lakeFS 업그레이드
이 가이드는 셀프 매니지드 lakeFS 배포의 업그레이드를 다뤄요. 데이터베이스 마이그레이션 안내는 lakeFS Community와 lakeFS Enterprise 모두에 적용되며, lakeFS Enterprise 업그레이드는 지원 중단된 Fluffy 서비스에서의 마이그레이션을 포함해 Enterprise 고유의 단계를 다뤄요. 호스티드 배포를 사용한다면 업그레이드는 여러분을 위해 대신 처리돼요.
출처: 문서
본문
이전 버전에서 lakeFS를 업그레이드하는 것은 보통 최신 이미지로 재배포하거나, 바이너리를 사용한다면 최신 버전을 다운로드하는 것만으로 충분해요. 업그레이드 전에 릴리스에 마이그레이션이 필요한지 확인하세요.
DB 마이그레이션이 필요한 경우
lakeFS 0.103.0 이상
버전 0.103.0은 롤링 KV 업그레이드를 지원해요. 즉 이미 KV ref-store로 마이그레이션한 사용자(0.80.0 이상 버전)는 더 이상 특정 버전을 거쳐 마이그레이션할 필요가 없어요.
여기에는 lakeFS 0.98.0에서 도입된 ACL 마이그레이션도 포함돼요.
최신 lakeFS 버전에서 lakefs migrate up을 실행하면 그 시점까지의 모든 필요한 마이그레이션이 수행돼요.
lakeFS 0.80.0 이상 (KV 마이그레이션)
버전 0.80.2부터 lakeFS는 PostgreSQL 기반 데이터베이스 구현에서 여러 데이터베이스 구현을 지원하는 키-값 데이터스토어 인터페이스로 전환했어요. 자세한 내용은 여기에서 확인할 수 있어요. 이전 버전의 lakeFS에서 업그레이드하는 사용자는 더 새로운 lakeFS 버전으로 올라가기 전에 KV 마이그레이션 버전(0.80.2)을 반드시 거쳐야 해요.
Important
사전 마이그레이션 요구 사항:
- 데이터베이스 구성에 OS 환경 변수를 사용하는 사용자는 마이그레이션 진행 전에
connection_string을 명시적으로 또는 환경 변수로 정의해야 해요.
- 현재 사용 중인 용량의 최소 2배 이상의 데이터베이스 스토리지 여유 용량
- 다음 추가 단계를 수행하는 것이 강력히 권장돼요:
- 브랜치의 모든 커밋되지 않은 데이터를 커밋
- 데이터베이스 스냅샷 생성
- 기본적으로 마이그레이션 프로세스는 오래된 데이터베이스 테이블을 삭제하지 않으므로, 성공적인 마이그레이션 후 수동으로 제거해야 해요. 마이그레이션의 일부로 테이블 드롭을 활성화하려면
database.drop_tables구성 파라미터를true로 설정하세요
마이그레이션 단계
데이터베이스와 함께 현재 실행 중인 각 lakeFS 인스턴스에 대해
-
lakeFS 설정 yaml의
database섹션을 수정하세요: -
값이
"postgres"인type필드를 추가하세요 -
현재 구성 파라미터를
postgres라는 새 섹션으로 복사하세요
---
database:
type: "postgres"
connection_string: "postgres://localhost:5432/postgres?sslmode=disable"
max_open_connections: 20
postgres:
connection_string: "postgres://localhost:5432/postgres?sslmode=disable"
max_open_connections: 20
-
모든 lakeFS 인스턴스를 중지하세요
-
새 버전(0.80.2)의
lakefs바이너리를 사용해 다음을 실행하세요:
lakefs migrate up
- lakeFS가 마이그레이션 프로세스를 실행하고, 마지막에 오류 없이 다음 메시지가 표시되어야 해요:
time="2022-08-10T14:46:25Z" level=info msg="KV Migration took 717.629563ms" func="pkg/logging.(*logrusEntryWrapper).Infof" file="build/pkg/logging/logger.go:246" TempDir=/tmp/kv_migrate_2913402680
- 이제 오래된 데이터베이스 구성을 제거할 수 있어요. 업데이트된 구성은 다음과 같아야 해요:
---
database:
type: "postgres"
postgres:
connection_string: "postgres://localhost:5432/postgres?sslmode=disable"
max_open_connections: 20
- lakeFS의 새 버전을 배포(또는 실행)하세요.
lakeFS 0.30.0 이상
마이그레이션이 필요한 경우 먼저 실행 중인 lakeFS 서비스를 중지해야 해요.
새 버전의 lakefs 바이너리를 사용해 다음을 실행하세요:
lakefs migrate up
lakeFS의 새 버전을 배포(또는 실행)하세요.
오래된 lakeFS 버전은 마이그레이션된 데이터베이스에서 실행될 수 없다는 점을 유의하세요.
lakeFS 0.30.0 이전
Note
lakeFS < 0.30.0에서는 먼저 이 가이드에 따라 0.30.0으로 업그레이드한 후, 최신 버전으로 업그레이드를 진행하세요.
버전 0.30.0부터 lakeFS는 커밋된 메타데이터를 더 견고하고 성능이 좋은 새로운 방식으로 처리해요. 기존 데이터를 옮기려면 다음 업그레이드 명령을 실행해야 해요.
lakeFS 버전 == 0.30.0 확인 (Docker 사용 시 생략 가능)
lakefs --version
이전 형식에서 데이터 마이그레이션:
lakefs migrate db
또는 Docker 이미지로 마이그레이션:
docker run --rm -it -e LAKEFS_DATABASE_CONNECTION_STRING=<database connection string> treeverse/lakefs:rocks-migrate migrate db
마이그레이션 후에는 더 최신 lakeFS 버전을 사용할 수 있어요. 업그레이드와 사용에 대한 자세한 내용은 각 릴리스 노트를 참고하세요.
기존 데이터를 버리고 처음부터 다시 시작하고 싶다면 lakeFS 설정 파일에 명시적으로 이를 표시해야 해요. 그러려면 구성에 다음을 추가하세요 (0.30.0에서만 해당):
cataloger:
type: rocks
버전 v0.50.0용 데이터 마이그레이션
Warning
0.50.0 이전 버전을 사용 중이라면, 먼저 해당 버전으로 이전 업그레이드를 수행해야 해요.
lakeFS Enterprise 업그레이드
lakeFS Enterprise는 모든 엔터프라이즈 기능을 단일 바이너리로 통합해요. 기존 Enterprise 배포를 업그레이드한다면 위 데이터베이스 마이그레이션 단계가 Community와 마찬가지로 적용돼요. 가장 중요한 Enterprise 고유 변화는 아래에서 설명하는 별도 Fluffy 서비스의 제거예요.
Fluffy에서 lakeFS Enterprise로 마이그레이션
새 lakeFS Enterprise는 모든 엔터프라이즈 기능을 단일 바이너리에 직접 통합해 별도 Fluffy 서비스의 필요성을 없애요. 이로써 배포, 구성, 유지 보수가 단순해져요.
사전 준비
-
fluffy가 포함된 lakeFS enterprise 바이너리 또는 Dockerhub의 treeverse/lakefs-enterprise 이미지를 사용 중이에요.
-
lakeFS-Enterprise 버전이 >= 1.63.0이에요
-
lakeFS Enterprise 라이선스를 보유하고 있어요.
Note
lakeFS Enterprise 접근 권한은 문의하기를 통해 받을 수 있어요. lakeFS Enterprise 실행 라이선스가 부여될 거예요.
fluffy에서 lakeFS Enterprise로 마이그레이션하려면 아래 단계를 따르세요:
-
온전성 테스트(선택): 현재 프로덕션 구성을 옮기기 전에 새 테스트용 lakeFS Enterprise를 설치하세요. 셋업 전에 구성에 lakeFS Enterprise 라이선스를 반드시 포함하세요. 구성 테스트 → 로그인 → 리포지토리 생성 등을 진행해요. 모든 것이 잘 동작하는 것을 확인하면 테스트 구성을 삭제·정리하고 마이그레이션 프로세스로 넘어가요.
-
구성 업데이트: lakeFS + Fluffy와 달리 lakeFS Enterprise는 하나의 설정 파일만 사용해요. Configuration Changes를 참고하고 구성에 라이선스를 추가했는지 확인하세요.
-
lakeFS와 fluffy를 내리고 lakeFS Enterprise를 실행하세요!
Warning
lakeFS 인스턴스를 교체하는 동안 짧은 다운타임이 발생한다는 점을 유의하세요.
구성 변경 사항
인증 구성
대부분의 Fluffy auth.* 설정은 동일한 구조로 lakeFS Enterprise에 직접 마이그레이션돼요. 아래는 구성 간 차이점이에요.
