-
Notifications
You must be signed in to change notification settings - Fork 268
feat(iam): change iam doc structure #5980
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
f5ac040
9564624
76a1926
257ce9d
6c5e478
86f22f6
6f90220
66bfe5b
974fbec
d0b80ce
d09c353
3ef1fcd
4844a4c
e254218
8553de1
811f091
54bd499
3bc2a1f
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,53 @@ | ||||||||||
| --- | ||||||||||
| title: Organizations Security - Concepts | ||||||||||
| description: This page explains all the concepts related to Organizations Security | ||||||||||
| tags: authentication saml security | ||||||||||
| dates: | ||||||||||
| validation: 2025-12-18 | ||||||||||
| --- | ||||||||||
|
|
||||||||||
| ## Alias | ||||||||||
|
|
||||||||||
| Each [Organization](#organization) can have an alias set up by an Organization Manager. Once set-up, all members can log in using a dedicated URL for the Organization using the alias, under the format [alias].account.scaleway.com | ||||||||||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||||||
|
|
||||||||||
| ## API key | ||||||||||
|
|
||||||||||
| An API key is a unique identifier, used to authenticate requests made to the [Scaleway API](https://www.scaleway.com/en/developers/api/). An API key consists of an access key and a secret key. The access key is like a unique ID or username, and is not a sensitive piece of information. The secret key is more sensitive as it is like a password to authenticate the access key. | ||||||||||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Just to check, you think it's best to have the API key concept both here and also in the IAM Concepts page? |
||||||||||
|
|
||||||||||
| API keys can have a validity duration defined by its creator. The maximum validity duration can also be enforced by an IAM administrator. | ||||||||||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I hope I understood correctly what the IAM administrator can do in terms of enforcing duration for an Orga? |
||||||||||
|
|
||||||||||
| ## Console session | ||||||||||
|
|
||||||||||
| A console session is an active, authenticated user session that allows interaction with the [Scaleway console](/account/concepts/#console). Console sessions duration can be limited by an [IAM administrator](#iam-administator). | ||||||||||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||||||
|
|
||||||||||
| ## Grace period | ||||||||||
|
|
||||||||||
| The grace period is the time an [IAM Member](#members) has to comply with the security requirements that are enforced in your Organization before their account is automatically locked. The accounts can be manually unlocked by an Owner or [IAM Manager](#iam-manager). Upon regaining access, the grace period resets, giving IAM Members another chance to meet security requirements. | ||||||||||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. We need to consistently capitalize member (or not) throughout the doc, at the moment capitalization is inconsistent. To check. |
||||||||||
|
|
||||||||||
| ## IAM manager | ||||||||||
|
|
||||||||||
| An IAM manager can be the Owner of the Organization, or any IAM member with permission sets enabling them to perform administrative actions in the Organization, such as managing members or enforcing Security Requierements. | ||||||||||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||||||
|
|
||||||||||
|
|
||||||||||
| ## Identity Provider | ||||||||||
|
|
||||||||||
| An Identity Provider (IdP) is a service that authenticates users and provides identity information to Scaleway to enable secure access through [Single Sign-On (SSO)](#single-sign-on) | ||||||||||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||||||
|
|
||||||||||
|
|
||||||||||
| ## Multi-Factor Authentication (MFA) | ||||||||||
|
|
||||||||||
| Multi-factor authentication (MFA) is a security method that requires users to verify their identity using two or more independent factors, such as something they know, have, or are, before logging into an [Organization](/organizations-and-projects/concepts/#organization). | ||||||||||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Maybe we should link to the existing concept in Account as well, which provides more information. |
||||||||||
|
|
||||||||||
| ## SAML | ||||||||||
|
|
||||||||||
| Security Assertion Markup Language (SAML) is a standard protocol that enables secure authentication by exchanging identity and authorization data between an identity provider and a service provider. | ||||||||||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||||||
|
|
||||||||||
| ## Security requirements | ||||||||||
|
|
||||||||||
| Security requirements are a set of actions that must be underdone by all members of an Organization to be compliant with its security standards. Security requirements can be enforced by an [IAM manager](#iam-manager). | ||||||||||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||||||
|
|
||||||||||
| ## Single Sign On | ||||||||||
|
|
||||||||||
| Single sign-on (SSO) allows users to access multiple applications - including Scaleway - with one set of login credentials through a centralized authentication system. | ||||||||||
|
|
||||||||||
|
|
||||||||||
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
| @@ -0,0 +1,32 @@ | ||||||
| --- | ||||||
| title: Organization Security Documentation | ||||||
| description: Dive into Scaleway Organization security with our concepts and how-tos. | ||||||
| --- | ||||||
|
|
||||||
| <ProductHeader | ||||||
| productName="Organization Security" | ||||||
| productLogo="iam" | ||||||
| description="Learn the measures you can undertake to secure access to the Organization." | ||||||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||
| url="/organizations-security/concepts/" | ||||||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Change links to Quickstart, for conformity |
||||||
| label="Organization Security Concepts" | ||||||
| /> | ||||||
|
|
||||||
| ## Getting Started | ||||||
|
|
||||||
| <Grid> | ||||||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Add Quickstart and FAQ |
||||||
| <SummaryCard | ||||||
| title="Concepts" | ||||||
| icon="info" | ||||||
| description="Core concepts that give you a better understanding of Organization security" | ||||||
| label="View Concepts" | ||||||
| url="/organization-security/concepts/" | ||||||
| /> | ||||||
| <SummaryCard | ||||||
| title="How-Tos" | ||||||
| icon="help-circle-outline" | ||||||
| description="Learn how to manage your Organization security via the Scaleway console." | ||||||
| label="View How-Tos" | ||||||
| url="/organization-security/how-to/" | ||||||
| /> | ||||||
| </Grid> | ||||||
|
|
||||||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Usually we also have a Changelog widget on the Overview page, which suggests we should also create a new Changelog category here? |
||||||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Need to replace links towards this anchor with the new URL (find in "/pages" /iam/concepts/#grace-period replace with /organization-security/concepts/#grace-period
Possible also check for links from the console