How do I configure Hub to Hub client access?
Last Updated: | Applicable Hub Versions: 24.3 and later
Last Updated: | Applicable Hub Versions: 24.3 and later
Before using the Hub to Hub feature, the Satellite Hub system administrator should create the PlanviewLinkBridgeUser role and map a client to this role.
Note: The PlanviewLinkBridgeUser role must be created before creating the client. See instructions here.
See the instructions below for how to create the client and map the PlanviewLinkBridgeUser role to it.
Select Clients on the sidebar and click Create client.
In the General settings section:
In the Capability config section:
Toggle Client authentication on.
Under Authentication flow, enable the following options:
Standard flow
Direct access grants
Service accounts roles
In the Login settings section:
Configure the Home URL using the https://<subdomain>.tasktop.net of your Hub Cloud instance.
Once the client ID has been created, go to the Service accounts roles tab.
Click the username service-account-<client ID> to manage detail and group mappings.
In the user details, click the Role mapping tab.
Click Assign role.
In the filter dropdown, select Filter by realm roles.
Select PlanviewLinkBridgeUser from the list of realm roles and click Assign.
PlanviewLinkBridgeUser should now appear in the list of roles for the service-account-<client ID> user.
Navigate to the Clients section of your Keycloak instance, click on the client ID you configured for Hub to Hub connectivity.
Select the Service accounts roles tab and confirm that PlanviewLinkBridgeUser appears in the roles list for your Hub to Hub client.