Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -43,3 +43,4 @@ yarn.lock

# Do not commit diagrams generated for downstream
crw*
CLAUDE.md
1 change: 1 addition & 0 deletions antora.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ nav:
- modules/secure/nav.adoc
- modules/optimize/nav.adoc
- modules/observe/nav.adoc
- modules/integrate/nav.adoc
- modules/administration-guide/nav.adoc
- modules/extensions/nav.adoc
- modules/glossary/nav.adoc
Expand Down
7 changes: 0 additions & 7 deletions modules/administration-guide/nav.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -43,13 +43,6 @@
*** xref:configuring-ai-providers.adoc[]
**** xref:ai-provider-api-key-secret-reference.adoc[]
*** xref:customizing-openshift-che-branding-images.adoc[]
** xref:configuring-oauth-for-git-providers.adoc[]
*** xref:configuring-oauth-2-for-github.adoc[]
*** xref:configuring-oauth-2-for-gitlab.adoc[]
*** xref:configuring-oauth-2-for-a-bitbucket-server.adoc[]
*** xref:configuring-oauth-2-for-the-bitbucket-cloud.adoc[]
*** xref:configuring-oauth-1-for-a-bitbucket-server.adoc[]
*** xref:configuring-oauth-2-for-microsoft-azure-devops-services.adoc[]
** xref:configuring-fuse.adoc[]
*** xref:enabling-access-to-dev-fuse-for-openshift.adoc[]
*** xref:enabling-fuse-for-all-workspaces.adoc[]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ To manage {prod-short} server and {prod-short} dashboard workloads, use the Swag
- `pass:c,a,q[{prod-url}]/swagger` ({prod-short} server)
- `pass:c,a,q[{prod-url}]/dashboard/swagger` ({prod-short} dashboard)

IMPORTANT: DevWorkspace is a k8s object and manipulations should happen on the Kubernetes API level - xref:end-user-guide:managing-workspaces-with-apis.adoc[]
IMPORTANT: {devworkspace} is a k8s object and manipulations should happen on the {orch-name} API level - xref:integrate:managing-workspaces-with-apis.adoc[]

.Additional resources

Expand Down
2 changes: 1 addition & 1 deletion modules/discover/pages/roles-and-tasks.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ Common tasks include:

* Deploy {prod-short} on a cluster. See xref:install:con_installation-overview.adoc[].
* Configure the `CheCluster` custom resource. See xref:administration-guide:understanding-the-checluster-custom-resource.adoc[].
* Set up OAuth for Git providers. See xref:administration-guide:configuring-oauth-for-git-providers.adoc[].
* Set up OAuth for Git providers. See xref:integrate:configuring-oauth-for-git-providers.adoc[].
* Control workspace start times with image caching. See xref:optimize:caching-images-for-faster-workspace-start.adoc[].
* Upgrade to the latest version. See xref:upgrade:upgrading-che.adoc[].
* Monitor metrics and logs. See xref:observe:configuring-observability.adoc[].
Expand Down
13 changes: 0 additions & 13 deletions modules/end-user-guide/nav.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -46,20 +46,7 @@
** xref:mounting-secrets.adoc[]
*** xref:creating-image-pull-secrets.adoc[]
*** xref:get-started-user:using-a-git-provider-access-token.adoc[]
*** xref:connecting-to-github-using-device-authorization.adoc[]
** xref:mounting-configmaps.adoc[]
*** xref:mounting-git-configuration.adoc[]
*** xref:mounting-ssh-configuration.adoc[]
** xref:enabling-artifact-repositories-in-a-restricted-environment.adoc[]
*** xref:enabling-maven-artifact-repositories.adoc[]
*** xref:enabling-gradle-artifact-repositories.adoc[]
*** xref:enabling-npm-artifact-repositories.adoc[]
*** xref:enabling-python-artifact-repositories.adoc[]
*** xref:enabling-go-artifact-repositories.adoc[]
*** xref:enabling-nuget-artifact-repositories.adoc[]
* xref:requesting-persistent-storage-for-workspaces.adoc[]
* xref:integrating-with-kubernetes.adoc[]
** xref:managing-workspaces-with-apis.adoc[]
** xref:automatic-token-injection.adoc[]
** xref:navigating-che-from-openshift-developer-perspective.adoc[]
** xref:navigating-openshift-web-console-from-che.adoc[]
Original file line number Diff line number Diff line change
Expand Up @@ -67,5 +67,5 @@ EOF
[role="_additional-resources"]
.Additional resources

