feat: report SCIM configuration on Deployment (#26628)

Adds two nullable booleans to `telemetry.Deployment`:

- `SCIMEnabled`: `true` when `CODER_SCIM_AUTH_HEADER` is set.
- `SCIMUseLegacy`: `true` when `CODER_SCIM_USE_LEGACY` is set.

Both mirror `Deployment.IDPOrgSync`: nullable for backward
compatibility, and report configuration state rather than license
entitlement (#16323).

Lives on `Deployment` rather than `Snapshot` so the existing
`bqDeployment` table on `coder/coder-telemetry-server` gets two columns
instead of a new table.

`SCIMAPIKey` is annotated as a secret and is scrubbed by
`WithoutSecrets` before the config reaches telemetry, so
`DeploymentConfig.SCIMAPIKey` is always empty in production. The
booleans are pre-computed from the pre-scrub `DeploymentValues` in
`cli/server.go` and passed in via `telemetry.Options.SCIMEnabled` /
`SCIMUseLegacy`.

Pairs with
[coder/coder-telemetry-server#43](https://github.com/coder/coder-telemetry-server/pull/43),
which adds the matching `bqDeployment` columns and the manual BigQuery
`ALTER TABLE` step.

---

Generated by Coder Agents on behalf of @Emyrk.
This commit is contained in:
Steven Masley
2026-06-25 08:54:37 -05:00
committed by GitHub
parent 75993c2ea0
commit 84350e4e7c
3 changed files with 68 additions and 0 deletions
+40
View File
@@ -585,6 +585,46 @@ func TestTelemetry(t *testing.T) {
deployment, _ = collectSnapshot(ctx, t, db, nil)
require.True(t, *deployment.IDPOrgSync)
})
t.Run("SCIM", func(t *testing.T) {
t.Parallel()
ctx := testutil.Context(t, testutil.WaitMedium)
db, _ := dbtestutil.NewDB(t)
// 1. Default Options: both flags false (and reported as such).
deployment, _ := collectSnapshot(ctx, t, db, nil)
require.NotNil(t, deployment.SCIMEnabled)
require.False(t, *deployment.SCIMEnabled)
require.NotNil(t, deployment.SCIMUseLegacy)
require.False(t, *deployment.SCIMUseLegacy)
// 2. Both Options flags true: both reported true.
deployment, _ = collectSnapshot(ctx, t, db, func(opts telemetry.Options) telemetry.Options {
opts.SCIMEnabled = true
opts.SCIMUseLegacy = true
return opts
})
require.True(t, *deployment.SCIMEnabled)
require.True(t, *deployment.SCIMUseLegacy)
// 3. Enabled only: enabled true, legacy false.
deployment, _ = collectSnapshot(ctx, t, db, func(opts telemetry.Options) telemetry.Options {
opts.SCIMEnabled = true
return opts
})
require.True(t, *deployment.SCIMEnabled)
require.False(t, *deployment.SCIMUseLegacy)
// 4. The reporter never reads DeploymentConfig.SCIMAPIKey directly:
// even if a non-empty key sneaks through (it would not in production
// because of WithoutSecrets), SCIMEnabled reflects only Options.
deployment, _ = collectSnapshot(ctx, t, db, func(opts telemetry.Options) telemetry.Options {
opts.DeploymentConfig = &codersdk.DeploymentValues{
SCIMAPIKey: "a-secret-bearer-token",
}
return opts
})
require.False(t, *deployment.SCIMEnabled)
})
}
// nolint:paralleltest