본문 바로가기
WIKI 기술 지식 베이스

lakeFS 업그레이드

원문 보기 위키 갱신

이 가이드는 셀프 매니지드 lakeFS 배포의 업그레이드를 다뤄요. 데이터베이스 마이그레이션 안내는 lakeFS Community와 lakeFS Enterprise 모두에 적용되며, lakeFS Enterprise 업그레이드는 지원 중단된 Fluffy 서비스에서의 마이그레이션을 포함해 Enterprise 고유의 단계를 다뤄요. 호스티드 배포를 사용한다면 업그레이드는 여러분을 위해 대신 처리돼요.

출처: 문서

본문

이전 버전에서 lakeFS를 업그레이드하는 것은 보통 최신 이미지로 재배포하거나, 바이너리를 사용한다면 최신 버전을 다운로드하는 것만으로 충분해요. 업그레이드 전에 릴리스에 마이그레이션이 필요한지 확인하세요.

DB 마이그레이션이 필요한 경우

lakeFS 0.103.0 이상

버전 0.103.0은 롤링 KV 업그레이드를 지원해요. 즉 이미 KV ref-store로 마이그레이션한 사용자(0.80.0 이상 버전)는 더 이상 특정 버전을 거쳐 마이그레이션할 필요가 없어요. 여기에는 lakeFS 0.98.0에서 도입된 ACL 마이그레이션도 포함돼요. 최신 lakeFS 버전에서 lakefs migrate up을 실행하면 그 시점까지의 모든 필요한 마이그레이션이 수행돼요.

lakeFS 0.80.0 이상 (KV 마이그레이션)

버전 0.80.2부터 lakeFS는 PostgreSQL 기반 데이터베이스 구현에서 여러 데이터베이스 구현을 지원하는 키-값 데이터스토어 인터페이스로 전환했어요. 자세한 내용은 여기에서 확인할 수 있어요. 이전 버전의 lakeFS에서 업그레이드하는 사용자는 더 새로운 lakeFS 버전으로 올라가기 전에 KV 마이그레이션 버전(0.80.2)을 반드시 거쳐야 해요.

Important

사전 마이그레이션 요구 사항:

  • 데이터베이스 구성에 OS 환경 변수를 사용하는 사용자는 마이그레이션 진행 전에 connection_string을 명시적으로 또는 환경 변수로 정의해야 해요.
  • 현재 사용 중인 용량의 최소 2배 이상의 데이터베이스 스토리지 여유 용량
  • 다음 추가 단계를 수행하는 것이 강력히 권장돼요:
  • 브랜치의 모든 커밋되지 않은 데이터를 커밋
  • 데이터베이스 스냅샷 생성
  • 기본적으로 마이그레이션 프로세스는 오래된 데이터베이스 테이블을 삭제하지 않으므로, 성공적인 마이그레이션 후 수동으로 제거해야 해요. 마이그레이션의 일부로 테이블 드롭을 활성화하려면 database.drop_tables 구성 파라미터를 true로 설정하세요

마이그레이션 단계

데이터베이스와 함께 현재 실행 중인 각 lakeFS 인스턴스에 대해

  • lakeFS 설정 yaml의 database 섹션을 수정하세요:

  • 값이 "postgres"인 type 필드를 추가하세요

  • 현재 구성 파라미터를 postgres라는 새 섹션으로 복사하세요

---
database:
type: "postgres"
connection_string: "postgres://localhost:5432/postgres?sslmode=disable"
max_open_connections: 20

postgres:
  connection_string: "postgres://localhost:5432/postgres?sslmode=disable"
  max_open_connections: 20
  • 모든 lakeFS 인스턴스를 중지하세요

  • 새 버전(0.80.2)의 lakefs 바이너리를 사용해 다음을 실행하세요:

lakefs migrate up
  • lakeFS가 마이그레이션 프로세스를 실행하고, 마지막에 오류 없이 다음 메시지가 표시되어야 해요:
time="2022-08-10T14:46:25Z" level=info msg="KV Migration took 717.629563ms" func="pkg/logging.(*logrusEntryWrapper).Infof" file="build/pkg/logging/logger.go:246" TempDir=/tmp/kv_migrate_2913402680
  • 이제 오래된 데이터베이스 구성을 제거할 수 있어요. 업데이트된 구성은 다음과 같아야 해요:
---
database:
 type: "postgres"

 postgres:
   connection_string: "postgres://localhost:5432/postgres?sslmode=disable"
   max_open_connections: 20
  • lakeFS의 새 버전을 배포(또는 실행)하세요.

lakeFS 0.30.0 이상

마이그레이션이 필요한 경우 먼저 실행 중인 lakeFS 서비스를 중지해야 해요. 새 버전의 lakefs 바이너리를 사용해 다음을 실행하세요:

lakefs migrate up

lakeFS의 새 버전을 배포(또는 실행)하세요.

오래된 lakeFS 버전은 마이그레이션된 데이터베이스에서 실행될 수 없다는 점을 유의하세요.

lakeFS 0.30.0 이전

Note

lakeFS < 0.30.0에서는 먼저 이 가이드에 따라 0.30.0으로 업그레이드한 후, 최신 버전으로 업그레이드를 진행하세요.

버전 0.30.0부터 lakeFS는 커밋된 메타데이터를 더 견고하고 성능이 좋은 새로운 방식으로 처리해요. 기존 데이터를 옮기려면 다음 업그레이드 명령을 실행해야 해요.

lakeFS 버전 == 0.30.0 확인 (Docker 사용 시 생략 가능)

lakefs --version

이전 형식에서 데이터 마이그레이션:

lakefs migrate db

또는 Docker 이미지로 마이그레이션:

docker run --rm -it -e LAKEFS_DATABASE_CONNECTION_STRING=<database connection string> treeverse/lakefs:rocks-migrate migrate db

마이그레이션 후에는 더 최신 lakeFS 버전을 사용할 수 있어요. 업그레이드와 사용에 대한 자세한 내용은 각 릴리스 노트를 참고하세요.

기존 데이터를 버리고 처음부터 다시 시작하고 싶다면 lakeFS 설정 파일에 명시적으로 이를 표시해야 해요. 그러려면 구성에 다음을 추가하세요 (0.30.0에서만 해당):

cataloger:
  type: rocks

버전 v0.50.0용 데이터 마이그레이션

Warning

0.50.0 이전 버전을 사용 중이라면, 먼저 해당 버전으로 이전 업그레이드를 수행해야 해요.

lakeFS Enterprise 업그레이드

lakeFS Enterprise는 모든 엔터프라이즈 기능을 단일 바이너리로 통합해요. 기존 Enterprise 배포를 업그레이드한다면 위 데이터베이스 마이그레이션 단계가 Community와 마찬가지로 적용돼요. 가장 중요한 Enterprise 고유 변화는 아래에서 설명하는 별도 Fluffy 서비스의 제거예요.

Fluffy에서 lakeFS Enterprise로 마이그레이션

새 lakeFS Enterprise는 모든 엔터프라이즈 기능을 단일 바이너리에 직접 통합해 별도 Fluffy 서비스의 필요성을 없애요. 이로써 배포, 구성, 유지 보수가 단순해져요.

사전 준비

  • fluffy가 포함된 lakeFS enterprise 바이너리 또는 Dockerhub의 treeverse/lakefs-enterprise 이미지를 사용 중이에요.

  • lakeFS-Enterprise 버전이 >= 1.63.0이에요

  • lakeFS Enterprise 라이선스를 보유하고 있어요.

Note

lakeFS Enterprise 접근 권한은 문의하기를 통해 받을 수 있어요. lakeFS Enterprise 실행 라이선스가 부여될 거예요.

fluffy에서 lakeFS Enterprise로 마이그레이션하려면 아래 단계를 따르세요:

  • 온전성 테스트(선택): 현재 프로덕션 구성을 옮기기 전에 새 테스트용 lakeFS Enterprise를 설치하세요. 셋업 전에 구성에 lakeFS Enterprise 라이선스를 반드시 포함하세요. 구성 테스트 → 로그인 → 리포지토리 생성 등을 진행해요. 모든 것이 잘 동작하는 것을 확인하면 테스트 구성을 삭제·정리하고 마이그레이션 프로세스로 넘어가요.

  • 구성 업데이트: lakeFS + Fluffy와 달리 lakeFS Enterprise는 하나의 설정 파일만 사용해요. Configuration Changes를 참고하고 구성에 라이선스를 추가했는지 확인하세요.

  • lakeFS와 fluffy를 내리고 lakeFS Enterprise를 실행하세요!

Warning

lakeFS 인스턴스를 교체하는 동안 짧은 다운타임이 발생한다는 점을 유의하세요.

구성 변경 사항

인증 구성

대부분의 Fluffy auth.* 설정은 동일한 구조로 lakeFS Enterprise에 직접 마이그레이션돼요. 아래는 구성 간 차이점이에요.

SAML

lakeFS & Fluffy (old)lakeFS Enterprise (new)

# fluffy.yaml
auth:
  logout_redirect_url: https://lakefs.company.com
  post_login_redirect_url: https://lakefs.company.com
  saml:
    enabled: true
    sp_root_url: https://lakefs.company.com
    sp_x509_key_path: dummy_saml_rsa.key
    sp_x509_cert_path: dummy_saml_rsa.cert
    sp_sign_request: true
    sp_signature_method: http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
    idp_metadata_url: https://my.saml-provider.com/federationmetadata/2007-06/federationmetadata.xml
    # idp_authn_name_id_format: "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
    external_user_id_claim_name: samName
    # idp_metadata_file_path:
    # idp_skip_verify_tls_cert: true
# lakefs.yaml
auth:
  logout_redirect_url: https://lakefs.company.com
  cookie_auth_verification:
    auth_source: saml
    friendly_name_claim_name: displayName
    persist_friendly_name: true
    external_user_id_claim_name: samName
    validate_id_token_claims:
      department: r_n_d
    default_initial_groups:
    - "Developers"
ui_config:
  login_url: https://lakefs.company.com/sso/login-saml
  logout_url: https://lakefs.company.com/sso/logout-saml
  login_cookie_names:
  - internal_auth_session
  - saml_auth_session
# lakefs.yaml
auth:
  logout_redirect_url: https://lakefs.company.com/ # optional, URL to redirect to after logout
  cookie_auth_verification:
    auth_source: saml
    friendly_name_claim_name: displayName
    default_initial_groups: ["Admins"]
    external_user_id_claim_name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
    validate_id_token_claims:
      department: r_n_d
  providers:
    saml:
      # enabled: true  # This field was dropped!
      sp_root_url: https://lakefs.company.com
      sp_x509_key_path: dummy_saml_rsa.key
      sp_x509_cert_path: dummy_saml_rsa.cert
      sp_sign_request: true
      sp_signature_method: http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
      idp_metadata_url: https://my.saml-provider.com/federationmetadata/2007-06/federationmetadata.xml
      post_login_redirect_url: / # Where to redirect after successful SAML login
      # external_user_id_claim_name: # This field was moved to auth.cookie_auth_verification
  ui_config:
    login_url: https://lakefs.company.com/sso/login-saml
    logout_url: https://lakefs.company.com/sso/logout-saml
    login_cookie_names:
      - internal_auth_session
      - saml_auth_session

OIDC + OIDC STS

lakeFS + Fluffy (old)lakeFS Enterprise (new)

# fluffy.yaml
auth:
  post_login_redirect_url: /
  logout_redirect_url: https://oidc-provider-url.com/logout/url
  oidc:
    enabled: true
    url: https://oidc-provider-url.com/
    client_id: <oidc-client-id>
    client_secret: <oidc-client-secret>
    callback_base_url: https://lakefs.company.com
    is_default_login: true
    logout_client_id_query_parameter: client_id
    logout_endpoint_query_parameters:
    - returnTo
    - https://lakefs.company.com/oidc/login
# lakefs.yaml
auth:
  oidc:
    friendly_name_claim_name: "name"
    persist_friendly_name: true
    default_initial_groups: ["Developers"]
  ui_config:
    login_url: /oidc/login
    logout_url: /oidc/logout
    login_cookie_names:
    - internal_auth_session
    - oidc_auth_session
# lakefs.yaml
auth:
  logout_redirect_url:  https://oidc-provider-url.com/logout/url # optional, URL to redirect to after logout
  ui_config:
    login_url: /oidc/login
    logout_url: /oidc/logout
    login_cookie_names:
      - internal_auth_session
      - oidc_auth_session
  oidc:
    friendly_name_claim_name: "nickname"
    default_initial_groups: ["Admins"]
  providers:
    oidc:
      # enabled: true  # This field was dropped!
      post_login_redirect_url: / # This field was moved here!
      url: https://oidc-provider-url.com/
      client_id: <oidc-client-id>
      client_secret: <oidc-client-secret>
      callback_base_url: https://lakefs.company.com
      logout_client_id_query_parameter: client_id
      logout_endpoint_query_parameters:
        - returnTo
        - http://lakefs.company.com/oidc/login

LDAP

lakeFS + Fluffy (old)lakeFS Enterprise (new)

# fluffy.yaml
auth:
  post_login_redirect_url: /
  ldap:
    server_endpoint: ldaps://ldap.company.com:636
    bind_dn: uid=<bind-user-name>,ou=<some-ou>,o=<org-id>,dc=<company>,dc=com
    bind_password: '<ldap password>'
    username_attribute: uid
    user_base_dn: ou=<some-ou>,o=<org-id>,dc=<company>,dc=com
    user_filter: (objectClass=inetOrgPerson)
    connection_timeout_seconds: 15
    request_timeout_seconds: 7
# lakefs.yaml
auth:
  remote_authenticator:
    enabled: true
    endpoint: http://<Fluffy URL>:<Fluffy http port>/api/v1/ldap/login
    default_user_group: "Developers" # Value needs to correspond with an existing group in lakeFS
  ui_config:
    logout_url: /logout
    login_cookie_names:
    - internal_auth_session
# lakefs.yaml
auth:
  ui_config:
    logout_url: /logout
    login_cookie_names:
      - internal_auth_session
  providers:
    ldap:
      server_endpoint: ldaps://ldap.company.com:636
      bind_dn: uid=<bind-user-name>,ou=<some-ou>,o=<org-id>,dc=<company>,dc=com
      bind_password: '<ldap password>'
      username_attribute: uid
      user_base_dn: ou=<some-ou>,o=<org-id>,dc=<company>,dc=com
      user_filter: (objectClass=inetOrgPerson)
      connection_timeout_seconds: 15
      request_timeout_seconds: 7
      default_user_group: "Developers" # This field moved here!

AWS IAM

lakeFS + Fluffy (old)lakeFS Enterprise (new)

# fluffy.yaml
serve_listen: "localhost:9001"
auth:
  external:
    aws_auth:
      enabled: true
      required_headers:
        X-LakeFS-Server-ID: "localhost"
# lakefs.yaml
auth:
  authentication_api:
    endpoint: http://localhost:9001/api/v1
    external_principals_enabled: true
# lakefs.yaml
auth:
  external_aws_auth:
    enabled: true
    required_headers:
      X-LakeFS-Server-ID: "localhost"

권한 부여 구성

RBAC

lakeFS + Fluffy (old)lakeFS Enterprise (new)

# fluffy.yaml
auth:
  serve_listen_address: "localhost:9000"
  cache:
    enabled: true
# lakefs.yaml
auth:
  api:
   endpoint: http://localhost:9000/api/v1
# lakefs.yaml
auth:
  # serve_disable_authentication: false      # this field was dropped!
  # serve_listen_address: "localhost:9000"   # this field was dropped!
  # api:                                     # this field was dropped!
  #   endpoint: http://localhost:9000/api/v1 # this field was dropped!
  cache:
    enabled: true

Kubernetes: Helm으로 Fluffy에서 새 lakeFS Enterprise로 마이그레이션

개요

lakeFS Helm 차트 버전 1.5.0부터 Fluffy 인증 서비스는 지원 중단되었고 네이티브 lakeFS Enterprise 인증으로 대체되었어요. 이 마이그레이션은 인증을 메인 lakeFS 애플리케이션으로 통합해 배포와 유지 보수를 단순화해요.

