GoogleCloudPlatform / GoogleCloudPlatform/pubsec-declarative-toolkit

DI-38: Document AAD specific IdP SSO only federation creation a GCP Identity stub account pair post sync

Open
#182 0 comments 0 reactions 1 assignee Claimed by @fmichaelobrien View on GitHub
automation azure validate_with_v2
Dominant language
Shell
Stars
36
Forks
26
PR merge metrics
No merged PRs in 30d

Description

see design issue 38 https://github.com/GoogleCloudPlatform/pubsec-declarative-toolkit/blob/dev/solutions/landing-zone/architecture.md#di-38-identity-federation

see https://github.com/GoogleCloudPlatform/pbmm-on-gcp-onboarding/blob/main/docs/architecture.md#di-4-cloud-identity-federation

See Identity Onboarding and Federation options at https://cloud.google.com/architecture/landing-zones/decide-how-to-onboard-identities
- using Option 2
- using https://cloud.google.com/architecture/identity/federating-gcp-with-azure-active-directory
- https://cloud.google.com/architecture/identity/reference-architectures#using_an_external_idp

#### SSO only
- Verify details of backing IAM Identity user/role as part SSO federated IdP user auth during IAP session https://cloud.google.com/iap/docs/concepts-overview
- Verify GCP Identity role for application use is available via the IAP session token - thinking https://cloud.google.com/iap/docs/signed-headers-howto#controlling_access_with_sign_in_attributes
- see https://cloud.google.com/architecture/identity/single-sign-on
"To use SSO, a user must have a user account in Cloud Identity or Google Workspace and a corresponding identity in the external IdP"

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.