From c52ff975029ea7cd06e09d50a18b6a21afd50eb9 Mon Sep 17 00:00:00 2001 From: Thore Cimbal Date: Tue, 28 Jul 2026 17:56:09 +0200 Subject: [PATCH] feat(authentik): capture MAS OIDC Provider/Application as a Blueprint Closes issue #36. The OAuth2 Provider ("Matrix Authentication Service") and its Application ("matrix" slug) linking Authentik to MAS were originally clicked together by hand in the UI and existed nowhere as code - unlike the flow fixes already captured in authentik-blueprints.yaml. Losing the Authentik DB would have meant re-creating this from scratch, including a fresh client_secret that MAS would no longer match. The client_secret is read via !Env from AUTHENTIK_MAS_OIDC_CLIENT_SECRET, sourced from a new key in the existing SOPS-encrypted authentik-credentials Secret, rather than inlined into the blueprint ConfigMap (which isn't itself encrypted). Value used is the actual live secret already in use, read directly from the running Authentik DB - not a new/rotated one, so this changes nothing about the current MAS<->Authentik pairing. Co-Authored-By: Claude Sonnet 5 --- apps/authentik/authentik-blueprints.yaml | 55 ++++++++++++++++++++++++ apps/authentik/authentik-secret.yaml | 9 ++-- apps/authentik/authentik.yaml | 9 ++++ 3 files changed, 69 insertions(+), 4 deletions(-) diff --git a/apps/authentik/authentik-blueprints.yaml b/apps/authentik/authentik-blueprints.yaml index 731ad37..73ed5f2 100644 --- a/apps/authentik/authentik-blueprints.yaml +++ b/apps/authentik/authentik-blueprints.yaml @@ -226,3 +226,58 @@ data: domain: authentik-default attrs: default_application: !Find [authentik_core.application, [slug, matrix]] + matrix-oidc-provider.yaml: | + # yaml-language-server: $schema=https://goauthentik.io/blueprints/schema.json + version: 1 + metadata: + name: matrix-oidc-provider + labels: + blueprints.goauthentik.io/instantiate: "true" + entries: + # The OIDC Provider + Application linking Authentik to MAS was originally + # clicked together by hand in the UI and existed nowhere as code (issue + # #36): losing the Authentik DB would have meant re-creating this from + # scratch, including a new client_secret that MAS would then no longer + # match. client_secret is read from AUTHENTIK_MAS_OIDC_CLIENT_SECRET + # (see authentik.yaml HelmRelease values) rather than inlined here, + # since this ConfigMap itself is not SOPS-encrypted - the actual value + # lives in the authentik-credentials Secret instead. + - model: authentik_providers_oauth2.oauth2provider + state: present + identifiers: + name: Matrix Authentication Service + id: matrix_mas_provider + attrs: + client_type: confidential + client_id: dHbTAgAgXvjh3VALh220mB3dxcVXAifiXU2ZO3U6 + client_secret: !Env AUTHENTIK_MAS_OIDC_CLIENT_SECRET + # Path includes MAS's own upstream-provider ID, not Authentik's - + # must match MAS's config exactly or the OIDC callback breaks. + redirect_uris: + - matching_mode: strict + url: https://account.axion1337.chat/upstream/callback/01KQDJTR1ZVTG8JQ220F5BNBFZ + # Stable across username renames - this is what keeps + # upstream_oauth_links rows valid after e.g. the elbojoloco rename. + sub_mode: hashed_user_id + include_claims_in_id_token: true + access_code_validity: minutes=1 + access_token_validity: minutes=5 + signing_key: !Find [authentik_crypto.certificatekeypair, [name, "authentik Self-signed Certificate"]] + authorization_flow: !Find [authentik_flows.flow, [slug, default-provider-authorization-implicit-consent]] + invalidation_flow: !Find [authentik_flows.flow, [slug, default-provider-invalidation-flow]] + property_mappings: + - !Find [authentik_core.propertymapping, [managed, "goauthentik.io/providers/oauth2/scope-openid"]] + - !Find [authentik_core.propertymapping, [managed, "goauthentik.io/providers/oauth2/scope-email"]] + - !Find [authentik_core.propertymapping, [managed, "goauthentik.io/providers/oauth2/scope-profile"]] + + - model: authentik_core.application + state: present + identifiers: + slug: matrix + attrs: + name: aXion1337.chat Accountverwaltung + provider: !KeyOf matrix_mas_provider + meta_description: Matrixclient tailored for aXionCommunity + meta_publisher: aXionGaming + policy_engine_mode: any + open_in_new_tab: false diff --git a/apps/authentik/authentik-secret.yaml b/apps/authentik/authentik-secret.yaml index e35fef9..f754ac7 100644 --- a/apps/authentik/authentik-secret.yaml +++ b/apps/authentik/authentik-secret.yaml @@ -7,10 +7,10 @@ stringData: secret_key: ENC[AES256_GCM,data:yIyQapbFtFM11LynFtkV3ffExhaDfN9QHeFbI1T0xkIhgsV+9sjg3qwMVmeBlAe7xZl8gsAM4kDj2Q6O91OdDg==,iv:+Cl8vOcxG9/mgRheaCO0bLWyCJXN+f1F2DD3oeHbPFY=,tag:711ytyKf6/tmXomBLoffGA==,type:str] pg-password: ENC[AES256_GCM,data:3w8R9mRjMXMJDLjrC8QYaXFHsCU3yYZs2PcaFQNp3Z4=,iv:G/aXgoGz3vBOzZ5K3Y+DDJsqer4F5gvcMmtkzRx93CU=,tag:dXPs1pY/APvnMlxdvB1EkA==,type:str] smtp-password: ENC[AES256_GCM,data:JpMgaQFPkBzOg5WjvpmhM0kPwvZkH+4tQjT17RJHjG14WjmWtfG9Bg==,iv:zjQRLIlrxKv5hbd4JZowNUEiibiCUMf79acZY0+dYAc=,tag:ORPafTPyOQJvVvHWQGmqhA==,type:str] + mas-oidc-client-secret: ENC[AES256_GCM,data:0yx55FroLSxlnuYgfNwczu3PnbPm1kW74JtiU9oFevVqeQDZc385wU6x5X5TN7owXDO7QaOfGTTMvqIpbwQb6Q5Vt1VMToR+0f44oJcktYoTiDFU9Sy6lR/y6nlvBCNqeJg7vIyVpkIqxwqty15EekyqMpkIMp1fT6Pxmek0SO0=,iv:Ey06ljnqbVARDLVt2sLe8R776VEWpTlzI/+Nka5NocA=,tag:I+GNLHz4V8TFa2ijzK5y2Q==,type:str] sops: age: - - recipient: age14l0hwfqylwpemz5y2ghh2yxk0phszlnj3qlejhue0fw0kz3tmfgqdsjzdh - enc: | + - enc: | -----BEGIN AGE ENCRYPTED FILE----- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBRekJuZythYzliTFJ3RlhS R2p6TG9NeFdabFlPRWtpNHJMYVVxTWZEcmlRClk0WUorSzdxNlcyWHYwWFBTMnlq @@ -18,7 +18,8 @@ sops: QXVrY1NTeHZkeTlPRWNlVThzWno3T0kKC0KBoLT64GNqb8Ri9u69G7nqb1KftwwP /24aVHrPxKi9d4ij9n3bvCYDF4rhtfexhrE4n7CfuKn2DcSiuTniuw== -----END AGE ENCRYPTED FILE----- - lastmodified: "2026-04-29T21:43:59Z" - mac: ENC[AES256_GCM,data:Y+dJppkaVZ5NOhlvwbbsF5+vDFqGUI1Ps8IcE4J7FIW4HIdMVf6RKM0EInvPUW1LaBlmelCitcE30w0As7ysNRhLY8yUDaKUvuU6mRejlNUIF8wAHzhciL2jTvAQsArHjybJatEig28+wM9VcY8JEa/d/CmuiB9Nq4WbIV+JXlA=,iv:UQj2rIVLNPjtYp3d/jRyNfJyyyUsZ3+NDCgpI4aztzc=,tag:cwiCzG/A+rfRFfLjXVt82w==,type:str] + recipient: age14l0hwfqylwpemz5y2ghh2yxk0phszlnj3qlejhue0fw0kz3tmfgqdsjzdh encrypted_regex: ^(data|stringData)$ + lastmodified: "2026-07-28T15:54:53Z" + mac: ENC[AES256_GCM,data:P6IF+jukwzldK92nHl6s4h6sS4ldXLwpyLpwv2tpI3vFWgTLEnGCnowi2k5lmWUlITEVmLLC0HvsBuduTiGI2sIHHt+r3RdqkV88HGn6oYDVq5a+Ax7ESfqti/4B7ClQCSxl/tU6hBUFe812DiBXJgA03UJQZn8uHY/dP/RgRpc=,iv:V8sqhbJcKglkKsQmJBdgoxDaCYJ3Wt/qRa18jEviH60=,tag:EiNotrYAKIzKndgjU/kTFQ==,type:str] version: 3.12.2 diff --git a/apps/authentik/authentik.yaml b/apps/authentik/authentik.yaml index 70702f7..0bb264d 100644 --- a/apps/authentik/authentik.yaml +++ b/apps/authentik/authentik.yaml @@ -40,6 +40,15 @@ spec: global: security: allowInsecureImages: true + # Read by the matrix-oidc-provider blueprint via !Env, so the OAuth2 + # Provider's client_secret can be captured as code without ever + # inlining the live credential into a plain (non-SOPS) ConfigMap. + env: + - name: AUTHENTIK_MAS_OIDC_CLIENT_SECRET + valueFrom: + secretKeyRef: + name: authentik-credentials + key: mas-oidc-client-secret authentik: log_level: info