Repository navigation
Conversation
✅ Deploy Preview for authentik-docs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
d1ff144 to
558a3e6
Compare
❌ 1 Tests Failed:
View the top 1 failed test(s) by shortest run time
To view more test analytics, go to the Test Analytics Dashboard |
558a3e6 to
0419e62
Compare
0419e62 to
4bd4ff5
Compare
4bd4ff5 to
26254b6
Compare
26254b6 to
fec7256
Compare
fec7256 to
a3e19cf
Compare
a3e19cf to
4654586
Compare
|
authentik PR Installation instructions Instructions for docker-composeAdd the following block to your AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-122c0ce7c18b268065db2e58bc93d418e3f7e49a
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)sAfterwards, run the upgrade commands from the latest release notes. Instructions for KubernetesAdd the following block to your authentik:
outposts:
container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
image:
repository: ghcr.io/goauthentik/dev-server
tag: gh-122c0ce7c18b268065db2e58bc93d418e3f7e49aAfterwards, run the upgrade commands from the latest release notes. |
Playwright e2e — ✅ Passed
Download the HTML report · Workflow run gh run download 35163650928 -n playwright-report -D playwright-report
npx playwright show-report playwright-report |
✅ Deploy Preview for authentik-storybook ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview for authentik-integrations ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Playwright e2eDownload this run's HTML report and traces, then open the report: gh run download 38088919156 -D playwright-artifacts
npx playwright show-report playwright-artifacts/playwright-reportInstallation instructionsInstructions for docker-composeAdd the following block to your AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-2cbb90ff0e5162098aa7d2a786922def8afd5940
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)sAfterwards, run the upgrade commands from the latest release notes. Instructions for KubernetesAdd the following block to your authentik:
outposts:
container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
image:
repository: ghcr.io/goauthentik/dev-server
tag: gh-2cbb90ff0e5162098aa7d2a786922def8afd5940Afterwards, run the upgrade commands from the latest release notes. |
fc3654b to
d2673fd
Compare
d2673fd to
0e6dd68
Compare
…on-mfa-stages # Conflicts: # web/src/admin/stages/authenticator_duo/AuthenticatorDuoStageForm.ts # web/src/admin/stages/authenticator_sms/AuthenticatorSMSStageForm.ts
…ns in place The legacy columns stay where they were, the references get related names that say which credential they hold, and the SMS stage API keeps its stage_uuid filter. The write-only field test checks again that the stage API never renders the credentials.
Details
Part of the managed secrets stack, see #25415.
What does this PR change?
Duo and SMS authenticator setup stages store their API credentials as secrets. The SMS stage API keeps its
stage_uuidfilter.Why is this change needed?
Each credential becomes a secret with its own permissions, rotation and audit trail. See #25415.
How was this tested?
Ran the Duo, SMS and authenticator validation tests, and checked that stage API responses never contain the credentials.
Linked issues
Checklist
make all)make docs)