Users & groups
Backed by config/users.yaml — the single data source both SAML and LDAP read.
Saving here rewrites that file atomically; editing the file directly hot-reloads with no restart.
Users
| Username | Name | Groups | Flags | |
|---|---|---|---|---|
alice |
Alice Anderson | alice@example.test | 2 | |
bob |
Brown | — | 1 | |
carol |
恵子 O'Brien-Þorsteinsdóttir de la Cruz-Wąsikowska III | carol.obrien@example.test | 2 | |
dave |
Dave Davis | dave@example.test | 1 | disabled |
eve |
Eve Evans | eve@example.test | 1 | pwd expired |
frank |
Frank Franklin | frank@example.test | 201 | |
mallory |
Mallory "The Fuzzer" <mallory> & co | mallory+"test"@example.test | 1 | |
grace |
Grace Hopper | grace@example.test | 2 | MFA |
wchangadmin |
Winston Chang | wchangadmin@example.test | 2 | |
svc-ldap |
LDAP Service Account | — | 1 | service |
Add or update a user
An existing username is merged; a new one is appended. Groups are comma-separated.
Groups
engineeringEngineeringadminsAdministratorscontractorsContractorsredteamRed Teamservice-accountsService Accountsgroup with spacesGroup With Spaces
plus 200 generated dept-* groups (the oversized-AttributeStatement fixture)
Keys
- SAML signing
- 92:CC:F9:FE:3F:78:28:66:18:49:42:28:09:34:CB:82:F2:A8:85:34:84:6D:1F:84:D9:EE:34:27:E6:47:4F:A4
- CA for host trust
certs/ca.crt
Rotating publishes both the new and the previous certificate in metadata, so an SP that has not refreshed keeps working. Rotation is a scenario to test on purpose, not an accident.
Active IdP sessions
None.