
A Role With Nothing but a Name: Seeding OneLogin
OneLogin gives a role, a group and a policy nothing but a name, and a Smart Hook not even that. Teardown still has to delete only what my seed made, so each object is proved by what it holds.

OneLogin gives a role, a group and a policy nothing but a name, and a Smart Hook not even that. Teardown still has to delete only what my seed made, so each object is proved by what it holds.

The first PingOne seed I ran from Windows PowerShell 5.1 turned every accented and Han name into question marks. The fault was in how 5.1 encodes a request body, and all six providers in the module had it.

My seed asks the FreeIPA realm’s own CA for ten real certificates, and a CA has no delete. Teardown revokes them, so every seeded realm keeps a record of the run, next to HBAC and sudo rules built to be misread.

Authentik was already in my homelab doing single sign-on, so there was no license cap to design around. Of everything the provider seeds, the three hundred users are the least interesting.

I opened the Okta provider expecting to write the ten-user post again with better numbers. The eight users are the same eight users. Nearly everything around them has been replaced.

Okta, Authentik, FreeIPA, PingOne and OneLogin all hand me a token to paste into a config file. Entra hands me nothing, so the seeder has to solve its own access problem before it can create a single user.

In August 2025 I published a module that filled a lab domain and tore it down again. Its three commands still run, and almost nothing underneath them survived the move into TestEnvironment.

I built a lab by hand to test an RC4 migration script, and every run came back clean. The two accounts it should have caught were invisible, because my fixture held the same wrong assumption as the filter.

Every login in the house resolved against one thin client, and the only spare machine ran Ubuntu. The second server became a container, and a bad image tag left me a replica that looked healthy.

The rule a fresh FreeIPA install ships lets every account reach every service on every host, and it is on. That set my order: harden first, enroll second, then argue with each distro about sudo.