安全

认证

师成师成· 更新于 2026-09-28· 阅读 11 分钟· 0 次阅读

登录后可跨设备保存划线和私人笔记登录

Apache Atlas 中的认证。

认证

Atlas 支持以下认证方式

  • 文件(File)
  • Kerberos
  • LDAP
  • Keycloak(OpenID Connect / OAUTH2)
  • PAM

要在 atlas-application.properties 文件中启用相应类型的认证,应将下列属性设置为 true。

atlas.authentication.method.kerberos=true|false
atlas.authentication.method.ldap=true|false
atlas.authentication.method.file=true|false
atlas.authentication.method.keycloak=true|false

如果两个或多个认证方法被设置为 true,则当前一个方法失败时,认证将回退到后一个方法。例如,如果 Kerberos 认证设置为 true,LDAP 认证也设置为 true,那么对于一个不带 Kerberos principal 和 keytab 的请求,将使用 LDAP 认证作为回退方案。

FILE 方法

文件认证要求在用户凭据文件中包含用户的登录信息,格式如下所示,并且该文件路径需要在 atlas-application.properties 中通过属性 atlas.authentication.method.file.filename 进行设置。

atlas.authentication.method.file=true
atlas.authentication.method.file.filename=sys:atlas.home/conf/users-credentials.properties

用户凭据文件应遵循以下格式:

username=group::sha256-password

例如。

admin=ADMIN::e7cf3ef4f17c3999a94f2c6f612e8a888e5b1026878e4e19398b23bd38ec221a

用户组可以是 ADMIN、DATA_STEWARD 或 DATA_SCIENTIST。

注意:密码使用 sha256 编码方法进行编码,可以使用 unix 工具生成。

例如:

echo -n "Password" | sha256sum
e7cf3ef4f17c3999a94f2c6f612e8a888e5b1026878e4e19398b23bd38ec221a  -

Kerberos 方式

要在 Atlas 中启用 Kerberos 模式的认证,请在 atlas-application.properties 中将属性 atlas.authentication.method.kerberos 设置为 true。

atlas.authentication.method.kerberos = true

此外,还应设置以下属性。

atlas.authentication.method.kerberos.principal=<principal>/<fqdn>@EXAMPLE.COM
atlas.authentication.method.kerberos.keytab = /<key tab filepath>.keytab
atlas.authentication.method.kerberos.name.rules = RULE:[2:$1@$0](atlas@EXAMPLE.COM)s/.*/atlas/
atlas.authentication.method.kerberos.token.validity = 3600 [ in Seconds (optional)]

LDAP 方式

要在 Atlas 中启用 LDAP 模式认证,请在 atlas-application.properties 中将属性 atlas.authentication.method.ldap 设置为 true,并将 LDAP 类型属性 atlas.authentication.method.ldap.type 设置为 LDAP 或 AD。如果连接的是 Active Directory,请使用 AD。

atlas.authentication.method.ldap=true
atlas.authentication.method.ldap.type=ldap|ad

对于 LDAP 或 AD,需要在 Atlas 应用属性中设置以下配置。

Active Directory

atlas.authentication.method.ldap.ad.domain= example.com
atlas.authentication.method.ldap.ad.url=ldap://<AD server ip>:389
atlas.authentication.method.ldap.ad.base.dn=DC=example,DC=com
atlas.authentication.method.ldap.ad.bind.dn=CN=Administrator,CN=Users,DC=example,DC=com
atlas.authentication.method.ldap.ad.bind.password=<password>
atlas.authentication.method.ldap.ad.referral=ignore
atlas.authentication.method.ldap.ad.user.searchfilter=(sAMAccountName={0})
atlas.authentication.method.ldap.ad.default.role=ROLE_USER

LDAP 目录

atlas.authentication.method.ldap.url=ldap://<Ldap server ip>:389
atlas.authentication.method.ldap.userDNpattern=uid={0},ou=users,dc=example,dc=com
atlas.authentication.method.ldap.groupSearchBase=dc=example,dc=com
atlas.authentication.method.ldap.groupSearchFilter=(member=cn={0},ou=users,dc=example,dc=com
atlas.authentication.method.ldap.groupRoleAttribute=cn
atlas.authentication.method.ldap.base.dn=dc=example,dc=com
atlas.authentication.method.ldap.bind.dn=cn=Manager,dc=example,dc=com
atlas.authentication.method.ldap.bind.password=<password>
atlas.authentication.method.ldap.referral=ignore
atlas.authentication.method.ldap.user.searchfilter=(uid={0})
atlas.authentication.method.ldap.default.role=ROLE_USER

Keycloak 方式。

要启用 Atlas 中的 Keycloak 认证模式,请在 atlas-application.properties 中将属性 atlas.authentication.method.keycloak 设置为 true,并将属性 atlas.authentication.method.keycloak.file 设置为你的 keycloak.json 文件所在的位置。同时,如果你想从 Keycloak 中获取组信息,请将 atlas.authentication.method.keycloak.ugi-groups 设置为 false。默认情况下,组信息将从 Keycloak 中定义的*角色(roles)*中获取。如果你想使用组信息,则需要在 Keycloak 中创建一个映射,并将 atlas.authentication.method.keycloak.groups_claim 设置为令牌声明的名称。请确保不要使用完整的组路径,并将该信息添加到访问令牌中。

atlas.authentication.method.keycloak=true
atlas.authentication.method.keycloak.file=/opt/atlas/conf/keycloak.json
atlas.authentication.method.keycloak.ugi-groups=false

按照 Keycloak 的说明配置你的 keycloak.json。请务必包含 "principal-attribute": "preferred_username" 以确保用户名可读,并包含 "autodetect-bearer-only": true。

{
  "realm": "auth",
  "auth-server-url": "http://keycloak-server/auth",
  "ssl-required": "external",
  "resource": "atlas",
  "public-client": true,
  "confidential-port": 0,
  "principal-attribute": "preferred_username",
  "autodetect-bearer-only": true
}

PAM

启用 PAM 认证的前提是在 /etc/pam.d/ 中存在登录服务文件。

要在 Atlas 中启用 PAM 认证模式:

  • 在 atlas-application.properties 中将 Atlas 属性 atlas.authentication.method.pam 设置为 true。
atlas.authentication.method.pam=true
  • 设置属性 atlas.authentication.method.pam.service=<登录服务> 以使用所需的 PAM 登录服务。例如,设置以下属性以使用 /etc/pam.d/login。
atlas.authentication.method.pam.service=login

评论

登录后参与评论

正在加载评论…