Terraform Cloud SSO user/team mappings from via SAML / Google Workspace aren't working.
sengi opened this issue · 2 comments
sengi commented
We have Terrform Cloud hooked up to Google Workspace for single-sign-on, but it isn’t assigning groups to people correctly. Pretty sure it used to work back when we first started using TFC.
This means we’re having to manually assign groups as people request them, which is toil (and raises the chance of mistakes).
dj-maisy commented
Is this because people aren't authenticating via SSO once they've got an account, or is this because the groups only sync on initial account creation?
sengi commented
TFC definitely is supposed to require all users except org owners to authn via SSO in order to access projects owned by the org, so I don't think it's the first one. Perhaps the second one? (I haven't looked into it myself.)