256:2a3fdd639c71c6cad69fbc8cac2467648855dac29961efec3b155466cc4fa730
image: mirror.gcr.io/alpine/k8s:1.31.76@sha256:2a3fdd639c71c6cad69fbc8cac2467648855dac29961efec3b155466cc4fa730 command:
command: - /bin/bash
- /bin/bash - '-c'
- '-c' - >-
- >- rm -fv /tmp/update.sql; jq
rm -fv /tmp/update.sql; jq '{"name":"oauth.client_id","value":$ENV.OIDC_CLIENT_ID} | "UPDATE
'{"name":"oauth.client_id","value":$ENV.OIDC_CLIENT_ID} | "UPDATE options SET value=\(.value|tostring|@sh) WHERE
options SET value=\(.value|tostring|@sh) WHERE name=\(.name|tostring|@sh) LIMIT 1;"' -n -r >> /tmp/update.sql; jq
name=\(.name|tostring|@sh) LIMIT 1;"' -n -r >> /tmp/update.sql; jq '{"name":"oauth.client_secret","value":$ENV.OIDC_CLIENT_SECRET} |
'{"name":"oauth.client_secret","value":$ENV.OIDC_CLIENT_SECRET} | "UPDATE options SET value=\(.value|tostring|@sh) WHERE
"UPDATE options SET value=\(.value|tostring|@sh) WHERE name=\(.name|tostring|@sh) LIMIT 1;"' -n -r >> /tmp/update.sql; jq
name=\(.name|tostring|@sh) LIMIT 1;"' -n -r >> /tmp/update.sql; jq '{"name":"oauth.auth_url","value":$ENV.OIDC_IDP_AUTH_URI} |
'{"name":"oauth.auth_url","value":$ENV.OIDC_IDP_AUTH_URI} | "UPDATE options SET value=\(.value + "?scope=openid+profile"
"UPDATE options SET value=\(.value + "?scope=openid+profile" |tostring|@sh) WHERE name=\(.name|tostring|@sh) LIMIT 1;"' -n -r
|tostring|@sh) WHERE name=\(.name|tostring|@sh) LIMIT 1;"' -n -r >> /tmp/update.sql; jq
>> /tmp/update.sql; jq '{"name":"oauth.token_url","value":$ENV.OIDC_IDP_TOKEN_URI} |
'{"name":"oauth.token_url","value":$ENV.OIDC_IDP_TOKEN_URI} | "UPDATE options SET value=\(.value|tostring|@sh) WHERE
"UPDATE options SET value=\(.value|tostring|@sh) WHERE name=\(.name|tostring|@sh) LIMIT 1;"' -n -r >> /tmp/update.sql; jq
name=\(.name|tostring|@sh) LIMIT 1;"' -n -r >> /tmp/update.sql; jq '{"name":"oauth.user_url","value":$ENV.OIDC_IDP_USERINFO_URI}
'{"name":"oauth.user_url","value":$ENV.OIDC_IDP_USERINFO_URI} | "UPDATE options SET value=\(.value|tostring|@sh) WHERE
| "UPDATE options SET value=\(.value|tostring|@sh) WHERE name=\(.name|tostring|@sh) LIMIT 1;"' -n -r >> /tmp/update.sql;
name=\(.name|tostring|@sh) LIMIT 1;"' -n -r >> /tmp/update.sql; cat /tmp/update.sql
cat /tmp/update.sql envFrom:
envFrom: - secretRef:
- secretRef: name: oidc-client-freescout-owner-secrets
name: oidc-client-freescout-owner-secrets resources: {}
resources: {} volumeMounts:
volumeMounts: - name: tmp
- name: tmp mountPath: /tmp
mountPath: /tmp terminationMessagePath: /dev/termination-log
terminationMessagePath: /dev/termination-log terminationMessagePolicy: File
terminationMessagePolicy: File imagePullPolicy: IfNotPresent
imagePullPolicy: IfNotPresent containers:
containers: - name: mysql
- name: mysql image: mirror.gcr.io/library/mysql:latest
image: mirror.gcr.io/library/mysql:latest command:
command: - /bin/bash
- /bin/bash - '-c'
- '-c' - >-
- >- mysql -u freescout freescout -h mariadb
mysql -u freescout freescout -h mariadb -p${MYSQL_PWD} < /tmp/update.sql
-p${MYSQL_PWD} < /tmp/update.sql env:
env: - name: MYSQL_PWD
- name: MYSQL_PWD valueFrom:
valueFrom: secretKeyRef:
secretKeyRef: name: mariadb-secrets
name: mariadb-secrets key: MYSQL_PASSWORD
key: MYSQL_PASSWORD resources: {}
resources: {} volumeMounts:
volumeMounts: - name: tmp
- name: tmp mountPath: /tmp
mountPath: /tmp terminationMessagePath: /dev/termination-log
terminationMessagePath: /dev/termination-log terminationMessagePolicy: File
terminationMessagePolicy: File imagePullPolicy: IfNotPresent
imagePullPolicy: IfNotPresent restartPolicy: OnFailure
restartPolicy: OnFailure
--- ---
apiVersion: networking.k8s.io/v1 apiVersion: networking.k8s.io/v1
kind: Ingress kind: Ingress
+39 -40
View File
@@ -76,50 +76,49 @@ spec:
responseTypes: responseTypes:
- code - code
availableScopes: availableScopes:
- email
- openid - openid
- profile - profile
overrideIncomingScopes: true overrideIncomingScopes: true
pkce: false pkce: false
secretRefreshPod: secretRefreshJobSpec:
apiVersion: v1 template:
kind: Pod spec:
metadata: restartPolicy: OnFailure
name: reset-oidc-config volumes:
spec: - name: tmp
volumes: emptyDir: {}
- name: tmp initContainers:
emptyDir: {} - name: jq
initContainers: image: mirror.gcr.io/alpine/k8s:1.31.76@sha256:2a3fdd639c71c6cad69fbc8cac2467648855dac29961efec3b155466cc4fa730
- name: jq imagePullPolicy: IfNotPresent
image: mirror.gcr.io/alpine/k8s:1.31.76@sha256:2a3fdd639c71c6cad69fbc8cac2467648855dac29961efec3b155466cc4fa730 volumeMounts:
imagePullPolicy: IfNotPresent - mountPath: /tmp
volumeMounts: name: tmp
- mountPath: /tmp envFrom:
name: tmp - secretRef:
envFrom: name: oidc-client-gitea-owner-secrets
- secretRef: command:
name: oidc-client-gitea-owner-secrets - /bin/bash
command: - -c
- /bin/bash - jq '{"strategyKey":"OpenID","config":{"Provider":"openidConnect","ClientID":$ENV.OIDC_CLIENT_ID,"ClientSecret":$ENV.OIDC_CLIENT_SECRET,"OpenIDConnectAutoDiscoveryURL":"https://auth.k-space.ee/.well-known/openid-configuration","CustomURLMapping":null,"IconURL":"","Scopes":null,"RequiredClaimName":"","RequiredClaimValue":"","GroupClaimName":"","AdminGroup":"","GroupTeamMap":"","GroupTeamMapRemoval":false,"RestrictedGroup":""}} | "UPDATE login_source SET cfg=\(.config|tostring|@sh) WHERE name=\(.strategyKey|tostring|@sh) LIMIT 1"' -n -r > /tmp/update.sql
- -c containers:
- jq '{"strategyKey":"OpenID","config":{"Provider":"openidConnect","ClientID":$ENV.OIDC_CLIENT_ID,"ClientSecret":$ENV.OIDC_CLIENT_SECRET,"OpenIDConnectAutoDiscoveryURL":"https://auth.k-space.ee/.well-known/openid-configuration","CustomURLMapping":null,"IconURL":"","Scopes":null,"RequiredClaimName":"","RequiredClaimValue":"","GroupClaimName":"","AdminGroup":"","GroupTeamMap":"","GroupTeamMapRemoval":false,"RestrictedGroup":""}} | "UPDATE login_source SET cfg=\(.config|tostring|@sh) WHERE name=\(.strategyKey|tostring|@sh) LIMIT 1"' -n -r > /tmp/update.sql - name: mysql
containers: image: mirror.gcr.io/library/mysql:latest
- name: mysql imagePullPolicy: IfNotPresent
image: mirror.gcr.io/library/mysql:latest volumeMounts:
imagePullPolicy: IfNotPresent - mountPath: /tmp
volumeMounts: name: tmp
- mountPath: /tmp env:
name: tmp - name: MYSQL_PWD
env: valueFrom:
- name: MYSQL_PWD secretKeyRef:
valueFrom: name: mariadb-secrets
secretKeyRef: key: MYSQL_PASSWORD
name: mariadb-secrets command:
key: MYSQL_PASSWORD - /bin/bash
command: - -c
- /bin/bash - mysql -u gitea gitea -h mariadb -p${MYSQL_PWD} < /tmp/update.sql
- -c
- mysql -u gitea gitea -h mariadb -p${MYSQL_PWD} < /tmp/update.sql
--- ---
apiVersion: apps/v1 apiVersion: apps/v1
kind: StatefulSet kind: StatefulSet
+3
View File
@@ -15,7 +15,10 @@ spec:
- refresh_token - refresh_token
responseTypes: responseTypes:
