Skip to content

docs: correct rbac.md against engine main and settle the Okta setup page - #785

Merged
catinspace-au merged 1 commit into
mainfrom
docs/idp-setup-landing-rbac
Oct 10, 2026
Merged

catinspace-au merged 1 commit into
mainfrom
docs/idp-setup-landing-rbac

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

Follow-up to #783. Three things, all docs.

  • docs/control-plane/idp-setup/README.md -- a landing page for the three IdP pages: which page, which provider type, what a group links on, the shared redirect URI.
  • docs/control-plane/idp-setup/okta.md -- the org authorization server sends no groups claim in the ID token, so that alternative is gone. The default custom server is the one path. A claim with no scope condition arrives whether or not groups is requested, and the scope and access-policy checks stay.
  • docs/control-plane/rbac.md -- accuracy only, checked against main:
    • auth paths: the X-Oidc-* headers need auth.trust_proxy_auth_headers, and auth disabled needs a dev DFE_ENV
    • API keys default to a 90-day TTL (auth.api_key_default_ttl_days)
    • roles live in rbac/roles.yaml, there are 8 built-in roles (dfe_operator), custom roles go through /api/v1/auth/roles
    • the permission table matches the scope catalogue (delete actions, source:deploy, transform not transforms, no dashboard:write)
    • authorize() takes a scope and decides on scoped grants
    • the auth routes and CRUD prefixes are listed
    • the OIDC adapter diagram and table match the code (Okta is not a stub, Google reads Cloud Identity as the user, Entra reads Graph on overage)
    • the audit table lists what is emitted, and says group, API key, account and role CRUD emit nothing
    • the settings block lists the fields actually read
    • edge cases for multi-role, ClickHouse down and the default password match the code

No restructure, no cuts beyond the corrections. Done when this is on main with CI green.

rbac.md: the auth paths now name the proxy-header trust flag and the dev-posture gate, API keys carry the default TTL, roles live in rbac/roles.yaml with eight built-in roles, the permission table matches the scope catalogue, the auth routes and OIDC adapters match the code, the audit table lists the events actually emitted, and the settings block lists the fields actually read. okta.md drops the org authorization server, which sends no groups claim in the ID token, and keeps the default custom server as the one path. Adds a landing page for idp-setup/.
@catinspace-au
catinspace-au merged commit afb92d0 into main Oct 10, 2026
20 checks passed
@catinspace-au
catinspace-au deleted the docs/idp-setup-landing-rbac branch October 10, 2026 07:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant