Add comprehensive OIDC troubleshooting documentation
Problem: Frontend still not redirecting to OIDC after all config changes. Created detailed troubleshooting doc covering: - All 6 commits of configuration changes applied - What's verified working (OIDC config, IDM, no local users) - Current behavior vs expected behavior - Possible root causes - Next investigation steps Suggests further investigation needed: - Check OpenCloud web frontend source code - Test OIDC flow with curl/API - Consult OpenCloud community/support - Browser dev tools debugging All backend config appears correct. Issue likely in frontend SPA logic or undocumented configuration requirement for OIDC-only mode. Co-Authored-By: Paperclip <noreply@paperclip.ing>
This commit is contained in:
parent
64ec7094ac
commit
c149a278dc
1 changed files with 205 additions and 0 deletions
205
apps/opencloud/OIDC_TROUBLESHOOTING.md
Normal file
205
apps/opencloud/OIDC_TROUBLESHOOTING.md
Normal file
|
|
@ -0,0 +1,205 @@
|
||||||
|
# OpenCloud OIDC Authentication Troubleshooting
|
||||||
|
|
||||||
|
## Issue Summary
|
||||||
|
OpenCloud deployment configured for Pocket ID (external OIDC) authentication, but the web frontend continues to serve a page instead of redirecting to OIDC provider.
|
||||||
|
|
||||||
|
## All Configuration Changes Applied
|
||||||
|
|
||||||
|
### 1. Deployment Environment Variables (`caf32a3`, `64ec709`)
|
||||||
|
```yaml
|
||||||
|
# OIDC Configuration
|
||||||
|
OC_OIDC_ISSUER: "https://auth.basicstack.de"
|
||||||
|
OC_OIDC_CLIENT_ID: (from opencloud-oidc-secret)
|
||||||
|
OC_OIDC_CLIENT_SECRET: (from opencloud-oidc-secret)
|
||||||
|
OC_OIDC_CLIENT_SCOPES: "openid profile email groups offline_access"
|
||||||
|
OC_JWT_SECRET: (from opencloud-jwt-secret) ✓ Added per user suggestion
|
||||||
|
|
||||||
|
# Proxy OIDC
|
||||||
|
PROXY_OIDC_REWRITE_WELLKNOWN: "true"
|
||||||
|
PROXY_USER_OIDC_CLAIM: "email"
|
||||||
|
PROXY_ENABLE_BASIC_AUTH: "false"
|
||||||
|
|
||||||
|
# Web Service OIDC
|
||||||
|
WEB_OIDC_CLIENT_ID: (from opencloud-oidc-secret)
|
||||||
|
WEB_OIDC_AUTHORITY: "https://auth.basicstack.de"
|
||||||
|
WEB_OIDC_METADATA_URL: "https://auth.basicstack.de/.well-known/openid-configuration"
|
||||||
|
WEB_OIDC_RESPONSE_TYPE: "code"
|
||||||
|
WEB_OIDC_SCOPE: "openid profile email groups offline_access"
|
||||||
|
|
||||||
|
# Disable Demo Users
|
||||||
|
IDM_CREATE_DEMO_USERS: "false"
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2. ConfigMap Changes (`169cd31`, `c993aaf`, `4c89d5d`)
|
||||||
|
|
||||||
|
**Proxy Service:**
|
||||||
|
```yaml
|
||||||
|
proxy:
|
||||||
|
oidc:
|
||||||
|
issuer: https://auth.basicstack.de
|
||||||
|
insecure: false
|
||||||
|
auto_provision_accounts: true # ✓ Enables auto-provisioning
|
||||||
|
user_oidc_claim: email
|
||||||
|
role_assignment:
|
||||||
|
driver: oidc
|
||||||
|
oidc_role_mapper:
|
||||||
|
role_claim: groups
|
||||||
|
role_mapping:
|
||||||
|
- role_name: admin
|
||||||
|
claim_value: opencloudAdmin
|
||||||
|
- role_name: spaceadmin
|
||||||
|
claim_value: opencloudSpaceAdmin
|
||||||
|
- role_name: user
|
||||||
|
claim_value: opencloudUser
|
||||||
|
- role_name: guest
|
||||||
|
claim_value: opencloudGuest
|
||||||
|
enable_basic_auth: false # ✓ Disabled
