Register Zot as OIDC client in Authentik #236
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "register-zot-oidc-client"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
zot.yaml) with OAuth2 provider, application,artifact-workloadsgroup, andzot-ciservice accountzot-client-secretthrough ExternalSecret → worker Deployment env var → blueprint!Envoor7os5kapczgpbwv7obkca4y4)oidc-credentials.json.j2template and deploy task in zot role (withwhenguard)Manual Steps Required Before Deploy
openssl rand -hex 32zot-client-secretto "Authentik (blumeops)" item in vaultblumeopsWhat This Does NOT Do
config.json.j2(that's the root goalharden-zot-registry)wire-ci-registry-auth)Verification
After ArgoCD sync:
https://authentik.ops.eblu.me/application/o/zot/.well-known/openid-configurationreturns valid JSONsuccessfulartifact-workloadsgroup exists withzot-ciservice account🤖 Generated with Claude Code