Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-6741

Quay 3.11 can't sync team members from Redhat keycloak OIDC groups

XMLWordPrintable

    • False
    • None
    • False
    • 0

      Description:

      This is an issue found in Quay 3.11 when configuring Quay to use OIDC authentication, and allow team syncing from Azure OIDC Groups, after login Quay with Azure user via OIDC successfully, create new team and click 'Enable Directory Synchronization', waiting for some time, found can't see new team members sync from Azure OIDC groups, checked Quay APP logs, get error "Got error when trying to iterate group members with config {}: Not supported", pls review this issue, see attached Quay APP POD logs quay311-app-pod1.logs 

      Azure Entra ID groups:

      Quay: quay-operator-bundle-container-v3.11.0-12

      Quay 3.11 can't sync team members from Azure OIDC Groups

      Quay Logs:

      teamsyncworker stdout | 2024-02-29 05:04:13,343 [87] [DEBUG] [data.users.teamsync] Existing membership of 0 for team `myteam1` under organization qateam via {} (#2)
      teamsyncworker stdout | 2024-02-29 05:04:13,343 [87] [ERROR] [data.users.teamsync] Got error when trying to iterate group members with config {}: Not supported 

      Quay config.yaml:

      AUTHENTICATION_TYPE: OIDC
      FEATURE_TEAM_SYNCING: true
      FEATURE_NONSUPERUSER_TEAM_SYNCING_SETUP: true
      AZUREID_LOGIN_CONFIG:
        CLIENT_ID: d38adba5-f32e-4342-b57e-bc0e6dcc4fbe
        CLIENT_SECRET: *******
        LOGIN_SCOPES: [ 'openid', 'roles' ]
        PREFERRED_GROUP_CLAIM_NAME: groupNames
        OIDC_SERVER: https://login.microsoftonline.com/250926f3-c788-4a52-acfa-e3aac5386ac1/v2.0/
        SERVICE_NAME: AzureAD 

        1. image-2024-02-29-13-17-52-015.png
          image-2024-02-29-13-17-52-015.png
          343 kB
        2. image-2024-02-29-13-17-59-884.png
          image-2024-02-29-13-17-59-884.png
          343 kB
        3. image-2024-02-29-13-23-43-803.png
          image-2024-02-29-13-23-43-803.png
          393 kB
        4. image-2024-02-29-13-23-57-928.png
          image-2024-02-29-13-23-57-928.png
          362 kB
        5. image-2024-03-01-13-56-32-545.png
          image-2024-03-01-13-56-32-545.png
          320 kB
        6. image-2024-03-01-13-57-11-945.png
          image-2024-03-01-13-57-11-945.png
          330 kB
        7. image-2024-03-01-13-57-45-882.png
          image-2024-03-01-13-57-45-882.png
          502 kB
        8. image-2024-03-01-14-00-59-152.png
          image-2024-03-01-14-00-59-152.png
          467 kB
        9. image-2024-03-01-14-07-46-494.png
          image-2024-03-01-14-07-46-494.png
          508 kB
        10. image-2024-03-01-15-51-10-864.png
          image-2024-03-01-15-51-10-864.png
          274 kB
        11. image-2024-03-01-15-51-50-730.png
          image-2024-03-01-15-51-50-730.png
          298 kB
        12. image-2024-03-07-17-15-20-135.png
          image-2024-03-07-17-15-20-135.png
          326 kB
        13. image-2024-03-07-17-17-15-950.png
          image-2024-03-07-17-17-15-950.png
          311 kB
        14. quay311-app-pod1.logs
          2.01 MB

            sdadi@redhat.com Sunanda Dadi
            lzha1981 luffy zhang
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: