Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Docs: Improve SSO Settings docs #83914

Merged
merged 3 commits into from Mar 9, 2024
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
4 changes: 4 additions & 0 deletions docs/sources/developers/http_api/sso-settings.md
Expand Up @@ -22,6 +22,10 @@ title: SSO Settings API

> If you are running Grafana Enterprise, for some endpoints you'll need to have specific permissions. Refer to [Role-based access control permissions]({{< relref "/docs/grafana/latest/administration/roles-and-permissions/access-control/custom-role-actions-scopes" >}}) for more information.

{{% admonition type="note" %}}
Available in Public Preview in Grafana 10.4 and on Grafana Cloud behind the `ssoSettingsApi` feature toggle.
{{% /admonition %}}

The API can be used to create, update, delete, get, and list SSO Settings.

## List SSO Settings
Expand Down
Expand Up @@ -21,6 +21,10 @@ weight: 800

The Azure AD authentication allows you to use an Azure Active Directory tenant as an identity provider for Grafana. You can use Azure AD application roles to assign users and groups to Grafana roles from the Azure Portal.

{{% admonition type="note" %}}
If Users use the same email address in Azure AD that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [doc-validator] reported by reviewdog 🐶
The relref shortcode argument '{{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}' has a trailing slash, which can break the resolution.
You can reference an index.md file either by its path or by its containing folder without the ending /.
You can reference an _index.md file only by its containing folder.

Remove the trailing slash to make sure that changing the index type doesn't break the link.

Suggested change
If Users use the same email address in Azure AD that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.
If Users use the same email address in Azure AD that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.

{{% /admonition %}}

## Create the Azure AD application

To enable the Azure AD OAuth2, register your application with Azure AD.
Expand Down
Expand Up @@ -23,6 +23,10 @@ weight: 900

This topic describes how to configure GitHub OAuth2 authentication.

{{% admonition type="note" %}}
If Users use the same email address in GitHub that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [doc-validator] reported by reviewdog 🐶
The relref shortcode argument '{{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}' has a trailing slash, which can break the resolution.
You can reference an index.md file either by its path or by its containing folder without the ending /.
You can reference an _index.md file only by its containing folder.

Remove the trailing slash to make sure that changing the index type doesn't break the link.

Suggested change
If Users use the same email address in GitHub that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.
If Users use the same email address in GitHub that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.

{{% /admonition %}}

## Before you begin

Ensure you know how to create a GitHub OAuth app. Consult GitHub's documentation on [creating an OAuth app](https://docs.github.com/en/apps/oauth-apps/building-oauth-apps/creating-an-oauth-app) for more information.
Expand Down
Expand Up @@ -23,6 +23,10 @@ weight: 1000

This topic describes how to configure GitLab OAuth2 authentication.

{{% admonition type="note" %}}
If Users use the same email address in GitLab that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [doc-validator] reported by reviewdog 🐶
The relref shortcode argument '{{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}' has a trailing slash, which can break the resolution.
You can reference an index.md file either by its path or by its containing folder without the ending /.
You can reference an _index.md file only by its containing folder.

Remove the trailing slash to make sure that changing the index type doesn't break the link.

Suggested change
If Users use the same email address in GitLab that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.
If Users use the same email address in GitLab that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.

{{% /admonition %}}

## Before you begin

Ensure you know how to create a GitLab OAuth application. Consult GitLab's documentation on [creating a GitLab OAuth application](https://docs.gitlab.com/ee/integration/oauth_provider.html) for more information.
Expand Down
Expand Up @@ -16,6 +16,10 @@ weight: 1100

To enable Google OAuth2 you must register your application with Google. Google will generate a client ID and secret key for you to use.

{{% admonition type="note" %}}
If Users use the same email address in Google that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [doc-validator] reported by reviewdog 🐶
The relref shortcode argument '{{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}' has a trailing slash, which can break the resolution.
You can reference an index.md file either by its path or by its containing folder without the ending /.
You can reference an _index.md file only by its containing folder.

Remove the trailing slash to make sure that changing the index type doesn't break the link.

Suggested change
If Users use the same email address in Google that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.
If Users use the same email address in Google that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.

{{% /admonition %}}

## Create Google OAuth keys

First, you need to create a Google OAuth Client:
Expand Down
Expand Up @@ -24,6 +24,10 @@ Keycloak OAuth2 authentication allows users to log in to Grafana using their Key

Refer to [Generic OAuth authentication]({{< relref "../generic-oauth" >}}) for extra configuration options available for this provider.

{{% admonition type="note" %}}
If Users use the same email address in Keycloak that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [doc-validator] reported by reviewdog 🐶
The relref shortcode argument '{{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}' has a trailing slash, which can break the resolution.
You can reference an index.md file either by its path or by its containing folder without the ending /.
You can reference an _index.md file only by its containing folder.

Remove the trailing slash to make sure that changing the index type doesn't break the link.

Suggested change
If Users use the same email address in Keycloak that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.
If Users use the same email address in Keycloak that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.

{{% /admonition %}}

You may have to set the `root_url` option of `[server]` for the callback URL to be
correct. For example in case you are serving Grafana behind a proxy.

Expand Down
Expand Up @@ -16,6 +16,10 @@ weight: 1400

{{< docs/shared lookup="auth/intro.md" source="grafana" version="<GRAFANA VERSION>" >}}

{{% admonition type="note" %}}
If Users use the same email address in Okta that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [doc-validator] reported by reviewdog 🐶
The relref shortcode argument '{{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}' has a trailing slash, which can break the resolution.
You can reference an index.md file either by its path or by its containing folder without the ending /.
You can reference an _index.md file only by its containing folder.

Remove the trailing slash to make sure that changing the index type doesn't break the link.

Suggested change
If Users use the same email address in Okta that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication/#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.
If Users use the same email address in Okta that they use with other authentication providers (such as Grafana.com), you need to do additional configuration to ensure that the users are matched correctly. Please refer to the [Using the same email address to login with different identity providers]({{< relref "../configure-authentication#using-the-same-email-address-to-login-with-different-identity-providers" >}}) documentation for more information.

{{% /admonition %}}

## Before you begin

To follow this guide, ensure you have permissions in your Okta workspace to create an OIDC app.
Expand Down