SAML
lakeFS & Fluffy (old)lakeFS Enterprise (new)
# fluffy.yaml
auth:
logout_redirect_url: https://lakefs.company.com
post_login_redirect_url: https://lakefs.company.com
saml:
enabled: true
sp_root_url: https://lakefs.company.com
sp_x509_key_path: dummy_saml_rsa.key
sp_x509_cert_path: dummy_saml_rsa.cert
sp_sign_request: true
sp_signature_method: http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
idp_metadata_url: https://my.saml-provider.com/federationmetadata/2007-06/federationmetadata.xml
# idp_authn_name_id_format: "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
external_user_id_claim_name: samName
# idp_metadata_file_path:
# idp_skip_verify_tls_cert: true
# lakefs.yaml
auth:
logout_redirect_url: https://lakefs.company.com
cookie_auth_verification:
auth_source: saml
friendly_name_claim_name: displayName
persist_friendly_name: true
external_user_id_claim_name: samName
validate_id_token_claims:
department: r_n_d
default_initial_groups:
- "Developers"
ui_config:
login_url: https://lakefs.company.com/sso/login-saml
logout_url: https://lakefs.company.com/sso/logout-saml
login_cookie_names:
- internal_auth_session
- saml_auth_session
# lakefs.yaml
auth:
logout_redirect_url: https://lakefs.company.com/ # optional, URL to redirect to after logout
cookie_auth_verification:
auth_source: saml
friendly_name_claim_name: displayName
default_initial_groups: ["Admins"]
external_user_id_claim_name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
validate_id_token_claims:
department: r_n_d
providers:
saml:
# enabled: true # This field was dropped!
sp_root_url: https://lakefs.company.com
sp_x509_key_path: dummy_saml_rsa.key
sp_x509_cert_path: dummy_saml_rsa.cert
sp_sign_request: true
sp_signature_method: http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
idp_metadata_url: https://my.saml-provider.com/federationmetadata/2007-06/federationmetadata.xml
post_login_redirect_url: / # Where to redirect after successful SAML login
# external_user_id_claim_name: # This field was moved to auth.cookie_auth_verification
ui_config:
login_url: https://lakefs.company.com/sso/login-saml
logout_url: https://lakefs.company.com/sso/logout-saml
login_cookie_names:
- internal_auth_session
- saml_auth_session
OIDC + OIDC STS
lakeFS + Fluffy (old)lakeFS Enterprise (new)
# fluffy.yaml
auth:
post_login_redirect_url: /
logout_redirect_url: https://oidc-provider-url.com/logout/url
oidc:
enabled: true
url: https://oidc-provider-url.com/
client_id: <oidc-client-id>
client_secret: <oidc-client-secret>
callback_base_url: https://lakefs.company.com
is_default_login: true
logout_client_id_query_parameter: client_id
logout_endpoint_query_parameters:
- returnTo
- https://lakefs.company.com/oidc/login
# lakefs.yaml
auth:
oidc:
friendly_name_claim_name: "name"
persist_friendly_name: true
default_initial_groups: ["Developers"]
ui_config:
login_url: /oidc/login
logout_url: /oidc/logout
login_cookie_names:
- internal_auth_session
- oidc_auth_session
# lakefs.yaml
auth:
logout_redirect_url: https://oidc-provider-url.com/logout/url # optional, URL to redirect to after logout
ui_config:
login_url: /oidc/login
logout_url: /oidc/logout
login_cookie_names:
- internal_auth_session
- oidc_auth_session
oidc:
friendly_name_claim_name: "nickname"
default_initial_groups: ["Admins"]
providers:
oidc:
# enabled: true # This field was dropped!
post_login_redirect_url: / # This field was moved here!
