mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-07-28 12:49:03 +00:00
bd4008f509
* feat: SSO & LDAP authentication for Team Pro Add SSO integration allowing Team Pro users to authenticate via LDAP/Active Directory, Google, GitHub, and Okta identity providers. SSO works alongside password authentication with auto-provisioning and role mapping. - LDAP bind+search authentication with group-based role mapping - OIDC/OAuth2 flows with PKCE and CSRF protection for Google, GitHub, Okta - Auto-provisioning: first SSO login creates a Sencho account automatically - Role mapping via LDAP group membership or OIDC JWT claims - SSO settings UI in Settings → SSO with per-provider config and test connection - SSO login buttons on login page with LDAP toggle - Environment variable seeding for infrastructure-as-code workflows - Secrets encrypted at rest via CryptoService (AES-256-GCM) - Seat limit enforcement during auto-provisioning - Full documentation: feature docs, quickstart guides, env var reference * fix: resolve ESLint errors in SSO feature - Remove unnecessary escape characters in regex character classes - Remove unused `issuer` variable from OIDC callback handler - Fix setState-in-effect lint error in Login.tsx by using useState initializer - Suppress set-state-in-effect for SSOSection fetch pattern (matches existing codebase convention)
71 lines
2.5 KiB
Plaintext
71 lines
2.5 KiB
Plaintext
---
|
|
title: RBAC & User Management
|
|
description: Role-based access control for Sencho Pro - create admin and viewer accounts to control who can modify your stacks.
|
|
---
|
|
|
|
<Note>
|
|
RBAC requires a Sencho Pro license. Community Edition supports a single admin account only.
|
|
</Note>
|
|
|
|
Sencho Pro introduces role-based access control with two distinct roles: **Admin** and **Viewer**. This lets you give team members read-only access to your infrastructure without risking accidental changes.
|
|
|
|
## Roles
|
|
|
|
| Role | Description |
|
|
|------|-------------|
|
|
| **Admin** | Full access to all features - deploy, edit, manage users, configure nodes, and more |
|
|
| **Viewer** | Read-only access to dashboards, logs, stats, and file contents |
|
|
|
|
### What viewers can see
|
|
|
|
- Dashboard and home metrics
|
|
- Stacks list and stack detail view
|
|
- Compose and `.env` file contents (read-only)
|
|
- Per-container stats and logs
|
|
- Fleet view
|
|
- Resources hub (images, volumes, networks - read-only)
|
|
- Global logs
|
|
- Notifications
|
|
|
|
### What viewers cannot do
|
|
|
|
- Edit compose or environment files
|
|
- Deploy, restart, stop, or start stacks
|
|
- Create or delete stacks
|
|
- Manage users, nodes, webhooks, or alerts
|
|
- Access the host console
|
|
- Prune resources
|
|
- Change settings
|
|
|
|
## Managing users
|
|
|
|
<Frame>
|
|
<img src="/images/rbac/users-settings.png" alt="Users management panel showing user list with roles" />
|
|
</Frame>
|
|
|
|
Admins can manage accounts in **Settings → Users**. From there you can:
|
|
|
|
- **Create** a new user with a username, password, and role (Admin or Viewer)
|
|
- **Edit** an existing user's password or role
|
|
- **Delete** a user account
|
|
|
|
## SSO auto-provisioning
|
|
|
|
With a Team Pro license, users can also be created automatically when they log in via SSO (LDAP, Google, GitHub, or Okta). SSO users appear in the Users list alongside local accounts. They are assigned a role based on identity provider group membership or claim mapping.
|
|
|
|
SSO users cannot log in with a password — they must always authenticate through their identity provider.
|
|
|
|
To set up identity provider authentication, see [SSO Authentication →](/features/sso).
|
|
|
|
## Migration from single-admin setup
|
|
|
|
When you upgrade to Sencho Pro, your existing single-admin credentials are automatically migrated to the new users table. No manual action is required - your login continues to work as before, and your account is assigned the Admin role.
|
|
|
|
## License tiers
|
|
|
|
| Tier | Admin accounts | Viewer accounts |
|
|
|------|---------------|-----------------|
|
|
| **Community** | 1 | 0 |
|
|
| **Personal Pro** | 1 | 3 |
|
|
| **Team Pro** | Unlimited | Unlimited |
|