Users, roles and single sign-on
CommunityTeamPro

Roles
| Role | May |
|---|---|
VIEWER | read everything: queues, messages (sensitive values hidden), history, audit log, alerts and rules |
OPERATOR | everything a viewer may, plus replay, park, discard, purge, export, publish, notes, replay rules, and showing hidden values of one message |
ADMIN | everything an operator may, plus alert rules and channels, users and the licence |
In Community every user is an admin; roles separate support from on-call in Team and Pro.
Local users
Users (g u) creates accounts, changes roles, disables and re-enables them and resets passwords; everyone can change their own password. Users from the configuration (warren.users, or WARREN_ADMIN_USERNAME and WARREN_ADMIN_PASSWORD) are only created on the first start; after that the UI is in charge.
Single sign-on with OIDC (Pro)
Sign in through Keycloak, Entra ID, Okta or any other OIDC provider, with roles taken from a claim:
warren:
oidc:
enabled: true
issuer-uri: https://login.example.com/realms/platform
client-id: warren
client-secret: ${OIDC_CLIENT_SECRET}
roles-claim: realm_access.roles
role-mapping:
mq-admins: ADMIN
mq-oncall: OPERATOR
default-role: VIEWER
username-claim: preferred_username
Register https://<warren>/login/oauth2/code/oidc as redirect URI at the provider. Local users keep working next to SSO; the login page offers both. Without default-role, users with no mapped role cannot sign in.