Hi all. I’ve been wondering about account separations while reviewing my SSO stuff. Do you all create a separate account for administrative tasks for your services? Or do you just give your normal account admin rights?

In my opinion, a different account is nice to separate impactful admin work (like provisioning users and groups) from general usage. Having this UX “barrier” also somewhat prevents doing dumb things like accidentally deactivating other people’s accounts. But the downside is it can be quite inconvenient, especially if I need to administer or debug something quickly. I’m also not sure if my homelab expands, should I share the admin user credentials with other human admins or not.

What’s the best topology to use? Or is there some other “accounts structure” that I’ve missed? I’m looking to replicate the same mapping between my identity provider and all dependent services as well (so that if an account is marked as admin on the IDP, it’ll also be the admin for Forgejo or my Matrix server). So it’d be nice to settle on a plan right now.

Thanks for any responses!

  • Lem453@lemmy.ca
    link
    fedilink
    English
    arrow-up
    4
    ·
    5 hours ago

    Keep your personal account separate from the admin. Don’t even think of making other users admin on a self hosted server.

    If you need to login, open a private tab in your browser and use a password manager to quickly login with admin credentials.

  • non_burglar@lemmy.world
    link
    fedilink
    English
    arrow-up
    14
    ·
    7 hours ago

    I have been in IT for 30 years, and in security for the last 16.

    You’ll find lots of arguments from a productivity and removing barriers point of view that say don’t bother with strict user access controls, just layer on other security measures. Others (usually older-school sysadmins) preach “doing the work”, meaning secure your users well and audit access often. There are advantages and disadvantages to both approaches.

    I personally do a bit of both. The old way of being meticulous with access works, but not without diligence and self-audit. The newer devops way if doing things with secrets management and treating everyone as untrusted works too, as long as you document the automation.

    Maybe one suggestion about user control in a homelab setting is not to use the same username across multiple services, but rather name your users something like name.of.service.admin so that you a) don’t forget where you are and b) if you start collecting logs centrally, you can easily identify which system the logs came from.

  • frongt@lemmy.zip
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    6 hours ago

    I certainly wouldn’t give people admin. Too much risk of them accidentally breaking stuff.

  • gastroglizzy@piefed.social
    link
    fedilink
    English
    arrow-up
    5
    ·
    7 hours ago

    In general, shared accounts/credentials aren’t recommended; each user should have their own account. Even in a homelab setting, the audit trail may prove useful in ways that are difficult to foresee.

    In general, separation of privileges is recommended. However, the granularity should be informed by the risks mitigated. In an enterprise setting, more risks are generally mitigated by more granularity. In a homelab setting, there are diminishing returns. A risk assessment will determine the appropriate configuration in your environment, but in general, if the scope or severity of an incident wouldn’t be substantially lessened, it is better to accept the risk than to mitigate it.

  • AllYourSmurf@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    7 hours ago

    Separate admin accounts is a good idea. It can be overdone. For example, you might decide you need one account for proxmox admin, one for network devices, a third for your IAM stack and a fourth for apps. I personally think that’s too much.

    Every human admin needs a separate admin account. If you’re using AI, each agent needs its own privileged access too.

    I recommend having as few privileged accounts as is reasonable. It might make sense to separate network admin from the rest, for example, or some other separation. But it might be fine in your case to have one master-admin account.

    Getting the mapping right is the hard part. Most IdP-aware apps have some way to map roles, groups, or whatever privilege management they use.

  • Brickfrog@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    3
    ·
    6 hours ago

    I’m definitely in the thinking with others that keep admin/privileged and normal users separate. I kind of look at it as a way to minimize fallout from any unexpected security compromises. Will always do my best to prevent/avoid that, but if it happens it better happen on a non-privileged account.

    But the downside is it can be quite inconvenient, especially if I need to administer or debug something quickly.

    A bit, but I don’t find that to be too cumbersome. The initial setup period yeah, you’re constantly jumping into admin mode, but once things are configured and settled down you hopefully don’t need to jump into admin mode often.

    I’m also not sure if my homelab expands, should I share the admin user credentials with other human admins or not.

    That’s a fair question and it depends on the service(s) really. I don’t know what the general consensus is on that but I’d say that other admins should have their own separate admin account and user account (e.g. call it “joe” and “joe_admin” or whatever). Sharing credentials, especially admin credentials, seems like its own security risk. But I also get that sometimes it’s simply not possible to maintain multiple admin accounts and you just have to do the best you can.

  • glizzyguzzler@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    5
    ·
    7 hours ago

    I have an admin account on the server and an SSO admin login for the services. Different credentials obviously - ones an SSH key and ones a password/passkey for SSO - but it seems to fit well. My regular account is bozo level and I don’t need to worry much, I just logout or go to a private window to do admin for an specific program, which is rare but easy enough when it’s needed.

    So far for the SSO services with an admin account design, I just set it up so the admin account for the service is named the SSO admin account so it maps directly when I connect the SSO to it.

    And I SSH into the server for admin there as needed.

    And no mixing with my regular user account!