You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I have SSO working on headscale v0.28.0 and am trying to set up SSO for headplane 0.6.2b5.
Based on the headplane documentation, I'm trying to reuse the existing OIDC credentials created and tested for headscale. Here's the entire oidc config for headscale:
When I try to log in via SSO, I see the following request parameters going into Google's OAuth flow:
The login flow continues as expected with the following returned to the headplane callback:
However next I am redirected to a Headplane login error:
Configuration Issue(s)
Authentication with the SSO provider failed. Please try again later. Headplane logs may provide more information.
The container logs:
[auth] ERROR: Got an OIDC response error body: {"error":"invalid_client","error_description":"The OAuth client was not found."}
I've double checked the client_id passed to the Google OAuth flow and it matches the one displayed in the google cloud configuration and is correct in both config files also. The secret is mounted in a volume at the same location in both containers. What else can I check? I don't really understand what could be wrong at this point. Any help diagnosing this would be appreciated :)
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
I have SSO working on headscale v0.28.0 and am trying to set up SSO for headplane 0.6.2b5.
Based on the headplane documentation, I'm trying to reuse the existing OIDC credentials created and tested for headscale. Here's the entire oidc config for headscale:
and here is the headplane oidc config:
When I try to log in via SSO, I see the following request parameters going into Google's OAuth flow:
The login flow continues as expected with the following returned to the headplane callback:
However next I am redirected to a Headplane login error:
The container logs:
I've double checked the
client_idpassed to the Google OAuth flow and it matches the one displayed in the google cloud configuration and is correct in both config files also. The secret is mounted in a volume at the same location in both containers. What else can I check? I don't really understand what could be wrong at this point. Any help diagnosing this would be appreciated :)Beta Was this translation helpful? Give feedback.
All reactions