{"id":70869,"date":"2020-02-22T06:41:02","date_gmt":"2020-02-22T03:41:02","guid":{"rendered":"https:\/\/prohoster.info\/blog\/prikruchivaem-activedirectory-avtorizacziyu-k-kubernetes-c-pomoshhyu-keycloak"},"modified":"2020-03-03T16:14:37","modified_gmt":"2020-03-03T13:14:37","slug":"prikruchivaem-activedirectory-avtorizacziyu-k-kubernetes-c-pomoshhyu-keycloak","status":"publish","type":"post","link":"https:\/\/prohoster.info\/et\/blog\/administrirovanie\/prikruchivaem-activedirectory-avtorizacziyu-k-kubernetes-c-pomoshhyu-keycloak","title":{"rendered":"Lisame ActiveDirectory autentimise Kubernetesesse Keycloak'i kaudu","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u0414\u0430\u043d\u043d\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0430 \u0441 \u0446\u0435\u043b\u044c\u044e \u0440\u0430\u0441\u0448\u0438\u0440\u0438\u0442\u044c \u0443\u0436\u0435 <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/441112\/\">\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0449\u0443\u044e<\/a><\/noindex>, \u043d\u043e \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442 \u043f\u0440\u043e \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0441\u0432\u044f\u0437\u043a\u0438 \u0438\u043c\u0435\u043d\u043d\u043e \u0441 Microsoft ActiveDirectory, \u0430 \u0442\u0430\u043a \u0436\u0435 \u0434\u043e\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u0435\u0435.<\/p>\n<p>\u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u044f \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0443 \u043a\u0430\u043a \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c:<\/p>\n<ul>\n<li><b>Keycloak <\/b> \u2014 \u044d\u0442\u043e \u043f\u0440\u043e\u0435\u043a\u0442 \u0441 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u043c \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u043c \u043a\u043e\u0434\u043e\u043c. \u041a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u0435\u0434\u0438\u043d\u0443\u044e \u0442\u043e\u0447\u043a\u0443 \u0432\u0445\u043e\u0434\u0430 \u0434\u043b\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439. \u0420\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0441 \u043c\u043d\u043e\u0436\u0435\u0441\u0442\u0432\u043e\u043c \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0441 LDAP \u0438 OpenID \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0430\u0441 \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u0443\u044e\u0442.<\/li>\n<li><b>Keycloak gatekeeper<\/b> \u2014 \u0440\u0435\u0432\u0435\u0440\u0441 \u043f\u0440\u043e\u043a\u0441\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0435 \u0438\u043d\u0442\u0435\u0433\u0440\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0438\u044e \u0447\u0435\u0440\u0435\u0437 Keycloak.<\/li>\n<li><b>Gangway <\/b> \u2014 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u043a\u043e\u0442\u043e\u0440\u0435 \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u0442 \u043a\u043e\u043d\u0444\u0438\u0433 \u0434\u043b\u044f kubectl \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u0447\u0435\u0440\u0435\u0437 OpenID \u043c\u043e\u0436\u043d\u043e \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c\u0441\u044f \u043a Kubernetes API.<\/li>\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h3>\u041a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0442 \u043f\u0440\u0430\u0432\u0430 \u0432 Kubernetes.<\/h3>\n<p>\n\u0423\u043f\u0440\u0430\u0432\u043b\u044f\u0442\u044c \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\/\u0433\u0440\u0443\u043f\u043f \u043c\u044b \u043c\u043e\u0436\u0435\u043c \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e RBAC, \u043e\u0431 \u044d\u0442\u043e\u043c \u0441\u043e\u0437\u0434\u0430\u043d\u043e \u0443\u0436\u0435 \u043a\u0443\u0447\u0443 \u0441\u0442\u0430\u0442\u0435\u0439, \u043d\u0435 \u0431\u0443\u0434\u0443 \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u043e \u043d\u0430 \u044d\u0442\u043e\u043c \u043e\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0442\u044c\u0441\u044f. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432 \u0442\u043e\u043c \u0447\u0442\u043e \u0432\u044b \u043c\u043e\u0436\u0435\u0442\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f RBAC \u0434\u043b\u044f \u0442\u043e\u0433\u043e \u0447\u0442\u043e \u0431\u044b \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u043d\u043e Kubernetes \u043d\u0435 \u0447\u0435\u0433\u043e \u043d\u0435 \u0437\u043d\u0430\u0435\u0442 \u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u0445. \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u0442\u0441\u044f \u0447\u0442\u043e \u043d\u0443\u0436\u0435\u043d \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c \u0434\u043e\u0441\u0442\u0430\u0432\u043a\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0432 Kubernetes. \u0414\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u043c\u044b \u0434\u043e\u0431\u0430\u0432\u0438\u043c \u0432 Kuberntes OpenID \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0438 \u0431\u0443\u0434\u0435\u0442 \u0433\u043e\u0432\u043e\u0440\u0438\u0442\u044c \u043e \u0442\u043e\u043c \u0447\u0442\u043e \u0442\u0430\u043a\u043e\u0439 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0442\u0435\u043b\u044c\u043d\u043e \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u0435\u0442, \u0430 \u043f\u0440\u0430\u0432\u0430 \u0435\u043c\u0443 \u0443\u0436\u0435 \u0432\u044b\u0434\u0430\u0441\u0442 \u0441\u0430\u043c Kubernetes.<\/p>\n<p><b>\u041f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043a\u0430<\/b><\/p>\n<ul>\n<li>\u0412\u0430\u043c \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u0442\u0441\u044f Kubernetes \u043a\u043b\u0430\u0441\u0442\u0435\u0440 \u0438\u043b\u0438 minikube<\/li>\n<li>Active Directory<\/li>\n<li>\u0414\u043e\u043c\u0435\u043d\u044b:<br \/>\n keycloak.example.org<br \/>\n kubernetes-dashboard.example.org<br \/>\n gangway.example.org<\/li>\n<li>\u0421\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u0434\u043b\u044f \u0434\u043e\u043c\u0435\u043d\u043e\u0432 \u0438\u043b\u0438 \u0441\u0430\u043c\u043e\u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0439 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442<\/li>\n<\/ul>\n<p>\n\u041f\u043e\u0434\u0440\u043e\u0431\u043d\u043e \u043e\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0442\u044c\u0441\u044f \u043d\u0430 \u0442\u043e\u043c \u043a\u0430\u043a \u0441\u043e\u0437\u0434\u0430\u0432\u0430\u0442\u044c \u0441\u0430\u043c\u043e\u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0435 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u044f \u043d\u0435 \u0431\u0443\u0434\u0443, \u043d\u0430\u0434\u043e \u0441\u043e\u0437\u0434\u0430\u0442\u044c 2 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430, \u044d\u0442\u043e \u043a\u043e\u0440\u043d\u0435\u0432\u043e\u0439(\u0426\u0435\u043d\u0442\u0440 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438) \u0438 wildcard \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u0438\u0439 \u0434\u043b\u044f \u0434\u043e\u043c\u0435\u043d\u0430 *.example.org<\/p>\n<p>\u041f\u043e\u0441\u043b\u0435 \u0442\u043e\u0433\u043e \u043a\u0430\u043a \u0432\u044b \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u0435\/\u0432\u044b\u043f\u0438\u0448\u0438\u0442\u0435 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u044b, \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u0438\u0439 \u043d\u0430\u0434\u043e \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c \u0432 Kubernetes, \u0434\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u0441\u043e\u0437\u0434\u0430\u0435\u043c \u0434\u043b\u044f \u043d\u0435\u0433\u043e secret:<\/p>\n<pre><code class=\"bash\">kubectl create secret tls tls-keycloak --cert=example.org.crt --key=example.org.pem<\/code><\/pre>\n<p>\n\u0414\u0430\u043b\u0435\u0435 \u043c\u044b \u0431\u0443\u0434\u0435\u0442 \u0435\u0433\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u043b\u044f \u043d\u0430\u0448\u0435\u0433\u043e Ingress \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u0430<\/p>\n<h3>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak<\/h3>\n<p>\n\u042f \u0440\u0435\u0448\u0438\u043b \u0447\u0442\u043e \u043f\u0440\u043e\u0449\u0435 \u0432\u0441\u0435\u0433\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0433\u043e\u0442\u043e\u0432\u044b\u0435 \u0440\u0435\u0448\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u044d\u0442\u043e\u0433\u043e, \u0430 \u0438\u043c\u0435\u043d\u043d\u043e helm chart-\u044b.<\/p>\n<p>\u0423\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u043c \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0439 \u0438 \u043e\u0431\u043d\u043e\u0432\u043b\u044f\u0435\u043c \u0435\u0433\u043e:<\/p>\n<pre><code class=\"bash\">helm repo add codecentric https:\/\/codecentric.github.io\/helm-charts\nhelm repo update<\/code><\/pre>\n<p>\n\u0421\u043e\u0437\u0434\u0430\u0435\u043c \u0444\u0430\u0439\u043b keycloak.yml c\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u044b\u043c:<\/p>\n<p><b class=\"spoiler_title\">keycloak.yml<\/b><\/p>\n<pre><code class=\"plaintext\">keycloak:\n  # \u0418\u043c\u044f \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u0430\n  username: &quot;test_admin&quot;\n  # \u041f\u0430\u0440\u043e\u043b\u044c \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440  \n  password: &quot;admin&quot;\n  # \u042d\u0442\u0438 \u0444\u043b\u0430\u0433\u0438 \u043d\u0443\u0436\u043d\u044b \u0447\u0442\u043e \u0431\u044b \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442\u044c \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0442\u044c \u0432 Keycloak \u0441\u043a\u0440\u0438\u043f\u0442\u044b \u043f\u0440\u044f\u043c\u043e \u0447\u0435\u0440\u0435\u0437 web \u043c\u043e\u0440\u0434\u0443. \u042d\u0442\u043e \u043d\u0430\u043c \n  \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0447\u0442\u043e \u0431\u044b \u043f\u043e\u0447\u0438\u043d\u0438\u0442\u044c \u043e\u0434\u0438\u043d \u0431\u0430\u0433, \u043e \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043d\u0438\u0436\u0435.\n  extraArgs: &quot;-Dkeycloak.profile.feature.script=enabled -Dkeycloak.profile.feature.upload_scripts=enabled&quot; \n  # \u0412\u043a\u043b\u044e\u0447\u0430\u0435\u043c ingress, \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u0438\u043c\u044f \u0445\u043e\u0441\u0442\u0430 \u0438 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043c\u044b \u043f\u0440\u0435\u0434\u0432\u0430\u0440\u0438\u0442\u0435\u043b\u044c\u043d\u043e \u0441\u043e\u0445\u0440\u0430\u043d\u0438\u043b\u0438 \u0432 secrets\n  ingress:\n    enabled: true \n    path: \/\n    annotations:\n      kubernetes.io\/ingress.class: nginx\n      ingress.kubernetes.io\/affinity: cookie\n    hosts:\n      - keycloak.example.org\n    tls:\n    - hosts:\n        - keycloak.example.org\n      secretName: tls-keycloak\n  # Keycloak \u0434\u043b\u044f \u0441\u0432\u043e\u0435\u0439 \u0440\u0430\u0431\u043e\u0442\u044b \u0442\u0440\u0435\u0431\u0443\u0435\u0442 \u0431\u0430\u0437\u0443 \u0434\u0430\u043d\u043d\u044b\u0445, \u0432 \u0442\u0435\u0441\u0442\u043e\u0432\u044b\u0445 \u0446\u0435\u043b\u044f\u0445 \u044f \u0440\u0430\u0437\u0432\u043e\u0440\u0430\u0447\u0438\u0432\u0430\u044e Postgresql \u043f\u0440\u044f\u043c\u043e \u0432 Kuberntes, \u0432 \u043f\u0440\u043e\u0434\u0430\u043a\u0448\u0435\u043d\u0435 \u0442\u0430\u043a \u043b\u0443\u0447\u0448\u0435 \u043d\u0435 \u0434\u0435\u043b\u0430\u0442\u044c!\n  persistence:\n    deployPostgres: true\n    dbVendor: postgres\n\npostgresql:\n  postgresUser: keycloak\n  postgresPassword: &quot;&quot;\n  postgresDatabase: keycloak\n  persistence:\n    enabled: true<\/code><\/pre>\n<h3>\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u0444\u0435\u0434\u0435\u0440\u0430\u0446\u0438\u0438<\/h3>\n<p>\n\u0414\u0430\u043b\u0435\u0435 \u0437\u0430\u0445\u043e\u0434\u0438\u043c \u0432 \u0432\u0435\u0431 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 <noindex><a rel=\"nofollow\" href=\"https:\/\/keycloak.example.org\/\" rel=\"nofollow\">keycloak.example.org<\/a><\/noindex><\/p>\n<p>\u0412 \u043b\u0435\u0432\u043e\u043c \u0443\u0433\u043b\u0443 \u043d\u0430\u0436\u0438\u043c\u0430\u0435\u043c <b>Add realm<\/b><\/p>\n<p>Key<br \/>\nValue<\/p>\n<p>Name<br \/>\nkubernetes<\/p>\n<p>Display Name<br \/>\nKubernetes<\/p>\n<p>\n\u041e\u0442\u043a\u043b\u044e\u0447\u0430\u0435\u043c \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0443 \u043f\u043e\u0434\u0442\u0432\u0435\u0440\u0436\u0434\u0435\u043d\u0438\u044f email \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f:<br \/>\n<b>Client scopes &#8212;&gt; Email &#8212;&gt; Mappers &#8212;&gt; Email verified (Delete)<\/b><\/p>\n<p>\u041d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c \u0444\u0435\u0434\u0435\u0440\u0430\u0446\u0438\u044e \u0434\u043b\u044f \u0438\u043c\u043f\u043e\u0440\u0442\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 ActiveDirectory, \u044f \u043e\u0441\u0442\u0430\u0432\u043b\u044e \u043d\u0438\u0436\u0435 \u0441\u043a\u0440\u0438\u043d\u0448\u043e\u0442\u044b \u0434\u0443\u043c\u0430\u044e \u0442\u0430\u043a \u0431\u0443\u0434\u0435\u0442 \u043f\u043e\u043d\u044f\u0442\u043d\u0435\u0439.<\/p>\n<p><b>User federation &#8212;&gt; Add provider\u2026 &#8212;&gt; ldap<\/b><\/p>\n<p><b class=\"spoiler_title\">\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u0444\u0435\u0434\u0435\u0440\u0430\u0446\u0438\u0438<\/b><img decoding=\"async\" alt=\"\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c ActiveDirectory \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes c \u043f\u043e\u043c\u043e\u0449\u044c\u044e Keycloak\" src=\"\/wp-content\/uploads\/2020\/02\/97baf4be6c99c75320cc3ba6ea6bf329.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<img decoding=\"async\" alt=\"\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c ActiveDirectory \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes c \u043f\u043e\u043c\u043e\u0449\u044c\u044e Keycloak\" src=\"\/wp-content\/uploads\/2020\/02\/02e226425bd69c9529f06e3d211355b5.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n\u0415\u0441\u043b\u0438 \u0432\u0441\u0435 \u0445\u043e\u0440\u043e\u0448\u043e, \u0442\u043e \u043f\u043e\u0441\u043b\u0435 \u043d\u0430\u0436\u0430\u0442\u0438\u044f \u043a\u043d\u043e\u043f\u043a\u0438 <b>Synchronize all users<\/b> \u0432\u044b \u0443\u0432\u0435\u0434\u0438\u0442\u0435 \u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u0435 \u043e\u0431 \u0443\u0441\u043f\u0435\u0448\u043d\u043e\u043c \u0438\u043c\u043f\u043e\u0440\u0442\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439.<\/p>\n<p>\u0414\u0430\u043b\u0435\u0435 \u043d\u0430\u0434\u043e \u0437\u0430\u043c\u0430\u043f\u0438\u0442\u044c \u043d\u0430\u0448\u0438 \u0433\u0440\u0443\u043f\u043f\u044b<\/p>\n<p><b>User federation &#8212;&gt; ldap_localhost &#8212;&gt; Mappers &#8212;&gt; Create<\/b><\/p>\n<p><b class=\"spoiler_title\">\u0421\u043e\u0437\u0434\u0430\u043d\u0438\u0435 \u043c\u0430\u043f\u043f\u0435\u0440\u0430<\/b><img decoding=\"async\" alt=\"\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c ActiveDirectory \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes c \u043f\u043e\u043c\u043e\u0449\u044c\u044e Keycloak\" src=\"\/wp-content\/uploads\/2020\/02\/9cbb3338f0602f18142bfef0550e94f0.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u043a\u043b\u0438\u0435\u043d\u0442\u0430<\/h3>\n<p>\n\u041d\u0430\u0434\u043e \u0441\u043e\u0437\u0434\u0430\u0442\u044c \u043a\u043b\u0438\u0435\u043d\u0442\u0430, \u0432 \u043f\u043e\u043d\u044f\u0442\u0438\u044f\u0445 Keycloak \u044d\u0442\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u0431\u0443\u0434\u0435\u0442 \u0443 \u043d\u0435\u0433\u043e \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u043e\u0432\u044b\u0432\u0430\u0442\u044c\u0441\u044f. \u0412\u0430\u0436\u043d\u044b\u0435 \u043f\u0443\u043d\u043a\u0442\u044b \u0432\u044b\u0434\u0435\u043b\u044e \u043d\u0430 \u0441\u043a\u0440\u0438\u043d\u0448\u043e\u0442\u0435 \u043a\u0440\u0430\u0441\u043d\u044b\u043c.<\/p>\n<p><b>Clients &#8212;&gt; Create<\/b><\/p>\n<p><b class=\"spoiler_title\">\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u043a\u043b\u0438\u0435\u043d\u0442\u0430<\/b><img decoding=\"async\" alt=\"\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c ActiveDirectory \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes c \u043f\u043e\u043c\u043e\u0449\u044c\u044e Keycloak\" src=\"\/wp-content\/uploads\/2020\/02\/3dfa15ac02ffcd645c48d3397cdf35f5.