Skip to content

Add support for OIDC admin groups in addition to admin users - #6

Merged
brianhlin merged 3 commits into
PelicanPlatform:mainfrom
matyasselmeci:pr/admingroups
Jul 30, 2026
Merged

brianhlin merged 3 commits into
PelicanPlatform:mainfrom
matyasselmeci:pr/admingroups

Conversation

@matyasselmeci

Copy link
Copy Markdown
Contributor

The chart variable is oidc.adminGroups, which is a list of CILogon group names.
This is added to Server.AdminGroups in the Pelican configmap.
Either oidc.adminUsers or oidc.adminGroups (or both) must be nonempty when OIDC is enabled.

matyasselmeci and others added 2 commits July 23, 2026 17:32
The chart variable is `oidc.adminGroups`, which is a list of CILogon group names.
This is added to `Server.AdminGroups` in the Pelican configmap.
Either `oidc.adminUsers` or `oidc.adminGroups` (or both) must be nonempty when OIDC is enabled.

Co-authored-by: Copilot <copilot@github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR extends the pelican-cache Helm chart’s OIDC configuration to support granting Pelican Web UI admin privileges via CILogon group names (oidc.adminGroups) in addition to the existing per-user sub allowlist (oidc.adminUsers). It updates both the rendered Pelican configuration and the chart’s template-time validation/docs to ensure OIDC admin authorization is configured safely when OIDC is enabled.

Changes:

  • Add oidc.adminGroups to values.yaml and render it into the Pelican config as Server.AdminGroups.
  • Update Helm render-time validation so that when oidc.enabled=true, at least one of oidc.adminUsers or oidc.adminGroups is nonempty (and vice versa).
  • Update README documentation/examples and bump chart version to 0.2.4.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated no comments.

Show a summary per file
File Description
values.yaml Adds oidc.adminGroups value and documents the “users and/or groups required when enabled” rule.
templates/configmap-pelican.yaml Renders oidc.adminGroups into Server.AdminGroups in config.yaml.
templates/_helpers.tpl Updates validation logic to require admin users and/or groups when OIDC is enabled and to reject admin lists when OIDC is disabled.
README.md Documents the new setting and provides examples for users-only, groups-only, and mixed configurations.
Chart.yaml Bumps chart version from 0.2.3 to 0.2.4.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@matyasselmeci
matyasselmeci requested a review from a team July 30, 2026 15:40

@brianhlin brianhlin left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@brianhlin
brianhlin merged commit 4bcaa34 into PelicanPlatform:main Jul 30, 2026
6 checks passed
@matyasselmeci
matyasselmeci deleted the pr/admingroups branch July 30, 2026 17:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants