Self-managed SAML Group Sync

Merged Drew Blessing requested to merge dblessing_self_managed_saml_group_sync into master

What does this MR do and why?

Related to #285150 (closed). This is part two (part one was tlab-org/gitlab/-/merge_requests/85209).

Adds the new Sidekiq worker that manages group membership based on the groups sent in a SAML response.

Screenshots or screen recordings

These are strongly recommended to assist reviewers and reduce the time to merge your change.

How to set up and validate locally

Setup is unfortunately lengthy.

  1. Set up a test SAML IdP. Okta provides free developer accounts at

    • Find Okta setup notes in GitLab docs at
    • Also be sure to specify a groups attribute in Okta so groups are sent in the payload (see screenshot). This will automatically send Everyone as a group name for every user, or more custom groups can be added in the user directory in Okta.
    • Screen_Shot_2022-04-21_at_2.07.40_PM
  2. Set up your local GDK with some SAML provider -

  3. Create a group in GitLab. If you've configured SAML correctly you should now see 'SAML Group Links' in the Settings menu of any given GitLab group.

  4. Create a SAML Group Link in one or more groups. Use Everyone as the group name unless you've created and assigned more groups in Okta.

  5. Sign in using SAML as a user in your Okta dev environment.

  6. Observe the Sidekiq worker is kicked off and once complete, your user is now a member of the groups where you created the Group Links.

Numbered steps to set up and validate the change are strongly suggested.

MR acceptance checklist

This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Drew Blessing