{"id":70867,"date":"2020-02-22T06:40:58","date_gmt":"2020-02-22T03:40:58","guid":{"rendered":"https:\/\/prohoster.info\/blog\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes"},"modified":"2020-03-03T16:14:36","modified_gmt":"2020-03-03T13:14:36","slug":"prikruchivaem-ldap-avtorizacziyu-k-kubernetes","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","title":{"rendered":"Colleghiamo l'autenticazione LDAP a Kubernetes.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Colleghiamo l&#039;autenticazione LDAP a Kubernetes.\" src=\"\/wp-content\/uploads\/2020\/02\/2b0f0a4921e049a78a015e7693d697cf.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>Una breve guida su come utilizzare Keycloak per collegare Kubernetes al vostro server LDAP e configurare l'importazione di utenti e gruppi. Questo permetter\u00e0 di impostare RBAC per i vostri utenti e utilizzare l'auth-proxy per proteggere il Kubernetes Dashboard e altre applicazioni che non possono gestire l'autenticazione da sole.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2 id=\"ustanovka-keycloak\">Installazione di Keycloak<\/h2>\n<p><\/p>\n<p>Supponiamo che abbiate gi\u00e0 un server LDAP. Pu\u00f2 essere Active Directory, FreeIPA, OpenLDAP o altro. Se non avete un server LDAP, in effetti potete creare utenti direttamente nell'interfaccia di Keycloak, oppure utilizzare provider oidc pubblici (Google, Github, Gitlab), il risultato sar\u00e0 praticamente lo stesso.<\/p>\n<p><\/p>\n<p>Per prima cosa installiamo Keycloak. L'installazione pu\u00f2 essere eseguita separatamente o direttamente nel cluster Kubernetes. In genere, se avete pi\u00f9 cluster Kubernetes, sarebbe pi\u00f9 semplice installarlo separatamente. D'altra parte, potete sempre utilizzare <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/helm\/charts\/tree\/master\/stable\/keycloak\">il chart helm ufficiale<\/a><\/noindex> e installarlo direttamente nel vostro cluster.<\/p>\n<p><\/p>\n<p>Per memorizzare i dati di Keycloak avrete bisogno di un database. Di default viene utilizzato <code>h2<\/code> (tutti i dati sono memorizzati localmente), ma \u00e8 possibile utilizzare anche <code>postgres<\/code>, <code>mysql<\/code> o <code>mariadb<\/code>.<br \/>\nSe hai deciso di installare Keycloak separatamente, troverai istruzioni pi\u00f9 dettagliate in <noindex><a rel=\"nofollow\" href=\"https:\/\/www.keycloak.org\/docs\/latest\/getting_started\/index.html\">documentazione ufficiale<\/a><\/noindex>.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-federacii\">Configurazione della federazione<\/h2>\n<p><\/p>\n<p>Per prima cosa, creiamo un nuovo realm. Un realm \u00e8 uno spazio della nostra applicazione. Ogni applicazione pu\u00f2 avere il proprio realm con diversi utenti e impostazioni di autorizzazione. Il realm master \u00e8 utilizzato da Keycloak stesso e non \u00e8 corretto utilizzarlo per altro.<\/p>\n<p><\/p>\n<p>Clicchiamo su <strong>Aggiungi realm<\/strong><\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValore<\/p>\n<p><strong>Name<\/strong><br \/>\n<code>kubernetes<\/code><\/p>\n<p><strong>Nome visualizzato<\/strong><br \/>\n<code>Kubernetes<\/code><\/p>\n<p><strong>Nome visualizzato in HTML<\/strong><br \/>\n<code>&lt;img src=&quot;https:\/\/kubernetes.io\/images\/nav_logo.svg&quot; width=&quot;400&quot; &gt;<\/code><\/p>\n<p><\/p>\n<p>Kubernetes per impostazione predefinita verifica se l'email dell'utente \u00e8 stata confermata o meno. Poich\u00e9 stiamo usando un server LDAP proprietario, questa verifica restituir\u00e0 quasi sempre <code>false<\/code>. Disattiviamo la visualizzazione di questo parametro in Kubernetes:<\/p>\n<p><\/p>\n<p><strong>Client scopes<\/strong> &mdash;&gt; <strong>Email<\/strong> &mdash;&gt; <strong>Mappers<\/strong> &mdash;&gt; <strong>Email verificata<\/strong> (Elimina)<\/p>\n<p><\/p>\n<p>Ora configuriamo la federazione, quindi andiamo a:<\/p>\n<p><\/p>\n<p><strong>Federazione utenti<\/strong> &mdash;&gt; <strong>Aggiungi provider\u2026<\/strong> &mdash;&gt; <strong>ldap<\/strong><\/p>\n<p><\/p>\n<p>Ecco un esempio di configurazione per FreeIPA:<\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValore<\/p>\n<p><strong>Nome visualizzato della console<\/strong><br \/>\n<code>freeipa.example.org<\/code><\/p>\n<p><strong>Fornitore<\/strong><br \/>\n<code>Red Hat Directory Server<\/code><\/p>\n<p><strong>Attributo UUID LDAP<\/strong><br \/>\n<code>ipauniqueid<\/code><\/p>\n<p><strong>URL di connessione<\/strong><br \/>\n<code>ldaps:\/\/freeipa.example.org<\/code><\/p>\n<p><strong>DN utenti<\/strong><br \/>\n<code>cn=users,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>DN di bind<\/strong><br \/>\n<code>uid=keycloak-svc,cn=users,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>Credenziale di bind<\/strong><br \/>\n<code>&lt;password&gt;<\/code><\/p>\n<p><strong>Consenti l'autenticazione Kerberos:<\/strong><br \/>\n<code>on<\/code><\/p>\n<p><strong>Realm Kerberos:<\/strong><br \/>\n<code>EXAMPLE.ORG<\/code><\/p>\n<p><strong>Server Principal:<\/strong><br \/>\n<code>HTTP\/freeipa.example.org@EXAMPLE.ORG<\/code><\/p>\n<p><strong>KeyTab:<\/strong><br \/>\n<code>\/etc\/krb5.keytab<\/code><\/p>\n<p><\/p>\n<p>L'utente <code>keycloak-svc<\/code> deve essere creato in anticipo sul nostro server LDAP.<\/p>\n<p><\/p>\n<p>Nel caso di Active Directory, \u00e8 sufficiente selezionare <strong>Fornitore: Active Directory<\/strong> e le impostazioni necessarie verranno automaticamente inserite nel modulo.<\/p>\n<p><\/p>\n<p>Clicchiamo su <strong>Salva<\/strong><\/p>\n<p><\/p>\n<p>Ora passiamo a:<\/p>\n<p><\/p>\n<p><strong>Federazione utenti<\/strong> &mdash;&gt; <strong>freeipa.example.org<\/strong> &mdash;&gt; <strong>Mappers<\/strong> &mdash;&gt; <strong>Nome<\/strong><\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValore<\/p>\n<p><strong>Attributo LDAP<\/strong><br \/>\n<code>givenName<\/code><\/p>\n<p><\/p>\n<p>Ora abilitiamo il mapping dei gruppi:<\/p>\n<p><\/p>\n<p><strong>Federazione utenti<\/strong> &mdash;&gt; <strong>freeipa.example.org<\/strong> &mdash;&gt; <strong>Mappers<\/strong> &mdash;&gt; <strong>Crea<\/strong><\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValore<\/p>\n<p><strong>Name<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><strong>Tipo di mapper<\/strong><br \/>\n<code>group-ldap-mapper<\/code><\/p>\n<p><strong>DN dei gruppi LDAP<\/strong><br \/>\n<code>cn=groups,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>Strategia di recupero dei gruppi utente<\/strong><br \/>\n<code>GET_GROUPS_FROM_USER_MEMBEROF_ATTRIBUTE<\/code><\/p>\n<p><\/p>\n<p>Questa \u00e8 la conclusione della configurazione della federazione, passiamo alla configurazione del client.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-klienta\">Configurazione del client<\/h2>\n<p><\/p>\n<p>Creeremo un nuovo client (l'applicazione che ricever\u00e0 utenti da Keycloak). Passiamo a:<\/p>\n<p><\/p>\n<p><strong>Clienti<\/strong> &mdash;&gt; <strong>Crea<\/strong><\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValore<\/p>\n<p><strong>ID del Client<\/strong><br \/>\n<code>kubernetes<\/code><\/p>\n<p><strong>Tipo di accesso<\/strong><br \/>\n<code>confidenziale<\/code><\/p>\n<p><strong>URL di root<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/<\/code><\/p>\n<p><strong>URI di reindirizzamento validi<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/*<\/code><\/p>\n<p><strong>URL di amministrazione<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/<\/code><\/p>\n<p><\/p>\n<p>Creeremo anche uno scope per i gruppi:<\/p>\n<p><\/p>\n<p><strong>Scope del client<\/strong> &mdash;&gt; <strong>Crea<\/strong><\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValore<\/p>\n<p><strong>Template<\/strong><br \/>\n<code>Nessun modello<\/code><\/p>\n<p><strong>Name<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><strong>Percorso completo del gruppo<\/strong><br \/>\n<code>false<\/code><\/p>\n<p><\/p>\n<p>E configureremo il mapper per essi:<\/p>\n<p><\/p>\n<p><strong>Scope del client<\/strong> &mdash;&gt; <strong>groups<\/strong> &mdash;&gt; <strong>Mappers<\/strong> &mdash;&gt; <strong>Crea<\/strong><\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValore<\/p>\n<p><strong>Name<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><strong>Tipo di mapper<\/strong><br \/>\n<code>Appartenenza al gruppo<\/code><\/p>\n<p><strong>Nome di reclamo del token<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><\/p>\n<p>Ora dobbiamo abilitare il mapping dei gruppi nel nostro client scope:<\/p>\n<p><\/p>\n<p><strong>Clienti<\/strong> &mdash;&gt; <strong>kubernetes<\/strong> &mdash;&gt; <strong>Scope del client<\/strong> &mdash;&gt; <strong>Scope client predefiniti<\/strong><\/p>\n<p><\/p>\n<p>Selezioniamo <strong>groups<\/strong> in <strong>Scope client disponibili<\/strong>, facciamo clic su <strong>Aggiungi selezionati<\/strong><\/p>\n<p><\/p>\n<p>Ora configuriamo l'autenticazione della nostra applicazione, passiamo a:<\/p>\n<p><\/p>\n<p><strong>Clienti<\/strong> &mdash;&gt; <strong>kubernetes<\/strong><\/p>\n<p><\/p>\n<p>Opzione<br \/>\nValore<\/p>\n<p><strong>Autorizzazione abilitata<\/strong><br \/>\n<code>ON<\/code><\/p>\n<p><\/p>\n<p>Facciamo clic su <strong>salva<\/strong> e con questo la configurazione del client \u00e8 completata, ora nella scheda<\/p>\n<p><\/p>\n<p><strong>Clienti<\/strong> &mdash;&gt; <strong>kubernetes<\/strong> &mdash;&gt; <strong>Credenziali<\/strong><\/p>\n<p><\/p>\n<p>potrete ottenere <strong>Secret<\/strong> che utilizzeremo in seguito.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-kubernetes\">Configurazione di Kubernetes<\/h2>\n<p><\/p>\n<p>La configurazione di Kubernetes per l'autenticazione OIDC \u00e8 piuttosto semplice e non presenta nulla di complesso. tutto ci\u00f2 di cui avete bisogno \u00e8 posizionare il certificato CA del vostro server OIDC in <code>\/etc\/kubernetes\/pki\/oidc-ca.pem<\/code> e aggiungere le opzioni necessarie per kube-apiserver.<br \/>\nPer fare ci\u00f2, aggiornate <code>\/etc\/kubernetes\/manifests\/kube-apiserver.yaml<\/code> su tutti i vostri nodi master:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">...\nspec:\n  containers:\n  - command:\n    - kube-apiserver\n...\n    - --oidc-ca-file=\/etc\/kubernetes\/pki\/oidc-ca.pem\n    - --oidc-client-id=kubernetes\n    - --oidc-groups-claim=groups\n    - --oidc-issuer-url=https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\n    - --oidc-username-claim=email\n...<\/code><\/pre>\n<p><\/p>\n<p>Inoltre, aggiornate il file di configurazione kubeadm nel cluster per non perdere queste impostazioni durante l'aggiornamento:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">kubectl edit -n kube-system configmaps kubeadm-config<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"plaintext\">...\ndata:\n  ClusterConfiguration: |\n    apiServer:\n      extraArgs:\n        oidc-ca-file: \/etc\/kubernetes\/pki\/oidc-ca.pem\n        oidc-client-id: kubernetes\n        oidc-groups-claim: groups\n        oidc-issuer-url: https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\n        oidc-username-claim: email\n...<\/code><\/pre>\n<p><\/p>\n<p>A questo punto la configurazione di Kubernetes \u00e8 completata. Potete ripetere queste azioni in tutti i vostri cluster Kubernetes.<\/p>\n<p><\/p>\n<h2 id=\"nachalnaya-avtorizaciya\">Autenticazione iniziale<\/h2>\n<p><\/p>\n<p>Dopo queste operazioni avrete un cluster Kubernetes con l'autenticazione OIDC configurata. L'unico problema \u00e8 che i vostri utenti non hanno ancora un client configurato n\u00e9 un proprio kubeconfig. Per risolvere questo problema, dovete impostare la generazione automatica del kubeconfig per gli utenti dopo l'autenticazione riuscita.<\/p>\n<p><\/p>\n<p>A questo scopo \u00e8 possibile utilizzare applicazioni web speciali che consentono di autenticare l'utente e poi scaricare il kubeconfig pronto. Una delle pi\u00f9 comode \u00e8 <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/negz\/kuberos\">Kuberos<\/a><\/noindex>, consente di descrivere tutti i cluster Kubernetes in un'unica configurazione e di passare facilmente da uno all'altro.<\/p>\n<p><\/p>\n<p>Per configurare Kuberos, \u00e8 sufficiente descrivere il template per kubeconfig e avviarlo con i seguenti parametri:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">kuberos https:\/\/keycloak.example.org\/auth\/realms\/kubernetes kubernetes \/cfg\/secret \/cfg\/template<\/code><\/pre>\n<p><\/p>\n<p>Per informazioni pi\u00f9 dettagliate, consulta <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/negz\/kuberos#usage\">Utilizzo<\/a><\/noindex> GitHub.<\/p>\n<p><\/p>\n<p>\u00c8 anche possibile utilizzare <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/int128\/kubelogin\">kubelogin<\/a><\/noindex> se desideri eseguire l'autenticazione direttamente sul computer dell'utente. In questo caso, si aprir\u00e0 un browser con un modulo di autenticazione su localhost.<\/p>\n<p><\/p>\n<p>Il kubeconfig ottenuto pu\u00f2 essere controllato sul sito <noindex><a rel=\"nofollow\" href=\"https:\/\/jwt.io\/#debugger-io\">jwt.io<\/a><\/noindex>. Basta copiare il valore <code>users[].user.auth-provider.config.id-token<\/code> dal tuo kubeconfig nel modulo sul sito e ottenere immediatamente la decodifica.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-rbac\">Configurazione RBAC<\/h2>\n<p><\/p>\n<p>Durante la configurazione di RBAC, puoi fare riferimento sia al nome utente (campo <code>name<\/code> nel token jwt), sia al gruppo di utenti (campo <code>groups<\/code> nel token jwt). Ecco un esempio di configurazione dei diritti per il gruppo <code>kubernetes-default-namespace-admins<\/code>:<\/p>\n<p>\n<b class=\"spoiler_title\">kubernetes-default-namespace-admins.yaml<\/b><\/p>\n<pre><code class=\"plaintext\">apiVersion: rbac.authorization.k8s.io\/v1\nkind: Role\nmetadata:\n  name: default-admins\n  namespace: default\nrules:\n- apiGroups:\n  - '*'\n  resources:\n  - '*'\n  verbs:\n  - '*'\n---\napiVersion: rbac.authorization.k8s.io\/v1\nkind: RoleBinding\nmetadata:\n  name: kubernetes-default-namespace-admins\n  namespace: default\nroleRef:\n  apiGroup: rbac.authorization.k8s.io\n  kind: Role\n  name: default-admins\nsubjects:\n- apiGroup: rbac.authorization.k8s.io\n  kind: Group\n  name: kubernetes-default-namespace-admins<\/code><\/pre>\n<p><\/p>\n<p>Ulteriori esempi per RBAC possono essere trovati in <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/reference\/access-authn-authz\/rbac\/\">documentazione ufficiale di Kubernetes<\/a><\/noindex><\/p>\n<p><\/p>\n<h2 id=\"nastroyka-auth-proxy\">Configurazione auth-proxy<\/h2>\n<p><\/p>\n<p>C'\u00e8 un ottimo progetto <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/keycloak\/keycloak-gatekeeper\">keycloak-gatekeeper<\/a><\/noindex>, che consente di proteggere qualsiasi applicazione, offrendo all'utente la possibilit\u00e0 di autenticarsi su un server OIDC. Mostrer\u00f2 come configurarlo utilizzando l'esempio di Kubernetes Dashboard:<\/p>\n<p>\n<b class=\"spoiler_title\">dashboard-proxy.yaml<\/b><\/p>\n<pre><code class=\"plaintext\">apiVersion: extensions\/v1beta1\nkind: Deployment\nmetadata:\n  name: kubernetes-dashboard-proxy\nspec:\n  replicas: 1\n  template:\n    metadata:\n      labels:\n        app: kubernetes-dashboard-proxy\n    spec:\n      containers:\n      - args:\n        - --listen=0.0.0.0:80\n        - --discovery-url=https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\n        - --client-id=kubernetes\n        - --client-secret=\n        - --redirection-url=https:\/\/kubernetes-dashboard.example.org\n        - --enable-refresh-tokens=true\n        - --encryption-key=ooTh6Chei1eefooyovai5ohwienuquoh\n        - --upstream-url=https:\/\/kubernetes-dashboard.kube-system\n        - --resources=uri=\/*\n        image: keycloak\/keycloak-gatekeeper\n        name: kubernetes-dashboard-proxy\n        ports:\n        - containerPort: 80\n          livenessProbe:\n            httpGet:\n              path: \/oauth\/health\n              port: 80\n            initialDelaySeconds: 3\n            timeoutSeconds: 2\n          readinessProbe:\n            httpGet:\n              path: \/oauth\/health\n              port: 80\n            initialDelaySeconds: 3\n            timeoutSeconds: 2\n---\napiVersion: v1\nkind: Service\nmetadata:\n  name: kubernetes-dashboard-proxy\nspec:\n  ports:\n  - port: 80\n    protocol: TCP\n    targetPort: 80\n  selector:\n    app: kubernetes-dashboard-proxy\n  type: ClusterIP<\/code><\/pre>\n<p>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/441112\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Keycloak \u043c\u043e\u0436\u043d\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c Kubernetes \u0441 \u0432\u0430\u0448\u0438\u043c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0438\u043c\u043f\u043e\u0440\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0433\u0440\u0443\u043f\u043f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c auth-proxy \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c Kubernetes Dashboard \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0447\u0442\u043e \u0443 \u0432\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c Active [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":70868,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-70867","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Keycloak \u043c\u043e\u0436\u043d\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c Kubernetes \u0441 \u0432\u0430\u0448\u0438\u043c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0438\u043c\u043f\u043e\u0440\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0433\u0440\u0443\u043f\u043f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c auth-proxy \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c Kubernetes Dashboard \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0447\u0442\u043e \u0443 \u0432\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c Active\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c LDAP-\u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Keycloak \u043c\u043e\u0436\u043d\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c Kubernetes \u0441 \u0432\u0430\u0448\u0438\u043c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0438\u043c\u043f\u043e\u0440\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0433\u0440\u0443\u043f\u043f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c auth-proxy \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c Kubernetes Dashboard \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0447\u0442\u043e \u0443 \u0432\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c Active\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-22T03:40:58+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-03T13:14:36+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Colleghiamo l'autenticazione LDAP a Kubernetes | ProHoster","description":"Una breve guida su come utilizzare Keycloak per connettere Kubernetes al tuo server LDAP e configurare l'importazione di utenti e gruppi. Questo permetter\u00e0 di impostare RBAC per i tuoi utenti e utilizzare un auth-proxy per proteggere il Kubernetes Dashboard e altre applicazioni che non possono gestire l'autenticazione autonomamente. Installazione di Keycloak Supponiamo che tu abbia gi\u00e0 un server LDAP. Questo pu\u00f2 essere Active","canonical_url":"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c LDAP-\u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes | ProHoster","og:description":"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Keycloak \u043c\u043e\u0436\u043d\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c Kubernetes \u0441 \u0432\u0430\u0448\u0438\u043c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0438\u043c\u043f\u043e\u0440\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0433\u0440\u0443\u043f\u043f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c auth-proxy \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c Kubernetes Dashboard \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0447\u0442\u043e \u0443 \u0432\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c Active","og:url":"https:\/\/prohoster.info\/it\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-22T03:40:58+00:00","article:modified_time":"2020-03-03T13:14:36+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"70867","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:12:23","updated":"2022-09-28 01:58:51"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/70867","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=70867"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/70867\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/70868"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=70867"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=70867"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=70867"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}