Configuring group authorization in Jenkins using SAML

Viewed 2773

I am trying to setup group authorizations using my IDP (Identity Provider) with the Jenkins instance I have.

For individual users, I have been able to setup this up successfully by installing the SAML 2.0 plugin , sending up the Service Provider Metadata to my IDP and completing a successful registration.

I am able to login to my Jenkins successfully using my SAML credentials.

Further more I am able to give users certain roles using the Role Strategy Plugin. I have defined roles like "Job Reader" , "Job Admin" etc etc and assigned those roles to individual users.

All until here is done.

But what Im looking for is rather than having to assign roles to users on the Jenkins layer, I want Jenkins to pull groups defined in my IDP and assign those groups to roles that Ive defined rather than me having to assign roles to individual users.

On my IDP side, I have created groups (I have a group ID) and assigned users to those groups. All I want to do is to have my Jenkins reads those group IDs. Is there some documentation I can follow ?

Below are the steps Ive done so far with unsuccessful results.

In my IDP, Ive created a group jenkins-reader and assigned a user to the group.

enter image description here

When I curl on the data of the user, I can clearly see that my user P000002 is part of a particular group.

{
    "uid": "P000002",
.
.

    "companyGroups": [
        "jenkins-reader"
    ],
.
.
. }

Now switching to Jenkins, I have the following config.

Under Manage Roles , ive configured Project Roles. Creating a jenkins-reader roles and assigning in Job Read permissions.

enter image description here

Under Assign Roles , I added the group jenkins-reader (same name as defined in IDP) and assigned it the jenkins-reader role configured in the last step.

enter image description here

When I hit Apply and Save, I try to login again and I get the ERROR

Access Denied
P000002 is missing the Overall/Read permission

Now Im not sure whether Ive missed something here or am taking a wrong approach to this. Ive been following this doc.

0 Answers
Related