diff --git a/k8s/core/argocd/values.yaml b/k8s/core/argocd/values.yaml index 5ddd666..892361d 100644 --- a/k8s/core/argocd/values.yaml +++ b/k8s/core/argocd/values.yaml @@ -23,14 +23,22 @@ configs: admin.enabled: false statusbadge.enabled: true timeout.reconciliation: 60s - oidc.config: | - name: Keycloak - issuer: https://auth.hexor.cy/auth/realms/hexor - clientID: $oidc-creds:id - clientSecret: $oidc-creds:secret - requestedScopes: ["openid", "profile", "email", "offline_access"] - requestedIDTokenClaims: {"groups": {"essential": true}} - refreshTokenThreshold: 2m + dex.config: | + connectors: + - type: oidc + id: keycloak + name: Keycloak + config: + issuer: https://auth.hexor.cy/auth/realms/hexor + clientID: $oidc-creds:id + clientSecret: $oidc-creds:secret + insecureEnableGroups: true + scopes: + - openid + - profile + - email + - offline_access + getUserInfo: true rbac: create: true policy.default: "" @@ -64,7 +72,7 @@ dex: replicas: 1 nodeSelector: <<: *nodeSelector - enabled: false + enabled: true # Standard Redis disabled because Redis HA is enabled redis: