29a900226d
* add new directive in the global scope `certificates_directory` which is used to bulk load certs and trust them in Authelia * this is in ADDITION to system certs and are trusted by both LDAP and SMTP * added a shared TLSConfig struct to be used by both SMTP and LDAP, and anything else in the future that requires tuning the TLS * remove usage of deprecated LDAP funcs Dial and DialTLS in favor of DialURL which is also easier to use * use the server name from LDAP URL or SMTP host when validating the certificate unless otherwise defined in the TLS section * added temporary translations from the old names to the new ones for all deprecated options * added docs * updated example configuration * final deprecations to be done in 4.28.0 * doc updates * fix misc linting issues * uniform deprecation notices for ease of final removal * added additional tests covering previously uncovered areas and the new configuration options * add non-fatal to certificate loading when system certs could not be loaded * adjust timeout of Suite ShortTimeouts * add warnings pusher for the StructValidator * make the schema suites uninform * utilize the warnings in the StructValidator * fix test suite usage for skip_verify * extract LDAP filter parsing into it's own function to make it possible to test * test LDAP filter parsing * update ErrorContainer interface * add tests to the StructValidator * add NewTLSConfig test * move baseDN for users/groups into parsed values * add tests to cover many of the outstanding areas in LDAP * add explicit deferred LDAP conn close to UpdatePassword * add some basic testing to SMTP notifier * suggestions from code review |
||
---|---|---|
.. | ||
apps | ||
authelia | ||
ingress-controller | ||
ldap | ||
storage | ||
bootstrap-authelia.sh | ||
bootstrap-dashboard.sh | ||
bootstrap.sh | ||
dashboard.yml | ||
namespace.yml | ||
README.md | ||
test.yml |
Authelia on Kubernetes
Authelia is now available on Kube in order to protect your most critical applications using 2-factor authentication and Single Sign-On.
This example leverages ingress-nginx to delegate authentication and authorization to Authelia within the cluster.
Getting started
You can either try to install Authelia on your running instance of Kubernetes or deploy the dedicated suite called kubernetes.
Set up a Kube cluster
The simplest way to start a Kubernetes cluster is to deploy the kubernetes suite with
authelia-scripts suites setup kubernetes
This will take a few seconds (or minutes) to deploy the cluster.
How does it work?
Authentication via Authelia
In a Kube clusters, the routing logic of requests is handled by ingress controllers following rules provided by ingress configurations.
In this example, ingress-nginx controller has been installed to handle the incoming requests. Some of them (specified in the ingress configuration) are forwarded to Authelia so that it can verify whether they are allowed and should reach the protected endpoint.
The authentication is provided at the ingress level by an annotation called
nginx.ingress.kubernetes.io/auth-url
that is filled with the URL of
Authelia's verification endpoint.
The ingress controller also requires the URL to the
authentication portal so that the user can be redirected if he is not
yet authenticated. This annotation is as follows:
nginx.ingress.kubernetes.io/auth-signin: "https://login.example.com:8080/"
Those annotations can be seen in apps/apps.yml
configuration.
Production grade infrastructure
What is great with using ingress-nginx is that it is compatible with kube-lego which removes the usual pain of manually renewing SSL certificates. It uses letsencrypt to issue and renew certificates every three month without any manual intervention.
What do I need to know to deploy it in my cluster?
Given your cluster already runs a LDAP server, a Redis, a SQL database, a SMTP server and a nginx ingress-controller, you can deploy Authelia and update your ingress configurations. An example is provided here.
Questions
If you have questions about the implementation, please post them on