This is an automated email from the ASF dual-hosted git repository. lahirujayathilake pushed a commit to branch auth-endpoints in repository https://gitbox.apache.org/repos/asf/airavata-custos.git
commit eb909c74152776cb524b87dfd0cb3d9fb3520322 Author: lahiruj <[email protected]> AuthorDate: Tue Jun 16 22:12:08 2026 -0400 Drop custos.yaml.example, fold the one useful hint inline --- config/custos.yaml | 1 + config/custos.yaml.example | 74 ---------------------------------------------- 2 files changed, 1 insertion(+), 74 deletions(-) diff --git a/config/custos.yaml b/config/custos.yaml index 5ae769950..7466284db 100644 --- a/config/custos.yaml +++ b/config/custos.yaml @@ -6,6 +6,7 @@ core: auth: issuer: "${OIDC_ISSUER_URL}" audience: "${OIDC_AUDIENCE}" + # jwks_url: "" # optional; leave unset to discover via issuer's .well-known cors: allowed_origins: - "http://localhost:3000" diff --git a/config/custos.yaml.example b/config/custos.yaml.example deleted file mode 100644 index 26749adc8..000000000 --- a/config/custos.yaml.example +++ /dev/null @@ -1,74 +0,0 @@ -# Custos configuration template. Copy to config/custos.yaml and either -# replace the ${ENV_VAR} placeholders with literal values or export them -# in the runtime environment. Anything secret-shaped (DSN passwords, -# API keys, OIDC client secrets) must come from the environment, never -# from a committed YAML. - -core: - database: - url: "${DATABASE_DSN}" # MariaDB DSN - api: - port: 8080 - auth: - issuer: "${OIDC_ISSUER_URL}" # OIDC IdP issuer URL - audience: "${OIDC_AUDIENCE}" # JWT audience claim the IdP issues for this server - # jwks_url: "" # optional override; leave empty to discover via issuer - cors: - allowed_origins: # browser callers; empty list disables CORS - - "http://localhost:3000" - - "${CUSTOS_PORTAL_ORIGIN}" # deployed portal URL, set per environment - log_level: "info" - -connectors: - slurm-mapper: - type: "slurm-association-mapper" - enabled: true - slurm_api: - url: "https://slurm-api.example.com" - version: "0.0.38" - username: "slurm_admin" - token: "${SLURM_TOKEN}" - - slurm-usage-monitor: - type: "slurm-usage-monitor" - enabled: true - slurm_api: - url: "https://slurm-api.example.com" - version: "0.0.38" - username: "slurm_admin" - token: "${SLURM_TOKEN}" - cluster_id: "slurm-cluster" - - comanage-provisioner: - type: "comanage-identity-provisioner" - enabled: true - registry: - url: "${COMANAGE_REGISTRY_URL}" - co_id: ${COMANAGE_CO_ID} - api_user: "${COMANAGE_API_USER}" - api_key: "${COMANAGE_API_KEY}" - unix_cluster: - id: ${COMANAGE_UNIX_CLUSTER_ID} - person_id_type: "${COMANAGE_PERSON_ID_TYPE}" - provisioning: - custos_cluster_id: "${CUSTOS_CLUSTER_ID}" - default_shell: "/bin/bash" - homedir_prefix: "/home/" - http_timeout: "30s" - - amie-processor: - type: "amie-processor" - enabled: true - credentials: - base_url: "${AMIE_BASE_URL}" - site_code: "${AMIE_SITE_CODE}" - api_key: "${AMIE_API_KEY}" - cluster: - id: "${AMIE_CLUSTER_ID}" - polling: - poll_interval: "30s" - worker_interval: "5s" - poller_enabled: true - timeouts: - connect_timeout: "5s" - read_timeout: "20s"