url: https://oidc-provider-url.com/
client_id: <oidc-client-id>
client_secret: <oidc-client-secret>
callback_base_url: https://lakefs.company.com
logout_client_id_query_parameter: client_id
logout_endpoint_query_parameters:
- returnTo
- http://lakefs.company.com/oidc/login
LDAP
lakeFS + Fluffy (old)lakeFS Enterprise (new)
# fluffy.yaml
auth:
post_login_redirect_url: /
ldap:
server_endpoint: ldaps://ldap.company.com:636
bind_dn: uid=<bind-user-name>,ou=<some-ou>,o=<org-id>,dc=<company>,dc=com
bind_password: '<ldap password>'
username_attribute: uid
user_base_dn: ou=<some-ou>,o=<org-id>,dc=<company>,dc=com
user_filter: (objectClass=inetOrgPerson)
connection_timeout_seconds: 15
request_timeout_seconds: 7
# lakefs.yaml
auth:
remote_authenticator:
enabled: true
endpoint: http://<Fluffy URL>:<Fluffy http port>/api/v1/ldap/login
default_user_group: "Developers" # Value needs to correspond with an existing group in lakeFS
ui_config:
logout_url: /logout
login_cookie_names:
- internal_auth_session
# lakefs.yaml
auth:
ui_config:
logout_url: /logout
login_cookie_names:
- internal_auth_session
providers:
ldap:
server_endpoint: ldaps://ldap.company.com:636
bind_dn: uid=<bind-user-name>,ou=<some-ou>,o=<org-id>,dc=<company>,dc=com
bind_password: '<ldap password>'
username_attribute: uid
user_base_dn: ou=<some-ou>,o=<org-id>,dc=<company>,dc=com
user_filter: (objectClass=inetOrgPerson)
connection_timeout_seconds: 15
request_timeout_seconds: 7
default_user_group: "Developers" # This field moved here!
AWS IAM
lakeFS + Fluffy (old)lakeFS Enterprise (new)
# fluffy.yaml
serve_listen: "localhost:9001"
auth:
external:
aws_auth:
enabled: true
required_headers:
X-LakeFS-Server-ID: "localhost"
# lakefs.yaml
auth:
authentication_api:
endpoint: http://localhost:9001/api/v1
external_principals_enabled: true
# lakefs.yaml
auth:
external_aws_auth:
enabled: true
required_headers:
X-LakeFS-Server-ID: "localhost"
권한 부여 구성
RBAC
lakeFS + Fluffy (old)lakeFS Enterprise (new)
# fluffy.yaml
auth:
serve_listen_address: "localhost:9000"
cache:
enabled: true
# lakefs.yaml
auth:
api:
endpoint: http://localhost:9000/api/v1
# lakefs.yaml
auth:
# serve_disable_authentication: false # this field was dropped!
# serve_listen_address: "localhost:9000" # this field was dropped!
# api: # this field was dropped!
# endpoint: http://localhost:9000/api/v1 # this field was dropped!
cache:
enabled: true
Kubernetes: Helm으로 Fluffy에서 새 lakeFS Enterprise로 마이그레이션
개요
lakeFS Helm 차트 버전 1.5.0부터 Fluffy 인증 서비스는 지원 중단되었고 네이티브 lakeFS Enterprise 인증으로 대체되었어요. 이 마이그레이션은 인증을 메인 lakeFS 애플리케이션으로 통합해 배포와 유지 보수를 단순화해요.
바뀌는 내용
lakeFS Enterprise로 업그레이드하면:
-
Fluffy 배포 제거: 별도의 Fluffy 배포, 서비스, 연관 Kubernetes 리소스가 더 이상 필요 없어요
-
단순화된 아키텍처: 인증이 lakeFS Enterprise가 직접 처리해 파드와 서비스 수가 줄어요
-
간소화된 Ingress: Fluffy와 lakeFS 사이의 라우팅이 사라지고 모든 트래픽이 lakeFS로 직접 가요
-
업데이트된 values.yaml 구조: 인증 구성이
fluffy.*에서enterprise.auth.*와lakefsConfig.auth.providers.*로 이동해요
사전 준비
-
Fluffy 인증을 사용하는 현재 lakeFS 배포 (차트 버전 < 1.5.0)
-
Helm values 업데이트 접근 권한
-
현재 values.yaml 백업
단계별 마이그레이션 가이드
1단계: Helm 리포지토리 업데이트
helm repo update lakefs
차트 버전 1.5.0 이상에 접근할 수 있는지 확인하세요:
helm search repo lakefs/lakefs --versions
2단계: 새 차트 값 검토
새 차트의 사용 가능한 모든 구성 옵션을 검토하세요:
helm show values lakefs/lakefs --version 1.5.0 > new-values-reference.yaml
3단계: 이미지 구성 업데이트
values.yaml에서 이미지를 오버라이드하고 있다면 lakeFS Enterprise를 사용하도록 업데이트하세요:
image:
repository: treeverse/lakefs-enterprise
tag: 1.63.0
참고: 이미지를 오버라이드하지 않으면 차트가 자동으로 올바른 Enterprise 이미지를 사용해요.
3.5단계: 라이선스 구성
Note
당장은 이 단계 없이 진행할 수 있어요. 하지만 라이선스 강제 적용이 곧 도입될 예정이에요. 설치 라이선스를 받으려면 지원팀에 연락하세요.
lakeFS Enterprise는 동작하려면 유효한 라이선스가 필요해요.
Helm 차트에서 라이선스는 기존 시크릿이나 명시적으로 JWT 토큰 형태로 제공돼요.
values 파일에서 라이선스를 구성하는 방법은 다음과 같아요:
시크릿에 토큰을 담아 제공하는 라이선스License with token provided from existing secret
enterprise:
enabled: true
secrets:
licenseContents: <Your licese JWT token>
enterprise:
enabled: true
# Name of existing secret to use
existingSecret: <Name of existing secret>
secretKeys:
# Use to fetch license token from an existing secret:
licenseContentsKey: <Name of license contents key from existing secret>
4단계: 인증 구성 마이그레이션
아래 구성 예시를 사용해 values.yaml 파일을 업데이트하세요:
- 모든
fluffy.*구성 섹션을 제거하세요 - 인증 방식에 맞는 새
enterprise.auth.*구성을 추가하세요 - 인증 설정을
lakefsConfig.auth.providers.*로 옮기세요
lakeFS Helm 차트 리포지토리의 전체 예시를 참고하세요.
5단계: 드라이 런으로 검증
변경 적용 전에 구성을 검증하세요:
helm upgrade <release-name> lakefs/lakefs \
--version 1.5.0 \
--namespace <namespace> \
--values <your-updated-values.yaml> \
--dry-run
출력을 검토해 다음을 확인하세요:
- Fluffy 리소스가 생성되지 않음
- lakeFS Enterprise 배포가 올바르게 구성됨
- Ingress 구성이 간소화됨
6단계: 업그레이드 수행
검증이 끝나면 실제 업그레이드를 수행하세요:
helm upgrade <release-name> lakefs/lakefs \
--version 1.5.0 \
--namespace <namespace> \
--values <your-updated-values.yaml>
7단계: 마이그레이션 검증
업그레이드가 완료되면:
- 파드 상태 확인:
kubectl get pods -n <namespace>
# Fluffy pods should no longer exist
- lakeFS 헬스 확인:
kubectl exec -n <namespace> <lakefs-pod> -- curl http://localhost:8000/_health
- 로그 확인:
kubectl logs -n <namespace> <lakefs-pod>
# Look for successful authentication provider initialization
-
인증 테스트:
-
여러분의 lakeFS URL로 이동하세요
-
SSO 로그인이 올바르게 동작하는지 확인하세요
-
RBAC 권한이 보존되었는지 확인하세요
-
Fluffy 리소스 제거 확인:
kubectl get all -n <namespace> | grep fluffy
# Should return no results
8단계: 롤백 (필요한 경우)
문제가 발생하면 이전 버전으로 롤백하세요:
# Find the previous revision
helm history <release-name> -n <namespace>
# Rollback to previous revision
helm rollback <release-name> <previous-revision> -n <namespace>
구성 예시
아래는 인증 방식별 전체 구성 예시로, 이전(Fluffy)과 새(Enterprise) 구성을 모두 보여줘요:
Helm으로 OIDC
OIDC with Helm
lakeFS + Fluffy (old)lakeFS Enterprise (new)
ingress:
enabled: true
ingressClassName: <class-name>
hosts:
# the ingress that will be created for lakeFS
- host: <lakefs.ingress.domain>
paths:
- /
fluffy:
enabled: true
fluffyConfig: |
auth:
logout_redirect_url: https://oidc-provider-url.com/logout/example
oidc:
enabled: true
url: https://oidc-provider-url.com/
client_id: <oidc-client-id>
callback_base_url: https://<lakefs.ingress.domain>
# the claim name that represents the client identifier in the OIDC provider (e.g Okta)
logout_client_id_query_parameter: client_id
# the query parameters that will be used to redirect the user to the OIDC provider (e.g Okta) after logout
logout_endpoint_query_parameters:
- returnTo
- https://<lakefs.ingress.domain>/oidc/login
secrets:
create: true
sso:
enabled: true
oidc:
enabled: true
# secret given by the OIDC provider (e.g auth0, Okta, etc)
client_secret: <oidc-client-secret>
rbac:
enabled: true
lakefsConfig: |
database:
type: local
blockstore:
type: local
auth:
ui_config:
login_cookie_names:
- internal_auth_session
- oidc_auth_session
oidc:
friendly_name_claim_name: <some-oidc-provider-claim-name>
default_initial_groups: ["Developers"]
ingress:
enabled: true
ingressClassName: <class-name>
hosts:
# the ingress that will be created for lakeFS
- host: <lakefs.ingress.domain>
paths:
- /
enterprise:
enabled: true
auth:
oidc:
enabled: true
# secret given by the OIDC provider (e.g auth0, Okta, etc)
client_secret: <oidc-client-secret>
lakefsConfig: |
blockstore:
type: local
auth:
logout_redirect_url: https://oidc-provider-url.com/logout/example
oidc:
friendly_name_claim_name: <some-oidc-provider-claim-name>
default_initial_groups: ["Developers"]
providers:
oidc:
post_login_redirect_url: /
url: https://oidc-provider-url.com/
client_id: <oidc-client-id>
callback_base_url: https://<lakefs.ingress.domain>
# the claim name that represents the client identifier in the OIDC provider (e.g Okta)
logout_client_id_query_parameter: client_id
# the query parameters that will be used to redirect the user to the OIDC provider (e.g Okta) after logout
logout_endpoint_query_parameters:
- returnTo
- https://<lakefs.ingress.domain>/oidc/login
Helm으로 SAML
SAML with Helm
lakeFS + Fluffy (old)lakeFS Enterprise (new)
ingress:
enabled: true
ingressClassName: <class-name>
hosts:
# the ingress that will be created for lakeFS
- host: <lakefs.ingress.domain>
paths:
- /
fluffy:
enabled: true
fluffyConfig: |
auth:
# logout_redirect_url: https://<lakefs.ingress.domain>
# post_login_redirect_url: https://<lakefs.ingress.domain>
saml:
sp_sign_request: true
# depends on IDP
sp_signature_method: "http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"
# url to the metadata of the IDP
idp_metadata_url: "https://<adfs-auth.company.com>/federationmetadata/2007-06/federationmetadata.xml"
# IDP SAML claims format default unspecified
# idp_authn_name_id_format: "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
# claim name from IDP to use as the unique user name
external_user_id_claim_name: samName
# depending on IDP setup, if CA certs are self signed and not trusted by a known CA
idp_skip_verify_tls_cert: true
rbac:
enabled: true
secrets:
create: true
sso:
enabled: true
saml:
enabled: true
createSecret: true
lakeFSServiceProviderIngress: https://<lakefs.ingress.domain>
certificate:
saml_rsa_public_cert: |
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
saml_rsa_private_key: |
[REDACTED PRIVATE KEY]
lakefsConfig: |
blockstore:
type: local
auth:
cookie_auth_verification:
# claim name to display user in the UI
friendly_name_claim_name: displayName
# claim name from IDP to use as the unique user name
external_user_id_claim_name: samName
default_initial_groups:
- "Developers"
ui_config:
login_cookie_names:
- internal_auth_session
- saml_auth_session
ingress:
enabled: true
ingressClassName: <class-name>
hosts:
# the ingress that will be created for lakeFS
- host: <lakefs.ingress.domain>
paths:
- /
enterprise:
enabled: true
auth:
saml:
enabled: true
createCertificateSecret: true
certificate:
samlRsaPublicCert: |
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
samlRsaPrivateKey: |
[REDACTED PRIVATE KEY]
lakefsConfig: |
blockstore:
type: local
auth:
logout_redirect_url: https://<lakefs.ingress.domain>
cookie_auth_verification:
auth_source: saml
# claim name to display user in the UI
friendly_name_claim_name: displayName
# claim name from IDP to use as the unique user name
external_user_id_claim_name: samName
default_initial_groups:
- "Developers"
providers:
saml:
post_login_redirect_url: https://<lakefs.ingress.domain>
sp_root_url: https://<lakefs.ingress.domain>
sp_sign_request: true
# depends on IDP
sp_signature_method: "http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"
# url to the metadata of the IDP
idp_metadata_url: "https://<adfs-auth.company.com>/federationmetadata/2007-06/federationmetadata.xml"
