Files
ThothII/docs/install/authentik.md
T
Codex 043ffdfad6
Publish documentation / publish (push) Successful in 27s
docs: separate public manual from internal project documentation
2026-09-15 10:26:35 +02:00

49 lines
1.9 KiB
Markdown

# Authentik provider configuration
For **full with direct OIDC**, ThothII uses generic OIDC in the browser. Authentik
provides the identity provider and group catalog without adding a proprietary flow.
The provider/client/group setup below applies to that case only.
For **embedded in Omics**, retain Omics's existing Authentik authentication and
configure ThothII as upstream. Omics verifies `datamart_builder.access` and
administrator status and the proxy supplies the identity; no additional ThothII
OIDC client, login or local user is required for that path. Follow the
[portal integration guide](shell-and-language.md).
```mermaid
sequenceDiagram
participant Browser
participant ThothII
participant Authentik
Browser->>ThothII: Sign in
ThothII->>Authentik: Authorization Code with PKCE
Authentik-->>Browser: Login and consent
Browser->>ThothII: Callback with code
ThothII->>Authentik: Token exchange
Authentik-->>ThothII: Identity and groups
ThothII-->>Browser: Opaque session
```
## OIDC provider
1. Create an OAuth2/OIDC application and provider.
2. Register exactly `PUBLIC_URL/api/auth/oidc/callback`.
3. Enable the `openid`, `profile`, and `email` scopes.
4. Configure a direct `groups` claim as an array of strings.
## Group catalog
Create a dedicated service account with read-only access to groups. Store its token in the
protected bundle as `THT_AUTHENTIK_API_TOKEN`.
Map the exact enterprise group names to the ThothII `user` and `admin` roles in `auth.yaml`.
Unmapped groups are ignored. A configured group that does not exist produces a closed error.
## Diagnostics
`tht auth check` checks discovery, the issuer, JWKS, catalog access, and the configured groups.
The `--interactive` option also verifies identity through device flow when the provider supports it.
Rotate the OIDC secret and group-catalog token separately. Neither may appear in YAML, shell
history, logs, or diagnostic output.