Learn how to integrate Vultr Single Sign-On with Okta, creating an OIDC app integration in Okta and connecting it to your Vultr organization's SSO settings.
Okta is an identity provider that authenticates your users and manages their lifecycle from a central directory. Connecting Okta to Vultr combines two features. Single Sign-On (SSO) through OpenID Connect (OIDC) lets your team sign in to Vultr with Okta, and System for Cross-domain Identity Management (SCIM) provisioning automatically creates, updates, and deactivates Vultr users and groups from Okta.
Follow this guide to connect Okta to Vultr for SSO and SCIM provisioning using the Vultr Console and the Okta Admin Console.
Keep at least one Vultr root user that is not managed by Okta. Okta can never remove, deactivate, or lock out a root user, and a root user can still sign in with a password while SSO is enabled. This is your guaranteed way back in if Okta is ever misconfigured or unavailable. Set it up before you connect Okta.
This guide requires access to the Vultr Console as a root user of your organization, administrator access to an Okta organization, and, if you plan to enable SCIM using the Vultr API instead of the Console, a Vultr API key.
SSO and SCIM work together, so the order matters. Configure the SSO connection first, then enable and configure SCIM, then provision a user, and test the login last. SSO controls how people sign in, but it can sign in only users that already exist in Vultr, and SCIM is what creates them. Configure both features before you verify a sign-in, because a provisioned user has no password and cannot log in until SSO works.
The two features also use opposite configuration directions:
A user created by SCIM has no Vultr password and signs in through Okta only. Because SSO can sign in only users that already exist in Vultr, test the login after you provision a user, not before. A login attempt before the user exists fails with an Invalid email address error.
Single Sign-On lets your Vultr users authenticate with Okta. You create an OIDC application in Okta and enter its details in your Vultr organization's Single Sign-On settings.
Log in to the Okta Admin Console.
In the left navigation, click Applications, then click Applications.
Click Create App Integration.
Select OIDC - OpenID Connect as the sign-in method, select Web Application as the application type, then click Next.
Enter a descriptive name such as Vultr SSO in the App integration name field.
Enter https://console.vultr.com/openid/ in the Sign-in redirect URIs and Sign-out redirect URIs fields.
The redirect URI must match exactly, including the trailing slash. A mismatch is the most common cause of login errors.
Under Assignments, choose who can access the application, then click Save.
On the application's General tab, copy the Client ID and Client Secret, and note your Okta issuer or discovery URL for the next step.
Log in to the Vultr Console.
Click the organization name in the top navigation bar.
Click Manage Organization.
Click Federated Identity under Identity and Access Management in the left sidebar.
Under Single Sign-On, click Enable. The Enable Single Sign-On panel opens on the right.
Enter the Provider URL (the Okta issuer or discovery URL), the Client ID, and the Client Secret from Okta.
Click Enable SSO.
The Single Sign-On card displays your Provider URL and Client ID, and Status shows Active, which confirms the connection is configured.
SCIM provisioning lets Okta manage the Vultr user and group lifecycle automatically. You enable SCIM in Vultr to generate an authentication token, then add a SCIM application in Okta and connect it to the Vultr SCIM endpoint.
Only a root user can enable SCIM for an organization.
Log in to the Vultr Console.
Click the organization name in the top navigation bar.
Click Manage Organization.
Click Federated Identity under Identity and Access Management in the left sidebar.
Under System for Cross-domain Identity Management (SCIM), click Enable.
The SCIM Status changes to Enabled, and the card displays the SCIM Base URL and a generated SCIM Token.
Note the following values to enter in Okta:
https://api.vultr.com/scim/v2You can also enable SCIM using the Vultr API. See How to Enable SCIM for an Organization.
Okta provisions through a dedicated SCIM application, separate from the SSO application. Add a SCIM application from the Okta catalog and connect it to the Vultr SCIM endpoint.
In the Okta Admin Console, click Applications, click Browse App Catalog, then search for and select SCIM 2.0 Test App (OAuth Bearer Token).
Click Add Integration, enter an application label such as Vultr SCIM, then complete the wizard. This application handles provisioning only, so continue past the sign-on options.
Open the Provisioning tab, click Configure API Integration, then select Enable API integration.
Enter the Base URL https://api.vultr.com/scim/v2, then paste the SCIM token as the API Token.
Click Test API Credentials to confirm the connection, then click Save.
Under To App, click Edit, enable Create Users, Update User Attributes, and Deactivate Users, then click Save.
The Vultr SCIM application is now connected and ready to provision users and groups.
On the Vultr SCIM application, open the Assignments tab and assign the users or groups you want to provision.
Open the Push Groups tab and push each Okta group to mirror it into Vultr and keep its membership in sync.
Provisioning is now live. Adding a person to a pushed group in Okta creates or links them in Vultr, and removing them takes their access away.
How SCIM handles an assigned user depends on the email address:
Email is already in use error. Invite that user to your organization and have them accept the invitation first.Users assigned to the application, and members of groups assigned to it, can now sign in to the Vultr Console with SSO. Test the login with a user that SCIM has provisioned.
Open a fresh or incognito browser window and go to the Vultr Console.
Click SSO in the login options.
Enter the email address of a user to which the Vultr SCIM application is assigned, then click Continue.
The Vultr Console redirects you to Okta for authentication.
Authenticate with the Okta user account.
Okta redirects you back and signs you in to the Vultr Console. Vultr verifies that the user Okta returns matches the email address you entered. If your browser is already signed in to Okta as a different person, the login is rejected, so use an incognito window signed in as the intended user. A successful sign-in confirms the integration is complete.
Okta decides who is in a group, and Vultr decides what that group can do. In Okta, you control group membership. In Vultr, you attach roles and permission policies to those groups to define what members can do, such as managing servers or viewing billing.
The recommended model is to assign permissions to groups in Vultr and add or remove people from those groups in Okta. You grant access by adding someone to a group in Okta, and you revoke it by removing them.
After Okta and Vultr are connected, routine changes in Okta drive the matching changes in Vultr.
Root users are exempt from this flow. Okta cannot remove, deactivate, or lock out a root user, and a root user can still sign in with a password while SSO is enabled.
Disabling SCIM does not delete anything. All users, groups, and memberships stay exactly as they are, and no access is revoked. The only change is that SCIM-managed records become editable in the Vultr Console again, because the identity provider lock lifts. If you move off Okta, plan to manually clean up or hand-manage those users and groups afterward.
Use these fixes for the most common errors.
https://console.vultr.com/openid/, including the trailing slash.https://api.vultr.com/scim/v2, not the Console address.Error: Unlink the group, click Refresh App Groups, then push it again instead of retrying.Email is already in use: The email address already belongs to a Vultr user. Invite that user to your organization and have them accept the invitation, then provision the email address again.
0 Comments
Be the first to comment and share your perspective with the community.