# gitlab-oidc-secret was a manually kubectl-created plain Secret (never # git-tracked, never rotatable, no record of what it was) - found and # fixed 2026-08-20 alongside infrastructure/authentik/gitlab-blueprint.yaml # (same value, same Vault path - see that file for the full story). # # `provider` key added 2026-08-21: found live that GITLAB_OMNIBUS_CONFIG's # `gitlab_rails['omniauth_providers'] = [...]` (still set in this app's # values.yaml's extraEnv, for reference/documentation only at this point) # is an omnibus-image-only convention - the CNG webservice image this # chart actually runs never processes it, so it was always a no-op and # GitLab never had SSO configured despite it looking configured. The # REAL mechanism (gitlab/charts/gitlab/templates/_omniauth.tpl in the # chart) is global.appConfig.omniauth.providers: a list of # {secret, key} refs, each pointing at a Secret key whose value is a # whole YAML-encoded provider block (loaded via Ruby's YAML.load_file # at container start, baked into gitlab.yml) - not raw client_id/secret # strings. This is also why the `providers:` list got removed entirely # a day earlier chasing a "FailedMount: references non-existent secret # key: provider" error: the fix should have been to populate that key # correctly (this), not remove the reference to it - doing so silently # killed SSO on both home and VPS GitLab (no error, the login page just # had no SSO button). apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: gitlab-oidc namespace: gitlab spec: refreshInterval: 1h secretStoreRef: kind: ClusterSecretStore name: vault-backend target: name: gitlab-oidc-secret creationPolicy: Owner template: type: Opaque data: GITLAB_OIDC_CLIENT_ID: "{{ .clientId }}" GITLAB_OIDC_CLIENT_SECRET: "{{ .clientSecret }}" provider: | name: openid_connect label: Authentik args: name: openid_connect scope: - openid - profile - email response_type: code issuer: 'https://auth.kube.huskypup.net/application/o/gitlab/' discovery: true client_auth_method: query uid_field: sub send_scope_to_token_endpoint: true pkce: true client_options: identifier: '{{ .clientId }}' secret: '{{ .clientSecret }}' redirect_uri: 'https://gitlab.kube.huskypup.net/users/auth/openid_connect/callback' data: - secretKey: clientId remoteRef: key: gitlab-oauth property: client-id - secretKey: clientSecret remoteRef: key: gitlab-oauth property: client-secret