Merge "Updated OIDC service parameter names"

This commit is contained in:
Zuul 2022-11-30 12:48:13 +00:00 committed by Gerrit Code Review
commit 3774dbf685
3 changed files with 17 additions and 12 deletions

View File

@ -68,11 +68,11 @@ For a centralized |OIDC| authentication setup, use the following procedure:
each subcloud during bootstrapping, or by using the **system each subcloud during bootstrapping, or by using the **system
service-parameter-add kubernetes kube\_apiserver** command after service-parameter-add kubernetes kube\_apiserver** command after
bootstrapping the system, using the System Controller's floating OAM IP bootstrapping the system, using the System Controller's floating OAM IP
address as the oidc\_issuer\_url for all clouds. address as the oidc-issuer-url for all clouds.
address as the oidc\_issuer\_url for all clouds. address as the oidc-issuer-url for all clouds.
For example, For example,
oidc\_issuer\_url=https://<central-cloud-floating-ip>:<oidc-auth-apps-dex oidc-issuer-url=https://<central-cloud-floating-ip>:<oidc-auth-apps-dex
-service-NodePort>/dex on the subcloud. -service-NodePort>/dex on the subcloud.
For more information, see: For more information, see:

View File

@ -30,24 +30,24 @@ you can do so at any time using service parameters.
.. code-block:: none .. code-block:: none
~(keystone_admin)]$ system service-parameter-add kubernetes kube_apiserver oidc_client_id=stx-oidc-client-app ~(keystone_admin)]$ system service-parameter-add kubernetes kube_apiserver oidc-client-id=stx-oidc-client-app
- oidc\_client\_id=<client> - oidc-client-id=<client>
The value of this parameter may vary for different group The value of this parameter may vary for different group
configurations in your Windows Active Directory server. configurations in your Windows Active Directory server.
- oidc\_groups\_claim=<groups> - oidc-groups-claim=<groups>
- oidc\_issuer\_url=https://<oam-floating-ip>:<oidc-auth-apps-dex-service-NodePort>/dex - oidc-issuer-url=https://<oam-floating-ip>:<oidc-auth-apps-dex-service-NodePort>/dex
.. note:: .. note::
For IPv6 deployments, ensure that the IPv6 OAM floating address For IPv6 deployments, ensure that the IPv6 OAM floating address
is, https://\[<oam-floating-ip>\]:30556/dex \(that is, in lower is, https://\[<oam-floating-ip>\]:30556/dex \(that is, in lower
case, and wrapped in square brackets\). case, and wrapped in square brackets\).
- oidc\_username\_claim=<email> - oidc-username-claim=<email>
The values of this parameter may vary for different user The values of this parameter may vary for different user
configurations in your Windows Active Directory server. configurations in your Windows Active Directory server.
@ -58,10 +58,15 @@ you can do so at any time using service parameters.
- none of the parameters - none of the parameters
- oidc\_issuer\_url, oidc\_client\_id, and oidc\_username\_claim - oidc-issuer-url, oidc-client-id, and oidc-username-claim
- oidc\_issuer\_url, oidc\_client\_id, oidc\_username\_claim, and oidc\_groups\_claim - oidc-issuer-url, oidc-client-id, oidc-username-claim, and oidc-groups-claim
.. note::
Historical service parameters for |OIDC| with underscores are still
accepted: oidc_client_id, oidc_issuer_url, oidc_username_claim and
oidc_groups_claim. These are equivalent to: oidc-client-id, oidc-issuer-url,
oidc-username-claim and oidc-groups-claim.
#. Apply the service parameters. #. Apply the service parameters.

View File

@ -16,8 +16,8 @@ You can remove Windows Active Directory authentication from |prod-long|.
#. Determine the UUIDs of parameters used in the kubernetes **kube-apiserver** group. #. Determine the UUIDs of parameters used in the kubernetes **kube-apiserver** group.
These include oidc\_client\_id, oidc\_groups\_claim, These include oidc-client-id, oidc-groups-claim,
oidc\_issuer\_url and oidc\_username\_claim. oidc-issuer-url and oidc-username-claim.
.. code-block:: none .. code-block:: none