Use of authentication.oidc.groups_claim ? RBAC rules based on external group membership?

Description

Running a self-hosted Weaviate on an on-prem k8s cluster in a corporate environment. I am trying to understand options for configuring RBAC in Weaviate.

I currently have authentication via OIDC working, using my company’s PingFederate IdP. Part of the JWT provided by the IdP is a field called memberOf. This is a list of all of the Active Directory groups that the authenticated person is a member of.

In my Helm values.yaml file, I set the authentication.oidc.groups_claim to memberOf.

Is there a way for Weaviate to use these “external” group memberships to build RBAC roles / permissions? I see in the docs and tutorial information on what is essentially internally managed groups.

But is there a way to use externally-supplied group membership of the authenticated OIDC user in some way?

If not, what is the purpose of authentication.oidc.groups_claim in the Helm chart? I have not seen much, if any, documentation on the purpose and usage of this field.

Just trying to understand options.

Server Setup Information

  • Weaviate Server Version: 1.31.4
  • Deployment Method: k8s
  • Multi Node? Number of Running Nodes: 1
  • Client Language and Version: Python 3.12.4, weaviate-client==4.15.0
  • Multitenancy?: no

Any additional Information

Self-hosted / BYOC / on-prem RKE2 kubernetes cluster

hi @tpanza !!

Welcome to our community :hugs:

AFAIK, you need to set authentication.oidc.groups_claim according to your JWT and then create those roles with the same name in Weaviate.

Let me know if this works out for you!

THanks!

thanks @DudaNogueira . I’ll try it, but a worked example would be very helpful. I’m a little unclear on what “create roles with same name in Weaviate” entails.

Hello @tpanza,

support for groups is there, but it is a bit hidden right now because it is not finished.

You can do:

Thanks @Dirk ! Would you know an approximate schedule for groups being finished?

Probably during the 1.33 cycle but I cannot promise it

That’s something I was wondering about as well. From reading the documentation, it seems like Weaviate’s RBAC is primarily based on roles managed within Weaviate itself, but it’s not entirely clear how groups_claim fits into that model.

If the OIDC token already includes group memberships (such as memberOf from Active Directory), it would be very useful if those could be mapped directly to Weaviate roles instead of maintaining a separate set of groups internally.

If that isn’t currently supported, could someone clarify what authentication.oidc.groups_claim is actually used for? The Helm chart exposes the option, but I haven’t found much documentation explaining its purpose or whether it’s intended for future RBAC integration or another feature.

We have full support for role/user management via OIDC.

Whatever you set as group claim via environment variable will be part of your principal as group membership. You can assign roles to groups with `client.groups.oidc.assign_roles(…)`. Use `client.users.get_my_user()` to check if everything works.

There is not much documentation around, but you can have a look at the tests here: weaviate-python-client/integration/test_groups.py at main · weaviate/weaviate-python-client · GitHub