Connecter OVHcloud à Lutril
Lutril connects to OVHcloud with a service account, using the OAuth2 client credentials flow, and governs the IAM users of your account: the people who can reach the Manager and the API. It reads every user with the privilege their IAM groups carry, and it time boxes access two ways. A request from somebody with no account creates one, and the deadline disables it; a request from somebody who already has an account adds them to one IAM group for the life of the grant, and the deadline removes that membership and nothing else. OVHcloud users are disabled, never deleted, so a second request to the same person re enables the account they already had.
Accès demandés
- account:apiovh:me/identity/user/* (read the IAM users, create one, enable or disable one)
- account:apiovh:me/identity/group/* (read the groups and their privilege, add or remove a membership)
Étapes de configuration
- 1
Sign in to the OVHcloud Manager as the account holder or an administrator, and open Identity, Security & Operations, then Service accounts. A service account is a machine credential: it does not expire with a person and is not tied to anyone's consumer key.
Create and manage a service account - 2
Create the service account, name it something like Lutril, and copy the client ID and the client secret straight away. OVHcloud shows the secret once and will not display it again.
- 3
Give the service account an IAM policy covering account:apiovh:me/identity/user/* and account:apiovh:me/identity/group/*. Nothing else is needed: Lutril reads your users and groups, creates or enables or disables a user, and adds or removes a group membership. It never touches your services, your billing or your domains.
Use IAM policies with the OVHcloud API - 4
Note the region your OVHcloud account was created in: Europe, Canada or United States. Accounts are not shared between regions and a service account created in one is refused by the others.
- 5
In Lutril, connect OVHcloud, paste the client ID and the client secret, then pick the matching region.
- 6
To time box OVHcloud access, set the access levels on the OVHcloud app in your catalogue to the names of your IAM groups. Those are your own group names, so what somebody requests is exactly the group they are put in. ADMIN, DEFAULT and UNPRIVILEGED are the three OVHcloud ships with, and any group you created yourself works the same way.
Permission groups managed by OVHcloud - 7
Lutril never deletes an OVHcloud user. Deleting one would destroy its personal access tokens and the IAM URN every policy referencing it points at, so a deadline only ever disables an account Lutril created, or removes the one group membership a grant added. Anybody who already held the group they asked for is left exactly as they were.
Où le créer
Documentation officielle
Connectez-vous à Lutril pour brancher OVHcloud, ou réservez une démo et nous le mettons en place avec vous. Sans slides.