Security authentication and authorization system for user to access Kubernetes cluster
By designing a security authentication and authorization system for users to access Kubernetes clusters, and using the Keycloak authentication server to achieve identity authentication and authorization, the problem of insufficient security of Kubernetes clusters is solved, and fine-grained secure access control is achieved, which is especially suitable for remote office scenarios.
Patent Information
- Application Number
- CN202411928985.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-25
- Publication Date
- 2025-05-06
AI Technical Summary
The security of Kubernetes clusters is insufficient, and user identity authentication and permission verification cannot be effectively carried out, especially in the scenario where remote office users access the enterprise cloud.
A secure authentication and authorization system for users to access Kubernetes clusters is designed, including data planes and control planes. The data plane flows data between users and applications through ingress proxy and container applications, while the control plane implements the management of Kubernetes clusters, including identity authentication components, authorization policy components and other security configuration components. The system relies on the Keycloak authentication server to realize user identity authentication and authorization, which is divided into two stages: user access to Kubernetes cluster token and Kubernetes cluster internal authentication and authorization.
The Kubernetes cluster infrastructure built by the enterprise has provided a production-level identity authentication and authorization mechanism, and realized fine-grained secure access control at various application systems within the enterprise, which is especially suitable for remote office users to access the enterprise cloud.
Smart Images

Figure CN119945730A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer security, and in particular relates to a security authentication and authorization system for users to access a Kubernetes cluster. Background Art
[0002] The traditional security model builds a strong boundary around the deployment environment, verifies user identity through a centralized security gateway, and only allows authorized users to access the internal infrastructure. With the popularity of microservices, cloud, and distributed deployment, especially the rise of remote work, more and more data and resources are used from outside the network instead of accessing the internal enterprise network. In this environment, the boundaries have become blurred, and it is even uncertain whether the boundaries still exist. The traditional security model is no longer applicable.
[0003] Many IT companies use Kubernetes to build internal cloud infrastructure to maintain the agility and portability of application systems. Cloud-native applications run in containers. They are designed to be portable and loosely coupled, and can change location and status as needed. Therefore, continuous user authentication and permission verification are required for remote office user access.
[0004] Native Kubernetes focuses on container management and does not focus on security. By default, each Kubernetes cluster provides a flat network where each container can communicate directly with other containers without restrictions. Application containers usually treat this container network as a trusted network, so trusted users within the Kubernetes cluster can perform any operation. Summary of the invention
[0005] 1. Technical issues to be resolved
[0006] The technical problem to be solved by the present invention is how to provide a secure authentication and authorization system for users to access a Kubernetes cluster, so as to solve the problem of insufficient security of the Kubernetes cluster.
[0007] (II) Technical solution
[0008] In order to solve the above technical problems, the present invention proposes a security authentication and authorization system for users to access a Kubernetes cluster, the system comprising: a data plane and a control plane;
[0009] The data plane includes: ingress proxy and container application. The ingress proxy is the entry point for external users to access the Kubernetes cluster, and the data plane is responsible for the data flow between users and applications.
[0010] The control plane implements Kubernetes cluster management; Kubernetes cluster security authentication and authorization are implemented around the control plane. The Kubernetes management components in the control plane include identity authentication components, authorization policy components, and other security configuration components; the API server is the core role of the control plane. The API server is the access point for each component of the control plane and controls all Kubernetes management components. Users query and operate the status of all Kubernetes management components by calling the API; the Kubernetes cluster relies on the Keycloak authentication server to implement user identity authentication and authorization, which includes two stages: users obtain access tokens to the Kubernetes cluster and authentication and authorization within the Kubernetes cluster.
[0011] (III) Beneficial effects
[0012] The present invention proposes a security authentication and authorization system for users to access Kubernetes clusters. Through the design of the present invention, a production-level identity authentication and authorization mechanism can be provided for the Kubernetes cluster infrastructure built by the enterprise, and fine-grained security access control at the application system level within the enterprise can be achieved. It is particularly suitable for working scenarios in which remote office users access the enterprise cloud. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 A schematic diagram of security authentication and authorization for users of the present invention to access a Kubernetes cluster;
[0014] Figure 2 Flowchart for obtaining a token to access a Kubernetes cluster for a user;
[0015] Figure 3 Flowchart for authentication and authorization within a Kubernetes cluster. DETAILED DESCRIPTION
[0016] In order to make the purpose, content and advantages of the present invention more clear, the specific implementation methods of the present invention are further described in detail below in conjunction with the drawings and examples.
[0017] The present invention designs security authentication and authorization for the above-mentioned weaknesses in native Kubernetes security capabilities. First, a security policy suitable for user remote access scenarios is designed. In terms of network policy, transmission encryption and reverse proxy protection are performed on Kubernetes cluster access. In terms of identity policy, external users need to perform continuous identity authentication and permission verification to access the Kubernetes cluster to ensure security. Second, Keycloak is relied upon to implement a reliable authentication and authorization mechanism, and the identity agent of each application is used to implement fine-grained authentication and authorization at the application level.
[0018] The present invention proposes a security authorization system for a Kubernetes cluster, wherein the system includes: a data plane and a control plane;
[0019] The data plane includes: ingress proxy and container application. The ingress proxy is the entry point for external users to access the Kubernetes cluster, and the data plane is responsible for the data flow between users and applications.
[0020] The control plane implements Kubernetes cluster management. Kubernetes cluster security authentication and authorization are mainly implemented around the control plane. The Kubernetes management components in the control plane include identity authentication components, authorization policy components, and other security configuration components. The API server is the core role of the control plane, because the API server is the access point for each component of the control plane. It controls all Kubernetes management components. Users can query and operate the status of all Kubernetes management components by calling the API. The Kubernetes cluster relies on the Keycloak authentication server to implement user identity authentication and authorization, which includes two stages: users obtain access tokens to the Kubernetes cluster and authentication and authorization within the Kubernetes cluster.
[0021] Figure 1 The security authentication and authorization system of the Kubernetes cluster proposed in the present invention is demonstrated.
[0022] 1. Security Strategy
[0023] In terms of communication strategy, ensuring the security of communication between external users and the Kubernetes cluster is the key to achieving controlled access. To this end, the network access policy of the Kubernetes cluster should be appropriately set:
[0024] ●All traffic entering, exiting, and flowing within a Kubernetes cluster must be transmitted using Transport Layer Security (TLS).
[0025] ●Turn off the firewall inbound rules for the API server and keep it hidden to avoid direct access from the Internet.
[0026] ● Use a reverse proxy as the access boundary of the API server, including an ingress proxy and an egress proxy. Users can only access the API server through the ingress proxy, and the data traffic returned by the API server to the user can only leave through the egress proxy, so that the API server does not need to expose the external IP address.
[0027] In terms of identity strategy, identity identification is the basis of authorization and authentication. Therefore, every human user should have an identity identification to achieve internal and external secure authentication access. For human users, IP identification alone cannot be used for security reasons. Therefore, JWT tokens (JsonWeb Token) are used to identify user identities, and JWT+TLS is used for transmission authentication.
[0028] 2. Authentication and Authorization Process
[0029] After ensuring network security and assigning identities, users can perform subsequent identity authentication and authorization when accessing the Kubernetes cluster. The ingress proxy redirects user access to the API server, and completes the authentication and authorization process in the control plane of the Kubernetes cluster. Once the user is successfully authenticated, they can access the backend container application, but whether the container application allows or denies access and the granularity of access are controlled by the application-level authorization policy.
[0030] Users can configure fine-grained access authorization policies (AuthorizationPolicy) to customize permissions. The granularity of the authorization policy is refined to the application layer through the identity proxy in the container application, achieving more fine-grained authorization control. For example, only specific application load identities have access to the service, or only certain specific interfaces (HTTP routing, gRPC methods) are allowed to access the service. The source and target of the specified rules are based on user identity and application identity as the basis for authentication and authorization, rather than IP as the basis for authentication and authorization, meeting high-level security requirements.
[0031] The Kubernetes native cluster does not have sufficient security capabilities for identity, authorization, and authentication. In order to meet the above advanced security requirements, the present invention uses Keycloak to implement a customizable identity management service. Keycloak is an open source identity management software that introduces concepts such as domains, groups, roles, and users, allowing users to perform more sophisticated configurations. The present invention introduces Keycloak as a third-party identity management component. The user identity authentication and authorization process based on Keycloak is divided into two stages:
[0032] (1) Phase 1: Users obtain a token to access the Kubernetes cluster
[0033] In the first stage, the user's client is responsible for communicating with the Keycloak authentication server to obtain the user certificate. Its working principle is to request an access token from the Keycloak authentication server. The Keycloak authentication server will respond with an access token after verifying the user's identity. The user client combines the request into a JWT token and then accesses the Kubernetes cluster. The schematic diagram is as follows Figure 2 As shown, the specific steps are as follows:
[0034] S11. Before entering the Kubernetes cluster, the user access request will be redirected to the Keycloak authentication server. For security reasons, each access request from a remote user will be redirected to the Keycloak authentication server for user identity authentication.
[0035] S12, the Keycloak authentication server checks the cached logged-in user information. If the user has not logged in, the Keycloak authentication server will ask the user to enter the user name and password. If the user has already logged in, it will directly enter S13.
[0036] S13. After the username / password authentication is completed, the Keycloak authentication server returns an authentication success response and caches the user login information; otherwise, it returns an authentication failure response.
[0037] S14. After receiving the authentication success response, the user terminal requests an identity token, and the Keycloak authentication server sends an identity token containing necessary information to the user client.
[0038] S15. The user client combines the identity token with the access request into a JWT token and requests access to the Kubernetes cluster.
[0039] (2) Phase 2: Kubernetes cluster internal authentication and authorization
[0040] In the second stage, the client uses the JWT token to request access to the Kubernetes cluster and completes the authentication process in the control plane. All communications within the Kubernetes cluster are completed in the TLS protocol encrypted channel. Figure 3 As shown, the specific steps are as follows:
[0041] S21. The user's request is accompanied by a JWT token to access the Kubernetes cluster application.
[0042] S22. User requests first access the ingress proxy. Within the Kubernetes cluster, to maximize cluster security, user access does not directly reach the control plane and application services, but is implemented through proxy components.
[0043] S23, the user request enters the control plane for authentication. In the Kubernetes cluster, the identity authentication component of the control plane is responsible for identity authentication. In order to maintain the identity consistency of the entire system, the present invention reconfigures the identity authentication component, which forwards the user request to the Keycloak authentication server for authentication.
[0044] S24. The Keycloak authentication server verifies the identity and returns the authentication result to the control plane authentication component, which then forwards the result to the ingress proxy.
[0045] S25. After identity authentication is passed, the entry proxy releases the user and directs the user access to the accessed container application.
[0046] S26. In container applications, the identity agent deployed in the same container controls the user's application operation permissions. When a user request reaches the identity agent, the identity agent reads the pre-configured authorization policy and evaluates the user request context, and decides whether to grant access to the application based on the authorization result. Because each container application can be configured with an independent authorization policy, fine-grained permission control at the application level can be achieved.
[0047] S27. Cluster egress traffic leaves through the egress proxy.
[0048] Through the design of the present invention, a production-level identity authentication and authorization mechanism can be provided for the Kubernetes cluster infrastructure built by the enterprise, and fine-grained security access control at the application system level within the enterprise can be achieved, which is particularly suitable for work scenarios where remote office users access the enterprise cloud.
[0049] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A security authentication and authorization system for users to access a Kubernetes cluster, characterized in that: The system includes: a data plane and a control plane; The data plane includes: ingress proxy and container application. The ingress proxy is the entry point for external users to access the Kubernetes cluster, and the data plane is responsible for the data flow between users and applications. The control plane implements Kubernetes cluster management; Kubernetes cluster security authentication and authorization are implemented around the control plane. The Kubernetes management components in the control plane include identity authentication components, authorization policy components, and other security configuration components; the API server is the core role of the control plane. The API server is the access point for each component of the control plane and controls all Kubernetes management components. Users query and operate the status of all Kubernetes management components by calling the API; the Kubernetes cluster relies on the Keycloak authentication server to implement user identity authentication and authorization, which includes two stages: users obtain access tokens to the Kubernetes cluster and authentication and authorization within the Kubernetes cluster.
2. The security authentication and authorization system for user access to a Kubernetes cluster as claimed in claim 1, characterized in that: The system sets the network access policy for the Kubernetes cluster as follows: All traffic entering, exiting, and flowing within the Kubernetes cluster must be transmitted using the Transport Layer Security protocol TLS. Disable the API server’s firewall inbound rules and keep it hidden from direct Internet access. Use a reverse proxy as the access boundary of the API server, including an ingress proxy and an egress proxy; Users can access the API server only through the entry proxy, and the data traffic returned by the API server to the user can only leave through the exit proxy, so there is no need for the API server to expose the external IP address.
