Skip to content

feat: add kerberos authentication provider #880

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 8 commits into from
Sep 30, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions crates/stackable-operator/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,12 @@ All notable changes to this project will be documented in this file.

## [Unreleased]

### Added

- Add Kerberos AuthenticationProvider ([#880]).

[#880]: https://github.com/stackabletech/operator-rs/pull/880

## [0.77.1] - 2024-09-27

### Fixed
Expand Down
11 changes: 11 additions & 0 deletions crates/stackable-operator/src/commons/authentication/kerberos.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
use schemars::JsonSchema;
use serde::{Deserialize, Serialize};

#[derive(
Clone, Debug, Deserialize, Eq, Hash, JsonSchema, Ord, PartialEq, PartialOrd, Serialize,
)]
#[serde(rename_all = "camelCase")]
pub struct AuthenticationProvider {
/// Mandatory SecretClass used to obtain keytabs.
pub kerberos_secret_class: String,
}
14 changes: 13 additions & 1 deletion crates/stackable-operator/src/commons/authentication/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ use strum::Display;

use crate::client::Client;

pub mod kerberos;
pub mod ldap;
pub mod oidc;
pub mod static_;
Expand Down Expand Up @@ -77,6 +78,10 @@ pub enum AuthenticationClassProvider {
/// The [TLS provider](DOCS_BASE_URL_PLACEHOLDER/concepts/authentication#_tls).
/// The TLS AuthenticationClass is used when users should authenticate themselves with a TLS certificate.
Tls(tls::AuthenticationProvider),

/// The [Kerberos provider](DOCS_BASE_URL_PLACEHOLDER/concepts/authentication#_kerberos).
/// The Kerberos AuthenticationClass is used when users should authenticate themselves via Kerberos.
Kerberos(kerberos::AuthenticationProvider),
}

impl AuthenticationClass {
Expand Down Expand Up @@ -183,6 +188,13 @@ mod tests {
let tls_provider = AuthenticationClassProvider::Tls(AuthenticationProvider {
client_cert_secret_class: None,
});
assert_eq!("Tls", tls_provider.to_string())
assert_eq!("Tls", tls_provider.to_string());

let kerberos_provider = AuthenticationClassProvider::Kerberos(
crate::commons::authentication::kerberos::AuthenticationProvider {
kerberos_secret_class: "kerberos".to_string(),
},
);
assert_eq!("Kerberos", kerberos_provider.to_string());
}
}
Loading