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n\u0421\u043e\u0437\u0434\u0430\u0434\u0438\u043c scoupe \u0434\u043b\u044f \u0433\u0440\u0443\u043f\u043f:<\/p>\n<p><b>Client Scopes &#8212;&gt; Create<\/b><\/p>\n<p><b class=\"spoiler_title\">\u0421\u043e\u0437\u0434\u0430\u043d\u0438\u0435 scoupe<\/b><img decoding=\"async\" alt=\"\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c ActiveDirectory \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes c \u043f\u043e\u043c\u043e\u0449\u044c\u044e Keycloak\" src=\"\/wp-content\/uploads\/2020\/02\/4a7075623075f4e20f453e39fd68dd8c.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n\u0418 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u043c mapper \u0434\u043b\u044f \u043d\u0438\u0445:<\/p>\n<p><b>Client Scopes &#8212;&gt; groups &#8212;&gt; Mappers &#8212;&gt; Create<\/b><\/p>\n<p><b class=\"spoiler_title\">\u041c\u0430\u043f\u043f\u0435\u0440<\/b><img decoding=\"async\" alt=\"\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c ActiveDirectory \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes c \u043f\u043e\u043c\u043e\u0449\u044c\u044e Keycloak\" src=\"\/wp-content\/uploads\/2020\/02\/988475b6484e92c8e9af55cbbe395418.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n\u0414\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u043c \u043c\u0430\u043f\u043f\u0438\u043d\u0433 \u043d\u0430\u0448\u0438\u0445 \u0433\u0440\u0443\u043f\u043f \u0432 Default Client Scopes:<\/p>\n<p><b>Clients &#8212;&gt; kubernetes &#8212;&gt; Client Scopes &#8212;&gt; Default Client Scopes<\/b><br \/>\n\u0412\u044b\u0431\u0438\u0440\u0430\u0435\u043c <b>groups<\/b> \u0432 <b>Available Client Scopes<\/b>, \u043d\u0430\u0436\u0438\u043c\u0430\u0435\u043c <b>Add selected<\/b><\/p>\n<p>\u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c secret(\u0438 \u0437\u0430\u043f\u0438\u0441\u044b\u0432\u0430\u0435\u043c \u0435\u0433\u043e \u043a\u0443\u0434\u0430 \u043d\u0438\u0442\u044c) \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u043b\u044f \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 \u0432 Keycloak:<\/p>\n<p><b>Clients &#8212;&gt; kubernetes &#8212;&gt; Credentials &#8212;&gt; Secret<\/b><br \/>\n\u041d\u0430 \u044d\u0442\u043e\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u043e\u043a\u043e\u043d\u0447\u0435\u043d\u0430, \u043d\u043e \u0443 \u043c\u0435\u043d\u044f \u0432\u043e\u0437\u043d\u0438\u043a\u043b\u0430 \u043e\u0448\u0438\u0431\u043a\u0430 \u043a\u043e\u0433\u0434\u0430 \u043f\u043e\u0441\u043b\u0435 \u0443\u0441\u043f\u0435\u0448\u043d\u043e\u0439 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 \u044f \u043f\u043e\u043b\u0443\u0447\u0430\u043b \u043e\u0448\u0438\u0431\u043a\u0443 403. <noindex><a rel=\"nofollow\" href=\"https:\/\/issues.redhat.com\/browse\/KEYCLOAK-8954\" rel=\"nofollow\">\u0411\u0430\u0433 \u0440\u0435\u043f\u043e\u0440\u0442<\/a><\/noindex>. <\/p>\n<p>\u0424\u0438\u043a\u0441:<\/p>\n<p><b>Client Scopes &#8212;&gt; roles &#8212;&gt; Mappers &#8212;&gt; Create<\/b><\/p>\n<p><b class=\"spoiler_title\">Mapper<\/b><img decoding=\"async\" alt=\"\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c ActiveDirectory \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes c \u043f\u043e\u043c\u043e\u0449\u044c\u044e Keycloak\" src=\"\/wp-content\/uploads\/2020\/02\/622df845ec0d8a2f3864495e275b988b.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b class=\"spoiler_title\">\u041a\u043e\u0434 \u0441\u043a\u0440\u0438\u043f\u0442\u0430<\/b><\/p>\n<pre><code class=\"javascript\">\/\/ add current client-id to token audience\ntoken.addAudience(token.getIssuedFor());\n\n\/\/ return token issuer as dummy result assigned to iss again\ntoken.getIssuer();\n<\/code><\/pre>\n<h2>\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 Kubernetes<\/h2>\n<p>\n\u041d\u0430\u043c \u043d\u0430\u0434\u043e \u0443\u043a\u0430\u0437\u0430\u0442\u044c \u0433\u0434\u0435 \u043b\u0435\u0436\u0438\u0442 \u043d\u0430\u0448 \u043a\u043e\u0440\u043d\u0435\u0432\u043e\u0439 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u043e\u0442 \u0441\u0430\u0439\u0442\u0430, \u0438 \u0433\u0434\u0435 \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u044c\u0441\u044f \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440 OIDC.<br \/>\n\u0414\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u0440\u0435\u0434\u0430\u043a\u0442\u0438\u0440\u0443\u0435\u043c \u0444\u0430\u0439\u043b \/etc\/kubernetes\/manifests\/kube-apiserver.yaml<\/p>\n<p><b class=\"spoiler_title\">kube-apiserver.yaml<\/b><\/p>\n<pre><code class=\"bash\">\n...\nspec:\n  containers:\n  - command:\n    - kube-apiserver\n...\n    - --oidc-ca-file=\/var\/lib\/minikube\/certs\/My_Root.crt\n    - --oidc-client-id=kubernetes\n    - --oidc-groups-claim=groups\n    - --oidc-issuer-url=https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\n    - --oidc-username-claim=email\n...\n<\/code><\/pre>\n<p>\u041e\u0431\u043d\u043e\u0432\u043b\u044f\u0435\u043c kubeadm \u043a\u043e\u043d\u0444\u0438\u0433 \u0432 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0435:<\/p>\n<p><b class=\"spoiler_title\">kubeadm config<\/b><\/p>\n<pre><code class=\"bash\">kubectl edit -n kube-system configmaps kubeadm-config<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"bash\">\n...