infra:services:hacker-id
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
infra:services:hacker-id [2025/08/01 08:05] – [Changing account name] d404d_idp.hackeriet.no | infra:services:hacker-id [2025/08/13 21:24] (current) – [System setup] d404d_idp.hackeriet.no | ||
---|---|---|---|
Line 12: | Line 12: | ||
Regards, 404'd | Regards, 404'd | ||
</ | </ | ||
- | |||
A simple self-service portal on https:// | A simple self-service portal on https:// | ||
Access control is currently managed through the Kanidm CLI. [[https:// | Access control is currently managed through the Kanidm CLI. [[https:// | ||
+ | |||
+ | ===== Onboarding ===== | ||
+ | Hackeriet members can begin onboarding by visiting the Hacker-ID section in Hula: | ||
+ | |||
+ | https:// | ||
===== Hacker-ID capable services ===== | ===== Hacker-ID capable services ===== | ||
Line 38: | Line 42: | ||
This includes the login name used for both the web portal, and any Unix accounts used on servers. | This includes the login name used for both the web portal, and any Unix accounts used on servers. | ||
- | Unless noted otherwise here, all services consuming Hacker-ID supports account renames. | ||
- | |||
This can be done from the profile section of the self-service portal: https:// | This can be done from the profile section of the self-service portal: https:// | ||
- | You can also rename | + | Unless noted otherwise here, all services consuming Hacker-ID supports account renames/ |
+ | |||
+ | <WRAP center round alert 60%> | ||
+ | Mobilizon (events.hackeriet.no) uses your EMAIL for account bindings. It does not seem like we can change this. | ||
+ | |||
+ | Please get someone to help you with updating your email in Mobilizon in order to avoid losing access to your account. | ||
+ | |||
+ | When changing emails, you should keep your old primary email on-account | ||
+ | </ | ||
- | <code>kanidm person | + | <WRAP center round important 60%> |
+ | Note that some applications (e.g. Netbox and Wiki) will not automatically | ||
+ | </WRAP> | ||
+ | You can also rename and update your account profile using the CLI: | ||
+ | * Account name: < | ||
+ | * Display name: < | ||
+ | * Email: < | ||
===== ACL structure ===== | ===== ACL structure ===== | ||
During the draft phase, the following groups have been configured: | During the draft phase, the following groups have been configured: | ||
Line 60: | Line 76: | ||
| '' | | '' | ||
| '' | | '' | ||
+ | | '' | ||
| '' | | '' | ||
- | | '' | + | | '' |
| '' | | '' | ||
| '' | | '' | ||
Line 140: | Line 157: | ||
* Located in ''/ | * Located in ''/ | ||
* One docker compose stack with Traefik (for certificate issuance as LE needs this in-line) and Kanidm | * One docker compose stack with Traefik (for certificate issuance as LE needs this in-line) and Kanidm | ||
+ | * [[https:// | ||
* Communication between the two are encrypted using a self-signed certificate (Kanidm requires last-hop encryption) | * Communication between the two are encrypted using a self-signed certificate (Kanidm requires last-hop encryption) | ||
* Created user and group " | * Created user and group " |
/srv/hackeriet-wiki/dokuwiki/data/attic/infra/services/hacker-id.1754035551.txt.gz · Last modified: by d404d_idp.hackeriet.no