Files
Homelabv4/apps/gitlab/manifests/sync-admin-job.yaml
T
Scooby HuskyandClaude Opus 4.6 7640fb895b Fix degraded ArgoCD applications
- frigate: Remove duplicate PVCs (Helm manages them), update config size to 15Gi
- gitlab: Fix sync-admin-job secretKeyRef schema error, fetch password via kubectl
- nextcloud: Remove duplicate PVC, remove invalid pod-level securityContext
- rook-ceph: Update cephfs-smb-pvc to 50Gi, remove unsupported dashboard.config
- nessus: Add privileged PSS label for NET_ADMIN/NET_RAW capabilities
- scylla-manager: Add privileged PSS label for SYS_NICE capability
- n8n: Create missing n8n-main-persistence PVC
- projects: Add authentik namespace to applications project destinations

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-10 00:05:29 -05:00

138 lines
3.8 KiB
YAML

---
# Job to sync GitLab admin status from Authentik groups
# Run this after users login via Authentik SSO to grant them admin access
apiVersion: batch/v1
kind: Job
metadata:
name: gitlab-sync-admin
namespace: gitlab
spec:
ttlSecondsAfterFinished: 3600 # Clean up after 1 hour
template:
spec:
restartPolicy: OnFailure
containers:
- name: sync-admin
image: docker.io/library/alpine:3.21
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
command:
- /bin/sh
- -c
- |
set -e
apk add --no-cache postgresql-client curl
echo "Syncing GitLab admin permissions from Authentik..."
# Fetch Authentik DB password from secret in authentik namespace
AUTHENTIK_DB_PASSWORD=$(kubectl get secret pg-authentik-app -n authentik -o jsonpath='{.data.password}' | base64 -d)
# Get list of users in "authentik Admins" group
ADMIN_USERS=$(PGPASSWORD="$AUTHENTIK_DB_PASSWORD" psql -h pg-authentik-rw.authentik.svc.cluster.local -U app -d app -t -c "
SELECT DISTINCT u.email
FROM authentik_core_user u
JOIN authentik_core_user_groups ug ON u.id = ug.user_id
JOIN authentik_core_group g ON ug.group_id = g.group_uuid
WHERE g.name = 'authentik Admins' AND u.is_active = true;
" | xargs)
if [ -z "$ADMIN_USERS" ]; then
echo "No users found in 'authentik Admins' group"
exit 0
fi
echo "Found admin users: $ADMIN_USERS"
echo ""
# For each admin user, grant admin access in GitLab
for email in $ADMIN_USERS; do
echo "Checking user: $email"
# Use GitLab Rails runner to promote user
kubectl exec -n gitlab deployment/gitlab-toolbox -- \
gitlab-rails runner "
user = User.find_by(email: '$email')
if user
if user.admin?
puts ' Already admin'
else
user.update(admin: true)
puts ' Promoted to admin'
end
else
puts ' User not found (needs to login via SSO first)'
end
" || echo " Failed to update user"
done
echo ""
echo "Admin sync complete"
serviceAccountName: gitlab-sync-admin
---
# ServiceAccount for the sync job
apiVersion: v1
kind: ServiceAccount
metadata:
name: gitlab-sync-admin
namespace: gitlab
---
# Role to allow exec into toolbox pod
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: gitlab-sync-admin
namespace: gitlab
rules:
- apiGroups: [""]
resources: ["pods", "pods/exec"]
verbs: ["get", "list", "create"]
- apiGroups: ["apps"]
resources: ["deployments"]
verbs: ["get", "list"]
---
# RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: gitlab-sync-admin
namespace: gitlab
subjects:
- kind: ServiceAccount
name: gitlab-sync-admin
namespace: gitlab
roleRef:
kind: Role
name: gitlab-sync-admin
apiGroup: rbac.authorization.k8s.io
---
# Role to read Authentik DB secret
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: gitlab-sync-admin-reader
namespace: authentik
rules:
- apiGroups: [""]
resources: ["secrets"]
verbs: ["get"]
resourceNames: ["pg-authentik-app"]
---
# RoleBinding for Authentik secret access
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: gitlab-sync-admin-reader
namespace: authentik
subjects:
- kind: ServiceAccount
name: gitlab-sync-admin
namespace: gitlab
roleRef:
kind: Role
name: gitlab-sync-admin-reader
apiGroup: rbac.authorization.k8s.io