ovh / public-cloud-roadmap

Agile roadmap for OVHcloud Public Cloud services. Discover the features our product teams are working on, comment and influence our backlog.
https://www.ovhcloud.com/en/public-cloud/
187 stars 5 forks source link

Identity Federation #43

Open JacquesMrz opened 3 years ago

JacquesMrz commented 3 years ago

As a customer I should be able to federate Public Cloud User&Roles Mgmt with my private directory.

desaintmartin commented 3 years ago

How would "private directory" be defined?

mhurtrel commented 3 years ago

@desaintmartin my colleague @JacquesMrz will precise but at this time, the most current request we have is the federation with either ActiveDirectory, LDAP and OpendID Connect (OIDC). We want to keep ensure you benefit both from the rich features of the different RBAC granularity brought with K8s RBAC, Hadoop RBAC etc but, when you want so, be able to federate those to a common list of users accros all public cloud products and federate this list with a AD/LDAP/OIDC that you may have onprem or in the cloud.

gbarideau commented 1 year ago

OVHcloud allow now to federate any directory using SAMLv2 to the OVHcloud Manager : https://help.ovhcloud.com/csm/en-gb-connect-saml-sso-azure-ad?id=kb_article_view&sysparm_article=KB0057535 Other guide for Okta, AD FS and Google Workspace are available.

The ability to use the same federation to log as well to the Public Cloud environment is coming for this summer.

gbarideau commented 1 year ago

It's now possible using the OVHcloud IAM to use an account coming from the federation with OVHcloud to log automatically to Openstack. More information available on our website : https://www.ovhcloud.com/en-gb/identity-security/identity-access-management/