Sign-in across products
Every TinyBlox product signs people in through one identity provider, with OpenID Connect. Signed in once, a person opens any other console without signing in again: the identity provider remembers them.
Choosing the identity provider
Section titled “Choosing the identity provider”| When | |
|---|---|
| TinyGuard | You want the platform to bring its own: tenants, multifactor sign-in, sign-in through Google or another provider, and setup by the provisioner. See the TinyGuard guide. |
| Keycloak | You already run it. The provisioner supports it as well. |
| Microsoft Entra ID, Okta, others | You already run them. Register each product’s clients by hand (how); the provisioner’s support for Entra ID and Okta is planned. |
Whatever the provider, each product needs:
- a client for its console, with the product’s redirect address
(
https://<console address>/auth/callbackfor TinyConductor); - the groups and roles of the person in the token, in the
groupsandrolesclaims, so the product can give them their rights.
Roles and groups
Section titled “Roles and groups”Each product has its own roles, for example admin, operator and
viewer in TinyConductor. Who holds them is decided per environment: give
roles to groups once, for every product, in the
access file, or in your identity provider’s
console. Each product’s guide lists its roles and how it maps groups to
them.
Tenants
Section titled “Tenants”A product that serves several customers or teams keeps them apart as
tenants. Across products the same tenant has the same name: TinyConductor’s
tenant acme reads its secrets from TinyVault’s tenant acme.
When a person or service may act in more than one tenant, it names the
tenant on every API call in the header X-Tenant-Id. A call without it is
refused rather than given a default tenant. TinyConductor works this way
today; the other products follow coming.
The app switcher
Section titled “The app switcher”coming Each console will show an Apps button in its top bar, listing the other consoles of the environment that this person may open:
┌ Apps ──────────────────────────┐│ ◆ TinyConductor Current ││ ◆ TinyVault │└────────────────────────────────┘- Only what you may open. A console you have no access to is not listed. Who may open which console is set per environment, as any of a list of roles or groups, in the environment file.
- No second sign-in. Choosing a console opens it already signed in, through the identity provider’s existing session. If that session has ended, the provider asks you to sign in, as it would anyway.
- Any OpenID Connect provider. The list comes from your environment, not from the provider, so it works with TinyGuard, Keycloak, Entra ID, Okta or your own.
The details are still being settled; this section will grow when the first release with the switcher is listed on Release status.