Chuyển đến nội dung chính

Bài 13: Kubernetes, AWS và Cloud Auth Methods

Kubernetes Auth Method (Service Account token review, bound namespaces, bound service accounts), AWS Auth Method (IAM auth, EC2 auth, cross-account), Azure Auth Method, GCP Auth Method, SPIFFE Auth Method (mới trong 1.21), best practices cho workload identity.

🔒 DevSecOps — Bài 13 Bài 13: Kubernetes, AWS và Cloud Auth Methods

HashiCorp Vault từ Cơ bản đến Nâng cao

Phần 3: Auth Methods - Xác thực và Ủy quyền

xdev.asia

1. Kubernetes Auth Method

Kubernetes Auth Method cho phép Pods trên Kubernetes xác thực với Vault bằng Kubernetes Service Account tokens. Đây là phương pháp xác thực tự nhiên nhất cho workloads chạy trên Kubernetes — không cần quản lý secrets riêng.

Kiến trúc

┌───────────────────┐                    ┌──────────────┐
│   Pod             │  1. Login với SA   │    Vault     │
│   (ServiceAccount)│     JWT token      │  K8s Auth    │
│                   │ ─────────────────▶ │              │
│                   │                    │              │
│                   │  4. Vault Token    │              │
│                   │ ◀───────────────── │              │
└───────────────────┘                    └──────┬───────┘
                                                │
                                       2. TokenReview API
                                          (verify SA token)
                                                │
                                                ▼
                                         ┌──────────────┐
                                         │  Kubernetes  │
                                         │  API Server  │
                                         └──────────────┘

Enable và cấu hình

# Enable Kubernetes auth
vault auth enable kubernetes

# Cấu hình — Vault chạy trong Kubernetes
vault write auth/kubernetes/config \
  kubernetes_host="https://kubernetes.default.svc:443"

# Cấu hình — Vault chạy ngoài Kubernetes
vault write auth/kubernetes/config \
  kubernetes_host="https://k8s-api.company.com:6443" \
  kubernetes_ca_cert=@/etc/vault/k8s-ca.pem \
  token_reviewer_jwt=@/etc/vault/k8s-reviewer-token

Tạo roles

# Role cho namespace cụ thể
vault write auth/kubernetes/role/webapp \
  bound_service_account_names="webapp-sa" \
  bound_service_account_namespaces="production" \
  token_policies="webapp-policy,db-readonly" \
  token_ttl=1h \
  token_max_ttl=4h

# Role cho nhiều namespaces
vault write auth/kubernetes/role/monitoring \
  bound_service_account_names="prometheus-sa,grafana-sa" \
  bound_service_account_namespaces="monitoring,observability" \
  token_policies="monitoring-readonly" \
  token_ttl=30m

# Role với wildcard (tất cả service accounts trong namespace)
vault write auth/kubernetes/role/dev-all \
  bound_service_account_names="*" \
  bound_service_account_namespaces="development" \
  token_policies="dev-readonly" \
  token_ttl=30m

# Alias name source
vault write auth/kubernetes/role/webapp \
  bound_service_account_names="webapp-sa" \
  bound_service_account_namespaces="production" \
  token_policies="webapp-policy" \
  alias_name_source="serviceaccount_name"

Login từ Pod

# Service Account token tự động mount tại Pod
SA_TOKEN=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token)

# Login
curl -s --request POST \
  --data "{\"jwt\": \"${SA_TOKEN}\", \"role\": \"webapp\"}" \
  ${VAULT_ADDR}/v1/auth/kubernetes/login | jq .

# Hoặc dùng Vault CLI
vault write auth/kubernetes/login \
  role=webapp \
  jwt=@/var/run/secrets/kubernetes.io/serviceaccount/token

Kubernetes RBAC cho Vault

# Vault cần ClusterRole để verify SA tokens
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: vault-token-reviewer
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: system:auth-delegator
subjects:
  - kind: ServiceAccount
    name: vault
    namespace: vault

2. AWS Auth Method

AWS Auth Method cho phép EC2 instances và Lambda functions xác thực với Vault bằng AWS IAM hoặc EC2 metadata — không cần quản lý secrets thủ công.

Hai loại AWS Auth

LoạiCách xác thựcUse case
IAM AuthKý STS GetCallerIdentityEC2, Lambda, ECS, EKS, bất kỳ AWS workload
EC2 AuthEC2 instance metadata (PKCS7 document)Chỉ EC2 instances

AWS IAM Auth

# Enable AWS auth
vault auth enable aws

# Cấu hình AWS credentials cho Vault
vault write auth/aws/config/client \
  access_key="AKIAIOSFODNN7EXAMPLE" \
  secret_key="wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY" \
  iam_server_id_header_value="vault.company.com"

# Tạo IAM role
vault write auth/aws/role/webapp \
  auth_type=iam \
  bound_iam_principal_arn="arn:aws:iam::123456789012:role/webapp-role" \
  token_policies="webapp-policy" \
  token_ttl=1h \
  token_max_ttl=4h

# Role cho nhiều IAM principals
vault write auth/aws/role/services \
  auth_type=iam \
  bound_iam_principal_arn='["arn:aws:iam::123456789012:role/service-a","arn:aws:iam::123456789012:role/service-b"]' \
  token_policies="services-policy"

# Cross-account (từ AWS account khác)
vault write auth/aws/config/sts/987654321098 \
  sts_role="arn:aws:iam::123456789012:role/vault-sts-assume"

vault write auth/aws/role/cross-account \
  auth_type=iam \
  bound_iam_principal_arn="arn:aws:iam::987654321098:role/external-app" \
  token_policies="cross-account-readonly"

Login từ AWS workload

# Từ EC2/Lambda/ECS — CLI
vault login -method=aws role=webapp

# API call
vault write auth/aws/login \
  role=webapp \
  iam_http_request_method="POST" \
  iam_request_url="$(echo -n 'https://sts.amazonaws.com/' | base64)" \
  iam_request_body="$(echo -n 'Action=GetCallerIdentity&Version=2011-06-15' | base64)" \
  iam_request_headers="..."

3. Azure Auth Method

# Enable Azure auth
vault auth enable azure

# Cấu hình
vault write auth/azure/config \
  tenant_id="<tenant-id>" \
  resource="https://management.azure.com/" \
  client_id="<vault-app-id>" \
  client_secret="<vault-app-secret>"

# Tạo role cho VM với Managed Identity
vault write auth/azure/role/webapp \
  bound_subscription_ids="<subscription-id>" \
  bound_resource_groups="production-rg" \
  bound_service_principal_ids="<managed-identity-principal-id>" \
  token_policies="webapp-policy" \
  token_ttl=1h

4. GCP Auth Method

# Enable GCP auth
vault auth enable gcp

# Cấu hình
vault write auth/gcp/config \
  credentials=@/etc/vault/gcp-credentials.json

# IAM auth (Service Account)
vault write auth/gcp/role/webapp \
  type="iam" \
  bound_service_accounts="[email protected]" \
  token_policies="webapp-policy" \
  token_ttl=1h

# GCE auth (Compute Engine instances)
vault write auth/gcp/role/gce-instances \
  type="gce" \
  bound_projects="my-project" \
  bound_zones="asia-southeast1-a,asia-southeast1-b" \
  bound_labels="env:production,team:platform" \
  token_policies="gce-policy"

5. SPIFFE Auth Method (Vault 1.21)

SPIFFE (Secure Production Identity Framework for Everyone) Auth Method là tính năng mới trong Vault 1.21, cho phép workloads xác thực bằng SPIFFE SVID (SPIFFE Verifiable Identity Document).

SPIFFE Concepts

Thuật ngữMô tả
SPIFFE IDURI dạng spiffe://trust-domain/workload-identifier
SVIDDocument chứng minh identity (X.509 cert hoặc JWT)
SPIRESPIFFE Runtime Environment — implementation phổ biến nhất
Trust DomainDomain of trust (ví dụ: company.com)
# Enable SPIFFE auth (Vault 1.21+)
vault auth enable spiffe

# Cấu hình trust domain
vault write auth/spiffe/config \
  spiffe_trust_domain="company.com" \
  spiffe_trust_bundle=@/etc/vault/spire-root-ca.pem

# Tạo role
vault write auth/spiffe/role/webapp \
  bound_spiffe_ids="spiffe://company.com/ns/production/sa/webapp" \
  token_policies="webapp-policy" \
  token_ttl=1h

# Wildcard matching
vault write auth/spiffe/role/production-all \
  bound_spiffe_id_patterns="spiffe://company.com/ns/production/*" \
  token_policies="production-readonly"

6. Workload Identity Best Practices

Chọn Auth Method phù hợp

PlatformAuth MethodGhi chú
KubernetesKubernetes AuthTự nhiên nhất cho K8s workloads
AWS EC2/Lambda/ECSAWS IAM AuthPreferred over EC2 auth
Azure VMs/FunctionsAzure AuthDùng Managed Identity
GCP GCE/GKE/FunctionsGCP AuthIAM hoặc GCE type
Multi-platform/SPIRESPIFFE AuthPlatform-agnostic identity
CI/CD (GitHub/GitLab)JWT AuthOIDC tokens từ CI platform
Legacy/On-prem appsAppRoleFallback cho non-cloud workloads

Least Privilege

  • Mỗi service/workload có role riêng — không share roles

  • Bind chặt: specific service account, namespace, project

  • Token TTL ngắn nhất có thể

  • Policies granular theo path cụ thể

Multi-cluster Kubernetes

# Mount riêng cho mỗi cluster
vault auth enable -path=k8s-prod kubernetes
vault auth enable -path=k8s-staging kubernetes

# Cấu hình riêng biệt
vault write auth/k8s-prod/config \
  kubernetes_host="https://prod-k8s-api:6443" \
  kubernetes_ca_cert=@/etc/vault/prod-ca.pem

vault write auth/k8s-staging/config \
  kubernetes_host="https://staging-k8s-api:6443" \
  kubernetes_ca_cert=@/etc/vault/staging-ca.pem

7. Tổng kết

  • Kubernetes Auth — standard cho K8s workloads, dùng Service Account token

  • AWS IAM Auth — preferred cho mọi AWS workloads, không cần static credentials

  • Azure/GCP Auth — tương tự cho Azure Managed Identity và GCP Service Accounts

  • SPIFFE Auth (1.21) — platform-agnostic, phù hợp multi-cloud/hybrid

Bài tiếp theo sẽ đi sâu vào Vault Policies — cơ chế kiểm soát quyền truy cập chi tiết với ACL, Sentinel và RBAC.