Authentication

GitOps supports three authentication methods. Authentication settings are configured independently for each organization, so different organizations can adopt different identity providers.

Sign-in flow

Open the GitOps URL and sign in with an enabled method. After authentication, GitOps establishes a session and shows the organizations available to the user.

Local authentication

Local authentication is always enabled. Users sign in with a GitOps username and password. On a new installation, the first local account is created at /bootstrap and becomes the cluster administrator.

See First Steps for the complete bootstrap sequence.

Google SSO

Google Workspace SSO is planned and is not connected yet. The organization settings screen will allow an organization administrator to configure the Google client ID and client secret when this method is available.

SAML

SAML support is planned and is not connected yet. The organization settings screen is prepared for an entry point, issuer, and IdP certificate when this method is available.

Organization scope

Open an organization’s Settings > Global area to configure its authentication options. Changes apply to that organization and do not change the authentication configuration of other organizations in the same GitOps installation.