Skip to content

Rancher OIDC scope docs - #433

Merged
rb3ckers merged 4 commits into
stagingfrom
rancher-oidc-scope-docs
Sep 25, 2026
Merged

rb3ckers merged 4 commits into
stagingfrom
rancher-oidc-scope-docs

Conversation

@rb3ckers

Copy link
Copy Markdown
Contributor

Document Rancher OIDC scope configuration, upgrade ordering, and known authentication issues, including the latest troubleshooting updates.

Tracks https://github.com/StackVista/helm-charts-internal/issues/233 and accompanies https://github.com/StackVista/helm-charts-internal/pull/236. Replaces #432 using a branch in this repository; targets staging.

Validation: English link syntax and navigation checks passed.

@rb3ckers
rb3ckers requested a review from a team as a code owner September 24, 2026 10:43
@netlify

netlify Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for suse-obs ready!

Name Link
🔨 Latest commit b8972ed
🔍 Latest deploy log https://app.netlify.com/projects/suse-obs/deploys/6ab61e2789b3260008933c3e
😎 Deploy Preview https://deploy-preview-433--suse-obs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@LouisLotter

LouisLotter commented Sep 24, 2026 •

Copy link
Copy Markdown

Four findings from the review:

  • P2 — Preserve session lifetime (troubleshooting.adoc:55). Switching from rancher to generic oidc changes the default from 16 hours to seven days, confirmed with a focused render of the template from #236. Set stackstate.authentication.sessionLifetime: 16h when no explicit value exists; retain custom values.
  • P2 — Preserve provider settings (troubleshooting.adoc:49). The replacement example drops custom redirect URIs, logout options and custom parameters. A registered custom callback can then fail login. Carry over the preservation instructions from Document Rancher group permissions workaround #434.
  • P3 — Repair list continuations (oidc.adoc:118–128). In the deploy preview, the final upgrade steps render as a literal block, including an unsubstituted {next-release-version}. Add AsciiDoc continuations around the patch example and following paragraph so the list resumes correctly.
  • P3 — Fix both troubleshooting anchors (oidc.adoc:18,80). Use _known_issues; the current _known-issues does not match the generated heading. Document Rancher group permissions workaround #434 already uses the correct fragment.

Validation: source review, focused authentication-template rendering and the docs preview. No live Rancher login test.

@rb3ckers

Copy link
Copy Markdown
Contributor Author

Adding the session lifetime, but I have no clue why I would be adding a custom redirect uri. That only makes sense if someone had that for Rancher. I'll only add a line saying to take any of the other custom Rancher settings and copy them over (although I don't expect anyone to have any custom settings at all).

For the P3s: adoc is hard 😢

@rb3ckers
rb3ckers force-pushed the rancher-oidc-scope-docs branch from 6879fb4 to 03b3b5a Compare September 24, 2026 15:02
@rb3ckers
rb3ckers force-pushed the rancher-oidc-scope-docs branch from 03b3b5a to bb9c61d Compare September 24, 2026 15:13
@rb3ckers
rb3ckers merged commit 142d2d6 into staging Sep 25, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants