Project

General

Custom queries

Profile

Actions

Idea #15529

closed

[API] [Controller] Share user account database with a group of trusted clusters

Added by Peter Amstutz over 5 years ago. Updated about 5 years ago.

Status:
Resolved
Priority:
Normal
Assigned To:
Category:
-
Target version:
Start date:
08/22/2019
Due date:
Story points:
5.0
Release relationship:
Auto

Description

Multi-cluster user database

Configuration

Add Login.LoginCluster config mentioned on the Multi-cluster user database wiki

Login

  1. Instead of logging in to a local SSO provider, can designate a home cluster (cluster A) where login is always sent
  2. After logging in, user is sent to original cluster (cluster B) with a token issued by the home cluster (cluster A)
  3. Users from LoginCluster (cluster A) have extra trust on cluster B (respects admin flag)

Subtasks 1 (0 open1 closed)

Task #15552: Review 15529-federated-user-accountsResolvedPeter Amstutz08/22/2019Actions

Related issues 4 (0 open4 closed)

Related to Arvados - Idea #15477: Use email address for Arvados account linkingDuplicateActions
Related to Arvados - Feature #15531: [SDK] Migrate federation to central LoginClusterResolvedPeter Amstutz09/23/2019Actions
Related to Arvados - Feature #15530: Workbench2 trusts federation usersResolvedPeter AmstutzActions
Related to Arvados - Idea #15558: [SSO] [API] Identify users by (alternate) email addressesResolvedPeter Amstutz08/22/2019Actions
#1

Updated by Peter Amstutz over 5 years ago

  • Description updated (diff)
#2

Updated by Tom Clegg over 5 years ago

  • Related to Idea #15477: Use email address for Arvados account linking added
#3

Updated by Peter Amstutz over 5 years ago

  • Related to Feature #15531: [SDK] Migrate federation to central LoginCluster added
#4

Updated by Peter Amstutz over 5 years ago

#5

Updated by Peter Amstutz over 5 years ago

  • Description updated (diff)
#6

Updated by Peter Amstutz over 5 years ago

  • Subject changed from Federated users to Trust federated users from other clusters
#7

Updated by Tom Clegg over 5 years ago

  • Subject changed from Trust federated users from other clusters to [API] [Controller] Share user account database with a group of trusted clusters
  • Description updated (diff)
#8

Updated by Tom Clegg over 5 years ago

  • Description updated (diff)
#9

Updated by Tom Clegg over 5 years ago

  • Description updated (diff)
#10

Updated by Tom Clegg over 5 years ago

  • Description updated (diff)
#11

Updated by Tom Clegg over 5 years ago

  • Description updated (diff)
#12

Updated by Tom Clegg over 5 years ago

  • Description updated (diff)
#13

Updated by Tom Morris over 5 years ago

  • Story points set to 5.0
#14

Updated by Tom Clegg over 5 years ago

  • Description updated (diff)
#15

Updated by Tom Morris over 5 years ago

  • Target version changed from To Be Groomed to 2019-08-28 Sprint
#16

Updated by Tom Morris over 5 years ago

  • Assigned To set to Peter Amstutz
#20

Updated by Peter Amstutz over 5 years ago

  • Description updated (diff)
#21

Updated by Tom Clegg over 5 years ago

  • Description updated (diff)
#22

Updated by Peter Amstutz over 5 years ago

  • Description updated (diff)
#23

Updated by Peter Amstutz over 5 years ago

  • Description updated (diff)
#24

Updated by Peter Amstutz over 5 years ago

  • Description updated (diff)
#26

Updated by Peter Amstutz over 5 years ago

  • Related to Idea #15558: [SSO] [API] Identify users by (alternate) email addresses added
#27

Updated by Tom Morris over 5 years ago

  • Target version changed from 2019-08-28 Sprint to 2019-09-11 Sprint
#31

Updated by Peter Amstutz over 5 years ago

  • Status changed from New to Resolved
#32

Updated by Peter Amstutz about 5 years ago

  • Release set to 22
Actions

Also available in: Atom PDF