[INFRA] Installation Keycloak of Ubuntu 22.04.01 LTS in Docker Container

2023. 1. 6. 21:46ใ†System ์ž‘์—…์‹ค/DevOps

728x90
๋ฐ˜์‘ํ˜•

 

 

 

 

 

ํฌ๋ฃจ ๋ชจ์ง‘ ๊ณต๊ณ 

IT์ง๊ตฐ ํฌํด + ๋ธ”๋กœ๊ทธ ํ”Œ๋žซํผ ์‚ฌ์ด๋“œ ํ”„๋กœ์ ํŠธ

productive-ornament-cad.notion.site

 




๐Ÿ—‚ ๋ชฉ์ฐจ

โ— [INFRA] OpenLDAP๊ณผ LDAP Account Manager ์„ค์น˜ํ•˜๊ธฐ
โ— [INFRA] OpenLDAP๊ณผ Client CentOS 7.9 ์—ฐ๋™ํ•˜๊ธฐ
โ— [INFRA] Installation Keycloak of Ubuntu 22.04.01 LTS in Docker Container
โ— 



 

 

 

Deployment with Docker

COUPANG

www.coupang.com

"์ด ํฌ์ŠคํŒ…์€ ์ฟ ํŒก ํŒŒํŠธ๋„ˆ์Šค ํ™œ๋™์˜ ์ผํ™˜์œผ๋กœ, ์ด์— ๋”ฐ๋ฅธ ์ผ์ •์•ก์˜ ์ˆ˜์ˆ˜๋ฃŒ๋ฅผ ์ œ๊ณต๋ฐ›์Šต๋‹ˆ๋‹ค."






๐Ÿš€ Keycloak ์„ค์น˜ ๋ฐ ๊ตฌ์„ฑ

    ๐Ÿ”ฝ  ๊ฐœ์š”

        ๐Ÿ“ฆ ์†Œ๊ฐœ

์ฃผ๋‹ˆํ•˜๋ž‘์€ ์ด์ „์— Ubuntu 22.04.01 LTS Docker Container๋ฅผ ์ด์šฉํ•˜์—ฌ OpenLDAP Server๋ฅผ ๊ตฌ์„ฑํ•˜๊ณ , CentOS 7.9 Client๋ฅผ ์—ฐ๋™ํ•˜๋Š” ๊ฒƒ์„ ์ง„ํ–‰ํ•ด ๋ณด์•˜์–ด์š”.

์ด๋ฒˆ์—๋Š” ๋ณด๋‹ค ํŽธ๋ฆฌํ•˜๊ฒŒ ๊ณ„์ • ๊ด€๋ฆฌ๋ฅผ ์œ„ํ•ด Keycloak๋ฅผ ์„ค์น˜ํ•ด๋ณด๋ ค๊ณ  ํ•ด์š”.

Keycloak์ด๋ž€ ํ˜„๋Œ€ Application๊ณผ Service์— ์ดˆ์ ์„ ๋‘” ID ๋ฐ ์ ‘๊ทผ ๊ด€๋ฆฌ(Access Management)์— ํ†ตํ•ฉ ์ธ์ฆ(SSO; Sigle Sign On)์„ ํ—ˆ์šฉํ•˜๋Š” Open Source Software๋กœ Kubernetes ๋˜๋Š” MSA ํ™˜๊ฒฝ์— ์ตœ์ ํ™”๋œ ์†”๋ฃจ์…˜์ด์—์š”.
์ข€ ๋” ์‰ฝ๊ฒŒ ์„ค๋ช…ํ•˜๋ฉด ์ธ์ฆ(Authentification)๊ณผ ์ธ๊ฐ€(Authorizaion)์„ ์‰ฝ๊ฒŒ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ฃผ๋Š” ์†”๋ฃจ์…˜์ด๋ž๋‹ˆ๋‹ค.

๋Œ€ํ‘œ์ ์ธ ๊ธฐ๋Šฅ์€ ์•„๋ž˜์™€ ๊ฐ™์•„์š”.

โˆ™ ํ‘œ์ค€ Protocol ์ง€์›(OpenID Connect, OAuth 2.0 - GitHub, Google ๋“ฑ, SAML)
โˆ™ ๋™์ผ Realm์— ์†ํ•œ ๋ชจ๋“  Application์— ๋Œ€ํ•œ ํ†ตํ•ฉ ์ธ์ฆ(SSO; Single Sign-On) ๋ฐ Sign-Off
โˆ™ ๊ด€๋ฆฌ์ž / ๊ณ„์ •๊ด€๋ฆฌ Console ์ œ๊ณต
โˆ™ ID ์ค‘๊ฐœ
โˆ™ ์‚ฌ์šฉ์ž UI ์ •์˜
โˆ™ Client Adapters (๋‹ค์ˆ˜ ํ”Œ๋žซํผ๊ณผ ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์–ธ์–ด๊ฐ€ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ Adapter ์ง€์›)
โˆ™ Two fact ์ธ์ฆ
โˆ™ LDAP ํ†ตํ•ฉ
โˆ™ Kerberos ๋ธŒ๋กœ์ปค
โˆ™ ์˜์—ญ ๋ณ„ ์‚ฌ์šฉ์ž ์ง€์ • ๊ฐ€๋Šฅ ์Šคํ‚จ์„ ์‚ฌ์šฉํ•œ ๋ฉ€ํ‹ฐ ํƒœ๋„Œ์‹œ



 

 

 

    ๐Ÿ”ฝ  ์ดˆ๊ธฐ ๋‹จ๊ณ„

        ๐Ÿ“ฆ ์„ค์น˜

์ฃผ๋‹ˆํ•˜๋ž‘์€ ์ด๋ฒˆ System ๊ตฌ์„ฑ์„ ์œ„ํ•ด Ubuntu 22.04.01 LTS Docker Container๋ฅผ ์ด์šฉํ•ด์ฃผ๋ ค๊ณ  ํ•ด์š”.

vim /opt/docker/start/keycloak/keycloack-docker-build.sh


์ตœ์ดˆ Docker Container ๊ตฌ๋™์„ ์œ„ํ•ด ์œ„์™€ ๊ฐ™์ด Shell Script๋ฅผ ๋งŒ๋“ค์–ด ์ฃผ์—ˆ์–ด์š”.


๊ทธ๋Ÿฐ ๋’ค ์œ„์™€ ๊ฐ™์ด ๊ถŒํ•œ์„ ์ˆ˜์ •ํ•ด ์ฃผ์—ˆ์–ด์š”.



๊ทธ๋Ÿฐ ๋’ค ์œ„์™€ ๊ฐ™์ด Shell Script๋ฅผ ๋™์ž‘ ์‹œ์ผœ Container๊ฐ€ ๊ตฌ๋™๋˜๊ฒŒ ํ•ด ์ฃผ์—ˆ์–ด์š”.


apt-get update && apt-get upgrade -y


๊ทธ๋Ÿฐ ๋’ค Ubuntu Package๋ฅผ ์ตœ์‹ ํ™” ํ•ด ์ฃผ์—ˆ์–ด์š”.



apt-get install openjdk-17-jdk


Keycloak๋ฅผ ์ด์šฉํ•˜๊ธฐ ์œ„ํ•ด์„  JDK๋ฅผ ์„ค์น˜ํ•ด ์ฃผ์–ด์•ผํ•ด์š”.
JDK๋Š” 11 version ์ด์ƒ์„ ์ด์šฉํ•ด์•ผ ํ•˜๋ฉฐ, ์ฃผ๋‹ˆํ•˜๋ž‘์€ 17 Version์„ ์„ค์น˜ํ•ด ๋ณด๋ ค๊ณ  ํ•ด์š”.


java -version


JDK๊ฐ€ ์ •์ƒ ์„ค์น˜ ๋˜์—ˆ์–ด์š”.


wget https://github.com/keycloak/keycloak/releases/download/17.0.0/keycloak-17.0.0.tar.gz


wget์œผ๋กœ ๋‚ด๋ ค๋ฐ›๊ธฐ๋ฅผ ํ•˜๋ ค๊ณ  ํ–ˆ์ง€๋งŒ, wget์€ ์„ค์น˜๊ฐ€ ๋˜์–ด ์žˆ์ง€ ์•Š์•„ ๋ช‡๊ฐ€์ง€ Package๋ฅผ ๋‚ด๋ ค ๋ฐ›์•„ ์ค„๊ฒŒ์š”.


apt-get install -y vim systemd net-tools iputils-ping ntp wget


์œ„์™€ ๊ฐ™์ด ๋ช‡๊ฐ€์ง€ Package๋ฅผ ์„ค์น˜ ํ•ด์ฃผ์—ˆ์–ด์š”.


wget https://github.com/keycloak/keycloak/releases/download/17.0.0/keycloak-17.0.0.tar.gz


๋‹ค์‹œ ํ•„์š” ์‚ฌํ•ญ์„ wget์œผ๋กœ ๋‚ด๋ ค ๋ฐ›๊ธฐ๋ฅผ ํ•ด ์ฃผ์—ˆ์–ด์š”.


tar -zxvf {์••์ถ• File ์ด๋ฆ„}


๋‚ด๋ ค ๋ฐ›์€ ์••์ถ• ํŒŒ์ผ์„ ์œ„์™€ ๊ฐ™์ด ํ’€์–ด ์ฃผ์—ˆ์–ด์š”.



์œ„์™€ ๊ฐ™์ด Keycloak์„ ์‹œ์ž‘ํžˆ ์ „์— ์ดˆ๊ธฐ ๊ด€๋ฆฌ์ž ๊ณ„์ •์„ ์ƒ์„ฑ ํ•ด์•ผ ๋˜์š”.


bin/kc.sh start-dev




๋ธŒ๋ผ์šฐ์ €๋ฅผ ํ†ตํ•ด http://{Server IP}:{Keyloak Port Number}๋ฅผ
์ž…๋ ฅํ•˜๋ฉด ์œ„์™€ ๊ฐ™์ด WEB Interface์— ์ ‘์†ํ•  ์ˆ˜ ์žˆ์–ด์š”.


์ด ๊ณณ์—์„œ Administration Console์„ ํด๋ฆญํ•˜์—ฌ ๋“ค์–ด๊ฐ€ ์ค„๊ฒŒ์š”.




์œ„์™€ ๊ฐ™์ด ์ธ์ฆ์ฐฝ์ด ๋‚˜์˜ค๋ฉด ์œ„์—์„œ ์„ค์ •ํ–ˆ๋˜ ๊ด€๋ฆฌ์ž ๊ณ„์ •์„ ์ž…๋ ฅํ•ด ์ฃผ๋ฉด ๋˜์š”.

์ฐธ๊ณ ๋กœ ๊ด€๋ฆฌ์ž ๊ณ„์ •์„ ์ฒ˜์Œ ์ƒ์„ฑํ•  ๋•Œ, ํŠน์ˆ˜๋ฌธ์ž๋Š” ์ง€์›์„ ์•ˆํ•˜๋Š” ๊ฑฐ ๊ฐ™์•„์š”.
์˜ˆ๋ฅผ ๋“ค์–ด abc123$%^์ด๋ผ๊ณ  ๋“ฑ๋กํ–ˆ๋‹ค๋ฉด ํŠน์ˆ˜๋ฌธ์ž๋Š” ๋‹ค ์งค๋ฆฌ๊ณ  abc123๋งŒ ๋“ฑ๋ก์ด ๋˜๋Š”๊ฑธ๋กœ ํ™•์ธํ–ˆ์Šต๋‹ˆ๋‹ค.




์ ‘์†์ด ์„ฑ๊ณตํ•˜๋ฉด ์œ„์™€ ๊ฐ™์ด Keycloak Dash Board๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์–ด์š”.

 

 

 

    ๐Ÿ”ฝ  ๊ตฌ์„ฑ

        ๐Ÿ“ฆ ์‚ฌ์šฉ์ž ๊ณ„์ •๊ณผ Client ์ƒ์„ฑ

์ด๋ฒˆ์—๋Š” ์‚ฌ์šฉ์ž ๊ณ„์ •๊ณผ Client๋ฅผ ๋งŒ๋“ค์–ด ๋ณผ๊ฒŒ์š”.

์™ผ์ชฝ ์œ„์— Master๋ผ๊ณ  ๋œ ๋ถ€๋ถ„์— Mouse๋ฅผ ๊ฐ€์ ธ๋‹ค ๋Œ€๋ฉด ์œ„์™€ ๊ฐ™์ด Add realm์ด ๋‚˜์˜ฌ๊ฑฐ์—์š”.
์ด ๋ถ€๋ถ„์„ ํด๋ฆญํ•ด ์ค„๊ฒŒ์š”.



์ตœ์ดˆ ์œ„์™€ ๊ฐ™์ด Name์— ์ด๋ฆ„์„ ์ ์–ด์ฃผ๊ณ , create๋ฅผ ๋ˆŒ๋Ÿฌ์ฃผ์—ˆ์–ด์š”.



