🔖 Feature description
Hi Devtron team,
We are using Keycloak as our SSO provider (OIDC) with Devtron.
Currently, users must be manually created in Devtron before they can log in via SSO, and users removed from Keycloak remain in Devtron.
This makes user lifecycle management difficult and does not align with standard enterprise SSO behavior.
🎤 Pitch / Usecases
Expected / Standard Behavior
In platforms like Rancher, Argo CD, GitLab, Grafana, etc.:
- Users are automatically created on first successful SSO login (Just-In-Time provisioning)
- IdP groups can be mapped to platform roles
- Users are automatically deprovisioned when removed from the IdP
- The IdP is the single source of truth for identity lifecycle
Current Behavior in Devtron
- Users must be created manually (or via custom automation)
- No JIT provisioning for OIDC/Keycloak
- No automatic deprovisioning
- Requires external sync service using Devtron APIs
Request
Please consider adding:
- JIT user creation on first SSO login (OIDC/Keycloak)
- Group → role mapping (Keycloak groups → Devtron role groups)
- Documentation & examples for enterprise SSO lifecycle management
- If possible: Rely on IdP as the source of truth so users removed from the IdP can no longer authenticate, without requiring manual local cleanup
This is a standard enterprise requirement and would significantly improve Devtron’s SSO integration.
Thank you!
🔄️ Alternative
No response
👀 Have you spent some time to check if this issue has been raised before?
🏢 Have you read the Code of Conduct?
🔖 Feature description
Hi Devtron team,
We are using Keycloak as our SSO provider (OIDC) with Devtron.
Currently, users must be manually created in Devtron before they can log in via SSO, and users removed from Keycloak remain in Devtron.
This makes user lifecycle management difficult and does not align with standard enterprise SSO behavior.
🎤 Pitch / Usecases
Expected / Standard Behavior
In platforms like Rancher, Argo CD, GitLab, Grafana, etc.:
Current Behavior in Devtron
Request
Please consider adding:
This is a standard enterprise requirement and would significantly improve Devtron’s SSO integration.
Thank you!
🔄️ Alternative
No response
👀 Have you spent some time to check if this issue has been raised before?
🏢 Have you read the Code of Conduct?