For applications that run on an ACK cluster, obtain temporary STS credentials for a specific RAM role without static credentials, by combining an OIDC token injected through ACK RRSA for federated authentication with PAM authorization.
How it works
An M2M client application that runs in an ACK pod calls the IDaaS SDK. The SDK uses the Kubernetes ServiceAccount OIDC token injected by ACK RRSA to complete federated authentication for the M2M client application. The SDK then uses the resulting token to call PAM and obtain temporary STS credentials for the target cloud role. The application does not need to store a client secret or a long-term AccessKey.
Prerequisites
The Machine Identity Management and Privileged Access Management capabilities of IDaaS EIAM are enabled.
You have RAM administrative permissions and have identified the least privileges that the target RAM role needs.
You have created an ACK managed cluster (version 1.22 or later) and have ACK administrative permissions.
The workload pod can reach the public endpoint of the EIAM instance.
References
Configuration steps
Step 1: Add a cloud account and system cloud role in Asset Management
In the IDaaS EIAM console, go to Asset Management > Cloud Identity and add the target Alibaba Cloud account. Follow the console prompts to configure the identity provider, system cloud role, and detection items, and confirm that both the cloud account and the system cloud role are in the Available state.
Step 2: Add the target cloud role that obtains the final STS credentials
In Cloud Role Management for the managed cloud account, add the target RAM role. Confirm that the cloud role is in the Enabled and Available state. On the RAM side, the role's trust policy trusts the corresponding identity provider as guided by the IDaaS console, and the role's permission policy grants only the resource permissions that your workload requires.
Step 3: Create an M2M client and configure ACK OIDC federated credentials
If an ACK federated trust source already exists, you can select it directly when you create an application federated credential. You do not need to create one for each M2M client.
In the left-side navigation pane, click M2M Application.
Click Add Application, and select the OIDC with M2M Application type.
Enter the application name and other basic information, complete the creation, and record the
client_id.
3.1 Enable ACK RRSA and inject an OIDC token into the pod
On the Basic Information tab of the ACK cluster details page, go to Security and Auditing, turn on RRSA OIDC, and wait until the cluster returns to the Running state.
On the cluster list page, click the target cluster name, and then in the left-side navigation pane, choose Add-ons.
On the Add-ons page, find the
ack-pod-identity-webhookadd-on, and click Install in the lower-right corner of the add-on.Create or configure an RRSA RAM role. This role trusts the cluster's OIDC identity provider and restricts
oidc:subtosystem:serviceaccount:<namespace>:<serviceaccount>. This role is used only to trigger RRSA injection and does not replace the target cloud role in PAM.Add the label
pod-identity.alibabacloud.com/injection: 'on'to the workload namespace, and add the annotationpod-identity.alibabacloud.com/role-name: <rrsa-ram-role-name>to the workload ServiceAccount.After you deploy the workload pod, run
kubectl -n <namespace> get pod <pod-name> -o yamland confirm that theALIBABA_CLOUD_OIDC_TOKEN_FILEenvironment variable and therrsa-oidc-tokenmount are injected.
For detailed instructions, see Use RRSA for pod-level access control.
3.2 Create or select an ACK OIDC federated trust source
Go to Sign-in > Authentication Configuration > Federated Trust Source Management, and add a federated trust source of the OIDC type.
Click Add federated trust source, and select the OIDC option.
Configure the parameters:
Federated trust source name: This document uses
aliyun_ack.Network endpoint: This document uses Shared endpoint. IDaaS uses the network endpoint address to access the Issuer URL and obtain the public key over the OIDC protocol.
Trust source: This document uses Issuer URL resolution.
Issuer: The identity provider identifier. Obtain the provider URL from the ACK cluster information and enter it.
Audience identifier:
sts.aliyuncs.com(a fixed value for ACK).Trust condition: A condition expression for further authentication of ACK. This is optional and is not used in this document. If needed, see Use federated credential expressions to configure it.
Complete the configuration.
3.3 Create an OIDC application federated credential for the M2M client
Go to Application Management > M2M Application Management.
Find the M2M client application, and click Manage.
In General > Authentication Management, select the OIDC authentication type.
Click Add federated credential, and configure the following:
Federated trust source: Select
aliyun_ack.Federated credential name: This document uses ack-oidc-credential. The application must pass this name when it obtains an M2M token, and the name must exactly match applicationFederatedCredentialName in client-config.json.
Validation condition mode: Select Kubernetes mode.
Namespace: The namespace where the container pod is deployed. This document uses
default. The default namespace in Kubernetes isdefault; specify a value based on your environment.ServiceAccount: The ServiceAccount used by the container pod that runs the application. This example uses
default. The default ServiceAccount in Kubernetes isdefault; specify a value based on your container pod.
Complete the configuration.
Step 4: Grant PAM feature permissions
In the left-side navigation pane, click Permission Center, and then select Feature Permission Management.
On the Feature Permission Management page, search for the
Privileged Access Managementapplication, and click Authorization Management.Select Application Authorization. In Authorized Application, select the M2M client that you created in Step 3. In Select Permissions, search for and grant Obtain cloud role access credentials (
cloud_account_role:obtain_access_credential).
Step 5: Grant data permissions for the cloud role
In the left-side navigation pane, click Permission Center, and then select Data Permission Management.
Add an authorization rule, enter its basic information, and then complete the creation.
Select the authorization rule that you created, and click Permission Management.
On the Associate Identity tab, select Application, and then select the M2M client that you created in Step 3.
On the Asset Management tab, select Cloud Role, click Add Asset, and select the target cloud role from Step 2 that obtains the final STS token.
Step 6: Download and import the IDaaS SDK
On GitHub, get the latest version of the IDaaS SDK. Only Java and Python are currently supported.
Configure the dependencies as described in the SDK
README.md.
Step 7: Create the SDK configuration file
Create a
client-config.jsonfile. By default, you can place it at~/.cloud_idaas/client-config.json.On GitHub, find the
IDaaS Core SDK.In the SDK's GitHub repository, review the
README.mdfile, find the OIDC client-config.json example, and copy it into theclient-config.jsonfile that you created. The following example shows the configuration:
{
"idaasInstanceId": "idaas_xxx",
"clientId": "app_xxx",
"issuer": "https://xxx/api/v2/iauths_system/oauth2",
"tokenEndpoint": "https://xxx/api/v2/iauths_system/oauth2/token",
"scope": "urn:cloud:idaas:pam|cloud_account_role:obtain_access_credential",
"openApiEndpoint": "eiam.[region_id].aliyuncs.com",
"developerApiEndpoint": "eiam-developerapi.[region_id].aliyuncs.com",
"authnConfiguration": {
"identityType": "CLIENT",
"authnMethod": "OIDC",
"applicationFederatedCredentialName": "ack-oidc-credential",
"clientDeployEnvironment": "KUBERNETES",
"oidcTokenFilePathEnvVarName": "ALIBABA_CLOUD_OIDC_TOKEN_FILE"
},
"httpConfiguration": {
"connectTimeout": 5000,
"readTimeout": 10000
}
}Parameter | Value | Description |
|
| The ID of the IDaaS instance. |
|
| The |
|
| Replace |
|
| The IDaaS token endpoint. |
| A fixed value. See the JSON configuration above. | The scope that PAM uses to obtain cloud role access credentials. |
|
| Optional. |
|
| Required. |
| ||
└ |
| A fixed value. |
└ |
| A fixed value. Uses OIDC federated authentication. |
└ |
| The name of the application federated credential that you created in Step 3.3. |
└ |
| A fixed value that indicates the application runs in a Kubernetes pod. |
└ |
| A fixed value. The SDK reads the OIDC token from the token file path specified by this environment variable. |
| ||
└ |
| The maximum time to wait for a connection to be established, in milliseconds. |
└ |
| The maximum time to wait for a server response after the connection is established, in milliseconds. |
Step 8: Integrate the code
Complete the following operations by referring to the SDK quick start:
Initialize the IDaaS Core SDK.
Pass in the target cloud role ARN to create the Alibaba Cloud credentials provider.
Obtain the temporary STS credentials.
public static void main(String[] args) {
// 1. Initialize the IDaaS Core SDK
IDaaSCredentialProviderFactory.init();
// 2. Create the Alibaba Cloud credentials provider
AlibabaCloudCredentialsProvider credentialsProvider =
IDaaSPamAklessCredentialFactory.getAlibabaCloudCredentialsProvider(
"acs:ram::123456789:role/your-role-name"
);
// 3. Obtain the credentials
CredentialModel credentials = credentialsProvider.getCredentials();
System.out.println(credentials.getAccessKeyId());
System.out.println(credentials.getAccessKeySecret());
System.out.println(credentials.getSecurityToken());
}Verify the result
Confirm that RRSA has injected the
ALIBABA_CLOUD_OIDC_TOKEN_FILEenvironment variable and therrsa-oidc-tokenmount into the workload pod.Place the configuration file from Step 7 at the default path
~/.cloud_idaas/client-config.json.Deploy the workload pod that uses the namespace and ServiceAccount from Step 3.3.
Run the application in the pod and confirm that it can obtain temporary STS credentials.
Use the temporary credentials to call the cloud service API operations that the target cloud role's permission policy allows.