단기 토큰
단기 토큰 (STS 방식)
lakeFS Team과 lakeFS Enterprise에서 사용할 수 있어요. 무료 체험을 시작하거나 문의하세요.
lakeFS의 Secure Token Service(STS) 인증은 사용자가 OpenID Connect(OIDC) 인증 워크플로를 통해 아이덴티티 프로바이더(IdP)에서 얻은 임시 자격 증명으로 lakeFS에 인증할 수 있게 해줘요. 이 문서는 STS 인증 플로우를 설정하고 임시 자격 증명으로 High-Level Python SDK를 통해 lakeFS와 상호작용하는 과정을 다뤄요.
출처: 단기 토큰 (STS 방식)
본문
로그인
High-Level Python SDK로 임시 자격 증명을 사용한 클라이언트 세션을 시작해요:
import lakefs
my_client = lakefs.client.from_web_identity(code = '<CODE_FROM_IDP>', state = '<STATE_FROM_IDP>' , redirect_uri = '<URI_USED_FOR_REDIRECT_FROM_IDP>', ttl_seconds = 7200)
설정
사전 요구 사항
STS 로그인 기능을 사용해 새 클라이언트 세션을 시작하는 데 필요한 code, redirect_uri, state 값을 생성할 방법이 있는지 확인하세요. 레퍼런스 구현은 sample implementation 섹션을 참고하세요.
설정
STS 인증을 활성화하려면 lakeFS 인스턴스에 외부 인증 서비스의 엔드포인트를 설정하세요.
auth:
authentication_api:
endpoint: <url-to-remote-authenticator-endpoint>
endpoint 값은 authentication.yml에 설명된 외부 인증 서비스를 가리켜야 해요.
을 여러분의 인증 서비스 실제 URL로 교체하는 것을 잊지 마세요.
code, redirect_uri, state를 생성하는 구현 샘플
다음 코드 스니펫은 STS 로그인 기능을 사용해 새 클라이언트 세션을 시작하는 데 필요한 값을 생성하는 방법을 보여줘요.
Info
<your-authorize-endpoint>를 여러분의 IdP authorize 엔드포인트 경로로 교체하세요.
Examples
-
Auth0: authorize 엔드포인트는
https://<your-auth0-domain>/authorize가 될 거예요 -
Entra ID: authorize 엔드포인트는
https://<your-entra-domain>/oauth2/v2.0/authorize가 될 거예요
import crypto from 'crypto';
import express from 'express';
import axios from 'axios';
import url from 'url';
import jsonwebtoken from 'jsonwebtoken';
const app = express();
// the local script will will spin up the server and the IdP provider will return to this endpoint the response.
const callback = "http://localhost:8080/oidc/callback"
const authorizeEndpoint = "<your-authorize-endpoint>"
// step 1
// Create a code_verifier, which is a cryptographically-random, Base64-encoded key that will eventually be sent to Auth0 to request tokens.
function base64URLEncode(str) {
return str.toString('base64')
.replace(/\+/g, '-')
.replace(/\//g, '_')
.replace(/=/g, '');
}
var verifier = base64URLEncode(crypto.randomBytes(32));
console.log(`verifier: ${verifier}`);
// step 2
// Generate a code_challenge from the code_verifier that will be sent to Auth0 to request an authorization_code.
function sha256(buffer) {
return crypto.createHash('sha256').update(buffer).digest();
}
var challenge = base64URLEncode(sha256(verifier));
console.log(`challenge: ${challenge}`);
const authorizeURL = `${authorizeEndpoint}?response_type=code&code_challenge=${challenge}&code_challenge_method=S256&client_id=${auth0ClientId}&redirect_uri=${callback}&scope=openid&state=${verifier}`
console.log(`authorizeURL: ${authorizeURL}`)
// Endpoint for OIDC callback
app.get('/oidc/callback', async (req, res) => {
try {
const code = req.query.code;
const state = req.query.state;
console.log(`code: ${code}`);
console.log(`state: ${state}`);
// Return a success response
res.status(200).json({ code, state, redirect_uri: callback, python-cmd: `lakefs.client.from_web_identity(code = ${code} redirect_uri = ${callback} state = ${state}, ttl_seconds = 7200) ` });
return
} catch (err) {
console.error(err);
res.status(500).json({ message: 'Internal server error' });
}
});
// Start the server
const PORT = 8080;
app.listen(PORT, () => {
console.log(`Server is running on port ${PORT}`);
});
아키텍처
STS 인증 플로우는 lakeFS 클라이언트, lakeFS 서버, remote authenticator, IdP 사이의 안전한 통신을 돕는 여러 구성 요소로 이루어져 있어요.
sequenceDiagram
participant A as lakeFS Client
participant B as lakeFS Server
participant C as Remote Authenticator
participant D as IdP
A->>B: Call STS login endpoint
B->>C: POST idp code state and redirect uri
C->>D: IdP request
D->>C: IdP response
C->>B: Auth response
B->>A: auth JWT
-
lakeFS Client: IdP 자격 증명을 제공해 인증 프로세스를 시작해요.
-
lakeFS Server: 클라이언트와 remote authenticator 사이의 인증 요청을 중개해요.
-
Remote Authenticator: lakeFS와 IdP 사이의 다리 역할을 하며 자격 증명 검증을 처리해요.
-
IdP (Identity Provider): 제공된 자격 증명을 검증하고 인증 상태를 반환해요.
더 알아보기 (Learn more)
공식 문서의 원문은 https://docs.lakefs.io/security/sts-login/ 에서 확인할 수 있어요.