blumeops/argocd/manifests/authentik
Erich Blume 6576880b0e heph Authentik: register heph-pwa redirect URIs (PKCE login) (#370)
Adds the heph-pwa redirect URIs to the Authentik `heph` OAuth2 provider so the new browser **Login with Authentik** flow (Authorization Code + PKCE, hephaestus PR #9) can redirect back and exchange the code:

- `https://heph.ops.eblu.me/` (the PWA origin)
- `http://localhost:8787/` (local dev: `hephd --web-root`)

Authentik also keys token-endpoint CORS off these origins, so they're required for the browser token exchange. Additive (the provider was `redirect_uris: []`); harmless until the PWA feature deploys.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Reviewed-on: #370
2026-06-05 07:30:31 -07:00
..
configmap-blueprint.yaml heph Authentik: register heph-pwa redirect URIs (PKCE login) (#370) 2026-06-05 07:30:31 -07:00
deployment-redis.yaml Add :kustomized sentinel tag to manifest images, review devpi 2026-03-06 08:15:06 -08:00
deployment-server.yaml Add :kustomized sentinel tag to manifest images, review devpi 2026-03-06 08:15:06 -08:00
deployment-worker.yaml C0: remove argocd OIDC client_secret wiring 2026-04-21 10:38:26 -07:00
external-secret.yaml C0: remove argocd OIDC client_secret wiring 2026-04-21 10:38:26 -07:00
ingress-tailscale.yaml Deploy Authentik identity provider (C2 Mikado) (#227) 2026-02-20 12:55:59 -08:00
kustomization.yaml Deploy authentik 2026.2.2 container to ringtail 2026-04-08 10:56:50 -07:00
service-redis.yaml Deploy Authentik identity provider (C2 Mikado) (#227) 2026-02-20 12:55:59 -08:00
service.yaml Deploy Authentik identity provider (C2 Mikado) (#227) 2026-02-20 12:55:59 -08:00