Feature description
ADR-0001 describes client projects building on SRDP. There is no supported mechanism for the final
step: placing a client app behind Traefik + oauth2-proxy + Zitadel. Client projects hand-write
Traefik labels against SRDP internals.
Use case
Adding the datavloot dashboard to the Compose stack required:
- Traefik labels matching
zitadel-auth@docker, zitadel-errors@docker, the srdp-app network and
router naming conventions.
- Replacing the entire
oauth2-proxy command to add one scope
(urn:zitadel:iam:org:projects:roles), needed so Zitadel asserts project roles in the token.
- Overriding Traefik
authResponseHeaders to forward X-Auth-Request-Access-Token.
The third item is the notable one. The default forwards X-Auth-Request-User and
X-Auth-Request-Email and withholds the access token. ADR-0008 says not to trust the former and to
validate the latter. A client app following ADR-0008 must reconfigure Traefik to do so.
Proposed solution
- A declarative way to register an app. Options, in preference order:
scopes as configuration rather than a full command override.
authResponseHeaders as configuration, with the access token included by default.
Alternatives considered
| Alternative |
Why not |
| Hand-written labels (current) |
Couples every client to SRDP internals; breaks silently on rename |
| Fork the compose file |
Loses upstream changes |
| Run client apps outside the gate |
Defeats single sign-on; contradicts the client-project model |
| Wait for #42 |
Possibly correct. If srdp.toml is the intended home, close this and fold it in |
Component
deploy/docker, services/traefik, services/oauth2-proxy
Feature description
ADR-0001 describes client projects building on SRDP. There is no supported mechanism for the final
step: placing a client app behind Traefik + oauth2-proxy + Zitadel. Client projects hand-write
Traefik labels against SRDP internals.
Use case
Adding the datavloot dashboard to the Compose stack required:
zitadel-auth@docker,zitadel-errors@docker, thesrdp-appnetwork androuter naming conventions.
oauth2-proxycommand to add one scope(
urn:zitadel:iam:org:projects:roles), needed so Zitadel asserts project roles in the token.authResponseHeadersto forwardX-Auth-Request-Access-Token.The third item is the notable one. The default forwards
X-Auth-Request-UserandX-Auth-Request-Emailand withholds the access token. ADR-0008 says not to trust the former and tovalidate the latter. A client app following ADR-0008 must reconfigure Traefik to do so.
Proposed solution
srdp.toml(Proposal: srdp.toml, a single platform config #42) that renders the labelsx-srdp-app:Compose extension fieldscopesas configuration rather than a full command override.authResponseHeadersas configuration, with the access token included by default.Alternatives considered
srdp.tomlis the intended home, close this and fold it inComponent
deploy/docker,services/traefik,services/oauth2-proxy