# Glue: register the secret store's browser UI as an OIDC client wherever # authelia runs. # # ONE PAIRING PER FILE — the store's `oidc` auth method ← authelia, and nothing # else. Deleting this leaves a UI whose OIDC button sends the browser to a # client authelia has never heard of, and nothing mints the secret # `swarm-bao-operator-viewer-policy` waits for. # # ⚠️ Gated on authelia being HERE, and deliberately NOT on this host running # the store, for the reason ./glue-grafana-oidc-client.nix gives: a client is a # row in THIS host's provider config. { lib, config, ... }: let hyperhiveCfg = config.services.hyperhive; deployCfg = hyperhiveCfg.deploy; uiCfg = hyperhiveCfg.swarm.bao.ui; in { config = lib.mkIf deployCfg.authelia.enable { # `kind` is left at its `interactive` default: a person logs in here, and # that kind is what permits the `profile` and `groups` scopes the store's # role asks for. services.hyperhive.swarm.authelia.oidc.clients = [ { id = uiCfg.oidc.clientId; description = "HyperHive secret store UI"; redirectUris = [ uiCfg.oidc.redirectUri ]; } ]; }; }