mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-27 21:50:21 +00:00
Apply da5890332 (Add client roles mapping section) to other doc versions/languages
This commit is contained in:
+4
-7
@@ -62,13 +62,10 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
`Add to access token` | `ON`
|
`Add to access token` | `ON`
|
||||||
`Add to user info` | `ON`
|
`Add to user info` | `ON`
|
||||||
|
|
||||||
- Add the following Role Mappings to all users or groups that need to query the Keycloak users
|
- Go to **Role Mappings > Client Roles > realm-management** and add the following Role Mappings to all users or groups that need to query the Keycloak users.
|
||||||
```
|
- query-users
|
||||||
Role Mappings > Client Roles > realm-management
|
- query-groups
|
||||||
+ query-users
|
- view-users
|
||||||
+ query-groups
|
|
||||||
+ view-users
|
|
||||||
```
|
|
||||||
|
|
||||||
## Configuring Keycloak in Rancher
|
## Configuring Keycloak in Rancher
|
||||||
|
|
||||||
|
|||||||
+9
@@ -31,6 +31,7 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Name` | `Groups Mapper` |
|
| `Name` | `Groups Mapper` |
|
||||||
| `Mapper Type` | `Group Membership` |
|
| `Mapper Type` | `Group Membership` |
|
||||||
| `Token Claim Name` | `groups` |
|
| `Token Claim Name` | `groups` |
|
||||||
|
| `Full group path` | `OFF` |
|
||||||
| `Add to ID token` | `OFF` |
|
| `Add to ID token` | `OFF` |
|
||||||
| `Add to access token` | `OFF` |
|
| `Add to access token` | `OFF` |
|
||||||
| `Add to user info` | `ON` |
|
| `Add to user info` | `ON` |
|
||||||
@@ -42,6 +43,7 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Name` | `Client Audience` |
|
| `Name` | `Client Audience` |
|
||||||
| `Mapper Type` | `Audience` |
|
| `Mapper Type` | `Audience` |
|
||||||
| `Included Client Audience` | <CLIENT_NAME> |
|
| `Included Client Audience` | <CLIENT_NAME> |
|
||||||
|
| `Add to ID token` | `OFF` |
|
||||||
| `Add to access token` | `ON` |
|
| `Add to access token` | `ON` |
|
||||||
|
|
||||||
- 使用以下设置创建一个新的 "Groups Path":
|
- 使用以下设置创建一个新的 "Groups Path":
|
||||||
@@ -52,8 +54,15 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Mapper Type` | `Group Membership` |
|
| `Mapper Type` | `Group Membership` |
|
||||||
| `Token Claim Name` | `full_group_path` |
|
| `Token Claim Name` | `full_group_path` |
|
||||||
| `Full group path` | `ON` |
|
| `Full group path` | `ON` |
|
||||||
|
| `Add to ID token` | `ON` |
|
||||||
|
| `Add to access token` | `ON` |
|
||||||
| `Add to user info` | `ON` |
|
| `Add to user info` | `ON` |
|
||||||
|
|
||||||
|
- Go to **Role Mappings > Client Roles > realm-management** and add the following Role Mappings to all users or groups that need to query the Keycloak users.
|
||||||
|
- query-users
|
||||||
|
- query-groups
|
||||||
|
- view-users
|
||||||
|
|
||||||
## 在 Rancher 中配置 Keycloak
|
## 在 Rancher 中配置 Keycloak
|
||||||
|
|
||||||
1. 在 Rancher UI 中,单击 **☰ > 用户 & 认证**。
|
1. 在 Rancher UI 中,单击 **☰ > 用户 & 认证**。
|
||||||
|
|||||||
+9
@@ -31,6 +31,7 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Name` | `Groups Mapper` |
|
| `Name` | `Groups Mapper` |
|
||||||
| `Mapper Type` | `Group Membership` |
|
| `Mapper Type` | `Group Membership` |
|
||||||
| `Token Claim Name` | `groups` |
|
| `Token Claim Name` | `groups` |
|
||||||
|
| `Full group path` | `OFF` |
|
||||||
| `Add to ID token` | `OFF` |
|
| `Add to ID token` | `OFF` |
|
||||||
| `Add to access token` | `OFF` |
|
| `Add to access token` | `OFF` |
|
||||||
| `Add to user info` | `ON` |
|
| `Add to user info` | `ON` |
|
||||||
@@ -42,6 +43,7 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Name` | `Client Audience` |
|
| `Name` | `Client Audience` |
|
||||||
| `Mapper Type` | `Audience` |
|
| `Mapper Type` | `Audience` |
|
||||||
| `Included Client Audience` | <CLIENT_NAME> |
|
| `Included Client Audience` | <CLIENT_NAME> |
|
||||||
|
| `Add to ID token` | `OFF` |
|
||||||
| `Add to access token` | `ON` |
|
| `Add to access token` | `ON` |
|
||||||
|
|
||||||
- 使用以下设置创建一个新的 "Groups Path":
|
- 使用以下设置创建一个新的 "Groups Path":
|
||||||
@@ -52,8 +54,15 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Mapper Type` | `Group Membership` |
|
| `Mapper Type` | `Group Membership` |
|
||||||
| `Token Claim Name` | `full_group_path` |
|
| `Token Claim Name` | `full_group_path` |
|
||||||
| `Full group path` | `ON` |
|
| `Full group path` | `ON` |
|
||||||
|
| `Add to ID token` | `ON` |
|
||||||
|
| `Add to access token` | `ON` |
|
||||||
| `Add to user info` | `ON` |
|
| `Add to user info` | `ON` |
|
||||||
|
|
||||||
|
- Go to **Role Mappings > Client Roles > realm-management** and add the following Role Mappings to all users or groups that need to query the Keycloak users.
|
||||||
|
- query-users
|
||||||
|
- query-groups
|
||||||
|
- view-users
|
||||||
|
|
||||||
## 在 Rancher 中配置 Keycloak
|
## 在 Rancher 中配置 Keycloak
|
||||||
|
|
||||||
1. 在 Rancher UI 中,单击 **☰ > 用户 & 认证**。
|
1. 在 Rancher UI 中,单击 **☰ > 用户 & 认证**。
|
||||||
|
|||||||
+9
@@ -31,6 +31,7 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Name` | `Groups Mapper` |
|
| `Name` | `Groups Mapper` |
|
||||||
| `Mapper Type` | `Group Membership` |
|
| `Mapper Type` | `Group Membership` |
|
||||||
| `Token Claim Name` | `groups` |
|
| `Token Claim Name` | `groups` |
|
||||||
|
| `Full group path` | `OFF` |
|
||||||
| `Add to ID token` | `OFF` |
|
| `Add to ID token` | `OFF` |
|
||||||
| `Add to access token` | `OFF` |
|
| `Add to access token` | `OFF` |
|
||||||
| `Add to user info` | `ON` |
|
| `Add to user info` | `ON` |
|
||||||
@@ -42,6 +43,7 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Name` | `Client Audience` |
|
| `Name` | `Client Audience` |
|
||||||
| `Mapper Type` | `Audience` |
|
| `Mapper Type` | `Audience` |
|
||||||
| `Included Client Audience` | <CLIENT_NAME> |
|
| `Included Client Audience` | <CLIENT_NAME> |
|
||||||
|
| `Add to ID token` | `OFF` |
|
||||||
| `Add to access token` | `ON` |
|
| `Add to access token` | `ON` |
|
||||||
|
|
||||||
- 使用以下设置创建一个新的 "Groups Path":
|
- 使用以下设置创建一个新的 "Groups Path":
|
||||||
@@ -52,8 +54,15 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Mapper Type` | `Group Membership` |
|
| `Mapper Type` | `Group Membership` |
|
||||||
| `Token Claim Name` | `full_group_path` |
|
| `Token Claim Name` | `full_group_path` |
|
||||||
| `Full group path` | `ON` |
|
| `Full group path` | `ON` |
|
||||||
|
| `Add to ID token` | `ON` |
|
||||||
|
| `Add to access token` | `ON` |
|
||||||
| `Add to user info` | `ON` |
|
| `Add to user info` | `ON` |
|
||||||
|
|
||||||
|
- Go to **Role Mappings > Client Roles > realm-management** and add the following Role Mappings to all users or groups that need to query the Keycloak users.
|
||||||
|
- query-users
|
||||||
|
- query-groups
|
||||||
|
- view-users
|
||||||
|
|
||||||
## 在 Rancher 中配置 Keycloak
|
## 在 Rancher 中配置 Keycloak
|
||||||
|
|
||||||
1. 在 Rancher UI 中,单击 **☰ > 用户 & 认证**。
|
1. 在 Rancher UI 中,单击 **☰ > 用户 & 认证**。
|
||||||
|
|||||||
+9
@@ -31,6 +31,7 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Name` | `Groups Mapper` |
|
| `Name` | `Groups Mapper` |
|
||||||
| `Mapper Type` | `Group Membership` |
|
| `Mapper Type` | `Group Membership` |
|
||||||
| `Token Claim Name` | `groups` |
|
| `Token Claim Name` | `groups` |
|
||||||
|
| `Full group path` | `OFF` |
|
||||||
| `Add to ID token` | `OFF` |
|
| `Add to ID token` | `OFF` |
|
||||||
| `Add to access token` | `OFF` |
|
| `Add to access token` | `OFF` |
|
||||||
| `Add to user info` | `ON` |
|
| `Add to user info` | `ON` |
|
||||||
@@ -42,6 +43,7 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Name` | `Client Audience` |
|
| `Name` | `Client Audience` |
|
||||||
| `Mapper Type` | `Audience` |
|
| `Mapper Type` | `Audience` |
|
||||||
| `Included Client Audience` | <CLIENT_NAME> |
|
| `Included Client Audience` | <CLIENT_NAME> |
|
||||||
|
| `Add to ID token` | `OFF` |
|
||||||
| `Add to access token` | `ON` |
|
| `Add to access token` | `ON` |
|
||||||
|
|
||||||
- 使用以下设置创建一个新的 "Groups Path":
|
- 使用以下设置创建一个新的 "Groups Path":
|
||||||
@@ -52,8 +54,15 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Mapper Type` | `Group Membership` |
|
| `Mapper Type` | `Group Membership` |
|
||||||
| `Token Claim Name` | `full_group_path` |
|
| `Token Claim Name` | `full_group_path` |
|
||||||
| `Full group path` | `ON` |
|
| `Full group path` | `ON` |
|
||||||
|
| `Add to ID token` | `ON` |
|
||||||
|
| `Add to access token` | `ON` |
|
||||||
| `Add to user info` | `ON` |
|
| `Add to user info` | `ON` |
|
||||||
|
|
||||||
|
- Go to **Role Mappings > Client Roles > realm-management** and add the following Role Mappings to all users or groups that need to query the Keycloak users.
