{"id":70867,"date":"2020-02-22T06:40:58","date_gmt":"2020-02-22T03:40:58","guid":{"rendered":"https:\/\/prohoster.info\/blog\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes"},"modified":"2020-03-03T16:14:36","modified_gmt":"2020-03-03T13:14:36","slug":"prikruchivaem-ldap-avtorizacziyu-k-kubernetes","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","title":{"rendered":"Lidhja e autorizimit LDAP me Kubernetes","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Lidhja e autorizimit LDAP me Kubernetes\" src=\"\/wp-content\/uploads\/2020\/02\/2b0f0a4921e049a78a015e7693d697cf.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>Nj\u00eb udh\u00ebzues i shkurt\u00ebr p\u00ebr m\u00ebnyr\u00ebn se si, duke p\u00ebrdorur Keycloak, mund t\u00eb lidheni Kubernetes me serverin tuaj LDAP dhe t\u00eb konfiguroni importimin e p\u00ebrdoruesve dhe grupeve. Kjo do t\u00eb lejoj\u00eb konfigurimin e RBAC p\u00ebr p\u00ebrdoruesit tuaj dhe p\u00ebrdorimin e auth-proxy p\u00ebr t\u00eb mbrojtur Kubernetes Dashboard dhe aplikacione t\u00eb tjera q\u00eb nuk din\u00eb t\u00eb kryejn\u00eb autorizimin vet\u00eb.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2 id=\"ustanovka-keycloak\">Instalimi i Keycloak<\/h2>\n<p><\/p>\n<p>Supozoni se tashm\u00eb keni nj\u00eb server LDAP. Kjo mund t\u00eb jet\u00eb Active Directory, FreeIPA, OpenLDAP ose ndonj\u00eb gj\u00eb tjet\u00ebr. N\u00ebse nuk keni nj\u00eb server LDAP, mund t\u00eb krijoni p\u00ebrdorues direkt n\u00eb nd\u00ebrfaqen e Keycloak, ose t\u00eb p\u00ebrdorni ofrues publik oidc (Google, Github, Gitlab), rezultati do t\u00eb jet\u00eb pothuajse i nj\u00ebjt\u00eb.<\/p>\n<p><\/p>\n<p>S\u00eb pari, le t\u00eb instalojm\u00eb vet\u00eb Keycloak, instalimi mund t\u00eb realizohet ve\u00e7mas, si dhe direkt n\u00eb klasterin Kubernetes; zakonisht, n\u00ebse keni disa klaster\u00eb Kubernetes, do t\u00eb ishte m\u00eb e leht\u00eb ta instaloni ve\u00e7mas. Nga ana tjet\u00ebr, gjithmon\u00eb mund t\u00eb p\u00ebrdorni <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/helm\/charts\/tree\/master\/stable\/keycloak\">chart-in zyrtar helm<\/a><\/noindex> dhe ta instaloni at\u00eb direkt n\u00eb klasterin tuaj.<\/p>\n<p><\/p>\n<p>P\u00ebr ruajtjen e t\u00eb dh\u00ebnave t\u00eb Keycloak ju nevojitet nj\u00eb baz\u00eb t\u00eb dhash. N\u00eb m\u00ebnyr\u00eb default p\u00ebrdoret <code>h2<\/code> (t\u00eb dh\u00ebnat ruhen lokalisht), por \u00ebsht\u00eb e mundur gjithashtu t\u00eb p\u00ebrdoret <code>postgres<\/code>, <code>mysql<\/code> ose <code>mariadb<\/code>.<br \/>\nN\u00ebse vendosni t\u00eb instaloni Keycloak ve\u00e7mas, do t\u00eb gjeni udh\u00ebzime m\u00eb t\u00eb detajuara n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/www.keycloak.org\/docs\/latest\/getting_started\/index.html\">dokumenti zyrtar<\/a><\/noindex>.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-federacii\">Konfigurimi i federat\u00ebs<\/h2>\n<p><\/p>\n<p>S\u00eb pari, le t\u00eb krijojm\u00eb nj\u00eb realm t\u00eb ri. Realm \u00ebsht\u00eb hap\u00ebsira e aplikacionit ton\u00eb. \u00c7do aplikacion mund t\u00eb ket\u00eb realm t\u00eb vet me p\u00ebrdorues dhe cil\u00ebsime ndihm\u00ebse t\u00eb ndryshme. Master realm p\u00ebrdoret nga vet\u00eb Keycloak dhe nuk \u00ebsht\u00eb e drejt\u00eb ta p\u00ebrdorni at\u00eb p\u00ebr ndonj\u00eb gj\u00eb tjet\u00ebr.<\/p>\n<p><\/p>\n<p>Klikoni <strong>Shto realm<\/strong><\/p>\n<p><\/p>\n<p>Opsioni<br \/>\nVlera<\/p>\n<p><strong>Emri<\/strong><br \/>\n<code>kubernetes<\/code><\/p>\n<p><strong>Emri i Shfaqjes<\/strong><br \/>\n<code>Kubernetes<\/code><\/p>\n<p><strong>Emri i Shfaqjes n\u00eb HTML<\/strong><br \/>\n<code>&lt;img src=&quot;https:\/\/kubernetes.io\/images\/nav_logo.svg&quot; width=&quot;400&quot; &gt;<\/code><\/p>\n<p><\/p>\n<p>Kubernetes n\u00eb m\u00ebnyr\u00eb t\u00eb paracaktuar kontrollon n\u00ebse emaili i p\u00ebrdoruesit \u00ebsht\u00eb konfirmuar apo jo. Duke qen\u00eb se ne p\u00ebrdorim nj\u00eb server LDAP t\u00eb paracaktuar, kjo kontrollim pothuajse gjithmon\u00eb do t\u00eb kthej\u00eb <code>false<\/code>. Le ta \u00e7aktivizojm\u00eb shfaqjen e k\u00ebtij parametri n\u00eb Kubernetes:<\/p>\n<p><\/p>\n<p><strong>Klient\u00ebt scopes<\/strong> \u2014&gt; <strong>Email<\/strong> \u2014&gt; <strong>Mapper<\/strong> \u2014&gt; <strong>Email i verifikuar<\/strong> (Fshi)<\/p>\n<p><\/p>\n<p>Tani le t\u00eb konfigurojm\u00eb federat\u00ebn, p\u00ebr k\u00ebt\u00eb kalojm\u00eb n\u00eb:<\/p>\n<p><\/p>\n<p><strong>Federata e p\u00ebrdoruesve<\/strong> \u2014&gt; <strong>Shto ofruesi&#8230;<\/strong> \u2014&gt; <strong>ldap<\/strong><\/p>\n<p><\/p>\n<p>Ja nj\u00eb shembull konfigurimi p\u00ebr FreeIPA:<\/p>\n<p><\/p>\n<p>Opsioni<br \/>\nVlera<\/p>\n<p><strong>Emri i Shfaqjes n\u00eb Konsol\u00eb<\/strong><br \/>\n<code>freeipa.example.org<\/code><\/p>\n<p><strong>T\u00eb dh\u00ebnat e ofruesit<\/strong><br \/>\n<code>Red Hat Directory Server<\/code><\/p>\n<p><strong>Atributi UUID t\u00eb LDAP<\/strong><br \/>\n<code>ipauniqueid<\/code><\/p>\n<p><strong>URL e Lidhjes<\/strong><br \/>\n<code>ldaps:\/\/freeipa.example.org<\/code><\/p>\n<p><strong>DN e P\u00ebrdoruesve<\/strong><br \/>\n<code>cn=users,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>Bind DN<\/strong><br \/>\n<code>uid=keycloak-svc,cn=users,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>Kredenciali i lidhjes<\/strong><br \/>\n<code>&lt;password&gt;<\/code><\/p>\n<p><strong>Lejo autentifikimin Kerberos:<\/strong><br \/>\n<code>n\u00eb<\/code><\/p>\n<p><strong>Realm-i Kerberos:<\/strong><br \/>\n<code>EXAMPLE.ORG<\/code><\/p>\n<p><strong>Server Principal:<\/strong><br \/>\n<code>HTTP\/freeipa.example.org@EXAMPLE.ORG<\/code><\/p>\n<p><strong>KeyTab:<\/strong><br \/>\n<code>\/etc\/krb5.keytab<\/code><\/p>\n<p><\/p>\n<p>P\u00ebrdoruesi <code>keycloak-svc<\/code> duhet t\u00eb krijohet paraprakisht n\u00eb serverin ton\u00eb LDAP.<\/p>\n<p><\/p>\n<p>N\u00eb rastin e Active Directory, mjafton t\u00eb zgjidhni <strong>Shit\u00ebsi: Active Directory<\/strong> dhe cil\u00ebsimet e nevojshme do t\u00eb vendosen automatikisht n\u00eb formular.<\/p>\n<p><\/p>\n<p>Klikoni <strong>Ruaj<\/strong><\/p>\n<p><\/p>\n<p>Tani kalojm\u00eb te:<\/p>\n<p><\/p>\n<p><strong>Federata e p\u00ebrdoruesve<\/strong> \u2014&gt; <strong>freeipa.example.org<\/strong> \u2014&gt; <strong>Mapper<\/strong> \u2014&gt; <strong>Emri<\/strong><\/p>\n<p><\/p>\n<p>Opsioni<br \/>\nVlera<\/p>\n<p><strong>Attributi Ldap<\/strong><br \/>\n<code>givenName<\/code><\/p>\n<p><\/p>\n<p>Tani aktivizojm\u00eb mapimin e grupeve:<\/p>\n<p><\/p>\n<p><strong>Federata e