Repository navigation
Expand file tree
/
Copy pathsso.yml.example
More file actions
77 lines (71 loc) · 2.45 KB
/
Copy pathsso.yml.example
File metadata and controls
77 lines (71 loc) · 2.45 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
# This config file lets you configure Single Sign-On (SSO) for logging into
# Mathesar with your preferred Identity Provider (IdP).
#
# Two schema versions are supported:
#
# - version: 1 - OIDC providers only (the original schema). Still fully
# supported; existing installations continue to work.
#
# - version: 2 - Adds support for GitHub Oauth2 alongside OIDC. Uses an
# explicit `type:` field per provider.
#
# If `version:` is omitted, the schema defaults to version 1.
#
# Pick one of the examples below.
# -----------------------------------------------------------------------------
# version: 2 example (recommended for new setups)
# -----------------------------------------------------------------------------
version: 2
providers:
provider1:
# (REQUIRED) For OIDC providers (Okta, Google, Microsoft, etc.).
type: oidc
provider_name: google
client_id: # your_client_id
secret: # your_secret_key
server_url: https://accounts.google.com
# (OPTIONAL)
# Restrict logins to the specified email domains.
# Default (allow all domains): []
# Example: ['xyz.org', 'example.com']
allowed_email_domains: []
# (OPTIONAL)
# Default postgres roles provisioned to users on their first login.
default_pg_role:
db1:
name: # your_db_name
host: # your_db_host
port: # your_db_port
role: # your_db_role
db2:
# Use the same config as db1 to provision default roles to users on additional databases.
provider2:
# (REQUIRED) For github.com
type: github
client_id: # your_github_client_id
secret: # your_github_client_secret
# (OPTIONAL) Same semantics as the OIDC provider above.
allowed_email_domains: []
default_pg_role:
db1:
name: # your_db_name
host: # your_db_host
port: # your_db_port
role: # your_db_role
# -----------------------------------------------------------------------------
# version: 1 example (legacy, OIDC only)
# -----------------------------------------------------------------------------
# version: 1
# oidc_providers:
# provider1:
# provider_name: google
# client_id: # your_client_id
# secret: # your_secret_key
# server_url: https://accounts.google.com
# allowed_email_domains: []
# default_pg_role:
# db1:
# name: # your_db_name
# host: # your_db_host
# port: # your_db_port
# role: # your_db_role