3. The security authentication and authorization system for user access to a Kubernetes cluster as claimed in claim 2, characterized in that: Every human user should have an identity to achieve internal and external secure authentication access; for human users, JWT tokens are used to identify user identities, and JWT+TLS is used for transmission authentication.
4. The security authentication and authorization system for user access to a Kubernetes cluster as claimed in claim 1, characterized in that: The ingress proxy redirects user access to the API server and completes the authentication and authorization process on the control plane of the Kubernetes cluster. Once the user is successfully authenticated, they can access the backend container application, but whether the container application allows or denies access and the granularity of access are controlled by the application-level authorization policy.
5. The security authentication and authorization system for user access to a Kubernetes cluster as claimed in claim 4, characterized in that: Users can configure fine-grained access authorization policies to customize permissions. The granularity of authorization policies is refined to the application layer through the identity proxy within the container application to achieve more fine-grained authorization control. The source and target of the specified rules are based on user identity and application identity as the basis for authentication and authorization, meeting high-level security requirements.
6. The security authentication and authorization system for user access to a Kubernetes cluster as claimed in claim 5, characterized in that: Fine-grained authorization control includes: only specific application payload identities have access to the service, and access to the service is only allowed through certain specific interfaces.
7. The security authentication and authorization system for user access to a Kubernetes cluster according to any one of claims 1 to 6, characterized in that: When a user obtains a token to access the Kubernetes cluster, the user's client is responsible for communicating with the Keycloak authentication server to obtain the user certificate. The principle is to request an access token from the Keycloak authentication server. After verifying the user's identity, the Keycloak authentication server will respond with an access token. The user client combines the request into a JWT token and then accesses the Kubernetes cluster.
8. The security authentication and authorization system for user access to a Kubernetes cluster as claimed in claim 7, characterized in that: The specific steps for users to obtain a token to access the Kubernetes cluster include: S11. Before user access enters the Kubernetes cluster, the access request will be redirected to the Keycloak authentication server. For security reasons, each access request from a remote user will be redirected to the Keycloak authentication server for user identity authentication. S12, the Keycloak authentication server checks the cached logged-in user information. If the user has not logged in, the Keycloak authentication server will ask the user to enter the user name and password; if the user has already logged in, it will directly enter S13; S13. After the username / password authentication is completed, the Keycloak authentication server returns an authentication success response and caches the user login information; otherwise, it returns an authentication failure response; S14. After receiving the authentication success response, the user terminal requests an identity token, and the Keycloak authentication server sends an identity token containing necessary information to the user client; S15. The user client combines the identity token with the access request into a JWT token and requests access to the Kubernetes cluster.
9. The security authentication and authorization system for user access to a Kubernetes cluster as claimed in claim 8, characterized in that: During authentication and authorization within the Kubernetes cluster, the client uses the JWT token to request access to the Kubernetes cluster and completes the authentication process in the control plane. All communications within the Kubernetes cluster are completed in the TLS protocol encrypted channel.
10. The security authentication and authorization system for user access to a Kubernetes cluster as claimed in claim 8, characterized in that: The specific steps of authentication and authorization within the Kubernetes cluster include: S21. The user's request is accompanied by a JWT token to access the Kubernetes cluster application. S22: User requests first access the ingress proxy. Within the Kubernetes cluster, user access does not directly reach the control plane and application services, but is implemented through the proxy component. S23. The user request enters the control plane for authentication. The identity authentication component of the control plane in the Kubernetes cluster is responsible for identity authentication. The identity authentication component is reconfigured and forwards the user request to the Keycloak authentication server for authentication. S24, the Keycloak authentication server verifies the identity and returns the authentication result to the control plane authentication component, which then forwards the result to the ingress proxy; S25. After identity authentication is passed, the entry proxy allows access and directs the user access to the accessed container application; S26. In container applications, the identity agent deployed in the same container controls the user's application operation permissions. When a user request reaches the identity agent, the identity agent reads the pre-configured authorization policy and evaluates the user request context, and decides whether to grant access to the application based on the authorization result. Because each container application can be configured with an independent authorization policy, fine-grained permission control at the application level can be achieved. S27. Cluster egress traffic leaves through the egress proxy.
Citation Information
Cited By
Private network cluster access system and method based on gRPC bidirectional authentication
CN121711101A