Google Workspace
Read the Identity overview first to understand the
IdentityProvider resource, userInfoPrefix, and claim mappings.
Configure Google Workspace as a Hub identity provider. Google is OIDC-
compliant for login but does not emit group membership in the ID token.
That means you either bind roles to individual users by email, or inject a
groups claim upstream (via Cloud Identity or an identity broker).
Prerequisites
- A Google Workspace tenant and admin access to a Google Cloud project.
- An OAuth 2.0 client in the Google Cloud Console. See Setting up OAuth 2.0.
Provider-side setup
- Create an OAuth 2.0 Client ID of type Web application in the Google Cloud Console under APIs & Services → Credentials.
- Add
https://<hub-url>/oidc/callbackto Authorized redirect URIs. - Record the client ID and client secret.
Google's ID token does not include group memberships. Choose one of:
- Bind to users. Skip groups and bind roles to individual users by their email address. Simple but doesn't scale beyond a handful of admins.
- Custom claim. Inject a
groupsclaim from an upstream source (Cloud Identity custom attributes or an identity broker fronting Google), then map it underclaimMappings.groups.
IdentityProvider resource
User bindings only
apiVersion: authentication.hub.upbound.io/v1beta1
kind: IdentityProvider
metadata:
name: google
spec:
redirect:
browserLogin: true
clientSecret: "<client-secret>"
scopes:
- openid
- email
- profile
validation:
userInfoPrefix: "google:"
issuer:
url: https://accounts.google.com
audiences:
- <client-id>
claimMappings:
username:
claim: email
claimValidationRules:
- expression: "claims.email_verified == true"
message: "email must be verified"
Role bindings then target users by email:
google:alice@example.com.
With custom groups claim
If an upstream broker (or a directly-configured custom claim) injects
groups into the ID token, add the groups mapping:
spec:
validation:
userInfoPrefix: "google:"
issuer:
url: https://accounts.google.com
audiences:
- <client-id>
claimMappings:
username:
claim: email
groups:
claim: groups
Notes
- The issuer URL is fixed:
https://accounts.google.com. Hub reads discovery athttps://accounts.google.com/.well-known/openid-configuration. - Google's ID tokens always carry the
email_verifiedclaim; keep theclaimValidationRulesrequirement above to reject unverified accounts.
Next step
With the provider registered, decide what its identities may do: Access management covers binding the prefixed usernames and groups above to Hub roles.