Skip to content

Support validate claims with CEL expr for SSO #20083

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 10 commits into from
Aug 7, 2024
Merged

Support validate claims with CEL expr for SSO #20083

merged 10 commits into from
Aug 7, 2024

Conversation

mustard-mh
Copy link
Contributor

@mustard-mh mustard-mh commented Aug 1, 2024

Description

image

Related Issue(s)

Relates ENT-561

How to test

Current CEL expression in preview env is 'gitpod-team' in claims.groups_direct || (claims.email_verified && claims.email.endsWith("@gitpod.io"))

  • Log into preview env with GitLab.com x SSO, conditions below depends whether you could login successfully:
    • If your validated email is ends with @gitpod.io, you should be able to login
    • If your are a member of group gitpod-team, you should be able to login

Setup Preview envs with Self-hosted / SaaS GitLab

  • Re trigger GHA if preview env is deleted, (or delete preview env when needed)
  • Login with OIDC setup
previewctl admin credentials create
kubectl rollout restart deploy/server
  • Setup OIDC with gitlab.com and Self-Hosted gitlab
  • Play with CEL expression

Documentation

Preview status

Gitpod was successfully deployed to your preview environment.

Build Options

Build
  • /werft with-werft
    Run the build with werft instead of GHA
  • leeway-no-cache
  • /werft no-test
    Run Leeway with --dont-test
Publish
  • /werft publish-to-npm
  • /werft publish-to-jb-marketplace
Installer
  • analytics=segment
  • with-dedicated-emulation
  • workspace-feature-flags
    Add desired feature flags to the end of the line above, space separated
Preview Environment / Integration Tests
  • /werft with-local-preview
    If enabled this will build install/preview
  • /werft with-preview
  • /werft with-large-vm
  • /werft with-gce-vm
    If enabled this will create the environment on GCE infra
  • /werft preemptible
    Saves cost. Untick this only if you're really sure you need a non-preemtible machine.
  • with-integration-tests=all
    Valid options are all, workspace, webapp, ide, jetbrains, vscode, ssh. If enabled, with-preview and with-large-vm will be enabled.
  • with-monitoring

/hold

@mustard-mh mustard-mh changed the title WIP WIP Support validate claims with CEL expr for SSO Aug 2, 2024
@geropl
Copy link
Member

geropl commented Aug 7, 2024

Going to configure the preview env now 👀

@geropl
Copy link
Member

geropl commented Aug 7, 2024

And it works nicely! 🥳

Copy link
Member

@geropl geropl left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code LGTM, tested and works! ✔️

There are two nits I have (alignment and a trim() we could sprinkle in) but let's do those separately.

Nice work @mustard-mh !

@geropl
Copy link
Member

geropl commented Aug 7, 2024

/unblock

@geropl
Copy link
Member

geropl commented Aug 7, 2024

/unhold

@roboquat roboquat merged commit c4b53f9 into main Aug 7, 2024
19 checks passed
@roboquat roboquat deleted the hw/oidc-cel branch August 7, 2024 06:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants