assign-operator-to-engineers-label.yaml for the SAMLLabelRule resource, with the following content:
Copy
omnictl:
Copy
Operator role to any user that logs in with SAML and has the SAML attribute Role with the value engineers.
Log in to Omni as a new SAML user with the SAML attribute with name Role and value engineers.
This will cause the user created on the Omni side to be labeled as saml.omni.sidero.dev/role/engineers.
This label will match the SAMLLabelRule resource we created above, and the user will automatically be assigned the Operator role.
Note
When there are multiple matches from different SAMLLabelRule resources, the matched role with the highest access level will be assigned to the user.
Warning
This role assignment will only work for the new users logging in with SAML.
The SAML users who have already logged in to Omni at least once will not be matched by the SAMLLabelRule resource and their roles will not be updated.
Warning
If the logged in SAML user is the very first user logging in to an Omni instance, it will not be matched by the SAMLLabelRule resource and always be assigned the Admin role.