p\u00ebrdoruesve<\/strong> \u2014&gt; <strong>freeipa.example.org<\/strong> \u2014&gt; <strong>Mapper<\/strong> \u2014&gt; <strong>Create<\/strong><\/p>\n<p><\/p>\n<p>Opsioni<br \/>\nVlera<\/p>\n<p><strong>Emri<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><strong>Lloji i mapuesit<\/strong><br \/>\n<code>group-ldap-mapper<\/code><\/p>\n<p><strong>LDAP Grupi DN<\/strong><br \/>\n<code>cn=groups,cn=accounts,dc=example,dc=org<\/code><\/p>\n<p><strong>Strategjia e Marrjes s\u00eb Grupeve t\u00eb P\u00ebrdoruesve<\/strong><br \/>\n<code>GET_GROUPS_FROM_USER_MEMBEROF_ATTRIBUTE<\/code><\/p>\n<p><\/p>\n<p>Me k\u00ebt\u00eb mbaron konfigurimi i federat\u00ebs, kalojm\u00eb te konfigurimi i klientit.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-klienta\">Konfigurimi i klientit<\/h2>\n<p><\/p>\n<p>Do t\u00eb krijojm\u00eb nj\u00eb klient t\u00eb ri (aplikacioni q\u00eb do t\u00eb marr\u00eb p\u00ebrdoruesit nga Keycloak). Kalojm\u00eb:<\/p>\n<p><\/p>\n<p><strong>Klient\u00ebt<\/strong> \u2014&gt; <strong>Create<\/strong><\/p>\n<p><\/p>\n<p>Opsioni<br \/>\nVlera<\/p>\n<p><strong>Identifikuesi i Klientit<\/strong><br \/>\n<code>kubernetes<\/code><\/p>\n<p><strong>Lloji i Qasjes<\/strong><br \/>\n<code>konfidencial<\/code><\/p>\n<p><strong>URL e Rr\u00ebnj\u00ebs<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/<\/code><\/p>\n<p><strong>URI t\u00eb Sakta p\u00ebr Ridrejtim<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/*<\/code><\/p>\n<p><strong>URL e Administratorit<\/strong><br \/>\n<code>http:\/\/kubernetes.example.org\/<\/code><\/p>\n<p><\/p>\n<p>Po ashtu do t\u00eb krijojm\u00eb nj\u00eb skop p\u00ebr grupet:<\/p>\n<p><\/p>\n<p><strong>Skopet e Klientit<\/strong> \u2014&gt; <strong>Create<\/strong><\/p>\n<p><\/p>\n<p>Opsioni<br \/>\nVlera<\/p>\n<p><strong>Shabllon<\/strong><br \/>\n<code>Nuk ka shabllon<\/code><\/p>\n<p><strong>Emri<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><strong>Rruga e Plot\u00eb e Grupit<\/strong><br \/>\n<code>false<\/code><\/p>\n<p><\/p>\n<p>Dhe do t\u00eb konfiguroni mapper p\u00ebr to:<\/p>\n<p><\/p>\n<p><strong>Skopet e Klientit<\/strong> \u2014&gt; <strong>groups<\/strong> \u2014&gt; <strong>Mapper<\/strong> \u2014&gt; <strong>Create<\/strong><\/p>\n<p><\/p>\n<p>Opsioni<br \/>\nVlera<\/p>\n<p><strong>Emri<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><strong>Tipi i Mapper-it<\/strong><br \/>\n<code>An\u00ebtar\u00ebsia n\u00eb Grup<\/code><\/p>\n<p><strong>Emri i K\u00ebrkes\u00ebs p\u00ebr Token<\/strong><br \/>\n<code>groups<\/code><\/p>\n<p><\/p>\n<p>Tani na nevojitet t\u00eb aktivizojm\u00eb mapimin e grupeve n\u00eb skopin ton\u00eb t\u00eb klientit:<\/p>\n<p><\/p>\n<p><strong>Klient\u00ebt<\/strong> \u2014&gt; <strong>kubernetes<\/strong> \u2014&gt; <strong>Skopet e Klientit<\/strong> \u2014&gt; <strong>Skopet Standard t\u00eb Klientit<\/strong><\/p>\n<p><\/p>\n<p>Zgjidhni <strong>groups<\/strong> n\u00eb <strong>Skopet e Disponueshme t\u00eb Klientit<\/strong>, klikoni <strong>Shto t\u00eb zgjedhurat<\/strong><\/p>\n<p><\/p>\n<p>Tani do t\u00eb konfigurojm\u00eb autentifikimin e aplikacionit ton\u00eb, kalojm\u00eb te:<\/p>\n<p><\/p>\n<p><strong>Klient\u00ebt<\/strong> \u2014&gt; <strong>kubernetes<\/strong><\/p>\n<p><\/p>\n<p>Opsioni<br \/>\nVlera<\/p>\n<p><strong>Autorizimi Aktivizuar<\/strong><br \/>\n<code>ON<\/code><\/p>\n<p><\/p>\n<p>Klikojm\u00eb <strong>ruaj<\/strong> dhe me k\u00ebt\u00eb p\u00ebrfundon konfigurimi i klientit, tani te skeda<\/p>\n<p><\/p>\n<p><strong>Klient\u00ebt<\/strong> \u2014&gt; <strong>kubernetes<\/strong> \u2014&gt; <strong>Kredencialet<\/strong><\/p>\n<p><\/p>\n<p>do t\u00eb jeni n\u00eb gjendje t\u00eb merrni <strong>Secret<\/strong> t\u00eb cilin do ta p\u00ebrdorim m\u00eb von\u00eb.