{"id":415513,"date":"2024-06-30T00:24:49","date_gmt":"2024-06-30T00:24:49","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=415513"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=415513","title":{"rendered":"<span>About \u00abfree\u00bb #iam, #oidc, #saml, #etc<\/span>"},"content":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<p><strong>Reasons for writing this article<\/strong>: at the moment, an investigation is in progress, and some of the collected and tested information will be useful for others. Perhaps someone will add some tips. Thank you.<\/p>\n<p><strong>There is a solve task<\/strong> I need to solve:<\/p>\n<ul>\n<li>\n<p>Keeping users\/groups in the single directory.<\/p>\n<\/li>\n<li>\n<p>Control access, based on group memberships in directory:<\/p>\n<ul>\n<li>\n<p>Access control to web applications via #oidc\/#saml<\/p>\n<\/li>\n<li>\n<p>Access control to vanilla #Kubernetes<\/p>\n<\/li>\n<li>\n<p>SSH access control to bare-metal hosts &#8212; using SSH certificate technology if possible<\/p>\n<\/li>\n<li>\n<p>Authorize users to other server applications such as #Vault, #PostgreSQL, #Kafka, #ClickHouse, #MongoDB<\/p>\n<\/li>\n<li>\n<p>Being able to connect users from third-party organizations to certain resources based on group membership, etc<\/p>\n<\/li>\n<li>\n<p>Ensuring that everything described above works, including the bare metal environment<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>At first glance, many #open-source products\/technologies provide techniques, but the devil is in the details. This is the reason why businesses of the below-mentioned companies exist.<\/p>\n<p>I don&#8217;t see a big reason to pay for #teleport, #Okta, #JumpCloud, #OneLogin, and other commercial enterprise solutions at $15\/user\/month, considering our number of users. It&#8217;s not particularly relevant.<\/p>\n<p><strong>There are nuances<\/strong>:<\/p>\n<ol>\n<li>\n<p>Azure AD &#8212; In #OIDC scopes issues, only group object IDs are provided, which is not very convenient to manage, regardless of whether it&#8217;s Kubernetes RBAC or something else.<\/p>\n<\/li>\n<li>\n<p>Google Workshop does not know how to give information about groups in OIDC at all<\/p>\n<\/li>\n<\/ol>\n<p><strong>The original idea was to use #keycloak as an aggregator, but it was dropped due to the following reasons<\/strong>:<\/p>\n<p>1. There are no free, productive quality SSH authorization solutions without LDAP. With LDAP &#8212; everything is okay &#8212; #sssd<\/p>\n<p>2. Free IAM solutions OIDC\/SAML:<\/p>\n<ul>\n<li>\n<p>Only Dex can work normally with group resolving from Azure &amp; Google<\/p>\n<\/li>\n<li>\n<p>Keycloak with varying success (<em>you will have to manually copy the Azure AD object group IDs with mappers<\/em>), for Google workplace exists a module for Google groups mapping (<a href=\"https:\/\/github.com\/lunatech-labs\/lunatech-keycloak-google-groups-mapper\" rel=\"noopener noreferrer nofollow\">https:\/\/github.com\/lunatech-labs\/lunatech-keycloak-google-groups-mapper<\/a>)<\/p>\n<\/li>\n<\/ul>\n<p><em>3. Keycloak user federation nuances:<\/em><\/p>\n<ul>\n<li>\n<p>#keycloak works nicely with Azure LDAP, all users\/groups look like native<\/p>\n<\/li>\n<li>\n<p>#keycloak doesn&#8217;t work with Google LDAP because Google LDAP schema contains two (!!!) &#171;cn&#187; fields. #keycloak UI just dies:)<\/p>\n<\/li>\n<\/ul>\n<p>The following concept we are testing:<\/p>\n<ol>\n<li>\n<p>All users\/groups live in Azure AD.<\/p>\n<\/li>\n<li>\n<p>If necessary, external contractors can connect as additional iDPs to Azure External Identities.<\/p>\n<\/li>\n<li>\n<p>SSH access to hosts: #sssd via LDAP (Azure Domain Services).<\/p>\n<\/li>\n<li>\n<p>Vanilla Kubernetes (yes, our [c]rb will contain Azure Groups IDs), Vault will use Azure AD OIDC as iDP.