How can I resolve OIDC authentication to policies?...
# getting-started
t
How can I resolve OIDC authentication to policies? Is it required to set this for every user? Is there a way to assign a policy based on external IAM, e.g. in Google Cloud?
g
We recommend ingesting users & groups from OIDCs, then assigning policies to those groups in datahub.
What OIDC provider do you use?
t
Thanks @green-football-43791 I would be using Google Identity. (I don’t think it matters, but FYI Google IAP will be in front of datahub at the project level.)
Ah, ok, I found what I needed (using group claims) in this section of the documentation. https://datahubproject.io/docs/authentication/guides/sso/configure-oidc-react