|
||||||
|
- query-users
|
||||||
|
- query-groups
|
||||||
|
- view-users
|
||||||
|
|
||||||
## 在 Rancher 中配置 Keycloak
|
## 在 Rancher 中配置 Keycloak
|
||||||
|
|
||||||
1. 在 Rancher UI 中,单击 **☰ > 用户 & 认证**。
|
1. 在 Rancher UI 中,单击 **☰ > 用户 & 认证**。
|
||||||
|
|||||||
+9
@@ -31,6 +31,7 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Name` | `Groups Mapper` |
|
| `Name` | `Groups Mapper` |
|
||||||
| `Mapper Type` | `Group Membership` |
|
| `Mapper Type` | `Group Membership` |
|
||||||
| `Token Claim Name` | `groups` |
|
| `Token Claim Name` | `groups` |
|
||||||
|
| `Full group path` | `OFF` |
|
||||||
| `Add to ID token` | `OFF` |
|
| `Add to ID token` | `OFF` |
|
||||||
| `Add to access token` | `OFF` |
|
| `Add to access token` | `OFF` |
|
||||||
| `Add to user info` | `ON` |
|
| `Add to user info` | `ON` |
|
||||||
@@ -42,6 +43,7 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Name` | `Client Audience` |
|
| `Name` | `Client Audience` |
|
||||||
| `Mapper Type` | `Audience` |
|
| `Mapper Type` | `Audience` |
|
||||||
| `Included Client Audience` | <CLIENT_NAME> |
|
| `Included Client Audience` | <CLIENT_NAME> |
|
||||||
|
| `Add to ID token` | `OFF` |
|
||||||
| `Add to access token` | `ON` |
|
| `Add to access token` | `ON` |
|
||||||
|
|
||||||
- 使用以下设置创建一个新的 "Groups Path":
|
- 使用以下设置创建一个新的 "Groups Path":
|
||||||
@@ -52,8 +54,15 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
|||||||
| `Mapper Type` | `Group Membership` |
|
| `Mapper Type` | `Group Membership` |
|
||||||
| `Token Claim Name` | `full_group_path` |
|
| `Token Claim Name` | `full_group_path` |
|
||||||
| `Full group path` | `ON` |
|
| `Full group path` | `ON` |
|
||||||
|
| `Add to ID token` | `ON` |
|
||||||
|
| `Add to access token` | `ON` |
|
||||||
| `Add to user info` | `ON` |
|
| `Add to user info` | `ON` |
|
||||||
|
|
||||||
|
- Go to **Role Mappings > Client Roles > realm-management** and add the following Role Mappings to all users or groups that need to query the Keycloak users.
|
||||||
|
- query-users
|
||||||
|
- query-groups
|
||||||
|
- view-users
|
||||||
|
|
||||||
## 在 Rancher 中配置 Keycloak
|
## 在 Rancher 中配置 Keycloak
|
||||||
|
|
||||||
1. 在 Rancher UI 中,单击 **☰ > 用户 & 认证**。
|
1. 在 Rancher UI 中,单击 **☰ > 用户 & 认证**。
|
||||||
|
|||||||
+9
@@ -35,6 +35,7 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
`Name` | `Groups Mapper`
|
`Name` | `Groups Mapper`
|
||||||
`Mapper Type` | `Group Membership`
|
`Mapper Type` | `Group Membership`
|
||||||
`Token Claim Name` | `groups`
|
`Token Claim Name` | `groups`
|
||||||
|
`Full group path` | `OFF`
|
||||||
`Add to ID token` | `OFF`
|
`Add to ID token` | `OFF`
|
||||||
`Add to access token` | `OFF`
|
`Add to access token` | `OFF`
|
||||||
`Add to user info` | `ON`
|
`Add to user info` | `ON`
|
||||||
@@ -46,6 +47,7 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
`Name` | `Client Audience`
|
`Name` | `Client Audience`
|
||||||
`Mapper Type` | `Audience`
|
`Mapper Type` | `Audience`
|
||||||
`Included Client Audience` | <CLIENT_NAME>
|
`Included Client Audience` | <CLIENT_NAME>
|
||||||
|
`Add to ID token` | `OFF`
|
||||||
`Add to access token` | `ON`
|
`Add to access token` | `ON`
|
||||||
|
|
||||||
- Create a new "Groups Path" with the settings below.
|
- Create a new "Groups Path" with the settings below.
|
||||||
@@ -56,8 +58,15 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
`Mapper Type` | `Group Membership`
|
`Mapper Type` | `Group Membership`
|
||||||
`Token Claim Name` | `full_group_path`
|
`Token Claim Name` | `full_group_path`
|
||||||
`Full group path` | `ON`
|
`Full group path` | `ON`
|
||||||
|
`Add to ID token` | `ON`
|
||||||
|
`Add to access token` | `ON`
|
||||||
`Add to user info` | `ON`
|
`Add to user info` | `ON`
|
||||||
|
|
||||||
|
- Go to **Role Mappings > Client Roles > realm-management** and add the following Role Mappings to all users or groups that need to query the Keycloak users.
|
||||||
|
- query-users
|
||||||
|
- query-groups
|
||||||
|
- view-users
|
||||||
|
|
||||||
## Configuring Keycloak in Rancher
|
## Configuring Keycloak in Rancher
|
||||||
|
|
||||||
1. In the Rancher UI, click **☰ > Users & Authentication**.
|
1. In the Rancher UI, click **☰ > Users & Authentication**.
|
||||||
|
|||||||
+9
@@ -35,6 +35,7 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
`Name` | `Groups Mapper`
|
`Name` | `Groups Mapper`
|
||||||
`Mapper Type` | `Group Membership`
|
`Mapper Type` | `Group Membership`
|
||||||
`Token Claim Name` | `groups`
|
`Token Claim Name` | `groups`
|
||||||
|
`Full group path` | `OFF`
|
||||||
`Add to ID token` | `OFF`
|
`Add to ID token` | `OFF`
|
||||||
`Add to access token` | `OFF`
|
`Add to access token` | `OFF`
|
||||||
`Add to user info` | `ON`
|
`Add to user info` | `ON`
|
||||||
@@ -46,6 +47,7 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
`Name` | `Client Audience`
|
`Name` | `Client Audience`
|
||||||
`Mapper Type` | `Audience`
|
`Mapper Type` | `Audience`
|
||||||
`Included Client Audience` | <CLIENT_NAME>
|
`Included Client Audience` | <CLIENT_NAME>
|
||||||
|
`Add to ID token` | `OFF`
|
||||||
`Add to access token` | `ON`
|
`Add to access token` | `ON`
|
||||||
|
|
||||||
- Create a new "Groups Path" with the settings below.
|
- Create a new "Groups Path" with the settings below.
|
||||||
@@ -56,8 +58,15 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
`Mapper Type` | `Group Membership`
|
`Mapper Type` | `Group Membership`
|
||||||
`Token Claim Name` | `full_group_path`
|
`Token Claim Name` | `full_group_path`
|
||||||
`Full group path` | `ON`
|
`Full group path` | `ON`
|
||||||
|
`Add to ID token` | `ON`
|
||||||
|
`Add to access token` | `ON`
|
||||||
`Add to user info` | `ON`
|
`Add to user info` | `ON`
|
||||||
|
|
||||||
|
- Go to **Role Mappings > Client Roles > realm-management** and add the following Role Mappings to all users or groups that need to query the Keycloak users.
|
||||||
|
- query-users
|
||||||
|
- query-groups
|
||||||
|
- view-users
|
||||||
|
|
||||||
## Configuring Keycloak in Rancher
|
## Configuring Keycloak in Rancher
|
||||||
|
|
||||||
1. In the Rancher UI, click **☰ > Users & Authentication**.
|
1. In the Rancher UI, click **☰ > Users & Authentication**.
|
||||||
|
|||||||
+9
@@ -35,6 +35,7 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
`Name` | `Groups Mapper`
|
`Name` | `Groups Mapper`
|
||||||
`Mapper Type` | `Group Membership`
|
`Mapper Type` | `Group Membership`
|
||||||
`Token Claim Name` | `groups`
|
`Token Claim Name` | `groups`
|
||||||
|
`Full group path` | `OFF`
|
||||||
`Add to ID token` | `OFF`
|
`Add to ID token` | `OFF`
|
||||||
`Add to access token` | `OFF`
|
`Add to access token` | `OFF`
|
||||||
`Add to user info` | `ON`
|
`Add to user info` | `ON`
|
||||||
@@ -46,6 +47,7 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
`Name` | `Client Audience`
|
`Name` | `Client Audience`
|
||||||
`Mapper Type` | `Audience`
|
`Mapper Type` | `Audience`
|
||||||
`Included Client Audience` | <CLIENT_NAME>
|
`Included Client Audience` | <CLIENT_NAME>
|
||||||
|
`Add to ID token` | `OFF`
|
||||||
`Add to access token` | `ON`
|
`Add to access token` | `ON`
|
||||||
|
|
||||||
- Create a new "Groups Path" with the settings below.
