fix(prom): Only use oidc once and delete github auth

This commit is contained in:
2025-11-10 17:45:07 +01:00
parent 69d2d7f704
commit c6c8ae5459
+18 -16
View File
@@ -135,32 +135,34 @@ grafana:
allow_sign_up: true allow_sign_up: true
role_attribute_strict: false role_attribute_strict: false
allow_assign_grafana_admin: true allow_assign_grafana_admin: true
{{- else if eq .provider "github" }} #{{- else if eq .provider "github" }}
auth.{{ .provider }}: #auth.{{ .provider }}:
name: {{ .name }} # name: {{ .name }}
enabled: true # enabled: true
client_id: $__file{/etc/secrets/oauth/{{ .name }}/client_id} # client_id: $__file{/etc/secrets/oauth/{{ .name }}/client_id}
client_secret: $__file{/etc/secrets/oauth/{{ .name }}/client_secret} # client_secret: $__file{/etc/secrets/oauth/{{ .name }}/client_secret}
allowed_organizations: {{ .allowed_organizations }} # allowed_organizations: {{ .allowed_organizations }}
{{- if .allowed_teams }} # {{- if .allowed_teams }}
allowed_teams: "{{ .allowed_teams }}" # allowed_teams: "{{ .allowed_teams }}"
{{- end }} # {{- end }}
scopes: user:email,read:org # scopes: user:email,read:org
auth_url: https://github.com/login/oauth/authorize # auth_url: https://github.com/login/oauth/authorize
token_url: https://github.com/login/oauth/access_token # token_url: https://github.com/login/oauth/access_token
allow_sign_up: true # allow_sign_up: true
role_attribute_strict: false # role_attribute_strict: false
allow_assign_grafana_admin: true # allow_assign_grafana_admin: true
{{- end }} {{- end }}
{{- end }} {{- end }}
extraSecretMounts: extraSecretMounts:
{{- range .Values.clusterConfig.oidc }} {{- range .Values.clusterConfig.oidc }}
{{- if eq .group "analytics" }}
- name: {{ .name }} - name: {{ .name }}
secretName: {{ .secret_ref.name }} secretName: {{ .secret_ref.name }}
defaultMode: 0440 defaultMode: 0440
mountPath: /etc/secrets/oauth/{{ .name }} mountPath: /etc/secrets/oauth/{{ .name }}
readOnly: true readOnly: true
{{- end }} {{- end }}
{{- end }}
{{- if .Values.prometheus.grafana.persistence }} {{- if .Values.prometheus.grafana.persistence }}
persistence: persistence: