--- apiVersion: v1 kind: ConfigMap metadata: name: authentik-blueprints-gitlab-saml namespace: authentik labels: goauthentik.io/blueprint: "true" data: gitlab-saml.yaml: |- # yaml-language-server: $schema=https://goauthentik.io/blueprints/schema.json version: 1 metadata: name: gitlab-saml entries: # SAML Provider for GitLab - model: authentik_providers_saml.samlprovider id: gitlab-saml-provider state: present identifiers: name: GitLab SAML attrs: name: GitLab SAML authorization_flow: !Find [authentik_flows.flow, [slug, default-provider-authorization-implicit-consent]] authentication_flow: !Find [authentik_flows.flow, [slug, default-authentication-flow]] invalidation_flow: !Find [authentik_flows.flow, [slug, default-provider-invalidation-flow]] # Redirect URI from the GitLab SAML docs # https://gitlab.kube.huskypup.net/users/auth/saml/callback acs_url: "https://gitlab.kube.huskypup.net/users/auth/saml/callback" audience: "https://gitlab.kube.huskypup.net" issuer: "https://gitlab.kube.huskypup.net" # SAML-specific settings service_provider_slo_url: "https://gitlab.kube.huskypup.net/users/auth/saml/slo" digest_algorithm: "http://www.w3.org/2001/04/xmlenc#sha256" signature_algorithm: "http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" require_signing: true # Property mappings for SAML attributes property_mappings: - !Find [authentik_providers_saml.samlpropertymapping, [managed, goauthentik.io/providers/saml/name]] - !Find [authentik_providers_saml.samlpropertymapping, [managed, goauthentik.io/providers/saml/email]] - !Find [authentik_providers_saml.samlpropertymapping, [managed, goauthentik.io/providers/saml/username]] # Signing certificate signing_key: !Find [authentik_crypto.certificatekeypair, [name, default]] # Application for GitLab SAML - model: authentik_core.application id: gitlab-saml-application state: present identifiers: slug: gitlab-saml attrs: name: GitLab SAML slug: gitlab-saml policy_engine_mode: any provider: !KeyOf gitlab-saml-provider launch_url: "https://gitlab.kube.huskypup.net"