chore: remove the Gitea/generic-OIDC auth provider - #25
Merged
Merged
Conversation
The Gitea integration is no longer needed, so remove the Gitea auth-provider option added in #22 (now living in charts/eduide after the chart split): - values: drop the gitea.* block. - oauth2-proxy configmap: remove the gitea provider branch, the gitea secret guards, the keycloak/gitea mutual-exclusion guard, and the gitea host/issuer wiring; back to keycloak-only. - operator: drop the --gitea argument. - landing-page config: drop useGiteaOidc/giteaIssuerUrl/giteaClientId. - preflight: the keycloak placeholder check now always runs (was skipped when gitea was enabled). - README: drop the generated gitea.* rows. Kept oauth2Proxy.sslInsecureSkipVerify: it is a provider-agnostic setting (applies to keycloak) that enforces TLS certificate validation by default; removing it would revert to the previous hardcoded insecure default. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012iEasFrsCzFTCkRh5SP1KY
|
Warning Review limit reachedNext included review available in 4 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (6)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Rendered diff across all environments221 lines changeddiff -ru out-base/bonn.yaml out-head/bonn.yaml
--- out-base/bonn.yaml 2026-08-26 22:04:14.618893838 +0000
+++ out-head/bonn.yaml 2026-08-26 22:04:15.828905061 +0000
@@ -51,9 +51,6 @@
keycloakAuthUrl: "https://keycloak.url/auth/",
keycloakRealm: "TheiaCloud",
keycloakClientId: "theia-cloud",
- useGiteaOidc: false,
- giteaIssuerUrl: "",
- giteaClientId: "",
serviceUrl: "https://service.bonn.eduide.aet.cit.tum.de",
appDefinition: "java-17-templates-latest",
additionalApps: [
@@ -509,7 +506,7 @@
app: landing-page
annotations:
helm.sh/revision: "1"
- checksum/config: 8890022b9ea9412085db5131403314df2d612aff28838812fc4fde747636c76d
+ checksum/config: c4db37c57105ac279169c0f636ec12db979e141e51cda5803cb75bc51fd8a7f1
spec:
automountServiceAccountToken: false
containers:
diff -ru out-base/e2e-test.yaml out-head/e2e-test.yaml
--- out-base/e2e-test.yaml 2026-08-26 22:04:14.684894450 +0000
+++ out-head/e2e-test.yaml 2026-08-26 22:04:15.894905674 +0000
@@ -90,7 +90,7 @@
data:
adminToken: "YWRtaW46Y2hhbmdlbWU="
prometheusUsername: "cHJvbWV0aGV1cw=="
- prometheusPassword: "RkZJTDBESWNJQ3gzMmVYM3VheDBSbWx0OXpqV0VsTjg="
+ prometheusPassword: "aEl5dmo2RHZSUnZ2TmFTUVBkU1JrRWhvVGpxWXlqbFA="
---
# Source: eduide/templates/admin-api-token-secret.yaml
apiVersion: v1
@@ -205,9 +205,6 @@
keycloakAuthUrl: "https://keycloak-test.aet.cit.tum.de/",
keycloakRealm: "tum",
keycloakClientId: "eduide",
- useGiteaOidc: false,
- giteaIssuerUrl: "",
- giteaClientId: "",
serviceUrl: "https://service.e2e.eduide.student.k8s.aet.cit.tum.de",
appDefinition: "java-17-templates-latest",
additionalApps: [
@@ -1078,7 +1075,7 @@
app: landing-page
annotations:
helm.sh/revision: "1"
- checksum/config: 0cd9df87a873460a110ff27e58e44cd1ebfd3bdf03401d6dd99ab00609dd2c13
+ checksum/config: ce067348878f63302020500e9bb34a5b444c253ccf66bf77c47079c99e192668
spec:
automountServiceAccountToken: false
containers:
diff -ru out-base/mannheim.yaml out-head/mannheim.yaml
--- out-base/mannheim.yaml 2026-08-26 22:04:14.745895016 +0000
+++ out-head/mannheim.yaml 2026-08-26 22:04:15.953906223 +0000
@@ -51,9 +51,6 @@
keycloakAuthUrl: "https://keycloak.aet.cit.tum.de/",
keycloakRealm: "external_register",
