Authentik - 登入 Harbor
本指南說明如何將 Authentik 設定為 OpenID Connect (OIDC) 提供者,以實現對 Harbor 的單一登入 (SSO) 功能。透過此設定,使用者可以利用他們在 Authentik 中的現有帳號安全地登入 Harbor。
先決條件
在開始之前,請確保您已準備好以下環境:
- Harbor 實例: 一個正常運行的 Harbor 實例,並可透過 FQDN (例如
harbor.company) 存取。 - Authentik 實例: 一個正常運行的 Authentik 實例,並可透過 FQDN (例如
authentik.company) 存取。 - 管理員權限: 對 Harbor 和 Authentik 皆具有管理員權限。
設定步驟
1. 在 Authentik 中建立 OIDC Provider
首先,登入您的 Authentik 管理介面,並建立一個新的 OAuth2/OpenID Provider。
- 導覽至 Applications -> Providers,點擊 Create。
- 選擇 OAuth2/OpenID Provider。
Provider 設定
- Name: 為此 Provider 命名,例如
Harbor。 - Client Type: 選擇
Confidential。 - Redirect URIs: 輸入 Harbor 的 OIDC 回調 URL。將
harbor.company替換為您 Harbor 實例的實際 FQDN:https://harbor.company/c/oidc/callback - Scopes: 至少需要勾選
openid,email, 和profile。這些範圍 (Scopes) 將允許 Harbor 從 Authentik 獲取使用者的基本資訊。 - Signing Key: 選擇一個可用的簽署金鑰。
2. 在 Authentik 中建立 Application
建立 Provider 後,您需要建立一個 Application 並將其與 Provider 關聯。
- 導覽至 Applications -> Applications,點擊 Create。
- Name: 為應用程式命名,例如
Harbor。 - Slug: 輸入一個簡短的識別符,例如
harbor。 - Provider: 選擇您剛剛建立的
HarborProvider。
3. 在 Harbor 中設定 OIDC 認證
接下來,登入您的 Harbor 管理介面,設定 OIDC 認證。
- 導覽至 Administration -> Configuration -> Authentication。
- Auth Mode: 從下拉選單中選擇
OIDC。
OIDC Provider 設定
- OIDC Provider Name: 輸入一個顯示名稱,例如
Authentik。 - OIDC Endpoint: 輸入您 Authentik 的 OIDC 端點 URL,通常是
https://authentik.company/application/o/。 - Client ID: 從您在 Authentik 中建立的 Provider 頁面複製 Client ID。
- Client Secret: ��您在 Authentik 中建立的 Provider 頁面複製 Client Secret。
- Scope: 輸入
openid email profile。 - Verify Certificate: 如果您的 Authentik 使用受信任的 SSL 憑證,請勾選此項。
儲存設定後,Harbor 的登入頁面將會顯示一個使用 Authentik 登入的按鈕。
總結
透過以上步驟,您已成功將 Harbor 與 Authentik 整合,實現了安全的 OIDC 單一登入。這不僅簡化了使用者管理,還透過集中式的身份驗證提升了系統的安全性。使用者現在可以使用他們的 Authentik 憑證無縫登入 Harbor,無需記住額外的帳號密碼。