KubeStacks trusts the proxy’s headers completely. Anyone who can reach KubeStacks without going through the proxy can name themselves anyone. Make sure nothing but the proxy can reach it.
Set it up
1
Put the proxy in front of KubeStacks
Point your proxy at the
kubestacks Service, port 80, and have it pass on who signed in, and their groups. The proxy must pass WebSockets through: each page keeps one open.With oauth2-proxy, --pass-user-headers sends the person’s email address in X-Forwarded-Email, and their groups in X-Forwarded-Groups.2
Configure KubeStacks, and keep everything else out
values.yaml
3
Give people roles
Bind roles to the names the proxy sends, with the prefixes you chose:
The headers
string
default:"X-Forwarded-User"
The request header that names the person. A request without it gets a page that says KubeStacks doesn’t know who you are, and asks people to have whoever runs KubeStacks check the proxy.
string
default:"X-Forwarded-Groups"
The request header that lists their groups, separated by commas.
string
Where signing out of the proxy is, like
https://kubestacks.example.com/oauth2/sign_out. KubeStacks has no session of its own behind a proxy, so signing out means signing out of the proxy.system:…), whatever the proxy says. It leaves out groups whose names start with system:, and refuses a user whose name does.
What it means for the cluster
Behind a proxy, KubeStacks impersonates people, so the chart gives its service account permission to impersonate users and groups, cluster-wide. Whoever can reach KubeStacks’ pod, or read its service account’s token, can act as anyone. Keep KubeStacks in a namespace only cluster administrators can exec into. See Security. There are no KubeStacks sessions behind a proxy: it reads the headers on every request. Restarting KubeStacks doesn’t sign anyone out, and how long people stay signed in is up to the proxy.Security
Hardening KubeStacks when it impersonates people.
Single sign-on
Or let KubeStacks talk to your provider directly.