Sysdig Documentation

Authentication and Authorization (SaaS)

Sysdig Monitor and Sysdig Secure are designed to work with several user authentication/authorization methods:

Type

Enabled by Default

Integration Steps Required

User email/password

Yes

No

Google OAuth

No

No

SAML

No

Yes

OpenID Connect

No

Yes

The user's view:

373575890.png

The pages in this section describe the integration and enablement steps required for SAML or OpenID Connect, and the Identity Provider (IdP) services that support these protocols, such as Okta, OneLogin, Keycloak.

In the SaaS environment, Google login can be enabled with a simple drop-down selection; the integration has already been performed.

Note

To integrate SAML or OpenID Connect with both Sysdig Monitor and Sysdig Secure, you must go through the integration steps twice, once for each Sysdig product.

Workflow

With the new Authorization UI, the basic process of enabling a Single Sign-On (SSO) option is:

  1. Determine which SSO option (GoogleOAuth, SAML, OpenID) your enterprise uses, and which IdP service (Okta, OneLogin, etc.) is used, if any.

  2. Enter the required connection settings for the chosen SSO on the appropriate Authentication tab. (Note: for Google, the settings are already entered.)

  3. Configure any associated IdP settings on the IdP side.

  4. Select the SSO option from the Enabled Single Sign-On drop-down and click Save Authentication.

  5. If enabling for both Sysdig Monitor and Sysdig Secure, repeat the process on the second application.

373575877.png

View of the Authentication page for Google OAuth in the SaaS environment.