- code - code
# Preserve 1.x email claims for clients whose requests only include profile.
overrideIncomingScopes: true
availableScopes: availableScopes:
- email
- openid - openid
- profile - profile
- groups - groups
+3
View File
@@ -12,7 +12,10 @@ spec:
- 'refresh_token' - 'refresh_token'
responseTypes: responseTypes:
- 'code' - 'code'
# Preserve 1.x email claims for clients whose requests only include profile.
overrideIncomingScopes: true
availableScopes: availableScopes:
- email
- 'openid' - 'openid'
- 'profile' - 'profile'
- 'groups' - 'groups'
+3
View File
@@ -16,7 +16,10 @@ spec:
- refresh_token - refresh_token
responseTypes: responseTypes:
- code - code
# Preserve 1.x email claims for clients whose requests only include profile.
overrideIncomingScopes: true
availableScopes: availableScopes:
- email
- openid - openid
- profile - profile
pkce: false pkce: false
+3
View File
@@ -54,7 +54,10 @@ spec:
- refresh_token - refresh_token
responseTypes: responseTypes:
- code - code
# Preserve 1.x email claims for clients whose requests only include profile.
overrideIncomingScopes: true
availableScopes: availableScopes:
- email
- openid - openid
- profile - profile
pkce: false pkce: false
+3
View File
@@ -15,7 +15,10 @@ spec:
- refresh_token - refresh_token
responseTypes: responseTypes:
- code - code
# Preserve 1.x email claims for clients whose requests only include profile.
overrideIncomingScopes: true
availableScopes: availableScopes:
- email
- openid - openid
- profile - profile
tokenEndpointAuthMethod: none tokenEndpointAuthMethod: none
+1 -1
View File
@@ -11,7 +11,7 @@ helmCharts:
releaseName: *name releaseName: *name
repo: oci://ghcr.io/passmower/charts repo: oci://ghcr.io/passmower/charts
valuesFile: values.yaml valuesFile: values.yaml
version: 1.3.0 version: 2.3.0
resources: resources:
- ssh://git@git.k-space.ee/secretspace/kube/passmower # secrets: email-credentials, github-client, slack-client - ssh://git@git.k-space.ee/secretspace/kube/passmower # secrets: email-credentials, github-client, slack-client
+3
View File
@@ -28,7 +28,10 @@ spec:
- refresh_token - refresh_token
responseTypes: responseTypes:
- code - code
# Preserve 1.x email claims for clients whose requests only include profile.
overrideIncomingScopes: true
availableScopes: availableScopes:
- email
- openid - openid
- profile - profile
--- ---
+15 -15
View File
@@ -6,34 +6,34 @@ passmower:
# Hostname on which Passmower will be deployed to. Will be used as ingress host. # Hostname on which Passmower will be deployed to. Will be used as ingress host.
host: "auth.k-space.ee" host: "auth.k-space.ee"
# Local groups will be created with given prefix. # Local groups will be created with given prefix.
group_prefix: 'k-space' groupPrefix: 'k-space'
# Local or remote group which members will automatically become admins. # Local or remote group which members will automatically become admins.
admin_group: 'k-space:onboarding' adminGroup: 'k-space:onboarding'
# If set, require all users to be member of the given local or remote group. # If set, require all users to be member of the given local or remote group.
# required_group: "" # required_group: ""
# GitHub organization to pull groups from. Set to keep users other organizations private from Passmower. # GitHub organization to pull groups from. Set to keep users other organizations private from Passmower.
github_organization: "codemowers" githubOrganization: "codemowers"
# Allow enrolling new users automatically. Actual access will be based on required_group parameter. Disable to only manually provision users. # Allow enrolling new users automatically. Actual access will be based on required_group parameter. Disable to only manually provision users.
enroll_users: false enrollUsers: false
# Disable making changes to users on their profile or via admin panel - use for enforcing GitOps practices via OIDCUser spec. # Disable making changes to users on their profile or via admin panel - use for enforcing GitOps practices via OIDCUser spec.
disable_frontend_edit: true disableFrontendEdit: true
# Comma-separated, wildcard enabled namespace selector to select, in which namespaces Passmower looks for client CRDs. # Comma-separated, wildcard enabled namespace selector to select, in which namespaces Passmower looks for client CRDs.
namespace_selector: "*" namespaceSelector: "*"
# Domain which will be preferred for determining primary emails. # Domain which will be preferred for determining primary emails.
