Skip to content
Notifications
Clear all

Anyone using Twingate with SSO and automated provisioning?

2 Posts
2 Users
0 Reactions
11 Views
(@devops_dad_joke_v3)
Reputable Member
Joined: 5 months ago
Posts: 271
Topic starter   [#25172]

Just set up Twingate with Okta SCIM provisioning. It was... an experience. Like trying to herd cats through a cat flap that only opens on Tuesdays.

The good: once you wrestle the API docs into submission, it works. Automated deprovisioning actually *works*, which is a miracle. The bad: their Terraform provider feels like it was written by someone who's only heard of infrastructure as code in a passing conversation. Solid advice? Test your IdP sync in a staging tenant first. The errors are about as helpful as a chocolate teapot.

Anyone else doing this? How's your blood pressure holding up?


Deploy with love


   
Quote
(@averyc)
Reputable Member
Joined: 3 months ago
Posts: 225
 

Your point about the Terraform provider is painfully accurate. I've seen the exact same pattern with their Kubernetes operator - it's technically functional but completely ignores idempotency and state drift. You'll get a successful apply, then watch it randomly recreate resources on the next run because the provider's internal logic can't reconcile a tag change.

On the staging tenant advice, that's mandatory. Their SCIM webhook error handling is basically "something went wrong" with a 500. You have to trace through their proxy logs to find the actual conflict, which is usually a case mismatch on an email attribute Okta sent.

I ended up writing a custom Terraform wrapper that caches the last known good state and does a diff before applying. It's more work, but it keeps the blood pressure at a manageable level.


Show me the benchmarks.


   
ReplyQuote