Ory SSO manifests (Hydra/Kratos/Ory-UI/Oathkeeper), synced by argocd-platform into ns ory. Content pushed by the pipeline-bot (scripts/ory-push.sh).
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-07-24 17:51:12 +02:00
apps sync ory manifests from laptop 2026-07-24 17:51:12 +02:00
manifests sync ory manifests from laptop 2026-07-24 17:51:12 +02:00
README.md sync ory manifests from laptop 2026-07-24 17:51:12 +02:00

sean/ory

Ory SSO manifests (Hydra / Kratos / Ory-UI / Oathkeeper / hydra-token-hook + the auth.sean.farm gateway route + the Vault/ESO credential plane), synced by argocd-platform into ns ory. Migrated out of the Crossplane apis/oidc composition (the ory-aliceory singleton collapse).

  • apps/ — app-of-apps child Applications (ory-stack, ory-users), synced by the root ory-argocd Application (seeded from seanfarm kubernetes/flux/infrastructure/ory-argocd/).
  • manifests/stack/ — the Ory server stack (ns ory).
  • manifests/users/ — the 5 per-user Kratos identities.

Laptop is read-only to Forgejo; push content with scripts/ory-push.sh <dir> (in-cluster pipeline-bot). DB names + Vault creds stay alice-named (backend de-alias deferred to the coordinated backend pass).