<\/p>\n<\/li>\n<li>\n<p>#PostgreSQL, #ClickHouse, etc. will use PAM\/NSS from #sssd<\/p>\n<\/li>\n<\/ol>\n<p><strong>Notes<\/strong>:<\/p>\n<ol>\n<li>\n<p>Perhaps I will try #Dex at the top of IAM and find new moments<\/p>\n<\/li>\n<li>\n<p>I know about <a href=\"https:\/\/smallstep.com\/\" rel=\"noopener noreferrer nofollow\"><u>https:\/\/smallstep.com<\/u><\/a>. I&#8217;m playing with that. Hopefully, I will replace SSSD with it.<\/p>\n<\/li>\n<li>\n<p>It seems that #rancher works with any combination of #OIDC, #SAML, #Azure, #GoogleWorkspace, and controls RBAC in a good UI. I will test it.<\/p>\n<\/li>\n<\/ol>\n<p>The article will be updated as soon as the solution is finalized, tested, etc.<\/p>\n<p>Tips and criticism are always welcome!<\/p>\n<p>thank you!<\/p>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><!----><!----><\/div>\n<p><!----><\/p>\n<div class=\"tm-article-poll-container\"><!--[--><\/p>\n<div class=\"tm-article-poll tm-article-poll_variant-bordered\">\n<div class=\"tm-notice tm-notice_positive tm-article-poll__notice\"><!----><\/p>\n<div class=\"tm-notice__inner\"><!----><\/p>\n<div class=\"tm-notice__content\" data-test-id=\"notice-content\"><!--[--><span>\u0422\u043e\u043b\u044c\u043a\u043e \u0437\u0430\u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043c\u043e\u0433\u0443\u0442 \u0443\u0447\u0430\u0441\u0442\u0432\u043e\u0432\u0430\u0442\u044c \u0432 \u043e\u043f\u0440\u043e\u0441\u0435. <a rel=\"nofollow\" href=\"\/kek\/v1\/auth\/habrahabr\/?back=\/ru\/articles\/724162\/&#038;hl=ru\">\u0412\u043e\u0439\u0434\u0438\u0442\u0435<\/a>, \u043f\u043e\u0436\u0430\u043b\u0443\u0439\u0441\u0442\u0430.<\/span><!--]--><\/div>\n<\/div>\n<\/div>\n<p><!--[--><\/p>\n<div class=\"tm-article-poll__header\">Are you interested that topic?<\/div>\n<div class=\"tm-article-poll__answers\"><!--[--><\/p>\n<div class=\"tm-article-poll__answer\">\n<div class=\"tm-article-poll__answer-data\"><span class=\"tm-article-poll__answer-percent tm-article-poll__answer-percent_winning\">100% <\/span><span class=\"tm-article-poll__answer-label\">yes, continue to improve the article<\/span><span class=\"tm-article-poll__answer-votes\">3<\/span><\/div>\n<div class=\"tm-article-poll__answer-bar\">\n<div class=\"tm-article-poll__answer-progress tm-article-poll__answer-progress_winning\" style=\"width: 100%\"><\/div>\n<\/div>\n<\/div>\n<div class=\"tm-article-poll__answer\">\n<div class=\"tm-article-poll__answer-data\"><span class=\"tm-article-poll__answer-percent\">0% <\/span><span class=\"tm-article-poll__answer-label\">yes<\/span><span class=\"tm-article-poll__answer-votes\">0<\/span><\/div>\n<div class=\"tm-article-poll__answer-bar\">\n<div class=\"tm-article-poll__answer-progress\" style=\"width: 0%\"><\/div>\n<\/div>\n<\/div>\n<div class=\"tm-article-poll__answer\">\n<div class=\"tm-article-poll__answer-data\"><span class=\"tm-article-poll__answer-percent\">0% <\/span><span class=\"tm-article-poll__answer-label\">no<\/span><span class=\"tm-article-poll__answer-votes\">0<\/span><\/div>\n<div class=\"tm-article-poll__answer-bar\">\n<div class=\"tm-article-poll__answer-progress\" style=\"width: 0%\"><\/div>\n<\/div>\n<\/div>\n<p><!--]--><\/div>\n<div class=\"tm-article-poll__stats\"> \u041f\u0440\u043e\u0433\u043e\u043b\u043e\u0441\u043e\u0432\u0430\u043b\u0438 3 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f.    \u0412\u043e\u0437\u0434\u0435\u0440\u0436\u0430\u0432\u0448\u0438\u0445\u0441\u044f \u043d\u0435\u0442. <\/div>\n<p><!--]--><\/div>\n<p><!--]--><\/div>\n<p> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/articles\/724162\/\"> https:\/\/habr.com\/ru\/articles\/724162\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<p><strong>Reasons for writing this article<\/strong>: at the moment, an investigation is in progress, and some of the collected and tested information will be useful for others. Perhaps someone will add some tips. Thank you.