Skip to content

Docs for IdentityServer 8.1.0-preview.4 / User Management 2.0.0-preview.3: multiple storage instances - #1243

Merged
maartenba merged 4 commits into
mainfrom
ev/8-1-preview-4-doc-updates
Oct 8, 2026
Merged

maartenba merged 4 commits into
mainfrom
ev/8-1-preview-4-doc-updates

Conversation

@Erwinvandervalk

@Erwinvandervalk Erwinvandervalk commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Updates the docs for IdentityServer 8.1.0-preview.4, Duende.Storage 2.0.0-preview.3 and User Management 2.0.0-preview.3. Based on the public API diff in products-private (is-8.1.0-preview.3..is-8.1.0-preview.4, um-2.0.0-preview.2..um-2.0.0-preview.3).

Multiple storage instances (headline)

  • New page: Duende Storage → Multiple Storage Instances. Covers storage instances and data categories, fallback to the default instance, the error when a second provider is registered for the same instance, and an example that puts IdentityServer, User Management and Spaces data in separate instances. It also notes that the outbox and the purge job run against every instance, and how to migrate each instance.
  • Duende Storage getting started, overview, schemas, admin APIs and the EF Core migration guide now use the new setup: AddStorage(...) only selects the provider, and AddConfigurationStorage() / AddOperationalStorage() / AddUserManagement([instance,] ...) assign data to an instance.
  • The User Management storage page is rewritten, with a new section on giving User Management its own database. The old keyed IPooledStore multi-tenant section is removed because that API no longer exists.

API renames and removals

  • Provider methods AddSqliteStore / AddPostgreSqlStore / AddMsSqlStore / AddOracleStore are now AddSqlite / AddPostgreSql / AddMsSql / AddOracle.
  • IDatabaseSchema is replaced by IStorageInstanceSchemaFactory / IStorageInstanceSchema (MigrateAsync).
  • EF Core: AddConfigurationStore / AddOperationalStore are now AddEntityFrameworkConfigurationStore / AddEntityFrameworkOperationalStore. The EF page gets "8.1 preview" notes, but the code samples keep the old names because these pages also serve 8.0 readers and the old names are only obsolete in 8.1, not removed.

User Management

Spaces

  • Getting started uses the new storage setup and has a note on ISpaceAdmin.UndeleteAsync.

Not covered (possible follow-ups)

  • Spaces license limits, auth cookies separated by space path, dynamic provider options per space, SAML SP AuthnRequest signing, PAR redirect URI restrictions, and the identity provider schema APIs.
  • An 8.0 → 8.1 upgrade guide (waiting for GA).

Checks

  • npx astro build: 420 pages built, all internal links valid.
  • Every API in the samples was checked against the source and tests at the release tags.

Extending built-in schemas (second commit)

  • fundamentals/profiles.md and attribute-groups.md documented IUserProfileSchemaAdmin, which doesn't exist in preview.2 or preview.3. They are rewritten around:
    • the built-in profile BuiltInSchemas.UserProfile (email, name, given_name, family_name);
    • adding attributes with AddInMemoryDataExtensionSchemas([BuiltInSchemas.UserProfile.Extend(...)]), including attribute groups;
    • replacing the profile completely with SchemaId.UserProfile; your schema wins whatever the registration order;
    • editing schemas at runtime with AddDynamicSchemas() + ISchemaAdmin.
  • duende-storage/schemas.md gets a "Built-in Schemas" section covering BuiltInSchemas.OidcProvider / SamlProvider / UserProfile and how to extend or replace them.
  • Breaking-change notes (schemas.md, ui/login/dynamicproviders.md): the idp:oidc / idp:saml schemas are now registered by AddOidcDynamicProvider() / AddSamlDynamicProvider(). With AddDynamicSchemas() they must be created through ISchemaAdmin.
  • AddUserManagement() samples now pass a callback, since there is no overload without parameters (this also affected passkeys.mdx).
  • Fixed a reference to a nonexistent SchemaId.IdentityProvider("oidc"); the real members are SchemaId.OidcIdentityProvider / SamlIdentityProvider.

…0.0-preview.3

- Document per-instance Duende Storage wiring (AddStorage selects the provider;
  AddConfigurationStorage/AddOperationalStorage/AddUserManagement map data categories)
- Add a Multiple Storage Instances guide
- Replace removed APIs (IPooledStore, IDatabaseSchema, *Store provider methods)
- Update User Management password defaults (NIST SP 800-63B-4) and passkey changes
- Note the EF Core store method renames in 8.1

@maartenba maartenba left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Some comments in relevant places.

Also consider comparing with #1241 so we don't end with merge conflicts between the two, if any.

Comment thread astro/src/content/docs/identityserver/data/providers/duende-storage/index.mdx Outdated
Comment thread astro/src/content/docs/identityserver/data/providers/duende-storage/index.mdx Outdated
Comment thread astro/src/content/docs/identityserver/data/providers/duende-storage/index.mdx Outdated
@Erwinvandervalk
Erwinvandervalk marked this pull request as ready for review October 2, 2026 11:46
- Rewrite profile and attribute-group schema docs around BuiltInSchemas.UserProfile,
  Extend(...), full replacement, and AddDynamicSchemas + ISchemaAdmin
- Add a Built-in Schemas section to the Duende Storage schemas page
- Note that SAML/OIDC provider schemas come from AddSamlDynamicProvider/AddOidcDynamicProvider
- Fix AddUserManagement() samples (a configure callback is required)
- Clearer note title and wording on the Duende Storage overview
- Rename 'Give User Management Its Own Database' to 'Using A Dedicated Database For User Management'
- Use department/job_title in the attribute-groups example and explain why built-in attributes can't be reused with Extend
- Leave password default changes to #1241 (keep only the ChallengeSize notes here)
@Erwinvandervalk

Copy link
Copy Markdown
Contributor Author

Thanks for the review. All comments are addressed in the latest commit.

About #1241: this PR and #1241 both changed the password defaults (MinLength 15, MinLower / MinUpper / MinDigits / MinSymbols 0) in passwords.mdx, security.md and configuration.md, which caused merge conflicts. #1241 covers this more thoroughly (NIST explanation, OTP limits), so this PR no longer changes the defaults. Those three files only keep:

  • the passkey ChallengeSize "must be at least 16 bytes" notes (security.md, configuration.md);
  • AddUserManagement() changed to AddUserManagement(...) in prose (configuration.md);
  • the example error message in passwords.mdx, now "Password must be at least 15 characters.".

A test merge of this branch with sf/user-management-defaults is clean. getting-started.mdx also changes in both PRs, but in different places, and merges without conflicts.

@maartenba maartenba left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Merge whenever needed 👍

@maartenba maartenba added the documentation Improvements or additions to documentation label Oct 6, 2026
@maartenba maartenba added this to the 2026-Q4 milestone Oct 6, 2026
@maartenba

Copy link
Copy Markdown
Member

@Erwinvandervalk can this one be merged?

@maartenba
maartenba merged commit 839180b into main Oct 8, 2026
6 checks passed
@maartenba
maartenba deleted the ev/8-1-preview-4-doc-updates branch October 8, 2026 09:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants