- There are a number of cases where the OIDC discovery url returns one
issuer, but its desirable to use a separately configured / named
issuer for validation instead.
There are cases in Azure where this is necessary due to their
non-standard OIDC configuration -- which is why this was originally
added:
https://github.com/coreos/go-oidc/pull/315
There are also cases where it's necessary to use an in-cluster
service address, but browser clients are using the external ingress
address. Due to cluster DNS configuration, it's possible that
flyteadmin may be unable to resolve or use the public ingress
address for an Idp, but the internal service address is available.
This configuration change allows for that.
- Regenerated flyteadmin code through mise with:
mise x go@1.22 -- make generate
Signed-off-by: ddl-ebrown <ethan.brown@dominodatalab.com>