ove*_*nge 5 go google-authentication gcloud kubectl google-anthos
kind:ClientConfig存储在.kube/configyaml 中,如下所示:
kind: ClientConfig
apiVersion: authentication.gke.io/v2alpha1
spec:
name: dev-corp
server: https://10.x.x.x:443
certificateAuthorityData: ccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc
authentication:
- name: oidc
oidc:
clientID: aaaaad3-9aa1-33c8-dd0-ddddd6b5bf5
clientSecret: ccccccccccccccccc-
issuerURI: https://login.microsoftonline.com/aaaa92-aab7-bbfa-cccf-ddaaaaaaaa/v2.0
kubectlRedirectURI: http://localhost:12345/callback
cloudConsoleRedirectURI: http://console.cloud.google.com/kubernetes/oidc
scopes: offline_access,profile
userClaim: upn
userPrefix: '-'
groupsClaim: groups
preferredAuthentication: oidc
Run Code Online (Sandbox Code Playgroud)
对于 kubectl,以上配置用作:
$ gcloud components install kubectl
All components are up to date.
$
$ kubectl oidc login --login-config ~/.kube/config --cluster dev-crop
Run Code Online (Sandbox Code Playgroud)
进行身份验证,然后与集群通信(如下所示):
kubectl get ns
Run Code Online (Sandbox Code Playgroud)
kubectl也是基于 GoLang 的工具,它能够加载配置--login-config然后进行身份验证。
$ kubectl version
Client Version: version.Info{Major:"1", Minor:"22+", GitVersion:"v1.22.12-dispatcher-dirty", GitCommit:"fde00375407ad0afadd681a3505054ec83f935ec", GitTreeState:"dirty", BuildDate:"2022-07-19T19:06:19Z", GoVersion:"go1.16.15", Compiler:"gc", Platform:"windows/amd64"}
Server Version: version.Info{Major:"1", Minor:"21", GitVersion:"v1.21.5-gke.1200", GitCommit:"90a16981ade07f163a0233adb631b42ac1fc53ff", GitTreeState:"clean", BuildDate:"2021-10-04T09:25:23Z", GoVersion:"go1.16.7b7", Compiler:"gc", Platform:"linux/amd64"}
Run Code Online (Sandbox Code Playgroud)
在我们的场景中,上述配置实际上存储在数据库(mongodb集合)中:
[
{
"apiVersion": "authentication.gke.io/v2alpha1",
"name": "dev-corp"
"server": "https://10.x.x.23:443"
"certificateAuthorityData": "ccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc"
"clientID": "aaaaad3-9aa1-33c8-dd0-ddddd6b5bf5"
"clientSecret": "ccccccccccccccccc-"
"issuerURI": "https://login.microsoftonline.com/aaaa92-aab7-bbfa-cccf-ddaaaaaaaa/v2.0"
"kubectlRedirectURI": "http://localhost:12345/callback"
"cloudConsoleRedirectURI": "http://console.cloud.google.com/kubernetes/oidc"
"scopes": "offline_access,profile"
"userClaim": "upn"
"userPrefix": "-"
"groupsClaim": "groups"
"preferredAuthentication": "oidc"
},
{
"apiVersion": "authentication.gke.io/v2alpha1",
"name": "test-corp"
"server": "https://10.x.x.24:443"
"certificateAuthorityData": "dddddddddddddddddddddddddfeeeeeeeeeeeeeeeeeeeeeeeeeeeccccccccccccccc"
"clientID": "bbbbb3-9aa1-33c8-dd0-ddddd6b5bf5"
"clientSecret": "eeeeecccccccccc-"
"issuerURI": "https://login.microsoftonline.com/aaaa92-aab7-bbfa-cccf-ddaaaaaaaa/v2.0"
"kubectlRedirectURI": "http://localhost:12345/callback"
"cloudConsoleRedirectURI": "http://console.cloud.google.com/kubernetes/oidc"
"scopes": "offline_access,profile"
"userClaim": "upn"
"userPrefix": "-"
"groupsClaim": "groups"
"preferredAuthentication": "oidc"
}
]
Run Code Online (Sandbox Code Playgroud)
将以上数据(来自 mongodb)加载到缓存中后(用户定义的结构如下所示):
type ClientConfig struct {
// ClientID is the application's ID.
ClientID string
// ClientSecret is the application's secret.
ClientSecret string
// Endpoint contains the resource server's token endpoint
// URLs. These are constants specific to each server and are
// often available via site-specific packages, such as
// google.Endpoint or github.Endpoint.
Endpoint Endpoint
// RedirectURL is the URL to redirect users going through
// the OAuth flow, after the resource owner's URLs.
RedirectURL string
// Scope specifies optional requested permissions.
Scopes []string
ApiVersion string
ServerName string // "dev-corp" in above case
ServerURL string // "https://10.x.x.24:443"
CertificateAuthorityData string
CloudConsoleRedirectURI string
UserClaim string
UserPrefix string
GroupsClaim string
PreferredAuthentication string
}
Run Code Online (Sandbox Code Playgroud)
kubectl能够使用--login-config选项加载此配置
如何从缓存加载配置并使用 kubernetes 集群(在谷歌云中)进行身份验证?目标是使用 kubernetes API 管理集群。oidc-auth-plugin不支持加载此配置。