Identity
One controlled front door to UNIQCloud. Identity decides who can reach the platform, which project they are acting in, and what they are allowed to do once they are there.
Information
Identity is the service every other component depends on. It holds the projects that act as the boundary for resources, quotas, and billing; the users — human and machine — that are allowed into them; and the roles that determine what each user can do.
For an organisation, this is what makes shared infrastructure safe to share. Corporate identities stay in the organisation's directory, so joiners and leavers are handled once, in one place. Automation gets its own credentials rather than borrowing a person's. And because a project is the unit of separation, a team, an environment, or a regulated workload can be isolated from everything else without needing separate infrastructure.
Corporate single sign-on
People sign in with their organisation account through SSO. There is no separate password to issue, rotate, or revoke when someone changes role or leaves.
Separate identities for automation
Pipelines and tooling authenticate as a project service user with scoped application credentials, so machine access is never tied to an individual's account.
The project is the boundary
Resources, quotas, network space, and cost all belong to a project. Access granted in one project carries no rights in another.
Reachable only from the inside
UNIQCloud is accessible from the internal network or over the Zero Trust Access. The management plane is not exposed to the public Internet.
Account types
Every user reaching UNIQCloud does so as one of two account types. They are not alternatives to choose between once: most teams use both — SSO accounts for people, and a service user for the automation that runs on the team's behalf.
| Characteristic | SSO user | Local / service user |
|---|---|---|
| Intended for | People | Automation, tooling, programmatic access |
| Authenticates with | Corporate credentials via SSO | OpenStack username and password |
| Managed at | Organisation directory level | Project level — one per project |
| Dashboard access | Yes | Yes |
| Application credentials | Not applicable | One per purpose — pipeline, Terraform, runner |
| Leaver handling | Automatic — follows the directory account | Not tied to any individual; stays with the project |
| Network requirement | Internal network or Zero Trust Access. | |