Hi all. I’ve been wondering about account separations while reviewing my SSO stuff. Do you all create a separate account for administrative tasks for your services? Or do you just give your normal account admin rights?

In my opinion, a different account is nice to separate impactful admin work (like provisioning users and groups) from general usage. Having this UX “barrier” also somewhat prevents doing dumb things like accidentally deactivating other people’s accounts. But the downside is it can be quite inconvenient, especially if I need to administer or debug something quickly. I’m also not sure if my homelab expands, should I share the admin user credentials with other human admins or not.

What’s the best topology to use? Or is there some other “accounts structure” that I’ve missed? I’m looking to replicate the same mapping between my identity provider and all dependent services as well (so that if an account is marked as admin on the IDP, it’ll also be the admin for Forgejo or my Matrix server). So it’d be nice to settle on a plan right now.

Thanks for any responses!

  • Brickfrog@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    3
    ·
    9 hours ago

    I’m definitely in the thinking with others that keep admin/privileged and normal users separate. I kind of look at it as a way to minimize fallout from any unexpected security compromises. Will always do my best to prevent/avoid that, but if it happens it better happen on a non-privileged account.

    But the downside is it can be quite inconvenient, especially if I need to administer or debug something quickly.

    A bit, but I don’t find that to be too cumbersome. The initial setup period yeah, you’re constantly jumping into admin mode, but once things are configured and settled down you hopefully don’t need to jump into admin mode often.

    I’m also not sure if my homelab expands, should I share the admin user credentials with other human admins or not.

    That’s a fair question and it depends on the service(s) really. I don’t know what the general consensus is on that but I’d say that other admins should have their own separate admin account and user account (e.g. call it “joe” and “joe_admin” or whatever). Sharing credentials, especially admin credentials, seems like its own security risk. But I also get that sometimes it’s simply not possible to maintain multiple admin accounts and you just have to do the best you can.