Marcus Hardt
November 2020
eduperson_entitlement
, aarc-g002 schemavm-operator
may manager virtual machines in EGI FedCloud✓ (Near-Trivial)
✓ (Easy)
✓ !#&@$ (Doable)
via kube-authoriser
component and ID-Tokens
WaTTS
+ wattson
+ oidc-agent
✓ (Just Finished 😄)
short demo
ssh
(requires local account)lcas
and lcmaps
pam
module + ssh wrapper
edu_person_*
claims
eduperson_assurance
"eduperson_assurance": [
"https://refeds.org/assurance/IAP/medium",
"https://refeds.org/assurance/IAP/local-enterprise",
"https://refeds.org/assurance/ID/eppn-unique-no-reassign",
"https://refeds.org/assurance/ATP/ePA-1m",
"https://refeds.org/assurance/ATP/ePA-1d",
"https://refeds.org/assurance/ID/unique",
"https://refeds.org/assurance/profile/cappuccino",
"https://refeds.org/assurance/IAP/low"
]
eduperson_assurance
eduperson_affiliation
eduperson_affiliation
and edu_person_affiliation
👍