added OIDC

This commit is contained in:
2026-02-18 14:51:15 +01:00
parent 07429800d1
commit 3f84b7ea20
+26 -26
View File
@@ -212,32 +212,32 @@ spec:
# --- Serve at / instead of /guacamole ---
- name: WEBAPP_CONTEXT
value: "ROOT"
# --- OpenID Connect (Authentik) ---
# - name: OPENID_AUTHORIZATION_ENDPOINT
# value: "https://authentik.dooplex.hu/application/o/authorize/"
# - name: OPENID_JWKS_ENDPOINT
# value: "https://authentik.dooplex.hu/application/o/guacamole/jwks/"
# - name: OPENID_ISSUER
# value: "https://authentik.dooplex.hu/application/o/guacamole/"
# - name: OPENID_CLIENT_ID
# valueFrom:
# secretKeyRef:
# name: guacamole-secrets
# key: openid-client-id
# - name: OPENID_REDIRECT_URI
# value: "https://remote.dooplex.hu/"
# - name: OPENID_USERNAME_CLAIM_TYPE
# value: "preferred_username"
# - name: OPENID_GROUPS_CLAIM_TYPE
# value: "groups"
# - name: OPENID_SCOPE
# value: "openid email profile"
# # Show both DB login form AND OIDC button on login page
# - name: EXTENSION_PRIORITY
# value: "*, openid"
# # Auto-create Guacamole accounts for OIDC users
# - name: POSTGRESQL_AUTO_CREATE_ACCOUNTS
# value: "true"
#--- OpenID Connect (Authentik) ---
- name: OPENID_AUTHORIZATION_ENDPOINT
value: "https://authentik.dooplex.hu/application/o/authorize/"
- name: OPENID_JWKS_ENDPOINT
value: "https://authentik.dooplex.hu/application/o/guacamole/jwks/"
- name: OPENID_ISSUER
value: "https://authentik.dooplex.hu/application/o/guacamole/"
- name: OPENID_CLIENT_ID
valueFrom:
secretKeyRef:
name: guacamole-secrets
key: openid-client-id
- name: OPENID_REDIRECT_URI
value: "https://remote.dooplex.hu/"
- name: OPENID_USERNAME_CLAIM_TYPE
value: "preferred_username"
- name: OPENID_GROUPS_CLAIM_TYPE
value: "groups"
- name: OPENID_SCOPE
value: "openid email profile"
# Show both DB login form AND OIDC button on login page
- name: EXTENSION_PRIORITY
value: "*, openid"
# Auto-create Guacamole accounts for OIDC users
- name: POSTGRESQL_AUTO_CREATE_ACCOUNTS
value: "true"
ports:
- containerPort: 8080
name: http