-
Notifications
You must be signed in to change notification settings - Fork 204
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[2.9.0] 1373 support authentication with service account tokens #1402
[2.9.0] 1373 support authentication with service account tokens #1402
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I left some comments alongside edit suggestions.
...es/new-user-guides/authentication-permissions-and-global-configuration/jwt-authentication.md
Outdated
Show resolved
Hide resolved
...es/new-user-guides/authentication-permissions-and-global-configuration/jwt-authentication.md
Outdated
Show resolved
Hide resolved
...es/new-user-guides/authentication-permissions-and-global-configuration/jwt-authentication.md
Outdated
Show resolved
Hide resolved
...es/new-user-guides/authentication-permissions-and-global-configuration/jwt-authentication.md
Outdated
Show resolved
Hide resolved
Co-authored-by: Billy Tat <[email protected]>
Co-authored-by: Marty Hernandez Avedon <[email protected]>
@crobby @samjustus May you provide a review when you get the chance? Thanks! |
...es/new-user-guides/authentication-permissions-and-global-configuration/jwt-authentication.md
Outdated
Show resolved
Hide resolved
...es/new-user-guides/authentication-permissions-and-global-configuration/jwt-authentication.md
Outdated
Show resolved
Hide resolved
Co-authored-by: Billy Tat <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think this is good. Accurate and concise.
Fixes #1373
Reminders
See the README for more details on how to work with the Rancher docs.
Verify if changes pertain to other versions of Rancher. If they do, finalize the edits on one version of the page, then apply the edits to the other versions.
If the pull request is dependent on an upcoming release, remember to add a "MERGE ON RELEASE" label and set the proper milestone.
Description
From issue:
Ranchers auth proxy can now support authentication of requests that specify a Service Account token in the Authorization Bearer header.
More info/context:
JWT Authentication is also known as Service Account Token Authentication.
This feature, when enabled, lets a user set up a downstream cluster to support authentication, through Rancher, of tokens that are created for a service account that exists on a downstream cluster (those tokens are in the form of a JWT).
Prior to this feature, Rancher would reject such requests because Rancher would only support Rancher-issued tokens (which are NOT JTWs). Some users worked-around this limitation by issuing those requests directly to the downstream cluster, rather than relying on Rancher's auth/security. With this feature enabled, users no longer have to work-around Rancher.
A common use case for this is to enable integration of secret vault solutions (like Hashicorp Vault). You can see the original rancher/rancher issue for more details rancher/rancher#22417.
Comments / Questions