\ndata:\n  ClusterConfiguration: |\n    apiServer:\n      extraArgs:\n        oidc-ca-file: \/var\/lib\/minikube\/certs\/My_Root.crt\n        oidc-client-id: kubernetes\n        oidc-groups-claim: groups\n        oidc-issuer-url: https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\n        oidc-username-claim: email\n...\n<\/code><\/pre>\n<h2>\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 auth-proxy<\/h2>\n<p>\n\u0414\u043b\u044f \u0437\u0430\u0449\u0438\u0442\u044b \u0432\u0430\u0448\u0435\u0433\u043e \u0432\u0435\u0431 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c keycloak gatekeeper. \u041f\u043e\u043c\u0438\u043c\u043e \u0442\u043e\u0433\u043e \u0447\u0442\u043e \u0434\u0430\u043d\u043d\u044b\u0439 \u0440\u0435\u0432\u0435\u0440\u0441 \u043f\u0440\u043e\u043a\u0441\u0438 \u0431\u0443\u0434\u0435\u0442 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u043f\u0435\u0440\u0435\u0434 \u0442\u0435\u043c \u043a\u0430\u043a \u043f\u043e\u043a\u0430\u0437\u0430\u0442\u044c \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0443, \u0434\u0430\u043a \u0435\u0449\u0435 \u0438 \u043f\u0435\u0440\u0435\u0434\u0430\u0432\u0430\u0442\u044c \u043a\u043e\u043d\u0435\u0447\u043d\u043e\u043c\u0443 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044e \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e \u0432\u0430\u0441 \u0432 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0430\u0445. \u0422\u0435\u043c \u0441\u0430\u043c\u044b\u043c \u0435\u0441\u043b\u0438 \u0432\u0430\u0448\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u0442 OpenID, \u0442\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0441\u0440\u0430\u0437\u0443 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0443\u0435\u0442\u0441\u044f. \u0420\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u043d\u0430 \u043f\u0440\u0438\u043c\u0435\u0440\u0435 Kubernetes Dashboard<\/p>\n<h3>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Kubernetes Dashboard<\/h3>\n<p><\/p>\n<pre><code class=\"bash\">\nhelm install stable\/kubernetes-dashboard --name dashboard -f values_dashboard.yaml\n<\/code><\/pre>\n<p>\n<b class=\"spoiler_title\">values_dashboard.yaml<\/b><\/p>\n<pre><code class=\"bash\">enableInsecureLogin: true\nservice:\n  externalPort: 80\nrbac:\n  clusterAdminRole: true\n  create: true\nserviceAccount:\n  create: true\n  name: 'dashboard-test'\n<\/code><\/pre>\n<h3>\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u043f\u0440\u0430\u0432 \u0434\u043e\u0441\u0442\u0443\u043f\u0430:<\/h3>\n<p>\n\u0421\u043e\u0437\u0434\u0430\u0434\u0438\u043c ClusterRoleBinding \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u0443\u0434\u0435\u0442 \u0434\u0430\u0432\u0430\u0442\u044c \u043f\u0440\u0430\u0432\u0430 \u0430\u0434\u043c\u0438\u043d\u0430 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0430(\u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u0430\u044f ClusterRole cluster-admin) \u0434\u043b\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0441\u043e\u0441\u0442\u043e\u044f\u0449\u0438\u0445 \u0432 \u0433\u0440\u0443\u043f\u043f\u0435 DataOPS.<\/p>\n<pre><code class=\"bash\">\nkubectl apply -f rbac.yaml\n<\/code><\/pre>\n<p>\n<b class=\"spoiler_title\">rbac.yaml<\/b><\/p>\n<pre><code class=\"bash\">\napiVersion: rbac.authorization.k8s.io\/v1\nkind: ClusterRoleBinding\nmetadata:\n  name: dataops_group\nroleRef:\n  apiGroup: rbac.authorization.k8s.io\n  kind: ClusterRole\n  name: cluster-admin\nsubjects:\n- apiGroup: rbac.authorization.k8s.io\n  kind: Group\n  name: DataOPS\n<\/code><\/pre>\n<h3>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 keycloak gatekeeper:<\/h3>\n<p><\/p>\n<pre><code class=\"bash\">\nhelm repo add gabibbo97 https:\/\/gabibbo97.github.io\/charts\/\nhelm repo update\nhelm install gabibbo97\/keycloak-gatekeeper --version 2.1.0 --name keycloak-gatekeeper -f values_proxy.yaml\n<\/code><\/pre>\n<p>\n<b class=\"spoiler_title\">values_proxy.yaml<\/b><\/p>\n<pre><code class=\"bash\">\n\n# \u0412\u043a\u043b\u044e\u0447\u0430\u0435\u043c ingress\ningress:\n  enabled: true\n  annotations:\n    kubernetes.io\/ingress.class: nginx\n  path: \/\n  hosts:\n    - kubernetes-dashboard.example.org\n  tls:\n   - secretName: tls-keycloak\n     hosts:\n       - kubernetes-dashboard.example.org\n\n# \u0413\u043e\u0432\u043e\u0440\u0438\u043c \u0433\u0434\u0435 \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u043e\u0432\u044b\u0432\u0430\u0442\u044c\u0441\u044f \u0443 OIDC \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u0430\ndiscoveryURL: &quot;https:\/\/keycloak.example.org\/auth\/realms\/kubernetes&quot;\n# \u0418\u043c\u044f \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u043c\u044b \u0441\u043e\u0437\u0434\u0430\u043b\u0438 \u0432 Keycloak\nClientID: &quot;kubernetes&quot;\n# Secret \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u044f \u043f\u0440\u043e\u0441\u0438\u043b \u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c\nClientSecret: &quot;c6ec03b8-d0b8-4cb6-97a0-03becba1d727&quot;\n# \u041a\u0443\u0434\u0430 \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0443\u0441\u043f\u0435\u0448\u043d\u043e\u0439 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438. \u0424\u043e\u0440\u043c\u0430\u0442 &lt;SCHEMA&gt;:\/\/&lt;SERVICE_NAME&gt;.&gt;&lt;NAMESAPCE&gt;.&lt;CLUSTER_NAME&gt;\nupstreamURL: &quot;http:\/\/dashboard-kubernetes-dashboard.default.svc.cluster.local&quot;\n# \u041f\u0440\u043e\u043f\u0443\u0441\u043a\u0430\u0435\u043c \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0443 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430, \u0435\u0441\u043b\u0438 \u0443 \u043d\u0430\u0441 \u0441\u0430\u043c\u043e\u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0439\nskipOpenidProviderTlsVerify: true\n# \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u043f\u0440\u0430\u0432 \u0434\u043e\u0441\u0442\u0443\u043f\u0430, \u043f\u0443\u0441\u043a\u0430\u0435\u043c \u043d\u0430 \u0432\u0441\u0435 path \u0435\u0441\u043b\u0438 \u043c\u044b \u0432 \u0433\u0440\u0443\u043f\u043f\u0435 DataOPS\nrules:\n  - &quot;uri=\/*|groups=DataOPS&quot;\n<\/code><\/pre>\n<p>\u041f\u043e\u0441\u043b\u0435 \u044d\u0442\u043e\u0433\u043e \u043f\u0440\u0438 \u043f\u043e\u043f\u044b\u0442\u043a\u0435 \u0437\u0430\u0439\u0442\u0438 \u043d\u0430 <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes-dashboard.example.org\" rel=\"nofollow\">kubernetes-dashboard.example.org<\/a><\/noindex>, \u043f\u0440\u043e\u0438\u0437\u043e\u0439\u0434\u0435\u0442 \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u043d\u0430 Keycloak \u0438 \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0443\u0434\u0430\u0447\u043d\u043e\u0439 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 \u043c\u044b \u043f\u043e\u043f\u0430\u0434\u0435\u043c \u0432 Dashboard \u0443\u0436\u0435 \u0437\u0430\u043b\u043e\u0433\u0438\u043d\u0435\u043d\u043d\u044b\u043c.<\/p>\n<h2>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 gangway<\/h2>\n<p>\n\u0414\u043b\u044f \u0443\u0434\u043e\u0431\u0441\u0442\u0432\u0430 \u043c\u043e\u0436\u043d\u043e \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c gangway \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u0443\u0434\u0435\u0442 \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0444\u0430\u0439\u043b \u043a\u043e\u043d\u0444\u0438\u0433\u0430 \u0434\u043b\u044f kubectl, \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u043c\u044b \u0443\u0436\u0435 \u043f\u043e\u0434 \u043d\u0430\u0448\u0438\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c \u043f\u043e\u043f\u0430\u0434\u0435\u043c \u0432 Kubernetes.<\/p>\n<pre><code class=\"bash\">\nhelm install --name gangway stable\/gangway -f values_gangway.yaml\n<\/code><\/pre>\n<p>\n<b class=\"spoiler_title\">values_gangway.yaml<\/b><\/p>\n<pre><code class=\"bash\">\ngangway:\n  # \u041f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u043e\u0435 \u0438\u043c\u044f \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0430\n  clusterName: &quot;my-k8s&quot;\n  # \u0413\u0434\u0435 \u0443 \u043d\u0430\u0441 OIDC \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\n  authorizeURL: &quot;https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\/protocol\/openid-connect\/auth&quot;\n  tokenURL: &quot;https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\/protocol\/openid-connect\/token&quot;\n  audience: &quot;https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\/protocol\/openid-connect\/userinfo&quot;\n  # \u0422\u0435\u043e\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438 \u0441\u044e\u0434\u0430 \u043c\u043e\u0436\u043d\u043e \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c groups \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u044b \u0437\u0430\u043c\u0430\u043f\u0438\u043b\u0438\n  scopes: [&quot;openid&quot;, &quot;profile&quot;, &quot;email&quot;, &quot;offline_access&quot;]\n  redirectURL: &quot;https:\/\/gangway.example.org\/callback&quot;\n  # \u0418\u043c\u044f \u043a\u043b\u0438\u0435\u043d\u0442\u0430\n  clientID: &quot;kubernetes&quot;\n  # \u0421\u0435\u043a\u0440\u0435\u0442\n  clientSecret: &quot;c6ec03b8-d0b8-4cb6-97a0-03becba1d727&quot;\n  # \u0415\u0441\u043b\u0438 \u043e\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0434\u0435\u0444\u043e\u043b\u0442\u043d\u043e\u0435 \u0437\u043d\u0430\u0447\u043d\u0438\u0435, \u0442\u043e \u0437\u0430 \u0438\u043c\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0431\u0443\u0434\u0435\u0442 \u0431\u0440\u0430\u0442\u044c\u044f &lt;b&gt;Frist name&lt;\/b&gt; &lt;b&gt;Second name&lt;\/b&gt;, \u0430 \u043f\u0440\u0438 &quot;sub&quot; \u0435\u0433\u043e \u043b\u043e\u0433\u0438\u043d\n  usernameClaim: &quot;sub&quot;\n  # \u0414\u043e\u043c\u0435\u043d\u043d\u043e\u0435 \u0438\u043c\u044f \u0438\u043b\u0438 IP \u0430\u0434\u0440\u0435\u0441\u0441 API \u0441\u0435\u0440\u0432\u0435\u0440\u0430\n  apiServerURL: &quot;https:\/\/192.168.99.111:8443&quot;\n\n# \u0412\u043a\u043b\u044e\u0447\u0430\u0435\u043c Ingress\ningress:\n  enabled: true\n  annotations:\n    kubernetes.io\/ingress.class: nginx\n    nginx.ingress.kubernetes.io\/proxy-buffer-size: &quot;64k&quot;\n  path: \/\n  hosts:\n  - gangway.example.org\n  tls:\n  - secretName: tls-keycloak\n    hosts:\n      - gangway.example.org\n\n# \u0415\u0441\u043b\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c \u0441\u0430\u043c\u043e\u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0439 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442, \u0442\u043e \u0435\u0433\u043e(\u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0439 \u043a\u043e\u0440\u043d\u0435\u0432\u043e\u0439 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442) \u043d\u0430\u0434\u043e \u0443\u043a\u0430\u0437\u0430\u0442\u044c.\ntrustedCACert: |-\n -----BEGIN CERTIFICATE-----\n MIIDVzCCAj+gAwIBAgIBATANBgkqhkiG9w0BAQsFADA1MQswCQYDVQQGEwJVUzEQMA4GA1UEChMHRGF0YU9QUzEUMBIGA1UEAxMLbXkgcm9vdCBrZXkwHhcNMjAwMjE0MDkxODAwWhcNMzAwMjE0MDkxODAwWjA1MQswCQYDVQQGEwJVUzEQMA4GA1UEChMHRGF0YU9QUzEUMBIGA1UEAxMLbXkgcm9vdCBrZXkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDyP749PqqIRwNSqaK6qr0Zsi03G4PTCUlgaYTPZuMrwUVPK8xX2dWWs9MPRMOdXpgr8aSTZnVfmelIlVz4D7o2vK5rfmAe9GPcK0WbwKwXyhFU0flS9sU\/g46ogHFrk03SZxQAeJhMLfEmAJm8LF5HghtGDs3t4uwGsB95o+lqPLiBvxRB8ZS3jSpYpvPgXAuZWKdZUQ3UUZf0X3hGLp7uIcIwJ7i4MduOGaQEO4cePeEJy9aDAO6qV78YmHbyh9kaW+1DL\/Sgq8NmTgHGV6UOnAPKHTnMKXl6KkyUz8uLBGIdVhPxrlzG1EzXresJbJenSZ+FZqm3oLqZbw54Yp5hAgMBAAGjcjBwMA8GA1UdEwEB\/wQFMAMBAf8wHQYDVR0OBBYEFHISTOU\/6BQqqnOZj+1xJfxpjiG0MAsGA1UdDwQEAwIBBjARBglghkgBhvhCAQEEBAMCAAcwHgYJYIZIAYb4QgENBBEWD3hjYSBjZXJ0aWZpY2F0ZTANBgkqhkiG9w0BAQsFAAOCAQEAj7HC8ObibwOLT4ZYmISJZwub9lcE0AZ5cWkPW39j\/syhdbbqjK\/6jy2D3WUEbR+s1Vson5Ov7JhN5In2yfZ\/ByDvBnoj7CP8Q\/ZMjTJgwN7j0rgmEb3CTZvnDPAz8Ijw3FP0cjxfoZ1Z0V2F44Ry7gtLJWr06+MztXVyto3aIz1\/XbMQnXYlzc3c3B5yUQIy44Ce5aLRVsAjmXNqVRmDJ2QPNLicvrhnUJsO0zFWI+zZ2hc4Ge1RotCrjfOc9hQY63jZJ17myCZ6QCD7yzMzAob4vrgmkD4q7tpGrhPY\/gDcE+lUNhC7DO3l0oPy2wsnT2TEn87eyWmDiTFG9zWDew==\n -----END CERTIFICATE-----\n<\/code><\/pre>\n<p>\u0412\u044b\u0433\u043b\u044f\u0434\u0438\u0442 \u043f\u0440\u0438\u043c\u0435\u0440\u043d\u043e \u0442\u0430\u043a. \u041f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043a\u0430\u043a \u0441\u0440\u0430\u0437\u0443 \u0441\u043a\u0430\u0447\u0430\u0442\u044c \u0444\u0430\u0439\u043b \u043a\u043e\u043d\u0444\u0438\u0433\u0430 \u0442\u0430\u043a \u0438 \u0441\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0435\u0433\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e \u043d\u0430\u0431\u043e\u0440 \u043a\u043e\u043c\u0430\u043d\u0434:<\/p>\n<p><img decoding=\"async\" alt=\"\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c ActiveDirectory \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes c \u043f\u043e\u043c\u043e\u0449\u044c\u044e Keycloak\" src=\"\/wp-content\/uploads\/2020\/02\/1995466b406e475c16c0a161ac428dba.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\u0418\u0441\u0442\u043e\u0447\u043d\u0438\u043a: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/489172\/\">habr.com<\/a> <\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u0430\u043d\u043d\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0430 \u0441 \u0446\u0435\u043b\u044c\u044e \u0440\u0430\u0441\u0448\u0438\u0440\u0438\u0442\u044c \u0443\u0436\u0435 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0449\u0443\u044e, \u043d\u043e \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442 \u043f\u0440\u043e \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0441\u0432\u044f\u0437\u043a\u0438 \u0438\u043c\u0435\u043d\u043d\u043e \u0441 Microsoft ActiveDirectory, \u0430 \u0442\u0430\u043a \u0436\u0435 \u0434\u043e\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u0435\u0435. \u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u044f \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0443 \u043a\u0430\u043a \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c: Keycloak \u2014 \u044d\u0442\u043e \u043f\u0440\u043e\u0435\u043a\u0442 \u0441 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u043c \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u043c \u043a\u043e\u0434\u043e\u043c. \u041a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u0435\u0434\u0438\u043d\u0443\u044e \u0442\u043e\u0447\u043a\u0443 \u0432\u0445\u043e\u0434\u0430 \u0434\u043b\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439. \u0420\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0441 \u043c\u043d\u043e\u0436\u0435\u0441\u0442\u0432\u043e\u043c \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0441 LDAP [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":70870,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-70869","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0414\u0430\u043d\u043d\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0430 \u0441 \u0446\u0435\u043b\u044c\u044e \u0440\u0430\u0441\u0448\u0438\u0440\u0438\u0442\u044c \u0443\u0436\u0435 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0449\u0443\u044e, \u043d\u043e \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442 \u043f\u0440\u043e \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0441\u0432\u044f\u0437\u043a\u0438 \u0438\u043c\u0435\u043d\u043d\u043e \u0441 Microsoft ActiveDirectory, \u0430 \u0442\u0430\u043a \u0436\u0435 \u0434\u043e\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u0435\u0435. \u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u044f \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0443 \u043a\u0430\u043a \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c: Keycloak \u2014 \u044d\u0442\u043e \u043f\u0440\u043e\u0435\u043a\u0442 \u0441 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u043c \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u043c \u043a\u043e\u0434\u043e\u043c. \u041a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u0435\u0434\u0438\u043d\u0443\u044e \u0442\u043e\u0447\u043a\u0443 \u0432\u0445\u043e\u0434\u0430 \u0434\u043b\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439. \u0420\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0441 \u043c\u043d\u043e\u0436\u0435\u0441\u0442\u0432\u043e\u043c \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0441 LDAP\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/et\/blog\/administrirovanie\/prikruchivaem-activedirectory-avtorizacziyu-k-kubernetes-c-pomoshhyu-keycloak\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"et_EE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c ActiveDirectory \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes c \u043f\u043e\u043c\u043e\u0449\u044c\u044e Keycloak | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0414\u0430\u043d\u043d\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0430 \u0441 \u0446\u0435\u043b\u044c\u044e \u0440\u0430\u0441\u0448\u0438\u0440\u0438\u0442\u044c \u0443\u0436\u0435 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0449\u0443\u044e, \u043d\u043e \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442 \u043f\u0440\u043e \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0441\u0432\u044f\u0437\u043a\u0438 \u0438\u043c\u0435\u043d\u043d\u043e \u0441 Microsoft ActiveDirectory, \u0430 \u0442\u0430\u043a \u0436\u0435 \u0434\u043e\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u0435\u0435. \u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u044f \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0443 \u043a\u0430\u043a \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c: Keycloak \u2014 \u044d\u0442\u043e \u043f\u0440\u043e\u0435\u043a\u0442 \u0441 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u043c \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u043c \u043a\u043e\u0434\u043e\u043c. \u041a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u0435\u0434\u0438\u043d\u0443\u044e \u0442\u043e\u0447\u043a\u0443 \u0432\u0445\u043e\u0434\u0430 \u0434\u043b\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439. \u0420\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0441 \u043c\u043d\u043e\u0436\u0435\u0441\u0442\u0432\u043e\u043c \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0441 LDAP\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/et\/blog\/administrirovanie\/prikruchivaem-activedirectory-avtorizacziyu-k-kubernetes-c-pomoshhyu-keycloak\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-22T03:41:02+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-03T13:14:37+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Seome Active Directory autoriseerimise Kubernetesega Keycloak'i abil | ProHoster","description":"Artikkel on kirjutatud eesm\u00e4rgiga laiendada juba olemasolevat teavet, k\u00e4sitledes erip\u00e4ra, mis on seotud just Microsoft Active Directory'ga, ning t\u00e4iendab seda. Selles artiklis tutvustan, kuidas installida ja seadistada: Keycloak \u2014 avatud l\u00e4htekoodiga projekt, mis pakub rakendustele \u00fchte sisenemispunkti. See t\u00f6\u00f6tab paljude protokollidega, sealhulgas LDAP-ga.","canonical_url":"https:\/\/prohoster.info\/et\/blog\/administrirovanie\/prikruchivaem-activedirectory-avtorizacziyu-k-kubernetes-c-pomoshhyu-keycloak","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"et_EE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c ActiveDirectory \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes c \u043f\u043e\u043c\u043e\u0449\u044c\u044e Keycloak | ProHoster","og:description":"\u0414\u0430\u043d\u043d\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0430 \u0441 \u0446\u0435\u043b\u044c\u044e \u0440\u0430\u0441\u0448\u0438\u0440\u0438\u0442\u044c \u0443\u0436\u0435 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0449\u0443\u044e, \u043d\u043e \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442 \u043f\u0440\u043e \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0441\u0432\u044f\u0437\u043a\u0438 \u0438\u043c\u0435\u043d\u043d\u043e \u0441 Microsoft ActiveDirectory, \u0430 \u0442\u0430\u043a \u0436\u0435 \u0434\u043e\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u0435\u0435. \u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u044f \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0443 \u043a\u0430\u043a \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c: Keycloak \u2014 \u044d\u0442\u043e \u043f\u0440\u043e\u0435\u043a\u0442 \u0441 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u043c \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u043c \u043a\u043e\u0434\u043e\u043c. \u041a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u0435\u0434\u0438\u043d\u0443\u044e \u0442\u043e\u0447\u043a\u0443 \u0432\u0445\u043e\u0434\u0430 \u0434\u043b\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439. \u0420\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0441 \u043c\u043d\u043e\u0436\u0435\u0441\u0442\u0432\u043e\u043c \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0441 LDAP","og:url":"https:\/\/prohoster.info\/et\/blog\/administrirovanie\/prikruchivaem-activedirectory-avtorizacziyu-k-kubernetes-c-pomoshhyu-keycloak","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-22T03:41:02+00:00","article:modified_time":"2020-03-03T13:14:37+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"70869","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:12:23","updated":"2022-09-27 23:03:47"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts\/70869","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/comments?post=70869"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts\/70869\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/media\/70870"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/media?parent=70869"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/categories?post=70869"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/tags?post=70869"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}