mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-25 20:48:11 +00:00
Merge pull request #1311 from enrichman/azuread-cli
[2.8.6] added doc for Rancher CLI login with AzureAD
This commit is contained in:
+13
-4
@@ -133,7 +133,17 @@ Here are a few examples of permission combinations that satisfy Rancher's needs:
|
||||
|
||||
:::
|
||||
|
||||
#### 4. Copy Azure Application Data
|
||||
#### 4. Allow Public Client Flows
|
||||
|
||||
To login from Rancher CLI you must allow public client flows:
|
||||
|
||||
1. From the left navigation menu, select **Authentication**.
|
||||
|
||||
1. Under **Advanced Settings**, select **Yes** on the toggle next to **Allow public client flows**.
|
||||
|
||||

|
||||
|
||||
#### 5. Copy Azure Application Data
|
||||
|
||||

|
||||
|
||||
@@ -176,7 +186,7 @@ You'll also need to manually enter the Graph, Token, and Auth Endpoints.
|
||||
- **OAuth 2.0 token endpoint (v1)** (Token Endpoint)
|
||||
- **OAuth 2.0 authorization endpoint (v1)** (Auth Endpoint)
|
||||
|
||||
#### 5. Configure Azure AD in Rancher
|
||||
#### 6. Configure Azure AD in Rancher
|
||||
|
||||
To complete configuration, enter information about your AD instance in the Rancher UI.
|
||||
|
||||
@@ -188,7 +198,7 @@ To complete configuration, enter information about your AD instance in the Ranch
|
||||
|
||||
1. Click **AzureAD**.
|
||||
|
||||
1. Complete the **Configure Azure AD Account** form using the information you copied while completing [Copy Azure Application Data](#4-copy-azure-application-data).
|
||||
1. Complete the **Configure Azure AD Account** form using the information you copied while completing [Copy Azure Application Data](#5-copy-azure-application-data).
|
||||
|
||||
:::caution
|
||||
|
||||
@@ -353,4 +363,3 @@ Since the filter prevents Rancher from seeing that the user belongs to an exclud
|
||||
>- If you don't wish to upgrade to v2.7.0+ after the Azure AD Graph API is retired, you'll need to either:
|
||||
- Use the built-in Rancher auth or
|
||||
- Use another third-party auth system and set that up in Rancher. Please see the [authentication docs](authentication-config.md) to learn how to configure other open authentication providers.
|
||||
|
||||
|
||||
@@ -32,5 +32,6 @@ This feature enables kubectl to authenticate with the Rancher server and get a n
|
||||
3. FreeIPA
|
||||
4. OpenLDAP
|
||||
5. SAML providers: Ping, Okta, ADFS, Keycloak, Shibboleth
|
||||
6. Azure AD
|
||||
|
||||
When you first run kubectl, for example, `kubectl get pods`, you are prompted to pick an auth provider and log in with the Rancher server. The kubeconfig token is cached in the path where you run kubectl under `./.cache/token`. This token is valid until [it expires](../../api/api-tokens.md#disable-tokens-in-generated-kubeconfigs), or [gets deleted from the Rancher server](../../api/api-tokens.md#deleting-tokens). Upon expiration, you must log in with the Rancher server again to run the `kubectl get pods` command.
|
||||
|
||||
Reference in New Issue
Block a user