mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
docs: convert alerts to use GitHub Flavored Markdown (GFM) (#16850)
followup to #16761 thanks @lucasmelin ! + thanks: @ethanndickson @Parkreiner @matifali @aqandrew - [x] update snippet - [x] find/replace - [x] spot-check [preview](https://coder.com/docs/@16761-gfm-callouts/admin/templates/managing-templates/schedule) (and others) --------- Co-authored-by: EdwardAngert <17991901+EdwardAngert@users.noreply.github.com> Co-authored-by: M Atif Ali <atif@coder.com>
This commit is contained in:
co-authored by
EdwardAngert
M Atif Ali
parent
e817713dc0
commit
101b62dc3e
@@ -47,12 +47,12 @@ GitHub will ask you for the following Coder parameters:
|
||||
`https://coder.domain.com`)
|
||||
- **User Authorization Callback URL**: Set to `https://coder.domain.com`
|
||||
|
||||
> Note: If you want to allow multiple coder deployments hosted on subdomains
|
||||
> e.g. coder1.domain.com, coder2.domain.com, to be able to authenticate with the
|
||||
> same GitHub OAuth app, then you can set **User Authorization Callback URL** to
|
||||
> the `https://domain.com`
|
||||
If you want to allow multiple Coder deployments hosted on subdomains, such as
|
||||
`coder1.domain.com`, `coder2.domain.com`, to authenticate with the
|
||||
same GitHub OAuth app, then you can set **User Authorization Callback URL** to
|
||||
the `https://domain.com`
|
||||
|
||||
Note the Client ID and Client Secret generated by GitHub. You will use these
|
||||
Take note of the Client ID and Client Secret generated by GitHub. You will use these
|
||||
values in the next step.
|
||||
|
||||
Coder will need permission to access user email addresses. Find the "Account
|
||||
@@ -67,8 +67,8 @@ server:
|
||||
coder server --oauth2-github-allow-signups=true --oauth2-github-allowed-orgs="your-org" --oauth2-github-client-id="8d1...e05" --oauth2-github-client-secret="57ebc9...02c24c"
|
||||
```
|
||||
|
||||
> For GitHub Enterprise support, specify the
|
||||
> `--oauth2-github-enterprise-base-url` flag.
|
||||
> [!NOTE]
|
||||
> For GitHub Enterprise support, specify the `--oauth2-github-enterprise-base-url` flag.
|
||||
|
||||
Alternatively, if you are running Coder as a system service, you can achieve the
|
||||
same result as the command above by adding the following environment variables
|
||||
@@ -81,11 +81,12 @@ CODER_OAUTH2_GITHUB_CLIENT_ID="8d1...e05"
|
||||
CODER_OAUTH2_GITHUB_CLIENT_SECRET="57ebc9...02c24c"
|
||||
```
|
||||
|
||||
**Note:** To allow everyone to signup using GitHub, set:
|
||||
|
||||
```env
|
||||
CODER_OAUTH2_GITHUB_ALLOW_EVERYONE=true
|
||||
```
|
||||
> [!TIP]
|
||||
> To allow everyone to sign up using GitHub, set:
|
||||
>
|
||||
> ```env
|
||||
> CODER_OAUTH2_GITHUB_ALLOW_EVERYONE=true
|
||||
> ```
|
||||
|
||||
Once complete, run `sudo service coder restart` to reboot Coder.
|
||||
|
||||
@@ -115,9 +116,9 @@ To upgrade Coder, run:
|
||||
helm upgrade <release-name> coder-v2/coder -n <namespace> -f values.yaml
|
||||
```
|
||||
|
||||
> We recommend requiring and auditing MFA usage for all users in your GitHub
|
||||
> organizations. This can be enforced from the organization settings page in the
|
||||
> "Authentication security" sidebar tab.
|
||||
We recommend requiring and auditing MFA usage for all users in your GitHub
|
||||
organizations. This can be enforced from the organization settings page in the
|
||||
"Authentication security" sidebar tab.
|
||||
|
||||
## Device Flow
|
||||
|
||||
|
||||
@@ -33,12 +33,9 @@ may use personal workspaces.
|
||||
|
||||
## Custom Roles
|
||||
|
||||
<blockquote class="info">
|
||||
|
||||
Custom roles are a Premium feature.
|
||||
[Learn more](https://coder.com/pricing#compare-plans).
|
||||
|
||||
</blockquote>
|
||||
> [!NOTE]
|
||||
> Custom roles are a Premium feature.
|
||||
> [Learn more](https://coder.com/pricing#compare-plans).
|
||||
|
||||
Starting in v2.16.0, Premium Coder deployments can configure custom roles on the
|
||||
[Organization](./organizations.md) level. You can create and assign custom roles
|
||||
|
||||
@@ -4,7 +4,7 @@ Headless user accounts that cannot use the web UI to log in to Coder. This is
|
||||
useful for creating accounts for automated systems, such as CI/CD pipelines or
|
||||
for users who only consume Coder via another client/API.
|
||||
|
||||
> You must have the User Admin role or above to create headless users.
|
||||
You must have the User Admin role or above to create headless users.
|
||||
|
||||
## Create a headless user
|
||||
|
||||
|
||||
@@ -1,12 +1,9 @@
|
||||
<!-- markdownlint-disable MD024 -->
|
||||
# IdP Sync
|
||||
|
||||
<blockquote class="info">
|
||||
|
||||
IdP sync is an Enterprise and Premium feature.
|
||||
[Learn more](https://coder.com/pricing#compare-plans).
|
||||
|
||||
</blockquote>
|
||||
> [!NOTE]
|
||||
> IdP sync is an Enterprise and Premium feature.
|
||||
> [Learn more](https://coder.com/pricing#compare-plans).
|
||||
|
||||
IdP (Identity provider) sync allows you to use OpenID Connect (OIDC) to
|
||||
synchronize Coder groups, roles, and organizations based on claims from your IdP.
|
||||
@@ -110,13 +107,10 @@ Below is an example that uses the `groups` claim and maps all groups prefixed by
|
||||
}
|
||||
```
|
||||
|
||||
<blockquote class="admonition note">
|
||||
|
||||
You must specify Coder group IDs instead of group names. The fastest way to find
|
||||
the ID for a corresponding group is by visiting
|
||||
`https://coder.example.com/api/v2/groups`.
|
||||
|
||||
</blockquote>
|
||||
> [!IMPORTANT]
|
||||
> You must specify Coder group IDs instead of group names. The fastest way to find
|
||||
> the ID for a corresponding group is by visiting
|
||||
> `https://coder.example.com/api/v2/groups`.
|
||||
|
||||
Here is another example which maps `coder-admins` from the identity provider to
|
||||
two groups in Coder and `coder-users` from the identity provider to another
|
||||
@@ -151,13 +145,9 @@ Visit the Coder UI to confirm these changes:
|
||||
|
||||
### Server Flags
|
||||
|
||||
<blockquote class="admonition note">
|
||||
|
||||
Use server flags only with Coder deployments with a single organization.
|
||||
|
||||
You can use the dashboard to configure group sync instead.
|
||||
|
||||
</blockquote>
|
||||
> [!NOTE]
|
||||
> Use server flags only with Coder deployments with a single organization.
|
||||
> You can use the dashboard to configure group sync instead.
|
||||
|
||||
1. Configure the Coder server to read groups from the claim name with the
|
||||
[OIDC group field](../../reference/cli/server.md#--oidc-group-field) server
|
||||
@@ -284,13 +274,9 @@ role:
|
||||
}
|
||||
```
|
||||
|
||||
<blockquote class="admonition note">
|
||||
|
||||
Be sure to use the `name` field for each role, not the display name. Use
|
||||
`coder organization roles show --org=<your-org>` to see roles for your
|
||||
organization.
|
||||
|
||||
</blockquote>
|
||||
> [!NOTE]
|
||||
> Be sure to use the `name` field for each role, not the display name.
|
||||
> Use `coder organization roles show --org=<your-org>` to see roles for your organization.
|
||||
|
||||
To set these role sync settings, use the following command:
|
||||
|
||||
@@ -306,13 +292,9 @@ Visit the Coder UI to confirm these changes:
|
||||
|
||||
### Server Flags
|
||||
|
||||
<blockquote class="admonition note">
|
||||
|
||||
Use server flags only with Coder deployments with a single organization.
|
||||
|
||||
You can use the dashboard to configure role sync instead.
|
||||
|
||||
</blockquote>
|
||||
> [!NOTE]
|
||||
> Use server flags only with Coder deployments with a single organization.
|
||||
> You can use the dashboard to configure role sync instead.
|
||||
|
||||
1. Configure the Coder server to read groups from the claim name with the
|
||||
[OIDC role field](../../reference/cli/server.md#--oidc-user-role-field)
|
||||
@@ -539,7 +521,8 @@ Below are some details specific to individual OIDC providers.
|
||||
|
||||
### Active Directory Federation Services (ADFS)
|
||||
|
||||
> **Note:** Tested on ADFS 4.0, Windows Server 2019
|
||||
> [!NOTE]
|
||||
> Tested on ADFS 4.0, Windows Server 2019
|
||||
|
||||
1. In your Federation Server, create a new application group for Coder.
|
||||
Follow the steps as described in the [Windows Server documentation]
|
||||
|
||||
@@ -166,6 +166,7 @@ You can also reset a password via the CLI:
|
||||
coder reset-password <username>
|
||||
```
|
||||
|
||||
> [!NOTE]
|
||||
> Resetting a user's password, e.g., the initial `owner` role-based user, only
|
||||
> works when run on the host running the Coder control plane.
|
||||
|
||||
|
||||
@@ -32,7 +32,8 @@ signing in via OIDC as a new user. Coder will log the claim fields returned by
|
||||
the upstream identity provider in a message containing the string
|
||||
`got oidc claims`, as well as the user info returned.
|
||||
|
||||
> **Note:** If you need to ensure that Coder only uses information from the ID
|
||||
> [!NOTE]
|
||||
> If you need to ensure that Coder only uses information from the ID
|
||||
> token and does not hit the UserInfo endpoint, you can set the configuration
|
||||
> option `CODER_OIDC_IGNORE_USERINFO=true`.
|
||||
|
||||
@@ -44,7 +45,8 @@ for the newly created user's email address.
|
||||
If your upstream identity provider users a different claim, you can set
|
||||
`CODER_OIDC_EMAIL_FIELD` to the desired claim.
|
||||
|
||||
> **Note** If this field is not present, Coder will attempt to use the claim
|
||||
> [!NOTE]
|
||||
> If this field is not present, Coder will attempt to use the claim
|
||||
> field configured for `username` as an email address. If this field is not a
|
||||
> valid email address, OIDC logins will fail.
|
||||
|
||||
@@ -59,7 +61,8 @@ disable this behavior with the following setting:
|
||||
CODER_OIDC_IGNORE_EMAIL_VERIFIED=true
|
||||
```
|
||||
|
||||
> **Note:** This will cause Coder to implicitly treat all OIDC emails as
|
||||
> [!NOTE]
|
||||
> This will cause Coder to implicitly treat all OIDC emails as
|
||||
> "verified", regardless of what the upstream identity provider says.
|
||||
|
||||
### Usernames
|
||||
@@ -70,7 +73,8 @@ claim field named `preferred_username` as the the username.
|
||||
If your upstream identity provider uses a different claim, you can set
|
||||
`CODER_OIDC_USERNAME_FIELD` to the desired claim.
|
||||
|
||||
> **Note:** If this claim is empty, the email address will be stripped of the
|
||||
> [!NOTE]
|
||||
> If this claim is empty, the email address will be stripped of the
|
||||
> domain, and become the username (e.g. `example@coder.com` becomes `example`).
|
||||
> To avoid conflicts, Coder may also append a random word to the resulting
|
||||
> username.
|
||||
@@ -99,12 +103,9 @@ CODER_DISABLE_PASSWORD_AUTH=true
|
||||
|
||||
## SCIM
|
||||
|
||||
<blockquote class="info">
|
||||
|
||||
SCIM is an Enterprise and Premium feature.
|
||||
[Learn more](https://coder.com/pricing#compare-plans).
|
||||
|
||||
</blockquote>
|
||||
> [!NOTE]
|
||||
> SCIM is an Enterprise and Premium feature.
|
||||
> [Learn more](https://coder.com/pricing#compare-plans).
|
||||
|
||||
Coder supports user provisioning and deprovisioning via SCIM 2.0 with header
|
||||
authentication. Upon deactivation, users are
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
# Organizations (Premium)
|
||||
|
||||
> Note: Organizations requires a
|
||||
> [!NOTE]
|
||||
> Organizations requires a
|
||||
> [Premium license](https://coder.com/pricing#compare-plans). For more details,
|
||||
> [contact your account team](https://coder.com/contact).
|
||||
|
||||
|
||||
@@ -15,7 +15,8 @@ If you remove the admin user account (or forget the password), you can run the
|
||||
[`coder server create-admin-user`](../../reference/cli/server_create-admin-user.md)command
|
||||
on your server.
|
||||
|
||||
> Note: You must run this command on the same machine running the Coder server.
|
||||
> [!IMPORTANT]
|
||||
> You must run this command on the same machine running the Coder server.
|
||||
> If you are running Coder on Kubernetes, this means using
|
||||
> [kubectl exec](https://kubernetes.io/docs/reference/kubectl/generated/kubectl_exec/)
|
||||
> to exec into the pod.
|
||||
|
||||
Reference in New Issue
Block a user