Vcenter NamespaceManagement Supervisors Identity Providers CreateSpec

Vcenter NamespaceManagement Supervisors Identity Providers CreateSpec
Vcenter NamespaceManagement Supervisors Identity Providers CreateSpec

The Vcenter NamespaceManagement Supervisors Identity Providers CreateSpec schema is used to register a new upstream identity provider for use with a Supervisor.

This schema was added in vSphere API 8.0.0.1.

JSON Example
{
    "display_name": "string",
    "issuer_url": "string",
    "username_claim": "string",
    "groups_claim": "string",
    "client_id": "string",
    "client_secret": "string",
    "certificate_authority_data": "string",
    "additional_scopes": [
        "string"
    ],
    "additional_authorize_parameters": {
        "additional_authorize_parameters": "string"
    },
    "allow_credentials_exchange": false
}
string
display_name
Required

A name to be used for the given identity provider. This name will be displayed in the vCenter UI.

This property was added in vSphere API 8.0.0.1.

string
issuer_url
Required

The URL to the identity provider issuing tokens. The OIDC discovery URL will be derived from the issuer URL, according to RFC8414: https://issuerURL/.well-known/openid-configuration. This must use HTTPS as the scheme.

This property was added in vSphere API 8.0.0.1.

string
username_claim
Optional

The claim from the upstream identity provider ID token or user info endpoint to inspect to obtain the username for the given user.

This property was added in vSphere API 8.0.0.1.

If missing or null, the upstream issuer URL will be concatenated with the 'sub' claim to generate the username to be used with Kubernetes.

string
groups_claim
Optional

The claim from the upstream identity provider ID token or user info endpoint to inspect to obtain the groups for the given user.

This property was added in vSphere API 8.0.0.1.

If missing or null, no groups will be used from the upstream identity provider.

string
client_id
Required

The clientID is the OAuth 2.0 client ID registered in the upstream identity provider and used by the Supervisor.

This property was added in vSphere API 8.0.0.1.

string As password As password
client_secret
Required

The OAuth 2.0 client secret to be used by the Supervisor when authenticating to the upstream identity provider.

This property was added in vSphere API 8.0.0.1.

string
certificate_authority_data
Optional

Certificate authority data to be used to establish HTTPS connections with the identity provider. This must be a PEM-encoded value.

This property was added in vSphere API 8.0.0.1.

If missing or null, HTTPS connections with the upstream identity provider will rely on a default set of system trusted roots.

array of string
additional_scopes
Optional

Additional scopes to be requested in tokens issued by this identity provider.

This property was added in vSphere API 8.0.0.1.

If missing or null, no additional scopes will be requested.

object
additional_authorize_parameters
Optional

Any additional parameters to be sent to the upstream identity provider during the authorize request in the OAuth2 authorization code flow. One use case is to pass in a default tenant ID if you have a multi-tenant identity provider. For instance, with VMware's Cloud Services Platform, if your organization ID is 'long-form-org-id', the 'orgLink' parameter can be set to "/csp/gateway/am/api/orgs/long-form-org-id" to allow users logging in to leverage that organization.

This property was added in vSphere API 8.0.0.1.

If missing or null, no additional parameters will be sent to the upstream identity provider.

boolean
allow_credentials_exchange
Optional

Enables a client to exchange an identity provider issued ID token for an mTLS client certificate key pair using the Supervisor 'TokenCredentialRequest' API. Note: Supervisor only supports public OAuth 2.0 clients, which do not require client secrets.

This property was added in vSphere API 9.0.0.0.

Defaults to false if missing or null.