All skills
secondsky avatar

/sap-btp-cloud-logging

@620a19a
by Eddiesecondsky/sap-skills456 stars
120

This skill provides comprehensive guidance for SAP Cloud Logging service on SAP BTP. Use when setting up Cloud Logging instances, configuring log ingestion from Cloud Foundry or Kyma runtimes, implementing OpenTelemetry observability, analyzing logs/metrics/traces in OpenSearch Dashboards, configuring SAML authentication, managing certificates, or troubleshooting ingestion issues. Covers service plans (dev/standard/large), all 4 instance creation methods (BTP Cockpit, CF CLI, BTP CLI, Service Operator), all 4 ingestion methods (Cloud Foundry, Kyma, OpenTelemetry, JSON API), and security best practices.

Use this Skill: https://skilld.dev/gh/secondsky/sap-skills/sap-btp-cloud-logging

This session only. Nothing lands on disk.

referencessaml-authentication.md

≈3.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

SAP Cloud Logging - SAML Authentication Reference

Source: https://github.com/SAP-docs/btp-cloud-logging/blob/main/docs/prerequisites-41d8559.md Last Updated: 2025-11-22


Table of Contents


Overview

SAP Cloud Logging strongly recommends integrating with SAP Cloud Identity Services using SAML 2.0 protocol for secure dashboard access. This enables centralized user management and group-based access control.

Security Notice: Review SAP BTP Security Recommendation BTP-CLS-0001 before configuring SAML.

Important: SAP officially recommends Identity Authentication. Other SAML providers may work but lack official support or documentation. SAML configurations can be reused across multiple SAP Cloud Logging instances.


Prerequisites

  1. SAP Cloud Identity Services tenant (Identity Authentication)
  2. Administrator access to Identity Authentication admin console: https://<tenantID>.accounts.ondemand.com/admin
  3. Cloud Logging instance ready for SAML configuration

SAML 2.0 Configuration Steps

Step 1: Gather Identity Provider Information

From your Identity Authentication tenant:

Metadata URL:

https://<tenant-id>.accounts.ondemand.com/saml2/metadata

Entity ID: Extract from metadata file - look for entityID attribute in the root element.

Example:

<EntityDescriptor entityID="https://mytenant.accounts.ondemand.com">

Step 2: Create SAML 2.0 Application

  1. Log into Identity Authentication admin console
  2. Navigate to Applications & Resources → Applications
  3. Click Create → SAML 2.0
  4. Enter application name (e.g., "SAP Cloud Logging - Production")

Step 3: Configure Application Attributes

3.1 Self-Defined Attribute
  1. Go to application → Attributes
  2. Add attribute:
    • Name: groups
    • Source: Identity Directory
    • Value: User Groups
3.2 Name ID Format
  1. Go to SAML 2.0 Configuration
  2. Set Name ID Format: E-mail
3.3 Manual SAML 2.0 Configuration

Configure the service provider settings:

Setting Value
Assertion Consumer Service https://<dashboards-url>/_opendistro/_security/saml/acs
Single Logout Service https://<dashboards-url>/_opendistro/_security/saml/logout
SP Entity ID cloud-logging-<instance-id>

Step 4: Configure SAML 2.0 (Choose One Option)

OPTION 1: Request Signing (Recommended)

Request signing removes the need to manually configure assertion/logout URLs for each instance.

Generate Certificate and Private Key (Official SAP Commands):

# Generate certificate and private key
openssl req -x509 -newkey rsa:2048 -keyout private.key -out cert.pem -nodes -days <validity>

# Convert to PKCS#8 format (REQUIRED)
openssl pkcs8 -topk8 -v1 PBE-SHA1-3DES -in private.key -out private_pkcs8.key

# Base64 encode the private key for configuration
printf "%s" "$(< private_pkcs8.key)" | base64

Configure in Identity Authentication:

  1. Go to application → SAML 2.0 Configuration
  2. Set Require signed authentication requests to ON
  3. Upload certificate in the Signing Certificate section
  4. Provide the signing key to sp.signature_private_key field
  5. Set sp.signature_private_key_password if the key is encrypted

Warning: Expired signing certificates cause login failures with message: "The digital signature of the received SAML2 message is invalid."

OPTION 2: Manual Endpoint Configuration

Only available after creating a Cloud Logging instance. Must be repeated for each new instance.

  1. Go to application → SAML 2.0 Configuration → Configure Manually
  2. Set Assertion Consumer Service Endpoint: <dashboards-url>/_opendistro/_security/saml/acs
  3. Set Single Logout Endpoint:
    • Binding: HTTP_REDIRECT
    • URL: <dashboards-url> (no path)
  4. Click Save

Step 5: Create Access Group

  1. In Identity Authentication, go to Users & Authorizations → User Groups
  2. Create a group (e.g., CLS-Administrators)
  3. Add users who need dashboard access

Important: The group configured as admin_group in Cloud Logging automatically maps to the all_access role in OpenSearch.


Step 6: Configure Cloud Logging Instance

Update your Cloud Logging instance with SAML parameters using the official nested structure:

{
  "saml": {
    "enabled": true,
    "initiated": true,
    "admin_group": "CLS-Administrators",
    "roles_key": "groups",
    "idp": {
      "metadata_url": "https://<tenant-id>.accounts.ondemand.com/saml2/metadata",
      "entity_id": "https://<tenant-id>.accounts.ondemand.com"
    },
    "sp": {
      "entity_id": "cloud-logging-<unique-identifier>"
    }
  }
}

With request signing (Option 1):

{
  "saml": {
    "enabled": true,
    "initiated": true,
    "admin_group": "CLS-Administrators",
    "roles_key": "groups",
    "idp": {
      "metadata_url": "https://<tenant-id>.accounts.ondemand.com/saml2/metadata",
      "entity_id": "https://<tenant-id>.accounts.ondemand.com"
    },
    "sp": {
      "entity_id": "cloud-logging-<unique-identifier>",
      "signature_private_key": "<base64-encoded-pkcs8-private-key>",
      "signature_private_key_password": ""
    }
  }
}

SAML Parameter Reference (Official Nested Structure)

Required Parameters (when enabled: true)

Parameter Type Conditional Description
enabled boolean Yes Enable SAML authentication
initiated boolean Required if enabled Enable IdP-initiated SSO
admin_group string Required if enabled Group mapped to all_access role
roles_key string Required if enabled Attribute for backend_roles during login
idp.metadata_url string Required if enabled Identity Provider metadata URL
idp.entity_id string Required if enabled Entity ID from metadata's entityID field
sp.entity_id string Required if enabled Service Provider application name in IdP

Optional Parameters (Request Signing)

Parameter Type Description
sp.signature_private_key string Base64-encoded PKCS#8 private key
sp.signature_private_key_password string Password for encrypted private key

Note: Identity Authentication group names are forwarded to OpenSearch as backend roles, which map to OpenSearch roles granting permissions.


Role Mapping

Default Role Mapping

Group OpenSearch Role
admin_group value all_access
Other groups Configurable via OpenSearch Security

Custom Role Mapping

After SAML setup, configure additional role mappings in OpenSearch Dashboards:

  1. Go to Security → Roles
  2. Create custom roles with specific index permissions
  3. Go to Security → Role Mappings
  4. Map SAML groups to OpenSearch roles

Example custom role for read-only access:

role_name: cls_readonly
cluster_permissions:
  - cluster_composite_ops_ro
index_permissions:
  - index_patterns:
      - "logs-*"
      - "metrics-*"
    allowed_actions:
      - read

Troubleshooting

Login Fails with "Invalid SAML Response"

  1. Verify idp_entity_id matches metadata exactly
  2. Check sp_entity_id is unique
  3. Ensure clock sync between IdP and Cloud Logging
  4. Validate certificate hasn't expired

User Not Authorized

  1. Verify user is in the configured admin_group
  2. Check group attribute is being sent in SAML assertion
  3. Confirm roles_key matches the attribute name (groups)

IdP Metadata URL Not Accessible

  1. Check URL is publicly accessible
  2. Verify network connectivity from Cloud Logging
  3. Try downloading metadata manually and hosting it

Request Signing Errors

  1. Ensure private key is PKCS#8 format
  2. Verify base64 encoding is correct (no headers)
  3. Check certificate matches private key
  4. Confirm certificate is uploaded to IdP

IdP-Initiated SSO Not Working

  1. Set idp_initiated_sso: true
  2. Configure correct Relay State in IdP
  3. Verify SP Entity ID matches

Security Best Practices

  1. Enable request signing for production environments
  2. Rotate signing certificates annually
  3. Use dedicated group for Cloud Logging admins
  4. Implement least privilege with custom role mappings
  5. Review access periodically
  6. Enable audit logging in Identity Authentication

Complete Configuration Example

Identity Authentication Application Settings

Setting Value
Application Type SAML 2.0
Name ID Format E-mail
Assertion Consumer Service https://dashboards.cls.example.com/_opendistro/_security/saml/acs
SP Entity ID cloud-logging-prod-001
Sign SAML Requests Enabled
Groups Attribute groups

Cloud Logging Instance Configuration

{
  "retention_period": 14,
  "saml": {
    "enabled": true,
    "initiated": true,
    "admin_group": "CLS-Administrators",
    "roles_key": "groups",
    "idp": {
      "metadata_url": "https://mytenant.accounts.ondemand.com/saml2/metadata",
      "entity_id": "https://mytenant.accounts.ondemand.com"
    },
    "sp": {
      "entity_id": "cloud-logging-prod-001",
      "signature_private_key": "MIIEvgIBADANBg...",
      "signature_private_key_password": ""
    }
  }
}

Documentation Links

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides operational guidance for SAP BTP Cloud Logging, including setup instructions, CLI commands, and telemetry configuration. It identifies an inherent surface for indirect prompt injection through the ingestion of external log data.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    8/10 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 620a19a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 months ago
Other metadata
metadata
{
  "maintainer": "Eduard Jiglau",
  "maintainer_email": "hello@sap-ai-skills.com",
  "website": "https://sap-ai-skills.com",
  "version": "2.4.1",
  "last_verified": "2025-11-27",
  "source_documentation": "https://github.com/SAP-docs/btp-cloud-logging",
  "sap_help_portal": "https://help.sap.com/docs/cloud-logging"
}

README badge

README badge for secondsky/sap-skills/sap-btp-cloud-logging