Skip to content

Add federated authorization tutorial - #599

Merged
sohanmaheshwar merged 6 commits into
mainfrom
federated-authorization-tutorial
Oct 5, 2026
Merged

sohanmaheshwar merged 6 commits into
mainfrom
federated-authorization-tutorial

Conversation

@sohanmaheshwar

Copy link
Copy Markdown
Contributor

What

Adds a SpiceDB tutorial on federating authorization across multiple identity providers — binding each external account (Keycloak OIDC, GitHub OAuth) to a canonical internal user, so disparate IdPs can share resources without an identity migration.

The tutorial walks through:

  • Writing a schema where each IdP gets its own *_account type that binds to a shared user
  • Resolving each login to an internal user via LookupSubjects on bound_to
  • Granting access, checking permissions, sharing, and listing resources (zed + Python)
  • Notes on persistence and consistency

Latest changes in this PR

Brings the tutorial in line with the current authzed/examples demo:

  • New architecture diagram showing the PostgreSQL datastore
  • Persistence note — SpiceDB now runs on --datastore-engine=postgres with a one-shot migration, so identity bindings and grants survive restarts (which is what keeps a returning user mapped to the same internal user)
  • Prominent callout linking to the runnable demo repo and its docker-compose stack
  • Aligned the zed preshared key with the demo's token

Verification

  • pnpm lint:markdown → 0 errors
  • Previewed on the dev server: page compiles (HTTP 200), diagram and new sections render correctly

Adds a tutorial showing how to federate authorization across multiple identity providers (Keycloak OIDC + GitHub OAuth) by binding each external account to a canonical internal SpiceDB user. Includes the architecture diagram and links to the runnable demo in authzed/examples.

Signed-off-by: Sohan Maheshwar <1119120+sohanmaheshwar@users.noreply.github.com>
Addresses review feedback: avoid two sequential callouts by nesting each warning under the list item it pertains to.

Signed-off-by: Sohan Maheshwar <1119120+sohanmaheshwar@users.noreply.github.com>
- Name LookupSubjects explicitly for the bound_to lookup in Step 2 (per review)
- Add a step to carry the resolved internal user id through the session
- Complete the Step 3 relationship-lifecycle explanation (create/update/delete)
- Expand the upstream/downstream auth boundary note in Step 4
- Describe the LookupResources API in Step 5
- Replace the architecture diagram (bindings now shown stored in SpiceDB) and update alt text
Reflect updates to the authzed/examples demo since the tutorial was written:

- Swap in the new architecture diagram showing the PostgreSQL datastore
- Add a persistence note: SpiceDB now runs on --datastore-engine=postgres
  with a one-shot migration, so identity bindings and grants survive restarts
- Add a prominent callout linking to the runnable demo repo and its
  docker-compose stack, and reword the Next steps pointer so it isn't a dupe
- Align the zed preshared key with the demo's token
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment status for this pull request.

Name Status Preview Updated (UTC)
docs 🟢 Ready Visit Preview Oct 05, 2026 04:21pm

…on-tutorial

# Conflicts:
#	app/spicedb/tutorials/federated-authorization/page.mdx
#	lib/changed-pages.json
#	public/images/federated-architecture.png

@tstirrat15 tstirrat15 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@sohanmaheshwar
sohanmaheshwar merged commit 2f4de99 into main Oct 5, 2026
12 checks passed
@sohanmaheshwar
sohanmaheshwar deleted the federated-authorization-tutorial branch October 5, 2026 16:31
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 5, 2026

This branch was successfully deployed

1 active deployment
Preview (GitHub Actions) — 77d95858 Deployed Oct 5, 2026 by github-actions[bot]
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants