Disabled OAuth resources

When you enable direct authentication, several OAuth resources are intentionally removed.

Important

Ensure that you do not rely on these removed resources before configuring direct authentication.

The following resources are unavailable when direct authentication is configured:

  • OpenShift OAuth server and OpenShift OAuth API server

  • User and group APIs (*.user.openshift.io)

  • OAuth APIs (*.oauth.openshift.io)

  • OAuth server and client configurations

Direct authentication identity providers

Direct authentication has been tested with multiple OpenID Connect (OIDC) identity providers to help you verify compatibility before configuring your cluster.

The following identity providers have been tested:

  • Active Directory Federation Services for Windows Server

  • GitLab

  • Google

  • Keycloak

  • Microsoft Entra ID

  • Okta

  • Ping Identity

  • Red Hat Single Sign-On

Note

Red Hat does not test all factors associated with third-party identity provider functionality.