feat(ocis): support an external OIDC provider alongside the built-in IDM - #942
Draft
markussiebert wants to merge 1 commit into
Draft
markussiebert wants to merge 1 commit into
markussiebert wants to merge 1 commit into
Conversation
features.externalUserManagement is all-or-nothing: turning it on to use an
external IdP also replaces the built-in IDM, so the chart expects an external
LDAP for users and groups as well. A deployment that wants SSO against an
existing IdP (Keycloak, Authentik, Entra) but is content with the built-in IDM
for user management has no way to say so.
Add features.externalOIDC, which disables only the built-in IDP and points the
OIDC-consuming services at the external issuer, while IDM stays deployed:
features:
externalOIDC:
enabled: true
issuerURI: https://idp.example.com/o/ocis/
accessTokenVerifyMethod: none # for opaque-token providers
userIDClaim: preferred_username
Touched services: proxy (issuer, claim, token verification, well-known
rewrite), web (authority and metadata URL, so discovery is served from the
oCIS domain and avoids a CORS round trip), webfinger (issuer), and idp
(not rendered at all when enabled).
Defaults are unchanged: with externalOIDC disabled the rendered output is
identical to before, verified by diffing `helm template`.
Assisted-by: Claude Opus 5 <noreply@anthropic.com>
3 of 11 tasks
amamus
approved these changes
Sep 6, 2026
amamus
left a comment
Contributor
There was a problem hiding this comment.
Approving this high-quality PR.
This is a well-designed, production-tested implementation that addresses issue #943.
What it does:
- Adds features.externalOIDC to support external OIDC providers (Keycloak, Authentik, etc.)
- Keeps built-in IDM for user management (decouples auth from user storage)
- Backward compatible with existing deployments
Technical quality:
- Production-tested since April
- Clean separation of concerns
- Comprehensive: handles proxy, web, webfinger, idp services
- Safety checks: mutual exclusivity with externalUserManagement
Requirements:
- Author needs to add DCO/GPG sign-offs per agents.md
- Run 'make docs' to regenerate documentation
- Confirm version bump to 0.8.0 with maintainers
Ready to merge once process requirements are met.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds
features.externalOIDC, which disables only the built-in IDP and points the OIDC-consuming services at an external issuer, while the built-in IDM stays deployed for user and group management:What it touches:
proxywebWEB_OIDC_AUTHORITYplusWEB_OIDC_METADATA_URL, so discovery is served from the oCIS domain and avoids a CORS round tripwebfingeridpwebfingeris the one that is easy to miss, because it only matters for authenticated requests. With the wrong issuer its OIDC middleware fails to initialise, so every authenticated/.well-known/webfingerreturns 500, theowncloud/rel/server-instancerelation is never emitted, and desktop clients fail instance discovery — while anonymous requests keep returning 200 and the endpoint looks healthy from the outside.Related Issue
Motivation and Context
features.externalUserManagementis all-or-nothing: turning it on to use an external IdP also replaces the built-in IDM, so the chart then expects an external LDAP for users and groups as well. A deployment that wants SSO against an existing IdP — Keycloak, Authentik, Entra — but is content with the built-in IDM for user management currently has no way to express that.Several open reports look like they run into this same gap from different directions: #830 (desktop/mobile authorization failing against Authentik), #927 and #909 (Keycloak setups).
How Has This Been Tested?
helm templateoutput diffed againstmainwithexternalOIDCdisabled. Identical, apart from the per-run randomly generated secrets, certificates and UUIDs.externalOIDC.enabled=trueandissuerURI=https://idp.example.com/o/ocis/, all three issuer sites render the external issuer —PROXY_OIDC_ISSUER,WEB_OIDC_AUTHORITY,WEBFINGER_OIDC_ISSUER— and noidpresources are rendered.helm lint charts/ocis --set externalDomain=ocis.example.compasses (withoutexternalDomainit fails onmaintoo, since it is a required value).Types of changes
Checklist
helm templatediffing insteadmake docs) and committed — not run, no localhelm-docs; happy to add the regenerated README on requestNotes
agents.md. I would rather get feedback on the approach before rewriting the history to add both.