Part of the Ultramarine Server roadmap (Outline: Server):
dashboard has integrated SSO for apps — see what apps we can define oauth through quadlets (nextcloud, portainer, that kinda thing)
Goal
Every UM server acts as its own OAuth/OIDC endpoint, so apps on the server can offer SSO without depending on a central service. Tetra is the natural home for the endpoint: it runs on the server, holds identity, and already terminates authenticated connections. The dashboard (centrally hosted, or local on the server) manages clients and consumes the metadata.
This issue is part design, part implementation. The exact shape of the endpoint needs settling before code.
Tasks
Dashboard consumer tracked in Ultramarine-Linux/dashboard#7.
Related: #29 (per-app SSO capability surfaces through the apps module).
Part of the Ultramarine Server roadmap (Outline: Server):
Goal
Every UM server acts as its own OAuth/OIDC endpoint, so apps on the server can offer SSO without depending on a central service. Tetra is the natural home for the endpoint: it runs on the server, holds identity, and already terminates authenticated connections. The dashboard (centrally hosted, or local on the server) manages clients and consumes the metadata.
This issue is part design, part implementation. The exact shape of the endpoint needs settling before code.
Tasks
recipes.contextso templates can consume it; expose SSO capability per appexamples/docs/recipes.md,docs/agent-protocol.mdDashboard consumer tracked in Ultramarine-Linux/dashboard#7.
Related: #29 (per-app SSO capability surfaces through the apps module).