Skip to content

website/docs: document managed credentials and manual rotation - #26098

Open
dominic-r wants to merge 87 commits into
dominic/rotation-admin-uifrom
dominic/rotation-docs
Open

dominic-r wants to merge 87 commits into
dominic/rotation-admin-uifrom
dominic/rotation-docs

Conversation

@dominic-r

@dominic-r dominic-r commented Sep 14, 2026 •

Copy link
Copy Markdown
Member

Details

Part of the managed secrets stack, see #25415.

What does this PR change?

Documents managed secrets under System > Secrets: what they are and how objects and blueprints reference them, how to manage and rotate them, and their permissions. Updates the pages of every object that now uses a secret, and adds the 2026.11 release notes, including what the upgrade does to existing credentials and permissions.

Why is this change needed?

Describes the managed secrets stack in #25415.

How was this tested?

Built the docs site locally and checked the links.

Linked issues


Checklist

  • The project has been linted, built, and tested (make all)
  • The documentation has been updated and formatted (make docs)
  • I have read the AI usage policy.

@dominic-r
dominic-r requested a review from a team as a code owner September 14, 2026 00:04
@dominic-r
dominic-r added this pull request to stack #26099 September 14, 2026 00:04
@netlify

netlify Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for authentik-docs ready!

Name Link
🔨 Latest commit 05f8c7d
🔍 Latest deploy log https://app.netlify.com/projects/authentik-docs/deploys/6acab2454c12830008755d84
😎 Deploy Preview https://deploy-preview-26098--authentik-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@dominic-r dominic-r added the area:docs Features or issues related to Docusaurus label Sep 14, 2026
@dominic-r dominic-r self-assigned this Sep 14, 2026
@dominic-r dominic-r added this to the Release 2026.11.0: Required milestone Sep 14, 2026
@dominic-r
dominic-r requested review from a team as code owners September 14, 2026 00:44
@dominic-r
dominic-r force-pushed the dominic/rotation-docs branch from 89bafc5 to 3c73aa4 Compare September 14, 2026 00:44
@dominic-r
dominic-r removed this pull request from stack #26099 September 14, 2026 00:48
@dominic-r
dominic-r changed the base branch from dominic/rotation-connectors to dominic/rotation-consumer-forms September 14, 2026 00:49
@dominic-r
dominic-r added this pull request to stack #26110 September 14, 2026 00:49
@codecov

codecov Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

❌ 1 Tests Failed:

Tests completed Failed Passed Skipped
4741 1 4740 14
View the top 1 failed test(s) by shortest run time
600-providers.test.ts::Provider Wizard › Complete OAuth2 Provider
Stack Traces | 92.6s run time
Client Secret should be visible when Client Type is Confidential

To view more test analytics, go to the Test Analytics Dashboard
📋 Got 3 mins? Take this short survey to help us improve Test Analytics.

@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

authentik PR Installation instructions

Instructions for docker-compose

Add the following block to your .env file:

AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-edf2a2eb3e373c7fc7004d4a158bab33a877f9a3
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s

Afterwards, run the upgrade commands from the latest release notes.

Instructions for Kubernetes

Add the following block to your values.yml file:

authentik:
    outposts:
        container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
    image:
        repository: ghcr.io/goauthentik/dev-server
        tag: gh-edf2a2eb3e373c7fc7004d4a158bab33a877f9a3

Afterwards, run the upgrade commands from the latest release notes.

@dominic-r
dominic-r force-pushed the dominic/rotation-docs branch from e07b27b to b088f00 Compare September 14, 2026 04:00
@dominic-r
dominic-r force-pushed the dominic/rotation-docs branch from bb1bdc0 to c7ce7c8 Compare October 5, 2026 17:57
…-controls

# Conflicts:
#	web/src/admin/secrets/SecretListPage.ts
The five secrets pages repeated the storage warning, the rotation
caveats, and the permission summary. They are now three pages: what
secrets are and how objects and blueprints reference them, how to
manage them, and their permissions, with UI labels as authentik shows
them. The docs describe the text, JSON, and file types, generated
lengths, Kerberos keytab locations, and what the upgrade does to role
and initial permissions.
@dominic-r
dominic-r removed this pull request from stack #26110 October 10, 2026 21:17
@dominic-r
dominic-r changed the base branch from dominic/rotation-consumer-forms to dominic/rotation-admin-ui October 10, 2026 21:17
@dominic-r
dominic-r added this pull request to stack #26820 October 10, 2026 21:17

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:docs Features or issues related to Docusaurus

Projects

Status: In Progress

Development

Successfully merging this pull request may close these issues.

2 participants