Actions
Support #387
openSupport #311: OAM - Security Hardening Auditing and Compliance
OAM: OIDC auth via Cloudron (IDP)
Support #387:
OAM: OIDC auth via Cloudron (IDP)
Start date:
08/06/2026
Due date:
% Done:
0%
Estimated time:
Description
Parent/umbrella: #311 (OAM - Security Hardening Auditing and Compliance).
Eliminate local non-root accounts by routing all system authentication through Cloudron as the identity provider using OIDC.
Scope¶
- Configure Cloudron as OIDC identity provider
- Integrate OIDC auth for system login (SSH, Cockpit, Webmin)
- Map Cloudron groups/roles to system access
- Remove local non-root accounts
- Validate in sectestbed-* before prod
Context¶
- Cloudron does NOT support LDAP for system login (LDAP is app-only).
- OIDC is the supported path for SSO.
- Roles executed via tsys-awx (AWX).
Dependencies¶
Depends on #379 (test lab). Blocks #388 (patch management), #390 (MDM).
Actions