gameplane / docs
ACCESS

User Administration

Invite and maintain local users, reset credentials, assign roles, and distinguish current capabilities from planned service accounts.

Users & Accessv0.215 MIN
Service accounts are planned

Gameplane has no service accounts or API tokens yet; machine-to-machine tokens are planned for v1.1. Until then, give automation its own local user with the narrowest role that works, and never share a person’s login.

Invite a local user

Create a unique identity, secure initial credential, and the minimum global role; add per-server collaboration separately.

Unique IdentityUse a unique username, optional display name/email, and 12+ character password.
Least PrivilegeAssign the minimum required global role; scope server access separately via role bindings.
Secure HandoffSend credentials securely (not email) and verify the user signs in privately for the first time.

New users start with a primary role applied cluster-wide. The three built-in roles are:

  • Admin — full access to users, servers, templates, backups, cluster settings, and audit logs
  • Operator — manage servers and backups; cannot create/edit users or templates
  • Viewer — read-only access to servers, backups, and status

You can refine permissions per namespace (e.g., restrict an operator to a specific game project) using per-namespace role bindings in the Role Bindings section of the user’s card.

Edit roles and reset credentials

Role changes affect global authorization; local and OIDC credentials have different owners.

Role ChangesEdit display name, email, and primary role deliberately — changes apply on the user's next login.
Local Password ResetReset only local passwords in Gameplane with a new 12+ character value; does not affect OIDC users.
OIDC ManagementFor OIDC-linked users, manage password, MFA, and account status at the upstream provider (Keycloak, Okta, etc.).

To reset a local user’s password:

  1. Find the user in the dashboard Users page
  2. Click the user card to open details
  3. Tap Reset Password and enter a new 12+ character value
  4. The user can log in with the new password immediately

For OIDC users:

  • Password resets happen at the identity provider, not in Gameplane
  • MFA and account disablement are provider-controlled
  • The user’s role and email in Gameplane mirror the provider’s state

Users who log in via OIDC have their role determined by:

  • Per-provider group mappings configured under Admin Settings → Authentication, re-evaluated against the user’s IdP groups on each login
  • Helm-seeded group mappings (api.oidc.groupsClaim, api.oidc.roleMappings) for the Helm-configured provider, from v0.3.0; an admin can override them in the dashboard
  • Manual assignment when no group mapping is configured: new OIDC users get the default role (viewer) and an admin promotes them

Review lifecycle and availability

Audit access changes and remove dormant roles/collaboration; treat service accounts as version-dependent until shipped.

Periodically review:

  • Active users — remove unused accounts to reduce the attack surface
  • Role changes — audit the role history in the Audit & Observability logs
  • Per-namespace bindings — clean up stale role bindings if a user’s scope narrows
  • Providers — verify OIDC providers are still responsive; expired provider certificates log an error in the system log

USER LIFECYCLE

01   01 Invite → unique identity + 12-char password + least privilege
02   02 Local reset in Gameplane; OIDC credentials remain upstream
03   03 Audit role/collaboration changes; service accounts depend on release

See also