Running a self-hosted Weaviate on an on-prem k8s cluster in a corporate environment. I am trying to understand options for configuring RBAC in Weaviate.
I currently have authentication via OIDC working, using my company’s PingFederate IdP. Part of the JWT provided by the IdP is a field called memberOf. This is a list of all of the Active Directory groups that the authenticated person is a member of.
In my Helm values.yaml file, I set the authentication.oidc.groups_claim to memberOf.
Is there a way for Weaviate to use these “external” group memberships to build RBAC roles / permissions? I see in the docs and tutorial information on what is essentially internally managed groups.
But is there a way to use externally-supplied group membership of the authenticated OIDC user in some way?
If not, what is the purpose of authentication.oidc.groups_claim in the Helm chart? I have not seen much, if any, documentation on the purpose and usage of this field.
Just trying to understand options.
Server Setup Information
Weaviate Server Version: 1.31.4
Deployment Method: k8s
Multi Node? Number of Running Nodes: 1
Client Language and Version: Python 3.12.4, weaviate-client==4.15.0
thanks @DudaNogueira . I’ll try it, but a worked example would be very helpful. I’m a little unclear on what “create roles with same name in Weaviate” entails.
That’s something I was wondering about as well. From reading the documentation, it seems like Weaviate’s RBAC is primarily based on roles managed within Weaviate itself, but it’s not entirely clear how groups_claim fits into that model.
If the OIDC token already includes group memberships (such as memberOf from Active Directory), it would be very useful if those could be mapped directly to Weaviate roles instead of maintaining a separate set of groups internally.
If that isn’t currently supported, could someone clarify what authentication.oidc.groups_claim is actually used for? The Helm chart exposes the option, but I haven’t found much documentation explaining its purpose or whether it’s intended for future RBAC integration or another feature.
We have full support for role/user management via OIDC.
Whatever you set as group claim via environment variable will be part of your principal as group membership. You can assign roles to groups with `client.groups.oidc.assign_roles(…)`. Use `client.users.get_my_user()` to check if everything works.