|
|
|
@@ -24,31 +24,30 @@ configs:
|
|
|
|
|
statusbadge.enabled: true
|
|
|
|
|
timeout.reconciliation: 60s
|
|
|
|
|
oidc.config: |
|
|
|
|
|
name: Authentik
|
|
|
|
|
issuer: https://idm.hexor.cy/application/o/argocd/
|
|
|
|
|
name: Keycloak
|
|
|
|
|
issuer: https://auth.hexor.cy/auth/realms/hexor
|
|
|
|
|
clientID: $oidc-creds:id
|
|
|
|
|
clientSecret: $oidc-creds:secret
|
|
|
|
|
requestedScopes: ["openid", "profile", "email", "groups", "offline_access"]
|
|
|
|
|
requestedScopes: ["openid", "profile", "email", "offline_access"]
|
|
|
|
|
requestedIDTokenClaims: {"groups": {"essential": true}}
|
|
|
|
|
refreshTokenThreshold: 2m
|
|
|
|
|
rbac:
|
|
|
|
|
create: true
|
|
|
|
|
policy.default: ""
|
|
|
|
|
policy.csv: |
|
|
|
|
|
# Bound OIDC Group and internal role
|
|
|
|
|
g, Game Servers Managers, GameServersManagersRole
|
|
|
|
|
# Role permissions
|
|
|
|
|
p, GameServersManagersRole, applications, get, games/*, allow
|
|
|
|
|
p, GameServersManagersRole, applications, update, games/*, allow
|
|
|
|
|
p, GameServersManagersRole, applications, sync, games/*, allow
|
|
|
|
|
p, GameServersManagersRole, applications, override, games/*, allow
|
|
|
|
|
p, GameServersManagersRole, applications, action/*, games/*, allow
|
|
|
|
|
p, GameServersManagersRole, exec, create, games/*, allow
|
|
|
|
|
p, GameServersManagersRole, logs, get, games/*, allow
|
|
|
|
|
p, GameServersManagersRole, applications, delete, games/*, deny
|
|
|
|
|
|
|
|
|
|
# Admin policy
|
|
|
|
|
g, ArgoCD Admins, role:admin
|
|
|
|
|
g, game-servers-managers, GameServersManagersRole
|
|
|
|
|
# Role permissions
|
|
|
|
|
p, GameServersManagersRole, applications, get, games/*, allow
|
|
|
|
|
p, GameServersManagersRole, applications, update, games/*, allow
|
|
|
|
|
p, GameServersManagersRole, applications, sync, games/*, allow
|
|
|
|
|
p, GameServersManagersRole, applications, override, games/*, allow
|
|
|
|
|
p, GameServersManagersRole, applications, action/*, games/*, allow
|
|
|
|
|
p, GameServersManagersRole, exec, create, games/*, allow
|
|
|
|
|
p, GameServersManagersRole, logs, get, games/*, allow
|
|
|
|
|
p, GameServersManagersRole, applications, delete, games/*, deny
|
|
|
|
|
|
|
|
|
|
# Admin policy
|
|
|
|
|
g, argocd-admins, role:admin
|
|
|
|
|
|
|
|
|
|
secret:
|
|
|
|
|
createSecret: true
|
|
|
|
|