Okta

Configure SAML 2.0 for Pulumi Cloud

This guide provides instructions on configuring SAML 2.0 Single Sign-On (SSO) for the Pulumi Cloud app.

Contents


Supported features

Pulumi Cloud supports the following features:

Prerequisites

Integrate the app in Okta

Retrieve your organization name from Pulumi Cloud

  1. Sign in to Pulumi Cloud.
  2. Note your organization name. Your organization name appears in the URL in the format https://app.pulumi.com/<orgName>, or on the Organization page.

Configure the app in Okta

  1. In the Admin Console, go to Applications and Resources > Applications (or Applications > Applications in Okta Classic Engine).
  2. Click Browse App Catalog.
  3. Search for and select the Pulumi Cloud app.
  4. Click Add Integration.
  5. On the General Settings tab, in the Organization Name field, enter the organization name you noted earlier. Click Done.
  6. On the Sign On tab, in the SAML Setup section, click the Identity Provider metadata link.
  7. Copy the XML metadata file. This file contains the certificates and endpoints that Pulumi Cloud needs to establish trust with Okta.
  8. Go to the Assignments tab. Click Assign > Assign to People (or Assign to Groups).
  9. Select the users or groups who need access.
  10. Click Save and Go Back, and then click Done.

Configure SAML in Pulumi Cloud

  1. Sign in to Pulumi Cloud.
  2. Go to Settings > Access Management.
  3. Go to the Other tab.
  4. In the Membership Requirements section, click Change requirements.
  5. Select SAML SSO, and then click Next.
  6. Paste the XML metadata file you copied earlier into the text area.
  7. Click Apply changes.

The following SAML attributes are supported:

Attribute Value
firstName user.firstName
lastName user.lastName
email user.email

Verify SP-initiated SSO

Go to https://app.pulumi.com/signin/sso/. Enter your Pulumi Cloud organization name, using the same name you entered during the Okta configuration. Click Submit. You're redirected to the sign-in page for your org. Enter your Okta credentials. You're signed in to your Pulumi Cloud dashboard.