Warren
Team and compliance

Users, roles and single sign-on

CommunityTeamPro
Three local users: an admin, an operator and a viewer for support
Three local users: an admin, an operator and a viewer for support

Roles

RoleMay
VIEWERread everything: queues, messages (sensitive values hidden), history, audit log, alerts and rules
OPERATOReverything a viewer may, plus replay, park, discard, purge, export, publish, notes, replay rules, and showing hidden values of one message
ADMINeverything an operator may, plus alert rules and channels, users and the licence

In Community every user is an admin; roles separate support from on-call in Team and Pro.

Local users

Users (g u) creates accounts, changes roles, disables and re-enables them and resets passwords; everyone can change their own password. Users from the configuration (warren.users, or WARREN_ADMIN_USERNAME and WARREN_ADMIN_PASSWORD) are only created on the first start; after that the UI is in charge.

Single sign-on with OIDC (Pro)

Sign in through Keycloak, Entra ID, Okta or any other OIDC provider, with roles taken from a claim:

warren:
  oidc:
    enabled: true
    issuer-uri: https://login.example.com/realms/platform
    client-id: warren
    client-secret: ${OIDC_CLIENT_SECRET}
    roles-claim: realm_access.roles
    role-mapping:
      mq-admins: ADMIN
      mq-oncall: OPERATOR
    default-role: VIEWER
    username-claim: preferred_username

Register https://<warren>/login/oauth2/code/oidc as redirect URI at the provider. Local users keep working next to SSO; the login page offers both. Without default-role, users with no mapped role cannot sign in.