{"id":70867,"date":"2020-02-22T06:40:58","date_gmt":"2020-02-22T03:40:58","guid":{"rendered":"https:\/\/prohoster.info\/blog\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes"},"modified":"2020-03-03T16:14:36","modified_gmt":"2020-03-03T13:14:36","slug":"prikruchivaem-ldap-avtorizacziyu-k-kubernetes","status":"publish","type":"post","link":"https:\/\/prohoster.info\/pl\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","title":{"rendered":"Pod\u0142\u0105czanie autoryzacji LDAP do Kubernetes","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Pod\u0142\u0105czanie autoryzacji LDAP do Kubernetes\" src=\"\/wp-content\/uploads\/2020\/02\/2b0f0a4921e049a78a015e7693d697cf.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>Ma\u0142a instrukcja, jak za pomoc\u0105 Keycloak po\u0142\u0105czy\u0107 Kubernetes z Twoim serwerem LDAP oraz skonfigurowa\u0107 import u\u017cytkownik\u00f3w i grup. Pozwoli to na skonfigurowanie RBAC dla Twoich u\u017cytkownik\u00f3w i u\u017cycie auth-proxy do zabezpieczenia Kubernetes Dashboard oraz innych aplikacji, kt\u00f3re nie potrafi\u0105 same przeprowadza\u0107 autoryzacji.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2 id=\"ustanovka-keycloak\">Instalacja Keycloak<\/h2>\n<p><\/p>\n<p>Zak\u0142adamy, \u017ce masz ju\u017c serwer LDAP. Mo\u017ce to by\u0107 Active Directory, FreeIPA, OpenLDAP lub co\u015b innego. Je\u015bli nie masz serwera LDAP, mo\u017cesz tworzy\u0107 u\u017cytkownik\u00f3w bezpo\u015brednio w interfejsie Keycloak lub korzysta\u0107 z publicznych dostawc\u00f3w oidc (Google, Github, Gitlab), wynik b\u0119dzie prawie taki sam.<\/p>\n<p><\/p>\n<p>Na pocz\u0105tku zainstalujemy sam Keycloak; instalacja mo\u017ce przebiega\u0107 osobno lub od razu w klastrze Kubernetes. Zazwyczaj, je\u015bli posiadasz kilka klastr\u00f3w Kubernetes, \u0142atwiej by\u0142oby zainstalowa\u0107 go osobno. Z drugiej strony, zawsze mo\u017cesz u\u017cy\u0107 <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/helm\/charts\/tree\/master\/stable\/keycloak\">oficjalnego szablonu helm<\/a><\/noindex> i zainstalowa\u0107 go bezpo\u015brednio w swoim klastrze.<\/p>\n<p><\/p>\n<p>Aby przechowywa\u0107 dane Keycloak, potrzebujesz bazy danych. Domy\u015blnie wykorzystywana jest <code>h2<\/code> (wszystkie dane s\u0105 przechowywane lokalnie), ale mo\u017cesz r\u00f3wnie\u017c u\u017cy\u0107 <code>postgres<\/code>, <code>mysql<\/code> lub <code>mariadb<\/code>.<br \/>\nJe\u015bli jednak zdecydujesz si\u0119 zainstalowa\u0107 Keycloak osobno, bardziej szczeg\u00f3\u0142owe instrukcje znajdziesz w <noindex><a rel=\"nofollow\" href=\"https:\/\/www.keycloak.org\/docs\/latest\/getting_started\/index.html\">oficjalnej dokumentacji<\/a><\/noindex>.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-federacii\">Konfigurowanie federacji<\/h2>\n<p><\/p>\n<p>Na pocz\u0105tku stw\u00f3rzmy nowy realm. Realm to przestrze\u0144 naszej aplikacji. Ka\u017cda aplikacja mo\u017ce mie\u0107 sw\u00f3j realm z r\u00f3\u017cnymi u\u017cytkownikami i ustawieniami autoryzacji. Realm g\u0142\u00f3wny jest u\u017cywany przez sam Keycloak i nie powinno si\u0119 go u\u017cywa\u0107 do innych cel\u00f3w.