<\/p>\n<p><strong>There is a solve task<\/strong> I need to solve:<\/p>\n<ul>\n<li>\n<p>Keeping users\/groups in the single directory.<\/p>\n<\/li>\n<li>\n<p>Control access, based on group memberships in directory:<\/p>\n<ul>\n<li>\n<p>Access control to web applications via #oidc\/#saml<\/p>\n<\/li>\n<li>\n<p>Access control to vanilla #Kubernetes<\/p>\n<\/li>\n<li>\n<p>SSH access control to bare-metal hosts &#8212; using SSH certificate technology if possible<\/p>\n<\/li>\n<li>\n<p>Authorize users to other server applications such as #Vault, #PostgreSQL, #Kafka, #ClickHouse, #MongoDB<\/p>\n<\/li>\n<li>\n<p>Being able to connect users from third-party organizations to certain resources based on group membership, etc<\/p>\n<\/li>\n<li>\n<p>Ensuring that everything described above works, including the bare metal environment<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>At first glance, many #open-source products\/technologies provide techniques, but the devil is in the details. This is the reason why businesses of the below-mentioned companies exist.<\/p>\n<p>I don&#8217;t see a big reason to pay for #teleport, #Okta, #JumpCloud, #OneLogin, and other commercial enterprise solutions at $15\/user\/month, considering our number of users. It&#8217;s not particularly relevant.<\/p>\n<p><strong>There are nuances<\/strong>:<\/p>\n<ol>\n<li>\n<p>Azure AD &#8212; In #OIDC scopes issues, only group object IDs are provided, which is not very convenient to manage, regardless of whether it&#8217;s Kubernetes RBAC or something else.<\/p>\n<\/li>\n<li>\n<p>Google Workshop does not know how to give information about groups in OIDC at all<\/p>\n<\/li>\n<\/ol>\n<p><strong>The original idea was to use #keycloak as an aggregator, but it was dropped due to the following reasons<\/strong>:<\/p>\n<p>1. There are no free, productive quality SSH authorization solutions without LDAP. With LDAP &#8212; everything is okay &#8212; #sssd<\/p>\n<p>2. Free IAM solutions OIDC\/SAML:<\/p>\n<ul>\n<li>\n<p>Only Dex can work normally with group resolving from Azure &amp; Google<\/p>\n<\/li>\n<li>\n<p>Keycloak with varying success (<em>you will have to manually copy the Azure AD object group IDs with mappers<\/em>), for Google workplace exists a module for Google groups mapping (<a href=\"https:\/\/github.com\/lunatech-labs\/lunatech-keycloak-google-groups-mapper\" rel=\"noopener noreferrer nofollow\">https:\/\/github.com\/lunatech-labs\/lunatech-keycloak-google-groups-mapper<\/a>)<\/p>\n<\/li>\n<\/ul>\n<p><em>3. Keycloak user federation nuances:<\/em><\/p>\n<ul>\n<li>\n<p>#keycloak works nicely with Azure LDAP, all users\/groups look like native<\/p>\n<\/li>\n<li>\n<p>#keycloak doesn&#8217;t work with Google LDAP because Google LDAP schema contains two (!!!) &#171;cn&#187; fields. #keycloak UI just dies:)<\/p>\n<\/li>\n<\/ul>\n<p>The following concept we are testing:<\/p>\n<ol>\n<li>\n<p>All users\/groups live in Azure AD.<\/p>\n<\/li>\n<li>\n<p>If necessary, external contractors can connect as additional iDPs to Azure External Identities.<\/p>\n<\/li>\n<li>\n<p>SSH access to hosts: #sssd via LDAP (Azure Domain Services).<\/p>\n<\/li>\n<li>\n<p>Vanilla Kubernetes (yes, our [c]rb will contain Azure Groups IDs), Vault will use Azure AD OIDC as iDP.<\/p>\n<\/li>\n<li>\n<p>#PostgreSQL, #ClickHouse, etc. will use PAM\/NSS from #sssd<\/p>\n<\/li>\n<\/ol>\n<p><strong>Notes<\/strong>:<\/p>\n<ol>\n<li>\n<p>Perhaps I will try #Dex at the top of IAM and find new moments<\/p>\n<\/li>\n<li>\n<p>I know about <a href=\"https:\/\/smallstep.com\/\" rel=\"noopener noreferrer nofollow\"><u>https:\/\/smallstep.com<\/u><\/a>. I&#8217;m playing with that. Hopefully, I will replace SSSD with it.