Skip to content

Commit 56f901b

Browse files
committed
fix(auth): forward OPENSHELL_OIDC_SCOPES through cluster bootstrap
Pass --oidc-scopes to gateway start so the metadata includes requested scopes after cluster bootstrap. Without this, users had to manually edit metadata.json to set scopes for gateway login. Usage: OPENSHELL_OIDC_SCOPES="openshell:all" mise run cluster
1 parent c602ab7 commit 56f901b

2 files changed

Lines changed: 18 additions & 10 deletions

File tree

‎architecture/oidc-local-testing.md‎

Lines changed: 17 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -193,9 +193,15 @@ issuer to the Helm chart so the gateway starts with JWT validation enabled.
193193

194194
```bash
195195
HOST_IP=$(hostname -I | awk '{print $1}')
196-
OPENSHELL_OIDC_ISSUER="http://${HOST_IP}:8180/realms/openshell" mise run cluster
196+
OPENSHELL_OIDC_ISSUER="http://${HOST_IP}:8180/realms/openshell" \
197+
OPENSHELL_OIDC_SCOPES="openshell:all" \
198+
mise run cluster
197199
```
198200

201+
Add `OPENSHELL_OIDC_SCOPES_CLAIM="scope"` to also enable scope enforcement.
202+
The `OPENSHELL_OIDC_SCOPES` value is stored in gateway metadata so `gateway login`
203+
requests these scopes automatically.
204+
199205
Wait for "Deploy complete!" and verify OIDC is active:
200206

201207
```bash
@@ -428,18 +434,14 @@ openshell gateway add http://127.0.0.1:8080 \
428434
--oidc-scopes "sandbox:read sandbox:write"
429435
```
430436

431-
Or for K3s testing:
437+
Or for K3s testing, pass `OPENSHELL_OIDC_SCOPES` during bootstrap:
432438

433439
```bash
434440
HOST_IP=$(hostname -I | awk '{print $1}')
435441
OPENSHELL_OIDC_ISSUER="http://${HOST_IP}:8180/realms/openshell" \
436442
OPENSHELL_OIDC_SCOPES_CLAIM="scope" \
443+
OPENSHELL_OIDC_SCOPES="sandbox:read sandbox:write" \
437444
mise run cluster
438-
439-
# Update gateway metadata with scopes
440-
jq '.oidc_scopes = "sandbox:read sandbox:write"' \
441-
~/.config/openshell/gateways/openshell/metadata.json > /tmp/meta.json \
442-
&& mv /tmp/meta.json ~/.config/openshell/gateways/openshell/metadata.json
443445
```
444446

445447
Then login and test:
@@ -454,10 +456,15 @@ openshell provider list # should fail (no provider:read scope)
454456

455457
### 5f. Test openshell:all via CLI
456458

459+
For K3s, restart the cluster with `openshell:all`:
460+
457461
```bash
458-
jq '.oidc_scopes = "openshell:all"' \
459-
~/.config/openshell/gateways/openshell/metadata.json > /tmp/meta.json \
460-
&& mv /tmp/meta.json ~/.config/openshell/gateways/openshell/metadata.json
462+
mise run cluster:stop
463+
HOST_IP=$(hostname -I | awk '{print $1}')
464+
OPENSHELL_OIDC_ISSUER="http://${HOST_IP}:8180/realms/openshell" \
465+
OPENSHELL_OIDC_SCOPES_CLAIM="scope" \
466+
OPENSHELL_OIDC_SCOPES="openshell:all" \
467+
mise run cluster
461468

462469
openshell gateway login
463470
openshell sandbox list # should work

‎tasks/scripts/cluster-bootstrap.sh‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -280,6 +280,7 @@ if [ -n "${OPENSHELL_OIDC_ISSUER:-}" ]; then
280280
[ -n "${OPENSHELL_OIDC_ADMIN_ROLE:-}" ] && DEPLOY_CMD+=(--oidc-admin-role "${OPENSHELL_OIDC_ADMIN_ROLE}")
281281
[ -n "${OPENSHELL_OIDC_USER_ROLE:-}" ] && DEPLOY_CMD+=(--oidc-user-role "${OPENSHELL_OIDC_USER_ROLE}")
282282
[ -n "${OPENSHELL_OIDC_SCOPES_CLAIM:-}" ] && DEPLOY_CMD+=(--oidc-scopes-claim "${OPENSHELL_OIDC_SCOPES_CLAIM}")
283+
[ -n "${OPENSHELL_OIDC_SCOPES:-}" ] && DEPLOY_CMD+=(--oidc-scopes "${OPENSHELL_OIDC_SCOPES}")
283284
fi
284285

285286
"${DEPLOY_CMD[@]}"

0 commit comments

Comments
 (0)