api: implement automatic ssh key fetching from keycloak
All checks were successful
Build Container / Build Container (push) Successful in 1m26s

This commit is contained in:
lilly 2026-05-31 22:02:39 +02:00
commit 914a4497c7
Signed by: lilly
SSH key fingerprint: SHA256:y9T5GFw2A20WVklhetIxG1+kcg/Ce0shnQmbu1LQ37g
6 changed files with 111 additions and 0 deletions

View file

@ -13,6 +13,7 @@ from aiohttp import BasicAuth
from dooris_api import deps, models, exceptions, app_config
from dooris_api.ccujack import CCUJackClient
from dooris_api.keycloak import KeycloakClient
logger = logging.getLogger(__name__)
@ -37,9 +38,18 @@ async def lifespan(app: FastAPI):
)
await app.extra["ccujack"].start()
app.extra["keycloak"] = KeycloakClient(
base_uri=app_cfg.openid_issuer,
oidc_client=app.extra["oidc_client"],
keycloak_attribute_group=app_cfg.kc_ssh_attr_group,
authorized_keys_file=app_cfg.authorized_keys_file,
)
app.extra["keycloak"].start()
yield
await app.extra["ccujack"].close_connections()
await app.extra["keycloak"].stop()
app = FastAPI(