<\/p>\n<\/li>\n<li>\n<p>It seems that #rancher works with any combination of #OIDC, #SAML, #Azure, #GoogleWorkspace, and controls RBAC in a good UI. I will test it.<\/p>\n<\/li>\n<\/ol>\n<p>The article will be updated as soon as the solution is finalized, tested, etc.<\/p>\n<p>Tips and criticism are always welcome!<\/p>\n<p>thank you!<\/p>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><!----><!----><\/div>\n<p><!----><\/p>\n<div class=\"tm-article-poll-container\"><!--[--><\/p>\n<div class=\"tm-article-poll tm-article-poll_variant-bordered\">\n<div class=\"tm-notice tm-notice_positive tm-article-poll__notice\"><!----><\/p>\n<div class=\"tm-notice__inner\"><!----><\/p>\n<div class=\"tm-notice__content\" data-test-id=\"notice-content\"><!--[--><span>\u0422\u043e\u043b\u044c\u043a\u043e \u0437\u0430\u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043c\u043e\u0433\u0443\u0442 \u0443\u0447\u0430\u0441\u0442\u0432\u043e\u0432\u0430\u0442\u044c \u0432 \u043e\u043f\u0440\u043e\u0441\u0435. <a rel=\"nofollow\" href=\"\/kek\/v1\/auth\/habrahabr\/?back=\/ru\/articles\/724162\/&#038;hl=ru\">\u0412\u043e\u0439\u0434\u0438\u0442\u0435<\/a>, \u043f\u043e\u0436\u0430\u043b\u0443\u0439\u0441\u0442\u0430.<\/span><!--]--><\/div>\n<\/div>\n<\/div>\n<p><!--[--><\/p>\n<div class=\"tm-article-poll__header\">Are you interested that topic?<\/div>\n<div class=\"tm-article-poll__answers\"><!--[--><\/p>\n<div class=\"tm-article-poll__answer\">\n<div class=\"tm-article-poll__answer-data\"><span class=\"tm-article-poll__answer-percent tm-article-poll__answer-percent_winning\">100% <\/span><span class=\"tm-article-poll__answer-label\">yes, continue to improve the article<\/span><span class=\"tm-article-poll__answer-votes\">3<\/span><\/div>\n<div class=\"tm-article-poll__answer-bar\">\n<div class=\"tm-article-poll__answer-progress tm-article-poll__answer-progress_winning\" style=\"width: 100%\"><\/div>\n<\/div>\n<\/div>\n<div class=\"tm-article-poll__answer\">\n<div class=\"tm-article-poll__answer-data\"><span class=\"tm-article-poll__answer-percent\">0% <\/span><span class=\"tm-article-poll__answer-label\">yes<\/span><span class=\"tm-article-poll__answer-votes\">0<\/span><\/div>\n<div class=\"tm-article-poll__answer-bar\">\n<div class=\"tm-article-poll__answer-progress\" style=\"width: 0%\"><\/div>\n<\/div>\n<\/div>\n<div class=\"tm-article-poll__answer\">\n<div class=\"tm-article-poll__answer-data\"><span class=\"tm-article-poll__answer-percent\">0% <\/span><span class=\"tm-article-poll__answer-label\">no<\/span><span class=\"tm-article-poll__answer-votes\">0<\/span><\/div>\n<div class=\"tm-article-poll__answer-bar\">\n<div class=\"tm-article-poll__answer-progress\" style=\"width: 0%\"><\/div>\n<\/div>\n<\/div>\n<p><!--]--><\/div>\n<div class=\"tm-article-poll__stats\"> \u041f\u0440\u043e\u0433\u043e\u043b\u043e\u0441\u043e\u0432\u0430\u043b\u0438 3 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f.    \u0412\u043e\u0437\u0434\u0435\u0440\u0436\u0430\u0432\u0448\u0438\u0445\u0441\u044f \u043d\u0435\u0442. <\/div>\n<p><!--]--><\/div>\n<p><!--]--><\/div>\n<p> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/articles\/724162\/\"> https:\/\/habr.com\/ru\/articles\/724162\/<\/a><br \/><\/br><\/br><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-415513","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/415513","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=415513"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/415513\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=415513"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=415513"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=415513"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}