Project

General

Profile

Actions

Support #387

open

Support #311: OAM - Security Hardening Auditing and Compliance

OAM: OIDC auth via Cloudron (IDP)

Support #387: OAM: OIDC auth via Cloudron (IDP)

Added by Charles N 1 day ago. Updated 1 day ago.

Status:
Feedback
Priority:
Normal
Assignee:
Target version:
-
Start date:
08/06/2026
Due date:
% Done:

0%

Estimated time:

Description

Parent/umbrella: #311 (OAM - Security Hardening Auditing and Compliance).

Eliminate local non-root accounts by routing all system authentication through Cloudron as the identity provider using OIDC.

Scope

  • Configure Cloudron as OIDC identity provider
  • Integrate OIDC auth for system login (SSH, Cockpit, Webmin)
  • Map Cloudron groups/roles to system access
  • Remove local non-root accounts
  • Validate in sectestbed-* before prod

Context

  • Cloudron does NOT support LDAP for system login (LDAP is app-only).
  • OIDC is the supported path for SSO.
  • Roles executed via tsys-awx (AWX).

Dependencies

Depends on #379 (test lab). Blocks #388 (patch management), #390 (MDM).


Related issues 3 (3 open0 closed)

Blocks Known Element Enterprises - Technology & Facility Services - Support #388: OAM: Patch managementFeedbackCharles N08/06/2026

Actions
Blocks Known Element Enterprises - Technology & Facility Services - Support #390: OAM: MDM solutionFeedbackCharles N08/06/2026

Actions
Blocked by Known Element Enterprises - Technology & Facility Services - Support #379: OAM: Compliance test lab (sectestbed-* vms)FeedbackCharles N08/06/2026

Actions
Actions

Also available in: PDF Atom