Skip to content

chore: remove the Gitea/generic-OIDC auth provider - #25

Merged
Mtze merged 1 commit into
mainfrom
chore/remove-gitea-auth
Aug 27, 2026
Merged

Mtze merged 1 commit into
mainfrom
chore/remove-gitea-auth

Conversation

@Mtze

@Mtze Mtze commented Aug 26, 2026

Copy link
Copy Markdown
Member

Summary

The Gitea integration is no longer needed. This removes the Gitea auth-provider option that was added in #22 (now located in charts/eduide after the chart split in #24). Branched off the latest main.

Removed:

  • gitea.* values block.
  • The gitea provider branch + secret guards + keycloak/gitea mutual-exclusion guard + gitea host/issuer wiring in the oauth2-proxy ConfigMap (back to keycloak-only).
  • The operator --gitea argument.
  • useGiteaOidc/giteaIssuerUrl/giteaClientId from the landing-page config.
  • The preflight if not gitea.enable wrapper (the keycloak placeholder check now always runs).
  • The generated gitea.* README rows.

Kept intentionally

oauth2Proxy.sslInsecureSkipVerify - it is provider-agnostic (applies to keycloak), defaults to false to enforce TLS certificate validation, and removing it would revert to the previous hardcoded insecure default. Shout if you'd rather I remove it too for a full revert.

Verification

helm lint clean; helm template renders with 0 gitea references; provider="keycloak-oidc", ssl_insecure_skip_verify=false; keycloak-enabled render still passes --keycloak and no --gitea.

🤖 Generated with Claude Code

https://claude.ai/code/session_012iEasFrsCzFTCkRh5SP1KY

The Gitea integration is no longer needed, so remove the Gitea auth-provider
option added in #22 (now living in charts/eduide after the chart split):
- values: drop the gitea.* block.
- oauth2-proxy configmap: remove the gitea provider branch, the gitea secret
  guards, the keycloak/gitea mutual-exclusion guard, and the gitea host/issuer
  wiring; back to keycloak-only.
- operator: drop the --gitea argument.
- landing-page config: drop useGiteaOidc/giteaIssuerUrl/giteaClientId.
- preflight: the keycloak placeholder check now always runs (was skipped when
  gitea was enabled).
- README: drop the generated gitea.* rows.

Kept oauth2Proxy.sslInsecureSkipVerify: it is a provider-agnostic setting
(applies to keycloak) that enforces TLS certificate validation by default;
removing it would revert to the previous hardcoded insecure default.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012iEasFrsCzFTCkRh5SP1KY
@coderabbitai

coderabbitai Bot commented Aug 26, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 4 minutes.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: e0aa52f6-9bef-4673-bd42-25fbacf76d43

📥 Commits

Reviewing files that changed from the base of the PR and between 1c6506b and 72ab9c5.

📒 Files selected for processing (6)
  • charts/eduide/README.md
  • charts/eduide/templates/_preflight.tpl
  • charts/eduide/templates/landing-page-config-map.yaml
  • charts/eduide/templates/oauth2-configmap-oauth2proxy-keycloak.yaml
  • charts/eduide/templates/operator.yaml
  • charts/eduide/values.yaml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

Rendered diff across all environments

221 lines changed
diff -ru out-base/bonn.yaml out-head/bonn.yaml
--- out-base/bonn.yaml	2026-08-26 22:04:14.618893838 +0000
+++ out-head/bonn.yaml	2026-08-26 22:04:15.828905061 +0000
@@ -51,9 +51,6 @@
       keycloakAuthUrl: "https://keycloak.url/auth/",
       keycloakRealm: "TheiaCloud",
       keycloakClientId: "theia-cloud",
-      useGiteaOidc: false,
-      giteaIssuerUrl: "",
-      giteaClientId: "",
       serviceUrl: "https://service.bonn.eduide.aet.cit.tum.de",
       appDefinition: "java-17-templates-latest",
       additionalApps: [
@@ -509,7 +506,7 @@
         app: landing-page
       annotations:
         helm.sh/revision: "1"
-        checksum/config: 8890022b9ea9412085db5131403314df2d612aff28838812fc4fde747636c76d
+        checksum/config: c4db37c57105ac279169c0f636ec12db979e141e51cda5803cb75bc51fd8a7f1
     spec:
       automountServiceAccountToken: false
       containers:
diff -ru out-base/e2e-test.yaml out-head/e2e-test.yaml
--- out-base/e2e-test.yaml	2026-08-26 22:04:14.684894450 +0000
+++ out-head/e2e-test.yaml	2026-08-26 22:04:15.894905674 +0000
@@ -90,7 +90,7 @@
 data:
   adminToken: "YWRtaW46Y2hhbmdlbWU="
   prometheusUsername: "cHJvbWV0aGV1cw=="
-  prometheusPassword: "RkZJTDBESWNJQ3gzMmVYM3VheDBSbWx0OXpqV0VsTjg="
+  prometheusPassword: "aEl5dmo2RHZSUnZ2TmFTUVBkU1JrRWhvVGpxWXlqbFA="
 ---
 # Source: eduide/templates/admin-api-token-secret.yaml
 apiVersion: v1
@@ -205,9 +205,6 @@
       keycloakAuthUrl: "https://keycloak-test.aet.cit.tum.de/",
       keycloakRealm: "tum",
       keycloakClientId: "eduide",
-      useGiteaOidc: false,
-      giteaIssuerUrl: "",
-      giteaClientId: "",
       serviceUrl: "https://service.e2e.eduide.student.k8s.aet.cit.tum.de",
       appDefinition: "java-17-templates-latest",
       additionalApps: [
@@ -1078,7 +1075,7 @@
         app: landing-page
       annotations:
         helm.sh/revision: "1"
-        checksum/config: 0cd9df87a873460a110ff27e58e44cd1ebfd3bdf03401d6dd99ab00609dd2c13
+        checksum/config: ce067348878f63302020500e9bb34a5b444c253ccf66bf77c47079c99e192668
     spec:
       automountServiceAccountToken: false
       containers:
diff -ru out-base/mannheim.yaml out-head/mannheim.yaml
--- out-base/mannheim.yaml	2026-08-26 22:04:14.745895016 +0000
+++ out-head/mannheim.yaml	2026-08-26 22:04:15.953906223 +0000
@@ -51,9 +51,6 @@
       keycloakAuthUrl: "https://keycloak.aet.cit.tum.de/",
       keycloakRealm: "external_register",
       keycloakClientId: "eduide",
-      useGiteaOidc: false,
-      giteaIssuerUrl: "",
-      giteaClientId: "",
       serviceUrl: "https://service.mannheim.eduide.aet.cit.tum.de",
       appDefinition: "java-17-templates-latest",
       additionalApps: [
@@ -513,7 +510,7 @@
         app: landing-page
       annotations:
         helm.sh/revision: "1"
-        checksum/config: ff01e8ed925d842602ab66a5d51de51279910205c76b4020f525541e0a151408
+        checksum/config: a3eda9270b657e2ebad71184bb36f8e81722fc50eeca0339708d32068ca35893
     spec:
       automountServiceAccountToken: false
       containers:
diff -ru out-base/staging.yaml out-head/staging.yaml
--- out-base/staging.yaml	2026-08-26 22:04:14.811895628 +0000
+++ out-head/staging.yaml	2026-08-26 22:04:16.020906848 +0000
@@ -90,7 +90,7 @@
 data:
   adminToken: "YWRtaW46Y2hhbmdlbWU="
   prometheusUsername: "cHJvbWV0aGV1cw=="
-  prometheusPassword: "aWxKOFY4WGdhVHJsVm5QTE5mREFuUzN1R0N1WVVPVms="
+  prometheusPassword: "enJhVFdJSVFPV1J6eVA4OW1yaDlSNkFsRTJ5SzlMaTY="
 ---
 # Source: eduide/templates/admin-api-token-secret.yaml
 apiVersion: v1
@@ -205,9 +205,6 @@
       keycloakAuthUrl: "https://keycloak-test.aet.cit.tum.de/",
       keycloakRealm: "tum",
       keycloakClientId: "eduide",
-      useGiteaOidc: false,
-      giteaIssuerUrl: "",
-      giteaClientId: "",
       serviceUrl: "https://service.staging.eduide.student.k8s.aet.cit.tum.de",
       appDefinition: "java-17-templates-latest",
       additionalApps: [
@@ -1078,7 +1075,7 @@
         app: landing-page
       annotations:
         helm.sh/revision: "1"
-        checksum/config: 025d453d0518dc8fc144b29671335b609baced141b4059f8b114306ffce67b5c
+        checksum/config: 6906d8034eae07f2b9268c1458f2d8aa59f1c962cf509173f292c2c3dbea876c
     spec:
       automountServiceAccountToken: false
       containers:
diff -ru out-base/test1.yaml out-head/test1.yaml
--- out-base/test1.yaml	2026-08-26 22:04:14.880896268 +0000
+++ out-head/test1.yaml	2026-08-26 22:04:16.087907472 +0000
@@ -90,7 +90,7 @@
 data:
   adminToken: "YWRtaW46Y2hhbmdlbWU="
