kubernetes/k8s-peterg/argocd/patches/configmap.yaml

46 lines
1.2 KiB
YAML
Raw Normal View History

---
apiVersion: v1
kind: ConfigMap
metadata:
name: argocd-cm
labels:
app.kubernetes.io/name: argocd-cm
app.kubernetes.io/part-of: argocd
data:
2025-11-10 20:47:47 +01:00
url: https://argocd.peterg.nl
dex.config: |
connectors:
- name: authentik
id: authentik
2025-11-10 14:15:01 +01:00
type: oidc
config:
issuer: $argocd-authentik-provider:dex.authentik.issuer
2025-11-10 20:47:47 +01:00
clientID: $argocd-authentik-provider:dex.authentik.clientID
clientSecret: $argocd-authentik-provider:dex.authentik.clientSecret
insecureEnableGroups: true
scopes:
- openid
- profile
- email
2026-01-29 17:22:11 +01:00
- groups
---
apiVersion: v1
kind: ConfigMap
metadata:
name: argocd-rbac-cm
labels:
app.kubernetes.io/part-of: argocd
data:
policy.default: role:readonly
policy.csv: |
2026-01-29 17:22:11 +01:00
p, role:org-admin, applications, *, */*, allow
p, role:org-admin, clusters, get, *, allow
p, role:org-admin, repositories, get, *, allow
p, role:org-admin, repositories, create, *, allow
p, role:org-admin, repositories, update, *, allow
p, role:org-admin, repositories, delete, *, allow
p, role:org-admin, logs, get, */*, allow
p, role:org-admin, exec, create, */*, allow
2026-01-29 16:38:17 +01:00
g, ArgoCD Admins, role:admin