Skip to content

fix(authentik): token lifetimes + rbac privilege - #11

Merged
cmdoret merged 4 commits into
mainfrom
fix/token-lifetimes
Aug 25, 2026
Merged

fix(authentik): token lifetimes + rbac privilege#11
cmdoret merged 4 commits into
mainfrom
fix/token-lifetimes

Conversation

@cmdoret

@cmdoret cmdoret commented Aug 25, 2026

Copy link
Copy Markdown
Member

No description provided.

@cmdoret
cmdoret requested a balanced review from Copilot August 25, 2026 09:11
@cmdoret cmdoret self-assigned this Aug 25, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Reduces Authentik token lifetimes and removes unnecessary OAuth grants and Kubernetes RBAC.

Changes:

  • Sets shorter authorization/device-code and access-token lifetimes.
  • Restricts OAuth grants to required flows.
  • Disables the unused Authentik remote-cluster service account.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

File Description
values.yaml Adds lifetime defaults and disables privileged RBAC.
templates/authentik-blueprints-secret.yaml Restricts grants and configures token lifetimes.
README.md Documents the new 8-hour default.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread templates/authentik-blueprints-secret.yaml Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@cmdoret
cmdoret merged commit 0ff8cd5 into main Aug 25, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants