時価総額: $2.2043T 0.58%
ボリューム(24時間): $56.8553B 3.76%
  • 時価総額: $2.2043T 0.58%
  • ボリューム(24時間): $56.8553B 3.76%
  • 恐怖と貪欲の指数:
  • 時価総額: $2.2043T 0.58%
暗号
トピック
暗号化
ニュース
暗号造園
動画
トップニュース
暗号
トピック
暗号化
ニュース
暗号造園
動画
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

暗号通貨のニュース記事

IAM Identity Center を使用した Tableau から Amazon Redshift へのシングル サインオン

2024/06/04 01:44

このブログ投稿は、Salesforce の Sid Wray および Jake Koskela、Tableau の Adiascar Cisneros との共著です。 Amazon Redshift は、あらゆる規模のワークロードに対応できるように構築された、高速でスケーラブルなクラウド データ ウェアハウスです。 Amazon Redshift をデータ ウェアハウスとして使用すると、高度なクエリ最適化を使用して複雑なクエリを実行し、結果を Tableau に迅速に配信できます。Tableau は、アナリストが企業全体で洞察を効率的に準備、発見、共有するための包括的な機能と接続オプションのセットを提供します。シングルサインオン機能を使用して Amazon Redshift と Tableau を統合したいお客様のために、認証と認可をシームレスに実装するための AWS IAM Identity Center 統合を導入しました。

IAM Identity Center を使用した Tableau から Amazon Redshift へのシングル サインオン

Amazon Redshift is a fast, fully managed, petabyte-scale cloud data warehouse service that makes it simple and cost-effective to analyze all your data using standard SQL and advanced analytics capabilities. It’s designed to handle massive volumes of structured and semi-structured data, and it scales up or down quickly to meet your changing needs.

Amazon Redshift は、高速でフルマネージドのペタバイト規模のクラウド データ ウェアハウス サービスで、標準 SQL と高度な分析機能を使用してすべてのデータを簡単かつコスト効率よく分析できます。大量の構造化データおよび半構造化データを処理できるように設計されており、変化するニーズに合わせて迅速にスケールアップまたはスケールダウンできます。

With Amazon Redshift as your data warehouse, you can run complex queries using sophisticated query optimization to quickly deliver results to Tableau, which offers a comprehensive set of capabilities and connectivity options for analysts to efficiently prepare, discover, and share insights across the enterprise. For customers who want to integrate Amazon Redshift with Tableau using single sign-on capabilities, we introduced AWS IAM Identity Center integration to seamlessly implement authentication and authorization.

Amazon Redshift をデータ ウェアハウスとして使用すると、高度なクエリ最適化を使用して複雑なクエリを実行し、結果を Tableau に迅速に配信できます。Tableau は、アナリストが企業全体で洞察を効率的に準備、発見、共有するための包括的な機能と接続オプションのセットを提供します。シングルサインオン機能を使用して Amazon Redshift と Tableau を統合したいお客様のために、認証と認可をシームレスに実装するための AWS IAM Identity Center 統合を導入しました。

IAM Identity Center provides capabilities to centrally manage single sign-on access to AWS accounts and applications. Redshift now integrates with IAM Identity Center, and supports trusted identity propagation, making it possible to integrate with third-party identity providers (IdP) such as Microsoft Entra ID (Azure AD), Okta, Ping, and OneLogin. This integration positions Amazon Redshift as an IAM Identity Center-managed application, enabling you to use database role-based access control on your data warehouse for enhanced security. Role-based access control allows you to apply fine grained access control using row level, column level, and dynamic data masking in your data warehouse.

IAM Identity Center は、AWS アカウントおよびアプリケーションへのシングル サインオン アクセスを一元管理する機能を提供します。 Redshift は IAM Identity Center と統合され、信頼できる ID 伝播をサポートするようになり、Microsoft Entra ID (Azure AD)、Okta、Ping、OneLogin などのサードパーティ ID プロバイダー (IdP) と統合できるようになりました。この統合により、Amazon Redshift が IAM Identity Center で管理されるアプリケーションとして位置付けられ、データ ウェアハウスでデータベース ロールベースのアクセス制御を使用してセキュリティを強化できるようになります。ロールベースのアクセス制御を使用すると、データ ウェアハウスで行レベル、列レベル、および動的データ マスキングを使用して、きめ細かいアクセス制御を適用できます。

