mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-26 21:18:04 +00:00
* Port Product docs PR #486 * Apply suggestions from code review Co-authored-by: Billy Tat <btat@suse.com> * Fix typo on Configure PingIdentity page --------- Co-authored-by: Billy Tat <btat@suse.com>
This commit is contained in:
co-authored by
Billy Tat
parent
492e5cec9e
commit
0d8c6f407d
+3
-3
@@ -73,12 +73,12 @@ Rancher 依赖用户和组来决定允许谁登录 Rancher 以及他们可以访
|
||||
|
||||
**结果:** Rancher 的访问配置被应用。
|
||||
|
||||
:::note SAML 认证警告:
|
||||
:::note SAML 认证警告
|
||||
|
||||
- SAML 协议不支持搜索或查找用户或组。因此,将用户或组添加到 Rancher 时不会对其进行验证。
|
||||
- Users and groups aren't validated when you assign permissions to them in Rancher.
|
||||
- 添加用户时,必须正确输入确切的用户 ID(即 UID 字段)。键入用户 ID 时,将不会搜索可能匹配的其他用户 ID。
|
||||
- 添加组时,必须从文本框旁边的下拉列表中选择组。Rancher 假定来自文本框的任何输入都是用户。
|
||||
- 用户组下拉列表仅显示您所属的用户组。您将无法添加您不是其成员的组。
|
||||
- The group drop-down shows only the groups that you are a member of. However, if you have Administrator permissions or Restricted Administrator permissions, you can join a group that you are not a member of.
|
||||
|
||||
:::
|
||||
|
||||
|
||||
+9
@@ -121,6 +121,15 @@ description: 创建 Keycloak OpenID Connect (OIDC) 客户端并配置 Rancher
|
||||
|
||||
**结果**:已将 Rancher 配置为使用 OIDC 协议与 Keycloak 一起工作。你的用户现在可以使用 Keycloak 登录名登录 Rancher。
|
||||
|
||||
:::note SAML 认证警告
|
||||
|
||||
- Users and groups aren't validated when you assign permissions to them in Rancher.
|
||||
- 添加用户时,必须正确输入确切的用户 ID(即 UID 字段)。键入用户 ID 时,将不会搜索可能匹配的其他用户 ID。
|
||||
- 添加组时,必须从文本框旁边的下拉列表中选择组。Rancher 假定来自文本框的任何输入都是用户。
|
||||
- The group drop-down shows only the groups that you are a member of. However, if you have Administrator permissions or Restricted Administrator permissions, you can join a group that you are not a member of.
|
||||
|
||||
:::
|
||||
|
||||
## 配置参考
|
||||
|
||||
| 字段 | 描述 |
|
||||
|
||||
+1
-1
@@ -67,7 +67,7 @@ Okta 集成仅支持服务提供商发起的登录。
|
||||
- 在 Rancher 中为用户和组分配权限时将不会验证用户和组。
|
||||
- 添加用户时,必须正确输入确切的用户 ID(即 `UID` 字段)。键入用户 ID 时,将不会搜索可能匹配的其他用户 ID。
|
||||
- 添加组时,必须从文本框旁边的下拉列表中选择组。Rancher 假定来自文本框的任何输入都是用户。
|
||||
- 用户组下拉列表仅显示你所属的用户组。如果你不是某个组的成员,你将无法添加该组。
|
||||
- The group drop-down shows only the groups that you are a member of. However, if you have Administrator permissions or restricted Administrator permissions, you can join a group that you are not a member of.
|
||||
|
||||
:::
|
||||
|
||||
|
||||
+1
-1
@@ -57,7 +57,7 @@ title: 配置 PingIdentity (SAML)
|
||||
- SAML 协议不支持搜索或查找用户或组。因此,将用户或组添加到 Rancher 时不会对其进行验证。
|
||||
- 添加用户时,必须正确输入确切的用户 ID(即 `UID` 字段)。键入用户 ID 时,将不会搜索可能匹配的其他用户 ID。
|
||||
- 添加组时,必须从文本框旁边的下拉列表中选择组。Rancher 假定来自文本框的任何输入都是用户。
|
||||
- 用户组下拉列表仅显示你所属的用户组。如果你不是某个组的成员,你将无法添加该组。
|
||||
- The group drop-down shows only the groups that you are a member of. However, if you have Administrator permissions or restricted Administrator permissions, you can join a group that you are not a member of.
|
||||
|
||||
:::
|
||||
|
||||
|
||||
+4
-4
@@ -12,12 +12,12 @@ Rancher 依赖用户和组来决定允许登录到 Rancher 的用户,以及他
|
||||
|
||||
你可以查看和管理所有用户,包括本地用户和来自身份验证提供程序的用户。在左上角,单击 **☰ > 用户 & 认证**。在左侧导航栏中单击**用户**。
|
||||
|
||||
:::note SAML 身份提供商注意事项
|
||||
:::note SAML 认证警告
|
||||
|
||||
- SAML 协议不支持搜索或查找用户或组。因此,将用户或组添加到 Rancher 时不会对其进行验证。
|
||||
- 添加用户时,必须正确输入确切的用户 ID(即 `UID` 字段)。键入用户 ID 时,将不会搜索可能匹配的其他用户 ID。
|
||||
- Users and groups aren't validated when you assign permissions to them in Rancher.
|
||||
- 添加用户时,必须正确输入确切的用户 ID(即 UID 字段)。键入用户 ID 时,将不会搜索可能匹配的其他用户 ID。
|
||||
- 添加组时,必须从文本框旁边的下拉列表中选择组。Rancher 假定来自文本框的任何输入都是用户。
|
||||
- 用户组下拉列表仅显示你所属的用户组。如果你不是某个组的成员,你将无法添加该组。
|
||||
- The group drop-down shows only the groups that you are a member of. However, if you have Administrator permissions or Restricted Administrator permissions, you can join a group that you are not a member of.
|
||||
|
||||
:::
|
||||
|
||||
|
||||
+4
-2
@@ -65,17 +65,19 @@ title: 配置 Shibboleth (SAML)
|
||||
|
||||
**结果**:已将 Rancher 配置为使用 Shibboleth。你的用户现在可以使用 Shibboleth 登录名登录 Rancher。
|
||||
|
||||
### SAML 提供商注意事项
|
||||
:::note SAML Provider Caveats
|
||||
|
||||
SAML 协议不支持用户或用户组的搜索或查找。因此,如果你没有为 Shibboleth 配置 OpenLDAP,则请留意以下警告。
|
||||
|
||||
- 在 Rancher 中为用户或组分配权限时,不会对用户或组进行验证。
|
||||
- 添加用户时,必须正确输入准确的用户 ID(即 UID 字段)。在你输入用户 ID 时,将不会搜索可能匹配的其他用户 ID。
|
||||
- 添加组时,必须从文本框旁边的下拉列表中选择组。Rancher 假定来自文本框的任何输入都是用户。
|
||||
- 用户组下拉列表仅显示你所属的用户组。如果你不是某个组的成员,你将无法添加该组。
|
||||
- The group drop-down shows only the groups that you are a member of. However, if you have Administrator permissions or restricted Administrator permissions, you can join a group that you are not a member of.
|
||||
|
||||
要在 Rancher 中分配权限时启用搜索组,你需要为 SAML 身份认证服务配置支持组的后端(例如 OpenLDAP)。
|
||||
|
||||
:::
|
||||
|
||||
### Configuring SAML Single Logout (SLO)
|
||||
|
||||
<ConfigureSLO />
|
||||
|
||||
Reference in New Issue
Block a user