-
Notifications
You must be signed in to change notification settings - Fork 1.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
docs: Identity Center Okta to Teleport migration guide #51861
base: master
Are you sure you want to change the base?
Conversation
Amplify deployment status
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks reasonable, left a few things to consider.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Let's please use LucidChart for the diagrams so all the graphics in our documentation are consistent.
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
--user-origin okta \ | ||
--account-name ${ACCOUNT_NAME_ALLOW_FILTER} \ | ||
--group-name ${GROUP_NAME_ALLOW_FILTER} |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
A logical question that arises, how can these filters be updated after the integration has been created? I didn't see a mention of this later in the guide.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nit: I see you added a section below on editing the integration. Maybe just add a quick note here that group filters can be updated and a reference to the later section of the guide.
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
Co-authored-by: Roman Tkachenko <[email protected]>
- Rearranged to move migration path into "how it works" - Added Uninstall section - Added edit section
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why does this one have a white background and the other images have transparent backgrounds?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
No idea. Will re-export from lucid and see what happens.
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
To make sure everything is working, wait until the first Okta to Teleport user | ||
sync has occurred. You can verify this by either | ||
- refreshing the user page and finding your Okta users, | ||
- checking the Okta integration status page, or |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
or what?
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Show resolved
Hide resolved
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Show resolved
Hide resolved
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
region: us-east-1 | ||
``` | ||
|
||
You can add or remove filters to the various filters. Once you save and quit the |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"filters to the various filters" reads strange
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
And this is why proofreading exists.
docs/pages/admin-guides/management/guides/migrating-iam-ic-from-okta-to-teleport.mdx
Outdated
Show resolved
Hide resolved
|
||
## Step 7: Retire Okta group provisioning | ||
|
||
Once you are happy that a group has been migrated to Teleport control, you can |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Feels like a word is missing here, maybe "that group provisioning has been migrated"?
|
||
## Deleting the Identity Center integration | ||
|
||
If you decide not to switch over to Teleport you can delete the Identity Center |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We should clarify what happens during deletion and how to clean up resources created by the integration.
Co-authored-by: Roman Tkachenko <[email protected]> Co-authored-by: Zac Bergquist <[email protected]>
$ tctl plugins install awsic \ | ||
--arn ${IDENTITY_CENTER_INSTANCE_ARN} \ | ||
--region ${IDENTITY_CENTER_INSTANCE_REGION} \ | ||
--use-system-credentials \ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can we add more details on use-system-credent?
Like provide hint that it refers to AWS credentials. Specifically, it should clarify that use-system-credent will allow to load AWS credentials from the local environment in Teleport Auth to authenticate with the AWS IC API.
No description provided.