Skip to content

The provisioner

A product that is running is not yet a product you can use. Its sign-in client must exist at the identity provider, your people need their roles, and the connections and secrets your processes use must be in place. The provisioner sets all of that up from files you keep, and puts it back when someone changes it by hand.

It is one small tool, provision, shipped only as the image registry.tinyfactory.ai/tinyblox/provision. You rarely run it yourself: the product charts run it as a Job, and you run it once more for the environment’s files.

Part What it sets up Status
Sign-in clients each product’s clients, roles and groups at the identity provider, and one Kubernetes Secret per client provisioner 0.1.0 coming; the product charts run it from their next releases
People and permissions groups, who is in them, which roles each group holds in each product, demo accounts provisioner 0.1.0 coming
The environment file which products make up an environment, and where they are coming
Product content connections, AI settings, prompts, secret names, sign-in providers coming
Platform secrets database passwords, keys and the other secrets the products need before they start coming

Identity providers: TinyGuard and Keycloak. Microsoft Entra ID and Okta are planned. With any other provider, switch provisioning off and register the clients by hand.

  • Plan first. provision plan shows what would be created, changed and deleted, and changes nothing.
  • The same run twice changes nothing. You can run it on every install, upgrade and Argo CD sync.
  • It puts things back. A redirect address someone edited by hand at the identity provider is set back to what the files say.
  • It removes what you removed. A client, group or role binding you take out of a file is deleted at the next run.
  • It touches only what it made. Everything it creates carries a marker naming the environment, namespace and product. Anything without that marker, such as a client made by hand, is left alone and reported.
  • It never shows a secret. No secret appears in its output or logs, and it never issues a new client secret unless you ask.

Every file has the same header, so you can keep them side by side in one folder of your Git repository:

apiVersion: tinyblox.ai/v1alpha1
kind: Access # or Environment, TinyConductorContent, PlatformSecrets, …
environment: production # recorded on everything the file creates

Each product publishes the schema of its own kind, so your editor can check a file as you write it.