keycloakClientId: "eduide",
- useGiteaOidc: false,
- giteaIssuerUrl: "",
- giteaClientId: "",
serviceUrl: "https://service.mannheim.eduide.aet.cit.tum.de",
appDefinition: "java-17-templates-latest",
additionalApps: [
@@ -513,7 +510,7 @@
app: landing-page
annotations:
helm.sh/revision: "1"
- checksum/config: ff01e8ed925d842602ab66a5d51de51279910205c76b4020f525541e0a151408
+ checksum/config: a3eda9270b657e2ebad71184bb36f8e81722fc50eeca0339708d32068ca35893
spec:
automountServiceAccountToken: false
containers:
diff -ru out-base/staging.yaml out-head/staging.yaml
--- out-base/staging.yaml 2026-08-26 22:04:14.811895628 +0000
+++ out-head/staging.yaml 2026-08-26 22:04:16.020906848 +0000
@@ -90,7 +90,7 @@
data:
adminToken: "YWRtaW46Y2hhbmdlbWU="
prometheusUsername: "cHJvbWV0aGV1cw=="
- prometheusPassword: "aWxKOFY4WGdhVHJsVm5QTE5mREFuUzN1R0N1WVVPVms="
+ prometheusPassword: "enJhVFdJSVFPV1J6eVA4OW1yaDlSNkFsRTJ5SzlMaTY="
---
# Source: eduide/templates/admin-api-token-secret.yaml
apiVersion: v1
@@ -205,9 +205,6 @@
keycloakAuthUrl: "https://keycloak-test.aet.cit.tum.de/",
keycloakRealm: "tum",
keycloakClientId: "eduide",
- useGiteaOidc: false,
- giteaIssuerUrl: "",
- giteaClientId: "",
serviceUrl: "https://service.staging.eduide.student.k8s.aet.cit.tum.de",
appDefinition: "java-17-templates-latest",
additionalApps: [
@@ -1078,7 +1075,7 @@
app: landing-page
annotations:
helm.sh/revision: "1"
- checksum/config: 025d453d0518dc8fc144b29671335b609baced141b4059f8b114306ffce67b5c
+ checksum/config: 6906d8034eae07f2b9268c1458f2d8aa59f1c962cf509173f292c2c3dbea876c
spec:
automountServiceAccountToken: false
containers:
diff -ru out-base/test1.yaml out-head/test1.yaml
--- out-base/test1.yaml 2026-08-26 22:04:14.880896268 +0000
+++ out-head/test1.yaml 2026-08-26 22:04:16.087907472 +0000
@@ -90,7 +90,7 @@
data:
adminToken: "YWRtaW46Y2hhbmdlbWU="
prometheusUsername: "cHJvbWV0aGV1cw=="
- prometheusPassword: "YVBIbGMyazVCOEROdVBIaklXV3R5TDJNT1NaRld1TWQ="
+ prometheusPassword: "bFVQMGlRN25ieDV1TmhDU0k4bmFCcUFRRkx5RXR2U24="
---
# Source: eduide/templates/admin-api-token-secret.yaml
apiVersion: v1
@@ -205,9 +205,6 @@
keycloakAuthUrl: "https://keycloak-test.aet.cit.tum.de/",
keycloakRealm: "tum",
keycloakClientId: "eduide",
- useGiteaOidc: false,
- giteaIssuerUrl: "",
- giteaClientId: "",
serviceUrl: "https://service.test1.eduide.student.k8s.aet.cit.tum.de",
appDefinition: "java-17-templates-latest",
additionalApps: [
@@ -1078,7 +1075,7 @@
app: landing-page
annotations:
helm.sh/revision: "1"
- checksum/config: 8b1a5af8d2847ecec94ce7585a0afb901befda3f3969d2f8a992353f3e46b7a2
+ checksum/config: 6ec3a8ac05b014641fefa2c4a774deeb6cd43e130b845c7b1036aa7a0b8a1ef2
spec:
automountServiceAccountToken: false
containers:
diff -ru out-base/test2.yaml out-head/test2.yaml
--- out-base/test2.yaml 2026-08-26 22:04:14.946896880 +0000
+++ out-head/test2.yaml 2026-08-26 22:04:16.154908097 +0000
@@ -90,7 +90,7 @@
data:
adminToken: "YWRtaW46Y2hhbmdlbWU="
prometheusUsername: "cHJvbWV0aGV1cw=="
- prometheusPassword: "Y1JuMWNzMTFSSkdiT0V4YTZzN001UVo3TW93b2hSOWw="
+ prometheusPassword: "dVF1VkluNlBmdFZGSXhNcEh0MjJZR3VpZUE0WHJhRjA="
---
# Source: eduide/templates/admin-api-token-secret.yaml
apiVersion: v1
@@ -205,9 +205,6 @@
keycloakAuthUrl: "https://keycloak-test.aet.cit.tum.de/",
keycloakRealm: "tum",
keycloakClientId: "eduide",
- useGiteaOidc: false,
- giteaIssuerUrl: "",
