v16 spike: IdP-driven team/org membership via dynamic OIDC group mappings #77

Öppen
öppnade 2026-07-17 11:52:21 +00:00 av supernaut · 1 kommentar
Ägare

Tier 2 v16 follow-up — spike (gated on #73 landing). v16 ships dynamic OIDC group mappings (PR 11656): placeholder patterns (e.g. group-{org}-{team}) on the auth source map IdP group claims → Forgejo org/team membership at login, with an optional "remove from unmatched teams" toggle. Docs page exists in released v16.

This is net-new membership sync — the reconciler does no team/org membership today — and it cannot set admin/restricted flags, org-create, LFS quota groups, or the has_actions unit, so it complements the reconciler rather than replacing anything (ADR 0017).

Spike scope (local-forgejo preview, not prod):

  • Map a Kanidm group → a Forgejo team via a dynamic pattern; verify claim delivery through our existing groups scope map.
  • Exercise the remove-from-unmatched toggle (the dangerous half — verify it can't strip manually-curated teams unexpectedly).
  • Decide the naming convention for Kanidm groups that encode {org}/{team}.
  • If adopted: design doc + ADR update; ties into the teams/organisation product story.
**Tier 2 v16 follow-up — spike** (gated on #73 landing). v16 ships dynamic OIDC group mappings (PR 11656): placeholder patterns (e.g. `group-{org}-{team}`) on the auth source map IdP group claims → Forgejo **org/team membership** at login, with an optional "remove from unmatched teams" toggle. Docs page exists in released v16. This is **net-new** membership sync — the reconciler does no team/org membership today — and it **cannot** set admin/restricted flags, org-create, LFS quota groups, or the `has_actions` unit, so it **complements** the reconciler rather than replacing anything (ADR 0017). Spike scope (local-forgejo preview, not prod): - [ ] Map a Kanidm group → a Forgejo team via a dynamic pattern; verify claim delivery through our existing `groups` scope map. - [ ] Exercise the remove-from-unmatched toggle (the dangerous half — verify it can't strip manually-curated teams unexpectedly). - [ ] Decide the naming convention for Kanidm groups that encode {org}/{team}. - [ ] If adopted: design doc + ADR update; ties into the teams/organisation product story.
Upphovsperson
Ägare

Spike written up internally (not committed). Headline: conditional GO, but not now — defer until the tenant-org/team product exists.

What it does (v16, PR 11656 + docs): the OIDC auth source reads one group claim (--group-claim-name) at login and syncs org-team membership. Static map (--group-team-map), dynamic placeholders {org}/{team} (--dyn-group-maps), plus removal toggles (--group-team-map-removal / --dyn-group-maps-removal) and admin/restricted group values. Login-time only (no timer); adds to existing orgs/teams only (won't create); names lowercased.

Fit: net-new — the reconciler does no team membership today, so this replaces nothing and complements it (reconciler keeps quota/org-create/has_actions/Renovate; ADR 0016/0017 — none are claim-mappable). Real value is future tenant-org teams; near-zero today (~a handful of users, one first-party org).

Interactions: login-time ⇒ membership lags to next login vs the reconciler's ~15-min timer; removal toggle is the "dangerous half" (can strip hand-curated teams) — keep off, additive only. Orthogonal to #80 (JWT).

Prerequisite (do first): our single group claim is already spoken-for — --group-claim-name=forgejo_role with --admin-group=admin; scopes include groups. Cleanest path: extend the Kanidm forgejo_role claim-map to also emit team tokens (keep admin intact) rather than repoint to raw groups. Verify Kanidm scope/claim-map on the live client before adopting. Also: oidc-source.yml is add-only — enabling on the existing source needs auth update-oauth (runbook).

**Spike written up** internally (not committed). Headline: **conditional GO, but not now** — defer until the tenant-org/team product exists. **What it does (v16, PR 11656 + [docs](https://forgejo.org/docs/latest/admin/advanced/oidc-group-mappings/)):** the OIDC auth source reads one group claim (`--group-claim-name`) at **login** and syncs org-**team** membership. Static map (`--group-team-map`), dynamic placeholders `{org}/{team}` (`--dyn-group-maps`), plus removal toggles (`--group-team-map-removal` / `--dyn-group-maps-removal`) and admin/restricted group values. Login-time only (no timer); adds to **existing** orgs/teams only (won't create); names lowercased. **Fit:** net-new — the reconciler does **no** team membership today, so this **replaces nothing** and complements it (reconciler keeps quota/org-create/`has_actions`/Renovate; ADR 0016/0017 — none are claim-mappable). Real value is future tenant-org teams; near-zero today (~a handful of users, one first-party org). **Interactions:** login-time ⇒ membership **lags to next login** vs the reconciler's ~15-min timer; removal toggle is the "dangerous half" (can strip hand-curated teams) — keep off, additive only. Orthogonal to #80 (JWT). **Prerequisite (do first):** our single group claim is already spoken-for — `--group-claim-name=forgejo_role` with `--admin-group=admin`; scopes include `groups`. Cleanest path: extend the Kanidm `forgejo_role` claim-map to also emit team tokens (keep admin intact) rather than repoint to raw `groups`. Verify Kanidm scope/claim-map on the live client before adopting. Also: `oidc-source.yml` is add-only — enabling on the existing source needs `auth update-oauth` (runbook).
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#77
Ingen beskrivning angiven.