Hi all. I’ve been wondering about account separations while reviewing my SSO stuff. Do you all create a separate account for administrative tasks for your services? Or do you just give your normal account admin rights?

In my opinion, a different account is nice to separate impactful admin work (like provisioning users and groups) from general usage. Having this UX “barrier” also somewhat prevents doing dumb things like accidentally deactivating other people’s accounts. But the downside is it can be quite inconvenient, especially if I need to administer or debug something quickly. I’m also not sure if my homelab expands, should I share the admin user credentials with other human admins or not.

What’s the best topology to use? Or is there some other “accounts structure” that I’ve missed? I’m looking to replicate the same mapping between my identity provider and all dependent services as well (so that if an account is marked as admin on the IDP, it’ll also be the admin for Forgejo or my Matrix server). So it’d be nice to settle on a plan right now.

Thanks for any responses!

  • AllYourSmurf@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    17 hours ago

    Separate admin accounts is a good idea. It can be overdone. For example, you might decide you need one account for proxmox admin, one for network devices, a third for your IAM stack and a fourth for apps. I personally think that’s too much.

    Every human admin needs a separate admin account. If you’re using AI, each agent needs its own privileged access too.

    I recommend having as few privileged accounts as is reasonable. It might make sense to separate network admin from the rest, for example, or some other separation. But it might be fine in your case to have one master-admin account.

    Getting the mapping right is the hard part. Most IdP-aware apps have some way to map roles, groups, or whatever privilege management they use.