|
- Create a new "Groups Path" with the settings below.
|
||||||
@@ -56,8 +58,15 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
`Mapper Type` | `Group Membership`
|
`Mapper Type` | `Group Membership`
|
||||||
`Token Claim Name` | `full_group_path`
|
`Token Claim Name` | `full_group_path`
|
||||||
`Full group path` | `ON`
|
`Full group path` | `ON`
|
||||||
|
`Add to ID token` | `ON`
|
||||||
|
`Add to access token` | `ON`
|
||||||
`Add to user info` | `ON`
|
`Add to user info` | `ON`
|
||||||
|
|
||||||
|
- Go to **Role Mappings > Client Roles > realm-management** and add the following Role Mappings to all users or groups that need to query the Keycloak users.
|
||||||
|
- query-users
|
||||||
|
- query-groups
|
||||||
|
- view-users
|
||||||
|
|
||||||
## Configuring Keycloak in Rancher
|
## Configuring Keycloak in Rancher
|
||||||
|
|
||||||
1. In the Rancher UI, click **☰ > Users & Authentication**.
|
1. In the Rancher UI, click **☰ > Users & Authentication**.
|
||||||
|
|||||||
+9
@@ -35,6 +35,7 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
`Name` | `Groups Mapper`
|
`Name` | `Groups Mapper`
|
||||||
`Mapper Type` | `Group Membership`
|
`Mapper Type` | `Group Membership`
|
||||||
`Token Claim Name` | `groups`
|
`Token Claim Name` | `groups`
|
||||||
|
`Full group path` | `OFF`
|
||||||
`Add to ID token` | `OFF`
|
`Add to ID token` | `OFF`
|
||||||
`Add to access token` | `OFF`
|
`Add to access token` | `OFF`
|
||||||
`Add to user info` | `ON`
|
`Add to user info` | `ON`
|
||||||
@@ -46,6 +47,7 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
`Name` | `Client Audience`
|
`Name` | `Client Audience`
|
||||||
`Mapper Type` | `Audience`
|
`Mapper Type` | `Audience`
|
||||||
`Included Client Audience` | <CLIENT_NAME>
|
`Included Client Audience` | <CLIENT_NAME>
|
||||||
|
`Add to ID token` | `OFF`
|
||||||
`Add to access token` | `ON`
|
`Add to access token` | `ON`
|
||||||
|
|
||||||
- Create a new "Groups Path" with the settings below.
|
- Create a new "Groups Path" with the settings below.
|
||||||
@@ -56,8 +58,15 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
`Mapper Type` | `Group Membership`
|
`Mapper Type` | `Group Membership`
|
||||||
`Token Claim Name` | `full_group_path`
|
`Token Claim Name` | `full_group_path`
|
||||||
`Full group path` | `ON`
|
`Full group path` | `ON`
|
||||||
|
`Add to ID token` | `ON`
|
||||||
|
`Add to access token` | `ON`
|
||||||
`Add to user info` | `ON`
|
`Add to user info` | `ON`
|
||||||
|
|
||||||
|
- Go to **Role Mappings > Client Roles > realm-management** and add the following Role Mappings to all users or groups that need to query the Keycloak users.
|
||||||
|
- query-users
|
||||||
|
- query-groups
|
||||||
|
- view-users
|
||||||
|
|
||||||
## Configuring Keycloak in Rancher
|
## Configuring Keycloak in Rancher
|
||||||
|
|
||||||
1. In the Rancher UI, click **☰ > Users & Authentication**.
|
1. In the Rancher UI, click **☰ > Users & Authentication**.
|
||||||
|
|||||||
Reference in New Issue
Block a user