Ory SSO manifests (Hydra/Kratos/Ory-UI/Oathkeeper), synced by argocd-platform into ns ory. Content pushed by the pipeline-bot (scripts/ory-push.sh).
| Filename | Latest commit message | Latest commit date |
|---|---|---|
| apps | ||
| manifests | ||
| README.md | ||
sean/ory
Ory SSO manifests (Hydra / Kratos / Ory-UI / Oathkeeper / hydra-token-hook +
the auth.sean.farm gateway route + the Vault/ESO credential plane), synced by
argocd-platform into ns ory. Migrated out of the Crossplane apis/oidc
composition (the ory-alice → ory singleton collapse).
apps/— app-of-apps child Applications (ory-stack,ory-users), synced by the rootory-argocdApplication (seeded from seanfarmkubernetes/flux/infrastructure/ory-argocd/).manifests/stack/— the Ory server stack (nsory).manifests/users/— the 5 per-user Kratos identities.
Laptop is read-only to Forgejo; push content with scripts/ory-push.sh <dir>
(in-cluster pipeline-bot). DB names + Vault creds stay alice-named (backend
de-alias deferred to the coordinated backend pass).