v16 spike: IdP-driven team/org membership via dynamic OIDC group mappings #77
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#77
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Tier 2 v16 follow-up — spike (gated on #73 landing). v16 ships dynamic OIDC group mappings (PR 11656): placeholder patterns (e.g.
group-{org}-{team}) on the auth source map IdP group claims → Forgejo org/team membership at login, with an optional "remove from unmatched teams" toggle. Docs page exists in released v16.This is net-new membership sync — the reconciler does no team/org membership today — and it cannot set admin/restricted flags, org-create, LFS quota groups, or the
has_actionsunit, so it complements the reconciler rather than replacing anything (ADR 0017).Spike scope (local-forgejo preview, not prod):
groupsscope map.Spike written up internally (not committed). Headline: conditional GO, but not now — defer until the tenant-org/team product exists.
What it does (v16, PR 11656 + docs): the OIDC auth source reads one group claim (
--group-claim-name) at login and syncs org-team membership. Static map (--group-team-map), dynamic placeholders{org}/{team}(--dyn-group-maps), plus removal toggles (--group-team-map-removal/--dyn-group-maps-removal) and admin/restricted group values. Login-time only (no timer); adds to existing orgs/teams only (won't create); names lowercased.Fit: net-new — the reconciler does no team membership today, so this replaces nothing and complements it (reconciler keeps quota/org-create/
has_actions/Renovate; ADR 0016/0017 — none are claim-mappable). Real value is future tenant-org teams; near-zero today (~a handful of users, one first-party org).Interactions: login-time ⇒ membership lags to next login vs the reconciler's ~15-min timer; removal toggle is the "dangerous half" (can strip hand-curated teams) — keep off, additive only. Orthogonal to #80 (JWT).
Prerequisite (do first): our single group claim is already spoken-for —
--group-claim-name=forgejo_rolewith--admin-group=admin; scopes includegroups. Cleanest path: extend the Kanidmforgejo_roleclaim-map to also emit team tokens (keep admin intact) rather than repoint to rawgroups. Verify Kanidm scope/claim-map on the live client before adopting. Also:oidc-source.ymlis add-only — enabling on the existing source needsauth update-oauth(runbook).