Z
ZITADEL
Z
ZITADEL
Integration with Harbor
Original message was deleted
ZITADEL
Join
ZITADEL - Identity infrastructure, simplified for you.
4,316
Members
View on Discord
F
FFO
•
9/20/23, 7:11 AM
Hm you could try
(domain
)
/
.well
-known
/openid
-configuration
F
FFO
•
9/20/23, 7:12 AM
That would be the openid discovery endpoint which lists all other endpoints needed
F
FFO
•
9/20/23, 2:44 PM
Can you provide logs from harbor
?
F
FFO
•
9/20/23, 2:44 PM
The code can be exchanged on
/oauth
/v2
/token
K
Kryptonian
It seems it's just the root of where Zitadel is at but despite having correct id...
F
FFO
•
9/20/23, 2:45 PM
This is usually called the issuer and is the zitadel domain
K
Kryptonian
In Authentik for example, it expects the /o/<app-slug> url.
F
FFO
•
9/20/23, 2:46 PM
In this case I think
https://whatever.com
is what will work
F
FFO
•
9/20/23, 2:46 PM
At the moment you get a code back
? I
.e you are redirected to the login
?
F
FFO
•
9/20/23, 2:48 PM
What client type did you select with zitadel
?
F
FFO
•
9/20/23, 2:48 PM
Ok that is good to know
F
FFO
•
9/20/23, 2:48 PM
Ok web should be correct
F
FFO
•
9/20/23, 2:49 PM
[/pkg/config/db/db.go:77]: encrypt password failed, error: crypto/aes: invalid key size 30
[/pkg/config/db/db.go:77]: encrypt password failed, error: crypto/aes: invalid key size 30
that is a weird error
F
FFO
•
9/20/23, 2:49 PM
are you using zitadel cloud or local
?
F
FFO
•
9/20/23, 2:50 PM
hm ok
F
FFO
•
9/20/23, 2:50 PM
the 401 is really weird
F
FFO
•
9/20/23, 2:51 PM
ok
F
FFO
•
9/20/23, 2:51 PM
I mean the callback looks working
F
FFO
•
9/20/23, 2:51 PM
but the code to token exchange not
F
FFO
•
9/20/23, 2:51 PM
IMO it looks like harbor does not send the secret along
F
FFO
•
9/20/23, 2:52 PM
Do you see the call being made to zitadel
?
F
FFO
•
9/20/23, 2:52 PM
you can enable logs in zitadel
F
FFO
•
9/20/23, 2:53 PM
https://github.com/zitadel/zitadel/blob/main/cmd/defaults.yaml#L455
GitHub
zitadel/cmd/defaults.yaml at main · zitadel/zitadel
ZITADEL
- Identity infrastructure
, simplified for you
.
- zitadel
/zitadel
F
FFO
•
9/20/23, 2:53 PM
you can enable the http logs with the setting above
F
FFO
•
9/20/23, 2:54 PM
btw
. i think you should also investigate this one
Integration with Harbor
F
FFO
•
9/20/23, 2:54 PM
could it not be that harbo can not access the client
_secret
?
F
FFO
•
9/20/23, 2:57 PM
Well its really a wild guess from me
F
FFO
•
9/20/23, 2:58 PM
Looking at the config there is not much that could go wrong
F
FFO
•
9/20/23, 3:02 PM
so zitadel printed out the 401 in the log
, right
F
FFO
•
9/20/23, 3:03 PM
hm that error looked weird though
F
FFO
•
9/20/23, 3:04 PM
maybe harbor has a problem with the client ID
F
FFO
•
9/20/23, 3:04 PM
ok interesting
F
FFO
•
9/20/23, 3:05 PM
so the clientID works
F
FFO
•
9/20/23, 3:05 PM
but the secret not
F
FFO
•
9/20/23, 3:06 PM
https://github.com/goharbor/harbor/issues/12158#issuecomment-639468213
GitHub
Define a remote registry fails with "crypto/aes: invalid key size 1...
When we try to define a remote registry to another Harbor instance
, with a valid user
/password
, the process fails with a
"internal server message
" and the following traces
: 2020
-06
-
0
4
T
2
0
:
.
.
.
Next page
Integration with Harbor - ZITADEL