PatchMon
Sign in to PatchMon with Pocket ID.
Replace patchmon.example.com with the domain of your PatchMon frontend and id.example.com with the domain of your Pocket ID instance.
Requirements
Section titled “Requirements”- PatchMon 1.4.0 or later (PatchMon added OIDC SSO in version 1.4.0)
Create the client in Pocket ID
Section titled “Create the client in Pocket ID”- In Pocket ID, open Administration → OIDC Clients and click Add OIDC Client.
- Enter a name such as
PatchMonand add the callback URLhttps://patchmon.example.com/api/v1/auth/oidc/callback. - Click Create and copy the Client ID, the Client secret and the OIDC Discovery URL. The client secret is only shown once.
- On the client’s General tab, turn on PKCE, then click Save.
- On the client’s Access tab, select the groups that may sign in under Allowed User Groups, or choose All Users.
Configure PatchMon
Section titled “Configure PatchMon”This example uses the Docker Compose deployment of PatchMon. See the official docs for more information.
-
Add or edit the following lines in your PatchMon
.envfile, with the OIDC Discovery URL, Client ID and Client secret from Pocket ID:OIDC_ENABLED=trueOIDC_ISSUER_URL=<your OIDC-Discovery-URL from above>OIDC_CLIENT_ID=<client-id>OIDC_CLIENT_SECRET=<client-secret>OIDC_REDIRECT_URI=https://patchmon.example.com/api/v1/auth/oidc/callbackOIDC_SCOPES=openid email profileOIDC_AUTO_CREATE_USERS=trueOIDC_DEFAULT_ROLE=userOIDC_DISABLE_LOCAL_AUTH=falseOIDC_BUTTON_TEXT=Login with PocketIDOIDC_SYNC_ROLES=false -
Save and redeploy PatchMon, then sign in with Pocket ID to test it.
Group claim
Section titled “Group claim”You can automatically assign permissions based on group membership.
Group matching is case-insensitive, so patchmon admins matches PatchMon Admins.
Create groups in Pocket ID
Section titled “Create groups in Pocket ID”- In Pocket ID, open Administration → User Groups and click Add Group to create a group for every role you want to use.
- Add users to the groups depending on the permissions you want them to have.
You only need to define the groups you intend to use. Any variables left unset are ignored.
PatchMon group environment variables
Section titled “PatchMon group environment variables”Change these values in your .env file:
OIDC_SCOPES→OIDC_SCOPES=openid email profile groupsOIDC_SYNC_ROLES→OIDC_SYNC_ROLES=true
Then add the groups for the roles you want to manage with Pocket ID:
OIDC_ADMIN_GROUP=PatchMon AdminsOIDC_USER_GROUP=PatchMon UsersOIDC_SUPERADMIN_GROUP=PatchMon SuperAdminsOIDC_HOST_MANAGER_GROUP=PatchMon Host ManagersOIDC_READONLY_GROUP=PatchMon Readonly