infra:services:hacker-id
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| infra:services:hacker-id [2025/07/26 17:01] – d404d_idp.hackeriet.no | infra:services:hacker-id [2025/08/13 21:24] (current) – [System setup] d404d_idp.hackeriet.no | ||
|---|---|---|---|
| Line 12: | Line 12: | ||
| Regards, 404'd | Regards, 404'd | ||
| </ | </ | ||
| - | |||
| A simple self-service portal on https:// | A simple self-service portal on https:// | ||
| Access control is currently managed through the Kanidm CLI. [[https:// | Access control is currently managed through the Kanidm CLI. [[https:// | ||
| + | |||
| + | ===== Onboarding ===== | ||
| + | Hackeriet members can begin onboarding by visiting the Hacker-ID section in Hula: | ||
| + | |||
| + | https:// | ||
| ===== Hacker-ID capable services ===== | ===== Hacker-ID capable services ===== | ||
| Line 34: | Line 38: | ||
| Implementation of Hacker-ID onboarding is discussed in this Github ticket: https:// | Implementation of Hacker-ID onboarding is discussed in this Github ticket: https:// | ||
| - | ==== Changing account name ==== | + | ==== Changing account name/display name/ |
| - | All users are able to change their own account | + | All users are able to change their personal information. |
| + | |||
| + | This includes the login name used for both the web portal, and any Unix accounts used on servers. | ||
| + | This can be done from the profile section of the self-service portal: https:// | ||
| + | |||
| + | Unless noted otherwise here, all services consuming Hacker-ID supports account renames/ | ||
| + | |||
| + | <WRAP center round alert 60%> | ||
| + | Mobilizon (events.hackeriet.no) uses your EMAIL for account bindings. It does not seem like we can change this. | ||
| - | This is the login name used for both the web portal, and any Unix accounts used on servers. | + | Please get someone to help you with updating your email in Mobilizon in order to avoid losing access to your account. |
| - | Unless noted otherwise here, all services consuming Hacker-ID supports | + | |
| - | You can rename | + | When changing emails, you should keep your old primary email on-account |
| + | </ | ||
| - | <code>kanidm person | + | <WRAP center round important 60%> |
| + | Note that some applications (e.g. Netbox and Wiki) will not automatically | ||
| + | </WRAP> | ||
| + | You can also rename and update your account profile using the CLI: | ||
| + | * Account name: < | ||
| + | * Display name: < | ||
| + | * Email: < | ||
| ===== ACL structure ===== | ===== ACL structure ===== | ||
| During the draft phase, the following groups have been configured: | During the draft phase, the following groups have been configured: | ||
| ^ Name ^ Entry manager ^ Description ^ | ^ Name ^ Entry manager ^ Description ^ | ||
| - | | '' | + | | '' |
| - | | '' | + | | '' |
| - | | '' | + | | '' |
| - | | '' | + | | '' |
| - | | '' | + | | '' |
| | '' | | '' | ||
| | '' | | '' | ||
| | '' | | '' | ||
| | '' | | '' | ||
| + | | '' | ||
| | '' | | '' | ||
| + | | '' | ||
| | '' | | '' | ||
| | '' | | '' | ||
| | '' | | '' | ||
| + | | '' | ||
| IDP admins may always step in to assist, shall any of the groups be orphaned (no active/ | IDP admins may always step in to assist, shall any of the groups be orphaned (no active/ | ||
| Line 136: | Line 157: | ||
| * Located in ''/ | * Located in ''/ | ||
| * One docker compose stack with Traefik (for certificate issuance as LE needs this in-line) and Kanidm | * One docker compose stack with Traefik (for certificate issuance as LE needs this in-line) and Kanidm | ||
| + | * [[https:// | ||
| * Communication between the two are encrypted using a self-signed certificate (Kanidm requires last-hop encryption) | * Communication between the two are encrypted using a self-signed certificate (Kanidm requires last-hop encryption) | ||
| * Created user and group " | * Created user and group " | ||
/srv/hackeriet-wiki/dokuwiki/data/attic/infra/services/hacker-id.1753549274.txt.gz · Last modified: by d404d_idp.hackeriet.no