Update k8s/core/argocd/values.yaml
Update Kubernetes Services Wiki / Generate and Update K8s Wiki (push) Successful in 10s
Check with kubeconform / lint (push) Successful in 10s
Auto-update README / Generate README and Create MR (push) Successful in 14s

This commit is contained in:
2026-05-05 17:37:20 +00:00
parent 70b652b079
commit 24218d4d50
+13 -14
View File
@@ -25,7 +25,7 @@ configs:
timeout.reconciliation: 60s timeout.reconciliation: 60s
oidc.config: | oidc.config: |
name: Authentik name: Authentik
issuer: https://idm.hexor.cy/application/o/argocd/ issuer: https://auth.hexor.cy/auth/realms/hexor
clientID: $oidc-creds:id clientID: $oidc-creds:id
clientSecret: $oidc-creds:secret clientSecret: $oidc-creds:secret
requestedScopes: ["openid", "profile", "email", "groups", "offline_access"] requestedScopes: ["openid", "profile", "email", "groups", "offline_access"]
@@ -35,20 +35,19 @@ configs:
create: true create: true
policy.default: "" policy.default: ""
policy.csv: | policy.csv: |
# Bound OIDC Group and internal role g, game-servers-managers, GameServersManagersRole
g, Game Servers Managers, GameServersManagersRole # Role permissions
# Role permissions p, GameServersManagersRole, applications, get, games/*, allow
p, GameServersManagersRole, applications, get, games/*, allow p, GameServersManagersRole, applications, update, games/*, allow
p, GameServersManagersRole, applications, update, games/*, allow p, GameServersManagersRole, applications, sync, games/*, allow
p, GameServersManagersRole, applications, sync, games/*, allow p, GameServersManagersRole, applications, override, games/*, allow
p, GameServersManagersRole, applications, override, games/*, allow p, GameServersManagersRole, applications, action/*, games/*, allow
p, GameServersManagersRole, applications, action/*, games/*, allow p, GameServersManagersRole, exec, create, games/*, allow
p, GameServersManagersRole, exec, create, games/*, allow p, GameServersManagersRole, logs, get, games/*, allow
p, GameServersManagersRole, logs, get, games/*, allow p, GameServersManagersRole, applications, delete, games/*, deny
p, GameServersManagersRole, applications, delete, games/*, deny
# Admin policy # Admin policy
g, ArgoCD Admins, role:admin g, argocd-admins, role:admin
secret: secret:
createSecret: true createSecret: true