mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: adopt markdownlint and markdown-table-formatter for *.md (#15831)
Co-authored-by: Edward Angert <EdwardAngert@users.noreply.github.com>
This commit is contained in:
co-authored by
Edward Angert
parent
08463c27d8
commit
94f5d52fdc
@@ -1,6 +1,6 @@
|
||||
## GitHub
|
||||
# GitHub
|
||||
|
||||
### Step 1: Configure the OAuth application in GitHub
|
||||
## Step 1: Configure the OAuth application in GitHub
|
||||
|
||||
First,
|
||||
[register a GitHub OAuth app](https://developer.github.com/apps/building-oauth-apps/creating-an-oauth-app/).
|
||||
@@ -22,7 +22,7 @@ values in the next step.
|
||||
Coder will need permission to access user email addresses. Find the "Account
|
||||
Permissions" settings for your app and select "read-only" for "Email addresses".
|
||||
|
||||
### Step 2: Configure Coder with the OAuth credentials
|
||||
## Step 2: Configure Coder with the OAuth credentials
|
||||
|
||||
Navigate to your Coder host and run the following command to start up the Coder
|
||||
server:
|
||||
|
||||
@@ -17,16 +17,16 @@ which templates developers can use. For example:
|
||||
Roles determine which actions users can take within the platform.
|
||||
|
||||
| | Auditor | User Admin | Template Admin | Owner |
|
||||
| --------------------------------------------------------------- | ------- | ---------- | -------------- | ----- |
|
||||
| Add and remove Users | | ✅ | | ✅ |
|
||||
| Manage groups (enterprise) (premium) | | ✅ | | ✅ |
|
||||
| Change User roles | | | | ✅ |
|
||||
| Manage **ALL** Templates | | | ✅ | ✅ |
|
||||
| View **ALL** Workspaces | | | ✅ | ✅ |
|
||||
| Update and delete **ALL** Workspaces | | | | ✅ |
|
||||
| Run [external provisioners](../provisioners.md) | | | ✅ | ✅ |
|
||||
| Execute and use **ALL** Workspaces | | | | ✅ |
|
||||
| View all user operation [Audit Logs](../security/audit-logs.md) | ✅ | | | ✅ |
|
||||
|-----------------------------------------------------------------|---------|------------|----------------|-------|
|
||||
| Add and remove Users | | ✅ | | ✅ |
|
||||
| Manage groups (enterprise) (premium) | | ✅ | | ✅ |
|
||||
| Change User roles | | | | ✅ |
|
||||
| Manage **ALL** Templates | | | ✅ | ✅ |
|
||||
| View **ALL** Workspaces | | | ✅ | ✅ |
|
||||
| Update and delete **ALL** Workspaces | | | | ✅ |
|
||||
| Run [external provisioners](../provisioners.md) | | | ✅ | ✅ |
|
||||
| Execute and use **ALL** Workspaces | | | | ✅ |
|
||||
| View all user operation [Audit Logs](../security/audit-logs.md) | ✅ | | | ✅ |
|
||||
|
||||
A user may have one or more roles. All users have an implicit Member role that
|
||||
may use personal workspaces.
|
||||
|
||||
@@ -1,3 +1,4 @@
|
||||
<!-- markdownlint-disable MD024 -->
|
||||
# IDP Sync
|
||||
|
||||
<blockquote class="info">
|
||||
@@ -7,6 +8,8 @@ IDP sync is an Enterprise and Premium feature.
|
||||
|
||||
</blockquote>
|
||||
|
||||
## Group Sync
|
||||
|
||||
If your OpenID Connect provider supports group claims, you can configure Coder
|
||||
to synchronize groups in your auth provider to groups within Coder. To enable
|
||||
group sync, ensure that the `groups` claim is being sent by your OpenID
|
||||
@@ -141,10 +144,10 @@ will be able to configure this in the UI. For now, you must use CLI commands.
