Skip to main content

Identity

One controlled front door to UNIQCloud. Identity decides who can reach the platform, which project they are acting in, and what they are allowed to do once they are there.


Information​

Identity is the service every other component depends on. It holds the projects that act as the boundary for resources, quotas, and billing; the users — human and machine — that are allowed into them; and the roles that determine what each user can do.

For an organisation, this is what makes shared infrastructure safe to share. Corporate identities stay in the organisation's directory, so joiners and leavers are handled once, in one place. Automation gets its own credentials rather than borrowing a person's. And because a project is the unit of separation, a team, an environment, or a regulated workload can be isolated from everything else without needing separate infrastructure.

Corporate single sign-on

People sign in with their organisation account through SSO. There is no separate password to issue, rotate, or revoke when someone changes role or leaves.

Separate identities for automation

Pipelines and tooling authenticate as a project service user with scoped application credentials, so machine access is never tied to an individual's account.

The project is the boundary

Resources, quotas, network space, and cost all belong to a project. Access granted in one project carries no rights in another.

Reachable only from the inside

UNIQCloud is accessible from the internal network or over the Zero Trust Access. The management plane is not exposed to the public Internet.


Account types​

Every user reaching UNIQCloud does so as one of two account types. They are not alternatives to choose between once: most teams use both — SSO accounts for people, and a service user for the automation that runs on the team's behalf.

Characteristic
SSO user
Local / service user
Intended forPeopleAutomation, tooling, programmatic access
Authenticates withCorporate credentials via SSOOpenStack username and password
Managed atOrganisation directory levelProject level — one per project
Dashboard accessYesYes
Application credentialsNot applicableOne per purpose — pipeline, Terraform, runner
Leaver handlingAutomatic — follows the directory accountNot tied to any individual; stays with the project
Network requirementInternal network or Zero Trust Access.

Usage​