Hi all. I’ve been wondering about account separations while reviewing my SSO stuff. Do you all create a separate account for administrative tasks for your services? Or do you just give your normal account admin rights?

In my opinion, a different account is nice to separate impactful admin work (like provisioning users and groups) from general usage. Having this UX “barrier” also somewhat prevents doing dumb things like accidentally deactivating other people’s accounts. But the downside is it can be quite inconvenient, especially if I need to administer or debug something quickly. I’m also not sure if my homelab expands, should I share the admin user credentials with other human admins or not.

What’s the best topology to use? Or is there some other “accounts structure” that I’ve missed? I’m looking to replicate the same mapping between my identity provider and all dependent services as well (so that if an account is marked as admin on the IDP, it’ll also be the admin for Forgejo or my Matrix server). So it’d be nice to settle on a plan right now.

Thanks for any responses!

  • greybeard@feddit.online
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 hours ago

    I think most of the comments misunderstood you, or I did.

    Keeping a dedicated admin separate from your daily use user is best practice. In a business setting it is a critical security line, and also seriously helps with auditing and logging. It makes sure that if my computer gets compromised, the active cookies and session tokens are all a standard user. It’s not fool proof, but it really reduces risk.

    That said, in my home lab, I don’t bother with that separation. It’s far more work than the effort justifies, when the worst result of your systems being compromised is your media library not being available. What you will want, in any case, is a “break glass” account into every system you setup to use SSO. A local administrator that isn’t tied to SSO available in case your IDP is down, certificates expire, or you accidentally paint yourself into a corner (and you will).

    I recommend, if you don’t already, using a password manager like BitWarden and having every single local admin be a long, randomly generated password.