Scalable User Authentication for Kubernetes Clusters with OpenID... Nathan Brahms & Shashwat Sehgal

  Рет қаралды 442

CNCF [Cloud Native Computing Foundation]

CNCF [Cloud Native Computing Foundation]

8 ай бұрын

Don't miss out! Join us at our next Flagship Conference: KubeCon + CloudNativeCon Europe in Paris from March 19-22, 2024. Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Scalable User Authentication for Kubernetes Clusters with OpenID Connector - Nathan Brahms & Shashwat Sehgal, P0 Security
Platform engineering teams face a challenge in managing developer access to Kubernetes clusters. Firstly, on the user provisioning side, the default client certificate based authentication strategy requires submitting signing requests for every user in every cluster. Secondly, a mapping of roles and role bindings must be defined inside each cluster. This talk evangelizes the Kubernetes built-in OpenID Connector and emphasizes how easy it is to move away from these defaults, and how automation can decrease the ongoing maintenance burden. The talk discusses configuring an OIDC authentication for Kubernetes clusters, and details of how to do that in each major cloud provider (AWS, Azure, Google) and identity provider (Azure AD, Google Workspace, Okta, Jumpcloud). Finally, it discusses how to set up developer access using the open-source kubelogin kubectl plugin. This approach works well in environments with a large number of clusters or Kubernetes deployments in multiple clouds.

Пікірлер
🦝 RBAC to the Future: Untangling Authorization in Kubernetes - Jimmy Mesta, KSOC
26:30
CNCF [Cloud Native Computing Foundation]
Рет қаралды 2,3 М.
OIDC and Workload Identity in Kubernetes - Ashutosh Kumar, Elastic & Anish Ramasekar, Microsoft
35:25
CNCF [Cloud Native Computing Foundation]
Рет қаралды 1,7 М.
One moment can change your life ✨🔄
00:32
A4
Рет қаралды 34 МЛН
A little girl was shy at her first ballet lesson #shorts
00:35
Fabiosa Animated
Рет қаралды 4,2 МЛН
Double Stacked Pizza @Lionfield @ChefRush
00:33
albert_cancook
Рет қаралды 81 МЛН
Splunk RUM Real User Monitoring with Shashwat Sehgal
29:24
Automation Testing with Joe Colantonio
Рет қаралды 557
Distributed Systems Wizardry by John A. De Goes
46:26
Durable Computing
Рет қаралды 977
Self-service Stream Processing Platform on Kubernetes at Apple - Chenya Zhang, Apple Inc.
33:03
CNCF [Cloud Native Computing Foundation]
Рет қаралды 739
OAuth 2.0 & OpenID Connect (OIDC): Technical Overview
16:19
VMware End-User Computing
Рет қаралды 153 М.
Single Sign-On for Kubernetes - Joel Speed, Pusher
34:28
CNCF [Cloud Native Computing Foundation]
Рет қаралды 11 М.
Kubernetes Explained in 15 Minutes | Hands On (2024 Edition)
15:18
Travis Media
Рет қаралды 71 М.
The cloud is over-engineered and overpriced (no music)
14:39
Tom Delalande
Рет қаралды 507 М.
Managing Access to Kubernetes with Keycloak
13:43
Engineering with Morris
Рет қаралды 3,2 М.
RBAC in Kubernetes
20:27
Pavan Elthepu
Рет қаралды 30 М.
1$ vs 500$ ВИРТУАЛЬНАЯ РЕАЛЬНОСТЬ !
23:20
GoldenBurst
Рет қаралды 1,9 МЛН
Battery  low 🔋 🪫
0:10
dednahype
Рет қаралды 13 МЛН
ОБСЛУЖИЛИ САМЫЙ ГРЯЗНЫЙ ПК
1:00
VA-PC
Рет қаралды 2,3 МЛН
Самый тонкий смартфон в мире!
0:55
Не шарю!
Рет қаралды 175 М.