* xref:administration-guide:configuring-oauth-for-git-providers.adoc[Connect Git providers with OAuth for GitHub, GitLab, Bitbucket, and Azure DevOps]
* xref:integrate:configuring-oauth-for-git-providers.adoc[Connect Git providers with OAuth for GitHub, GitLab, Bitbucket, and Azure DevOps]
* link:https://docs.github.com/en/developers/apps/building-oauth-apps/creating-an-oauth-app[GitHub Docs: Creating an OAuth App]
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ After verifying the platform and configuring Git access, continue with these con

| Recommended
| Configure OAuth for additional Git providers (GitLab, Bitbucket, Azure DevOps).
| xref:administration-guide:configuring-oauth-for-git-providers.adoc[Connect Git providers with OAuth]
| xref:integrate:configuring-oauth-for-git-providers.adoc[Connect Git providers with OAuth]

| As needed
| Control access to {prod-short} with role-based access control.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ User authentication to a Git server from a cloud development environment is conf
// vale RedHat.GitLinks = NO
* link:https://github.com/devfile/devworkspace-operator/blob/main/docs/additional-configuration.adoc#configuring-devworkspaces-to-use-ssh-keys-for-git-operations[Configuring DevWorkspaces to use SSH keys for Git operations]
// vale RedHat.GitLinks = YES
* xref:administration-guide:configuring-oauth-for-git-providers.adoc[Give developers credential-free Git access]
* xref:integrate:configuring-oauth-for-git-providers.adoc[Give developers credential-free Git access]

// vale RedHat.CaseSensitiveTerms = YES
Original file line number Diff line number Diff line change
Expand Up @@ -32,4 +32,4 @@ Stop, restart, and delete cloud development environments from the {prod-short} d

|===

NOTE: Each cloud development environment is an {orch-name} `DevWorkspace` custom resource. You can also manage cloud development environments from the command line with `{orch-cli}` or `kubectl`. See xref:end-user-guide:managing-workspaces-with-apis.adoc[].
NOTE: Each cloud development environment is an {orch-name} `DevWorkspace` custom resource. You can also manage cloud development environments from the command line with `{orch-cli}` or `kubectl`. See xref:integrate:managing-workspaces-with-apis.adoc[].
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,6 @@ include::partial$snip_persona-admin.adoc[]
.Additional resources

* xref:administration-guide:understanding-the-checluster-custom-resource.adoc[]
* xref:administration-guide:configuring-oauth-for-git-providers.adoc[]
* xref:integrate:configuring-oauth-for-git-providers.adoc[]
* xref:get-started-user:starting-a-workspace-from-a-git-repository-url.adoc[]
* xref:get-started-admin:verify-the-platform-end-to-end.adoc[]
21 changes: 21 additions & 0 deletions modules/integrate/nav.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
.Integrate
* xref:configuring-oauth-for-git-providers.adoc[]
** xref:configuring-oauth-2-for-github.adoc[]
** xref:configuring-oauth-2-for-gitlab.adoc[]
** xref:configuring-oauth-2-for-a-bitbucket-server.adoc[]
** xref:configuring-oauth-2-for-the-bitbucket-cloud.adoc[]
** xref:configuring-oauth-1-for-a-bitbucket-server.adoc[]
** xref:configuring-oauth-2-for-microsoft-azure-devops-services.adoc[]
* xref:connecting-to-github-using-device-authorization.adoc[]
* xref:managing-workspaces-with-apis.adoc[]
* xref:integrating-with-kubernetes.adoc[]
** xref:automatic-token-injection.adoc[]
** xref:navigating-che-from-openshift-developer-perspective.adoc[]
** xref:navigating-openshift-web-console-from-che.adoc[]
* xref:enabling-artifact-repositories-in-a-restricted-environment.adoc[]
** xref:enabling-maven-artifact-repositories.adoc[]
** xref:enabling-gradle-artifact-repositories.adoc[]
** xref:enabling-npm-artifact-repositories.adoc[]
** xref:enabling-python-artifact-repositories.adoc[]
** xref:enabling-go-artifact-repositories.adoc[]
** xref:enabling-nuget-artifact-repositories.adoc[]
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
:_content-type: PROCEDURE
:description: Automatic {orch-name} token injection
:keywords: user-guide, token, injection
:navtitle: Automatic {orch-name} token injection
:navtitle: Use automatic {orch-name} token injection
:page-aliases: .:automatic-token-injection.adoc, overview:automatic-token-injection.adoc

[id="automatic-token-injection"]
= Automatic {orch-name} token injection
= Use automatic {orch-name} token injection

This section describes how to use the {orch-name} user token that is automatically injected into workspace containers which allows running {prod-short} CLI commands against {orch-name} cluster.

Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
:_content-type: ASSEMBLY
:description: Configuring OAuth 1.0 for a Bitbucket Server
:keywords: configuring-oauth, authorization, bitbucket, bitbucket-server, oauth-1, oauth-1.0
:navtitle: Configuring OAuth 1.0 for a Bitbucket Server
:navtitle: Connect Bitbucket Server with OAuth 1.0
// :page-aliases:

[id="configuring-oauth-1-for-a-bitbucket-server"]
= Configuring OAuth 1.0 for a Bitbucket Server
= Connect Bitbucket Server with OAuth 1.0

To enable users to work with a remote Git repository that is hosted on a Bitbucket Server:

Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
:_content-type: ASSEMBLY
:description: Configuring OAuth 2.0 for a Bitbucket Server
:keywords: configuring-oauth, authorization, bitbucket, bitbucket-server, oauth-2, oauth-2.0
:navtitle: Configuring OAuth 2.0 for a Bitbucket Server
:navtitle: Connect Bitbucket Server with OAuth 2.0
// :page-aliases:

[id="configuring-oauth-2-for-a-bitbucket-server"]
= Configuring OAuth 2.0 for a Bitbucket Server
= Connect Bitbucket Server with OAuth 2.0

You can use OAuth 2.0 to enable users to work with a remote Git repository that is hosted on a Bitbucket Server:

Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
:_content-type: ASSEMBLY
:description: Configuring OAuth 2.0 for GitHub
:keywords: configuring-oauth, authorization, github, oauth-2, oauth-2.0
:navtitle: Configuring OAuth 2.0 for GitHub
:navtitle: Connect GitHub with OAuth
:page-aliases:

[id="configuring-oauth-2-for-github"]
= Configuring OAuth 2.0 for GitHub
= Connect GitHub with OAuth

To enable users to work with a remote Git repository that is hosted on GitHub:

Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
:_content-type: ASSEMBLY
:description: Configuring OAuth 2.0 for GitLab
:keywords: configuring-oauth, authorization, gitlab, oauth-2, oauth-2.0
:navtitle: Configuring OAuth 2.0 for GitLab
:navtitle: Connect GitLab with OAuth
:page-aliases:

[id="configuring-oauth-2-for-gitlab"]
= Configuring OAuth 2.0 for GitLab
= Connect GitLab with OAuth

To enable users to work with a remote Git repository that is hosted using a GitLab instance:

Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
:_content-type: ASSEMBLY
:description: Configuring OAuth 2.0 for Microsoft Azure DevOps Services
:keywords: configuring-oauth, authorization, microsoft azure devops services, microsoft azure repos, oauth-2, oauth-2.0
:navtitle: Configuring OAuth 2.0 for Microsoft Azure DevOps Services
:navtitle: Connect Azure DevOps with Microsoft Entra ID
:page-aliases:

