Skip to content

stages: use managed secrets for Duo and SMS - #26102

Open
dominic-r wants to merge 27 commits into
dominic/rotation-directory-sourcesfrom
dominic/rotation-mfa-stages
Open

dominic-r wants to merge 27 commits into
dominic/rotation-directory-sourcesfrom
dominic/rotation-mfa-stages

Conversation

@dominic-r

@dominic-r dominic-r commented Sep 14, 2026 •

Copy link
Copy Markdown
Member

Details

Part of the managed secrets stack, see #25415.

What does this PR change?

Duo and SMS authenticator setup stages store their API credentials as secrets. The SMS stage API keeps its stage_uuid filter.

Why is this change needed?

Each credential becomes a secret with its own permissions, rotation and audit trail. See #25415.

How was this tested?

Ran the Duo, SMS and authenticator validation tests, and checked that stage API responses never contain the credentials.

Linked issues


Checklist

  • The project has been linted, built, and tested (make all)
  • The documentation has been updated and formatted (make docs)
  • I have read the AI usage policy.

@dominic-r
dominic-r requested review from a team as code owners September 14, 2026 00:46
@dominic-r dominic-r added this to the Release 2026.11.0: Required milestone Sep 14, 2026
@dominic-r dominic-r self-assigned this Sep 14, 2026
@dominic-r
dominic-r added this pull request to stack #26110 September 14, 2026 00:49
@netlify

netlify Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for authentik-docs ready!

Name Link
🔨 Latest commit 0531636
🔍 Latest deploy log https://app.netlify.com/projects/authentik-docs/deploys/6acaaaef817d36000731ac02
😎 Deploy Preview https://deploy-preview-26102--authentik-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@dominic-r
dominic-r force-pushed the dominic/rotation-mfa-stages branch from d1ff144 to 558a3e6 Compare September 14, 2026 01:28
@codecov

codecov Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

❌ 1 Tests Failed:

Tests completed Failed Passed Skipped
4732 1 4731 14
View the top 1 failed test(s) by shortest run time
600-providers.test.ts::Provider Wizard › Complete OAuth2 Provider
Stack Traces | 81.9s run time
Client Secret should be visible when Client Type is Confidential

To view more test analytics, go to the Test Analytics Dashboard
📋 Got 3 mins? Take this short survey to help us improve Test Analytics.

@dominic-r
dominic-r force-pushed the dominic/rotation-mfa-stages branch from 558a3e6 to 0419e62 Compare September 14, 2026 01:55
@dominic-r
dominic-r force-pushed the dominic/rotation-mfa-stages branch from 0419e62 to 4bd4ff5 Compare September 14, 2026 02:18
@dominic-r
dominic-r force-pushed the dominic/rotation-mfa-stages branch from 4bd4ff5 to 26254b6 Compare September 14, 2026 02:28
@dominic-r
dominic-r force-pushed the dominic/rotation-mfa-stages branch from 26254b6 to fec7256 Compare September 14, 2026 02:48
@dominic-r
dominic-r force-pushed the dominic/rotation-mfa-stages branch from fec7256 to a3e19cf Compare September 14, 2026 03:32
@dominic-r
dominic-r force-pushed the dominic/rotation-mfa-stages branch from a3e19cf to 4654586 Compare September 14, 2026 03:59
@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

authentik PR Installation instructions

Instructions for docker-compose

Add the following block to your .env file:

AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-122c0ce7c18b268065db2e58bc93d418e3f7e49a
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s

Afterwards, run the upgrade commands from the latest release notes.

Instructions for Kubernetes

Add the following block to your values.yml file:

authentik:
    outposts:
        container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
    image:
        repository: ghcr.io/goauthentik/dev-server
        tag: gh-122c0ce7c18b268065db2e58bc93d418e3f7e49a

Afterwards, run the upgrade commands from the latest release notes.

@github-actions

Copy link
Copy Markdown
Contributor

Playwright e2e — ✅ Passed

Result Count
✅ Passed 47
❌ Failed 0
⚠️ Flaky 0
⏭️ Skipped 13

Download the HTML report · Workflow run

gh run download 35163650928 -n playwright-report -D playwright-report
npx playwright show-report playwright-report

@netlify

netlify Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for authentik-storybook ready!

Name Link
🔨 Latest commit 0531636
🔍 Latest deploy log https://app.netlify.com/projects/authentik-storybook/deploys/6acaaaef1fcbcb00079c498d
😎 Deploy Preview https://deploy-preview-26102--authentik-storybook.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify

netlify Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for authentik-integrations ready!

Name Link
🔨 Latest commit 0531636
🔍 Latest deploy log https://app.netlify.com/projects/authentik-integrations/deploys/6acaaaef55f2640008394d29
😎 Deploy Preview https://deploy-preview-26102--authentik-integrations.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions

github-actions Bot commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Playwright e2e

Download this run's HTML report and traces, then open the report:

gh run download 38088919156 -D playwright-artifacts
npx playwright show-report playwright-artifacts/playwright-report

Installation instructions

Instructions for docker-compose

Add the following block to your .env file:

AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-2cbb90ff0e5162098aa7d2a786922def8afd5940
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s

Afterwards, run the upgrade commands from the latest release notes.

Instructions for Kubernetes

Add the following block to your values.yml file:

authentik:
    outposts:
        container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
    image:
        repository: ghcr.io/goauthentik/dev-server
        tag: gh-2cbb90ff0e5162098aa7d2a786922def8afd5940

Afterwards, run the upgrade commands from the latest release notes.

@dominic-r
dominic-r force-pushed the dominic/rotation-mfa-stages branch from fc3654b to d2673fd Compare September 23, 2026 21:24
@dominic-r
dominic-r force-pushed the dominic/rotation-mfa-stages branch from d2673fd to 0e6dd68 Compare October 5, 2026 17:57
…on-mfa-stages

# Conflicts:
#	web/src/admin/stages/authenticator_duo/AuthenticatorDuoStageForm.ts
#	web/src/admin/stages/authenticator_sms/AuthenticatorSMSStageForm.ts
…ns in place

The legacy columns stay where they were, the references get related
names that say which credential they hold, and the SMS stage API keeps
its stage_uuid filter. The write-only field test checks again that the
stage API never renders the credentials.
@dominic-r
dominic-r removed this pull request from stack #26110 October 10, 2026 21:17
@dominic-r
dominic-r added this pull request to stack #26820 October 10, 2026 21:17

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: Todo

Development

Successfully merging this pull request may close these issues.

1 participant