diff --git a/core/authelia.tf b/core/authelia.tf index 4cf126a..bbe7c0e 100644 --- a/core/authelia.tf +++ b/core/authelia.tf @@ -172,7 +172,7 @@ resource "nomad_acl_auth_method" "nomad_authelia" { oidc_discovery_url = "https://authelia.${var.base_hostname}" oidc_client_id = module.nomad_oidc_client.client_id oidc_client_secret = module.nomad_oidc_client.secret - bound_audiences = ["nomad"] + bound_audiences = [module.nomad_oidc_client.client_id] oidc_scopes = [ "groups", "openid", @@ -190,7 +190,7 @@ resource "nomad_acl_auth_method" "nomad_authelia" { resource "nomad_acl_binding_rule" "nomad_authelia_admin" { description = "engineering rule" auth_method = nomad_acl_auth_method.nomad_authelia.name - selector = "\"nomad-deploy\" in list.roles" + selector = "\"nomad-admin\" in list.roles" bind_type = "role" bind_name = "admin" # acls.nomad_acl_role.admin.name }