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-kubernetes\">Konfigurimi i Kubernetes<\/h2>\n<p><\/p>\n<p>Konfigurimi i Kubernetes p\u00ebr autorizimin OIDC \u00ebsht\u00eb mjaft i thjesht\u00eb dhe nuk paraqet ndonj\u00eb sfid\u00eb t\u00eb madhe. E vetmja gj\u00eb q\u00eb ju nevojitet \u00ebsht\u00eb t\u00eb vendosni certifikat\u00ebn CA t\u00eb serverit tuaj OIDC n\u00eb <code>\/etc\/kubernetes\/pki\/oidc-ca.pem<\/code> dhe t\u00eb shtoni opsionet e nevojshme p\u00ebr kube-apiserver.<br \/>\nP\u00ebr k\u00ebt\u00eb, p\u00ebrdit\u00ebsoni <code>\/etc\/kubernetes\/manifests\/kube-apiserver.yaml<\/code> n\u00eb t\u00eb gjith\u00eb masterat tuaj:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">...\nspec:\n  containers:\n  - command:\n    - kube-apiserver\n...\n    - --oidc-ca-file=\/etc\/kubernetes\/pki\/oidc-ca.pem\n    - --oidc-client-id=kubernetes\n    - --oidc-groups-claim=groups\n    - --oidc-issuer-url=https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\n    - --oidc-username-claim=email\n...<\/code><\/pre>\n<p><\/p>\n<p>Po ashtu, p\u00ebrdit\u00ebsoni konfigurimin e kubeadm n\u00eb klaster, n\u00eb m\u00ebnyr\u00eb q\u00eb t\u00eb mos humbni k\u00ebto parametra gjat\u00eb p\u00ebrdit\u00ebsimit:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">kubectl edit -n kube-system configmaps kubeadm-config<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"plaintext\">...\ndata:\n  ClusterConfiguration: |\n    apiServer:\n      extraArgs:\n        oidc-ca-file: \/etc\/kubernetes\/pki\/oidc-ca.pem\n        oidc-client-id: kubernetes\n        oidc-groups-claim: groups\n        oidc-issuer-url: https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\n        oidc-username-claim: email\n...<\/code><\/pre>\n<p><\/p>\n<p>Me k\u00ebt\u00eb, konfigurimi i Kubernetes p\u00ebrfundon. Ju mund t\u00eb p\u00ebrs\u00ebrisni k\u00ebto veprime n\u00eb t\u00eb gjith\u00eb klaster\u00ebt tuaj Kubernetes.<\/p>\n<p><\/p>\n<h2 id=\"nachalnaya-avtorizaciya\">Autorizimi fillestar<\/h2>\n<p><\/p>\n<p>Pas k\u00ebtyre veprimeve, ju do t\u00eb keni nj\u00eb kluster Kubernetes me autorizimin OIDC t\u00eb konfiguruar. Nj\u00eb \u00e7\u00ebshtje \u00ebsht\u00eb se p\u00ebrdoruesit tuaj nuk kan\u00eb ende nj\u00eb klient t\u00eb konfiguruar si dhe nj\u00eb kubeconfig t\u00eb vetin. P\u00ebr t\u00eb zgjidhur k\u00ebt\u00eb problem, duhet t\u00eb konfiguroni dh\u00ebnien automatike t\u00eb kubeconfig p\u00ebr p\u00ebrdoruesit pas autorizimit t\u00eb suksessh\u00ebm.<\/p>\n<p><\/p>\n<p>P\u00ebr k\u00ebt\u00eb mund t\u00eb p\u00ebrdorni aplikacione speciale n\u00eb web, t\u00eb cilat lejojn\u00eb autentifikimin e p\u00ebrdoruesit dhe m\u00eb pas shkarkimin e kubeconfig t\u00eb gatsh\u00ebm. Nj\u00eb nga m\u00eb t\u00eb p\u00ebrshtatshmet \u00ebsht\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/negz\/kuberos\">Kuberos<\/a><\/noindex>, i cili lejon t\u00eb p\u00ebrshkruani t\u00eb gjith\u00eb klust\u00ebrat Kubernetes n\u00eb nj\u00eb konfigurim dhe t\u00eb kaloni leht\u00ebsisht mes tyre.