Add Render access review driver support

Register Render as an API-key connector provider and add an access
review driver that fetches workspace members from the Render API
(GET /v1/owners/{ownerId}/members).

Render exposes no partner OAuth program, so the connector authenticates
with a read-scoped API key (Authorization: Bearer) plus the customer's
Workspace ID. The flat members endpoint reports an explicit account
status and MFA flag, surfaced as the Active and MFAStatus fields; the
stable "usr-" id becomes ExternalID. There is no picker -- the
workspace is captured up front via ExtraSettings -- so
SetOrganizationSettings is omitted.

Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
Aurélien Sibiril
2026-06-09 23:32:58 +02:00
parent 7a43acd3c2
commit 7640376d32
17 changed files with 752 additions and 1 deletions

View File

@@ -63,6 +63,7 @@ const (
ConnectorProviderOkta ConnectorProvider = "OKTA"
ConnectorProviderZendesk ConnectorProvider = "ZENDESK"
ConnectorProviderQovery ConnectorProvider = "QOVERY"
ConnectorProviderRender ConnectorProvider = "RENDER"
)
var (
@@ -113,6 +114,7 @@ func ConnectorProviders() []ConnectorProvider {
ConnectorProviderOkta,
ConnectorProviderZendesk,
ConnectorProviderQovery,
ConnectorProviderRender,
}
}
@@ -158,7 +160,8 @@ func (v ConnectorProvider) IsValid() bool {
ConnectorProviderDatadog,
ConnectorProviderOkta,
ConnectorProviderZendesk,
ConnectorProviderQovery:
ConnectorProviderQovery,
ConnectorProviderRender:
return true
}

View File

@@ -144,6 +144,14 @@ type (
QoveryConnectorSettings struct {
OrganizationID string `json:"organization_id"`
}
// RenderConnectorSettings stores the Render workspace identifier. The
// value is Render's owner ID (e.g. "tea-..." for a team workspace or
// "usr-..." for a personal one), surfaced to operators as "Workspace ID"
// and used as the {ownerId} path segment on /v1/owners/{ownerId}/...
RenderConnectorSettings struct {
OwnerID string `json:"owner_id"`
}
)
// GrantType returns the OAuth2 grant type recorded on the connector's

View File

@@ -0,0 +1,15 @@
-- Copyright (c) 2026 Probo Inc <hello@probo.com>.
--
-- Permission to use, copy, modify, and/or distribute this software for any
-- purpose with or without fee is hereby granted, provided that the above
-- copyright notice and this permission notice appear in all copies.
--
-- THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
-- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
-- AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
-- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
-- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
-- OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
-- PERFORMANCE OF THIS SOFTWARE.
ALTER TYPE connector_provider ADD VALUE IF NOT EXISTS 'RENDER';