바뀌는 내용

lakeFS Enterprise로 업그레이드하면:

  • Fluffy 배포 제거: 별도의 Fluffy 배포, 서비스, 연관 Kubernetes 리소스가 더 이상 필요 없어요

  • 단순화된 아키텍처: 인증이 lakeFS Enterprise가 직접 처리해 파드와 서비스 수가 줄어요

  • 간소화된 Ingress: Fluffy와 lakeFS 사이의 라우팅이 사라지고 모든 트래픽이 lakeFS로 직접 가요

  • 업데이트된 values.yaml 구조: 인증 구성이 fluffy.*에서 enterprise.auth.*와 lakefsConfig.auth.providers.*로 이동해요

사전 준비

  • Fluffy 인증을 사용하는 현재 lakeFS 배포 (차트 버전 < 1.5.0)

  • Helm values 업데이트 접근 권한

  • 현재 values.yaml 백업

단계별 마이그레이션 가이드

1단계: Helm 리포지토리 업데이트

helm repo update lakefs

차트 버전 1.5.0 이상에 접근할 수 있는지 확인하세요:

helm search repo lakefs/lakefs --versions

2단계: 새 차트 값 검토

새 차트의 사용 가능한 모든 구성 옵션을 검토하세요:

helm show values lakefs/lakefs --version 1.5.0 > new-values-reference.yaml

3단계: 이미지 구성 업데이트

values.yaml에서 이미지를 오버라이드하고 있다면 lakeFS Enterprise를 사용하도록 업데이트하세요:

image:
  repository: treeverse/lakefs-enterprise
  tag: 1.63.0

참고: 이미지를 오버라이드하지 않으면 차트가 자동으로 올바른 Enterprise 이미지를 사용해요.

3.5단계: 라이선스 구성

Note

당장은 이 단계 없이 진행할 수 있어요. 하지만 라이선스 강제 적용이 곧 도입될 예정이에요. 설치 라이선스를 받으려면 지원팀에 연락하세요.

lakeFS Enterprise는 동작하려면 유효한 라이선스가 필요해요. Helm 차트에서 라이선스는 기존 시크릿이나 명시적으로 JWT 토큰 형태로 제공돼요. values 파일에서 라이선스를 구성하는 방법은 다음과 같아요:

시크릿에 토큰을 담아 제공하는 라이선스License with token provided from existing secret

enterprise:
  enabled: true

secrets:
    licenseContents: <Your licese JWT token>
enterprise:
  enabled: true

# Name of existing secret to use
existingSecret: <Name of existing secret>

secretKeys:
    # Use to fetch license token from an existing secret:
    licenseContentsKey: <Name of license contents key from existing secret>

4단계: 인증 구성 마이그레이션

아래 구성 예시를 사용해 values.yaml 파일을 업데이트하세요:

  1. 모든 fluffy.* 구성 섹션을 제거하세요
  2. 인증 방식에 맞는 새 enterprise.auth.* 구성을 추가하세요
  3. 인증 설정을 lakefsConfig.auth.providers.*로 옮기세요

lakeFS Helm 차트 리포지토리의 전체 예시를 참고하세요.

5단계: 드라이 런으로 검증

변경 적용 전에 구성을 검증하세요:

helm upgrade <release-name> lakefs/lakefs \
  --version 1.5.0 \
  --namespace <namespace> \
  --values <your-updated-values.yaml> \
  --dry-run

출력을 검토해 다음을 확인하세요:

  • Fluffy 리소스가 생성되지 않음
  • lakeFS Enterprise 배포가 올바르게 구성됨
  • Ingress 구성이 간소화됨

6단계: 업그레이드 수행

검증이 끝나면 실제 업그레이드를 수행하세요:

helm upgrade <release-name> lakefs/lakefs \
  --version 1.5.0 \
  --namespace <namespace> \
  --values <your-updated-values.yaml>

7단계: 마이그레이션 검증

업그레이드가 완료되면:

  • 파드 상태 확인:
kubectl get pods -n <namespace>
# Fluffy pods should no longer exist
  • lakeFS 헬스 확인:
kubectl exec -n <namespace> <lakefs-pod> -- curl http://localhost:8000/_health
  • 로그 확인:
kubectl logs -n <namespace> <lakefs-pod>
# Look for successful authentication provider initialization
  • 인증 테스트:

  • 여러분의 lakeFS URL로 이동하세요

  • SSO 로그인이 올바르게 동작하는지 확인하세요

  • RBAC 권한이 보존되었는지 확인하세요

  • Fluffy 리소스 제거 확인:

kubectl get all -n <namespace> | grep fluffy
# Should return no results

8단계: 롤백 (필요한 경우)

문제가 발생하면 이전 버전으로 롤백하세요:

# Find the previous revision
helm history <release-name> -n <namespace>

# Rollback to previous revision
helm rollback <release-name> <previous-revision> -n <namespace>

구성 예시

아래는 인증 방식별 전체 구성 예시로, 이전(Fluffy)과 새(Enterprise) 구성을 모두 보여줘요:

Helm으로 OIDC

OIDC with Helm

lakeFS + Fluffy (old)lakeFS Enterprise (new)

ingress:
  enabled: true
  ingressClassName: <class-name>
  hosts:
    # the ingress that will be created for lakeFS
    - host: <lakefs.ingress.domain>
      paths:
        - /

fluffy:
  enabled: true
  fluffyConfig: |
    auth:
      logout_redirect_url: https://oidc-provider-url.com/logout/example
      oidc:
        enabled: true
        url: https://oidc-provider-url.com/
        client_id: <oidc-client-id>
        callback_base_url: https://<lakefs.ingress.domain>
        # the claim name that represents the client identifier in the OIDC provider (e.g Okta)
        logout_client_id_query_parameter: client_id
        # the query parameters that will be used to redirect the user to the OIDC provider (e.g Okta) after logout
        logout_endpoint_query_parameters:
          - returnTo
          - https://<lakefs.ingress.domain>/oidc/login
  secrets:
    create: true
  sso:
    enabled: true
    oidc:
      enabled: true
      # secret given by the OIDC provider (e.g auth0, Okta, etc)
      client_secret: <oidc-client-secret>
  rbac:
    enabled: true

lakefsConfig: |
  database:
    type: local
  blockstore:
    type: local
  auth:
    ui_config:
      login_cookie_names:
        - internal_auth_session
        - oidc_auth_session
    oidc:
      friendly_name_claim_name: <some-oidc-provider-claim-name>
      default_initial_groups: ["Developers"]
ingress:
  enabled: true
  ingressClassName: <class-name>
  hosts:
    # the ingress that will be created for lakeFS
    - host: <lakefs.ingress.domain>
      paths:
        - /

enterprise:
  enabled: true
  auth:
    oidc:
      enabled: true
      # secret given by the OIDC provider (e.g auth0, Okta, etc)
      client_secret: <oidc-client-secret>

lakefsConfig: |
  blockstore:
    type: local
  auth:
    logout_redirect_url: https://oidc-provider-url.com/logout/example
    oidc:
      friendly_name_claim_name: <some-oidc-provider-claim-name>
      default_initial_groups: ["Developers"]
    providers:
      oidc:
        post_login_redirect_url: /
        url: https://oidc-provider-url.com/
        client_id: <oidc-client-id>
        callback_base_url: https://<lakefs.ingress.domain>
        # the claim name that represents the client identifier in the OIDC provider (e.g Okta)
        logout_client_id_query_parameter: client_id
        # the query parameters that will be used to redirect the user to the OIDC provider (e.g Okta) after logout
        logout_endpoint_query_parameters:
          - returnTo
          - https://<lakefs.ingress.domain>/oidc/login

Helm으로 SAML

SAML with Helm

lakeFS + Fluffy (old)lakeFS Enterprise (new)

ingress:
  enabled: true
  ingressClassName: <class-name>
  hosts:
    # the ingress that will be created for lakeFS
    - host: <lakefs.ingress.domain>
      paths:
        - /

fluffy:
  enabled: true
  fluffyConfig: |
    auth:
      # logout_redirect_url: https://<lakefs.ingress.domain>
      # post_login_redirect_url: https://<lakefs.ingress.domain>
      saml:
        sp_sign_request: true
        # depends on IDP
        sp_signature_method: "http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"
        # url to the metadata of the IDP
        idp_metadata_url: "https://<adfs-auth.company.com>/federationmetadata/2007-06/federationmetadata.xml"
        # IDP SAML claims format default unspecified
        # idp_authn_name_id_format: "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
        # claim name from IDP to use as the unique user name
        external_user_id_claim_name: samName
        # depending on IDP setup, if CA certs are self signed and not trusted by a known CA
        idp_skip_verify_tls_cert: true
  rbac:
    enabled: true
  secrets:
    create: true
  sso:
    enabled: true
    saml:
      enabled: true
      createSecret: true
      lakeFSServiceProviderIngress: https://<lakefs.ingress.domain>
      certificate:
        saml_rsa_public_cert: |
          -----BEGIN CERTIFICATE-----
          ...
          -----END CERTIFICATE-----
        saml_rsa_private_key: |
          [REDACTED PRIVATE KEY]

lakefsConfig: |
  blockstore:
    type: local
  auth:
    cookie_auth_verification:
    # claim name to display user in the UI
      friendly_name_claim_name: displayName
      # claim name from IDP to use as the unique user name
      external_user_id_claim_name: samName
      default_initial_groups:
        - "Developers"
    ui_config:
      login_cookie_names:
        - internal_auth_session
        - saml_auth_session
ingress:
  enabled: true
  ingressClassName: <class-name>
  hosts:
    # the ingress that will be created for lakeFS
    - host: <lakefs.ingress.domain>
      paths:
        - /

enterprise:
  enabled: true
  auth:
    saml:
      enabled: true
      createCertificateSecret: true
      certificate:
        samlRsaPublicCert: |
          -----BEGIN CERTIFICATE-----
          ...
          -----END CERTIFICATE-----
        samlRsaPrivateKey: |
          [REDACTED PRIVATE KEY]

lakefsConfig: |
  blockstore:
    type: local
  auth:
    logout_redirect_url: https://<lakefs.ingress.domain>
    cookie_auth_verification:
      auth_source: saml
      # claim name to display user in the UI
      friendly_name_claim_name: displayName
      # claim name from IDP to use as the unique user name
      external_user_id_claim_name: samName
      default_initial_groups:
        - "Developers"
    providers:
      saml:
        post_login_redirect_url: https://<lakefs.ingress.domain>
        sp_root_url: https://<lakefs.ingress.domain>
        sp_sign_request: true
        # depends on IDP
        sp_signature_method: "http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"
        # url to the metadata of the IDP
        idp_metadata_url: "https://<adfs-auth.company.com>/federationmetadata/2007-06/federationmetadata.xml"
        # IDP SAML claims format default unspecified
        idp_authn_name_id_format: "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
        # depending on IDP setup, if CA certs are self signed and not trusted by a known CA
        #idp_skip_verify_tls_cert: true

Helm으로 LDAP

LDAP with Helm

lakeFS + Fluffy (old)lakeFS Enterprise (new)

ingress:
  enabled: true
  ingressClassName: <class-name>
  hosts:
    # the ingress that will be created for lakeFS
    - host: <lakefs.ingress.domain>
      paths:
       - /

fluffy:
  enabled: true
  fluffyConfig: |
    auth:
      post_login_redirect_url: /
      ldap:
        server_endpoint: ldaps://ldap.company.com:636
        bind_dn: uid=<bind-user-name>,ou=Users,o=<org-id>,dc=<company>,dc=com
        username_attribute: uid
        user_base_dn: ou=Users,o=<org-id>,dc=<company>,dc=com
        user_filter: (objectClass=inetOrgPerson)
        connection_timeout_seconds: 15
        request_timeout_seconds: 7

  secrets:
    create: true

  sso:
    enabled: true
    ldap:
      enabled: true
      bind_password: <ldap bind password>
  rbac:
    enabled: true

lakefsConfig: |
  blockstore:
    type: local
  auth:
    remote_authenticator:
      enabled: true
      default_user_group: "Developers"
    ui_config:
      login_cookie_names:
        - internal_auth_session
ingress:
  enabled: true
  ingressClassName: <class-name>
  hosts:
    # the ingress that will be created for lakeFS
    - host: <lakefs.ingress.domain>
      paths:
        - /

enterprise:
  enabled: true
  auth:
    ldap:
      enabled: true
      bindPassword: <ldap bind password>

lakefsConfig: |
  blockstore:
    type: local
  auth:
    ui_config:
      login_cookie_names:
        - internal_auth_session
    providers:
      ldap:
        server_endpoint: ldaps://ldap.company.com:636
        bind_dn: uid=<bind-user-name>,ou=Users,o=<org-id>,dc=<company>,dc=com
        username_attribute: uid
        user_base_dn: ou=Users,o=<org-id>,dc=<company>,dc=com
        user_filter: (objectClass=inetOrgPerson)
        default_user_group: "Developers"
        connection_timeout_seconds: 15
        request_timeout_seconds: 7

Helm으로 AWS IAM

AWS IAM with Helm

lakeFS + Fluffy (old)lakeFS Enterprise (new)

lakefsConfig: |
  auth:
    authentication_api:
      external_principals_enabled: true
ingress:
  enabled: true
  ingressClassName: <class-name>
  hosts:
    # the ingress that will be created for lakeFS
    - host: <lakefs.ingress.domain>
      paths:
        - /

fluffy:
  enabled: true
  image:
    repository: treeverse/fluffy
    pullPolicy: IfNotPresent
  fluffyConfig: |
    auth:
      external:
        aws_auth:
          enabled: true
          # the maximum age in seconds for the GetCallerIdentity request
          #get_caller_identity_max_age: 60
          # headers that must be present by the client when doing login request
          required_headers:
            # same host as the lakeFS server ingress
            X-LakeFS-Server-ID: <lakefs.ingress.domain>
  secrets:
    create: true
  sso:
    enabled: true
  rbac:
    enabled: true
ingress:
  enabled: true
  ingressClassName: <class-name>
  hosts:
    # the ingress that will be created for lakeFS
    - host: <lakefs.ingress.domain>
      paths:
        - /

lakefsConfig: |
  auth:
    external_aws_auth:
      enabled: true
      # the maximum age in seconds for the GetCallerIdentity request
      #get_caller_identity_max_age: 60
      # headers that must be present by the client when doing login request
      required_headers:
        # same host as the lakeFS server ingress
        X-LakeFS-Server-ID: <lakefs.ingress.domain>

중요 참고 사항

  • 인증 방식별 완전한 구성 예시는 lakeFS Helm 차트 리포지토리에서 확인할 수 있어요

  • 예시에는 빠른 시작을 위한 로컬 블록스토어가 포함되어 있어요 - 프로덕션 배포에서는 S3/Azure/GCS로 교체하세요

  • 모든 플레이스홀더 값(<>로 표시)을 여러분의 실제 구성으로 업데이트하세요

트러블슈팅

마이그레이션 중 문제가 발생하면:

  • 인증 실패: 모든 인증 설정이 새 구성 구조로 올바르게 옮겨졌는지 확인하세요

  • Ingress 문제: Ingress가 Fluffy가 아닌 lakeFS를 직접 가리키는지 확인하세요

추가 지원이 필요하면 lakeFS 문서를 참고하거나 lakeFS 지원팀에 연락하세요.

더 알아보기 (Learn more)

공식 문서의 업그레이드 페이지는 https://docs.lakefs.io/admin/upgrade 에서 확인할 수 있어요.