ChaosSearch offers strong security controls with built-in interfaces and APIs to manage users and to define their roles (access) to features and information. ChaosSearch also supports connectors and single sign on (SSO) integrations with an identity provider (IdP) such as Auth0, Okta, Google, and others to authenticate and authorize user access to the interface, features, and customer data. The following topics describe the authentication and authorization methods in ChaosSearch.
The ChaosSearch login page highlights the types of supported user authentication services. Each ChaosSearch deployment has a primary user (also called tenant or root account), which is essentially the owner/superuser associated with the ChaosSearch setup and deployment. The primary user can perform all the important administration and related tasks for their environment. To access ChaosSearch, tenant users browse to the login page, type their email, password, and click Sign In.
The tenant account is typically used by the primary customer administrators who need all of the permissions and access. Tenant users can create accounts for end users—called subaccount users—to enable users to perform other common tasks such as managing object groups, Refinery® views, Kibana visualizations, and other tasks.
Subaccount users must specify their email, password, and also the Account ID of the tenant to which they are connecting and then click Sign In to authenticate. A subaccount can be associated with one or more tenants, so the tenant ID must be supplied as part of the login.
Local Accounts and SSO
Customers who have a configured identity provider (IdP) for authenticating their users in a single sign-on environment often prefer to use their IdP to authenticate their users. During setup planning, customers can work with Customer Success to configure one or more SSO connectors for their ChaosSearch access. Clicking Single Sign On on the login page redirects the user to the configured SSO authentication connector, which is described in more detail in Single Sign-On.
Updated 4 months ago