|
||||||
|
```
|
||||||
|
|
||||||
|
**Service Architecture:**
|
||||||
|
- IDP (Identity Provider) = EXCLUDED (Pocket ID handles authentication)
|
||||||
|
- IDM (Identity Management) = KEPT (provides LDAP storage for auto-provisioned users)
|
||||||
|
- `OC_EXCLUDE_RUN_SERVICES: "search,idp"`
|
||||||
|
|
||||||
|
**User/Group Storage:**
|
||||||
|
```yaml
|
||||||
|
users:
|
||||||
|
drivers:
|
||||||
|
ldap: # Connected to internal IDM LDAP
|
||||||
|
bind_password: ${OC_USERS_LDAP_BIND_PASSWORD}
|
||||||
|
|
||||||
|
groups:
|
||||||
|
drivers:
|
||||||
|
ldap: # Connected to internal IDM LDAP
|
||||||
|
bind_password: ${OC_GROUPS_LDAP_BIND_PASSWORD}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3. Removed Local User Creation (`56d9063`)
|
||||||
|
- Removed `--admin-password` flag from `opencloud init`
|
||||||
|
- Command now: `opencloud init --insecure=true --force-overwrite` (no local admin)
|
||||||
|
- `IDM_CREATE_DEMO_USERS=false`
|
||||||
|
|
||||||
|
## Verified Working
|
||||||
|
|
||||||
|
- ✓ IDM service running (LDAP listener on 127.0.0.1:9236)
|
||||||
|
- ✓ OIDC config present in `/config.json`:
|
||||||
|
```json
|
||||||
|
{
|
||||||
|
"metadata_url": "https://auth.basicstack.de/.well-known/openid-configuration",
|
||||||
|
"authority": "https://auth.basicstack.de",
|
||||||
|
"client_id": "2f3c0cea-697f-4dbc-9573-6f6e8adfd4b0",
|
||||||
|
"response_type": "code",
|
||||||
|
"scope": "openid profile email groups offline_access"
|
||||||
|
}
|
||||||
|
```
|
||||||
|
- ✓ Pocket ID accessible (https://auth.basicstack.de/.well-known/openid-configuration returns 200)
|
||||||
|
- ✓ OpenCloud pod healthy and running
|
||||||
|
- ✓ No errors in logs
|
||||||
|
- ✓ `oidc-client-ts` module loaded by frontend
|
||||||
|
|
||||||
|
## Current Behavior
|
||||||
|
|
||||||
|
When accessing https://opencloud.basicstack.de:
|
||||||
|
1. Frontend HTML loads successfully (HTTP 200)
|
||||||
|
2. `/config.json` loads with OIDC configuration
|
||||||
|
3. `/themes/opencloud/theme.json` loads
|
||||||
|
4. `oidc-client-ts` JavaScript module loads
|
||||||
|
5. **But: No redirect to Pocket ID occurs**
|
||||||
|
6. Page serves content instead of redirecting
|
||||||
|
|
||||||
|
Log evidence shows normal page serving:
|
||||||
|
- `GET / → 200`
|
||||||
|
- `GET /config.json → 200`
|
||||||
|
- `GET /app/list → 200`
|
||||||
|
- Warning: "core access token not set" (normal for unauthenticated)
|
||||||
|
|
||||||
|
## Expected Behavior
|
||||||
|
|
||||||
|
With OIDC configured and no local users:
|
||||||
|
1. Frontend loads
|
||||||
|
2. JavaScript detects OIDC config
|
||||||
|
3. JavaScript detects no local auth available
|
||||||
|
4. **Automatic redirect to: `https://auth.basicstack.de/authorize?...`**
|
||||||
|
5. User authenticates with Pocket ID
|
||||||
|
6. Redirect back to OpenCloud with auth code
|
||||||
|
7. Token exchange and user auto-provisioning
|
||||||
|
|
||||||
|
## Possible Causes
|
||||||
|
|
||||||
|
### 1. Frontend Logic Issue
|
||||||
|
The OpenCloud web SPA may have additional logic that prevents OIDC-only mode:
|
||||||
|
- Checks for local user availability before deciding to redirect
|
||||||
|
- Requires a specific config option we haven't found
|
||||||
|
- Has a bug in OIDC-only detection logic
|
||||||
|
|
||||||
|
### 2. Missing Configuration
|
||||||
|
Possible undocumented configuration options:
|
||||||
|
- Web service option to disable password login UI
|
||||||
|
- Proxy option to force OIDC redirect
|
||||||
|
- ConfigMap option to set "OIDC-only mode"
|
||||||
|
|
||||||
|
### 3. Version-Specific Issue
|
||||||
|
OpenCloud v7.2.0 may have:
|
||||||
|
- Incomplete OIDC-only support
|
||||||
|
- Bug in auto-redirect logic
|
||||||
|
- Regression from earlier versions
|
||||||
|
|
||||||
|
## Next Steps for Investigation
|
||||||
|
|
||||||
|
### 1. Check OpenCloud Source Code
|
||||||
|
Examine the web frontend (SPA) source to understand:
|
||||||
|
- How it decides to redirect to OIDC vs show login form
|
||||||
|
- What configuration flags control this behavior
|
||||||
|
- Whether there's a "force OIDC" option
|
||||||
|
|
||||||
|
### 2. Test with curl/API
|
||||||
|
Try to trigger OIDC flow manually:
|
||||||
|
```bash
|
||||||
|
# Try to initiate OIDC flow
|
||||||
|
curl -i "https://opencloud.basicstack.de/signin-oidc"
|
||||||
|
|
||||||
|
# Try to access protected resource
|
||||||
|
curl -i "https://opencloud.basicstack.de/app/list"
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3. Check OpenCloud Community
|
||||||
|
- Search OpenCloud GitHub issues for OIDC-only configuration
|
||||||
|
- Check OpenCloud documentation for OIDC-only examples
|
||||||
|
- Ask in OpenCloud community channels
|
||||||
|
|
||||||
|
### 4. Try Alternative Approach
|
||||||
|
Consider if OpenCloud requires a different architecture:
|
||||||
|
- Keep IDP running but configure it to proxy to Pocket ID
|
||||||
|
- Use a different authentication flow
|
||||||
|
- Check if web service needs additional OIDC configuration
|
||||||
|
|
||||||
|
### 5. Browser Developer Tools
|
||||||
|
Have user check browser console for JavaScript errors:
|
||||||
|
- Press F12 to open dev tools
|
||||||
|
- Check Console tab for errors
|
||||||
|
- Check Network tab for failed API calls
|
||||||
|
- Check if OIDC client initialization fails
|
||||||
|
|
||||||
|
## Configuration Files
|
||||||
|
|
||||||
|
All changes committed to: https://forgejo.basicstack.de/basicstack/stack.basicstack.de
|
||||||
|
|
||||||
|
Key files:
|
||||||
|
- `apps/opencloud/opencloud-deployment.yaml` - Environment variables
|
||||||
|
- `apps/opencloud/opencloud-configmap.yaml` - Service configuration
|
||||||
|
- `apps/opencloud/opencloud-oidc-sealed.yaml` - OIDC client credentials
|
||||||
|
|
||||||
|
## Commits Applied
|
||||||
|
|
||||||
|
1. `caf32a3` - Initial OIDC deployment config
|
||||||
|
2. `169cd31` - ConfigMap user/group drivers
|
||||||
|
3. `c993aaf` - Proxy auto-provisioning
|
||||||
|
4. `4c89d5d` - IDM service architecture fix
|
||||||
|
5. `56d9063` - Removed admin password
|
||||||
|
6. `64ec709` - Added OC_JWT_SECRET
|
||||||
|
|
||||||
|
## Contact Points
|
||||||
|
|
||||||
|
- OpenCloud Docs: https://docs.opencloud.eu/
|
||||||
|
- OpenCloud GitHub: https://github.com/opencloud-eu/opencloud
|
||||||
|
- Configuration we followed: https://docs.opencloud.eu/de/docs/dev/server/configuration/
|
||||||
Loading…
Add table
Reference in a new issue