Add SAML SSO configuration for Twistlock
Package Merge Request
Package Changes
Update the Twistlock init script to configure SAML SSO. Adding the twistlock-sso.sh
script after twistlock-license.sh
, so that we can automate the creation of additionalUsers
using the SAML
role. Focused on SAML rather than the other protocols since this is the one we got working with P1 Keycloak as compared to OIDC.
Package MR
https://repo1.dso.mil/platform-one/big-bang/apps/security-tools/twistlock/-/merge_requests/70
For Issue
Closes https://repo1.dso.mil/platform-one/big-bang/apps/security-tools/twistlock/-/issues/46
BB Processes
Add labels for affected packages so that they are deployed in CI as well as a status label:
Be sure to assign to yourself:
Once it is ready for review switch the status and assign reviewers:
Merge request reports
Activity
added statusdoing twistlock labels
assigned to @rsalcido
added community-contribution label
requested review from @micah.nagel
removed statusdoing label
added statusreview label
- Automatically resolved by Ryan Salcido
- Automatically resolved by Ryan Salcido
I'm going to take this out of review for now, would prefer to include the updated Twistlock tag in with these changes - https://repo1.dso.mil/platform-one/big-bang/apps/security-tools/twistlock/-/merge_requests/70
added statusdoing label and removed statusreview label
added 1 commit
- 3976e911 - Set default value for twistlock.sso.console_url
added 1 commit
- d4cbeb95 - Update Twistlock chart version to 0.10.0-bb.1
added 31 commits
-
d4cbeb95...e0e17e14 - 30 commits from branch
master
- 00133f11 - Merge branch 'master' into twistlock-sso
-
d4cbeb95...e0e17e14 - 30 commits from branch
removed statusdoing label
added statusreview label
- Resolved by Ryan Salcido
- Resolved by Micah Nagel
One other comment, would be nice to have the dev sso values documented for our BB devs. I'll add those to this thread once I deploy and validate they work.
changed milestone to %1.43.0
enabled an automatic merge when the pipeline for f1ec5dd5 succeeds
mentioned in commit e63ecff6