Skip to content

Refresh provisioning overview page - #26172

Open
akristen wants to merge 7 commits into
docker:mainfrom
akristen:scim-jit-clarification
Open

akristen wants to merge 7 commits into
docker:mainfrom
akristen:scim-jit-clarification

Conversation

@akristen

@akristen akristen commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Doc that adds some context about JIT vs SCIM, per SME resources. Makes updates to overview docs, troubleshooting, and FAQs. Also includes a freshness pass from tier 1 and tier 2 review agents.

The provisioning overview had an unfocused title, a thin SEO description, long unwrapped lines, and an attribute list that mixed required and optional fields into prose.

Retitle the page to 'User provisioning overview', expand the description and keywords, wrap body text at 80 characters, and move the SSO attributes into a table with a required column.

Co-authored-by: Cursor <cursoragent@cursor.com>
@netlify

netlify Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for docsdocker ready!

Name Link
🔨 Latest commit 5c6ca7a
🔍 Latest deploy log https://app.netlify.com/projects/docsdocker/deploys/6abd7c20e3f45a00087a1b05
😎 Deploy Preview https://deploy-preview-26172--docsdocker.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

akristen and others added 2 commits September 23, 2026 15:35
The provisioning overview described each method in isolation, so readers could not tell that JIT overwrites SCIM attributes or that JIT wins over auto-provisioning on an SSO domain.

Add a precedence list under the default setup, link each method from the comparison table, note that auto-provisioning only adds existing Docker accounts, and point to the provisioning troubleshooting page.

Co-authored-by: Cursor <cursoragent@cursor.com>
Admins who enable SCIM while JIT is on by default had no canonical guidance on overwrite and removal risks, and related FAQs mixed SCIM with auto-provisioning.

Put the recommended-source decision and both-enabled rules on the SCIM overview, then cross-link from JIT, SCIM setup, the provisioning overview, troubleshooting, and Security FAQs.

Co-authored-by: Cursor <cursoragent@cursor.com>
@github-actions github-actions Bot added the area/accounts Relates to Docker accounts label Sep 23, 2026

@aevesdocker aevesdocker left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wording-wise, LGTM. 2 non-blocking nits

Comment thread content/manuals/faqs/security.md Outdated
Comment thread content/manuals/security/provisioning/scim/provision-scim.md Outdated
akristen and others added 4 commits September 25, 2026 10:17
The SCIM pages described provisioning behavior inconsistently: the overview didn't explain how SCIM and JIT interact, group mapping didn't distinguish what SAML SSO sends at sign-in from what SCIM syncs on a schedule, and the setup and migration pages used stale Entra ID naming, mixed numbered-list styles, and long unwrapped lines.

Rewrote the four SCIM pages for accuracy and consistency: added a section on choosing how SCIM works with JIT, separated the SSO and SCIM group-mapping paths, corrected the Okta and Microsoft Entra ID setup values and links, and normalized front matter, list numbering, and line wrapping.

Co-authored-by: Cursor <cursoragent@cursor.com>
The provisioning docs said SCIM could not manage or deprovision users created through JIT or added manually, and they attributed removal and attribute conflicts to the wrong mechanism.

Describe SCIM as able to link and deprovision members whose email domain is verified on the SSO connection, correct deactivation and team-sync behavior, and align the JIT and SCIM toggle steps with the UI.

Co-authored-by: Cursor <cursoragent@cursor.com>
Resolve provisioning conflicts with the enforce-sign-in move and the dropped platform aliases. Address review wording: use you in the SSO FAQ, and tell readers to review how SCIM works with JIT before choosing a provisioning method.

Co-authored-by: Cursor <cursoragent@cursor.com>
The JIT page linked group mapping to a heading that is not on the SCIM overview, and several provisioning pages had long unwrapped lines and numbered steps that did not all use 1.

Wrap those pages, renumber the JIT flows, point the SCIM link at the setup page, and use the canonical Docker Team name in group mapping.

Co-authored-by: Cursor <cursoragent@cursor.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/accounts Relates to Docker accounts area/security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants