Skip to content

Want support for SCIM in silo creation #2885

@askfongjojo

Description

@askfongjojo

Today, when fleet admin sets up a new silo, the two IDP modes available are JIT-SAML and local user auth. SCIM-SAML will soon be available as another option user can choose.

  1. JIT and SCIM modes are mutually exclusive.
  2. The silo IDP mode will remain immutable, i.e., a silo can't be changed from JIT to SCIM and vice versa.
  3. The SCIM attributes to be provided by fleet admin at setup time are:
  • IDP system (in our initial implementation, only Okta is supported)
  • Attribute mapping (username, maybe email + other attributes - it'll be a short list since we don't use/track most of them)
  1. An initial bearer token will be generated during silo setup which fleet admin will specify on the IDP side for authorizing SCIM API requests.

Here is an example of SCIM setup in Duo for some ideas of how the config looks like: https://duo.com/docs/oktasync.

@jmpesp @papertigers - Please update the above as needed.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions