forked from coop-cloud/authentik
Compare commits
9
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
041eb3e4b9
|
||
|
|
e2cb5d2aae
|
||
|
|
2f01ac90a2
|
||
|
|
576aa69bdd | ||
|
|
ce22dab747 | ||
|
|
c288e6798c | ||
|
|
6ffae6ef43 | ||
|
|
d06589a5e3 | ||
|
|
ff5f93196d |
@@ -78,6 +78,7 @@ for group_name in groups:
|
||||
group.users.add(admin)
|
||||
print(f'add akadmin to group {group_name}')
|
||||
""" 2>&1 | quieten
|
||||
return ${PIPESTATUS[0]}
|
||||
|
||||
}
|
||||
|
||||
@@ -108,6 +109,7 @@ with open('/tmp/$1', newline='') as file:
|
||||
group.users.add(new_user)
|
||||
print(f'add {username} to group {group_name}')
|
||||
""" 2>&1 | quieten
|
||||
return ${PIPESTATUS[0]}
|
||||
}
|
||||
|
||||
set_user_pass() {
|
||||
@@ -119,7 +121,7 @@ user.set_password('$password')
|
||||
user.save()
|
||||
print('Changed $username password')
|
||||
""" 2>&1 | quieten
|
||||
|
||||
return ${PIPESTATUS[0]}
|
||||
}
|
||||
|
||||
set_admin_pass() {
|
||||
@@ -157,6 +159,7 @@ else:
|
||||
)
|
||||
print('Created authentik-bootstrap-token')
|
||||
""" 2>&1 | quieten
|
||||
return ${PIPESTATUS[0]}
|
||||
}
|
||||
|
||||
rotate_db_pass() {
|
||||
@@ -182,6 +185,7 @@ update_and_disable_blueprint() {
|
||||
apply_blueprint $@
|
||||
sleep 1
|
||||
disable_blueprint $@ 2>&1 | quieten
|
||||
return ${PIPESTATUS[0]}
|
||||
}
|
||||
|
||||
disable_blueprint() {
|
||||
@@ -195,6 +199,7 @@ enable_blueprint() {
|
||||
apply_blueprint() {
|
||||
echo apply blueprint $@
|
||||
ak apply_blueprint $@ 2>&1 | quieten
|
||||
return ${PIPESTATUS[0]}
|
||||
}
|
||||
|
||||
blueprint_state() {
|
||||
@@ -212,7 +217,7 @@ time.sleep(1)
|
||||
blueprint.save()
|
||||
print(f'{blueprint.name} enabled: {blueprint.enabled}')
|
||||
""" 2>&1 | quieten
|
||||
|
||||
return ${PIPESTATUS[0]}
|
||||
}
|
||||
|
||||
# This function adds each application with its name, slug and group if passed
|
||||
@@ -242,6 +247,7 @@ for name, details in applications.items():
|
||||
app.open_in_new_tab = True
|
||||
app.save()
|
||||
""" 2>&1 | quieten
|
||||
return ${PIPESTATUS[0]}
|
||||
}
|
||||
|
||||
# This function adds one application with its name, slug and group if passed
|
||||
@@ -271,6 +277,7 @@ else:
|
||||
app.open_in_new_tab = True
|
||||
app.save()
|
||||
""" 2>&1 | quieten
|
||||
return ${PIPESTATUS[0]}
|
||||
}
|
||||
|
||||
## This function is for renaming apps - usage: rename "old name" "new name"
|
||||
@@ -287,12 +294,13 @@ if app:
|
||||
else:
|
||||
print(f'No application found with name: {old_name}')
|
||||
""" 2>&1 | quieten
|
||||
return ${PIPESTATUS[0]}
|
||||
}
|
||||
|
||||
quieten() {
|
||||
# 'SyntaxWarning|version_regex|"http\['
|
||||
# is a workaround to get rid of some verbose syntax warnings, this might be fixed with another version
|
||||
grep -Pv '"level": "(info|debug)"|SyntaxWarning|version_regex|"http\[|RuntimeWarning:|### authentik shell|### Node| objects imported automatically|^$'
|
||||
grep -Pv '"level": "(info|debug)"|SyntaxWarning|version_regex|"http\[|RuntimeWarning:|### authentik shell|### Node| objects imported automatically|^$' || true
|
||||
}
|
||||
