Тёмный

Protecting internal apps on Kubernetes with OAuth2 Proxy 

Laszlo Fogas
Подписаться 422
Просмотров 13 тыс.
50% 1

Опубликовано:

 

11 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 15   
@leonidgaidai1989
@leonidgaidai1989 2 года назад
Good explanation. Thank you for video
@manasjain914
@manasjain914 3 года назад
please also make a video on the active directory OAuth2 Proxy
@SanjeevKumar-nq8td
@SanjeevKumar-nq8td Год назад
Would be wonderful to see how oauth2-proxy is configured with ISTIO
@yousrimefteh2506
@yousrimefteh2506 5 месяцев назад
i need help please can you help me ?
@g-luu
@g-luu Год назад
Great tutorial. Have a question regarding how would i protect a backend api with this? For instance the frontend already has the access token but the api is of a different system that is not public.
@laszlofogas
@laszlofogas Год назад
There is a problem. If you put the token in the frontend, it will go to the user's machine and the backend will not be protected anymore as you exposed your keys. So static tokens, and basic auth will not work here. Maybe if you use an OAuth based approach, like with Github, that's better. At least those tokens expire and are linked to your identity. What you need to check is what cookie the auth parameters are stored in. If you are lucky you can access those cookies and you can send those tokens when you request the backend with your frontend. But chances are there is a browser sandbox limitation, and you won't be able to access the cookie.
@JosiahRitchie
@JosiahRitchie 3 года назад
Very useful info, but hard to hear.
@laszlofogas1723
@laszlofogas1723 3 года назад
You are right, the sound level is way too low. I was using a condenser mic which I was never able to set up properly. Either picked up every noise from the whole house or it was too quiet. I picked up a podcaster mic since then. Hoping to produce better sound levels in the coming videos.
@JosiahRitchie
@JosiahRitchie 3 года назад
@@laszlofogas1723 Excellent!
@LuizJrDeveloper
@LuizJrDeveloper 2 года назад
How to validade group on keycloak?
@laszlofogas
@laszlofogas 2 года назад
These are the keycloak configs: oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider#keycloak-auth-provider You have to edit the manifests/oauth2-proxy.yaml manually, to match the config from the link above. Gimlet Stack will preserve your changes in future updates.
@rampanwar1316
@rampanwar1316 3 года назад
Can i add my custom auth server ?
@JerryOmann
@JerryOmann 3 года назад
Nice video. How can the application read the login Username? Is there a header field for the name, how can we add that? 🤔
@laszlofogas
@laszlofogas 3 года назад
I scanned the docs, but don't see such an option: oauth2-proxy.github.io/oauth2-proxy/docs/
@Yggdrasil42
@Yggdrasil42 2 года назад
Several headers are added to the forwarded request. The username is in one of them.
Далее
Securing Your APIs with OAuth 2.0 - API Days
31:36
Просмотров 70 тыс.
Securing Your Containerized Applications with NGINX
22:31
ГИГАЧАД МЭЙКЕР В PLANTS VS ZOMBIES 2!
00:49
Deploying Keycloak cluster on Kubernetes
13:31
Просмотров 36 тыс.
Protecting internal apps with Github login
12:24
OAuth 2.0 & OpenID Connect (OIDC): Technical Overview
16:19
Deploy Static Sites With Authentication For Free
30:25
Просмотров 2,3 тыс.
Single Sign-On for Kubernetes - Joel Speed, Pusher
34:28
An Illustrated Guide to OAuth and OpenID Connect
16:36
Просмотров 586 тыс.
OAuth 2.0 explained with examples
10:03
Просмотров 131 тыс.
ГИГАЧАД МЭЙКЕР В PLANTS VS ZOMBIES 2!
00:49