mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add azure oidc PKI auth instead of client secret (#9054)
* feat: add azure oidc PKI auth instead of client secret * add client cert and key as deployment options * Custom token refresher to handle pki auth
This commit is contained in:
+10
@@ -304,9 +304,19 @@ can safely ignore these settings.
|
||||
--oidc-auth-url-params struct[map[string]string], $CODER_OIDC_AUTH_URL_PARAMS (default: {"access_type": "offline"})
|
||||
OIDC auth URL parameters to pass to the upstream provider.
|
||||
|
||||
--oidc-client-cert-file string, $CODER_OIDC_CLIENT_CERT_FILE
|
||||
Pem encoded certificate file to use for oauth2 PKI/JWT authorization.
|
||||
The public certificate that accompanies oidc-client-key-file. A
|
||||
standard x509 certificate is expected.
|
||||
|
||||
--oidc-client-id string, $CODER_OIDC_CLIENT_ID
|
||||
Client ID to use for Login with OIDC.
|
||||
|
||||
--oidc-client-key-file string, $CODER_OIDC_CLIENT_KEY_FILE
|
||||
Pem encoded RSA private key to use for oauth2 PKI/JWT authorization.
|
||||
This can be used instead of oidc-client-secret if your IDP supports
|
||||
it.
|
||||
|
||||
--oidc-client-secret string, $CODER_OIDC_CLIENT_SECRET
|
||||
Client secret to use for Login with OIDC.
|
||||
|
||||
|
||||
+9
@@ -244,6 +244,15 @@ oidc:
|
||||
# Client ID to use for Login with OIDC.
|
||||
# (default: <unset>, type: string)
|
||||
clientID: ""
|
||||
# Pem encoded RSA private key to use for oauth2 PKI/JWT authorization. This can be
|
||||
# used instead of oidc-client-secret if your IDP supports it.
|
||||
# (default: <unset>, type: string)
|
||||
oidcClientKeyFile: ""
|
||||
# Pem encoded certificate file to use for oauth2 PKI/JWT authorization. The public
|
||||
# certificate that accompanies oidc-client-key-file. A standard x509 certificate
|
||||
# is expected.
|
||||
# (default: <unset>, type: string)
|
||||
oidcClientCertFile: ""
|
||||
# Email domains that clients logging in with OIDC must match.
|
||||
# (default: <unset>, type: string-array)
|
||||
emailDomain: []
|
||||
|
||||
Reference in New Issue
Block a user