* Update Tornjak deployment docs Signed-off-by: Mariusz Sabath <[email protected]> * Change the reference for installing standard Tornjak Signed-off-by: Mariusz Sabath <[email protected]> * Update examples/tornjak/README.md Co-authored-by: kfox1111 <[email protected]> Signed-off-by: Mariusz Sabath <[email protected]> * Adjust deployment paths Signed-off-by: Mariusz Sabath <[email protected]> * Remove the production README changes Signed-off-by: Mariusz Sabath <[email protected]> * Minor text edits Signed-off-by: Mariusz Sabath <[email protected]> * Fix incorrect namespace value Signed-off-by: Mariusz Sabath <[email protected]> * Updat Tornjak README Signed-off-by: Mariusz Sabath <[email protected]> * Update Keycloak README Signed-off-by: Mariusz Sabath <[email protected]> * Text updates in Keycloak doc Signed-off-by: Mariusz Sabath <[email protected]> * Post-review updates Signed-off-by: Mariusz Sabath <[email protected]> * Update Tornjak message for User Management Signed-off-by: Mariusz Sabath <[email protected]> * Update examples/tornjak/keycloak/README.md Co-authored-by: Mohammed Abdi <[email protected]> Signed-off-by: Mariusz Sabath <[email protected]> * Update Tornjak deployment doc Signed-off-by: Mariusz Sabath <[email protected]> * Improve the Tornjak Auth message Signed-off-by: Mariusz Sabath <[email protected]> * Fix error with incorrect Ingress value Signed-off-by: Mariusz Sabath <[email protected]> * Fix documentation format Signed-off-by: Mariusz Sabath <[email protected]> * Update parameter format Signed-off-by: Mariusz Sabath <[email protected]> * Removed redundand doc sections Signed-off-by: Mariusz Sabath <[email protected]> --------- Signed-off-by: Mariusz Sabath <[email protected]> Co-authored-by: kfox1111 <[email protected]> Co-authored-by: Mohammed Abdi <[email protected]>
Deploy Tornjak with Authentication Enabled
This example demonstrates Tornjak's capability to control access to the Frontend Application using User Management via Keycloak.
Tested on:
- Keycloak Application Version - 24.0.3
- Keycloak Chart Version - 21.0.3
For more information regarding Tornjak User Management, please refer to the following documentation:
- Tornjak User Management
- Keycloak Configuration for Tornjak
- Detailed Blogs on Tornjak User Management
Note
This example works only with the Vanilla version of Kubernetes; it does not yet support Openshift.
As part of the exercise, an instance of Keycloak is deployed to illustrate how to manage users' access to Tornjak. Once enabled, the Tornjak UI will redirect all authentication calls to the Keycloak instance to obtain the correct credentials. Authorization is based on these credentials and occurs at the Tornjak application level.
Deploy Keycloak Instance (Authentication Service)
We will deploy the instance of Keycloak in a dedicated namespace
# If does not exist, create a namespace to deploy Keycloak
kubectl create namespace keycloak
Important
The example uses default userid and password (
admin,admin). You must change these values by settingauth.adminUserandauth.adminPasswordas shown below.
# Deploy most recent Keycloak instance as an authentication service
helm upgrade --install -n keycloak keycloak \
--values examples/tornjak/keycloak/values.yaml \
--set auth.adminUser=your-userid --set auth.adminPassword=your-password \
oci://registry-1.docker.io/bitnamicharts/keycloak --render-subchart-notes
Important
It is important to start the Tornjak service before starting Tornjak with authentication
The example below demonstrates port forward for local access. In cloud deployment scenario, enable Ingress to the Keycloak service accordingly.
# Start an auth Service [Keycloak] in separate terminal
kubectl -n keycloak port-forward service/keycloak 8080:80
See the helm Notes for more information about accessing Keycloak
Deploy SPIRE with Tornjak User Management Enabled
Please follow the instructions for deploying Tornjak
with addition of the User Management values --values examples/tornjak/values-auth.yaml.
Important
Make sure Tornjak backend User Management issuer points to the correct Keycloak issuer URL. Which is in format
http://<your-keycloakServicename>.<keycloak-namespace>:<your-keycloak-portnumber>/realms/tornjak. For the example above it will be:http://keycloak.keycloak:8080/realms/tornjakYou can set the issuer URL using--set spire-server.tornjak.config.userManagement.issuer=http://tornjak.tornjak:8080/realms/tornjak[!IMPORTANT] If audience is set, make sure the Tornjak backend
audienceis set correctly. You can set it using:--set spire-server.tornjak.config.userManagement.audience=your-audience[!TIP] Keep in mind, when redeploying Tornjak, you might have to recreate port forwarding for that service.
The sample examples/tornjak/values-auth.yaml assumes local Keycloak deployment using port forwarding. When using Ingress, update the URLs accordingly.
Access Tornjak
Follow the standard steps for Accessing Tornjak