ClusterIdentityProvider

Group agentprimitives.authzed.com · Scope Cluster · Short names cidp

ClusterIdentityProvider configures cluster-wide human login: which registered idp.Kind authenticates people (pkg/platform/identity/idp), its OIDC client details, which email domains are admitted, and how long a browser session lives.

Cluster-scoped singleton -- the only permitted name is "default" (ClusterIdentityProviderName). Reconciled by pkg/controllers/clusteridentityprovider, which shares its spec judgment with the admission webhook so the two can never disagree, and refuses a local-only kind on a non-local cluster.

Spec

FieldTypeDescription
spec.allowAnyEmailbooleanAllowAnyEmail must be set explicitly to run with no domain gate.
spec.allowedEmailDomains[]stringAllowedEmailDomains gates who counts as logged in. Empty with AllowAnyEmail=false is invalid (fail closed) — enforced by webhook.
spec.clientID *stringClientID is the OAuth client id (not secret; inline).
spec.clientSecretRef *objectClientSecretRef names the Secret key holding the client secret.
spec.clientSecretRef.key *stringKey is the data key within the Secret holding the value.
spec.clientSecretRef.name *stringName is the Secret's name.
spec.clientSecretRef.namespace *stringNamespace is the Secret's namespace; required, since the referring CRD is cluster-scoped.
spec.federationobjectFederation, when Enabled, turns this IdP into an EMA federation source: login requests offline_access so the user's refresh token is captured, and the broker mints upstream tokens via ID-JAG. Requires kind=oidc and a confidential client (see the webhook).
spec.federation.enabledbooleanEnabled turns this IdP into an EMA federation source.
spec.issuerstringIssuer is the OIDC issuer URL. Required for kind=oidc; must be empty for kind=google (the kind pins it). Enforced by webhook.
spec.kind *stringKind names the registered idp kind: "oidc" or "google".
spec.scopes[]stringScopes are extra scopes beyond openid/email/profile.
spec.sessionTTLstringSessionTTL is the idd_session cookie lifetime for IdP-verified logins (and the CLI assertion lifetime). Default 12h.
* required

Status

Status is controller-owned (observed state).

FieldTypeDescription
status.conditions[]objectConditions carries Valid; identityd consults it before serving login.
status.conditions[].lastTransitionTime *string (date-time)lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
status.conditions[].message *stringmessage is a human readable message indicating details about the transition. This may be an empty string.
status.conditions[].observedGenerationinteger (int64)observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. (min 0)
status.conditions[].reason *stringreason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty.
status.conditions[].status *stringstatus of the condition, one of True, False, Unknown. (enum: True | False | Unknown)
status.conditions[].type *stringtype of condition in CamelCase or in foo.example.com/CamelCase.
status.observedGenerationinteger (int64)ObservedGeneration is the generation the conditions describe.
* required