Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. The moment you have more than one Cloudron instance and use one as the central IAM. What is your concept for a namespace?

The moment you have more than one Cloudron instance and use one as the central IAM. What is your concept for a namespace?

Scheduled Pinned Locked Moved Solved Discuss
4 Posts 3 Posters 244 Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • luckowL Offline
    luckowL Offline
    luckow
    translator
    wrote on last edited by luckow
    #1

    Cloudron branding is nice. But what is the ideal namespace for your instance, the moment you connect all your instance to one IAM (Identity and access management).

    my.example.org makes maybe sense. But the webserver instance which is named like my.web.example.org causes problems in the OIDC workflow. Login with "my.web" makes no sense. Should we rename every other instance to OIDC?

    This is what it looks like:
    ae33b5ee-114b-419e-9126-76ee7f5da305-image.png

    "Login in with" makes more sense. But it is not configurable.
    What are your concepts for normal users?

    Pronouns: he/him | Primary language: German

    1 Reply Last reply
    0
    • nebulonN Away
      nebulonN Away
      nebulon
      Staff
      wrote on last edited by
      #2

      If you have one organization using many Cloudrons, you could name all Cloudrons like the organization. This is not ideal, but for a proper fix in the future, we have to rework the auth between Cloudrons itself. Currently each Cloudron is still acting as the OIDC provider while the actual auth in the backend is done via LDAP. Ideally with OpenID we could designate one Coudron to be the auth provider of other Cloudrons. But that is not implemented yet.

      1 Reply Last reply
      2
      • luckowL luckow has marked this topic as solved on
      • N Offline
        N Offline
        Neiluj
        wrote on last edited by
        #3

        I think that this might relate to what I mentioned here:
        https://forum.cloudron.io/topic/13318/confusing-scenario-with-oidc-button/5

        If so, then this is something that I have definitely ran into and I find some solace in @nebulon's answer, even if this is not immediately available.

        The way I currently go around this is to "brand" all "child" servers with the same identity as the IAM "parent" and then:

        • amend the footer of each child server with the name of the local instance to mark the differentiation
        • eventually set a specific login background and/or a different user profile background (but this is per user and cannot be set for the whole server (as far as I am aware).

        Hopefully this makes sense and relates to the topic?

        luckowL 1 Reply Last reply
        1
        • N Neiluj

          I think that this might relate to what I mentioned here:
          https://forum.cloudron.io/topic/13318/confusing-scenario-with-oidc-button/5

          If so, then this is something that I have definitely ran into and I find some solace in @nebulon's answer, even if this is not immediately available.

          The way I currently go around this is to "brand" all "child" servers with the same identity as the IAM "parent" and then:

          • amend the footer of each child server with the name of the local instance to mark the differentiation
          • eventually set a specific login background and/or a different user profile background (but this is per user and cannot be set for the whole server (as far as I am aware).

          Hopefully this makes sense and relates to the topic?

          luckowL Offline
          luckowL Offline
          luckow
          translator
          wrote on last edited by
          #4

          @Neiluj I like the idea of the footer. In the past, we have always used different logos for different instances.

          Pronouns: he/him | Primary language: German

          1 Reply Last reply
          0
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Don't have an account? Register

          • Login or register to search.
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • Bookmarks
          • Search