<\/p>\n<p><\/p>\n<p>P\u00ebr t\u00eb konfiguruar Kuberos, mjafton t\u00eb p\u00ebrshkruani nj\u00eb template p\u00ebr kubeconfig dhe t\u00eb filloni me parametrat e m\u00ebposht\u00ebm:<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">kuberos https:\/\/keycloak.example.org\/auth\/realms\/kubernetes kubernetes \/cfg\/secret \/cfg\/template<\/code><\/pre>\n<p><\/p>\n<p>P\u00ebr m\u00eb shum\u00eb informacion, shihni <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/negz\/kuberos#usage\">P\u00ebrdorimi<\/a><\/noindex> n\u00eb Github.<\/p>\n<p><\/p>\n<p>Gjithashtu \u00ebsht\u00eb e mundur t\u00eb p\u00ebrdorni <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/int128\/kubelogin\">kubelogin<\/a><\/noindex> n\u00ebse d\u00ebshironi t\u00eb kryeni autorizimin drejtp\u00ebrdrejt n\u00eb kompjuterin e p\u00ebrdoruesit. N\u00eb k\u00ebt\u00eb rast, p\u00ebrdoruesit do t\u00eb hap\u00eb nj\u00eb shfletues me formularin e autorizimit n\u00eb localhost.<\/p>\n<p><\/p>\n<p>Kubeconfig i marr\u00eb mund t\u00eb kontrollohet n\u00eb faqen <noindex><a rel=\"nofollow\" href=\"https:\/\/jwt.io\/#debugger-io\">jwt.io<\/a><\/noindex>. Thjesht kopjoni vler\u00ebn <code>users[].user.auth-provider.config.id-token<\/code> nga kubeconfig juaj n\u00eb form\u00ebn n\u00eb faqen e internetit dhe menj\u00ebher\u00eb merrni shpjegimin.<\/p>\n<p><\/p>\n<h2 id=\"nastroyka-rbac\">Konfigurimi i RBAC<\/h2>\n<p><\/p>\n<p>N\u00eb konfigurimin e RBAC mund t\u00eb referoheni si p\u00ebr emrin e p\u00ebrdoruesit (fusha <code>emri<\/code> n\u00eb jwt-token), ashtu edhe p\u00ebr grupin e p\u00ebrdoruesve (fusha <code>groups<\/code> n\u00eb jwt-token). Ja nj\u00eb shembull i konfigurimit t\u00eb t\u00eb drejtave p\u00ebr grupin <code>kubernetes-default-namespace-admins<\/code>:<\/p>\n<p>\n<b class=\"spoiler_title\">kubernetes-default-namespace-admins.yaml<\/b><\/p>\n<pre><code class=\"plaintext\">apiVersion: rbac.authorization.k8s.io\/v1\nkind: Role\nmetadata:\n  name: default-admins\n  namespace: default\nrules:\n- apiGroups:\n  - '*'\n  resources:\n  - '*'\n  verbs:\n  - '*'\n---\napiVersion: rbac.authorization.k8s.io\/v1\nkind: RoleBinding\nmetadata:\n  name: kubernetes-default-namespace-admins\n  namespace: default\nroleRef:\n  apiGroup: rbac.authorization.k8s.io\n  kind: Role\n  name: default-admins\nsubjects:\n- apiGroup: rbac.authorization.k8s.io\n  kind: Group\n  name: kubernetes-default-namespace-admins<\/code><\/pre>\n<p><\/p>\n<p>M\u00eb shum\u00eb shembuj p\u00ebr RBAC mund t\u00eb gjenden n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/reference\/access-authn-authz\/rbac\/\">dokumentacionit zyrtar t\u00eb Kubernetes<\/a><\/noindex><\/p>\n<p><\/p>\n<h2 id=\"nastroyka-auth-proxy\">Konfigurimi i auth-proxy<\/h2>\n<p><\/p>\n<p>Ka nj\u00eb projekt t\u00eb shk\u00eblqyer <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/keycloak\/keycloak-gatekeeper\">keycloak-gatekeeper<\/a><\/noindex>, i cili lejon mbrojtjen e \u00e7do aplikacioni, duke i ofruar p\u00ebrdoruesit mund\u00ebsin\u00eb p\u00ebr t'u autentikuar n\u00eb serverin OIDC. Do t'ju tregoj si ta konfiguroni at\u00eb me shembullin e Kubernetes Dashboard:<\/p>\n<p>\n<b class=\"spoiler_title\">dashboard-proxy.yaml<\/b><\/p>\n<pre><code class=\"plaintext\">apiVersion: extensions\/v1beta1\nkind: Deployment\nmetadata:\n  name: kubernetes-dashboard-proxy\nspec:\n  replicas: 1\n  template:\n    metadata:\n      labels:\n        app: kubernetes-dashboard-proxy\n    spec:\n      containers:\n      - args:\n        - --listen=0.0.0.0:80\n        - --discovery-url=https:\/\/keycloak.example.org\/auth\/realms\/kubernetes\n        - --client-id=kubernetes\n        - --client-secret=\n        - --redirection-url=https:\/\/kubernetes-dashboard.example.org\n        - --enable-refresh-tokens=true\n        - --encryption-key=ooTh6Chei1eefooyovai5ohwienuquoh\n        - --upstream-url=https:\/\/kubernetes-dashboard.kube-system\n        - --resources=uri=\/*\n        image: keycloak\/keycloak-gatekeeper\n        name: kubernetes-dashboard-proxy\n        ports:\n        - containerPort: 80\n          livenessProbe:\n            httpGet:\n              path: \/oauth\/health\n              port: 80\n            initialDelaySeconds: 3\n            timeoutSeconds: 2\n          readinessProbe:\n            httpGet:\n              path: \/oauth\/health\n              port: 80\n            initialDelaySeconds: 3\n            timeoutSeconds: 2\n---\napiVersion: v1\nkind: Service\nmetadata:\n  name: kubernetes-dashboard-proxy\nspec:\n  ports:\n  - port: 80\n    protocol: TCP\n    targetPort: 80\n  selector:\n    app: kubernetes-dashboard-proxy\n  type: ClusterIP<\/code><\/pre>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/441112\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Keycloak \u043c\u043e\u0436\u043d\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c Kubernetes \u0441 \u0432\u0430\u0448\u0438\u043c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0438\u043c\u043f\u043e\u0440\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0433\u0440\u0443\u043f\u043f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c auth-proxy \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c Kubernetes Dashboard \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0447\u0442\u043e \u0443 \u0432\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c Active [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":70868,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-70867","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Keycloak \u043c\u043e\u0436\u043d\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c Kubernetes \u0441 \u0432\u0430\u0448\u0438\u043c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0438\u043c\u043f\u043e\u0440\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0433\u0440\u0443\u043f\u043f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c auth-proxy \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c Kubernetes Dashboard \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0447\u0442\u043e \u0443 \u0432\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c Active\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c LDAP-\u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Keycloak \u043c\u043e\u0436\u043d\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c Kubernetes \u0441 \u0432\u0430\u0448\u0438\u043c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0438\u043c\u043f\u043e\u0440\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0433\u0440\u0443\u043f\u043f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c