Sign inSign up

cyberark/conjur-kubernetes-authenticator

By cyberark

•Updated over 1 year ago

Authentication sidecar for Conjur Kubernetes integration

Image
2

1M+

cyberark/conjur-kubernetes-authenticator repository overview

⁠DEPRECATED: Please use https://hub.docker.com/r/cyberark/conjur-authn-k8s-client/⁠ instead.

⁠Overview

This image is meant to act as an authentication sidecar, to allow application containers in a pod to obtain a Conjur access token. Applications can use this access token to make calls to a Conjur service.

This image runs as a sidecar or init container and is responsible for authenticating to Conjur and writing a Conjur access token to /run/conjur/access-token. This access token is shared via volume mount with the pod's application container.

Complete documentation:

GitHub project: https://github.com/cyberark/conjur-authn-k8s-client⁠

Mirror of https://hub.docker.com/r/cyberark/conjur-authn-k8s-client⁠

⁠Configuration

Configuration of this sidecar container is applied via environment variables.

VariableDescriptionExample
CONJUR_ACCOUNTConjur account nameacmeco
CONJUR_AUTHN_URLURL pointing to authn-k8s endpointhttps://conjur.acmeco.com/api/authn-k8s/gke-prod⁠
CONJUR_AUTHN_LOGINConjur host identitynamespace01/deployment/myapp
CONJUR_SSL_CERTIFICATEContent of public SSL cert for Conjur connection-----BEGIN CERTIFICATE-----...
MY_POD_NAMEPod name (see downwards API⁠)metadata.name
MY_POD_NAMESPACEPod namespace (see downwards API⁠)metadata.namespace
CONTAINER_MODE(optional) Run container as sidecar or init container. Defaults to 'sidecar'; allowed values are 'sidecar' or 'init'. When set to "init", the container will exit after performing authentication and writing the access token.init
CONJUR_VERSION(optional) Conjur version. Defaults to '5'; allowed values are '4' or '5'. Only use value '4' for Conjur Enterprise v4.x. Must use a string value in the manifest due to YAML parsing not handling integer values well.5

Note that in this example we must load a Conjur policy named conjur/authn-k8s/gke-prod and permit the host namespace01/deployment/myappread to have execute privileges on the webservice defined in that policy. Reference the documentation for complete details.

⁠Volumes

The path /run/conjur should be mounted as a shared volume between the application and sidecar containers. The application container needs only read access.

The file /run/conjur/access-token can be read directly by summon-conjur⁠ as the environment variable CONJUR_AUTHN_TOKEN_FILE.

The contents of the file can also be read by the Conjur Ruby API client⁠ like so:

require 'conjur-api'

Conjur.configuration.apply_cert_config!
token = JSON.parse(File.read("/run/conjur/access-token"))
api = Conjur::API.new_from_token(token)
puts api.variable("inventory-db/password").value

The token will be refreshed by this sidecar container every 5 minutes.

There is no need to specify a user or host identity when using Conjur auth tokens.

Tag summary

Content type

Image

Digest

sha256:c1a6cf112…

Size

10.6 MB

Last updated

over 1 year ago

docker pull cyberark/conjur-kubernetes-authenticator