People and access
Single sign-on
Sign in with your OpenID Connect provider and map its groups to roles.
Settings, SSO tab. OpenID Connect is supported. SAML is not.
- In your provider, register an app with the redirect address
https://packages.example.com/_api/sso/callback. - Fill in Provider address (https), Client id and Client secret.
- Pick Role a new account comes in as: viewer, developer, publisher or approver. Admin is never given automatically.
- Optionally map groups in Roles from the provider's groups, one rule per line, like
approver = platform-team, security. - Click Check the provider, then Save settings, and sign in from a private window before you log out.
Roles from the provider's groups
# strongest matching role wins
admin = repo-admins
approver = platform-team, appsec
publisher = release-bots
developer = engineering
- What is accepted:
bothkeeps password sign in,sso_onlyturns it off. A half configuredsso_onlystill allows passwords, so you cannot lock yourself out by accident. - Keep roles in step on every sign in updates roles from groups each time, but never demotes the last admin.
- Refuse anybody no rule matches turns group mapping into an access list.
- People are matched to existing accounts by email first, then by username.
Locked out by SSO
on the server
./enable_local_login.sh --status # look, change nothing
./enable_local_login.sh # allow password sign in again
./enable_local_login.sh --off-sso # also switch SSO off
./enable_local_login.sh --admin admin # clear a lockout on that account
Note
The script cannot create accounts or set passwords. Keep one local admin with a strong password in your vault.