identity:identity service¶
Wires a module into single sign-on — the OIDC client, its redirect URIs and the groups allowed to use it. Changes are applied at the provider and reloaded; sessions already issued keep working until they expire.
A module that is not published gets no SSO¶
The redirect URI is built from the module's public domain: proxyDomain if it names one, otherwise <vmname>.<environment domain>. An environment need not have a domain — mgmt is the standard internal-only case, its modules reached at <vmname>.<zone>.internal and published nowhere — and then there is no URL a browser could be redirected back to. The service says so and skips, leaving the module on its own login; it does not fail the update of the module that depends on it (#698). identity:accessControl skips on the same fact, and network:proxy has done so since #438.
"Published" deliberately includes a domain the module does not spell out: the proxy publishes an app at <vmname>.<environment domain> whether or not the module sets proxyDomain, so treating a derived domain as "unpublished" would leave a reachable app with forward-auth switched off.
To give an internal module SSO, publish it: set proxyDomain on the module, or give its environment a domains.primary.
One field carrying a whole subsystem¶
identity is a single object holding the module's entire SSO configuration — client id, redirect URIs, group mappings, the lot. Changing any part of it is one drift record on one field, so the converge cannot say what changed and an operator cannot --set one piece without restating the whole object.
It is in-place because the reconcile rewrites the OIDC client at the provider and reloads; sessions already issued keep working until they expire. Recommendation 5 proposes breaking the object into declared sub-fields so drift is legible.
Fields¶
identity:identity owns 1 declared field(s). Each table below carries the field's full definition and, where the service applies it, its ADR-020 change semantics.
identity¶
OIDC integration contract for a module that dependsOn identity:identity (ADR-006). Consumed by services/identity/install-service.sh. Omit for forward-auth modules (those use identity:accessControl).
| Attribute | Value |
|---|---|
| Type | object |
| Default | |
| Required by | (none) |
| Used by | identity:identity |
| Change class | in-place |
| Apply mode | reconcile |
Why this change class. The whole SSO block — provider type, redirect URIs, the groups bound to the application. Re-applying it updates Authentik; sessions already issued keep working, so there is no downtime to authorize.