본문 바로가기
WIKI 기술 지식 베이스

단기 토큰

원문 보기 위키 갱신

단기 토큰 (STS 방식)

lakeFS Team과 lakeFS Enterprise에서 사용할 수 있어요. 무료 체험을 시작하거나 문의하세요.

lakeFS의 Secure Token Service(STS) 인증은 사용자가 OpenID Connect(OIDC) 인증 워크플로를 통해 아이덴티티 프로바이더(IdP)에서 얻은 임시 자격 증명으로 lakeFS에 인증할 수 있게 해줘요. 이 문서는 STS 인증 플로우를 설정하고 임시 자격 증명으로 High-Level Python SDK를 통해 lakeFS와 상호작용하는 과정을 다뤄요.

출처: 단기 토큰 (STS 방식)

본문

로그인

High-Level Python SDK로 임시 자격 증명을 사용한 클라이언트 세션을 시작해요:

import lakefs

my_client = lakefs.client.from_web_identity(code = '<CODE_FROM_IDP>', state = '<STATE_FROM_IDP>' , redirect_uri = '<URI_USED_FOR_REDIRECT_FROM_IDP>', ttl_seconds = 7200)

설정

사전 요구 사항

STS 로그인 기능을 사용해 새 클라이언트 세션을 시작하는 데 필요한 code, redirect_uri, state 값을 생성할 방법이 있는지 확인하세요. 레퍼런스 구현은 sample implementation 섹션을 참고하세요.

설정

STS 인증을 활성화하려면 lakeFS 인스턴스에 외부 인증 서비스의 엔드포인트를 설정하세요.

auth:
    authentication_api:
        endpoint: <url-to-remote-authenticator-endpoint>

endpoint 값은 authentication.yml에 설명된 외부 인증 서비스를 가리켜야 해요.

을 여러분의 인증 서비스 실제 URL로 교체하는 것을 잊지 마세요.

code, redirect_uri, state를 생성하는 구현 샘플

다음 코드 스니펫은 STS 로그인 기능을 사용해 새 클라이언트 세션을 시작하는 데 필요한 값을 생성하는 방법을 보여줘요.

Info

<your-authorize-endpoint>를 여러분의 IdP authorize 엔드포인트 경로로 교체하세요.

Examples

  • Auth0: authorize 엔드포인트는 https://<your-auth0-domain>/authorize가 될 거예요

  • Entra ID: authorize 엔드포인트는 https://<your-entra-domain>/oauth2/v2.0/authorize가 될 거예요

import crypto from 'crypto';

import express from 'express';
import axios from 'axios';
import url from 'url';
import jsonwebtoken from 'jsonwebtoken';

const app = express();
// the local script will will spin up the server and the IdP provider will return to this endpoint the response.
const callback = "http://localhost:8080/oidc/callback"
const authorizeEndpoint = "<your-authorize-endpoint>"

// step 1
// Create a code_verifier, which is a cryptographically-random, Base64-encoded key that will eventually be sent to Auth0 to request tokens.
function base64URLEncode(str) {
    return str.toString('base64')
        .replace(/\+/g, '-')
        .replace(/\//g, '_')
        .replace(/=/g, '');
}
var verifier = base64URLEncode(crypto.randomBytes(32));
console.log(`verifier: ${verifier}`);

// step 2
// Generate a code_challenge from the code_verifier that will be sent to Auth0 to request an authorization_code.
function sha256(buffer) {
    return crypto.createHash('sha256').update(buffer).digest();
}

var challenge = base64URLEncode(sha256(verifier));
console.log(`challenge: ${challenge}`);

const authorizeURL = `${authorizeEndpoint}?response_type=code&code_challenge=${challenge}&code_challenge_method=S256&client_id=${auth0ClientId}&redirect_uri=${callback}&scope=openid&state=${verifier}`

console.log(`authorizeURL: ${authorizeURL}`)

// Endpoint for OIDC callback
app.get('/oidc/callback', async (req, res) => {
    try {
        const code = req.query.code;
        const state = req.query.state;
        console.log(`code: ${code}`);
        console.log(`state: ${state}`);
        // Return a success response
        res.status(200).json({ code, state, redirect_uri: callback, python-cmd: `lakefs.client.from_web_identity(code = ${code} redirect_uri = ${callback} state = ${state}, ttl_seconds = 7200) ` });
        return
    } catch (err) {
        console.error(err);
        res.status(500).json({ message: 'Internal server error' });
    }
});

// Start the server
const PORT = 8080;
app.listen(PORT, () => {
    console.log(`Server is running on port ${PORT}`);
});

아키텍처

STS 인증 플로우는 lakeFS 클라이언트, lakeFS 서버, remote authenticator, IdP 사이의 안전한 통신을 돕는 여러 구성 요소로 이루어져 있어요.

sequenceDiagram
    participant A as lakeFS Client
    participant B as lakeFS Server
    participant C as Remote Authenticator
    participant D as IdP
    A->>B: Call STS login endpoint
    B->>C: POST idp code state and redirect uri
    C->>D: IdP request
    D->>C: IdP response
    C->>B: Auth response
    B->>A: auth JWT
  • lakeFS Client: IdP 자격 증명을 제공해 인증 프로세스를 시작해요.

  • lakeFS Server: 클라이언트와 remote authenticator 사이의 인증 요청을 중개해요.

  • Remote Authenticator: lakeFS와 IdP 사이의 다리 역할을 하며 자격 증명 검증을 처리해요.

  • IdP (Identity Provider): 제공된 자격 증명을 검증하고 인증 상태를 반환해요.

더 알아보기 (Learn more)

공식 문서의 원문은 https://docs.lakefs.io/security/sts-login/ 에서 확인할 수 있어요.