misc: zot registry, k8s OIDC, server configs, sandbox experiments, and notes
- docker-30/zot: add Zot OCI registry with on-demand sync to docker.io, registry.k8s.io, ghcr.io, quay.io - kubernetes-kvm-terraform: wire Kanidm OIDC via structured AuthenticationConfiguration; add reference apiserver manifest and join-node-02 helper - servers: reorganize shadow/ under servers/, add saint vhost config and utility-101 VM definition, add shadow hrajfrisbee.cz vhost and storage-23 notes - experiments: add notes and configs for e2b dev VM, kata + firecracker on kube, microsandbox, orb-stack k3s (terraform + cloud-init), rke2 - vms/docker: document tailscale + node-exporter setup - blog: stub post on Gateway API - chore: gitignore tmp/, smtp_password, and the two local-only credential caches; add per-project .claude/settings.json Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
14
kubernetes-kvm-terraform/files/auth-config.yaml
Normal file
14
kubernetes-kvm-terraform/files/auth-config.yaml
Normal file
@@ -0,0 +1,14 @@
|
||||
apiVersion: apiserver.config.k8s.io/v1beta1
|
||||
kind: AuthenticationConfiguration
|
||||
jwt:
|
||||
- issuer:
|
||||
url: https://idm.home.hrajfrisbee.cz/oauth2/openid/k8s
|
||||
audiences:
|
||||
- k8s
|
||||
claimMappings:
|
||||
username:
|
||||
claim: preferred_username
|
||||
prefix: ""
|
||||
groups:
|
||||
claim: groups
|
||||
prefix: ""
|
||||
Reference in New Issue
Block a user