Skip to content

[SSO] Add design doc for group to role mapping for OIDC#35899

Open
mtabebe wants to merge 1 commit intoMaterializeInc:mainfrom
mtabebe:ma/sso/scim-design-doc
Open

[SSO] Add design doc for group to role mapping for OIDC#35899
mtabebe wants to merge 1 commit intoMaterializeInc:mainfrom
mtabebe:ma/sso/scim-design-doc

Conversation

@mtabebe
Copy link
Copy Markdown
Contributor

@mtabebe mtabebe commented Apr 7, 2026

Proposes JWT-based group-to-role sync for self-managed.

On connection, Materialize reads group claims from the JWT and grants/revokes role memberships accordingly. Track these using a dedicated sentinel grantor (MZ_JWT_SYNC_ROLE_ID) to distinguish sync-managed from manually-managed grants.

@mtabebe mtabebe requested a review from SangJunBak April 7, 2026 20:51
@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 7, 2026

Thanks for opening this PR! Here are a few tips to help make the review process smooth for everyone.

PR title guidelines

  • Use imperative mood: "Fix X" not "Fixed X" or "Fixes X"
  • Be specific: "Fix panic in catalog sync when controller restarts" not "Fix bug" or "Update catalog code"
  • Prefix with area if helpful: compute: , storage: , adapter: , sql:

Pre-merge checklist

  • The PR title is descriptive and will make sense in the git log.
  • This PR has adequate test coverage / QA involvement has been duly considered. (trigger-ci for additional test/nightly runs)
  • If this PR includes major user-facing behavior changes, I have pinged the relevant PM to schedule a changelog post.
  • This PR has an associated up-to-date design doc, is a design doc (template), or is sufficiently small to not require a design.
  • If this PR evolves an existing $T ⇔ Proto$T mapping (possibly in a backwards-incompatible way), then it is tagged with a T-proto label.
  • If this PR will require changes to cloud orchestration or tests, there is a companion cloud PR to account for those changes that is tagged with the release-blocker label (example).

Proposes JWT-based group-to-role sync for self-managed.

On connection, Materialize reads group claims from the JWT and
grants/revokes role memberships accordingly. Track these using
a dedicated sentinel grantor (MZ_JWT_SYNC_ROLE_ID)
to distinguish sync-managed from manually-managed grants.
@mtabebe mtabebe force-pushed the ma/sso/scim-design-doc branch from e81c023 to f4c4dd1 Compare April 8, 2026 15:37
@mtabebe mtabebe marked this pull request as ready for review April 8, 2026 15:37
@mtabebe mtabebe requested a review from pH14 April 8, 2026 15:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant