--- # Job to sync GitLab admin status from Authentik groups # Run this after users login via Authentik SSO to grant them admin access apiVersion: batch/v1 kind: Job metadata: name: gitlab-sync-admin namespace: gitlab spec: ttlSecondsAfterFinished: 3600 # Clean up after 1 hour template: spec: restartPolicy: OnFailure containers: - name: sync-admin image: docker.io/library/alpine:3.21 securityContext: allowPrivilegeEscalation: false capabilities: drop: ["ALL"] command: - /bin/sh - -c - | set -e apk add --no-cache postgresql-client curl echo "Syncing GitLab admin permissions from Authentik..." # Fetch Authentik DB password from secret in authentik namespace AUTHENTIK_DB_PASSWORD=$(kubectl get secret pg-authentik-app -n authentik -o jsonpath='{.data.password}' | base64 -d) # Get list of users in "authentik Admins" group ADMIN_USERS=$(PGPASSWORD="$AUTHENTIK_DB_PASSWORD" psql -h pg-authentik-rw.authentik.svc.cluster.local -U app -d app -t -c " SELECT DISTINCT u.email FROM authentik_core_user u JOIN authentik_core_user_groups ug ON u.id = ug.user_id JOIN authentik_core_group g ON ug.group_id = g.group_uuid WHERE g.name = 'authentik Admins' AND u.is_active = true; " | xargs) if [ -z "$ADMIN_USERS" ]; then echo "No users found in 'authentik Admins' group" exit 0 fi echo "Found admin users: $ADMIN_USERS" echo "" # For each admin user, grant admin access in GitLab for email in $ADMIN_USERS; do echo "Checking user: $email" # Use GitLab Rails runner to promote user kubectl exec -n gitlab deployment/gitlab-toolbox -- \ gitlab-rails runner " user = User.find_by(email: '$email') if user if user.admin? puts ' Already admin' else user.update(admin: true) puts ' Promoted to admin' end else puts ' User not found (needs to login via SSO first)' end " || echo " Failed to update user" done echo "" echo "Admin sync complete" serviceAccountName: gitlab-sync-admin --- # ServiceAccount for the sync job apiVersion: v1 kind: ServiceAccount metadata: name: gitlab-sync-admin namespace: gitlab --- # Role to allow exec into toolbox pod apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: gitlab-sync-admin namespace: gitlab rules: - apiGroups: [""] resources: ["pods", "pods/exec"] verbs: ["get", "list", "create"] - apiGroups: ["apps"] resources: ["deployments"] verbs: ["get", "list"] --- # RoleBinding apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: gitlab-sync-admin namespace: gitlab subjects: - kind: ServiceAccount name: gitlab-sync-admin namespace: gitlab roleRef: kind: Role name: gitlab-sync-admin apiGroup: rbac.authorization.k8s.io --- # Role to read Authentik DB secret apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: gitlab-sync-admin-reader namespace: authentik rules: - apiGroups: [""] resources: ["secrets"] verbs: ["get"] resourceNames: ["pg-authentik-app"] --- # RoleBinding for Authentik secret access apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: gitlab-sync-admin-reader namespace: authentik subjects: - kind: ServiceAccount name: gitlab-sync-admin namespace: gitlab roleRef: kind: Role name: gitlab-sync-admin-reader apiGroup: rbac.authorization.k8s.io