Configure SAML 2.0 for Pulumi Cloud
This guide provides instructions on configuring SAML 2.0 Single Sign-On (SSO) for the Pulumi Cloud app.
Contents
Supported features
Pulumi Cloud supports the following features:
- SP-initiated SSO: Users can sign in directly from the Pulumi Cloud sign-in page.
- Just-In-Time (JIT) provisioning: Okta creates a new Pulumi Cloud account the first time a user signs in through SAML, provided the user's email isn't already associated with an existing Pulumi Cloud account.
Prerequisites
- You have an Okta admin role with permission to manage apps.
- You have admin access to your Pulumi Cloud org.
Integrate the app in Okta
Retrieve your organization name from Pulumi Cloud
- Sign in to Pulumi Cloud.
- Note your organization name. Your organization name appears in the URL in the format
https://app.pulumi.com/<orgName>, or on the Organization page.
Configure the app in Okta
- In the Admin Console, go to Applications and Resources > Applications (or Applications > Applications in Okta Classic Engine).
- Click Browse App Catalog.
- Search for and select the Pulumi Cloud app.
- Click Add Integration.
- On the General Settings tab, in the Organization Name field, enter the organization name you noted earlier. Click Done.
- On the Sign On tab, in the SAML Setup section, click the Identity Provider metadata link.
- Copy the XML metadata file. This file contains the certificates and endpoints that Pulumi Cloud needs to establish trust with Okta.
- Go to the Assignments tab. Click Assign > Assign to People (or Assign to Groups).
- Select the users or groups who need access.
- Click Save and Go Back, and then click Done.
Configure SAML in Pulumi Cloud
- Sign in to Pulumi Cloud.
- Go to Settings > Access Management.
- Go to the Other tab.
- In the Membership Requirements section, click Change requirements.
- Select SAML SSO, and then click Next.
- Paste the XML metadata file you copied earlier into the text area.
- Click Apply changes.
The following SAML attributes are supported:
| Attribute |
Value |
| firstName |
user.firstName |
| lastName |
user.lastName |
| email |
user.email |
Verify SP-initiated SSO
Go to https://app.pulumi.com/signin/sso/. Enter your Pulumi Cloud organization name, using the same name you entered during the Okta configuration. Click Submit. You're redirected to the sign-in page for your org. Enter your Okta credentials. You're signed in to your Pulumi Cloud dashboard.