preferred_email_domain: 'k-space.ee' preferredEmailDomain: 'k-space.ee'
# Require users to set a custom username instead of system generated one. Will be used as OIDCUser CRD name and OIDC username claim. # Require users to set a custom username instead of system generated one. Will be used as OIDCUser CRD name and OIDC username claim.
require_custom_username: true usernameSource: prompt
# Normalize incoming email addresses by removing aliases (e.g. username+alias@gmail.com) etc. # Normalize incoming email addresses by removing aliases (e.g. username+alias@gmail.com) etc.
normalize_email_addresses: false # makes members unable to login due to e-mail being stored unnormalized in user oidc crd. Normalizing it by force has had regressions elsewhere. normalizeEmailAddresses: false # makes members unable to login due to e-mail being stored unnormalized in user oidc crd. Normalizing it by force has had regressions elsewhere.
# Email credentials secret name. Secret must contain EMAIL_HOST, EMAIL_PASSWORD, EMAIL_PORT, EMAIL_SSL and EMAIL_USERNAME # Email credentials secret name. Secret must contain EMAIL_HOST, EMAIL_PASSWORD, EMAIL_PORT, EMAIL_SSL and EMAIL_USERNAME
email_credentials_secretRef: "email-credentials" emailCredentialsSecretRef: "email-credentials"
# GitHub OAuth client secret name. Secret must contain GH_CLIENT_ID and GH_CLIENT_SECRET # GitHub OAuth client secret name. Secret must contain GH_CLIENT_ID and GH_CLIENT_SECRET
github_client_secretRef: "github-client" githubClientSecretRef: "github-client"
# Generic OIDC upstream login providers. Each provider's credentials secret must # Generic OIDC upstream login providers. Each provider's credentials secret must
# contain <KEY>_CLIENT_ID and <KEY>_CLIENT_SECRET. Callback path is # contain <KEY>_CLIENT_ID and <KEY>_CLIENT_SECRET. Callback path is
# /interaction/callback/<key>. Provider appears once its secret is present. # /interaction/callback/<key>. Provider appears once its secret is present.
oidcProviders: oidcProviders:
- key: codeberg codeberg:
displayName: Codeberg displayName: Codeberg
issuer: https://codeberg.org issuer: https://codeberg.org
# Secret must contain CODEBERG_CLIENT_ID and CODEBERG_CLIENT_SECRET # Secret must contain CODEBERG_CLIENT_ID and CODEBERG_CLIENT_SECRET
@@ -41,7 +41,7 @@ passmower:
groupsClaim: groups groupsClaim: groups
icon: '<svg viewBox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"><path fill="#2185D0" d="M11.955.49A12 12 0 0 0 0 12.49a12 12 0 0 0 1.832 6.373L11.838 5.928a.187.14 0 0 1 .324 0l10.006 12.935A12 12 0 0 0 24 12.49a12 12 0 0 0-12-12 12 12 0 0 0-.045 0zm.375 6.467 4.416 17.043a12 12 0 0 0 5.137-4.213L12.516 7.008a.187.14 0 0 0-.186-.05z"/></svg>' icon: '<svg viewBox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"><path fill="#2185D0" d="M11.955.49A12 12 0 0 0 0 12.49a12 12 0 0 0 1.832 6.373L11.838 5.928a.187.14 0 0 1 .324 0l10.006 12.935A12 12 0 0 0 24 12.49a12 12 0 0 0-12-12 12 12 0 0 0-.045 0zm.375 6.467 4.416 17.043a12 12 0 0 0 5.137-4.213L12.516 7.008a.187.14 0 0 0-.186-.05z"/></svg>'
# Slack API client secret name. Secret must contain SLACK_TOKEN # Slack API client secret name. Secret must contain SLACK_TOKEN
slack_client_secretRef: "slack-client" slackClientSecretRef: "slack-client"
# Different texts displayed and sent to the user # Different texts displayed and sent to the user
texts: texts:
approval: approval:
@@ -50,10 +50,10 @@ passmower:
emails: emails:
configMapRef: configMapRef:
name: passmower-email-templates name: passmower-email-templates
terms_of_service: termsOfService:
configMapRef: configMapRef:
name: passmower-tos name: passmower-tos
disable_frontend_edit: disableFrontendEdit:
content: "Edit users via [the members repo](https://git.k-space.ee/k-space/members). The repository is automatically synced to cluster via [ArgoCD](https://argocd.k-space.ee/applications/argocd/members?view=tree&resource=)" content: "Edit users via [the members repo](https://git.k-space.ee/k-space/members). The repository is automatically synced to cluster via [ArgoCD](https://argocd.k-space.ee/applications/argocd/members?view=tree&resource=)"
+41 -40
View File
@@ -15,52 +15,53 @@ spec:
- refresh_token - refresh_token
responseTypes: responseTypes:
