blumeops/docs
Erich Blume b0023fef92 Switch Mealie OIDC to confidential client
Mealie requires OIDC_CLIENT_SECRET even though its docs say "public
client with PKCE". The token exchange happens server-side in Mealie's
Python backend, so the secret never reaches the browser.

- Generate client secret, store in 1Password
- Add to Authentik external-secret and worker env
- Switch blueprint from public to confidential
- Add ExternalSecret for mealie namespace
- Update docs to reflect confidential client

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-16 21:50:34 -07:00
..
changelog.d Add Mealie recipe manager service 2026-03-16 21:07:25 -07:00
explanation Update docs: fix mealie storageClass, borgmatic SQLite backups, federated-login 2026-03-16 21:38:36 -07:00
how-to Review operations docs: add last-reviewed dates and improve troubleshooting 2026-03-16 07:38:02 -07:00
reference Switch Mealie OIDC to confidential client 2026-03-16 21:50:34 -07:00
tutorials Restructure docs: consolidate, recategorize, and extract 2026-03-15 19:55:59 -07:00
index.md Fix spider trap: disable SPA mode, remove index files, relax wiki-links (#290) 2026-03-09 11:59:43 -07:00
quartz.config.ts Fix spider trap: disable SPA mode, remove index files, relax wiki-links (#290) 2026-03-09 11:59:43 -07:00
quartz.layout.ts Expose Forgejo publicly at forge.eblu.me (#278) 2026-03-03 08:40:41 -08:00