-
Type: Investigation
-
Resolution: Unresolved
-
Priority: Major - P3
-
None
-
Affects Version/s: None
-
Component/s: OIDC DB Auth
-
None
This project will backport support for internal authorization with OIDC authentication to v7.0. This would allow clients which possess access tokens without roles to authenticate to the server. Access rights are stored in user documents persisted in the server.
Description of Linked Ticket
Summary
This project will backport the feature implemented in PM-3385 to the v7.0 LTS branch.
Motivation
PM-3385 introduced support for internal authorization for OIDC authenticated clients. This feature simplified administration of clusters using OIDC for workload federation. Atlas configures this feature on Federations, and not necessarily at the level of individual clusters. If some clusters support internal authorization and some do not, Atlas administrators will have an inconsistent experience.
Documentation
Product Description
Scope
Technical Design
Docs Update