Skip to content
v2.18.0GitHub

PatchMon

Sign in to PatchMon with Pocket ID.

Replace patchmon.example.com with the domain of your PatchMon frontend and id.example.com with the domain of your Pocket ID instance.

  • PatchMon 1.4.0 or later (PatchMon added OIDC SSO in version 1.4.0)
  1. In Pocket ID, open Administration → OIDC Clients and click Add OIDC Client.
  2. Enter a name such as PatchMon and add the callback URL https://patchmon.example.com/api/v1/auth/oidc/callback.
  3. Click Create and copy the Client ID, the Client secret and the OIDC Discovery URL. The client secret is only shown once.
  4. On the client’s General tab, turn on PKCE, then click Save.
  5. On the client’s Access tab, select the groups that may sign in under Allowed User Groups, or choose All Users.

This example uses the Docker Compose deployment of PatchMon. See the official docs for more information.

  1. Add or edit the following lines in your PatchMon .env file, with the OIDC Discovery URL, Client ID and Client secret from Pocket ID:

    OIDC_ENABLED=true
    OIDC_ISSUER_URL=<your OIDC-Discovery-URL from above>
    OIDC_CLIENT_ID=<client-id>
    OIDC_CLIENT_SECRET=<client-secret>
    OIDC_REDIRECT_URI=https://patchmon.example.com/api/v1/auth/oidc/callback
    OIDC_SCOPES=openid email profile
    OIDC_AUTO_CREATE_USERS=true
    OIDC_DEFAULT_ROLE=user
    OIDC_DISABLE_LOCAL_AUTH=false
    OIDC_BUTTON_TEXT=Login with PocketID
    OIDC_SYNC_ROLES=false
  2. Save and redeploy PatchMon, then sign in with Pocket ID to test it.

You can automatically assign permissions based on group membership. Group matching is case-insensitive, so patchmon admins matches PatchMon Admins.

  1. In Pocket ID, open Administration → User Groups and click Add Group to create a group for every role you want to use.
  2. Add users to the groups depending on the permissions you want them to have.

You only need to define the groups you intend to use. Any variables left unset are ignored.

Change these values in your .env file:

  • OIDC_SCOPES → OIDC_SCOPES=openid email profile groups
  • OIDC_SYNC_ROLES → OIDC_SYNC_ROLES=true

Then add the groups for the roles you want to manage with Pocket ID:

OIDC_ADMIN_GROUP=PatchMon Admins
OIDC_USER_GROUP=PatchMon Users
OIDC_SUPERADMIN_GROUP=PatchMon SuperAdmins
OIDC_HOST_MANAGER_GROUP=PatchMon Host Managers
OIDC_READONLY_GROUP=PatchMon Readonly