Перейти до основного вмісту

Kubernetes

According to the Kubernetes documentation, the API Server of Kubernetes can be authenticated using OpenID Connect (OIDC). Ця стаття допоможе вам налаштувати аутентифікацію в Kubernetes за допомогою Casdoor.

Вимоги до середовища​

Необхідні умови:

  • Кластер Kubernetes.
  • A Casdoor application like this demo website.
  • Інструмент командного рядка kubectl (необов'язково).
примітка

Kubernetes oidc-issuer-url only accepts URLs which use the https:// prefix. Отже, ваш додаток Casdoor має бути розгорнутий на веб-сайті з HTTPS.

Крок 1: Створення додатку Casdoor та облікового запису користувача для аутентифікації​

In Casdoor add an application (e.g. Kubernetes). Note Name, Organization, Client ID, and Client secret. Enable the grant types the cluster will use.

Create an application in Casdoor Grant types

Add a user; set Organization and Signup application to the application you created.

Add a user in Casdoor

Крок 2: Налаштування сервера API Kubernetes з аутентифікацією OIDC​

To enable the OIDC plugin, set the following flags on the API server:

  • --oidc-issuer-url: URL of the provider that allows the API server to discover public signing keys.
  • --oidc-client-id: A client id that all tokens must be issued for.

Ця стаття використовує minikube для демонстрації. Configure the OIDC plugin for the minikube API server using the following command at startup:

minikube start --extra-config=apiserver.oidc-issuer-url=https://demo.casdoor.com --extra-config=apiserver.oidc-client-id=294b09fbc17f95daf2fe

Крок 3: Тестування аутентифікації OIDC​

Отримання інформації для аутентифікації​

Через відсутність фронтенду в kubectl, аутентифікацію можна виконати, надіславши POST-запит на сервер Casdoor. Here is the code in Python which sends a POST request to the Casdoor server and retrieves the id_token and refresh_token:

import requests
import json

url = "https://demo.casdoor.com/api/login/oauth/access_token"
payload = json.dumps({
"grant_type": "password",
"client_id": "Kubernetes",
"client_secret": "72c65c3912aec24a9f3ec41b65a7577114ed2bae",
"username": "user_3u94sf",
"password": "123456"
})
response = requests.request("POST", url, data=payload)

print(response.text)

Після виконання цього коду ви маєте отримати відповідь, подібну до наступної:

{
"access_token": "xxx",
"id_token": "yyy",
"refresh_token": "zzz",
"token_type": "Bearer",
"expires_in": 72000,
"scope": ""
}

Use the obtained id_token to authenticate with the Kubernetes API server.

Аутентифікація на основі HTTP-запиту​

Додайте токен до заголовка запиту.

curl https://www.xxx.com -k -H "Authorization: Bearer $(id_token)"
  • https://www.xxx.com is the Kubernetes API server deployment address.

Аутентифікація на основі клієнта Kubectl​

Метод файлу конфігурації​

Write the following configuration to the ~/.kube/config file. Вам слід замінити кожен елемент конфігурації у файлі конфігурації вище на значення, які ви отримали раніше.

users:
- name: minikube
user:
auth-provider:
config:
client-id: Kubernetes
client-secret: 72c65c3912aec24a9f3ec41b65a7577114ed2bae
id-token: $(id_token)
idp-issuer-url: https://demo.casdoor.com
refresh-token: $(refresh_token)
name: oidc

Access the API server with kubectl. Спробуйте виконати тестову команду.

kubectl cluster-info

Метод аргументу командного рядка​

Alternatively, pass the id_token in kubectl command-line parameters.

kubectl --token=$(id_token) cluster-info