补回旧工作区中仅存于本地的 Backstage OIDC、DNS 与 agent 说明
ansible / collection-test (pull_request) Successful in 2m12s
yaml / yaml (pull_request) Successful in 2m27s
ansible / lint (pull_request) Successful in 2m48s

清理 chore/recover-old-workspace 时发现以下内容已在线上使用,却只存在于未提交的工作区:

- Authelia `backstage` OIDC client(与 helm 现网 values 逐键比对一致;仅含 pbkdf2 哈希,
  与既有 client 写法相同)。
- `backstage.ad.ddupan.top` A 记录(现网已解析到 192.168.10.127)。
- CLAUDE.md:VyOS `cli-shell-api showConfig` 尾随节点名不会过滤、会输出含密钥的完整配置。
- .agents/skills/homelab-knowledge:让 agent 查询与维护 homelab-wiki 的技能说明。

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-01 17:30:07 +00:00
co-authored by Claude Opus 5.5
parent 69d3476a6b
commit 45437f27d0
4 changed files with 96 additions and 0 deletions
+16
View File
@@ -201,6 +201,22 @@ configMap:
# additionalSecrets entry lands at /secrets/<its own name>.
path: '/secrets/authelia-oidc-jwks/main.pem'
clients:
- client_id: 'backstage'
client_name: 'Backstage'
client_secret: '$pbkdf2-sha512$310000$gddaWiXG/xDzda/oRqCibw$MVYwCrDBKi1S4K0/l/O1lNPcH14WmQEb1dIJ48Rs2lrfk9m9dp22s9dFjBelVTzKEyzMwBA2t3eAUmMiu.TiFg'
public: false
authorization_policy: 'two_factor'
claims_policy: 'gitea'
require_pkce: false
token_endpoint_auth_method: 'client_secret_basic'
redirect_uris:
- 'https://backstage.ad.ddupan.top/api/auth/oidc/handler/frame'
scopes:
- 'openid'
- 'profile'
- 'email'
- 'groups'
userinfo_signed_response_alg: 'none'
- client_id: 'gitea'
client_name: 'Gitea'
# pbkdf2-sha512 hash of the plaintext secret Gitea holds (gitea-keycloak-secret).