blob: d9c5cd1ba74ae20ee1bdada025e249473c3af5ea [file] [log] [blame]
Giorgi Lekveishvilicc56ae92023-05-31 17:50:39 +04001{{- $secret := include "clientSecret" . -}}
2apiVersion: hydra.ory.sh/v1alpha1
3kind: OAuth2Client
4metadata:
5 name: headscale
6 namespace: {{ .Release.Namespace }}
7spec:
8 grantTypes:
9 - authorization_code
10 responseTypes:
11 - code
12 scope: "openid profile email"
13 secretName: {{ .Values.oauth2.secretName }}
14 redirectUris:
Giorgi Lekveishvilie390a142023-06-01 11:52:39 +040015 - https://{{ .Values.domain }}/oidc/callback
Giorgi Lekveishvilicc56ae92023-05-31 17:50:39 +040016 hydraAdmin:
17 url: {{ .Values.oauth2.hydraAdmin }}
18 port: 80
Giorgi Lekveishvilie390a142023-06-01 11:52:39 +040019 endpoint: /admin/clients
Giorgi Lekveishvilicc56ae92023-05-31 17:50:39 +040020 forwardedProto: https
Giorgi Lekveishvilie390a142023-06-01 11:52:39 +040021---
22apiVersion: v1
23kind: Secret
24metadata:
25 name: {{ .Values.oauth2.secretName }}
26 namespace: {{ .Release.Namespace }}
27data:
28 client_id: {{ .Values.oauth2.clientId | b64enc}}
29 client_secret: {{ $secret | b64enc }}