- code - code
# Preserve 1.x email claims for clients whose requests only include profile.
overrideIncomingScopes: true
availableScopes: availableScopes:
- email
- openid - openid
- profile - profile
- groups - groups
tokenEndpointAuthMethod: client_secret_post tokenEndpointAuthMethod: client_secret_post
pkce: false pkce: false
secretRefreshPod: secretRefreshJobSpec:
apiVersion: v1 template:
kind: Pod spec:
metadata: restartPolicy: OnFailure
name: reset-oidc-config volumes:
spec: - name: tmp
volumes: emptyDir: {}
- name: tmp initContainers:
emptyDir: {} - name: jq
initContainers: image: mirror.gcr.io/alpine/k8s:1.35.0
- name: jq imagePullPolicy: IfNotPresent
image: mirror.gcr.io/alpine/k8s:1.35.0 volumeMounts:
imagePullPolicy: IfNotPresent - mountPath: /tmp
volumeMounts: name: tmp
- mountPath: /tmp envFrom:
name: tmp - secretRef:
envFrom: name: oidc-client-wiki-owner-secrets
- secretRef: command:
name: oidc-client-wiki-owner-secrets - /bin/sh
command: - -c
- /bin/sh - jq '{"strategyKey":"oidc","config":{"clientId":$ENV.OIDC_CLIENT_ID,"clientSecret":$ENV.OIDC_CLIENT_SECRET,"authorizationURL":$ENV.OIDC_IDP_AUTH_URI,"tokenURL":$ENV.OIDC_IDP_TOKEN_URI,"userInfoURL":$ENV.OIDC_IDP_USERINFO_URI,"skipUserProfile":false,"issuer":$ENV.OIDC_IDP_URI,"emailClaim":"email","displayNameClaim":"name","mapGroups":true,"groupsClaim":"groups","logoutURL":$ENV.OIDC_IDP_URI,"acrValues":""}} | "UPDATE authentication SET config=\(.config|tostring|@sh) WHERE \"strategyKey\"=\(.strategyKey|tostring|@sh)"' -n -r > /tmp/update.sql
- -c containers:
- jq '{"strategyKey":"oidc","config":{"clientId":$ENV.OIDC_CLIENT_ID,"clientSecret":$ENV.OIDC_CLIENT_SECRET,"authorizationURL":$ENV.OIDC_IDP_AUTH_URI,"tokenURL":$ENV.OIDC_IDP_TOKEN_URI,"userInfoURL":$ENV.OIDC_IDP_USERINFO_URI,"skipUserProfile":false,"issuer":$ENV.OIDC_IDP_URI,"emailClaim":"email","displayNameClaim":"name","mapGroups":true,"groupsClaim":"groups","logoutURL":$ENV.OIDC_IDP_URI,"acrValues":""}} | "UPDATE authentication SET config=\(.config|tostring|@sh) WHERE \"strategyKey\"=\(.strategyKey|tostring|@sh)"' -n -r > /tmp/update.sql - name: psql
containers: image: mirror.gcr.io/alpine/psql
- name: psql imagePullPolicy: IfNotPresent
image: mirror.gcr.io/alpine/psql volumeMounts:
imagePullPolicy: IfNotPresent - mountPath: /tmp
volumeMounts: name: tmp
- mountPath: /tmp env:
name: tmp - name: PGPASSWORD
env: valueFrom:
- name: PGPASSWORD secretKeyRef:
valueFrom: name: postgres-appuser-password
secretKeyRef: key: password
name: postgres-appuser-password command:
key: password - /bin/sh
command: - -c
- /bin/sh - psql -U kspace_wiki -d wiki -h postgres < /tmp/update.sql
- -c
- psql -U kspace_wiki -d wiki -h postgres < /tmp/update.sql
--- ---
apiVersion: apps/v1 apiVersion: apps/v1
kind: StatefulSet kind: StatefulSet
+3
View File
@@ -26,7 +26,10 @@ spec:
- "refresh_token" - "refresh_token"
responseTypes: responseTypes:
- "code" - "code"
# Preserve 1.x email claims for clients whose requests only include profile.
overrideIncomingScopes: true
availableScopes: availableScopes:
- email
- "openid" - "openid"
- "profile" - "profile"
- "offline_access" - "offline_access"