Skip to content

Commit cc86a51

Browse files
authored
Merge pull request #255 from flashcatcloud/work/sso-network-docs
docs: fix IP whitelist placeholder and document SSO network requirements
2 parents 2207623 + 93f385b commit cc86a51

9 files changed

Lines changed: 107 additions & 1 deletion

File tree

‎en/on-call/integration/webhooks/alert-webhook.mdx‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -234,5 +234,13 @@ Click **View Details** on a record to see the complete request and response info
234234
- Services can filter based on event_time; if a later event has been received, earlier events can be filtered out. Each push carries the latest complete information, so occasional event loss is tolerable
235235

236236
4. **Trusted IP whitelist for push source?**
237+
{/* console:
237238
- {ip_whitelist}
238239
- May be updated in the future, please check regularly
240+
*/}
241+
<div className="hide">
242+
243+
- `47.94.95.118`, `123.56.8.183`, `47.94.193.81`, and `1.13.19.96` (SaaS only; in a private deployment, pushes originate from your own environment's egress address — check with your infrastructure team)
244+
- May be updated in the future, please check regularly
245+
246+
</div>

‎en/on-call/integration/webhooks/custom-actions.mdx‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -333,5 +333,13 @@ When an incident is confirmed to impact production services, trigger external st
333333
- eof
334334

335335
3. **Trusted IP whitelist for push source?**
336+
{/* console:
336337
- {ip_whitelist}
337338
- May be updated in the future, please check regularly
339+
*/}
340+
<div className="hide">
341+
342+
- `47.94.95.118`, `123.56.8.183`, `47.94.193.81`, and `1.13.19.96` (SaaS only; in a private deployment, pushes originate from your own environment's egress address — check with your infrastructure team)
343+
- May be updated in the future, please check regularly
344+
345+
</div>

‎en/on-call/integration/webhooks/incident-webhook.mdx‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -350,5 +350,13 @@ Click **View Details** on a record to see the complete request and response info
350350
- Services can filter based on event_time; if a later event has been received, earlier events can be filtered out. Each push carries the latest complete information, so occasional event loss is tolerable
351351

352352
4. **Trusted IP whitelist for push source?**
353+
{/* console:
353354
- {ip_whitelist}
354355
- May be updated in the future, please check regularly
356+
*/}
357+
<div className="hide">
358+
359+
- `47.94.95.118`, `123.56.8.183`, `47.94.193.81`, and `1.13.19.96` (SaaS only; in a private deployment, pushes originate from your own environment's egress address — check with your infrastructure team)
360+
- May be updated in the future, please check regularly
361+
362+
</div>

‎en/platform/configure-sso.mdx‎

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,28 @@ description: Sign in once and access multiple connected applications through sin
55

66
Flashduty supports Single Sign-On (SSO) via SAML2.0, OIDC, CAS, and LDAP (private deployment only) protocols, helping you easily integrate with various applications and platforms. Users only need to sign in once to access multiple connected applications and services without repeated authentication.
77

8+
## Network Access Requirements
9+
10+
---
11+
12+
Each protocol has different network reachability requirements for your identity provider (IdP). Confirm this before configuring to avoid sign-in failures caused by network access:
13+
14+
| Protocol | Does Flashduty need to reach the IdP? | Details |
15+
| --- | --- | --- |
16+
| SAML 2.0 | No | Sign-in happens entirely through the member's browser: the browser is redirected to the IdP, then posts the signed SAMLResponse back to Flashduty after login. Flashduty's servers never connect to the IdP directly — the signature is validated locally against the metadata you upload |
17+
| OIDC | Yes | On every sign-in, Flashduty's servers fetch the IdP's discovery document, then call its token endpoint and JWKS endpoint. When the ID Token doesn't carry every mapped field, Flashduty also calls the UserInfo endpoint |
18+
| CAS | Yes | On every sign-in, Flashduty's servers call the IdP's `/serviceValidate` endpoint to validate the login ticket. The CAS protocol offers no alternative — the ticket carries no signed content, so it can only be validated at the source |
19+
| LDAP | Not applicable | Available only in the private deployment version, where Flashduty runs inside your own network — public internet reachability doesn't apply |
20+
21+
If your identity provider is on a private network and not reachable from the public internet:
22+
23+
- You can allow Flashduty's egress IPs — `47.94.95.118`, `123.56.8.183`, `47.94.193.81`, and `1.13.19.96` — through your firewall to open access from Flashduty to the IdP
24+
- If you'd rather not open any public access to your identity provider, **SAML 2.0** is the only protocol that needs none — it's the recommended choice in that case
25+
26+
<Note>
27+
The egress IPs above apply only to Flashduty's **SaaS (public cloud) service**. If you're using a private (on-premises) deployment, Flashduty runs inside your own network and its egress IP depends on your deployment environment — check with your infrastructure team instead of using the addresses above.
28+
</Note>
29+
830
## Configuring SAML Protocol
931

