diff --git a/mojaloop/iac/roles/dex/templates/dex-config.yml.j2 b/mojaloop/iac/roles/dex/templates/dex-config.yml.j2 index 380c6351..ebcb3804 100644 --- a/mojaloop/iac/roles/dex/templates/dex-config.yml.j2 +++ b/mojaloop/iac/roles/dex/templates/dex-config.yml.j2 @@ -17,7 +17,7 @@ oauth2: staticClients: - id: {{ dex_static_client_id }} redirectURIs: - - http://localhost:8000 # for kubelogin + - https://{{ dex_fqdn }}/dex/callback name: '{{ dex_static_client_id }}' secret: ZXhhbXBsZS1hcHAtc2VjcmV0 diff --git a/mojaloop/iac/roles/microk8s/tasks/install.yml b/mojaloop/iac/roles/microk8s/tasks/install.yml index 280912b4..5f0202a4 100644 --- a/mojaloop/iac/roles/microk8s/tasks/install.yml +++ b/mojaloop/iac/roles/microk8s/tasks/install.yml @@ -138,7 +138,7 @@ dest: /var/snap/microk8s/current/args/kube-apiserver marker: "# {mark} ANSIBLE MANAGED: microk8s oidc config" content: | - --oidc-issuer-url=https://{{ k8s_oidc_issuer_fqdn }} + --oidc-issuer-url=https://{{ k8s_oidc_issuer_fqdn }}/dex --oidc-ca-file=/usr/share/ca-certificates/dex/{{ k8s_oidc_issuer_fqdn }}.crt --oidc-client-id={{ k8s_oidc_client_id }} --oidc-username-claim=email