docs/doc/source/security/kubernetes/configure-kubernetes-for-oidc-token-validation-after-bootstrapping-the-system.rst
Elaine Fonaro 0f57542f81 Updated OIDC service parameter names
- Added a note about historical service parameters for OIDC.

- Renamed the parameters to have dashes instead of underscores.

- Removed occurrences of "\" before "-".

Story: 2009766
Task: 46855

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: I47e5ab3c689184bdec20b39b2a00bf999ac5706a
2022-11-18 16:02:05 -03:00

2.8 KiB

Configure Kubernetes for OIDC Token Validation after Bootstrapping the System

You must configure the Kubernetes cluster's kube-apiserver to use the oidc-auth-apps identity provider for validation of tokens in Kubernetes API requests, which use authentication.

As an alternative to performing this configuration at bootstrap time as described in Configure Kubernetes for OIDC Token Validation while Bootstrapping the System <configure-kubernetes-for-oidc-token-validation-while-bootstrapping-the-system>, you can do so at any time using service parameters.

  1. Set the following service parameters using the system service-parameter-add kubernetes kube\_apiserver command.

    For example:

    ~(keystone_admin)]$ system service-parameter-add kubernetes kube_apiserver oidc-client-id=stx-oidc-client-app
    • oidc-client-id=<client>

      The value of this parameter may vary for different group configurations in your Windows Active Directory server.

    • oidc-groups-claim=<groups>

    • oidc-issuer-url=https://<oam-floating-ip>:<oidc-auth-apps-dex-service-NodePort>/dex

      Note

      For IPv6 deployments, ensure that the IPv6 OAM floating address is, https://\[<oam-floating-ip>]:30556/dex (that is, in lower case, and wrapped in square brackets).

    • oidc-username-claim=<email>

      The values of this parameter may vary for different user configurations in your Windows Active Directory server.

    The valid combinations of these service parameters are:

    • none of the parameters

    • oidc-issuer-url, oidc-client-id, and oidc-username-claim

    • oidc-issuer-url, oidc-client-id, oidc-username-claim, and oidc-groups-claim

      Note

      Historical service parameters for with underscores are still accepted: oidc_client_id, oidc_issuer_url, oidc_username_claim and oidc_groups_claim. These are equivalent to: oidc-client-id, oidc-issuer-url, oidc-username-claim and oidc-groups-claim.

  2. Apply the service parameters.

    ~(keystone_admin)]$ system service-parameter-apply kubernetes

    For more information on Authentication for subclouds, see Centralized OIDC Authentication Setup for Distributed Cloud <centralized-oidc-authentication-setup-for-distributed-cloud>.