{"id":70867,"date":"2020-02-22T06:40:58","date_gmt":"2020-02-22T03:40:58","guid":{"rendered":"https:\/\/prohoster.info\/blog\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes"},"modified":"2020-03-03T16:14:36","modified_gmt":"2020-03-03T13:14:36","slug":"prikruchivaem-ldap-avtorizacziyu-k-kubernetes","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","title":{"rendered":"LDAP-Authentifizierung zu Kubernetes hinzuf\u00fcgen","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"LDAP-Authentifizierung zu Kubernetes hinzuf\u00fcgen\" src=\"\/wp-content\/uploads\/2020\/02\/2b0f0a4921e049a78a015e7693d697cf.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>Eine kurze Anleitung, wie Sie Keycloak nutzen k\u00f6nnen, um Kubernetes mit Ihrem LDAP-Server zu verbinden und den Import von Benutzern und Gruppen einzurichten. Dies erm\u00f6glicht Ihnen, RBAC f\u00fcr Ihre Benutzer zu konfigurieren und einen Auth-Proxydienst zu nutzen, um das Kubernetes-Dashboard und andere Anwendungen, die keine eigene Autorisierung unterst\u00fctzen, abzusichern.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2 id=\"ustanovka-keycloak\">Installation von Keycloak<\/h2>\n<p><\/p>\n<p>Angenommen, Sie haben bereits einen LDAP-Server. Dies kann ein Active Directory, FreeIPA, OpenLDAP oder etwas anderes sein. Wenn Sie keinen LDAP-Server haben, k\u00f6nnen Sie Benutzer direkt \u00fcber die Keycloak-Oberfl\u00e4che erstellen oder \u00f6ffentliche OIDC-Anbieter (Google, Github, Gitlab) verwenden; das Ergebnis wird fast dasselbe sein.<\/p>\n<p><\/p>\n<p>Zuerst installieren wir Keycloak selbst. Die Installation kann sowohl separat als auch direkt im Kubernetes-Cluster erfolgen. In der Regel ist es einfacher, es separat zu installieren, wenn Sie mehrere Kubernetes-Cluster haben. Auf der anderen Seite k\u00f6nnen Sie immer <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/helm\/charts\/tree\/master\/stable\/keycloak\">das offizielle Helm-Chart<\/a><\/noindex> verwenden und es direkt in Ihrem Cluster installieren.<\/p>\n<p><\/p>\n<p>Zur Speicherung der Daten von Keycloak ben\u00f6tigen Sie eine Datenbank. Standardm\u00e4\u00dfig wird <code>h2<\/code> (alle Daten werden lokal gespeichert) verwendet, Sie k\u00f6nnen jedoch auch <code>postgres<\/code>, <code>mysql<\/code> oder <code>mariadb<\/code>.<br \/>\nWenn Sie dennoch Keycloak separat installieren m\u00f6chten, finden Sie detaillierte Anleitungen in <noindex><a rel=\"nofollow\" href=\"https:\/\/www.keycloak.org\/docs\/latest\/getting_started\/index.html\">offiziellen Dokumentation<\/a><\/noindex>.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-federacii\">Federationseinrichtung<\/h2>\n<p><\/p>\n<p>Zun\u00e4chst erstellen wir ein neues Realm. Ein Realm ist der Raum unserer Anwendung. Jede Anwendung kann ihr eigenes Realm mit unterschiedlichen Benutzern und Authentifizierungseinstellungen haben. Das Master-Realm wird von Keycloak selbst verwendet, und es w\u00e4re falsch, es f\u00fcr etwas anderes zu nutzen.<\/p>\n<p><\/p>\n<p>Klicken Sie auf <strong>Realm hinzuf\u00fcgen<\/strong><\/p>\n<p><\/p>\n<p>Option<br \/>\nValue<\/p>\n<p><strong>Name<\/strong><br \/>\n<code>kubernetes<\/code><\/p>\n<p><strong>Anzeigename<\/strong><br \/>\n<code>Kubernetes<\/code><\/p>\n<p><strong>HTML-Anzeigename<\/strong><br \/>\n<code>&lt;img src=&quot;https:\/\/kubernetes.io\/images\/nav_logo.svg&quot; width=&quot;400&quot; &gt;<\/code><\/p>\n<p><\/p>\n<p>Kubernetes \u00fcberpr\u00fcft standardm\u00e4\u00dfig, ob die E-Mail des Benutzers best\u00e4tigt ist oder nicht. Da wir einen eigenen LDAP-Server verwenden, wird diese \u00dcberpr\u00fcfung hier fast immer zur\u00fcckgeben <code>false<\/code>. Lassen Sie uns die Anzeige dieser Option in Kubernetes deaktivieren:<\/p>\n<p><\/p>\n<p><strong>Client-Bereiche<\/strong> \u2014&gt; <strong>E-Mail<\/strong> \u2014&gt; <strong>Mapper<\/strong> \u2014&gt; <strong>E-Mail verifiziert<\/strong> (L\u00f6schen)<\/p>\n<p><\/p>\n<p>Jetzt konfigurieren wir die F\u00f6deration, daf\u00fcr gehen wir zu:<\/p>\n<p><\/p>\n<p><strong>Benutzerf\u00f6deration<\/strong> \u2014&gt; <strong>Provider hinzuf\u00fcgen\u2026<\/strong> \u2014&gt; <strong>ldap<\/strong><\/p>\n<p><\/p>\n<p>Ich gebe ein Beispiel f\u00fcr die Konfiguration von FreeIPA:<\/p>\n<p><\/p>\n<p>Option<br \/>\nValue<\/p>\n<p><strong>Konsole Anzeigename<\/strong><br \/>\n<code>freeipa.example.org<\/code><\/p>\n<p><strong>Anbieter<\/strong><br \/>\n<code>Red Hat Verzeichnisdienst<\/code><\/p>\n<p><strong>UUID LDAP-Attribut<\/strong><br \/>\n<code>ipauniqueid<\/code><\/p>\n<p><strong>Verbindungs-URL<\/strong><br \/>\n<code>ldaps:\/\/freeipa.example.org<\/code><\/p>\n<p><strong>Benutzer-DN<\/strong><br \/>\n<code>cn=users,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>Bind DN<\/strong><br \/>\n<code>uid=keycloak-svc,cn=users,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>Bind Credential<\/strong><br \/>\n<code>&lt;password&gt;<\/code><\/p>\n<p><strong>Kerberos-Authentifizierung erlauben:<\/strong><br \/>\n<code>on<\/code><\/p>\n<p><strong>Kerberos-Realm:<\/strong><br \/>\n<code>EXAMPLE.ORG<\/code><\/p>\n<p><strong>Server Principal:<\/strong><br \/>\n<code>HTTP\/freeipa.example.org@EXAMPLE.ORG<\/code><\/p>\n<p><strong>KeyTab:<\/strong><br \/>\n<code>\/etc\/krb5.keytab<\/code><\/p>\n<p><\/p>\n<p>Benutzer <code>keycloak-svc<\/code> muss im Voraus auf unserem LDAP-Server erstellt werden.<\/p>\n<p><\/p>\n<p>Im Fall von Active Directory reicht es aus, einfach auszuw\u00e4hlen <strong>Anbieter: Active Directory<\/strong> und die erforderlichen Einstellungen werden automatisch in das Formular eingef\u00fcgt.<\/p>\n<p><\/p>\n<p>Klicken Sie auf <strong>), und klicken dann auf die Schaltfl\u00e4che<\/strong><\/p>\n<p><\/p>\n<p>Gehen wir nun weiter:<\/p>\n<p><\/p>\n<p><strong>Benutzerf\u00f6deration<\/strong> \u2014&gt; <strong>freeipa.example.org<\/strong> \u2014&gt; <strong>Mapper<\/strong> \u2014&gt; <strong>Vorname<\/strong><\/p>\n<p><\/p>\n<p>Option<br \/>\nValue<\/p>\n<p><strong>Ldap-Attribut<\/strong><br \/>\n<code>givenName<\/code><\/p>\n<p><\/p>\n<p>Aktivieren wir nun das Gruppenmapping:<\/p>\n<p><\/p>\n<p><strong>Benutzerf\u00f6deration<\/strong> \u2014&gt; <strong>freeipa.example.org<\/strong> \u2014&gt; <strong>Mapper<\/strong> \u2014&gt; <strong>Erstellen<\/strong><\/p>\n<p><\/p>\n<p>Option<br \/>\nValue<\/p>\n<p><strong>Name<\/strong><br \/>\n<code>Gruppen<\/code><\/p>\n<p><strong>Mapper-Typ<\/strong><br \/>\n<code>group-ldap-mapper<\/code><\/p>\n<p><strong>LDAP-Gruppen DN<\/strong><br \/>\n<code>cn=groups,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>Benutzergruppen-Abrufstrategie<\/strong><br \/>\n<code>GET_GROUPS_FROM_USER_MEMBEROF_ATTRIBUTE<\/code><\/p>\n<p><\/p>\n<p>Damit ist die Federation-Konfiguration beendet, wir gehen zur Kundeneinrichtung \u00fcber.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-klienta\">Client-Konfiguration<\/h2>\n<p><\/p>\n<p>Wir erstellen einen neuen Client (eine Anwendung, die Benutzer aus Keycloak abruft). Gehen wir weiter:<\/p>\n<p><\/p>\n<p><strong>Clients<\/strong> \u2014&gt; <strong>Erstellen<\/strong><\/p>\n<p><\/p>\n<p>Option<br \/>\nValue<\/p>\n<p><strong>Client-Geheimnis<\/strong><br \/>\n<code>kubernetes<\/code><\/p>\n<p><strong>Zugriffstyp<\/strong><br \/>\n<code>confidenzial<\/code><\/p>\n<p><strong>Root-URL<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/<\/code><\/p>\n<p><strong>G\u00fcltige Weiterleitungs-URIs<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/*<\/code><\/p>\n<p><strong>Admin-URL<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/<\/code><\/p>\n<p><\/p>\n<p>Wir erstellen auch einen Scope f\u00fcr Gruppen:<\/p>\n<p><\/p>\n<p><strong>Client-Scope<\/strong> \u2014&gt; <strong>Erstellen<\/strong><\/p>\n<p><\/p>\n<p>Option<br \/>\nValue<\/p>\n<p><strong>Vorlage<\/strong><br \/>\n<code>Kein Template<\/code><\/p>\n<p><strong>Name<\/strong><br \/>\n<code>Gruppen<\/code><\/p>\n<p><strong>Voller Gruppenspeicherpfad<\/strong><br \/>\n<code>false<\/code><\/p>\n<p><\/p>\n<p>Und wir konfigurieren den Mapper f\u00fcr sie:<\/p>\n<p><\/p>\n<p><strong>Client-Scope<\/strong> \u2014&gt; <strong>Gruppen<\/strong> \u2014&gt; <strong>Mapper<\/strong> \u2014&gt; <strong>Erstellen<\/strong><\/p>\n<p><\/p>\n<p>Option<br \/>\nValue<\/p>\n<p><strong>Name<\/strong><br \/>\n<code>Gruppen<\/code><\/p>\n<p><strong>Mapper-Typ<\/strong><br \/>\n<code>Gruppenmitgliedschaft<\/code><\/p>\n<p><strong>Token-Anspruchsname<\/strong><br \/>\n<code>Gruppen<\/code><\/p>\n<p><\/p>\n<p>Jetzt m\u00fcssen wir das Gruppenmapping in unserem Client-Scope aktivieren:<\/p>\n<p><\/p>\n<p><strong>Clients<\/strong> \u2014&gt; <strong>kubernetes<\/strong> \u2014&gt; <strong>Client-Scope<\/strong> \u2014&gt; <strong>Standard-Client-Scope<\/strong><\/p>\n<p><\/p>\n<p>W\u00e4hlen Sie <strong>Gruppen<\/strong> in <strong>Verf\u00fcgbare Client Scopes<\/strong>, dr\u00fccken Sie <strong>Ausgew\u00e4hlte hinzuf\u00fcgen<\/strong><\/p>\n<p><\/p>\n<p>Jetzt richten wir die Authentifizierung unserer Anwendung ein, weiter geht's:<\/p>\n<p><\/p>\n<p><strong>Clients<\/strong> \u2014&gt; <strong>kubernetes<\/strong><\/p>\n<p><\/p>\n<p>Option<br \/>\nValue<\/p>\n<p><strong>Autorisierung aktiviert<\/strong><br \/>\n<code>EIN<\/code><\/p>\n<p><\/p>\n<p>Dr\u00fccken wir auf <strong>speichern<\/strong> und damit ist die Konfiguration des Clients abgeschlossen, nun auf dem Tab<\/p>\n<p><\/p>\n<p><strong>Clients<\/strong> \u2014&gt; <strong>kubernetes<\/strong> \u2014&gt; <strong>Credentials<\/strong><\/p>\n<p><\/p>\n<p>wird es m\u00f6glich sein, <strong>Secret<\/strong> den wir sp\u00e4ter verwenden werden.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-kubernetes\">Kubernetes-Konfiguration<\/h2>\n<p><\/p>\n<p>Die Einrichtung von Kubernetes f\u00fcr OIDC-Authentifizierung ist recht trivial und nicht besonders komplex. Alles, was Sie ben\u00f6tigen, ist das CA-Zertifikat Ihres OIDC-Servers in <code>\/etc\/kubernetes\/pki\/oidc-ca.pem<\/code> zu hinterlegen und die notwendigen Optionen f\u00fcr kube-apiserver hinzuzuf\u00fcgen.<br \/>\nAktualisieren Sie daher <code>\/etc\/kubernetes\/manifests\/kube-apiserver.yaml<\/code> auf all Ihren Master-Servern:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">...<br>spec:<br>  containers:<br>  - command:<br>    - kube-apiserver<br>...\n    - --oidc-ca-file=\/etc\/kubernetes\/pki\/oidc-ca.pem<br>    - --oidc-client-id=kubernetes<br>    - --oidc-groups-claim=groups<br>    - --oidc-issuer-url=https:\/\/keycloak.example.org\/auth\/realms\/kubernetes<br>    - --oidc-username-claim=email<br>...<\/code><\/pre>\n<p><\/p>\n<p>Aktualisieren Sie auch die kubeadm-Konfiguration im Cluster, um diese Einstellungen bei einem Upgrade nicht zu verlieren:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">kubectl edit -n kube-system configmaps kubeadm-config<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"plaintext\">...<br>data:<br>  ClusterConfiguration: |<br>    apiServer:<br>      extraArgs:<br>        oidc-ca-file: \/etc\/kubernetes\/pki\/oidc-ca.pem<br>        oidc-client-id: kubernetes<br>        oidc-groups-claim: groups<br>        oidc-issuer-url: https:\/\/keycloak.example.org\/auth\/realms\/kubernetes<br>        oidc-username-claim: email<br>...<\/code><\/pre>\n<p><\/p>\n<p>Damit ist die Konfiguration von Kubernetes abgeschlossen. Sie k\u00f6nnen diese Schritte in all Ihren Kubernetes-Clustern wiederholen.<\/p>\n<p><\/p>\n<h2 id=\"nachalnaya-avtorizaciya\">Ersteinrichtung der Autorisierung<\/h2>\n<p><\/p>\n<p>Nach diesen Schritten haben Sie bereits einen Kubernetes-Cluster mit aktivierter OIDC-Autorisierung. Ein wichtiger Punkt ist, dass Ihre Benutzer derzeit keinen konfigurierten Client oder eigenen kubeconfig haben. Um dieses Problem zu l\u00f6sen, m\u00fcssen Sie die automatische Bereitstellung von kubeconfig f\u00fcr Benutzer nach erfolgreicher Autorisierung einrichten.<\/p>\n<p><\/p>\n<p>Hierf\u00fcr k\u00f6nnen spezielle Webanwendungen verwendet werden, die die Authentifizierung des Benutzers erm\u00f6glichen und dann das fertige kubeconfig zum Download bereitstellen. Eine der bequemsten Optionen ist <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/negz\/kuberos\">Kuberos<\/a><\/noindex>, er erm\u00f6glicht es, alle Kubernetes-Cluster in einer Konfiguration zu beschreiben und leicht zwischen ihnen zu wechseln.<\/p>\n<p><\/p>\n<p>F\u00fcr die Konfiguration von Kuberos m\u00fcssen Sie lediglich eine Vorlage f\u00fcr kubeconfig beschreiben und mit den folgenden Parametern starten:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">kuberos https:\/\/keycloak.example.org\/auth\/realms\/kubernetes kubernetes \/cfg\/secret \/cfg\/template<\/code><\/pre>\n<p><\/p>\n<p>F\u00fcr detailliertere Informationen siehe <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/negz\/kuberos#usage\">Nutzung<\/a><\/noindex> auf Github.<\/p>\n<p><\/p>\n<p>Es ist auch m\u00f6glich, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/int128\/kubelogin\">kubelogin<\/a><\/noindex> zu verwenden, wenn Sie die Authentifizierung direkt auf dem Benutzercomputer durchf\u00fchren m\u00f6chten. In diesem Fall wird dem Benutzer ein Browser mit dem Authentifizierungsformular auf localhost ge\u00f6ffnet.<\/p>\n<p><\/p>\n<p>Der erhaltene kubeconfig kann auf der Website \u00fcberpr\u00fcft werden <noindex><a rel=\"nofollow\" href=\"https:\/\/jwt.io\/#debugger-io\">jwt.io<\/a><\/noindex>. Kopieren Sie einfach den Wert <code>users[].user.auth-provider.config.id-token<\/code> aus Ihrem kubeconfig in das Formular auf der Website und Sie erhalten sofort die Entschl\u00fcsselung.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-rbac\">RBAC-Konfiguration<\/h2>\n<p><\/p>\n<p>Bei der Konfiguration von RBAC kann sowohl auf den Benutzernamen (Feld <code>name<\/code> im jwt-Token) als auch auf die Benutzergruppe (Feld <code>Gruppen<\/code> im jwt-Token) verwiesen werden. Hier ein Beispiel f\u00fcr die Rechtevergabe an die Gruppe <code>kubernetes-default-namespace-admins<\/code>:<\/p>\n<p>\n<b class=\"spoiler_title\">kubernetes-default-namespace-admins.yaml<\/b><\/p>\n<pre><code class=\"plaintext\">apiVersion: rbac.authorization.k8s.io\/v1\nkind: Role\nmetadata:\n  name: default-admins\n  namespace: default\nrules:\n- apiGroups:\n  - '*'\n  resources:\n  - '*'\n  verbs:\n  - '*'\n---\napiVersion: rbac.authorization.k8s.io\/v1\nkind: RoleBinding\nmetadata:\n  name: kubernetes-default-namespace-admins\n  namespace: default\nroleRef:\n  apiGroup: rbac.authorization.k8s.io\n  kind: Role\n  name: default-admins\nsubjects:\n- apiGroup: rbac.authorization.k8s.io\n  kind: Group\n  name: kubernetes-default-namespace-admins<\/code><\/pre>\n<p><\/p>\n<p>Weitere Beispiele f\u00fcr RBAC finden Sie unter <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/reference\/access-authn-authz\/rbac\/\">der offiziellen Kubernetes-Dokumentation<\/a><\/noindex><\/p>\n<p><\/p>\n<h2 id=\"nastroyka-auth-proxy\">Einrichtung des Auth-Proxys<\/h2>\n<p><\/p>\n<p>Es gibt ein gro\u00dfartiges Projekt <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/keycloak\/keycloak-gatekeeper\">keycloak-gatekeeper<\/a><\/noindex>, das es erm\u00f6glicht, jede Anwendung zu sichern, indem es dem Benutzer die Authentifizierung \u00fcber einen OIDC-Server erm\u00f6glicht. Ich zeige Ihnen, wie Sie es am Beispiel des Kubernetes Dashboards einrichten k\u00f6nnen:<\/p>\n<p>\n<b class=\"spoiler_title\">dashboard-proxy.yaml<\/b><\/p>\n<pre><code class=\"plaintext\">apiVersion: extensions\/v1beta1\nkind: Deployment\nmetadata:\n  name: kubernetes-dashboard-proxy\nspec:\n  replicas: 1\n  template:\n    metadata:\n      labels:\n        app: kubernetes-dashboard-proxy\n    spec:\n      containers:\n      - args:\n        - --listen=0.0.0.0:80\n        - --discovery-url=https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\n        - --client-id=kubernetes\n        - --client-secret=\n        - --redirection-url=https:\/\/kubernetes-dashboard.example.org\n        - --enable-refresh-tokens=true\n        - --encryption-key=ooTh6Chei1eefooyovai5ohwienuquoh\n        - --upstream-url=https:\/\/kubernetes-dashboard.kube-system\n        - --resources=uri=\/*\n        image: keycloak\/keycloak-gatekeeper\n        name: kubernetes-dashboard-proxy\n        ports:\n        - containerPort: 80\n          livenessProbe:\n            httpGet:\n              path: \/oauth\/health\n              port: 80\n            initialDelaySeconds: 3\n            timeoutSeconds: 2\n          readinessProbe:\n            httpGet:\n              path: \/oauth\/health\n              port: 80\n            initialDelaySeconds: 3\n            timeoutSeconds: 2\n---\napiVersion: v1\nkind: Service\nmetadata:\n  name: kubernetes-dashboard-proxy\nspec:\n  ports:\n  - port: 80\n    protocol: TCP\n    targetPort: 80\n  selector:\n    app: kubernetes-dashboard-proxy\n  type: ClusterIP<\/code><\/pre>\n<p>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/441112\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Keycloak \u043c\u043e\u0436\u043d\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c Kubernetes \u0441 \u0432\u0430\u0448\u0438\u043c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0438\u043c\u043f\u043e\u0440\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0433\u0440\u0443\u043f\u043f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c auth-proxy \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c Kubernetes Dashboard \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0447\u0442\u043e \u0443 \u0432\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c Active [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":70868,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-70867","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Keycloak \u043c\u043e\u0436\u043d\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c Kubernetes \u0441 \u0432\u0430\u0448\u0438\u043c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0438\u043c\u043f\u043e\u0440\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0433\u0440\u0443\u043f\u043f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c auth-proxy \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c Kubernetes Dashboard \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0447\u0442\u043e \u0443 \u0432\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c Active\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c LDAP-\u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Keycloak \u043c\u043e\u0436\u043d\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c Kubernetes \u0441 \u0432\u0430\u0448\u0438\u043c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0438\u043c\u043f\u043e\u0440\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0433\u0440\u0443\u043f\u043f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c auth-proxy \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c Kubernetes Dashboard \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0447\u0442\u043e \u0443 \u0432\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c Active\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-22T03:40:58+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-03T13:14:36+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Integration der LDAP-Authentifizierung in Kubernetes | ProHoster","description":"Eine kurze Anleitung, wie Sie mit Keycloak Kubernetes mit Ihrem LDAP-Server verbinden und den Import von Benutzern und Gruppen konfigurieren k\u00f6nnen. Dies erm\u00f6glicht die Einrichtung von RBAC f\u00fcr Ihre Benutzer und die Verwendung eines Auth-Proxys, um das Kubernetes Dashboard und andere Anwendungen zu sch\u00fctzen, die keine eigene Authentifizierung durchf\u00fchren k\u00f6nnen. Installation von Keycloak Angenommen, Sie haben bereits einen LDAP-Server. Dies kann Active sein.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c LDAP-\u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes | ProHoster","og:description":"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Keycloak \u043c\u043e\u0436\u043d\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c Kubernetes \u0441 \u0432\u0430\u0448\u0438\u043c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0438\u043c\u043f\u043e\u0440\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0433\u0440\u0443\u043f\u043f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c auth-proxy \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c Kubernetes Dashboard \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0447\u0442\u043e \u0443 \u0432\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c Active","og:url":"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-22T03:40:58+00:00","article:modified_time":"2020-03-03T13:14:36+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"70867","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:12:23","updated":"2022-09-28 01:58:51"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/70867","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=70867"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/70867\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media\/70868"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=70867"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=70867"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=70867"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}