Branding
A Branding resource themes the hosted sign-in UI for a
single OAuth client. Its branding object is the same JSON document that the gRPC
AdminService.UpsertBranding call accepts. The server stores it as-is and injects it
into the sign-in page for that client.
Status: defined, not yet reconciled. The operator does not act on
Brandingobjects yet. Applying branding from a manifest is tracked in #404. Today the only way to write branding is the gRPCUpsertBrandingcall.
| Property | Value |
|---|---|
| API group / version | nauthera.io/v1alpha1 |
| Kind | Branding |
| Plural / short name | brandings / brand |
| Scope | Namespaced |
| Definition | deploy/crds/branding-crd.yaml in nauthera-server |
Example
apiVersion: nauthera.io/v1alpha1
kind: Branding
metadata:
name: example-webapp-branding
namespace: nauthera
spec:
clientId: example-webapp
branding:
productName: Acme
logoUrl: https://acme.example/logo.svg
mode: system
supportUrl: https://acme.example/support
fonts:
- https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&display=swap
theme:
color:
accent: "#7B61FF"
neutralStyle: cool
typography:
scale:
base: 14
ratio: 1.2
body:
family: Inter
fallbacks: "-apple-system, sans-serif"
radius:
base: 8
multiplier: 1Spec
spec.branding
Type: object | Required
The auth UI branding document. Chrome fields drive screen UI;
theme is a full Astryx defineTheme input (color, typography,
radius, motion, tokens, components, …) and is opaque to this
schema. The operator serializes this object to JSON and sends
it as BrandingSpec.branding_json.
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
appName | string | No | — | App name, shown as "Continue to {appName}". |
companyName | string | No | — | Copyright holder shown in the footer. |
fonts | []string | No | — | Font stylesheet URLs to load (e.g. Google Fonts). |
hero | object | No | — | Hero pane content for the split layout. |
layout | string | No | — | Page layout — centered (default) or split. One of: centered, split. |
logoUrl | string | No | — | Logo image URL rendered in the header. https only — the /ui CSP img-src blocks http images (mixed content). |
mode | string | No | — | Default color mode. One of: system, light, dark. |
privacyUrl | string | No | — | |
productName | string | No | — | Tenant/product name shown in the auth header. |
supportUrl | string | No | — | |
termsUrl | string | No | — | |
theme | object | No | — | Full Astryx defineTheme input. Arbitrary token/component map — validated by the SPA, not by this schema. |
spec.clientId
Type: string | Required
The OAuth2 client_id this branding applies to.
spec.issuer
Type: string | Optional
Issuer/org this branding belongs to. Defaults to the server's primary issuer when empty.
Status
| Field | Type | Description |
|---|---|---|
clientId | string | The resolved client_id the branding is bound to. |
conditions | []object | Standard Kubernetes conditions (Ready, Synced, …). |
etag | string | The server's revision of this resource, returned on every write and read. A controller compares it against what it last wrote to tell its own change from one made elsewhere, and sends it back as the expected revision so a write that would overwrite someone else's is refused instead. |
lastReconciledTime | string | |
observedGeneration | integer | .metadata.generation last reconciled by the server. |
phase | string |