Repository navigation
Add federated authorization tutorial - #599
Merged
Merged
Conversation
Adds a tutorial showing how to federate authorization across multiple identity providers (Keycloak OIDC + GitHub OAuth) by binding each external account to a canonical internal SpiceDB user. Includes the architecture diagram and links to the runnable demo in authzed/examples. Signed-off-by: Sohan Maheshwar <1119120+sohanmaheshwar@users.noreply.github.com>
Addresses review feedback: avoid two sequential callouts by nesting each warning under the list item it pertains to. Signed-off-by: Sohan Maheshwar <1119120+sohanmaheshwar@users.noreply.github.com>
- Name LookupSubjects explicitly for the bound_to lookup in Step 2 (per review) - Add a step to carry the resolved internal user id through the session - Complete the Step 3 relationship-lifecycle explanation (create/update/delete) - Expand the upstream/downstream auth boundary note in Step 4 - Describe the LookupResources API in Step 5 - Replace the architecture diagram (bindings now shown stored in SpiceDB) and update alt text
Reflect updates to the authzed/examples demo since the tutorial was written: - Swap in the new architecture diagram showing the PostgreSQL datastore - Add a persistence note: SpiceDB now runs on --datastore-engine=postgres with a one-shot migration, so identity bindings and grants survive restarts - Add a prominent callout linking to the runnable demo repo and its docker-compose stack, and reword the Next steps pointer so it isn't a dupe - Align the zed preshared key with the demo's token
Contributor
|
Preview deployment status for this pull request.
|
…on-tutorial # Conflicts: # app/spicedb/tutorials/federated-authorization/page.mdx # lib/changed-pages.json # public/images/federated-architecture.png
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds a SpiceDB tutorial on federating authorization across multiple identity providers — binding each external account (Keycloak OIDC, GitHub OAuth) to a canonical internal
user, so disparate IdPs can share resources without an identity migration.The tutorial walks through:
*_accounttype that binds to a shareduserLookupSubjectsonbound_tozed+ Python)Latest changes in this PR
Brings the tutorial in line with the current
authzed/examplesdemo:--datastore-engine=postgreswith a one-shot migration, so identity bindings and grants survive restarts (which is what keeps a returning user mapped to the same internal user)docker-composestackzedpreshared key with the demo's tokenVerification
pnpm lint:markdown→ 0 errors