Skip to content

web/admin: add secret management pages - #26107

Open
dominic-r wants to merge 46 commits into
dominic/rotation-endpoint-connectorsfrom
dominic/rotation-admin-ui
Open

dominic-r wants to merge 46 commits into
dominic/rotation-endpoint-connectorsfrom
dominic/rotation-admin-ui

Conversation

@dominic-r

@dominic-r dominic-r commented Sep 14, 2026 •

Copy link
Copy Markdown
Member

Details

Part of the managed secrets stack, see #25415.

What does this PR change?

Adds System > Secrets to the Admin interface: the list of secrets with buttons to view or download, edit, rotate, and set permissions on each.

Why is this change needed?

Admins need one place to find, rotate, and permission the credentials authentik stores. See #25415.

How was this tested?

Used the page locally: opened the create form, rotated a secret, and opened the delete dialog for a secret in use, which lists the objects that block the deletion.

Linked issues


Checklist

  • The project has been linted, built, and tested (make all)
  • The documentation has been updated and formatted (make docs)
  • I have read the AI usage policy.

@dominic-r
dominic-r requested a review from a team as a code owner September 14, 2026 00:46
@dominic-r dominic-r added this to the Release 2026.11.0: Required milestone Sep 14, 2026
@dominic-r dominic-r added the area:frontend Features or issues related to the browser, TypeScript, Node.js, etc label Sep 14, 2026
@dominic-r dominic-r self-assigned this Sep 14, 2026
@dominic-r
dominic-r added this pull request to stack #26110 September 14, 2026 00:49
@netlify

netlify Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for authentik-docs ready!

Name Link
🔨 Latest commit 8f4924a
🔍 Latest deploy log https://app.netlify.com/projects/authentik-docs/deploys/6acaaaf33484ca00088a4367
😎 Deploy Preview https://deploy-preview-26107--authentik-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@dominic-r
dominic-r force-pushed the dominic/rotation-admin-ui branch from b567f43 to 24f3b19 Compare September 14, 2026 02:04
@codecov

codecov Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

❌ 1 Tests Failed:

Tests completed Failed Passed Skipped
4741 1 4740 14
View the top 1 failed test(s) by shortest run time
600-providers.test.ts::Provider Wizard › Complete OAuth2 Provider
Stack Traces | 91.5s run time
Client Secret should be visible when Client Type is Confidential

To view more test analytics, go to the Test Analytics Dashboard
📋 Got 3 mins? Take this short survey to help us improve Test Analytics.

@dominic-r
dominic-r requested a review from a team as a code owner September 14, 2026 02:18
@dominic-r
dominic-r force-pushed the dominic/rotation-admin-ui branch from 24f3b19 to aa1ac1c Compare September 14, 2026 02:18
@dominic-r
dominic-r force-pushed the dominic/rotation-admin-ui branch 2 times, most recently from 82e18ab to 251e12d Compare September 14, 2026 02:48
@dominic-r
dominic-r force-pushed the dominic/rotation-admin-ui branch from 251e12d to b643d05 Compare September 14, 2026 03:32
@dominic-r
dominic-r force-pushed the dominic/rotation-admin-ui branch from b643d05 to 38286ab Compare September 14, 2026 04:00
@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

authentik PR Installation instructions

Instructions for docker-compose

Add the following block to your .env file:

AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-b779c2ef3c6477cc63a80c6b1249a92af1d24e23
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s

Afterwards, run the upgrade commands from the latest release notes.

Instructions for Kubernetes

Add the following block to your values.yml file:

authentik:
    outposts:
        container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
    image:
        repository: ghcr.io/goauthentik/dev-server
        tag: gh-b779c2ef3c6477cc63a80c6b1249a92af1d24e23

Afterwards, run the upgrade commands from the latest release notes.

@dominic-r
dominic-r force-pushed the dominic/rotation-admin-ui branch from 8418d38 to 5755e75 Compare October 5, 2026 17:57
…tion-migration-tests

# Conflicts:
#	authentik/crypto/secrets/tests/test_credential_upgrades.py
The upgrade round trip moved to the layer that adds the migration
helpers, and the kubeconfig and Google credential checks either moved
next to their consumers or became redundant once JSON secrets are
validated when they're saved.
The list shows the rotate button next to the value and edit buttons and
uses the same type labels as the form, so the layer that only added the
button is no longer needed.
@dominic-r
dominic-r removed this pull request from stack #26110 October 10, 2026 21:17
@dominic-r
dominic-r changed the base branch from dominic/rotation-migration-tests to dominic/rotation-endpoint-connectors October 10, 2026 21:17
@dominic-r
dominic-r added this pull request to stack #26820 October 10, 2026 21:17

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:frontend Features or issues related to the browser, TypeScript, Node.js, etc

Projects

Status: Todo

Development

Successfully merging this pull request may close these issues.

1 participant