Pulumi Cloud & SCIM
Pulumi Cloud supports System for Cross-domain Identity Management (SCIM) 2.0 integration with different identity providers. SCIM enables you to manage your users and groups centrally in your Identity Provider (IdP) and then synchronize those users and groups to Pulumi Cloud.
SCIM provisions two things in Pulumi Cloud:
- Users become members of your Pulumi organization, able to sign in through your identity provider.
- Groups become teams, and group membership becomes team membership. Grant those teams access to stacks, environments, and other entities with RBAC.
Pulumi implements a single SCIM 2.0 endpoint. Every identity provider uses the same routes, schemas, and attributes, so only the IdP-side setup differs from one provider to the next. The guides at the end of this page cover popular providers.
Before you start
SCIM changes how accounts and teams behave in ways that matter before you connect an identity provider: deprovisioning deactivates users rather than deleting them, deleting a group deletes its team, usernames can’t change after an account is created, and provisioned accounts become organization-managed. Read SCIM provisioning for the capabilities, supported attributes, and behavior to plan for.
Next steps
To set up synchronization between Pulumi and your SAML 2.0 identity provider, refer to one of our example guides:
For the provisioning errors you are most likely to hit and how to resolve them, see Troubleshooting.