[id="configuring-oauth-2-for-microsoft-azure-devops-services"]
= Configuring OAuth 2.0 for Microsoft Azure DevOps Services
= Connect Azure DevOps with Microsoft Entra ID

++++
<!-- vale RedHat.Spelling = NO -->
Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
:_content-type: ASSEMBLY
:description: Configuring OAuth 2.0 for the Bitbucket Cloud
:keywords: configuring-oauth, authorization, bitbucket, bitbucket-cloud, cloud, oauth-2, oauth-2.0
:navtitle: Configuring OAuth 2.0 for the Bitbucket Cloud
:navtitle: Connect Bitbucket Cloud with OAuth
// :page-aliases:

[id="configuring-oauth-2-for-the-bitbucket-cloud"]
= Configuring OAuth 2.0 for the Bitbucket Cloud
= Connect Bitbucket Cloud with OAuth

You can enable users to work with a remote Git repository that is hosted in the Bitbucket Cloud:

Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
:_content-type: CONCEPT
:description: Configuring OAuth for Git providers
:keywords: azure, bitbucket, gitlab, github, git
:navtitle: Configuring OAuth for Git providers
:navtitle: Give developers credential-free Git access
// :page-aliases:

[id="configuring-oauth-for-git-providers"]
= Configuring OAuth for Git providers
= Give developers credential-free Git access

[NOTE]
====
Expand Down
Original file line number Diff line number Diff line change
@@ -1,19 +1,22 @@
:_content-type: PROCEDURE
:description: Connect your GitHub account to {prod-short} using the device authorization flow directly from the Dashboard.
:keywords: user-guide, github, device-authorization, device-auth, token, oauth
:navtitle: Connecting to GitHub using device authorization
:navtitle: Connect to GitHub with device authorization

[id="connecting-to-github-using-device-authorization"]
= Connecting to GitHub using device authorization
= Connect to GitHub with device authorization

[role="_abstract"]
Connect your GitHub account to {prod-short} using the device authorization flow directly from the Dashboard. Device Auth Tokens are GitHub OAuth tokens stored as {kubernetes} Secrets. They enable Git operations in your workspaces without requiring a personal access token.

.Prerequisites

* Your administrator has configured a GitHub OAuth App with Device Flow enabled as described in xref:administration-guide:configuring-oauth-2-for-github.adoc[Configuring OAuth 2.0 for GitHub].
* Your administrator has configured a GitHub OAuth App with Device Flow enabled as described in xref:configuring-oauth-2-for-github.adoc[].
+
NOTE: This feature requires the GitHub OAuth App configuration. It is not available when GitHub authentication is configured using a GitHub App.
[NOTE]
====
This feature requires the GitHub OAuth App configuration. It is not available when GitHub authentication is configured using a GitHub App.
====

.Procedure

Expand All @@ -27,22 +30,28 @@ A modal opens displaying a one-time code.

. Click link:https://github.com/login/device[github.com/login/device] to open the GitHub device activation page.
+
NOTE: For GitHub Enterprise Server, replace `github.com` with your instance hostname.
[NOTE]
====
For GitHub Enterprise Server, replace `github.com` with your instance hostname.
====

. Paste the one-time code on the GitHub page and click *Continue*.

. Authorize the application when prompted by GitHub.
+
NOTE: The permissions granted are determined by the OAuth App configuration set by your administrator.
[NOTE]
====
The permissions granted are determined by the OAuth App configuration set by your administrator.
====
+
After successful authorization, the modal closes and the new token appears in the *Device Auth Tokens* table.
After successful authorization, the modal closes and the new token is displayed in the *Device Auth Tokens* table.

.Verification

* Verify that the new token is listed in the *Device Auth Tokens* table with a valid status.

[id="reconnecting-to-github"]
== Reconnecting to GitHub
== Reconnect to GitHub

Use *Reconnect* when a token has been revoked or has expired on the GitHub side. Reconnecting starts a new device authorization flow and replaces the existing token in-place, preserving any labels on the {kubernetes} Secret.

