public-cloud-roadmap icon indicating copy to clipboard operation
public-cloud-roadmap copied to clipboard

Advanced OIDC parameters

Open mhurtrel opened this issue 3 years ago • 12 comments

As a Managed Kubernetes user using OIDC https://github.com/ovh/public-cloud-roadmap/issues/17 I want to be able to add optionnal parameters listed here : https://kubernetes.io/docs/reference/access-authn-authz/authentication/#configuring-the-api-server So that I can use more than basic user managements

mhurtrel avatar Dec 21 '21 17:12 mhurtrel

Any rough estimates for when this feature would be available via the API? I'm not looking for a watertight guarantee, just wondering if the time is best measured in weeks or months.

flying-kestrel avatar Dec 23 '21 01:12 flying-kestrel

@flying-kestrel i dont have yet a commited eta (will make to have one after the end-of-year holidays) but i have strong hope we will have it in the upcoming quarter

mhurtrel avatar Dec 23 '21 19:12 mhurtrel

I hope that we can use --oidc-username-claim=email at least, as it is quite a common requirement in production k8s for organisations.

kennylam777 avatar Jun 24 '22 21:06 kennylam777

Any news to that issue? Need also the Groups support.

OMarohn avatar Jul 06 '22 12:07 OMarohn

Hello @OMarohn group support is part of the feature yep. I do not have precise eta yet, the feature is being developped.

mhurtrel avatar Jul 12 '22 13:07 mhurtrel

Hello We planned to deliver this feature for the end of October.

New ApiServer's parameters (not yet defined on our API) --oidc-username-claim --oidc-username-prefix --oidc-groups-claim --oidc-groups-prefix --oidc-required-claim --oidc-ca-file

jMonsinjon avatar Sep 14 '22 13:09 jMonsinjon

Any news on that feature release date?

SimonRTC avatar Nov 07 '22 20:11 SimonRTC

Hi @SimonRTC We had some unexpected delay but plan to deliver the feature next week (API only at first)

mhurtrel avatar Nov 08 '22 11:11 mhurtrel

The new parameters appeared in the api today and worked like a charm :D

zeeZ avatar Nov 17 '22 18:11 zeeZ

Just tested and it works exactly as expected! Many thanks @mhurtrel

OlivierJavaux avatar Nov 18 '22 16:11 OlivierJavaux

Hi, for your information we published a tutorial in order to configure the new parameters through the Control Panel (soon), the API and Terraform: https://docs.ovh.com/gb/en/kubernetes/configure-oidc-provider/

scraly avatar Nov 25 '22 12:11 scraly

I think this issue can be closed, right ?

bmm-alc avatar Mar 12 '24 16:03 bmm-alc