1032
---

‎integration-docs/scripts/build.mjs‎

Lines changed: 15 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,8 +31,14 @@ function getFrontmatterAttr(content, name) {
3131
return (match?.[1] || match?.[2] || match?.[3] || '').trim();
3232
}
3333

34+
// The leading `^[ \t]*` matters when the block is indented inside a list item:
35+
// without it the indentation survives as a stray whitespace-only line, which
36+
// turns the surrounding tight list loose. Blocks at column zero are unaffected.
3437
function removeHiddenBlocks(content) {
35-
return content.replace(/<div\b(?=[^>]*\bclass(?:Name)?=["'][^"']*\bhide\b[^"']*["'])[^>]*>[\s\S]*?<\/div>/g, '\n');
38+
return content.replace(
39+
/^[ \t]*<div\b(?=[^>]*\bclass(?:Name)?=["'][^"']*\bhide\b[^"']*["'])[^>]*>[\s\S]*?<\/div>/gm,
40+
'\n',
41+
);
3642
}
3743

3844
function convertAnchorSpans(content) {
@@ -268,6 +274,14 @@ function mdxToMarkdown(content) {
268274
let output = convertAnchorSpans(removeHiddenBlocks(stripFrontmatter(content)));
269275

270276
output = convertDirectiveContainers(convertCallouts(convertCards(convertAccordions(output))))
277+
// Counterpart to removeHiddenBlocks: a `{/* console: ... */}` block is an MDX
278+
// comment, so the docs site renders nothing, while the console gets its
279+
// contents. Use it for text that only makes sense inside the product, such
280+
// as a value the console substitutes per deployment. The opening and closing
281+
// lines are consumed whole so the captured lines land at the same
282+
// indentation they were written at, with no blank line on either side.
283+
// Must run before the generic comment strip below, which would discard it.
284+
.replace(/^[ \t]*{[ \t]*\/\*[ \t]*console:[ \t]*\r?\n([\s\S]*?)\r?\n[ \t]*\*\/[ \t]*}[ \t]*(\r?\n)/gm, '$1$2')
271285
.replace(/{\s*\/\*[\s\S]*?\*\/\s*}/g, '')
272286
.replace(/^\s*import\s+.*$/gm, '')
273287
.replace(/^\s*export\s+.*$/gm, '')

‎zh/on-call/integration/webhooks/alert-webhook.mdx‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -234,5 +234,13 @@ curl -X POST 'https://example.com/alert/webhook?a=a' \
234234
- 服务可以根据 event_time 进行过滤,如果已经收到了更晚的事件,可以直接过滤掉更早的事件,每一次推送都会携带最新的、完整的信息,偶尔丢失事件是可以容忍的
235235

236236
4. **推送来源可信 IP 白名单?**
237+
{/* console:
237238
- {ip_whitelist}
238239
- 未来可能会更新,请定期查验
240+
*/}
241+
<div className="hide">
242+
243+
- `47.94.95.118`、`123.56.8.183`、`47.94.193.81` 和 `1.13.19.96`(SaaS 版本;私有化部署的推送来源为您自有环境的出口地址,请向您的基础设施团队确认)
244+
- 未来可能会更新,请定期查验
245+
246+
</div>

‎zh/on-call/integration/webhooks/custom-actions.mdx‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -321,5 +321,13 @@ curl -X POST 'https://example.com/incident/action?a=a' \
321321
- eof
322322

