Skip to content
Snippets Groups Projects
  1. Sep 18, 2022
  2. Jul 24, 2022
    • Evangelos Foutras's avatar
      tf/keycloak: add "Configure OTP" to default actions · 55f20a14
      Evangelos Foutras authored
      When signing into GitLab, opting to create a new keycloak account
      results in being able to sign into GitLab without setting up OTP.
      
      Since any subsequent login will require configuring OTP, it seems
      well advised to prompt for it as part of the registration process.
      Verified
      55f20a14
  3. May 10, 2022
    • Evangelos Foutras's avatar
      tf-stage2: update keycloak provider to 3.8.1 · 2b9e29ca
      Evangelos Foutras authored
      OpenID clients:
      - 'use_refresh_tokens' set to false to preserve the values on live
      - 'backchannel_logout_session_required' implicitly changed to true
        for the 'grafana_openid_client' and 'openid_gitlab' clients
      
      SAML client (GitLab):
      - 'front_channel_logout' set to false to preserve the live setting
      Verified
      2b9e29ca
  4. Apr 05, 2022
  5. Mar 25, 2022
  6. Feb 23, 2022
  7. Jan 21, 2022
    • Jelle van der Waa's avatar
      Add gluebuddy client · 1160eb68
      Jelle van der Waa authored
      The gluebuddy client is required for gluebuddy to retrieve users and
      groups membership without being able to change other keycloak data. The
      realm-management roles cannot be assigned yet via keycloak as it does
      not know about the roles and realm-management client.
      Verified
      1160eb68
  8. Oct 29, 2021
  9. Sep 04, 2021
  10. Jul 07, 2021
    • Evangelos Foutras's avatar
      misc/get_key.py: load vault file without chdir'ing · faba3a3d
      Evangelos Foutras authored
      Now that misc/get_key.py checks if the vault file passed to it exists,
      we cannot pass paths only resolvable from the root directory. Instead,
      use paths that make sense relative to the current directory and avoid
      calling chdir when loading the vault file.
      
      Fixes: 77542146 ("Rewrite get_key.py to use click instead of typer")
      Verified
      faba3a3d
  11. Jul 06, 2021
  12. May 18, 2021
  13. Apr 15, 2021
  14. Apr 08, 2021
    • Jelle van der Waa's avatar
      Restrict Grafana access to DevOps · a434870b
      Jelle van der Waa authored
      As our grafana now contains Loki logs, we don't want non devops to view
      logs which potentially contain sensitive data. As Grafana does not have
      a system to easily restrict data sources to roles we use Keycloak.
      Verified
      a434870b
  15. Mar 19, 2021
  16. Feb 01, 2021
    • Jelle van der Waa's avatar
      Add hedgedoc as new service · 3124cfd9
      Jelle van der Waa authored
      This adds a collaborative markdown editor as newly offered service which
      is available via login for all Arch Linux Staff with an option to allow
      anonymous edits by users (not default). Users are managed via keycloak
      and require the Staff role to be allowed in, non staff keycloak users
      currently will receive an internal server error due to an upstream
      issue.
      Verified
      3124cfd9
  17. Dec 24, 2020
  18. Dec 11, 2020
  19. Dec 10, 2020
  20. Oct 22, 2020
  21. Sep 22, 2020
  22. Sep 10, 2020
    • Jelle van der Waa's avatar
      Add a new Support groups · 76e334c6
      Jelle van der Waa authored
      Expand the Support group with subgroups for the Wiki, Forum, Security
      Tracker and Archweb. The subgroups are just a placeholder for groups for
      the roles which a user can be in for the service. New onboarded users
      should be assigned to correct groups for their Support staff team.
      Verified
      76e334c6
  23. Sep 09, 2020
  24. Sep 08, 2020
  25. Aug 29, 2020
  26. Aug 27, 2020
  27. Aug 20, 2020
  28. Aug 19, 2020
Loading