#kanidm — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #kanidm, aggregated by home.social.
-
My summer vacation starts soon. And my brain is spinning and accumulating stuff I could do. Move my hosted server to a better one finally.. I pay both for well over a year :/ Catch up with current development of #k8s, #cilium, #flux, #proxmox, move to Gateway API, #kanidm replication as it got more important. Document all that.. trying to get away from Google photos, but it's complicated with huge shared albums.. and that's just some ideas.. and only IT.
-
In my #SSO / #IdM adventures, looks like if I wanted to allow people to use my hackerspace's #OIDC SSO to access my services, I can configure this in #Authentik, but not in #KaniDM 🤔
-
In my #SSO / #IdM adventures, looks like if I wanted to allow people to use my hackerspace's #OIDC SSO to access my services, I can configure this in #Authentik, but not in #KaniDM 🤔
-
In my #SSO / #IdM adventures, looks like if I wanted to allow people to use my hackerspace's #OIDC SSO to access my services, I can configure this in #Authentik, but not in #KaniDM 🤔
-
commands for kanidm + bookstack
kanidm create group bookstack_admin
kanidm system oauth2 create-claim-map bookstack bookstack_roles bookstack_admin admin
kanidm system oauth2 update-scope-map bookstack bookstack_users email groups openid profile bookstack_roles
kanidm group add-members bookstack_admin stelb
Environment for bookstack:
OIDC_USER_TO_GROUPS=true
OIDC_GROUPS_CLAIM=bookstack_roles
OIDC_REMOVE_FROM_GROUPS=true -
commands for kanidm + bookstack
kanidm create group bookstack_admin
kanidm system oauth2 create-claim-map bookstack bookstack_roles bookstack_admin admin
kanidm system oauth2 update-scope-map bookstack bookstack_users email groups openid profile bookstack_roles
kanidm group add-members bookstack_admin stelb
Environment for bookstack:
OIDC_USER_TO_GROUPS=true
OIDC_GROUPS_CLAIM=bookstack_roles
OIDC_REMOVE_FROM_GROUPS=true -
I did this for bookstack with kanidm
Given the oauth2 app is 'bookstack':
map claims (roles in bookstack, say admin)
to scopes and groups in IAM, e.g. bookstack_roles and bookstack_adminadd the scope to the oauth2 application
assign users to these groups as needed.
configure app which scope to use for roles
-
I did this for bookstack with kanidm
Given the oauth2 app is 'bookstack':
map claims (roles in bookstack, say admin)
to scopes and groups in IAM, e.g. bookstack_roles and bookstack_adminadd the scope to the oauth2 application
assign users to these groups as needed.
configure app which scope to use for roles
-
Ok, first time I tried to use a custom scope to map oauth2 users to application specific roles.
Followed some sample and I just replaced names.
Working with one role.. adding another. Both roles not working anymore.
Reading more theory about scopes and claims did help to understand (oh well 🙈)
It's actually not that complicated 🤓
Both roles working now. Writing up some docs and adding another 2 roles is planned for tomorrow.
#oauth2 #idm #kanidm -
Ok, first time I tried to use a custom scope to map oauth2 users to application specific roles.
Followed some sample and I just replaced names.
Working with one role.. adding another. Both roles not working anymore.
Reading more theory about scopes and claims did help to understand (oh well 🙈)
It's actually not that complicated 🤓
Both roles working now. Writing up some docs and adding another 2 roles is planned for tomorrow.
#oauth2 #idm #kanidm -
@firstyear thank youuuu :3
Yea I wanna look into #kanidm soon;
Currently have #Zitadel deployed.Once I find time for that, ig :neocat_laptop:
-
@firstyear thank youuuu :3
Yea I wanna look into #kanidm soon;
Currently have #Zitadel deployed.Once I find time for that, ig :neocat_laptop:
-
@firstyear thank youuuu :3
Yea I wanna look into #kanidm soon;
Currently have #Zitadel deployed.Once I find time for that, ig :neocat_laptop:
-
-
-
-