Configuring an htpasswd identity provider¶
Configure the htpasswd identity provider so users can log in to OpenShift Container Platform with credentials from an htpasswd file.
To define an htpasswd identity provider, complete these tasks:
- Create an
htpasswdfile to store the user and password information. - Create a secret to represent the
htpasswdfile. - Define an
htpasswdidentity provider resource that references the secret. - Apply the resource to the default OAuth configuration to add the identity provider.
Identity providers in OpenShift Container Platform¶
You can configure identity providers by creating a custom resource (CR) that describes the provider and adding it to the cluster. Identity providers enable user authentication in OpenShift Container Platform beyond the default kubeadmin user.
Note
OpenShift Container Platform usernames containing /, :, and % are not supported.
About htpasswd authentication¶
Configure htpasswd authentication to use a flat password file for login to OpenShift Container Platform. The file stores hashed credentials for each user and enables local authentication without an external identity provider.
Warning
Do not use htpasswd authentication in OpenShift Container Platform for production environments. Use htpasswd authentication only for development environments.
Create the htpasswd file¶
To configure the htpasswd identity provider, create an htpasswd file so usernames and hashed passwords are available for the cluster secret. The following procedures describe how to create the file on Linux and Windows Operating Systems.
- Creating an
htpasswdfile using Linux - Creating an
htpasswdfile using Windows
Create an htpasswd file using Linux¶
Create a flat htpasswd file on Red Hat Enterprise Linux (RHEL) with the htpasswd utility to store usernames and hashed passwords for your cluster. The file enables the htpasswd identity provider to authenticate users in OpenShift Container Platform from locally stored credentials.
Prerequisites
- You have access to the
htpasswdutility. On Red Hat Enterprise Linux (RHEL), this is available by installing thehttpd-toolspackage.
Procedure
-
Create or update your
htpasswdfile with a username and hashed password by running the following command:The command generates a hashed version of the password.
For example:
-
Continue to add or update credentials to the file by running the following command:
Create an htpasswd file using Windows¶
Create a flat htpasswd file on Windows with the htpasswd.exe utility to store usernames and hashed passwords for your cluster. The file enables the htpasswd identity provider to authenticate users in OpenShift Container Platform from locally stored credentials.
Prerequisites
- You have access to the
htpasswd.exeutility. On Windows, this utility is included in the\binsubdirectory of many Apache httpd distributions.
Procedure
-
Create or update your
htpasswdfile with a username and hashed password by running the following command:The command generates a hashed version of the password.
For example:
-
Continue to add or update credentials to the file by running the following command:
Create the htpasswd secret¶
Create an OpenShift Container Platform secret from your htpasswd file so the htpasswd identity provider can read user credentials for cluster login.
Prerequisites
- You created an
htpasswdfile.
Procedure
-
Create a
Secretobject that contains thehtpasswdusers file by running the following command:$ oc create secret generic htpass-secret --from-file=htpasswd=<path_to_users.htpasswd> -n openshift-configThe
--from-filekey must be namedhtpasswd.
Sample htpasswd CR¶
Review the custom resource fields and acceptable values for configuring an htpasswd identity provider in OpenShift Container Platform.
apiVersion: config.openshift.io/v1
kind: OAuth
metadata:
name: cluster
spec:
identityProviders:
- name: my_htpasswd_provider
mappingMethod: claim
type: HTPasswd
htpasswd:
fileData:
name: htpass-secret
where:
spec.identityProviders.name- Specifies the provider name, which is prefixed to provider usernames to form an identity name.
spec.identityProviders.mappingMethod- Specifies how mappings are established between identities from this provider and
Userobjects. spec.identityProviders.htpasswd.fileData.name- Specifies an existing secret containing a file generated using
htpasswd. For more information, see "htpasswd".
Additional resources
Add an identity provider to your cluster¶
Apply the identity provider custom resource (CR) to your cluster after you define it. With this configuration, you can authenticate with the configured identity provider.
Prerequisites
- You have access to a OpenShift Container Platform cluster.
- You have created the CR for your identity providers.
- You are logged in as an administrator.
Procedure
-
Apply the defined CR by running the following command:
Note
If a CR does not exist,
oc applycreates a new CR and might trigger the following warning:Warning: oc apply should be used on resources created by either oc create --save-config or oc apply. In this case you can safely ignore this warning. -
Log in to the cluster as a user from your identity provider, entering the password when prompted.
-
Confirm that the user logged in successfully and that the username displays by running the following command:
Update users for an htpasswd identity provider¶
Update users in the htpasswd identity provider so login credentials in OpenShift Container Platform stay in sync when you add or remove accounts.
Prerequisites
- You have created a
Secretobject namedhtpass-secretthat contains thehtpasswduser file. - You have configured an
htpasswdidentity provider namedmy_htpasswd_provider. - You have access to the
htpasswdutility. On Red Hat Enterprise Linux (RHEL), this is available by installing thehttpd-toolspackage. - You have cluster administrator privileges.
Procedure
-
Retrieve the
htpasswdfile from thehtpass-secretSecretobject and save it to your local machine by running the following command: -
Add or remove users from the
users.htpasswdfile by running the following commands:-
To add a new user:
-
To remove an existing user:
-
-
Replace the
htpass-secretSecretobject with the updated users in theusers.htpasswdfile by running the following command: -
If you removed one or more users, you must remove the existing resources for each user by running the following commands:
-
Delete the
Userobject:Be sure to remove the user, otherwise the user can continue using their token as long as it has not expired.
-
Delete the
Identityobject for the user:
-
Configure identity providers using the web console¶
You can configure identity providers on your OpenShift Container Platform cluster through the web console by updating the OAuth settings in the Cluster Settings.
Prerequisites
- You are logged in to the web console as a cluster administrator.
Procedure
-
Navigate to Administration → Cluster Settings.
-
Under the Configuration tab, click OAuth.
-
Under the Identity Providers section, select your identity provider from the Add drop-down list.
Note
You can specify multiple identity providers through the web console without overwriting existing identity providers.
Additional resources