Authentication sidecar for Conjur Kubernetes integration
1M+
This image is meant to act as an authentication sidecar, to allow application containers in a pod to obtain a Conjur access token. Applications can use this access token to make calls to a Conjur service.
This image runs as a sidecar or init container and is responsible for authenticating to Conjur and writing a Conjur access token to /run/conjur/access-token. This access token is shared via volume mount with the pod's application container.
Complete documentation:
GitHub project: https://github.com/cyberark/conjur-authn-k8s-client
Mirror of https://hub.docker.com/r/cyberark/conjur-authn-k8s-client
Configuration of this sidecar container is applied via environment variables.
| Variable | Description | Example |
|---|---|---|
| CONJUR_ACCOUNT | Conjur account name | acmeco |
| CONJUR_AUTHN_URL | URL pointing to authn-k8s endpoint | https://conjur.acmeco.com/api/authn-k8s/gke-prod |
| CONJUR_AUTHN_LOGIN | Conjur host identity | namespace01/deployment/myapp |
| CONJUR_SSL_CERTIFICATE | Content of public SSL cert for Conjur connection | -----BEGIN CERTIFICATE-----... |
| MY_POD_NAME | Pod name (see downwards API) | metadata.name |
| MY_POD_NAMESPACE | Pod namespace (see downwards API) | metadata.namespace |
| CONTAINER_MODE | (optional) Run container as sidecar or init container. Defaults to 'sidecar'; allowed values are 'sidecar' or 'init'. When set to "init", the container will exit after performing authentication and writing the access token. | init |
| CONJUR_VERSION | (optional) Conjur version. Defaults to '5'; allowed values are '4' or '5'. Only use value '4' for Conjur Enterprise v4.x. Must use a string value in the manifest due to YAML parsing not handling integer values well. | 5 |
Note that in this example we must load a Conjur policy named conjur/authn-k8s/gke-prod and permit the host namespace01/deployment/myappread to have execute privileges on the webservice defined in that policy. Reference the documentation for complete details.
The path /run/conjur should be mounted as a shared volume between the application and sidecar containers. The application container needs only read access.
The file /run/conjur/access-token can be read directly by summon-conjur as the environment variable CONJUR_AUTHN_TOKEN_FILE.
The contents of the file can also be read by the Conjur Ruby API client like so:
require 'conjur-api'
Conjur.configuration.apply_cert_config!
token = JSON.parse(File.read("/run/conjur/access-token"))
api = Conjur::API.new_from_token(token)
puts api.variable("inventory-db/password").value
The token will be refreshed by this sidecar container every 5 minutes.
There is no need to specify a user or host identity when using Conjur auth tokens.
Content type
Image
Digest
sha256:c1a6cf112…
Size
10.6 MB
Last updated
over 1 year ago
docker pull cyberark/conjur-kubernetes-authenticator