<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>RBAC | Luis Cacho</title><link>https://luiscachog.io/category/rbac/</link><atom:link href="https://luiscachog.io/category/rbac/index.xml" rel="self" type="application/rss+xml"/><description>RBAC</description><generator>Wowchemy (https://wowchemy.com)</generator><language>en-us</language><lastBuildDate>Mon, 23 May 2022 00:00:00 +0000</lastBuildDate><image><url>https://luiscachog.io/media/icon_hu4fa4dbbaafd6f1b45a88958b9b4a0dd0_11007_512x512_fill_lanczos_center_3.png</url><title>RBAC</title><link>https://luiscachog.io/category/rbac/</link></image><item><title>OpenID autodiscovery URL integration in OpenShift</title><link>https://luiscachog.io/garden/openid-integration-openshift/</link><pubDate>Mon, 23 May 2022 00:00:00 +0000</pubDate><guid>https://luiscachog.io/garden/openid-integration-openshift/</guid><description>&lt;div class="highlight">&lt;pre tabindex="0" class="chroma">&lt;code class="language-shell" data-lang="shell">&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># Discover the available URLs from your autodiscovery URL&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">curl https://&amp;lt;idp_host&amp;gt;/.well-known/openid-configuration
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;div class="highlight">&lt;pre tabindex="0" class="chroma">&lt;code class="language-shell" data-lang="shell">&lt;span class="line">&lt;span class="cl">&lt;span class="nv">CLIENT_SECRET&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="k">$(&lt;/span>oc get secret -n openshift-config my-id-secret my-id-secret -o &lt;span class="nv">jsonpath&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="s1">&amp;#39;{.items[0].data.clientSecret}&amp;#39;&lt;/span> &lt;span class="p">|&lt;/span> base64 -D&lt;span class="k">)&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">curl -s -X POST https://&amp;lt;idp_host&amp;gt;/idp/userinfo.openid -H &lt;span class="s1">&amp;#39;content-type: application/x-www-form-urlencoded&amp;#39;&lt;/span> -d &lt;span class="s2">&amp;#34;client_id=ocp4testawsuswest2QA&amp;amp;client_secret=&lt;/span>&lt;span class="si">${&lt;/span>&lt;span class="nv">CLIENT_SECRET&lt;/span>&lt;span class="si">}&lt;/span>&lt;span class="s2">&amp;amp;access_token=&lt;/span>&lt;span class="si">${&lt;/span>&lt;span class="nv">ACCESS_TOKEN&lt;/span>&lt;span class="si">}&lt;/span>&lt;span class="s2">&amp;#34;&lt;/span> &lt;span class="p">|&lt;/span> jq
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>&lt;strong>References:&lt;/strong>
- &lt;sup id="fnref:1">&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref">1&lt;/a>&lt;/sup> &lt;a href="https://access.redhat.com/solutions/4605141" target="_blank" rel="noopener">https://access.redhat.com/solutions/4605141&lt;/a>&lt;/p>
&lt;div class="footnotes" role="doc-endnotes">
&lt;hr>
&lt;ol>
&lt;li id="fn:1">
&lt;p>&lt;a href="https://access.redhat.com/solutions/4605141" target="_blank" rel="noopener">https://access.redhat.com/solutions/4605141&lt;/a>&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink">&amp;#x21a9;&amp;#xfe0e;&lt;/a>&lt;/p>
&lt;/li>
&lt;/ol>
&lt;/div></description></item></channel></rss>