   prometheusUsername: "cHJvbWV0aGV1cw=="
-  prometheusPassword: "YVBIbGMyazVCOEROdVBIaklXV3R5TDJNT1NaRld1TWQ="
+  prometheusPassword: "bFVQMGlRN25ieDV1TmhDU0k4bmFCcUFRRkx5RXR2U24="
 ---
 # Source: eduide/templates/admin-api-token-secret.yaml
 apiVersion: v1
@@ -205,9 +205,6 @@
       keycloakAuthUrl: "https://keycloak-test.aet.cit.tum.de/",
       keycloakRealm: "tum",
       keycloakClientId: "eduide",
-      useGiteaOidc: false,
-      giteaIssuerUrl: "",
-      giteaClientId: "",
       serviceUrl: "https://service.test1.eduide.student.k8s.aet.cit.tum.de",
       appDefinition: "java-17-templates-latest",
       additionalApps: [
@@ -1078,7 +1075,7 @@
         app: landing-page
       annotations:
         helm.sh/revision: "1"
-        checksum/config: 8b1a5af8d2847ecec94ce7585a0afb901befda3f3969d2f8a992353f3e46b7a2
+        checksum/config: 6ec3a8ac05b014641fefa2c4a774deeb6cd43e130b845c7b1036aa7a0b8a1ef2
     spec:
       automountServiceAccountToken: false
       containers:
diff -ru out-base/test2.yaml out-head/test2.yaml
--- out-base/test2.yaml	2026-08-26 22:04:14.946896880 +0000
+++ out-head/test2.yaml	2026-08-26 22:04:16.154908097 +0000
@@ -90,7 +90,7 @@
 data:
   adminToken: "YWRtaW46Y2hhbmdlbWU="
   prometheusUsername: "cHJvbWV0aGV1cw=="
-  prometheusPassword: "Y1JuMWNzMTFSSkdiT0V4YTZzN001UVo3TW93b2hSOWw="
+  prometheusPassword: "dVF1VkluNlBmdFZGSXhNcEh0MjJZR3VpZUE0WHJhRjA="
 ---
 # Source: eduide/templates/admin-api-token-secret.yaml
 apiVersion: v1
@@ -205,9 +205,6 @@
       keycloakAuthUrl: "https://keycloak-test.aet.cit.tum.de/",
       keycloakRealm: "tum",
       keycloakClientId: "eduide",
-      useGiteaOidc: false,
-      giteaIssuerUrl: "",
-      giteaClientId: "",
       serviceUrl: "https://service.test2.eduide.student.k8s.aet.cit.tum.de",
       appDefinition: "java-17-templates-latest",
       additionalApps: [
@@ -1078,7 +1075,7 @@
         app: landing-page
       annotations:
         helm.sh/revision: "1"
-        checksum/config: 598f895c81490bfd69e3084bea5943d50e8aba7dd767c810a7c84402de1a934d
+        checksum/config: 8941dced50f25ec3fe5e21fa2fdcd36992bd50ef4fc1fe4e6f0187e24cc05e75
     spec:
       automountServiceAccountToken: false
       containers:
diff -ru out-base/test3.yaml out-head/test3.yaml
--- out-base/test3.yaml	2026-08-26 22:04:15.011897483 +0000
+++ out-head/test3.yaml	2026-08-26 22:04:16.220908712 +0000
@@ -90,7 +90,7 @@
 data:
   adminToken: "YWRtaW46Y2hhbmdlbWU="
   prometheusUsername: "cHJvbWV0aGV1cw=="
-  prometheusPassword: "TG1YR1R2TE92WTdLaDNGaVlmM3FFNkJreE1UdTNYc0c="
+  prometheusPassword: "YTZkWmo1dWJXeWFXaEp3TzhYaXlROFlwejUyc2QwRXE="
 ---
 # Source: eduide/templates/admin-api-token-secret.yaml
 apiVersion: v1
@@ -205,9 +205,6 @@
       keycloakAuthUrl: "https://keycloak-test.aet.cit.tum.de/",
       keycloakRealm: "tum",
       keycloakClientId: "eduide",
-      useGiteaOidc: false,
-      giteaIssuerUrl: "",
-      giteaClientId: "",
       serviceUrl: "https://service.test3.eduide.student.k8s.aet.cit.tum.de",
       appDefinition: "java-17-templates-latest",
       additionalApps: [
@@ -1078,7 +1075,7 @@
         app: landing-page
       annotations:
         helm.sh/revision: "1"
-        checksum/config: b82a5e0cbc8a8d41858a4f1d03bcfe7a449e6f9d25b45ec75db368d6547d0fed
+        checksum/config: 93c8d0def877b01b1e33e7eb8b7395243037ffea41dcda2f70ce3f7c2dacda1f
     spec:
       automountServiceAccountToken: false
       containers:
diff -ru out-base/tum-production.yaml out-head/tum-production.yaml
--- out-base/tum-production.yaml	2026-08-26 22:04:15.071898040 +0000
+++ out-head/tum-production.yaml	2026-08-26 22:04:16.281909281 +0000
@@ -51,9 +51,6 @@
       keycloakAuthUrl: "https://keycloak.aet.cit.tum.de/",
       keycloakRealm: "tum",
       keycloakClientId: "eduide",
-      useGiteaOidc: false,
-      giteaIssuerUrl: "",
-      giteaClientId: "",
       serviceUrl: "https://service.eduide.artemis.aet.cit.tum.de",
       appDefinition: "java-17-templates-latest",
       additionalApps: [
@@ -513,7 +510,7 @@
         app: landing-page
       annotations:
         helm.sh/revision: "1"
-        checksum/config: 420a23dfbe9db4ef129481076aad94ca9c5b187dddecbab4dddc89867b3f1f9c
+        checksum/config: b50786aa86463655bf5d034f96edd484e4ae8d82cb5d5775fa1930db960334d3
     spec:
       automountServiceAccountToken: false
       containers:

@Mtze
Mtze merged commit c865137 into main Aug 27, 2026
10 checks passed
@Mtze
Mtze deleted the chore/remove-gitea-auth branch September 24, 2026 17:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant