{"id":70867,"date":"2020-02-22T06:40:58","date_gmt":"2020-02-22T03:40:58","guid":{"rendered":"https:\/\/prohoster.info\/blog\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes"},"modified":"2020-03-03T16:14:36","modified_gmt":"2020-03-03T13:14:36","slug":"prikruchivaem-ldap-avtorizacziyu-k-kubernetes","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","title":{"rendered":"Colleghiamo l'autenticazione LDAP a Kubernetes","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Colleghiamo l&#039;autenticazione LDAP a Kubernetes\" src=\"\/wp-content\/uploads\/2020\/02\/2b0f0a4921e049a78a015e7693d697cf.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>Breve istruzione su come utilizzare Keycloak per collegare Kubernetes al tuo server LDAP e configurare l'importazione di utenti e gruppi. Questo permetter\u00e0 di configurare RBAC per i tuoi utenti e di utilizzare auth-proxy per proteggere il Kubernetes Dashboard e altre applicazioni che non possono eseguire l'autenticazione autonomamente.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2 id=\"ustanovka-keycloak\">Installazione di Keycloak<\/h2>\n<p><\/p>\n<p>Supponiamo che tu abbia gi\u00e0 un server LDAP. Pu\u00f2 essere Active Directory, FreeIPA, OpenLDAP o qualsiasi altra cosa. Se non hai un server LDAP, puoi comunque creare utenti direttamente nell'interfaccia di Keycloak oppure utilizzare provider oidc pubblici (Google, Github, Gitlab), il risultato sar\u00e0 quasi lo stesso.<\/p>\n<p><\/p>\n<p>Iniziamo installando Keycloak, l'installazione pu\u00f2 essere eseguita separatamente o direttamente nel cluster Kubernetes; in genere, se hai pi\u00f9 cluster Kubernetes, sarebbe pi\u00f9 semplice installarlo separatamente. D'altra parte, puoi sempre utilizzare <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/helm\/charts\/tree\/master\/stable\/keycloak\">il chart helm ufficiale<\/a><\/noindex> e installarlo direttamente nel tuo cluster.<\/p>\n<p><\/p>\n<p>Per memorizzare i dati di Keycloak, avrai bisogno di un database. Per impostazione predefinita, viene utilizzato <code>h2<\/code> (tutti i dati sono memorizzati localmente), ma \u00e8 anche possibile utilizzare <code>postgres<\/code>, <code>mysql<\/code> o <code>mariadb<\/code>.<br \/>\nSe hai deciso di installare Keycloak separatamente, troverai istruzioni pi\u00f9 dettagliate in <noindex><a rel=\"nofollow\" href=\"https:\/\/www.keycloak.org\/docs\/latest\/getting_started\/index.html\">documentazione ufficiale<\/a><\/noindex>.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-federacii\">Impostazione della federazione<\/h2>\n<p><\/p>\n<p>Per prima cosa, creiamo un nuovo realm. Un realm \u00e8 lo spazio della nostra applicazione. Ogni applicazione pu\u00f2 avere il proprio realm con utenti e impostazioni di autorizzazione differenti. Il realm Master \u00e8 utilizzato da Keycloak stesso e non \u00e8 corretto usarlo per qualcos'altro.<\/p>\n<p><\/p>\n<p>Clicchiamo su <strong>Aggiungi realm<\/strong><\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValue<\/p>\n<p><strong>Name<\/strong><br \/>\n<code>kubernetes<\/code><\/p>\n<p><strong>Nome visualizzato<\/strong><br \/>\n<code>Kubernetes<\/code><\/p>\n<p><strong>Nome da visualizzare in HTML<\/strong><br \/>\n<code>&lt;img src=&quot;https:\/\/kubernetes.io\/images\/nav_logo.svg&quot; width=&quot;400&quot; &gt;<\/code><\/p>\n<p><\/p>\n<p>Kubernetes verifica per impostazione predefinita se l'email dell'utente \u00e8 stata confermata. Poich\u00e9 stiamo utilizzando il nostro server LDAP, questa verifica restituir\u00e0 quasi sempre <code>false<\/code>. Disattiviamo la visualizzazione di questo parametro in Kubernetes:<\/p>\n<p><\/p>\n<p><strong>Ambiti client<\/strong> \u2192 <strong>Email<\/strong> \u2192 <strong>Mapper<\/strong> \u2192 <strong>Email verificata<\/strong> (Elimina)<\/p>\n<p><\/p>\n<p>Ora configuriamo la federazione, per farlo andiamo a:<\/p>\n<p><\/p>\n<p><strong>Federazione utenti<\/strong> \u2192 <strong>Aggiungi fornitore\u2026<\/strong> \u2192 <strong>ldap<\/strong><\/p>\n<p><\/p>\n<p>Riporter\u00f2 un esempio di configurazione per FreeIPA:<\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValue<\/p>\n<p><strong>Nome da visualizzare in console<\/strong><br \/>\n<code>freeipa.example.org<\/code><\/p>\n<p><strong>Vendor<\/strong><br \/>\n<code>Red Hat Directory Server<\/code><\/p>\n<p><strong>Attributo UUID LDAP<\/strong><br \/>\n<code>ipauniqueid<\/code><\/p>\n<p><strong>URL di connessione<\/strong><br \/>\n<code>ldaps:\/\/freeipa.example.org<\/code><\/p>\n<p><strong>DN utenti<\/strong><br \/>\n<code>cn=users,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>Bind DN<\/strong><br \/>\n<code>uid=keycloak-svc,cn=users,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>Credenziale Bind<\/strong><br \/>\n<code>&lt;password&gt;<\/code><\/p>\n<p><strong>Consenti l'autenticazione Kerberos:<\/strong><br \/>\n<code>on<\/code><\/p>\n<p><strong>Realm Kerberos:<\/strong><br \/>\n<code>EXAMPLE.ORG<\/code><\/p>\n<p><strong>Server Principale:<\/strong><br \/>\n<code>HTTP\/freeipa.example.org@EXAMPLE.ORG<\/code><\/p>\n<p><strong>KeyTab:<\/strong><br \/>\n<code>\/etc\/krb5.keytab<\/code><\/p>\n<p><\/p>\n<p>L'utente <code>keycloak-svc<\/code> deve essere creato in anticipo sul nostro server LDAP.<\/p>\n<p><\/p>\n<p>Nel caso di Active Directory, \u00e8 sufficiente selezionare <strong>Venditore: Active Directory<\/strong> e le impostazioni necessarie verranno automaticamente inserite nel modulo.<\/p>\n<p><\/p>\n<p>Clicchiamo su <strong>Salva<\/strong><\/p>\n<p><\/p>\n<p>Ora andiamo a:<\/p>\n<p><\/p>\n<p><strong>Federazione utenti<\/strong> \u2192 <strong>freeipa.example.org<\/strong> \u2192 <strong>Mapper<\/strong> \u2192 <strong>Nome<\/strong><\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValue<\/p>\n<p><strong>Attributo Ldap<\/strong><br \/>\n<code>givenName<\/code><\/p>\n<p><\/p>\n<p>Ora attiviamo il mapping dei gruppi:<\/p>\n<p><\/p>\n<p><strong>Federazione utenti<\/strong> \u2192 <strong>freeipa.example.org<\/strong> \u2192 <strong>Mapper<\/strong> \u2192 <strong>Crea<\/strong><\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValue<\/p>\n<p><strong>Name<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><strong>Tipo di Mapper<\/strong><br \/>\n<code>group-ldap-mapper<\/code><\/p>\n<p><strong>LDAP Groups DN<\/strong><br \/>\n<code>cn=groups,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>Strategia di Recupero dei Gruppi Utenti<\/strong><br \/>\n<code>GET_GROUPS_FROM_USER_MEMBEROF_ATTRIBUTE<\/code><\/p>\n<p><\/p>\n<p>Con questo, la configurazione della federazione \u00e8 completata, procediamo con la configurazione del client.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-klienta\">Configurazione del client<\/h2>\n<p><\/p>\n<p>Creiamo un nuovo client (l'applicazione che ricever\u00e0 gli utenti da Keycloak). Andiamo a:<\/p>\n<p><\/p>\n<p><strong>Clients<\/strong> \u2192 <strong>Crea<\/strong><\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValue<\/p>\n<p><strong>Client ID<\/strong><br \/>\n<code>kubernetes<\/code><\/p>\n<p><strong>Tipo di Accesso<\/strong><br \/>\n<code>confidenziale<\/code><\/p>\n<p><strong>URL Radice<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/<\/code><\/p>\n<p><strong>URI di Reindirizzamento Validi<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/*<\/code><\/p>\n<p><strong>URL Amministratore<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/<\/code><\/p>\n<p><\/p>\n<p>Creeremo anche uno scope per i gruppi:<\/p>\n<p><\/p>\n<p><strong>Scope del Client<\/strong> \u2192 <strong>Crea<\/strong><\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValue<\/p>\n<p><strong>Modello<\/strong><br \/>\n<code>Nessun template<\/code><\/p>\n<p><strong>Name<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><strong>Percorso completo del gruppo<\/strong><br \/>\n<code>false<\/code><\/p>\n<p><\/p>\n<p>E configuriamo il mapper per essi:<\/p>\n<p><\/p>\n<p><strong>Scope del Client<\/strong> \u2192 <strong>groups<\/strong> \u2192 <strong>Mapper<\/strong> \u2192 <strong>Crea<\/strong><\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValue<\/p>\n<p><strong>Name<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><strong>Tipo di Mapper<\/strong><br \/>\n<code>Appartenenza al gruppo<\/code><\/p>\n<p><strong>Nome del Token Claim<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><\/p>\n<p>Ora dobbiamo attivare il mapping dei gruppi nel nostro client scope:<\/p>\n<p><\/p>\n<p><strong>Clients<\/strong> \u2192 <strong>kubernetes<\/strong> \u2192 <strong>Scope del Client<\/strong> \u2192 <strong>Scopes Client Predefiniti<\/strong><\/p>\n<p><\/p>\n<p>Selezioniamo <strong>groups<\/strong> in <strong>Client Scopes Disponibili<\/strong>, facciamo clic su <strong>Aggiungi selezionati<\/strong><\/p>\n<p><\/p>\n<p>Ora configuriamo l'autenticazione della nostra applicazione, andiamo a:<\/p>\n<p><\/p>\n<p><strong>Clients<\/strong> \u2192 <strong>kubernetes<\/strong><\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValue<\/p>\n<p><strong>Autorizzazione Abilitata<\/strong><br \/>\n<code>ACCESO<\/code><\/p>\n<p><\/p>\n<p>Clicchiamo <strong>salva<\/strong> e con questo la configurazione del client \u00e8 completata, ora nella scheda<\/p>\n<p><\/p>\n<p><strong>Clients<\/strong> \u2192 <strong>kubernetes<\/strong> \u2192 <strong>Credenziali<\/strong><\/p>\n<p><\/p>\n<p>potrete ottenere <strong>Secret<\/strong> che utilizzeremo in seguito.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-kubernetes\">Configurazione Kubernetes<\/h2>\n<p><\/p>\n<p>La configurazione di Kubernetes per l'autenticazione OIDC \u00e8 piuttosto banale e non \u00e8 qualcosa di molto complesso. Tutto ci\u00f2 che \u00e8 necessario \u00e8 posizionare il certificato CA del vostro server OIDC in <code>\/etc\/kubernetes\/pki\/oidc-ca.pem<\/code> e aggiungere le opzioni necessarie per kube-apiserver.<br \/>\nA tale scopo, aggiornate <code>\/etc\/kubernetes\/manifests\/kube-apiserver.yaml<\/code> su tutti i vostri master:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">...\nspec:\n  containers:\n  - command:\n    - kube-apiserver\n...\n    - --oidc-ca-file=\/etc\/kubernetes\/pki\/oidc-ca.pem\n    - --oidc-client-id=kubernetes\n    - --oidc-groups-claim=groups\n    - --oidc-issuer-url=https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\n    - --oidc-username-claim=email\n...<\/code><\/pre>\n<p><\/p>\n<p>E aggiornate anche il file di configurazione kubeadm nel cluster, per non perdere queste impostazioni durante l'aggiornamento:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">kubectl edit -n kube-system configmaps kubeadm-config<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"plaintext\">...\ndata:\n  ClusterConfiguration: |\n    apiServer:\n      extraArgs:\n        oidc-ca-file: \/etc\/kubernetes\/pki\/oidc-ca.pem\n        oidc-client-id: kubernetes\n        oidc-groups-claim: groups\n        oidc-issuer-url: https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\n        oidc-username-claim: email\n...<\/code><\/pre>\n<p><\/p>\n<p>Con questo, la configurazione di Kubernetes \u00e8 completata. Potete ripetere queste azioni in tutti i vostri cluster Kubernetes.<\/p>\n<p><\/p>\n<h2 id=\"nachalnaya-avtorizaciya\">Autenticazione Iniziale<\/h2>\n<p><\/p>\n<p>Dopo queste operazioni avrete gi\u00e0 un cluster Kubernetes con l'autenticazione OIDC configurata. L'unico problema \u00e8 che i vostri utenti non hanno ancora un client configurato n\u00e9 un proprio kubeconfig. Per risolvere questo problema, \u00e8 necessario configurare il rilascio automatico del kubeconfig agli utenti dopo una autorizzazione riuscita.<\/p>\n<p><\/p>\n<p>A tal fine, si possono utilizzare applicazioni web specializzate, che permettono di autenticare l'utente e poi scaricare un kubeconfig pronto. Una delle pi\u00f9 comode \u00e8 <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/negz\/kuberos\">Kuberos<\/a><\/noindex>, esso consente di descrivere tutti i cluster Kubernetes in un'unica configurazione e passare facilmente tra di essi.<\/p>\n<p><\/p>\n<p>Per configurare Kuberos \u00e8 sufficiente descrivere un template per kubeconfig e avviarlo con i seguenti parametri:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">kuberos https:\/\/keycloak.example.org\/auth\/realms\/kubernetes kubernetes \/cfg\/secret \/cfg\/template<\/code><\/pre>\n<p><\/p>\n<p>Per informazioni pi\u00f9 dettagliate, vedere <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/negz\/kuberos#usage\">Utilizzo<\/a><\/noindex> su Github.<\/p>\n<p><\/p>\n<p>\u00c8 anche possibile utilizzare <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/int128\/kubelogin\">kubelogin<\/a><\/noindex> se desideri effettuare l'autenticazione direttamente sul computer dell'utente. In questo caso, si aprir\u00e0 un browser con un modulo di autenticazione su localhost.<\/p>\n<p><\/p>\n<p>Il kubeconfig ottenuto pu\u00f2 essere verificato sul sito <noindex><a rel=\"nofollow\" href=\"https:\/\/jwt.io\/#debugger-io\">jwt.io<\/a><\/noindex>. Basta copiare il valore <code>users[].user.auth-provider.config.id-token<\/code> dal tuo kubeconfig nel modulo del sito e riceverai subito la decodifica.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-rbac\">Configurazione RBAC<\/h2>\n<p><\/p>\n<p>Durante la configurazione dell'RBAC \u00e8 possibile riferirsi sia al nome utente (campo <code>name<\/code> nel token jwt), sia al gruppo di utenti (campo <code>groups<\/code> nel token jwt). Ecco un esempio di configurazione dei diritti per il gruppo <code>kubernetes-default-namespace-admins<\/code>:<\/p>\n<p>\n<b class=\"spoiler_title\">kubernetes-default-namespace-admins.yaml<\/b><\/p>\n<pre><code class=\"plaintext\">apiVersion: rbac.authorization.k8s.io\/v1\nkind: Role\nmetadata:\n  name: default-admins\n  namespace: default\nrules:\n- apiGroups:\n  - '*'\n  resources:\n  - '*'\n  verbs:\n  - '*'\n---\napiVersion: rbac.authorization.k8s.io\/v1\nkind: RoleBinding\nmetadata:\n  name: kubernetes-default-namespace-admins\n  namespace: default\nroleRef:\n  apiGroup: rbac.authorization.k8s.io\n  kind: Role\n  name: default-admins\nsubjects:\n- apiGroup: rbac.authorization.k8s.io\n  kind: Group\n  name: kubernetes-default-namespace-admins<\/code><\/pre>\n<p><\/p>\n<p>Ulteriori esempi per RBAC possono essere trovati in <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/reference\/access-authn-authz\/rbac\/\">della documentazione ufficiale di Kubernetes<\/a><\/noindex><\/p>\n<p><\/p>\n<h2 id=\"nastroyka-auth-proxy\">Configurazione dell'auth-proxy<\/h2>\n<p><\/p>\n<p>C'\u00e8 un ottimo progetto <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/keycloak\/keycloak-gatekeeper\">keycloak-gatekeeper<\/a><\/noindex>, che consente di proteggere qualsiasi applicazione, fornendo all'utente la possibilit\u00e0 di autenticarsi su un server OIDC. Ti mostrer\u00f2 come configurarlo usando come esempio il Kubernetes Dashboard:<\/p>\n<p>\n<b class=\"spoiler_title\">dashboard-proxy.yaml<\/b><\/p>\n<pre><code class=\"plaintext\">apiVersion: extensions\/v1beta1\nkind: Deployment\nmetadata:\n  name: kubernetes-dashboard-proxy\nspec:\n  replicas: 1\n  template:\n    metadata:\n      labels:\n        app: kubernetes-dashboard-proxy\n    spec:\n      containers:\n      - args:\n        - --listen=0.0.0.0:80\n        - --discovery-url=https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\n        - --client-id=kubernetes\n        - --client-secret=\n        - --redirection-url=https:\/\/kubernetes-dashboard.example.org\n        - --enable-refresh-tokens=true\n        - --encryption-key=ooTh6Chei1eefooyovai5ohwienuquoh\n        - --upstream-url=https:\/\/kubernetes-dashboard.kube-system\n        - --resources=uri=\/*\n        image: keycloak\/keycloak-gatekeeper\n        name: kubernetes-dashboard-proxy\n        ports:\n        - containerPort: 80\n          livenessProbe:\n            httpGet:\n              path: \/oauth\/health\n              port: 80\n            initialDelaySeconds: 3\n            timeoutSeconds: 2\n          readinessProbe:\n            httpGet:\n              path: \/oauth\/health\n              port: 80\n            initialDelaySeconds: 3\n            timeoutSeconds: 2\n---\napiVersion: v1\nkind: Service\nmetadata:\n  name: kubernetes-dashboard-proxy\nspec:\n  ports:\n  - port: 80\n    protocol: TCP\n    targetPort: 80\n  selector:\n    app: kubernetes-dashboard-proxy\n  type: ClusterIP<\/code><\/pre>\n<p>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/441112\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Keycloak \u043c\u043e\u0436\u043d\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c Kubernetes \u0441 \u0432\u0430\u0448\u0438\u043c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0438\u043c\u043f\u043e\u0440\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0433\u0440\u0443\u043f\u043f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c auth-proxy \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c Kubernetes Dashboard \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0447\u0442\u043e \u0443 \u0432\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c Active [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":70868,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-70867","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c LDAP-\u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-22T03:40:58+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-03T13:14:36+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Collegare l'autenticazione LDAP a Kubernetes | ProHoster","description":"Una piccola guida su come.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c LDAP-\u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes | ProHoster","og:description":"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a.","og:url":"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-22T03:40:58+00:00","article:modified_time":"2020-03-03T13:14:36+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"70867","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:12:23","updated":"2022-09-28 01:58:51","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/70867","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=70867"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/70867\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/70868"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=70867"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=70867"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=70867"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}