Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 10 additions & 1 deletion k8s/environments/production/configmap.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,4 +13,13 @@ data:
RABBITMQ_PORT: "5672"
HTTP_API_PORT: "8000"
ADMINER_PORT: "8080"
CORS_ALLOWED_ORIGINS: "https://app.example.com"
CORS_ALLOWED_ORIGINS: "https://smartem.diamond.ac.uk"
# Keycloak OIDC integration. The backend rejects every non-exempt
# request that doesn't carry a valid Bearer token (always-on since
# smartem-decisions#285). KEYCLOAK_ALLOWED_AZP is the comma-separated
# azp allow-list; unset means any valid token from the realm is accepted.
KEYCLOAK_URL: "https://identity.diamond.ac.uk"
KEYCLOAK_ALLOWED_AZP: "SmartEM_User,SmartEM_Agent"
# TODO: confirm with DLS Keycloak admins before go-live
# KEYCLOAK_REALM
# KEYCLOAK_VERIFY_ISS (set "true" once realm is known so the issuer URL can be validated)