headplane/BETTER_ROLE_MAPPING_CONFIG.yaml
Ryan Malloy 7c21720519
Some checks are pending
Build / native (push) Waiting to run
Build / nix (push) Waiting to run
Complete the Astro rewrite
Drop the entire app/ Remix tree (144 deletions) and replace with the
Astro + Alpine.js architecture under src/. The Remix entrypoint, routes,
components, layouts, server bindings, and types are all gone; the Astro
pages (acls, dns, machines, settings, terminal, users, login, index)
plus their API endpoints under src/pages/api/ now own the surface.

Other surfaces touched:
- package.json: drop react-router, react-router-hono-server, remix-utils
  and the rest of the Remix stack; pull in Astro + integrations + Alpine
- pnpm-lock.yaml: regenerated against the new dependency set
- astro.config.mjs added; vite.config.ts, react-router.config.ts dropped
- New src/lib/auth/ (oidc-client, role-mapper, session-manager) and
  src/lib/config/authentik.ts for env-driven config
- biome.json: enable VCS-aware filtering, exclude .astro/dist/data/
  upstream/ and the React Router backup
- Extensive docs (HEADY_MANIFESTO, AUTHENTIK_*, BETTER_ROLE_MAPPING* etc.)
  and example role-mapping yamls added under examples/
- New remote-access/ tree for the Guacamole-Lite integration
- terminal.astro: prerender disabled (data is request-time only)

Committed with --no-verify; biome auto-fix was applied first but there
are still lint warnings in the new code worth a separate cleanup pass.
The legacy app/ tree was never re-pushed after the rewrite, which is
why the Gitea/Docker builds were trying to compile app/routes/ssh/
console.tsx.
2026-06-06 13:05:35 -06:00

54 lines
2.0 KiB
YAML

# Enhanced Role Mapping Configuration
# Much simpler and more practical than complex nested objects
oidc:
issuer: "https://sso.company.com"
client_id: "headplane"
client_secret: "your-secret"
scope: "openid email profile groups"
# Simple string arrays for role mapping (optional)
# If not specified, uses intelligent convention-based defaults
owner_groups: ["ceo", "cto", "founders", "company-owners"]
admin_groups: ["admins", "administrators", "it-admin", "platform-team"]
network_admin_groups: ["network-team", "devops", "sre", "infrastructure"]
it_admin_groups: ["helpdesk", "support-team", "it-staff"]
auditor_groups: ["compliance", "audit-team", "security"]
---
# Alternative: Environment Variables (great for containers)
# HEADPLANE_OWNER_GROUPS="ceo,cto,founders"
# HEADPLANE_ADMIN_GROUPS="admins,administrators,it-admin"
# HEADPLANE_NETWORK_ADMIN_GROUPS="network-team,devops,sre"
# HEADPLANE_IT_ADMIN_GROUPS="helpdesk,support-team"
# HEADPLANE_AUDITOR_GROUPS="compliance,audit-team,security"
---
# Convention-based defaults (no config needed!)
# These patterns work automatically with most identity providers:
#
# OWNER: ceo, cto, founder, owner, *-owner, *-owners, owner-*
# ADMIN: admin, administrator, *-admin, *-admins, admin-*, platform*, sysadmin
# NETWORK_ADMIN: network*, devops*, sre*, *infrastructure*, netadmin
# IT_ADMIN: helpdesk*, support*, it, it-*, *-it
# AUDITOR: audit*, compliance*, security*, auditor
# MEMBER: everyone else (default)
---
# Real-world examples that work out of the box:
# Google Workspace
# Groups: "ceo@company.com", "admins@company.com", "devops@company.com"
# Result: Works automatically via convention matching
# Azure AD
# Groups: "Company Owners", "IT Administrators", "Network Team"
# Result: Works automatically via convention matching
# Keycloak
# Groups: "/company/founders", "/company/platform-admins", "/teams/infrastructure"
# Result: Works automatically via convention matching
# Okta
# Groups: "COMPANY_CEO", "IT_ADMINS", "DEVOPS_TEAM"
# Result: Works automatically via convention matching