Correct the docs I'd written for the (reverted) oauth2-proxy SSO. Reality: apiserver OIDC rejects all Authentik tokens (design §12), so the dashboard uses forward-auth (admits kubernetes-* groups) + per-namespace SA token-paste. Updates authentication.md, multi-tenancy.md, service-catalog, authentik-state, and add-user skill (onboarding now documents the dashboard token). oauth2-proxy + k8s-dashboard OIDC app noted as idle. [ci skip] Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| add-user | ||
| archived | ||
| cluster-health | ||
| disk-wear | ||
| extend-vm-storage | ||
| home-assistant | ||
| k8s-ndots-search-domain-nxdomain-flood | ||
| pfsense | ||
| post-mortem | ||
| setup-project | ||
| upgrade-state | ||
| uptime-kuma | ||