Hi all. I’ve been wondering about account separations while reviewing my SSO stuff. Do you all create a separate account for administrative tasks for your services? Or do you just give your normal account admin rights?

In my opinion, a different account is nice to separate impactful admin work (like provisioning users and groups) from general usage. Having this UX “barrier” also somewhat prevents doing dumb things like accidentally deactivating other people’s accounts. But the downside is it can be quite inconvenient, especially if I need to administer or debug something quickly. I’m also not sure if my homelab expands, should I share the admin user credentials with other human admins or not.

What’s the best topology to use? Or is there some other “accounts structure” that I’ve missed? I’m looking to replicate the same mapping between my identity provider and all dependent services as well (so that if an account is marked as admin on the IDP, it’ll also be the admin for Forgejo or my Matrix server). So it’d be nice to settle on a plan right now.

Thanks for any responses!

  • non_burglar@lemmy.world
    link
    fedilink
    English
    arrow-up
    15
    ·
    9 hours ago

    I have been in IT for 30 years, and in security for the last 16.

    You’ll find lots of arguments from a productivity and removing barriers point of view that say don’t bother with strict user access controls, just layer on other security measures. Others (usually older-school sysadmins) preach “doing the work”, meaning secure your users well and audit access often. There are advantages and disadvantages to both approaches.

    I personally do a bit of both. The old way of being meticulous with access works, but not without diligence and self-audit. The newer devops way if doing things with secrets management and treating everyone as untrusted works too, as long as you document the automation.

    Maybe one suggestion about user control in a homelab setting is not to use the same username across multiple services, but rather name your users something like name.of.service.admin so that you a) don’t forget where you are and b) if you start collecting logs centrally, you can easily identify which system the logs came from.