Do we need a Co-op Cloud single sign on solution? #669
Notifications
Due Date
No due date set.
Blocks
#665 A New Docs Platform?
toolshed/organising
Reference: toolshed/organising#669
Loading…
x
Reference in New Issue
Block a user
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
We currently have
https://git.coopcloud.tech
https://kimai.coopcloud.tech/
Perhaps we might want to think about oauth SSO if we do need any more platforms? Kimai may become necessary to track out time and manage budgets. We're thinking of moving to a GUI wiki e.g. Dokuwiki
Currently Autonomic, Local IT and Doop Coop all have their own SSO plugged into Gitea. Do we setup a new SSO server for those folks that don't have their own orga that has one?
What do folks think is the way forward?
Yeh, I would be up for centralising on a single SSO solution. Authentik seems to be the chosen weapon of choice lately and fedi members have experience with it. The existing provider integrations (Autonomic, Local-IT, etc.) could be migrated from the Gitea login to Authentik itself, so people could still retain their SSO setup. It might be a tricky migration but we could manage it.
Yeah, great suggestion.
Current plan:
Holy cow, look at this cursed solution for Kimai x OIDC:
rauthy
supportsAUTH_HEADERS_ENABLE=true
:This means an admin would have to log in and create the matching username/email before you could login from the SSO side of things 😂 I'm not sure I would recommend this but I'd be up for trying to hack it together one of the days if someone else is keen.
I mean I'm not totally against it, I don't expect a million people needing to use Kimai – and maybe the "radical administrator" could help make sure this work doesn't fall through the cracks. Fine with either this or Authentik.
Maybe we could just use something that supports oauth.
Open to it. Focustime doesn't seem to support SSO at all, and I'm not aware of other Kimai alternatives.