Expand All @@ -57,7 +66,7 @@ Use *Reconnect* when a token has been revoked or has expired on the GitHub side.
* Verify that the token card shows a valid status after reconnecting.

[id="deleting-device-auth-tokens"]
== Deleting device auth tokens
== Delete a device auth token

Deleting a device auth token removes the {kubernetes} Secret and revokes the GitHub authorization. Device Auth Tokens do not expire automatically. To disconnect your GitHub account, delete the token from this page or revoke access from your GitHub account settings.

Expand All @@ -75,14 +84,15 @@ Deleting a device auth token removes the {kubernetes} Secret and revokes the Git

.Verification

* Verify that the deleted token no longer appears in the *Device Auth Tokens* table.
* Verify that the deleted token is no longer displayed in the *Device Auth Tokens* table.

[id="troubleshooting-device-auth-tokens"]
== Troubleshooting
== Restart after an expired code

If the one-time code expires before you complete the authorization on GitHub (codes expire after approximately 15 minutes), close the modal and click *Connect to GitHub* again to start a new device authorization flow.

[role="_additional-resources"]
.Additional resources

* xref:administration-guide:configuring-oauth-2-for-github.adoc[]
* xref:configuring-oauth-2-for-github.adoc[]
* For an alternative Git authentication method, see xref:get-started-user:using-a-git-provider-access-token.adoc[].
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
:_content-type: ASSEMBLY
:description: Enabling artifact repositories in a restricted environment
:keywords: artifact-repositories, artifact-repository, maven, gradle, nuget, python, go, npm
:navtitle: Enabling artifact repositories in a restricted environment
:navtitle: Connect workspaces to your organization's package registries
:page-aliases: using-artifact-repositories-in-a-restricted-environment.adoc

[id="enabling-artifact-repositories-in-a-restricted-environment"]
= Enabling artifact repositories in a restricted environment
= Connect workspaces to your organization's package registries

By configuring technology stacks, you can work with artifacts from in-house repositories using self-signed certificates:

Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
:_content-type: PROCEDURE
:description: You can enable a Go artifact repository in Go workspaces that run in a restricted environment.
:keywords: go, artifact-repository, artifact-repositories
:navtitle: Go
:navtitle: Enable Go artifact repositories
:page-aliases: using-go-artifact-repositories.adoc

[id="enabling-go-artifact-repositories"]
= Enabling Go artifact repositories
= Enable Go artifact repositories

You can enable a Go artifact repository in Go workspaces that run in a restricted environment.

Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
:_content-type: PROCEDURE
:description: You can enable a Gradle artifact repository in Gradle workspaces that run in a restricted environment.
:keywords: gradle, artifact-repository, artifact-repositories
:navtitle: Gradle
:navtitle: Enable Gradle artifact repositories
:page-aliases: using-gradle-artifact-repositories.adoc

[id="enabling-gradle-artifact-repositories"]
= Enabling Gradle artifact repositories
= Enable Gradle artifact repositories

You can enable a Gradle artifact repository in Gradle workspaces that run in a restricted environment.

Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
:_content-type: PROCEDURE
:description: You can enable a Maven artifact repository in Maven workspaces that run in a restricted environment.
:keywords: maven, artifact-repository, artifact-repositories
:navtitle: Maven
:navtitle: Enable Maven artifact repositories
:page-aliases: using-maven-artifact-repositories.adoc

[id="enabling-maven-artifact-repositories"]
= Enabling Maven artifact repositories
= Enable Maven artifact repositories

You can enable a Maven artifact repository in Maven workspaces that run in a restricted environment.

Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
:_content-type: PROCEDURE
:description: You can enable an npm artifact repository in npm workspaces that run in a restricted environment.
:keywords: npm, artifact-repository, artifact-repositories
:navtitle: npm
:navtitle: Enable npm artifact repositories
:page-aliases: using-npm-artifact-repositories.adoc

[id="enabling-npm-artifact-repositories"]
= Enabling npm artifact repositories
= Enable npm artifact repositories

You can enable an npm artifact repository in npm workspaces that run in a restricted environment.

Expand Down
Loading
Loading