|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Amazon RedshiftとThoughtspotのAI駆動型分析サービスのこの組み合わせにより、組織は生データを実行可能な洞察に変換することができます

This post shows how to integrate ThoughtSpot with Amazon Redshift using the IAM Identity Center authentication. The combination of Amazon Redshift and ThoughtSpot’s AI-powered analytics service enables organizations to transform their raw data into actionable insights with unprecedented speed and efficiency.
この投稿では、IAM Identity Center認証を使用して、ThoughtspotをAmazon Redshiftと統合する方法を示しています。 Amazon RedshiftとThoughtspotのAI駆動型分析サービスの組み合わせにより、組織は未処理の速度と効率を備えた実行可能な洞察に生データを変換することができます。
Tens of thousands of customers use Amazon Redshift to process large amounts of data, modernize their data analytics workloads, and provide insights for their business users.
数万人の顧客がAmazon Redshiftを使用して、大量のデータを処理し、データ分析ワークロードを近代化し、ビジネスユーザーに洞察を提供します。
To streamline this integration even further, Amazon Redshift now supports AWS IAM Identity Center integration with ThoughtSpot. This single sign-on (SSO) integration spans ThoughtSpot’s entire cloud landscape and can be used for both embedded and standalone analytics implementations.
この統合をさらに合理化するために、Amazon RedshiftはAWS Iam Identity Centerの統合とThoughtspotをサポートするようになりました。このシングルサインオン(SSO)統合は、Thoughtspotのクラウドランドスケープ全体に及び、組み込みとスタンドアロンの両方の分析の実装に使用できます。
Prior to the IAM Identity Center integration, ThoughtSpot users didn’t have native connectivity to integrate Amazon Redshift with their identity providers (IdPs), which can provide unified governance and identity propagation across multiple AWS services like AWS Lake Formation and Amazon Simple Storage Service (Amazon S3).
IAM Identity Centerの統合の前に、Thoughtspotユーザーは、Amazon RedshiftをIDプロバイダー(IDP)と統合するためのネイティブ接続を持っていませんでした。これは、AWS Lake FormationやAmazon Simple Storage Service(Amazon S3)などの複数のAWSサービスで統一ガバナンスとアイデンティティの伝播を提供できます。
Now, ThoughtSpot users can natively connect to Amazon Redshift using the IAM Identity Center integration, which streamlines data analytics access management while maintaining robust security. By configuring Amazon Redshift as an AWS managed application, organizations benefit from SSO capabilities with trusted identity propagation and a trusted token issuer (TTI). The IAM Identity Center integration with Amazon Redshift provides centralized user management, automatically synchronizing access permissions with organizational changes—whether employees join, transition roles, or leave the organization. The solution uses Amazon Redshift role-based access control features that align with IdP groups synced in IAM Identity Center. Organizations can further enhance their security posture by using Lake Formation to define granular access control permissions on catalog resources for IdP identities. From a compliance and security standpoint, the integration offers comprehensive audit trails by logging end-user identities both in Amazon Redshift and AWS CloudTrail, providing visibility into data access patterns and user activities.
現在、Thoughtspotユーザーは、IAM Identity Center Integrationを使用してAmazon Redshiftにネイティブに接続できます。これにより、堅牢なセキュリティを維持しながら、データ分析アクセス管理を合理化できます。 Amazon RedshiftをAWSマネージドアプリケーションとして構成することにより、組織は信頼できるアイデンティティ伝播と信頼できるトークン発行者(TTI)を備えたSSO機能の恩恵を受けます。 Amazon RedshiftとのIAM Identity Centerの統合により、集中ユーザー管理は、アクセス許可を組織の変更と自動的に同期させ、従業員が参加、移行の役割、または組織を離れるかどうかを自動的に同期させます。このソリューションは、IAM Identity Centerで同期されたIDPグループと整合するAmazon Redshiftの役割ベースのアクセス制御機能を使用します。組織は、IDP IDのカタログリソースの粒状アクセス制御許可を定義するために、湖の形成を使用することにより、セキュリティの姿勢をさらに強化できます。コンプライアンスとセキュリティの観点から、統合は、Amazon RedshiftとAWS CloudTrailの両方でエンドユーザーのアイデンティティを記録することにより、包括的な監査証跡を提供し、データアクセスパターンとユーザーアクティビティの可視性を提供します。
Dime Dimovski, a Data Warehousing Architect at Merck, shares:
MerckのデータウェアハウジングアーキテクトであるDime Dimovskiは、共有しています。
“The recent integration of Amazon Redshift with our identity access management center will significantly enhance our data access management because we can propagate user identities across various tools. By using OAuth authentication from ThoughtSpot to Amazon Redshift, we will benefit from a seamless single sign-on experience—giving us granular access controls as well as the security and efficiency we need.”
