blumeops/argocd/manifests/authentik
Erich Blume b0023fef92 Switch Mealie OIDC to confidential client
Mealie requires OIDC_CLIENT_SECRET even though its docs say "public
client with PKCE". The token exchange happens server-side in Mealie's
Python backend, so the secret never reaches the browser.

- Generate client secret, store in 1Password
- Add to Authentik external-secret and worker env
- Switch blueprint from public to confidential
- Add ExternalSecret for mealie namespace
- Update docs to reflect confidential client

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-16 21:50:34 -07:00
..
configmap-blueprint.yaml Switch Mealie OIDC to confidential client 2026-03-16 21:50:34 -07:00
deployment-redis.yaml Add :kustomized sentinel tag to manifest images, review devpi 2026-03-06 08:15:06 -08:00
deployment-server.yaml Add :kustomized sentinel tag to manifest images, review devpi 2026-03-06 08:15:06 -08:00
deployment-worker.yaml Switch Mealie OIDC to confidential client 2026-03-16 21:50:34 -07:00
external-secret.yaml Switch Mealie OIDC to confidential client 2026-03-16 21:50:34 -07:00
ingress-tailscale.yaml Deploy Authentik identity provider (C2 Mikado) (#227) 2026-02-20 12:55:59 -08:00
kustomization.yaml Deploy authentik 2026.2.0 with migration ordering fix 2026-03-01 16:32:10 -08:00
service-redis.yaml Deploy Authentik identity provider (C2 Mikado) (#227) 2026-02-20 12:55:59 -08:00
service.yaml Deploy Authentik identity provider (C2 Mikado) (#227) 2026-02-20 12:55:59 -08:00