Hi all. I’ve been wondering about account separations while reviewing my SSO stuff. Do you all create a separate account for administrative tasks for your services? Or do you just give your normal account admin rights?

In my opinion, a different account is nice to separate impactful admin work (like provisioning users and groups) from general usage. Having this UX “barrier” also somewhat prevents doing dumb things like accidentally deactivating other people’s accounts. But the downside is it can be quite inconvenient, especially if I need to administer or debug something quickly. I’m also not sure if my homelab expands, should I share the admin user credentials with other human admins or not.

What’s the best topology to use? Or is there some other “accounts structure” that I’ve missed? I’m looking to replicate the same mapping between my identity provider and all dependent services as well (so that if an account is marked as admin on the IDP, it’ll also be the admin for Forgejo or my Matrix server). So it’d be nice to settle on a plan right now.

Thanks for any responses!

  • glizzyguzzler@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    5
    ·
    10 hours ago

    I have an admin account on the server and an SSO admin login for the services. Different credentials obviously - ones an SSH key and ones a password/passkey for SSO - but it seems to fit well. My regular account is bozo level and I don’t need to worry much, I just logout or go to a private window to do admin for an specific program, which is rare but easy enough when it’s needed.

    So far for the SSO services with an admin account design, I just set it up so the admin account for the service is named the SSO admin account so it maps directly when I connect the SSO to it.

    And I SSH into the server for admin there as needed.

    And no mixing with my regular user account!