「Amazon RedshiftのIDACHON Access Management Centerの最近の統合は、さまざまなツールでユーザーのアイデンティティを伝播できるため、データアクセス管理を大幅に強化します。ThoughtspotからAmazon RedshiftまでのOAuth認証を使用することにより、シームレスなシングルサインオンエクスペリエンスから利益を得ます。
In this post, we walk you through the process of setting up ThoughtSpot integration with Amazon Redshift using IAM Identity Center authentication. The solution provides a secure, streamlined analytics environment that empowers your team to focus on what matters most: discovering and sharing valuable business insights.
この投稿では、IAM Identity Center認証を使用してAmazon Redshiftとの思考スポット統合をセットアップするプロセスを説明します。このソリューションは、あなたのチームが最も重要なこと、つまり貴重なビジネス洞察を発見し共有することに集中できるようにする、安全で合理化された分析環境を提供します。
Solution overview
解決策の概要
The following diagram illustrates the architecture of the ThoughtSpot SSO integration with Amazon Redshift, IAM Identity Center, and your IdP.
次の図は、Amazon Redshift、IAM Identity Center、およびIDPとの思考スポットSSO統合のアーキテクチャを示しています。
The solution includes the following steps:
ソリューションには次の手順が含まれています。
In this post, you will use the following steps to build the solution:
この投稿では、次の手順を使用してソリューションを構築します。
Prerequisites
前提条件
Before you begin implementing the solution, you must have the following in place:
ソリューションの実装を開始する前に、次のように配置する必要があります。
Set up an OIDC application
OIDCアプリケーションを設定します
In this section, we’ll show you the step-by-step process to set up an OIDC application using both Okta and EntraID as the identity providers.
このセクションでは、OKTAとENTRIDの両方をIDプロバイダーとして使用してOIDCアプリケーションを設定するための段階的なプロセスを紹介します。
Set up an Okta OIDC application
OKTA OIDCアプリケーションをセットアップします
Complete the following steps to set up an Okta OIDC application:
OKTA OIDCアプリケーションをセットアップするには、次の手順を完了します。
Set up an EntraID OIDC application
Entrad oidcアプリケーションをセットアップします
To create your EntraID application, follow these steps:
Entradアプリケーションを作成するには、次の手順に従ってください。
The secret value will only be presented one time; after that you can’t read it. Make sure to copy it now. If you fail to save it, you must generate a new client secret.
秘密の値は1回のみ提示されます。その後、あなたはそれを読むことができません。今すぐコピーしてください。保存できない場合は、新しいクライアントの秘密を生成する必要があります。
If you’re setting up for the first time, you can see Add to the right of the application ID URI.
初めて設定している場合は、アプリケーションID URIの右側にADDを確認できます。
Set up a TTI in IAM Identity Center
IAM Identity CenterにTTIを設定します
Assuming you have completed the prerequisites, you will establish your IdP as a TTI in your delegated administration account. To create a TTI, refer to How to add a trusted token issuer to the IAM Identity Center console. In this post, we walk through the steps to set up a TTI for both Okta and EntraID.
前提条件を完了したと仮定すると、委任された管理アカウントでIDPをTTIとして確立します。 TTIを作成するには、IAM Identity Centerコンソールに信頼できるトークン発行者を追加する方法を参照してください。この投稿では、OKTAとENTRIDの両方にTTIを設定するために、手順を進めます。
Set up a TTI for Okta
OKTAのTTIをセットアップします
To get the issuer URL from Okta, complete the following steps:
OKTAから発行者URLを取得するには、次の手順を完了します。
Set up a TTI for EntraID
EntradのためにTTIを設定します
Complete the following steps to set up a TTI for EntraID:
以下の手順を完了して、ENTRIDのためにTTIを設定します。
Next, you need to find the tenant ID value from EntraID.
次に、EntRadからテナントID値を見つける必要があります。
Set up client connections and TTIs in Amazon Redshift
Amazon Redshiftでクライアント接続とTTIをセットアップします
In this step, we configure the Amazon Redshift applications that exchange externally generated tokens to use the TTI you created in the previous step. Also, the audience claim (or aud claim) from your IdP must be specified. You need to collect the audience value from the respective IdP.
このステップでは、外部から生成されたトークンを交換して、前のステップで作成したTTIを使用するAmazon Redshiftアプリケーションを構成します。また、IDPからの視聴者の主張(またはAUD請求)を指定する必要があります。それぞれのIDPから視聴者の価値を収集する必要があります。
Acquire the audience value from Okta
Oktaから視聴者の価値を取得します
To acquire the audience value from Okta, complete the following steps:
OKTAから視聴者の価値を取得するには、次の手順を完了します。
Acquire the audience value from EntraID
Entradから聴衆の価値を取得します
Similarly, to get the audience value EntraID, complete the following steps:
同様に、視聴者の価値を吸収するために、次の手順を完了します。
Configure the application
アプリケーションを構成します
After you collect the audience value from the respective IdP, you need to configure the
それぞれのIDPから聴衆の値を収集した後、あなたは
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































