Add auth option for Tornjak (#259)
* Added auth option, specifically keycloak for tornjak production use Signed-off-by: Mohammed Abdi <[email protected]> * Added auth values for tornjak Signed-off-by: Mohammed Abdi <[email protected]> * Update charts/spire/charts/tornjak-frontend/values.yaml Co-authored-by: Faisal Memon <[email protected]> Signed-off-by: Mohammed Abdi <[email protected]> * Update examples/tornjak/keycloak/README.md Co-authored-by: Faisal Memon <[email protected]> Signed-off-by: Mohammed Abdi <[email protected]> * Update examples/tornjak/keycloak/README.md Co-authored-by: Faisal Memon <[email protected]> Signed-off-by: Mohammed Abdi <[email protected]> * Update examples/tornjak/keycloak/README.md Co-authored-by: Faisal Memon <[email protected]> Signed-off-by: Mohammed Abdi <[email protected]> * Update examples/tornjak/keycloak/README.md Co-authored-by: Faisal Memon <[email protected]> Signed-off-by: Mohammed Abdi <[email protected]> * Update examples/tornjak/keycloak/README.md Co-authored-by: Faisal Memon <[email protected]> Signed-off-by: Mohammed Abdi <[email protected]> * Update examples/tornjak/keycloak/README.md Co-authored-by: Faisal Memon <[email protected]> Signed-off-by: Mohammed Abdi <[email protected]> * nit Signed-off-by: Mohammed Abdi <[email protected]> * nit Signed-off-by: Mohammed Abdi <[email protected]> * nit Signed-off-by: Mohammed Abdi <[email protected]> * Update examples/tornjak/keycloak/README.md Co-authored-by: Mariusz Sabath <[email protected]> Signed-off-by: Mohammed Abdi <[email protected]> * nit Signed-off-by: Mohammed Abdi <[email protected]> * install keycloak first Signed-off-by: Mohammed Abdi <[email protected]> * add logs volume back Signed-off-by: Mohammed Abdi <[email protected]> * Fixed NPM init error Signed-off-by: Mariusz Sabath <[email protected]> * Fixed the values documentation errors Signed-off-by: Mariusz Sabath <[email protected]> * Post-review suggestion fixes Signed-off-by: Mariusz Sabath <[email protected]> * Fixed typo Signed-off-by: Mariusz Sabath <[email protected]> * Updating Keyclaok examples README Signed-off-by: Mariusz Sabath <[email protected]> * Fixed the parameter reference Signed-off-by: Mariusz Sabath <[email protected]> * Fix typo Signed-off-by: Mariusz Sabath <[email protected]> * use keycloak-config-cli to simplify tornjak realm import Signed-off-by: MohammedAbdi <[email protected]> * edit client id Signed-off-by: MohammedAbdi <[email protected]> * reverse client id Signed-off-by: MohammedAbdi <[email protected]> * fix the doc Signed-off-by: Mariusz Sabath <[email protected]> * update tornjak version and backend auth Signed-off-by: MohammedAbdi <[email protected]> * update client id Signed-off-by: MohammedAbdi <[email protected]> * updates values yaml Signed-off-by: MohammedAbdi <[email protected]> * update documentation Signed-off-by: MohammedAbdi <[email protected]> * nit Signed-off-by: MohammedAbdi <[email protected]> * update doc Signed-off-by: MohammedAbdi <[email protected]> * add audience check tornjak Signed-off-by: MohammedAbdi <[email protected]> * remove unused file Signed-off-by: MohammedAbdi <[email protected]> * update doc Signed-off-by: MohammedAbdi <[email protected]> * nit and add auth not enabled warning back Signed-off-by: MohammedAbdi <[email protected]> * adjust liveness probe until tornjak handles liveendpoint for auth and direct connection to discovery Signed-off-by: MohammedAbdi <[email protected]> * update doc and add keycloak proxy Signed-off-by: MohammedAbdi <[email protected]> --------- Signed-off-by: Mohammed Abdi <[email protected]> Signed-off-by: Mohammed Abdi <[email protected]> Signed-off-by: Mariusz Sabath <[email protected]> Signed-off-by: MohammedAbdi <[email protected]> Co-authored-by: Mohammed Abdi <[email protected]> Co-authored-by: Faisal Memon <[email protected]> Co-authored-by: Mariusz Sabath <[email protected]>
This commit is contained in:
co-authored by
Faisal Memon
Mariusz Sabath
Mohammed Abdi
parent
f679a0dab6
commit
a2494ee45e
@@ -1,8 +1,5 @@
|
||||
# Recommended setup to deploy Tornjak
|
||||
|
||||
> [!Warning]
|
||||
> The current version of Tornjak in this chart is deployed without authentication. Therefore it is not suitable to run this version in production.
|
||||
|
||||
To install Spire with the least privileges possible we deploy spire across 2 namespaces.
|
||||
|
||||
```shell
|
||||
@@ -13,7 +10,7 @@ kubectl label namespace "spire-server" pod-security.kubernetes.io/enforce=restri
|
||||
|
||||
# deploy SPIRE with Tornjak enabled
|
||||
helm upgrade --install --namespace spire-server spire charts/spire \
|
||||
--values examples/production/values.yaml \
|
||||
--values tests/integration/psat/values.yaml \
|
||||
--values examples/tornjak/values.yaml \
|
||||
--render-subchart-notes
|
||||
|
||||
@@ -48,11 +45,10 @@ Update examples/production/example-your-values.yaml with your information, most
|
||||
|
||||
```shell
|
||||
helm upgrade --install --namespace spire-server spire charts/spire \
|
||||
--values examples/production/values.yaml \
|
||||
--values tests/integration/psat/values.yaml \
|
||||
--values examples/tornjak/values.yaml \
|
||||
--values examples/tornjak/values-ingress.yaml \
|
||||
--set global.spire.ingressControllerType=ingress-nginx \
|
||||
--values examples/production/example-your-values.yaml \
|
||||
--render-subchart-notes --debug
|
||||
```
|
||||
|
||||
|
||||
@@ -0,0 +1,114 @@
|
||||
# Deploy Tornjak with Authentication Enabled
|
||||
|
||||
This example demonstrates Tornjak's capability to control access to the Frontend Application using
|
||||
User Management via [Keycloak](https://www.keycloak.org/).
|
||||
|
||||
Tested on:
|
||||
- Keycloak Application Version - 24.0.3
|
||||
- Keycloak Chart Version - 21.0.3
|
||||
|
||||
For more information regarding Tornjak User Management, please refer to the following documentation:
|
||||
|
||||
* [Tornjak User Management](https://github.com/spiffe/tornjak/blob/main/docs/keycloak-configuration.md)
|
||||
* [Keycloak Configuration for Tornjak](https://github.com/spiffe/tornjak/blob/main/docs/keycloak-configuration.md)
|
||||
* [Detailed Blogs on Tornjak User Management](https://github.com/spiffe/tornjak/blob/main/docs/blogs.md)
|
||||
|
||||
**NOTE:** This example works only with the Vanilla version of Kubernetes; it does not yet support Openshift.
|
||||
|
||||
As part of the exercise, an instance of Keycloak is deployed to illustrate how to manage users' access to Tornjak.
|
||||
Once enabled, the Tornjak UI will redirect all authentication calls to the Keycloak instance to obtain the
|
||||
correct credentials. Authorization is based on these credentials and occurs at the Tornjak application level.
|
||||
|
||||
## Deploy Keycloak Instance (Authentication Service)
|
||||
|
||||
We will deploy the instance of Keycloak in the same namespace as the SPIRE Server
|
||||
|
||||
```shell
|
||||
# Create a namespace to deploy Keycloak and SPIRE-server
|
||||
kubectl create namespace spire-server
|
||||
```
|
||||
|
||||
```shell
|
||||
# Deploy Keycloak as an authentication service
|
||||
helm upgrade --install -n spire-server keycloak --values examples/tornjak/keycloak/values.yaml oci://registry-1.docker.io/bitnamicharts/keycloak --render-subchart-notes
|
||||
```
|
||||
|
||||
* It's important to start the service before configuring Tornjak with auth.
|
||||
|
||||
```shell
|
||||
# Start an auth Service [Keycloak] (Terminal 3)
|
||||
kubectl -n spire-server port-forward service/keycloak 8080:80
|
||||
```
|
||||
## Deploy SPIRE with Tornjak User Management Enabled
|
||||
|
||||
Please follow the instructions for deploying Tornjak as specified in Tornjak Example [here](../README.md)
|
||||
with addition of the User Management values `--values examples/tornjak/values-auth.yaml`.
|
||||
|
||||
For example:
|
||||
|
||||
```shell
|
||||
# Install SPIRE CRDs
|
||||
helm upgrade --install --create-namespace -n spire-mgmt spire-crds charts/spire-crds
|
||||
```
|
||||
|
||||
```shell
|
||||
# Standard SPIRE and Tornjak deployment with Authentication enabled
|
||||
helm upgrade --install \
|
||||
--set global.spire.namespaces.system.create=true \
|
||||
--values tests/integration/psat/values.yaml \
|
||||
--values examples/tornjak/values.yaml \
|
||||
--values examples/tornjak/values-auth.yaml \
|
||||
--render-subchart-notes spire charts/spire
|
||||
```
|
||||
|
||||
To test the deployment, you can run the SPIRE test:
|
||||
|
||||
```shell
|
||||
# Test the Tornjak deployment
|
||||
helm test spire
|
||||
```
|
||||
|
||||
## Access Tornjak
|
||||
|
||||
To access Tornjak use port-forwarding or check the ingress option below.
|
||||
|
||||
Run following commands from your shell, if you run with different values your namespace might differ. Consult the install notes printed when running above `helm upgrade` command in that case.
|
||||
|
||||
Since `port-forward` is a blocking command, execute them in three different consoles (one for backend, one for frontend and one for auth that you already started in the previous step):
|
||||
|
||||
```shell
|
||||
# Start a backend Service (Terminal 1)
|
||||
kubectl -n spire-server port-forward service/spire-tornjak-backend 10000:10000
|
||||
```
|
||||
|
||||
```shell
|
||||
# Start a frontend Service (Terminal 2)
|
||||
kubectl -n spire-server port-forward service/spire-tornjak-frontend 3000:3000
|
||||
```
|
||||
|
||||
* You can now access Tornjak at [localhost:3000](http://localhost:3000).
|
||||
|
||||
* This will redirect to the auth service for authentication to [localhost:8080](http://localhost:8080)
|
||||
|
||||
See [values.yaml](./values.yaml) for more details on the chart configurations to customize authentication config.
|
||||
|
||||
## Deploy SPIRE with Tornjak User Management Enabled using Ingress
|
||||
|
||||
When deployment uses Ingress, the access to Tornjak application and Keycloak will be different from above.
|
||||
Please follow the deployment and configuration instructions as described [here](../README.md)
|
||||
and make sure to add the `--values examples/tornjak/values-auth.yaml` parameter that is referencing Tornjak Authentication values.
|
||||
|
||||
And update your `examples/production/example-your-values.yaml` most importantly, `trustDomain`, accordingly.
|
||||
|
||||
E.g:
|
||||
|
||||
```shell
|
||||
helm upgrade --install \
|
||||
--set global.spire.namespaces.create=true \
|
||||
--set global.spire.ingressControllerType=ingress-nginx \
|
||||
--values tests/integration/psat/values.yaml \
|
||||
--values examples/tornjak/values.yaml \
|
||||
--values examples/tornjak/values-auth.yaml \
|
||||
--values examples/tornjak/values-ingress.yaml \
|
||||
--render-subchart-notes spire charts/spire
|
||||
```
|
||||
@@ -0,0 +1,128 @@
|
||||
auth:
|
||||
## @param keycloak.auth.realm Realm name in which to create users## @param auth.adminUser Keycloak administrator user
|
||||
##
|
||||
adminUser: admin
|
||||
## @param auth.adminPassword Keycloak administrator password for the new user
|
||||
##
|
||||
adminPassword: admin
|
||||
proxy: edge # for https proxy reverse mode
|
||||
keycloakConfigCli:
|
||||
enabled: true
|
||||
configuration: # tornjak realm configuration
|
||||
tornjak.json: |
|
||||
{
|
||||
"realm": "tornjak",
|
||||
"enabled": true,
|
||||
"roles" : {
|
||||
"realm" : [ {
|
||||
"name" : "tornjak-viewer-realm-role"
|
||||
}, {
|
||||
"name" : "tornjak-admin-realm-role"
|
||||
} ],
|
||||
"client" : {
|
||||
"tornjak" : [ {
|
||||
"name" : "viewer",
|
||||
"composite" : true,
|
||||
"composites" : {
|
||||
"realm" : [ "tornjak-viewer-realm-role" ]
|
||||
},
|
||||
"clientRole" : true
|
||||
}, {
|
||||
"name" : "admin",
|
||||
"composite" : true,
|
||||
"composites" : {
|
||||
"realm" : [ "tornjak-admin-realm-role" ]
|
||||
},
|
||||
"clientRole" : true
|
||||
} ]
|
||||
}
|
||||
},
|
||||
"groups" : [ {
|
||||
"name" : "admin",
|
||||
"path" : "/admin",
|
||||
"realmRoles" : [ "tornjak-admin-realm-role" ]
|
||||
}, {
|
||||
"name" : "viewer",
|
||||
"path" : "/viewer",
|
||||
"realmRoles" : [ "tornjak-viewer-realm-role" ]
|
||||
} ],
|
||||
"users" : [ {
|
||||
"username" : "admin",
|
||||
"enabled" : true,
|
||||
"firstName" : "Admin",
|
||||
"lastName" : "User",
|
||||
"credentials" : [ {
|
||||
"type" : "password",
|
||||
"userLabel" : "My password",
|
||||
"secretData" : "{\"value\":\"Y1Kcmx/XxLWtnRLyMy/zn6wWbfu2fSKdaefrXM50cva3P+kA2BqBDvTZDswGP6JZ+IWrJaitm8RKV0L9LiwaFQ==\",\"salt\":\"Mh5g1EgTo26xhzoj67bovA==\",\"additionalParameters\":{}}",
|
||||
"credentialData" : "{\"hashIterations\":27500,\"algorithm\":\"pbkdf2-sha256\",\"additionalParameters\":{}}"
|
||||
} ],
|
||||
"groups" : [ "/admin" ]
|
||||
}, {
|
||||
"username" : "viewer",
|
||||
"enabled" : true,
|
||||
"firstName" : "Viewer",
|
||||
"lastName" : "User",
|
||||
"credentials" : [ {
|
||||
"type" : "password",
|
||||
"userLabel" : "My password",
|
||||
"secretData" : "{\"value\":\"1ow3LfLDvpBRLfRbr2LtFRqje8NsKouHMw95Wwpsg5NP2Pga4ZBL7+T62bCDV6dOvy3U9xEEU4CRkhSWFaeDLg==\",\"salt\":\"qML2gBVSG7xYRZcaffW68A==\",\"additionalParameters\":{}}",
|
||||
"credentialData" : "{\"hashIterations\":27500,\"algorithm\":\"pbkdf2-sha256\",\"additionalParameters\":{}}"
|
||||
} ],
|
||||
"groups" : [ "/viewer" ]
|
||||
} ],
|
||||
"clients" : [ {
|
||||
"clientId" : "tornjak",
|
||||
"name" : "Tornjak",
|
||||
"enabled" : true,
|
||||
"alwaysDisplayInConsole" : true,
|
||||
"clientAuthenticatorType" : "client-secret",
|
||||
"redirectUris" : [ "http://localhost:3000/*" ],
|
||||
"webOrigins" : [ "*" ],
|
||||
"standardFlowEnabled" : true,
|
||||
"implicitFlowEnabled" : false,
|
||||
"directAccessGrantsEnabled" : false,
|
||||
"serviceAccountsEnabled" : false,
|
||||
"publicClient" : true,
|
||||
"frontchannelLogout" : true,
|
||||
"protocol" : "openid-connect",
|
||||
"attributes" : {
|
||||
"post.logout.redirect.uris" : "http://localhost:3000/*"
|
||||
},
|
||||
"fullScopeAllowed" : true,
|
||||
"defaultClientScopes": [
|
||||
"role_list",
|
||||
"profile",
|
||||
"email",
|
||||
"roles",
|
||||
"web-origins",
|
||||
"acr",
|
||||
"tornjak-backend",
|
||||
]
|
||||
}],
|
||||
"clientScopes": [{
|
||||
"name": "tornjak-backend",
|
||||
"description": "tornjak backend audience check",
|
||||
"protocol": "openid-connect",
|
||||
"attributes": {
|
||||
"include.in.token.scope": "false",
|
||||
"display.on.consent.screen": "false",
|
||||
"gui.order": "",
|
||||
"consent.screen.text": ""
|
||||
},
|
||||
"protocolMappers": [{
|
||||
"name": "tornjak-backend",
|
||||
"protocol": "openid-connect",
|
||||
"protocolMapper": "oidc-audience-mapper",
|
||||
"consentRequired": false,
|
||||
"config": {
|
||||
"introspection.token.claim": "true",
|
||||
"included.custom.audience": "tornjak-backend",
|
||||
"userinfo.token.claim": "false",
|
||||
"id.token.claim": "false",
|
||||
"lightweight.claim": "false",
|
||||
"access.token.claim": "true"
|
||||
}
|
||||
}]
|
||||
}]
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
spire-server:
|
||||
tornjak:
|
||||
config:
|
||||
## @extra tornjak.config.userManagement [object] UserManagement config
|
||||
userManagement:
|
||||
issuer: "http://keycloak:80/realms/tornjak"
|
||||
audience: "tornjak-backend"
|
||||
|
||||
tornjak-frontend:
|
||||
auth:
|
||||
enabled: true
|
||||
serverURL: http://localhost:8080/ # enable auth by providing url
|
||||
@@ -4,6 +4,7 @@ spire-server:
|
||||
|
||||
tornjak-frontend:
|
||||
enabled: true
|
||||
apiServerURL: "http://localhost:10000"
|
||||
service:
|
||||
type: ClusterIP
|
||||
port: 3000
|
||||
|
||||
Reference in New Issue
Block a user