323323
2. **推送来源可信 IP 白名单?**
324+
{/* console:
324325
- {ip_whitelist}
325326
- 未来可能会更新,请定期查验
327+
*/}
328+
<div className="hide">
329+
330+
- `47.94.95.118`、`123.56.8.183`、`47.94.193.81` 和 `1.13.19.96`(SaaS 版本;私有化部署的推送来源为您自有环境的出口地址,请向您的基础设施团队确认)
331+
- 未来可能会更新,请定期查验
332+
333+
</div>

‎zh/on-call/integration/webhooks/incident-webhook.mdx‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -350,5 +350,13 @@ curl -X POST 'https://example.com/incident/webhook?a=a' \
350350
- 服务可以根据 event_time 进行过滤,如果已经收到了更晚的事件,可以直接过滤掉更早的事件,每一次推送都会携带最新的、完整的信息,偶尔丢失事件是可以容忍的
351351

352352
4. **推送来源可信 IP 白名单?**
353+
{/* console:
353354
- {ip_whitelist}
354355
- 未来可能会更新,请定期查验
356+
*/}
357+
<div className="hide">
358+
359+
- `47.94.95.118`、`123.56.8.183`、`47.94.193.81` 和 `1.13.19.96`(SaaS 版本;私有化部署的推送来源为您自有环境的出口地址,请向您的基础设施团队确认)
360+
- 未来可能会更新,请定期查验
361+
362+
</div>

‎zh/platform/configure-sso.mdx‎

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,28 @@ keywords: ["单点登录", "SSO", "SAML", "OIDC", "LDAP"]
66

77
Flashduty 支持 SAML2.0、OIDC、CAS 和 LDAP(仅私有化版本)协议的单点登录(SSO)接入,帮助您轻松集成到各种应用和平台中。用户只需登录一次,便可访问多个关联的应用程序和服务,无需重复身份验证。
88

9+
## 网络访问要求
10+
11+
---
12+
13+
不同协议对身份提供商(IdP)的网络可达性要求不同,配置前建议先确认,避免因网络不通导致登录失败:
14+
15+
| 协议 | 是否需要 Flashduty 访问身份提供商 | 说明 |
16+
| --- | --- | --- |
17+
| SAML 2.0 | 不需要 | 登录全程通过成员的浏览器完成:浏览器被重定向到身份提供商,登录后再把签名的 SAMLResponse 回传给 Flashduty。Flashduty 服务端不会主动连接身份提供商,签名基于您上传的元数据在本地校验 |
18+
| OIDC | 需要 | 每次登录,Flashduty 服务端都需要访问身份提供商的 Discovery 文档、Token 端点和 JWKS 端点;当 ID Token 未携带完整的映射字段时,还会额外访问 UserInfo 端点 |
19+
| CAS | 需要 | 每次登录,Flashduty 服务端都需要调用身份提供商的 `/serviceValidate` 接口校验登录票据。CAS 协议本身不提供其他校验方式——票据不携带签名信息,只能回源验证 |
20+
| LDAP | 不涉及公网访问 | 仅私有化版本支持,Flashduty 部署在您自有网络内,不存在公网可达性问题 |
21+
22+
如果您的身份提供商部署在内网、无法从公网访问:
23+
24+
- 可以将 Flashduty 的出口 IP `47.94.95.118`、`123.56.8.183`、`47.94.193.81` 和 `1.13.19.96` 加入防火墙白名单,放通 Flashduty 到身份提供商的访问
25+
- 如果不希望为身份提供商开放任何公网访问,**SAML 2.0** 是唯一无需 Flashduty 访问身份提供商的协议,推荐优先选择
26+
27+
<Note>
28+
以上出口 IP 仅适用于 Flashduty **SaaS(公有云)服务**。如果您使用的是私有化部署版本,Flashduty 运行在您自己的网络中,出口 IP 由您自身的部署环境决定,请向您的基础设施团队确认,不要使用上述地址。
29+
</Note>
30+
931
## 配置 SAML 协议
1032

1133
---

0 commit comments

Comments
 (0)