auth-proxy \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c Kubernetes Dashboard \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0447\u0442\u043e \u0443 \u0432\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c Active\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-22T03:40:58+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-03T13:14:36+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Lidhim autorizimin LDAP me Kubernetes | ProHoster","description":"Nj\u00eb udh\u00ebzues i shkurt\u00ebr p\u00ebr m\u00ebnyr\u00ebn se si t\u00eb lidhni Kubernetes me serverin tuaj LDAP duke p\u00ebrdorur Keycloak dhe si t\u00eb konfiguroni importimin e p\u00ebrdoruesve dhe grupeve. Kjo do t'ju lejoj\u00eb t\u00eb konfiguroni RBAC p\u00ebr p\u00ebrdoruesit tuaj dhe t\u00eb p\u00ebrdorni auth-proxy p\u00ebr t\u00eb mbrojtur Kubernetes Dashboard dhe aplikacione t\u00eb tjera q\u00eb nuk mund t\u00eb b\u00ebjn\u00eb autorizim vet\u00eb. Instalimi i Keycloak Supozoni q\u00eb ju tashm\u00eb keni nj\u00eb server LDAP. Kjo mund t\u00eb jet\u00eb Active","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0440\u0438\u043a\u0440\u0443\u0447\u0438\u0432\u0430\u0435\u043c LDAP-\u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043a Kubernetes | ProHoster","og:description":"\u041d\u0435\u0431\u043e\u043b\u044c\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Keycloak \u043c\u043e\u0436\u043d\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c Kubernetes \u0441 \u0432\u0430\u0448\u0438\u043c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0438\u043c\u043f\u043e\u0440\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0433\u0440\u0443\u043f\u043f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c RBAC \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c auth-proxy \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c Kubernetes Dashboard \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u0443\u043c\u0435\u044e\u0442 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u0430\u043c\u043e\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u043d\u043e. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Keycloak \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0447\u0442\u043e \u0443 \u0432\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c LDAP-\u0441\u0435\u0440\u0432\u0435\u0440. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c Active","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/prikruchivaem-ldap-avtorizacziyu-k-kubernetes","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-22T03:40:58+00:00","article:modified_time":"2020-03-03T13:14:36+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"70867","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:12:23","updated":"2022-09-28 01:58:51"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/70867","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=70867"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/70867\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/70868"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=70867"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=70867"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=70867"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}