Method, device and system for performing authentication and authority management on user, and medium

A technology for authority management and device management, applied in the transmission system, electrical components, etc., can solve the problems of not supporting multi-tenant management across multiple Kubernetes clusters, not supporting cross-clusters, and increasing the burden on users

Active Publication Date: 2019-03-15
UCLOUD TECH CO LTD
View PDF5 Cites 10 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0005] Openshift is a PASS platform based on kubernetes and Docker, which supports user authentication and authority management. Openshift implements multi-tenant management of a single cluster, but does not support multi-tenant management across multiple Kubernetes clusters.
[0006] Rancher is an open source Kubernetes management platform, but Rancher is aimed at users of a certain cluster, and the user's project does not support cross-cluster
[0007] Kubernetes itself also provides four authentication methods, each of which can be used directly, but requires users to manage their own certificates, tokens, etc., and the relationship between users and namespaces also needs to be maintained by users themselves. increased burden

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method, device and system for performing authentication and authority management on user, and medium
  • Method, device and system for performing authentication and authority management on user, and medium
  • Method, device and system for performing authentication and authority management on user, and medium

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0034] Embodiments of the present invention will be described in detail below in conjunction with the accompanying drawings.

[0035] figure 1 It is a structural diagram of a system 1 for enabling a container management cluster to perform user authentication and authority management according to an embodiment of the present invention. Such as figure 1 As shown, the system 1 includes a management device 10 and one or more container management clusters 11a, 11b. figure 1 Only two container management clusters 11a, 11b are shown in , but there may be any number of container management clusters without limitation. Hereinafter, unless otherwise specified, the container management clusters 11a and 11b are collectively referred to as the cluster 11 . Each cluster 11 performs authentication and authority management on one or more different users via the management device 10 .

[0036] figure 2 yes figure 1 A structural diagram of the management device 10 and the cluster 11 in t...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention provides a method, device and system for performing authentication and authority management on a user using a container management cluster, and a medium. The method comprises the following steps: a registration step: sending a registration request to the container management cluster, and storing a service account and authentication information created by the container management cluster for the user; a login step: responding to a login request, taking out authentication information of the user, and authenticating whether the user successfully logs in according to the authentication information by the container management cluster; an authorization step: after determining that the user has successfully logged in, creating one or more items for an authorization request of the user, storing a namespace created by the container management cluster, and sending the service account and space of the user to the container management cluster for authorization; and an authenticationstep: responding to an operation request, taking out namespaces in one-to-one correspondence with items in the operation request, and authenticating the operation request by the container management cluster based on an authorization result of the service account and the namespaces.

Description

technical field [0001] The invention relates to a method, device, system and medium for user authentication and authority management. Background technique [0002] With the development of container technology, Kubernetes (k8s) as a container management system has gradually come into people's attention. Kubernetes can help users quickly build a container management service platform. [0003] Kubernetes is a distributed container management system launched and open sourced by Google, which provides functions such as container hosting, orchestration, deployment, networking, and service discovery. Apiserver (Application Programming Interface Server) is an external management portal provided by Kubernetes. Users interact with Apiserver through the command line tool kubectl or the web page Dashboard to realize the management and configuration of Kubernetes. [0004] For security reasons, users accessing Kubernetes generally have to go through authentication and authority managem...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06
CPCH04L63/08H04L63/10H04L63/20
Inventor 安雪艳王昌宇张苗磊高鹏
Owner UCLOUD TECH CO LTD
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products