Update Kube API OIDC configuration
This commit is contained in:
		| @@ -36,9 +36,9 @@ patch /etc/kubernetes/manifests/kube-apiserver.yaml - << EOF | ||||
|      - --etcd-certfile=/etc/kubernetes/pki/apiserver-etcd-client.crt | ||||
|      - --etcd-keyfile=/etc/kubernetes/pki/apiserver-etcd-client.key | ||||
|      - --etcd-servers=https://127.0.0.1:2379 | ||||
| +    - --oidc-issuer-url=https://auth.k-space.ee | ||||
| +    - --oidc-issuer-url=https://auth2.k-space.ee/ | ||||
| +    - --oidc-client-id=kubelogin | ||||
| +    - --oidc-username-claim=preferred_username | ||||
| +    - --oidc-username-claim=sub | ||||
| +    - --oidc-groups-claim=groups | ||||
|      - --kubelet-client-certificate=/etc/kubernetes/pki/apiserver-kubelet-client.crt | ||||
|      - --kubelet-client-key=/etc/kubernetes/pki/apiserver-kubelet-client.key | ||||
| @@ -77,8 +77,8 @@ users: | ||||
|       args: | ||||
|       - oidc-login | ||||
|       - get-token | ||||
|       - --oidc-issuer-url=https://auth.k-space.ee | ||||
|       - --oidc-client-id=kubelogin | ||||
|       - --oidc-issuer-url=https://auth2.k-space.ee/ | ||||
|       - --oidc-client-id=oidc-gateway-kubelogin | ||||
|       - --oidc-use-pkce | ||||
|       - --oidc-extra-scope=profile,email,groups | ||||
|       - --listen-address=127.0.0.1:27890 | ||||
|   | ||||
		Reference in New Issue
	
	Block a user