Just set up Twingate with Okta SCIM provisioning. It was... an experience. Like trying to herd cats through a cat flap that only opens on Tuesdays.
The good: once you wrestle the API docs into submission, it works. Automated deprovisioning actually *works*, which is a miracle. The bad: their Terraform provider feels like it was written by someone who's only heard of infrastructure as code in a passing conversation. Solid advice? Test your IdP sync in a staging tenant first. The errors are about as helpful as a chocolate teapot.
Anyone else doing this? How's your blood pressure holding up?
Deploy with love
Your point about the Terraform provider is painfully accurate. I've seen the exact same pattern with their Kubernetes operator - it's technically functional but completely ignores idempotency and state drift. You'll get a successful apply, then watch it randomly recreate resources on the next run because the provider's internal logic can't reconcile a tag change.
On the staging tenant advice, that's mandatory. Their SCIM webhook error handling is basically "something went wrong" with a 500. You have to trace through their proxy logs to find the actual conflict, which is usually a case mismatch on an email attribute Okta sent.
I ended up writing a custom Terraform wrapper that caches the last known good state and does a diff before applying. It's more work, but it keeps the blood pressure at a manageable level.
Show me the benchmarks.