Add auth option for Tornjak (#259)

* Added auth option, specifically keycloak for tornjak production use

Signed-off-by: Mohammed Abdi <[email protected]>

* Added auth values for tornjak

Signed-off-by: Mohammed Abdi <[email protected]>

* Update charts/spire/charts/tornjak-frontend/values.yaml

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* Update examples/tornjak/keycloak/README.md

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* Update examples/tornjak/keycloak/README.md

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* Update examples/tornjak/keycloak/README.md

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* Update examples/tornjak/keycloak/README.md

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* Update examples/tornjak/keycloak/README.md

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* Update examples/tornjak/keycloak/README.md

Co-authored-by: Faisal Memon <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* nit

Signed-off-by: Mohammed Abdi <[email protected]>

* nit

Signed-off-by: Mohammed Abdi <[email protected]>

* nit

Signed-off-by: Mohammed Abdi <[email protected]>

* Update examples/tornjak/keycloak/README.md

Co-authored-by: Mariusz Sabath <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>

* nit

Signed-off-by: Mohammed Abdi <[email protected]>

* install keycloak first

Signed-off-by: Mohammed Abdi <[email protected]>

* add logs volume back

Signed-off-by: Mohammed Abdi <[email protected]>

* Fixed NPM init error

Signed-off-by: Mariusz Sabath <[email protected]>

* Fixed the values documentation errors

Signed-off-by: Mariusz Sabath <[email protected]>

* Post-review suggestion fixes

Signed-off-by: Mariusz Sabath <[email protected]>

* Fixed typo

Signed-off-by: Mariusz Sabath <[email protected]>

* Updating Keyclaok examples README

Signed-off-by: Mariusz Sabath <[email protected]>

* Fixed the parameter reference

Signed-off-by: Mariusz Sabath <[email protected]>

* Fix typo

Signed-off-by: Mariusz Sabath <[email protected]>

* use keycloak-config-cli to simplify tornjak realm import

Signed-off-by: MohammedAbdi <[email protected]>

* edit client id

Signed-off-by: MohammedAbdi <[email protected]>

* reverse client id

Signed-off-by: MohammedAbdi <[email protected]>

* fix the doc

Signed-off-by: Mariusz Sabath <[email protected]>

* update tornjak version and backend auth

Signed-off-by: MohammedAbdi <[email protected]>

* update client id

Signed-off-by: MohammedAbdi <[email protected]>

* updates values yaml

Signed-off-by: MohammedAbdi <[email protected]>

* update documentation

Signed-off-by: MohammedAbdi <[email protected]>

* nit

Signed-off-by: MohammedAbdi <[email protected]>

* update doc

Signed-off-by: MohammedAbdi <[email protected]>

* add audience check tornjak

Signed-off-by: MohammedAbdi <[email protected]>

* remove unused file

Signed-off-by: MohammedAbdi <[email protected]>

* update doc

Signed-off-by: MohammedAbdi <[email protected]>

* nit and add auth not enabled warning back

Signed-off-by: MohammedAbdi <[email protected]>

* adjust liveness probe until tornjak handles liveendpoint for auth and direct connection to discovery

Signed-off-by: MohammedAbdi <[email protected]>

* update doc and add keycloak proxy

Signed-off-by: MohammedAbdi <[email protected]>

---------

Signed-off-by: Mohammed Abdi <[email protected]>
Signed-off-by: Mohammed Abdi <[email protected]>
Signed-off-by: Mariusz Sabath <[email protected]>
Signed-off-by: MohammedAbdi <[email protected]>
Co-authored-by: Mohammed Abdi <[email protected]>
Co-authored-by: Faisal Memon <[email protected]>
Co-authored-by: Mariusz Sabath <[email protected]>
This commit is contained in:
Mohammed Abdi
2024-04-25 15:49:20 -07:00
committed by GitHub
co-authored by Faisal Memon Mariusz Sabath Mohammed Abdi
parent f679a0dab6
commit a2494ee45e
15 changed files with 360 additions and 71 deletions
+2 -6
View File
@@ -1,8 +1,5 @@
# Recommended setup to deploy Tornjak
> [!Warning]
> The current version of Tornjak in this chart is deployed without authentication. Therefore it is not suitable to run this version in production.
To install Spire with the least privileges possible we deploy spire across 2 namespaces.
```shell
@@ -13,7 +10,7 @@ kubectl label namespace "spire-server" pod-security.kubernetes.io/enforce=restri
# deploy SPIRE with Tornjak enabled
helm upgrade --install --namespace spire-server spire charts/spire \
--values examples/production/values.yaml \
--values tests/integration/psat/values.yaml \
--values examples/tornjak/values.yaml \
--render-subchart-notes
@@ -48,11 +45,10 @@ Update examples/production/example-your-values.yaml with your information, most
```shell
helm upgrade --install --namespace spire-server spire charts/spire \
--values examples/production/values.yaml \
--values tests/integration/psat/values.yaml \
--values examples/tornjak/values.yaml \
--values examples/tornjak/values-ingress.yaml \
--set global.spire.ingressControllerType=ingress-nginx \
--values examples/production/example-your-values.yaml \
--render-subchart-notes --debug
```
+114
View File
@@ -0,0 +1,114 @@
# Deploy Tornjak with Authentication Enabled
This example demonstrates Tornjak's capability to control access to the Frontend Application using
User Management via [Keycloak](https://www.keycloak.org/).
Tested on:
- Keycloak Application Version - 24.0.3
- Keycloak Chart Version - 21.0.3
For more information regarding Tornjak User Management, please refer to the following documentation:
* [Tornjak User Management](https://github.com/spiffe/tornjak/blob/main/docs/keycloak-configuration.md)
* [Keycloak Configuration for Tornjak](https://github.com/spiffe/tornjak/blob/main/docs/keycloak-configuration.md)
* [Detailed Blogs on Tornjak User Management](https://github.com/spiffe/tornjak/blob/main/docs/blogs.md)
**NOTE:** This example works only with the Vanilla version of Kubernetes; it does not yet support Openshift.
As part of the exercise, an instance of Keycloak is deployed to illustrate how to manage users' access to Tornjak.
Once enabled, the Tornjak UI will redirect all authentication calls to the Keycloak instance to obtain the
correct credentials. Authorization is based on these credentials and occurs at the Tornjak application level.
## Deploy Keycloak Instance (Authentication Service)
We will deploy the instance of Keycloak in the same namespace as the SPIRE Server
```shell
# Create a namespace to deploy Keycloak and SPIRE-server
kubectl create namespace spire-server
```
```shell
# Deploy Keycloak as an authentication service
helm upgrade --install -n spire-server keycloak --values examples/tornjak/keycloak/values.yaml oci://registry-1.docker.io/bitnamicharts/keycloak --render-subchart-notes
```
* It's important to start the service before configuring Tornjak with auth.
```shell
# Start an auth Service [Keycloak] (Terminal 3)
kubectl -n spire-server port-forward service/keycloak 8080:80
```
## Deploy SPIRE with Tornjak User Management Enabled
Please follow the instructions for deploying Tornjak as specified in Tornjak Example [here](../README.md)
with addition of the User Management values `--values examples/tornjak/values-auth.yaml`.
For example:
```shell
# Install SPIRE CRDs
helm upgrade --install --create-namespace -n spire-mgmt spire-crds charts/spire-crds
```
```shell
# Standard SPIRE and Tornjak deployment with Authentication enabled
helm upgrade --install \
--set global.spire.namespaces.system.create=true \
--values tests/integration/psat/values.yaml \
--values examples/tornjak/values.yaml \
--values examples/tornjak/values-auth.yaml \
--render-subchart-notes spire charts/spire
```
To test the deployment, you can run the SPIRE test:
```shell
# Test the Tornjak deployment
helm test spire
```
## Access Tornjak
To access Tornjak use port-forwarding or check the ingress option below.
Run following commands from your shell, if you run with different values your namespace might differ. Consult the install notes printed when running above `helm upgrade` command in that case.
Since `port-forward` is a blocking command, execute them in three different consoles (one for backend, one for frontend and one for auth that you already started in the previous step):
```shell
# Start a backend Service (Terminal 1)
kubectl -n spire-server port-forward service/spire-tornjak-backend 10000:10000
```
```shell
# Start a frontend Service (Terminal 2)
kubectl -n spire-server port-forward service/spire-tornjak-frontend 3000:3000
```
* You can now access Tornjak at [localhost:3000](http://localhost:3000).
* This will redirect to the auth service for authentication to [localhost:8080](http://localhost:8080)
See [values.yaml](./values.yaml) for more details on the chart configurations to customize authentication config.
## Deploy SPIRE with Tornjak User Management Enabled using Ingress
When deployment uses Ingress, the access to Tornjak application and Keycloak will be different from above.
Please follow the deployment and configuration instructions as described [here](../README.md)
and make sure to add the `--values examples/tornjak/values-auth.yaml` parameter that is referencing Tornjak Authentication values.
And update your `examples/production/example-your-values.yaml` most importantly, `trustDomain`, accordingly.
E.g:
```shell
helm upgrade --install \
--set global.spire.namespaces.create=true \
--set global.spire.ingressControllerType=ingress-nginx \
--values tests/integration/psat/values.yaml \
--values examples/tornjak/values.yaml \
--values examples/tornjak/values-auth.yaml \
--values examples/tornjak/values-ingress.yaml \
--render-subchart-notes spire charts/spire
```
+128
View File
@@ -0,0 +1,128 @@
auth:
## @param keycloak.auth.realm Realm name in which to create users## @param auth.adminUser Keycloak administrator user
##
adminUser: admin
## @param auth.adminPassword Keycloak administrator password for the new user
##
adminPassword: admin
proxy: edge # for https proxy reverse mode
keycloakConfigCli:
enabled: true
configuration: # tornjak realm configuration
tornjak.json: |
{
"realm": "tornjak",
"enabled": true,
"roles" : {
"realm" : [ {
"name" : "tornjak-viewer-realm-role"
}, {
"name" : "tornjak-admin-realm-role"
} ],
"client" : {
"tornjak" : [ {
"name" : "viewer",
"composite" : true,
"composites" : {
"realm" : [ "tornjak-viewer-realm-role" ]
},
"clientRole" : true
}, {
"name" : "admin",
"composite" : true,
"composites" : {
"realm" : [ "tornjak-admin-realm-role" ]
},
"clientRole" : true
} ]
}
},
"groups" : [ {
"name" : "admin",
"path" : "/admin",
"realmRoles" : [ "tornjak-admin-realm-role" ]
}, {
"name" : "viewer",
"path" : "/viewer",
"realmRoles" : [ "tornjak-viewer-realm-role" ]
} ],
"users" : [ {
"username" : "admin",
"enabled" : true,
"firstName" : "Admin",
"lastName" : "User",
"credentials" : [ {
"type" : "password",
"userLabel" : "My password",
"secretData" : "{\"value\":\"Y1Kcmx/XxLWtnRLyMy/zn6wWbfu2fSKdaefrXM50cva3P+kA2BqBDvTZDswGP6JZ+IWrJaitm8RKV0L9LiwaFQ==\",\"salt\":\"Mh5g1EgTo26xhzoj67bovA==\",\"additionalParameters\":{}}",
"credentialData" : "{\"hashIterations\":27500,\"algorithm\":\"pbkdf2-sha256\",\"additionalParameters\":{}}"
} ],
"groups" : [ "/admin" ]
}, {
"username" : "viewer",
"enabled" : true,
"firstName" : "Viewer",
"lastName" : "User",
"credentials" : [ {
"type" : "password",
"userLabel" : "My password",
"secretData" : "{\"value\":\"1ow3LfLDvpBRLfRbr2LtFRqje8NsKouHMw95Wwpsg5NP2Pga4ZBL7+T62bCDV6dOvy3U9xEEU4CRkhSWFaeDLg==\",\"salt\":\"qML2gBVSG7xYRZcaffW68A==\",\"additionalParameters\":{}}",
"credentialData" : "{\"hashIterations\":27500,\"algorithm\":\"pbkdf2-sha256\",\"additionalParameters\":{}}"
} ],
"groups" : [ "/viewer" ]
} ],
"clients" : [ {
"clientId" : "tornjak",
"name" : "Tornjak",
"enabled" : true,
"alwaysDisplayInConsole" : true,
"clientAuthenticatorType" : "client-secret",
"redirectUris" : [ "http://localhost:3000/*" ],
"webOrigins" : [ "*" ],
"standardFlowEnabled" : true,
"implicitFlowEnabled" : false,
"directAccessGrantsEnabled" : false,
"serviceAccountsEnabled" : false,
"publicClient" : true,
"frontchannelLogout" : true,
"protocol" : "openid-connect",
"attributes" : {
"post.logout.redirect.uris" : "http://localhost:3000/*"
},
"fullScopeAllowed" : true,
"defaultClientScopes": [
"role_list",
"profile",
"email",
"roles",
"web-origins",
"acr",
"tornjak-backend",
]
}],
"clientScopes": [{
"name": "tornjak-backend",
"description": "tornjak backend audience check",
"protocol": "openid-connect",
"attributes": {
"include.in.token.scope": "false",
"display.on.consent.screen": "false",
"gui.order": "",
"consent.screen.text": ""
},
"protocolMappers": [{
"name": "tornjak-backend",
"protocol": "openid-connect",
"protocolMapper": "oidc-audience-mapper",
"consentRequired": false,
"config": {
"introspection.token.claim": "true",
"included.custom.audience": "tornjak-backend",
"userinfo.token.claim": "false",
"id.token.claim": "false",
"lightweight.claim": "false",
"access.token.claim": "true"
}
}]
}]
}
+12
View File
@@ -0,0 +1,12 @@
spire-server:
tornjak:
config:
## @extra tornjak.config.userManagement [object] UserManagement config
userManagement:
issuer: "http://keycloak:80/realms/tornjak"
audience: "tornjak-backend"
tornjak-frontend:
auth:
enabled: true
serverURL: http://localhost:8080/ # enable auth by providing url
+1
View File
@@ -4,6 +4,7 @@ spire-server:
tornjak-frontend:
enabled: true
apiServerURL: "http://localhost:10000"
service:
type: ClusterIP
port: 3000