์œ„์™€ ๊ฐ™์ด ์ด๋ฆ„์ด ์ž˜ ๋“ฑ๋ก๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์–ด์š”.


์ด๋ฒˆ์—๋Š” Keycloack์˜ ์ƒˆ๋กœ์šด ์‚ฌ์šฉ์ž๋ฅผ ํ•œ๋ฒˆ ๋งŒ๋“ค์–ด ๋ณผ๊ฒŒ์š”.

์œ„์™€ ๊ฐ™์ด ์™ผ์ชฝ์— Users๋ฅผ ๋ˆŒ๋Ÿฌ์ค๋‹ˆ๋‹ค.


์œ„์˜ ๊ทธ๋ฆผ ํ‘œ์‹œ๋œ Add user๋ฅผ ๋ˆŒ๋Ÿฌ์ค„๊ฒŒ์š”.



์œ„์™€ ๊ฐ™์ด ํ•ด๋‹น ์‚ฌ์šฉ์ž๊ฐ€ ์‚ฌ์šฉํ•  ID๋ฅผ ์ž…๋ ฅํ•˜๊ณ , Save๋ฅผ ๋ˆŒ๋Ÿฌ์ฃผ์—ˆ์–ด์š”.



๊ทธ๋Ÿผ ์œ„์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜ฌํ…๋ฐ ์—ฌ๊ธฐ์„œ ๊ทธ๋ฆผ๊ณผ ๊ฐ™์ด ํ‘œ์‹œ๋œ ๊ณณ์„ ํด๋ฆญํ•ด ์ค„๊ฒŒ์š”.



์œ„์™€ ๊ฐ™์ด ์‚ฌ์šฉ์ž ๊ณ„์ •์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์„ค์ •ํ•˜๊ณ , Set Password๋ฅผ ๋ˆŒ๋Ÿฌ์ค๋‹ˆ๋‹ค.

์ฐธ๊ณ ๋กœ Temporary๋Š” ๊ด€๋ฆฌ์ž๊ฐ€ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ƒ์„ฑํ•˜๊ณ ,
๋‹ค์Œ์— Login ์‹œ ๋น„๋ฐ€๋ฒˆํ˜ธ ๋ณ€๊ฒฝ์„ ํ•˜๋„๋ก ํ•  ๊ฒƒ์ธ์ง€๋ฅผ ๊ฒฐ์ •ํ•˜๋Š” ๊ฑฐ์—์š”.



๋‹ค์‹œ Users์— ๋Œ์•„์™€ View all Users๋ฅผ ๋ˆ„๋ฅด๋ฉด ์œ„์™€ ๊ฐ™์ด ์‚ฌ์šฉ์ž ๊ณ„์ •์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์–ด์š”.



์ด๋ฒˆ์—๋Š” Application ๋ณดํ˜ธ๋ฅผ ์œ„ํ•ด Keycloack ์ธ์Šคํ„ด์Šค์— Application ๋“ฑ๋ก์„ ํ•ด๋ณผ๊ฒŒ์š”.



์ด๋ฒˆ์—๋Š” ์œ„์™€ ๊ฐ™์ด Clients๋ฅผ ๋ˆŒ๋Ÿฌ์ค„๊ฒŒ์š”.



๊ทธ๋Ÿฐ ๋’ค ์œ„์— ํ‘œ์‹œ๋œ ๊ณณ๊ณผ ๊ฐ™์ด Create๋ฅผ ๋ˆŒ๋Ÿฌ ์ค๋‹ˆ๋‹ค.



์ฃผ๋‹ˆํ•˜๋ž‘์ด ํ˜„์žฌ ํฌ๋ฃจ๋“ค๊ณผ ํ•จ๊ป˜ ์ง„ํ–‰ํ•˜๊ณ  ์žˆ๋Š” WEB Service๋ฅผ ๋“ฑ๋กํ•ด ๋ณผ๊ฒŒ์š”




๋ฐ˜์‘ํ˜•



์œ„์™€ ๊ฐ™์ด ํ•ด๋‹น Service ์ด๋ฆ„์„ Client ID์— ๋„ฃ๊ณ , URL ์ •๋ณด๋ฅผ ์ž…๋ ฅํ•ด ์ฃผ์—ˆ์–ด์š”.

Save๋ฅผ ๋ˆ„๋ฅด๊ฒŒ ๋˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์ด ๋Œ€๋ถ€๋ถ„ ์„ค์ •์„ ์ž๊ธฐ๊ฐ€ ์•Œ์•„์„œ ์„ค์ •ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ๋ฐ”๋กœ ๋‹ค์‹œ Save๋ฅผ ๋ˆŒ๋Ÿฌ์ค„๊ฑฐ์—์š”.





์œ„์™€ ๊ฐ™์ด WEB Application์ด ๋“ฑ๋ก๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์–ด์š”.









        ๐Ÿ“ฆ KeyCloack์™€ OpenLDAP ์—ฐ๊ณ„

์ด๋ฒˆ์—๋Š” ์ด ์ „์— ๊ตฌ์„ฑํ•œ OpenLDAP๊ณผ KeyCloack๋ฅผ ์—ฐ๋™ ์‹œ์ผœ ๋ณผ๊ฒŒ์š”.


์ด๋ฒˆ์—๋Š” ์œ„์™€ ๊ฐ™์ด User Federation์„ ์„ ํƒํ•ด ์ค„๊ฒŒ์š”.



๊ทธ๋ฆฌ๊ณ  ์œ„์™€ ๊ฐ™์ด ldap์„ ์„ ํƒํ•ด ์ค๋‹ˆ๋‹ค.


728x90


์ฃผ๋‹ˆํ•˜๋ž‘์€ ์œ„์™€ ๊ฐ™์ด ์„ค์ •์„ ํ•ด์คฌ๊ณ , Connection URL๊ณผ Bind Credential๋Š”
๋ฏธ๋ฆฌ ์ œ๋Œ€๋กœ๋œ ๊ฐ’์ด ์ž…๋ ฅ ๋˜์—ˆ๋Š”์ง€ ํ™•์ธํ•ด ๋ณผ ์ˆ˜ ์žˆ์–ด์š”.

์ฐธ๊ณ ๋กœ Bind Credential์—๋Š” OpenLDAP ๊ด€๋ฆฌ์ž ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•ด ์ฃผ๋ฉด ๋˜์š”.



์œ„์™€ ๊ฐ™์ด ์„ค์ •ํ•˜๊ณ , Save๋ฅผ ๋ˆŒ๋Ÿฌ์ฃผ์—ˆ์–ด์š”.



Save๋ฅผ ๋ˆ„๋ฅด๋ฉด ์œ„์™€ ๊ฐ™์ด ๋ฒ„ํŠผ์ด ๋” ์ƒ๊ธธ๊ฑฐ์—์š”.

์œ„ ๊ทธ๋ฆผ์— ํ‘œ์‹œ๋œ ๋ฒ„ํŠผ์„ ๋ˆ„๋ฅด๊ฒŒ ๋˜๋ฉด OpenLDAP์— ์ƒ์„ฑํ•œ User ์ •๋ณด๋ฅผ ๊ฐ€์ ธ์˜ค๊ฒŒ ๋  ๊ฑฐ์—์š”.



Users Tab์— ๋‹ค์‹œ ๊ฐ€์„œ View All users๋ฅผ ๋ˆŒ๋Ÿฌ๋ณด๋ฉด
OpenLDAP์—์„œ ์ƒ์„ฑํ•œ ๊ณ„์ • ์ •๋ณด๋ฅผ ๊ฐ€์ ธ์˜ค๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์–ด์š”.



์ด๋ฒˆ์—๋Š” ๊ทธ๋ฃน ์ •๋ณด๋„ ์—ฐ๋™ ์‹œ์ผœ๋‘˜๊ฒŒ์š”.



์ด๋ฒˆ์—๋Š” ์ด์ „์— ๋งŒ๋“ค์—ˆ๋˜ LDAP ์—ฐ๋™ ์ •๋ณด์— ๋‹ค์‹œ ๋“ค์–ด๊ฐ€ ์ค„๊ฑฐ์—์š”.



๊ทธ๋Ÿฐ ๋’ค ์œ„์™€ ๊ฐ™์ด Mappers๋ฅผ ํด๋ฆญํ•ด ์ค„๊ฑฐ์—์š”.



๊ทธ๋ฆฌ๊ณ  ์˜ค๋ฅธ์ชฝ ์œ„์— Create๋ฅผ ๋ˆŒ๋Ÿฌ์ค„๊ฑฐ์—์š”.



๊ทธ๋Ÿฐ ๋’ค Name์€ Groups๋กœ ํ•˜๊ณ , Mapper Type์€ group-ldap-mapper๋กœ ์„ ํƒํ•ด ์ค„๊ฑฐ์—์š”.



๊ทธ๋ฆฌ๊ณ  ์œ„์™€ ๊ฐ™์ด ์ƒ์„ธ ์„ค์ •์ฐฝ์ด ๋‚˜์™€ ์œ„์™€ ๊ฐ™์ด ์„ค์ •ํ•ด ์ฃผ์—ˆ์–ด์š”.
๊ทธ๋Ÿฐ ๋’ค Save๋ฅผ ๋ˆŒ๋Ÿฌ์ฃผ์—ˆ์–ด์š”.



๊ทธ๋Ÿผ ์œ„์™€ ๊ฐ™์ด ๋˜ ๋ฒ„ํŠผ์ด ๋‘ ๊ฐœ ๋” ์ƒ๊ธธํ…๋ฐ, ํ‘œ์‹œ๋œ ๋ฒ„ํŠผ์„ ๋ˆŒ๋Ÿฌ์ฃผ๋ฉด LDAP์˜ ๊ทธ๋ฃน ์ •๋ณด๋ฅผ ๊ฐ€์ ธ์˜ค๊ฒŒ ๋˜์š”.


OpenLDAP LDAP Access Manager User ์ •๋ณด

 

OpenLDAP LDAP Access Manager Group ์ •๋ณด


์œ„์™€ ๊ฐ™์ด OpenLDAP์— User ์ •๋ณด๋Š” ์žˆ์ง€๋งŒ, Group ์ •๋ณด๋Š” ์—†๋Š” ์ƒํƒœ์—์š”.




๊ทธ๋ž˜์„œ Keycloak์—๋„ Group ์ •๋ณด๋Š” ์•„๋ฌด๊ฒƒ๋„ ์—†๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์–ด์š”.





๐Ÿง ์ฐธ๊ณ  ์ž๋ฃŒ

 

์ž์Šต์„œ-Keycloak ์„ค์น˜ ๊ตฌ์„ฑ

Keycloak ์€ ํ˜„๋Œ€์˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜๊ณผ ์„œ๋น„์Šค์— ์ดˆ์ ์„ ๋‘” ID ๋ฐ ์ ‘๊ทผ ๊ด€๋ฆฌ(Access Management)์— ํ†ตํ•ฉ ์ธ์ฆ(SSO)์„ ํ—ˆ์šฉํ•˜๋Š” ์˜คํ”ˆ ์†Œ์Šค ์†Œํ”„ํŠธ์›จ์–ด๋กœ ubuntu์— Keycloak์„ ์„ค์น˜ ๋ฐ ๊ตฌ์„ฑํ•˜์—ฌ ํ…Œ์ŠคํŠธ ํ•˜๋Š” ๋‹จ๊ณ„๋ฅผ

nginxstore.com

 

 

Keycloak(User Federation) - LDAP ์—ฐ๊ณ„

keycloak user management - keycloak์— ์ž์ฒด ์ƒ์„ฑ - user federation : ldap, AD ๋“ฑ ์™ธ๋ถ€ user database์™€ ์—ฐ๊ณ„ # minikube์— ์„ค์น˜ํ•œ openldap๊ณผ ์—ฐ๊ณ„ ๋ฐฉ๋ฒ• ์ •๋ฆฌ # Realm ์„ ํƒ > ์™ธ์ชฝ ๋ฉ”๋‰ด์—์„œ User Federation์„ ํƒ > ์˜ค๋ฅธ์ชฝ์—์„œ ldap

hs-note.tistory.com

 

 

Deployment with Docker

COUPANG

www.coupang.com

"์ด ํฌ์ŠคํŒ…์€ ์ฟ ํŒก ํŒŒํŠธ๋„ˆ์Šค ํ™œ๋™์˜ ์ผํ™˜์œผ๋กœ, ์ด์— ๋”ฐ๋ฅธ ์ผ์ •์•ก์˜ ์ˆ˜์ˆ˜๋ฃŒ๋ฅผ ์ œ๊ณต๋ฐ›์Šต๋‹ˆ๋‹ค."

 

 

 

 

 

 

 

๐Ÿ’ก ์ฐธ๊ณ  ์‚ฌํ•ญ
์•ˆ๋…•ํ•˜์„ธ์š”.

 

 

 

 

 

 

 

728x90
๋ฐ˜์‘ํ˜•