|
||||
add_email_templates() {
|
||||
@@ -386,6 +394,29 @@ Brand.objects.filter(default=True).delete()
|
||||
apply_blueprints
|
||||
}
|
||||
|
||||
check_blueprints() {
|
||||
failed_blueprints=$(/manage.py shell -c """
|
||||
print(','.join(b.path for b in BlueprintInstance.objects.exclude(status='successful').exclude(name='Default - Out-of-box-experience flow')))
|
||||
""" 2>&1 | quieten | tail -n1)
|
||||
|
||||
if [ -z "$failed_blueprints" ]; then
|
||||
echo "All Blueprints Successful"
|
||||
return 0
|
||||
fi
|
||||
|
||||
echo "These Blueprints failed:"
|
||||
echo "$failed_blueprints" | tr ',' '\n'
|
||||
|
||||
echo "execute failed Blueprints"
|
||||
export AUTHENTIK_LOG_LEVEL=warning
|
||||
for bp in $(echo "$failed_blueprints" | tr ',' '\n'); do
|
||||
echo "Applying: $bp"
|
||||
ak apply_blueprint "/blueprints/$bp" 2>&1 | quieten
|
||||
done
|
||||
|
||||
return 1
|
||||
}
|
||||
|
||||
get_certificate() {
|
||||
/manage.py shell -c """
|
||||
provider_name='$1'
|
||||
@@ -397,12 +428,14 @@ saml = provider.samlprovider
|
||||
cert = saml.signing_kp
|
||||
print(''.join(cert.certificate_data.splitlines()[1:-1]))
|
||||
""" 2>&1 | quieten
|
||||
return ${PIPESTATUS[0]}
|
||||
}
|
||||
|
||||
get_user_uid() {
|
||||
/manage.py shell -c """
|
||||
print(User.objects.filter(username='$1').first().uid)
|
||||
""" 2>&1 | quieten
|
||||
return ${PIPESTATUS[0]}
|
||||
}
|
||||
|
||||
get_secrets() {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
version: "3.8"
|
||||
services:
|
||||
authentik_ldap:
|
||||
image: ghcr.io/goauthentik/ldap:2026.5.4
|
||||
image: ghcr.io/goauthentik/ldap:2026.8.0
|
||||
# Optionally specify which networks the container should be
|
||||
# might be needed to reach the core authentik server
|
||||
networks:
|
||||
|
||||
+3
-3
@@ -35,7 +35,7 @@ x-env: &env
|
||||
version: '3.8'
|
||||
services:
|
||||
app:
|
||||
image: ghcr.io/goauthentik/server:2026.5.4
|
||||
image: ghcr.io/goauthentik/server:2026.8.0
|
||||
command: server
|
||||
depends_on:
|
||||
- db
|
||||
@@ -71,14 +71,14 @@ services:
|
||||
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect,${STACK_NAME}-frameOptions,${STACK_NAME}-redirect"
|
||||
- "traefik.http.middlewares.${STACK_NAME}-frameOptions.headers.customFrameOptionsValue=SAMEORIGIN"
|
||||
- "traefik.http.middlewares.${STACK_NAME}-frameOptions.headers.contentSecurityPolicy=frame-ancestors ${X_FRAME_OPTIONS_ALLOW_FROM}"
|
||||
- "coop-cloud.${STACK_NAME}.version=12.0.4+2026.5.4"
|
||||
- "coop-cloud.${STACK_NAME}.version=12.1.0+2026.8.0"
|
||||
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.regex=^https://(${REDIRECTS})/(.*)"
|
||||
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.replacement=https://${DOMAIN}/$${2}"
|
||||
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.permanent=true"
|
||||
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
|
||||
|
||||
worker:
|
||||
image: ghcr.io/goauthentik/server:2026.5.4
|
||||
image: ghcr.io/goauthentik/server:2026.8.0
|
||||
command: worker
|
||||
depends_on:
|
||||
- db
|
||||
|
||||
Reference in New Issue
Block a user