본문 바로가기
WIKI 기술 지식 베이스

Remote Authenticator

원문 보기 위키 갱신

lakeFS Team과 lakeFS Enterprise에서 사용할 수 있어요. 무료 체험을 시작하거나 문의하세요.

Remote Authenticator는 lakeFS의 플러그형 아키텍처로, 기존 조직의 아이덴티티 정책과 인프라를 lakeFS의 인증 메커니즘과 함께 사용할 수 있게 해줘요. Remote Authenticator의 역할은 기존 인프라의 복잡성을 추상화하고, lakeFS가 사용자 아이덴티티를 해석하고 lakeFS 접근을 관리하는 데 사용할 수 있는 표준 인터페이스를 구현하는 거예요. 이 느슨한 결합 덕분에 lakeFS에 아이덴티티 인프라에 대한 직접 접근 권한을 주지 않고도 연합 아이덴티티(federated identity)를 구현할 수 있어요.

출처: Remote Authenticator

본문

아키텍처

Remote Authenticator로 설정됐을 때 lakeFS가 사용하는 인증 플로우예요:

sequenceDiagram
    participant A as lakeFS Client
    participant B as lakeFS Server
    participant C as Remote Authenticator
    participant D as IdP
    A->>B: Submit login form
    B->>C: POST user credentials
    C->>D: IdP request
    D->>C: IdP response
    C->>B: Auth response
    B->>A: auth JWT

인터페이스

lakeFS를 Remote Authenticator와 함께 동작하도록 설정하려면 다음 YAML을 lakeFS 설정에 추가해요:

auth:
    remote_authenticator:
        enabled: true
        endpoint: <url-to-remote-authenticator-endpoint>
        default_user_group: "Developers"
    ui_config:
        logout_url: /logout
        login_cookie_names:
            - internal_auth_session

Remote Authenticator가 인증한 기존 사용자든 새 사용자든 모두 lakeFS에 로그인할 수 있고, 새 사용자는 설정된 기본 사용자 그룹에 연결돼요. 그래서 조직은 기존 아이덴티티 인프라를 재사용하면서 많은 사용자의 접근을 관리할 수 있어요.

  • auth.remote_authenticator.enabled - lakeFS가 remote authenticator를 사용하도록 설정해요

  • auth.remote_authenticator.endpoint - remote authenticator가 lakeFS로부터 POST 요청을 받을 수 있는 엔드포인트예요

  • auth.remote_authenticator.default_user_group - 새 사용자에게 기본으로 부여되는 그룹이에요

  • auth.ui_config.logout_url - 사용자 메뉴의 로그아웃 링크를 클릭할 때 브라우저를 리다이렉트할 URL이에요

  • auth.ui_config.login_cookie_names - 성공적인 인증 후 lakeFS가 설정할 쿠키의 이름이에요. 값은 인증된 사용자의 JWT예요

Remote Authenticator 구현은 단일 엔드포인트를 노출해야 하고, 다음과 같은 JSON 요청을 기대해요:

{
    "username": "[email protected]",
    "password": "Password1"
}

그리고 이런 JSON 응답을 반환해요:

{
    "external_user_identifier": "TestyMcTestface"
}

요청과 응답 예제

요청

POST https://remote-authenticator.example.com/auth
Content-Type: application/json

{
  "username": "[email protected]",
  "password": "Password1"
}

성공 응답

HTTP/1.1 200 OK
Content-Type: application/json

{
  "external_user_identifier": "TestyMcTestface"
}

미인증 응답

HTTP/1.1 401 Unauthorized
Content-Type: application/json

{
  "external_user_identifier": ""
}

Remote Authenticator가 2xx 범위의 어떤 HTTP 상태든 반환하면, lakeFS는 이를 성공적인 인증으로 간주해요. 200 미만이거나 300 초과인 어떤 HTTP 상태는 실패한 인증으로 간주돼요. Remote Authenticator가 성공 HTTP 상태와 함께 external_user_identifier 속성에 비어 있지 않은 값을 반환하면, lakeFS는 UI에서 내부 lakeFS 사용자 식별자 대신 이 식별자를 보여줘요.

구현 샘플

node와 express로 구현하고 TypeScript로 작성된 Remote Authenticator 샘플이에요. 이 예제 구현은 실제 IdP와 통합하지 않지만, 여러분이 구현해야 하는 요청/응답 패턴을 보여줘요.

import dotenv from "dotenv";
import express, { Express, Request, Response } from "express";
import { StatusCodes } from "http-status-codes";

type AuthRequestBody = {
  username: string;
  password: string;
};

type AuthResponseBody = {
  external_user_identifier: string;
};

const DEFAULT_PORT = 80;

dotenv.config();

const port = process.env.PORT || DEFAULT_PORT;
const app: Express = express();

app.post(
  "/auth",
  (req: Request<AuthResponseBody, {}, AuthRequestBody>, res: Response) => {
    const { username, password } = req.body;
    if (!username?.length || !password?.length) {
      return res.status(StatusCodes.BAD_REQUEST).json({
        external_user_identifier: "",
      });
    }

    // 👇🏻 This is where you would implement your own authentication logic
    if (
      username === "[email protected]" &&
      password === "Password1"
    ) {
      return res.status(StatusCodes.OK).json({
        external_user_identifier: "TestyMcTestface",
      });
    } else {
      return res.status(StatusCodes.UNAUTHORIZED).json({
        external_user_identifier: "",
      });
    }
  }
);

app.listen(port, () => {
  console.log(`Remote Authenticator listening on port ${port}`);
});

이 서비스를 idp.example.com 서브 도메인에서 실행하려면 다음과 같은 lakeFS 설정을 사용해요:

auth:
    remote_authenticator:
        enabled: true
        endpoint: https://idp.example.com/auth
        default_user_group: "Developers"
    ui_config:
        logout_url: /logout
        login_cookie_names:
            - internal_auth_session

더 알아보기 (Learn more)

공식 문서의 원문은 https://docs.lakefs.io/security/remote-authenticator/ 에서 확인할 수 있어요.