<\/p>\n<p><\/p>\n<p>Klikamy <strong>Dodaj realm<\/strong><\/p>\n<p><\/p>\n<p>Opcja<br \/>\n@Value<\/p>\n<p><strong>Nazwa<\/strong><br \/>\n<code>kubernetes<\/code><\/p>\n<p><strong>Nazwa wy\u015bwietlana<\/strong><br \/>\n<code>Kubernetes<\/code><\/p>\n<p><strong>Nazwa wy\u015bwietlana w HTML<\/strong><br \/>\n<code>&lt;img src=&quot;https:\/\/kubernetes.io\/images\/nav_logo.svg&quot; width=&quot;400&quot; &gt;<\/code><\/p>\n<p><\/p>\n<p>Kubernetes domy\u015blnie sprawdza, czy u\u017cytkownik potwierdzi\u0142 sw\u00f3j email. Poniewa\u017c u\u017cywamy w\u0142asnego serwera LDAP, ta weryfikacja prawie zawsze zwr\u00f3ci <code>false<\/code>. Wy\u0142\u0105czmy wy\u015bwietlanie tego parametru w Kubernetes:<\/p>\n<p><\/p>\n<p><strong>Zakresy klient\u00f3w<\/strong> \u2014&gt; <strong>Email<\/strong> \u2014&gt; <strong>Mapery<\/strong> \u2014&gt; <strong>Email zweryfikowany<\/strong> (Usu\u0144)<\/p>\n<p><\/p>\n<p>Teraz skonfigurujemy federacj\u0119, przejd\u017amy do:<\/p>\n<p><\/p>\n<p><strong>Federacja u\u017cytkownik\u00f3w<\/strong> \u2014&gt; <strong>Dodaj dostawc\u0119\u2026<\/strong> \u2014&gt; <strong>ldap<\/strong><\/p>\n<p><\/p>\n<p>Podam przyk\u0142ad konfiguracji dla FreeIPA:<\/p>\n<p><\/p>\n<p>Opcja<br \/>\n@Value<\/p>\n<p><strong>Nazwa wy\u015bwietlana w konsoli<\/strong><br \/>\n<code>freeipa.example.org<\/code><\/p>\n<p><strong>Dostawca<\/strong><br \/>\n<code>Red Hat Directory Server<\/code><\/p>\n<p><strong>Atrybut UUID LDAP<\/strong><br \/>\n<code>ipauniqueid<\/code><\/p>\n<p><strong>Adres URL po\u0142\u0105czenia<\/strong><br \/>\n<code>ldaps:\/\/freeipa.example.org<\/code><\/p>\n<p><strong>DN u\u017cytkownik\u00f3w<\/strong><br \/>\n<code>cn=u\u017cytkownicy,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>Bind DN<\/strong><br \/>\n<code>uid=keycloak-svc,cn=u\u017cytkownicy,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>Bind Credential<\/strong><br \/>\n<code>&lt;password&gt;<\/code><\/p>\n<p><strong>Zezw\u00f3l na uwierzytelnienie Kerberos:<\/strong><br \/>\n<code>w\u0142\u0105czony<\/code><\/p>\n<p><strong>Realm Kerberos:<\/strong><br \/>\n<code>EXAMPLE.ORG<\/code><\/p>\n<p><strong>Principal serwera:<\/strong><br \/>\n<code>HTTP\/freeipa.example.org@EXAMPLE.ORG<\/code><\/p>\n<p><strong>KeyTab:<\/strong><br \/>\n<code>\/etc\/krb5.keytab<\/code><\/p>\n<p><\/p>\n<p>U\u017cytkownik <code>keycloak-svc<\/code> musi by\u0107 wcze\u015bniej utworzony na naszym serwerze LDAP.<\/p>\n<p><\/p>\n<p>W przypadku Active Directory wystarczy po prostu wybra\u0107 <strong>Dostawca: Active Directory<\/strong> i niezb\u0119dne ustawienia zostan\u0105 automatycznie wstawione do formularza.<\/p>\n<p><\/p>\n<p>Klikamy <strong>Zapisz<\/strong><\/p>\n<p><\/p>\n<p>Teraz przejd\u017amy do:<\/p>\n<p><\/p>\n<p><strong>Federacja u\u017cytkownik\u00f3w<\/strong> \u2014&gt; <strong>freeipa.example.org<\/strong> \u2014&gt; <strong>Mapery<\/strong> \u2014&gt; <strong>Imi\u0119<\/strong><\/p>\n<p><\/p>\n<p>Opcja<br \/>\n@Value<\/p>\n<p><strong>Atrybut Ldap<\/strong><br \/>\n<code>givenName<\/code><\/p>\n<p><\/p>\n<p>Teraz w\u0142\u0105czymy mapowanie grup:<\/p>\n<p><\/p>\n<p><strong>Federacja u\u017cytkownik\u00f3w<\/strong> \u2014&gt; <strong>freeipa.example.org<\/strong> \u2014&gt; <strong>Mapery<\/strong> \u2014&gt; <strong>Utw\u00f3rz<\/strong><\/p>\n<p><\/p>\n<p>Opcja<br \/>\n@Value<\/p>\n<p><strong>Nazwa<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><strong>Typ mappera<\/strong><br \/>\n<code>group-ldap-mapper<\/code><\/p>\n<p><strong>LDAP Groups DN<\/strong><br \/>\n<code>cn=groups,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>Strategia pobierania grup u\u017cytkownik\u00f3w<\/strong><br \/>\n<code>GET_GROUPS_FROM_USER_MEMBEROF_ATTRIBUTE<\/code><\/p>\n<p><\/p>\n<p>Na tym konfiguracja federacji jest zako\u0144czona, przechodzimy do ustawienia klienta.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-klienta\">Konfiguracja klienta<\/h2>\n<p><\/p>\n<p>Utworzymy nowego klienta (aplikacja, kt\u00f3ra b\u0119dzie pobiera\u0107 u\u017cytkownik\u00f3w z Keycloak). Przechodzimy do:<\/p>\n<p><\/p>\n<p><strong>Klienci<\/strong> \u2014&gt; <strong>Utw\u00f3rz<\/strong><\/p>\n<p><\/p>\n<p>Opcja<br \/>\n@Value<\/p>\n<p><strong>ID klienta<\/strong><br \/>\n<code>kubernetes<\/code><\/p>\n<p><strong>Typ dost\u0119pu<\/strong><br \/>\n<code>confidenrial<\/code><\/p>\n<p><strong>Adres URL korzenia<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/<\/code><\/p>\n<p><strong>Poprawne adresy URL przekierowania<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/*<\/code><\/p>\n<p><strong>Adres URL admina<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/<\/code><\/p>\n<p><\/p>\n<p>Utworzymy tak\u017ce zakres dla grup:<\/p>\n<p><\/p>\n<p><strong>Zakresy klienta<\/strong> \u2014&gt; <strong>Utw\u00f3rz<\/strong><\/p>\n<p><\/p>\n<p>Opcja<br \/>\n@Value<\/p>\n<p><strong>Szablon<\/strong><br \/>\n<code>Brak szablonu<\/code><\/p>\n<p><strong>Nazwa<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><strong>Pe\u0142na \u015bcie\u017cka grupy<\/strong><br \/>\n<code>false<\/code><\/p>\n<p><\/p>\n<p>I skonfigurujemy mapper dla nich:<\/p>\n<p><\/p>\n<p><strong>Zakresy klienta<\/strong> \u2014&gt; <strong>groups<\/strong> \u2014&gt; <strong>Mapery<\/strong> \u2014&gt; <strong>Utw\u00f3rz<\/strong><\/p>\n<p><\/p>\n<p>Opcja<br \/>\n@Value<\/p>\n<p><strong>Nazwa<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><strong>Typ mappera<\/strong><br \/>\n<code>Cz\u0142onkostwo grupowe<\/code><\/p>\n<p><strong>Nazwa roszczenia tokena<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><\/p>\n<p>Teraz musimy w\u0142\u0105czy\u0107 mapowanie grup w naszym zakresie klienta:<\/p>\n<p><\/p>\n<p><strong>Klienci<\/strong> \u2014&gt; <strong>kubernetes<\/strong> \u2014&gt; <strong>Zakresy klienta<\/strong> \u2014&gt; <strong>Domy\u015blne zakresy klienta<\/strong><\/p>\n<p><\/p>\n<p>Wybieramy <strong>groups<\/strong> do <strong>Dost\u0119pne zakresy klienta<\/strong>, klikamy <strong>Dodaj wybrane<\/strong><\/p>\n<p><\/p>\n<p>Teraz skonfigurujemy autoryzacj\u0119 naszej aplikacji, przechodzimy do:<\/p>\n<p><\/p>\n<p><strong>Klienci<\/strong> \u2014&gt; <strong>kubernetes<\/strong><\/p>\n<p><\/p>\n<p>Opcja<br \/>\n@Value<\/p>\n<p><strong>Autoryzacja w\u0142\u0105czona<\/strong><br \/>\n<code>W\u0141\u0104CZONE<\/code><\/p>\n<p><\/p>\n<p>Klikamy <strong>zapisz<\/strong> i na tym ustawienie klienta zosta\u0142o zako\u0144czone, teraz na zak\u0142adce<\/p>\n<p><\/p>\n<p><strong>Klienci<\/strong> \u2014&gt; <strong>kubernetes<\/strong> \u2014&gt; <strong>Po\u015bwiadczenia<\/strong><\/p>\n<p><\/p>\n<p>b\u0119dziecie mogli uzyska\u0107 <strong>Secret<\/strong> kt\u00f3ry b\u0119dziemy u\u017cywa\u0107 w przysz\u0142o\u015bci.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-kubernetes\">Konfiguracja Kubernetes<\/h2>\n<p><\/p>\n<p>Konfiguracja Kubernetes dla autoryzacji OIDC jest wystarczaj\u0105co prosta i nie jest zbyt skomplikowana. Wszystko, co musisz zrobi\u0107, to umie\u015bci\u0107 certyfikat CA swojego serwera OIDC w <code>\/etc\/kubernetes\/pki\/oidc-ca.pem<\/code> i doda\u0107 niezb\u0119dne opcje do kube-apiserver.<br \/>\nW tym celu zaktualizuj <code>\/etc\/kubernetes\/manifests\/kube-apiserver.yaml<\/code> na wszystkich swoich w\u0119z\u0142ach master:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">...\nspec:\n  kontenery:\n  - komenda:\n    - kube-apiserver\n...\n    - --oidc-ca-file=\\\/etc\\\/kubernetes\\\/pki\\\/oidc-ca.pem\n    - --oidc-client-id=kubernetes\n    - --oidc-groups-claim=groups\n    - --oidc-issuer-url=https:\\\/\\\/keycloak.example.org\\\/auth\\\/realms\\\/kubernetes\n    - --oidc-username-claim=email\n...<\/code><\/pre>\n<p><\/p>\n<p>Zaktualizuj r\u00f3wnie\u017c konfiguracj\u0119 kubeadm w klastrze, aby nie straci\u0107 tych ustawie\u0144 podczas aktualizacji:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">kubectl edit -n kube-system configmaps kubeadm-config<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"plaintext\">...\ndata:\n  ClusterConfiguration: |\n    apiServer:\n      extraArgs:\n        oidc-ca-file: \\\/etc\\\/kubernetes\\\/pki\\\/oidc-ca.pem\n        oidc-client-id: kubernetes\n        oidc-groups-claim: groups\n        oidc-issuer-url: https:\\\/\\\/keycloak.example.org\\\/auth\\\/realms\\\/kubernetes\n        oidc-username-claim: email\n...<\/code><\/pre>\n<p><\/p>\n<p>Na tym konfiguracja Kubernetes jest zako\u0144czona. Mo\u017cesz powt\u00f3rzy\u0107 te same dzia\u0142ania we wszystkich swoich klastrach Kubernetes.<\/p>\n<p><\/p>\n<h2 id=\"nachalnaya-avtorizaciya\">Wst\u0119pna autoryzacja<\/h2>\n<p><\/p>\n<p>Po tych dzia\u0142aniach b\u0119dziesz mie\u0107 klaster Kubernetes z skonfigurowan\u0105 autoryzacj\u0105 OIDC. Jedyn\u0105 kwesti\u0105 jest to, \u017ce twoi u\u017cytkownicy na razie nie maj\u0105 skonfigurowanego klienta ani w\u0142asnego kubeconfig. Aby rozwi\u0105za\u0107 ten problem, musisz skonfigurowa\u0107 automatyczne wydawanie kubeconfig u\u017cytkownikom po pomy\u015blnej autoryzacji.<\/p>\n<p><\/p>\n<p>Mo\u017cesz do tego u\u017cy\u0107 specjalnych aplikacji webowych, kt\u00f3re umo\u017cliwiaj\u0105 przeprowadzenie autoryzacji u\u017cytkownika, a nast\u0119pnie pobranie gotowego kubeconfigu. Jedna z najdogodniejszych to <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/negz\/kuberos\">Kuberos<\/a><\/noindex>, umo\u017cliwia opisanie wszystkich klastr\u00f3w Kubernetes w jednej konfiguracji i \u0142atwe prze\u0142\u0105czanie si\u0119 mi\u0119dzy nimi.<\/p>\n<p><\/p>\n<p>Aby skonfigurowa\u0107 Kuberos, wystarczy opisa\u0107 szablon dla kubeconfig i uruchomi\u0107 go z nast\u0119puj\u0105cymi parametrami:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">kuberos https:\/\/keycloak.example.org\/auth\/realms\/kubernetes kubernetes \/cfg\/secret \/cfg\/template<\/code><\/pre>\n<p><\/p>\n<p>Aby uzyska\u0107 bardziej szczeg\u00f3\u0142owe informacje, zobacz <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/negz\/kuberos#usage\">Usage<\/a><\/noindex> na Githubie.<\/p>\n<p><\/p>\n<p>Mo\u017cna r\u00f3wnie\u017c u\u017cy\u0107 <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/int128\/kubelogin\">kubelogin<\/a><\/noindex> , je\u015bli chcesz przeprowadzi\u0107 autoryzacj\u0119 bezpo\u015brednio na komputerze u\u017cytkownika. W takim przypadku przegl\u0105darka u\u017cytkownika otworzy stron\u0119 z formularzem autoryzacji na localhost.<\/p>\n<p><\/p>\n<p>Otrzymany kubeconfig mo\u017cna sprawdzi\u0107 na stronie <noindex><a rel=\"nofollow\" href=\"https:\/\/jwt.io\/#debugger-io\">jwt.io<\/a><\/noindex>. Wystarczy skopiowa\u0107 warto\u015b\u0107 <code>users[].user.auth-provider.config.id-token<\/code> z twojego kubeconfig do formularza na stronie, aby natychmiast uzyska\u0107 rozszyfrowanie.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-rbac\">Konfiguracja RBAC<\/h2>\n<p><\/p>\n<p>Podczas konfigurowania RBAC mo\u017cna odnosi\u0107 si\u0119 zar\u00f3wno do nazwy u\u017cytkownika (pola <code>name<\/code> w tokenie jwt), jak i do grupy u\u017cytkownik\u00f3w (pola <code>groups<\/code> w tokenie jwt). Oto przyk\u0142ad konfiguracji uprawnie\u0144 dla grupy <code>kubernetes-default-namespace-admins<\/code>:<\/p>\n<p>\n<b class=\"spoiler_title\">kubernetes-default-namespace-admins.yaml<\/b><\/p>\n<pre><code class=\"plaintext\">apiVersion: rbac.authorization.k8s.io\/v1\nkind: Role\nmetadata:\n  name: default-admins\n  namespace: default\nrules:\n- apiGroups:\n  - '*'\n  resources:\n  - '*'\n  verbs:\n  - '*'\n---\napiVersion: rbac.authorization.k8s.io\/v1\nkind: RoleBinding\nmetadata:\n  name: kubernetes-default-namespace-admins\n  namespace: default\nroleRef:\n  apiGroup: rbac.authorization.k8s.io\n  kind: Role\n  name: default-admins\nsubjects:\n- apiGroup: rbac.authorization.k8s.io\n  kind: Group\n  name: kubernetes-default-namespace-admins<\/code><\/pre>\n<p><\/p>\n<p>Wi\u0119cej przyk\u0142ad\u00f3w dla RBAC mo\u017cna znale\u017a\u0107 w <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/reference\/access-authn-authz\/rbac\/\">oficjalnej dokumentacji Kubernetes<\/a><\/noindex><\/p>\n<p><\/p>\n<h2 id=\"nastroyka-auth-proxy\">Konfiguracja auth-proxy<\/h2>\n<p><\/p>\n<p>Istnieje wspania\u0142y projekt <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/keycloak\/keycloak-gatekeeper\">keycloak-gatekeeper<\/a><\/noindex>, kt\u00f3ry pozwala zabezpieczy\u0107 dowoln\u0105 aplikacj\u0119, daj\u0105c u\u017cytkownikowi mo\u017cliwo\u015b\u0107 uwierzytelnienia na serwerze OIDC. Poka\u017c\u0119, jak mo\u017cna go skonfigurowa\u0107 na przyk\u0142adzie Kubernetes Dashboard:<\/p>\n<p>\n<b class=\"spoiler_title\">dashboard-proxy.yaml<\/b><\/p>\n<pre><code class=\"plaintext\">apiVersion: extensions\/v1beta1\nkind: Deployment\nmetadata:\n  name: kubernetes-dashboard-proxy\nspec:\n  replicas: 1\n  template:\n    metadata:\n      labels:\n        app: kubernetes-dashboard-proxy\n    spec:\n      containers:\n      - args:\n        - --listen=0.0.0.0:80\n        - --discovery-url=https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\n        - --client-id=kubernetes\n        - --client-secret=\n        - --redirection-url=https:\/\/kubernetes-dashboard.example.org\n        - --enable-refresh-tokens=true\n        - --encryption-key=ooTh6Chei1eefooyovai5ohwienuquoh\n        - --upstream-url=https:\/\/kubernetes-dashboard.kube-system\n        - --resources=uri=\/*\n        image: keycloak\/keycloak-gatekeeper\n        name: kubernetes-dashboard-proxy\n        ports:\n        - containerPort: 80\n          livenessProbe:\n            httpGet:\n              path: \/oauth\/health\n              port: 80\n            initialDelaySeconds: 3\n            timeoutSeconds: 2\n          readinessProbe:\n            httpGet:\n              path: \/oauth\/health\n              port: 80\n            initialDelaySeconds: 3\n            timeoutSeconds: 2\n---\napiVersion: v1\nkind: Service\nmetadata:\n  name: kubernetes-dashboard-proxy\nspec:\n  ports:\n  - port: 80\n    protocol: TCP\n    targetPort: 80\n  selector:\n    app: kubernetes-dashboard-proxy\n  type: ClusterIP<\/code><\/pre>\n<p>\u0179r\u00f3d\u0142o: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/441112\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Keycloak \u043c\u043e\u0436\u043d\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c Kubernetes \u0441 \u0432\u0430\u0448\u0438\u043c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0438\u043c\u043f\u043e\u0440\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0433\u0440\u0443\u043f\u043f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c auth-proxy \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c Kubernetes Dashboard \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0447\u0442\u043e \u0443 \u0432\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c Active [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":70868,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-70867","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/pl\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"pl_PL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c LDAP-\u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/pl\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-22T03:40:58+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-03T13:14:36+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Integrujemy autoryzacj\u0119 LDAP z Kubernetes | ProHoster","description":"Kr\u00f3tkie wskaz\u00f3wki, jak to zrobi\u0107.","canonical_url":"https:\/\/prohoster.info\/pl\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"pl_PL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c LDAP-\u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes | ProHoster","og:description":"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a.","og:url":"https:\/\/prohoster.info\/pl\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-22T03:40:58+00:00","article:modified_time":"2020-03-03T13:14:36+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"70867","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:12:23","updated":"2022-09-28 01:58:51","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/70867","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/comments?post=70867"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/70867\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/media\/70868"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/media?parent=70867"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/categories?post=70867"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/tags?post=70867"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}