Single sign-on¶
Putting an identity provider and a forward-auth proxy in front of the platform, so it is not reachable by anyone who can route to the ingress.
Placeholder
This page is a skeleton. Single sign-on is optional and off by default.
Topics to cover: what the default deployment does and does not protect, the identity provider deployment, protecting the platform hostname, and the trade-offs of doing this in a lab versus in front of anything real.