|
||||
|
||||
```json
|
||||
{
|
||||
"field": "",
|
||||
"mapping": null,
|
||||
"regex_filter": null,
|
||||
"auto_create_missing_groups": false
|
||||
"field": "",
|
||||
"mapping": null,
|
||||
"regex_filter": null,
|
||||
"auto_create_missing_groups": false
|
||||
}
|
||||
```
|
||||
|
||||
@@ -153,10 +156,10 @@ Below is an example that uses the `groups` claim and maps all groups prefixed by
|
||||
|
||||
```json
|
||||
{
|
||||
"field": "groups",
|
||||
"mapping": null,
|
||||
"regex_filter": "^coder-.*$",
|
||||
"auto_create_missing_groups": true
|
||||
"field": "groups",
|
||||
"mapping": null,
|
||||
"regex_filter": "^coder-.*$",
|
||||
"auto_create_missing_groups": true
|
||||
}
|
||||
```
|
||||
|
||||
@@ -174,16 +177,16 @@ group:
|
||||
|
||||
```json
|
||||
{
|
||||
"field": "groups",
|
||||
"mapping": {
|
||||
"coder-admins": [
|
||||
"2ba2a4ff-ddfb-4493-b7cd-1aec2fa4c830",
|
||||
"93371154-150f-4b12-b5f0-261bb1326bb4"
|
||||
],
|
||||
"coder-users": ["2f4bde93-0179-4815-ba50-b757fb3d43dd"]
|
||||
},
|
||||
"regex_filter": null,
|
||||
"auto_create_missing_groups": false
|
||||
"field": "groups",
|
||||
"mapping": {
|
||||
"coder-admins": [
|
||||
"2ba2a4ff-ddfb-4493-b7cd-1aec2fa4c830",
|
||||
"93371154-150f-4b12-b5f0-261bb1326bb4"
|
||||
],
|
||||
"coder-users": ["2f4bde93-0179-4815-ba50-b757fb3d43dd"]
|
||||
},
|
||||
"regex_filter": null,
|
||||
"auto_create_missing_groups": false
|
||||
}
|
||||
```
|
||||
|
||||
@@ -209,7 +212,7 @@ Users who are not in a matching group will see the following error:
|
||||
|
||||
<Image height="412px" src="../../images/admin/group-allowlist.png" alt="Unauthorized group error" align="center" />
|
||||
|
||||
## Role sync
|
||||
## Role Sync
|
||||
|
||||
<blockquote class="info">
|
||||
|
||||
@@ -307,8 +310,8 @@ will be able to configure this in the UI. For now, you must use CLI commands.
|
||||
|
||||
```json
|
||||
{
|
||||
"field": "",
|
||||
"mapping": null
|
||||
"field": "",
|
||||
"mapping": null
|
||||
}
|
||||
```
|
||||
|
||||
@@ -318,11 +321,11 @@ role:
|
||||
|
||||
```json
|
||||
{
|
||||
"field": "roles",
|
||||
"mapping": {
|
||||
"coder-admins": ["organization-admin"],
|
||||
"infra-admins": ["provisioner-admin"]
|
||||
}
|
||||
"field": "roles",
|
||||
"mapping": {
|
||||
"coder-admins": ["organization-admin"],
|
||||
"infra-admins": ["provisioner-admin"]
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
@@ -372,7 +375,7 @@ dashboard:
|
||||
|
||||
<div class="tabs">
|
||||
|
||||
### Dashboard
|
||||
## Dashboard
|
||||
|
||||
1. Confirm that your OIDC provider is sending claims. Log in with OIDC and visit
|
||||
the following URL with an `Owner` account:
|
||||
@@ -412,7 +415,7 @@ dashboard:
|
||||
|
||||

|
||||
|
||||
### CLI
|
||||
## CLI
|
||||
|
||||
Use the Coder CLI to show and adjust the settings.
|
||||
|
||||
@@ -455,7 +458,7 @@ settings, a user's memberships will update when they log out and log back in.
|
||||
Analyzing the JSON payload:
|
||||
|
||||
| Field | Explanation |
|
||||
| :-------------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
|:----------------------------|:----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| field | If this field is the empty string `""`, then org-sync is disabled. </br> Org memberships must be manually configured through the UI or API. |
|
||||
| mapping | Mapping takes a claim from the IdP, and associates it with 1 or more organizations by UUID. </br> No validation is done, so you can put UUID's of orgs that do not exist (a noop). The UI picker will allow selecting orgs from a drop down, and convert it to a UUID for you. |
|
||||
| organization_assign_default | This setting exists for maintaining backwards compatibility with single org deployments, either through their upgrade, or in perpetuity. </br> If this is set to 'true', all users will always be assigned to the default organization regardless of the mappings and their IdP claims. |
|
||||
|
||||
@@ -76,7 +76,7 @@ the sum of their allowances.
|
||||
For example:
|
||||
|
||||
| Group Name | Quota Allowance |
|
||||
| ---------- | --------------- |
|
||||
|------------|-----------------|
|
||||
| Frontend | 10 |
|
||||
| Backend | 20 |
|
||||
| Data | 30 |
|
||||
@@ -84,7 +84,7 @@ For example:
|
||||
<br/>
|
||||
|
||||
| Username | Groups | Effective Budget |
|
||||
| -------- | ----------------- | ---------------- |
|
||||
|----------|-------------------|------------------|
|
||||
| jill | Frontend, Backend | 30 |
|
||||
| jack | Backend, Data | 50 |
|
||||
| sam | Data | 30 |
|
||||
|
||||
Reference in New Issue
Block a user