# IDP SAML claims format default unspecified
idp_authn_name_id_format: "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
# depending on IDP setup, if CA certs are self signed and not trusted by a known CA
#idp_skip_verify_tls_cert: true
Helm으로 LDAP
LDAP with Helm
lakeFS + Fluffy (old)lakeFS Enterprise (new)
ingress:
enabled: true
ingressClassName: <class-name>
hosts:
# the ingress that will be created for lakeFS
- host: <lakefs.ingress.domain>
paths:
- /
fluffy:
enabled: true
fluffyConfig: |
auth:
post_login_redirect_url: /
ldap:
server_endpoint: ldaps://ldap.company.com:636
bind_dn: uid=<bind-user-name>,ou=Users,o=<org-id>,dc=<company>,dc=com
username_attribute: uid
user_base_dn: ou=Users,o=<org-id>,dc=<company>,dc=com
user_filter: (objectClass=inetOrgPerson)
connection_timeout_seconds: 15
request_timeout_seconds: 7
secrets:
create: true
sso:
enabled: true
ldap:
enabled: true
bind_password: <ldap bind password>
rbac:
enabled: true
lakefsConfig: |
blockstore:
type: local
auth:
remote_authenticator:
enabled: true
default_user_group: "Developers"
ui_config:
login_cookie_names:
- internal_auth_session
ingress:
enabled: true
ingressClassName: <class-name>
hosts:
# the ingress that will be created for lakeFS
- host: <lakefs.ingress.domain>
paths:
- /
enterprise:
enabled: true
auth:
ldap:
enabled: true
bindPassword: <ldap bind password>
lakefsConfig: |
blockstore:
type: local
auth:
ui_config:
login_cookie_names:
- internal_auth_session
providers:
ldap:
server_endpoint: ldaps://ldap.company.com:636
bind_dn: uid=<bind-user-name>,ou=Users,o=<org-id>,dc=<company>,dc=com
username_attribute: uid
user_base_dn: ou=Users,o=<org-id>,dc=<company>,dc=com
user_filter: (objectClass=inetOrgPerson)
default_user_group: "Developers"
connection_timeout_seconds: 15
request_timeout_seconds: 7
Helm으로 AWS IAM
AWS IAM with Helm
lakeFS + Fluffy (old)lakeFS Enterprise (new)
lakefsConfig: |
auth:
authentication_api:
external_principals_enabled: true
ingress:
enabled: true
ingressClassName: <class-name>
hosts:
# the ingress that will be created for lakeFS
- host: <lakefs.ingress.domain>
paths:
- /
fluffy:
enabled: true
image:
repository: treeverse/fluffy
pullPolicy: IfNotPresent
fluffyConfig: |
auth:
external:
aws_auth:
enabled: true
# the maximum age in seconds for the GetCallerIdentity request
#get_caller_identity_max_age: 60
# headers that must be present by the client when doing login request
required_headers:
# same host as the lakeFS server ingress
X-LakeFS-Server-ID: <lakefs.ingress.domain>
secrets:
create: true
sso:
enabled: true
rbac:
enabled: true
ingress:
enabled: true
ingressClassName: <class-name>
hosts:
# the ingress that will be created for lakeFS
- host: <lakefs.ingress.domain>
paths:
- /
lakefsConfig: |
auth:
external_aws_auth:
enabled: true
# the maximum age in seconds for the GetCallerIdentity request
#get_caller_identity_max_age: 60
# headers that must be present by the client when doing login request
required_headers:
# same host as the lakeFS server ingress
X-LakeFS-Server-ID: <lakefs.ingress.domain>
중요 참고 사항
-
인증 방식별 완전한 구성 예시는 lakeFS Helm 차트 리포지토리에서 확인할 수 있어요
-
예시에는 빠른 시작을 위한 로컬 블록스토어가 포함되어 있어요 - 프로덕션 배포에서는 S3/Azure/GCS로 교체하세요
-
모든 플레이스홀더 값(
<>로 표시)을 여러분의 실제 구성으로 업데이트하세요
트러블슈팅
마이그레이션 중 문제가 발생하면:
-
인증 실패: 모든 인증 설정이 새 구성 구조로 올바르게 옮겨졌는지 확인하세요
-
Ingress 문제: Ingress가 Fluffy가 아닌 lakeFS를 직접 가리키는지 확인하세요
추가 지원이 필요하면 lakeFS 문서를 참고하거나 lakeFS 지원팀에 연락하세요.
더 알아보기 (Learn more)
공식 문서의 업그레이드 페이지는 https://docs.lakefs.io/admin/upgrade 에서 확인할 수 있어요.