Skip to content

feat(ocis): support an external OIDC provider alongside the built-in IDM - #942

Draft
markussiebert wants to merge 1 commit into
owncloud:mainfrom
markussiebert:pr/external-oidc
Draft

markussiebert wants to merge 1 commit into
owncloud:mainfrom
markussiebert:pr/external-oidc

Conversation

@markussiebert

@markussiebert markussiebert commented Aug 27, 2026 •

Copy link
Copy Markdown

Description

Adds features.externalOIDC, which disables only the built-in IDP and points the OIDC-consuming services at an external issuer, while the built-in IDM stays deployed for user and group management:

features:
  externalOIDC:
    enabled: true
    issuerURI: https://idp.example.com/o/ocis/
    accessTokenVerifyMethod: none   # for providers issuing opaque tokens
    userIDClaim: preferred_username

What it touches:

Service Change
proxy issuer, user claim, access-token verify method, well-known rewrite
web WEB_OIDC_AUTHORITY plus WEB_OIDC_METADATA_URL, so discovery is served from the oCIS domain and avoids a CORS round trip
webfinger issuer
idp not rendered at all when enabled

webfinger is the one that is easy to miss, because it only matters for authenticated requests. With the wrong issuer its OIDC middleware fails to initialise, so every authenticated /.well-known/webfinger returns 500, the owncloud/rel/server-instance relation is never emitted, and desktop clients fail instance discovery — while anonymous requests keep returning 200 and the endpoint looks healthy from the outside.

Related Issue

Motivation and Context

features.externalUserManagement is all-or-nothing: turning it on to use an external IdP also replaces the built-in IDM, so the chart then expects an external LDAP for users and groups as well. A deployment that wants SSO against an existing IdP — Keycloak, Authentik, Entra — but is content with the built-in IDM for user management currently has no way to express that.

Several open reports look like they run into this same gap from different directions: #830 (desktop/mobile authorization failing against Authentik), #927 and #909 (Keycloak setups).

How Has This Been Tested?

  • test environment: single-node Talos Kubernetes cluster, Authentik as the external IdP, built-in IDM retained. Running this patch in production since April, with web, desktop and mobile clients.
  • test case 1 — no regression by default: full helm template output diffed against main with externalOIDC disabled. Identical, apart from the per-run randomly generated secrets, certificates and UUIDs.
  • test case 2 — feature works: with externalOIDC.enabled=true and issuerURI=https://idp.example.com/o/ocis/, all three issuer sites render the external issuer — PROXY_OIDC_ISSUER, WEB_OIDC_AUTHORITY, WEBFINGER_OIDC_ISSUER — and no idp resources are rendered.
  • test case 3 — lint: helm lint charts/ocis --set externalDomain=ocis.example.com passes (without externalDomain it fails on main too, since it is a required value).

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Technical debt
  • Tests only (no source changes)

Checklist

  • Code changes
  • Unit tests added — the chart has no unit test harness; verified via helm template diffing instead
  • Acceptance tests added
  • Documentation generated (make docs) and committed — not run, no local helm-docs; happy to add the regenerated README on request
  • Documentation ticket raised
  • Documentation PR created

Notes

features.externalUserManagement is all-or-nothing: turning it on to use an
external IdP also replaces the built-in IDM, so the chart expects an external
LDAP for users and groups as well. A deployment that wants SSO against an
existing IdP (Keycloak, Authentik, Entra) but is content with the built-in IDM
for user management has no way to say so.

Add features.externalOIDC, which disables only the built-in IDP and points the
OIDC-consuming services at the external issuer, while IDM stays deployed:

    features:
      externalOIDC:
        enabled: true
        issuerURI: https://idp.example.com/o/ocis/
        accessTokenVerifyMethod: none   # for opaque-token providers
        userIDClaim: preferred_username

Touched services: proxy (issuer, claim, token verification, well-known
rewrite), web (authority and metadata URL, so discovery is served from the
oCIS domain and avoids a CORS round trip), webfinger (issuer), and idp
(not rendered at all when enabled).

Defaults are unchanged: with externalOIDC disabled the rendered output is
identical to before, verified by diffing `helm template`.

Assisted-by: Claude Opus 5 <noreply@anthropic.com>
@amamus amamus mentioned this pull request Sep 1, 2026
3 of 11 tasks

@amamus amamus left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving this high-quality PR.

This is a well-designed, production-tested implementation that addresses issue #943.

What it does:

  • Adds features.externalOIDC to support external OIDC providers (Keycloak, Authentik, etc.)
  • Keeps built-in IDM for user management (decouples auth from user storage)
  • Backward compatible with existing deployments

Technical quality:

  • Production-tested since April
  • Clean separation of concerns
  • Comprehensive: handles proxy, web, webfinger, idp services
  • Safety checks: mutual exclusivity with externalUserManagement

Requirements:

  • Author needs to add DCO/GPG sign-offs per agents.md
  • Run 'make docs' to regenerate documentation
  • Confirm version bump to 0.8.0 with maintainers

Ready to merge once process requirements are met.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support an external OIDC provider without also replacing the built-in IDM

2 participants