Remote Authenticator
lakeFS Team과 lakeFS Enterprise에서 사용할 수 있어요. 무료 체험을 시작하거나 문의하세요.
Remote Authenticator는 lakeFS의 플러그형 아키텍처로, 기존 조직의 아이덴티티 정책과 인프라를 lakeFS의 인증 메커니즘과 함께 사용할 수 있게 해줘요. Remote Authenticator의 역할은 기존 인프라의 복잡성을 추상화하고, lakeFS가 사용자 아이덴티티를 해석하고 lakeFS 접근을 관리하는 데 사용할 수 있는 표준 인터페이스를 구현하는 거예요. 이 느슨한 결합 덕분에 lakeFS에 아이덴티티 인프라에 대한 직접 접근 권한을 주지 않고도 연합 아이덴티티(federated identity)를 구현할 수 있어요.
본문
아키텍처
Remote Authenticator로 설정됐을 때 lakeFS가 사용하는 인증 플로우예요:
sequenceDiagram
participant A as lakeFS Client
participant B as lakeFS Server
participant C as Remote Authenticator
participant D as IdP
A->>B: Submit login form
B->>C: POST user credentials
C->>D: IdP request
D->>C: IdP response
C->>B: Auth response
B->>A: auth JWT
인터페이스
lakeFS를 Remote Authenticator와 함께 동작하도록 설정하려면 다음 YAML을 lakeFS 설정에 추가해요:
auth:
remote_authenticator:
enabled: true
endpoint: <url-to-remote-authenticator-endpoint>
default_user_group: "Developers"
ui_config:
logout_url: /logout
login_cookie_names:
- internal_auth_session
Remote Authenticator가 인증한 기존 사용자든 새 사용자든 모두 lakeFS에 로그인할 수 있고, 새 사용자는 설정된 기본 사용자 그룹에 연결돼요. 그래서 조직은 기존 아이덴티티 인프라를 재사용하면서 많은 사용자의 접근을 관리할 수 있어요.
-
auth.remote_authenticator.enabled- lakeFS가 remote authenticator를 사용하도록 설정해요 -
auth.remote_authenticator.endpoint- remote authenticator가 lakeFS로부터 POST 요청을 받을 수 있는 엔드포인트예요 -
auth.remote_authenticator.default_user_group- 새 사용자에게 기본으로 부여되는 그룹이에요 -
auth.ui_config.logout_url- 사용자 메뉴의 로그아웃 링크를 클릭할 때 브라우저를 리다이렉트할 URL이에요 -
auth.ui_config.login_cookie_names- 성공적인 인증 후 lakeFS가 설정할 쿠키의 이름이에요. 값은 인증된 사용자의 JWT예요
Remote Authenticator 구현은 단일 엔드포인트를 노출해야 하고, 다음과 같은 JSON 요청을 기대해요:
{
"username": "[email protected]",
"password": "Password1"
}
그리고 이런 JSON 응답을 반환해요:
{
"external_user_identifier": "TestyMcTestface"
}
요청과 응답 예제
요청
POST https://remote-authenticator.example.com/auth
Content-Type: application/json
{
"username": "[email protected]",
"password": "Password1"
}
성공 응답
HTTP/1.1 200 OK
Content-Type: application/json
{
"external_user_identifier": "TestyMcTestface"
}
미인증 응답
HTTP/1.1 401 Unauthorized
Content-Type: application/json
{
"external_user_identifier": ""
}
Remote Authenticator가 2xx 범위의 어떤 HTTP 상태든 반환하면, lakeFS는 이를 성공적인 인증으로 간주해요. 200 미만이거나 300 초과인 어떤 HTTP 상태는 실패한 인증으로 간주돼요. Remote Authenticator가 성공 HTTP 상태와 함께 external_user_identifier 속성에 비어 있지 않은 값을 반환하면, lakeFS는 UI에서 내부 lakeFS 사용자 식별자 대신 이 식별자를 보여줘요.
구현 샘플
node와 express로 구현하고 TypeScript로 작성된 Remote Authenticator 샘플이에요. 이 예제 구현은 실제 IdP와 통합하지 않지만, 여러분이 구현해야 하는 요청/응답 패턴을 보여줘요.
import dotenv from "dotenv";
import express, { Express, Request, Response } from "express";
import { StatusCodes } from "http-status-codes";
type AuthRequestBody = {
username: string;
password: string;
};
type AuthResponseBody = {
external_user_identifier: string;
};
const DEFAULT_PORT = 80;
dotenv.config();
const port = process.env.PORT || DEFAULT_PORT;
const app: Express = express();
app.post(
"/auth",
(req: Request<AuthResponseBody, {}, AuthRequestBody>, res: Response) => {
const { username, password } = req.body;
if (!username?.length || !password?.length) {
return res.status(StatusCodes.BAD_REQUEST).json({
external_user_identifier: "",
});
}
// 👇🏻 This is where you would implement your own authentication logic
if (
username === "[email protected]" &&
password === "Password1"
) {
return res.status(StatusCodes.OK).json({
external_user_identifier: "TestyMcTestface",
});
} else {
return res.status(StatusCodes.UNAUTHORIZED).json({
external_user_identifier: "",
});
}
}
);
app.listen(port, () => {
console.log(`Remote Authenticator listening on port ${port}`);
});
이 서비스를 idp.example.com 서브 도메인에서 실행하려면 다음과 같은 lakeFS 설정을 사용해요:
auth:
remote_authenticator:
enabled: true
endpoint: https://idp.example.com/auth
default_user_group: "Developers"
ui_config:
logout_url: /logout
login_cookie_names:
- internal_auth_session
더 알아보기 (Learn more)
공식 문서의 원문은 https://docs.lakefs.io/security/remote-authenticator/ 에서 확인할 수 있어요.