- giteaClientId: "",
serviceUrl: "https://service.test2.eduide.student.k8s.aet.cit.tum.de",
appDefinition: "java-17-templates-latest",
additionalApps: [
@@ -1078,7 +1075,7 @@
app: landing-page
annotations:
helm.sh/revision: "1"
- checksum/config: 598f895c81490bfd69e3084bea5943d50e8aba7dd767c810a7c84402de1a934d
+ checksum/config: 8941dced50f25ec3fe5e21fa2fdcd36992bd50ef4fc1fe4e6f0187e24cc05e75
spec:
automountServiceAccountToken: false
containers:
diff -ru out-base/test3.yaml out-head/test3.yaml
--- out-base/test3.yaml 2026-08-26 22:04:15.011897483 +0000
+++ out-head/test3.yaml 2026-08-26 22:04:16.220908712 +0000
@@ -90,7 +90,7 @@
data:
adminToken: "YWRtaW46Y2hhbmdlbWU="
prometheusUsername: "cHJvbWV0aGV1cw=="
- prometheusPassword: "TG1YR1R2TE92WTdLaDNGaVlmM3FFNkJreE1UdTNYc0c="
+ prometheusPassword: "YTZkWmo1dWJXeWFXaEp3TzhYaXlROFlwejUyc2QwRXE="
---
# Source: eduide/templates/admin-api-token-secret.yaml
apiVersion: v1
@@ -205,9 +205,6 @@
keycloakAuthUrl: "https://keycloak-test.aet.cit.tum.de/",
keycloakRealm: "tum",
keycloakClientId: "eduide",
- useGiteaOidc: false,
- giteaIssuerUrl: "",
- giteaClientId: "",
serviceUrl: "https://service.test3.eduide.student.k8s.aet.cit.tum.de",
appDefinition: "java-17-templates-latest",
additionalApps: [
@@ -1078,7 +1075,7 @@
app: landing-page
annotations:
helm.sh/revision: "1"
- checksum/config: b82a5e0cbc8a8d41858a4f1d03bcfe7a449e6f9d25b45ec75db368d6547d0fed
+ checksum/config: 93c8d0def877b01b1e33e7eb8b7395243037ffea41dcda2f70ce3f7c2dacda1f
spec:
automountServiceAccountToken: false
containers:
diff -ru out-base/tum-production.yaml out-head/tum-production.yaml
--- out-base/tum-production.yaml 2026-08-26 22:04:15.071898040 +0000
+++ out-head/tum-production.yaml 2026-08-26 22:04:16.281909281 +0000
@@ -51,9 +51,6 @@
keycloakAuthUrl: "https://keycloak.aet.cit.tum.de/",
keycloakRealm: "tum",
keycloakClientId: "eduide",
- useGiteaOidc: false,
- giteaIssuerUrl: "",
- giteaClientId: "",
serviceUrl: "https://service.eduide.artemis.aet.cit.tum.de",
appDefinition: "java-17-templates-latest",
additionalApps: [
@@ -513,7 +510,7 @@
app: landing-page
annotations:
helm.sh/revision: "1"
- checksum/config: 420a23dfbe9db4ef129481076aad94ca9c5b187dddecbab4dddc89867b3f1f9c
+ checksum/config: b50786aa86463655bf5d034f96edd484e4ae8d82cb5d5775fa1930db960334d3
spec:
automountServiceAccountToken: false
containers: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The Gitea integration is no longer needed. This removes the Gitea auth-provider option that was added in #22 (now located in
charts/eduideafter the chart split in #24). Branched off the latestmain.Removed:
gitea.*values block.--giteaargument.useGiteaOidc/giteaIssuerUrl/giteaClientIdfrom the landing-page config.if not gitea.enablewrapper (the keycloak placeholder check now always runs).gitea.*README rows.Kept intentionally
oauth2Proxy.sslInsecureSkipVerify- it is provider-agnostic (applies to keycloak), defaults tofalseto enforce TLS certificate validation, and removing it would revert to the previous hardcoded insecure default. Shout if you'd rather I remove it too for a full revert.Verification
helm lintclean;helm templaterenders with 0 gitea references;provider="keycloak-oidc",ssl_insecure_skip_verify=false; keycloak-enabled render still passes--keycloakand no--gitea.🤖 Generated with Claude Code
https://claude.ai/code/session_012iEasFrsCzFTCkRh5SP1KY