AWS and Tableau have collaborated to enable single sign-on support for accessing Amazon Redshift from Tableau. Tableau now supports single sign-on capabilities with Amazon Redshift connector to simplify the authentication and authorization. The Tableau Desktop 2024.1 and Tableau Server 2023.3.4 releases support trusted identity propagation with IAM Identity Center. This allows users to seamlessly access Amazon Redshift data within Tableau using their external IdP credentials without needing to specify AWS Identity and Access Management (IAM) roles in Tableau. This single sign-on integration is available for Tableau Desktop, Tableau Server, and Tableau Prep.

AWS と Tableau は協力して、Tableau から Amazon Redshift にアクセスするためのシングル サインオン サポートを有効にしました。 Tableau は、認証と認可を簡素化するために、Amazon Redshift コネクタを使用したシングル サインオン機能をサポートするようになりました。 Tableau Desktop 2024.1 および Tableau Server 2023.3.4 リリースは、IAM ID センターによる信頼された ID の伝播をサポートしています。これにより、ユーザーは Tableau で AWS Identity and Access Management (IAM) ロールを指定することなく、外部 IdP 認証情報を使用して Tableau 内の Amazon Redshift データにシームレスにアクセスできるようになります。このシングル サインオン統合は、Tableau Desktop、Tableau Server、および Tableau Prep で利用できます。

In this post, we outline a comprehensive guide for setting up single sign-on to Amazon Redshift using integration with IAM Identity Center and Okta as the IdP. By following this guide, you’ll learn how to enable seamless single sign-on authentication to Amazon Redshift data sources directly from within Tableau Desktop, streamlining your analytics workflows and enhancing security.

この投稿では、IAM Identity Center および IdP としての Okta との統合を使用して、Amazon Redshift へのシングル サインオンを設定するための包括的なガイドの概要を説明します。このガイドに従うことで、Tableau Desktop 内から Amazon Redshift データ ソースへのシームレスなシングル サインオン認証を直接有効にして、分析ワークフローを合理化し、セキュリティを強化する方法を学びます。

Prerequisites

前提条件

Before you begin implementing the solution, make sure that you have the following in place:

ソリューションの実装を開始する前に、次のものが整っていることを確認してください。

Walkthrough

ウォークスルー

In this walkthrough, you build the solution with following steps:

このチュートリアルでは、次の手順でソリューションを構築します。

Set up the Okta OIDC application

Okta OIDC アプリケーションをセットアップする

To create an OIDC web app in Okta, follow the instructions in this video, or use the following steps to create the wep app in Okta admin console:

Okta で OIDC Web アプリを作成するには、このビデオの手順に従うか、次の手順に従って Okta 管理コンソールで wep アプリを作成します。

Note: The Tableau Desktop redirect URLs should always use localhost. The examples below also use localhost for the Tableau Server hostname for ease of testing in a test environment. For this setup, you should also access the server at localhost in the browser. If you decide to use localhost for early testing, you will also need to configure the gateway to accept localhost using this tsm command:

注: Tableau Desktop リダイレクト URL は常に localhost を使用する必要があります。以下の例では、テスト環境でのテストを容易にするために、Tableau Server ホスト名に localhost も使用しています。この設定では、ブラウザでローカルホストのサーバーにアクセスする必要もあります。初期のテストに localhost を使用することにした場合は、次の tsm コマンドを使用して localhost を受け入れるようにゲートウェイを構成する必要もあります。

In a production environment, or Tableau Cloud, you should use the full hostname that your users will access Tableau on the web, along with https. If you already have an environment with https configured, you may skip the localhost configuration and use the full hostname from the start.

実稼働環境または Tableau Cloud では、ユーザーが Web 上の Tableau にアクセスする完全なホスト名を https とともに使用する必要があります。 https が設定された環境がすでにある場合は、localhost 設定をスキップして、最初から完全なホスト名を使用できます。

Set up the Okta authorization server

Okta 認証サーバーをセットアップする

Okta allows you to create multiple custom authorization servers that you can use to protect your own resource servers. Within each authorization server you can define your own OAuth 2.0 scopes, claims, and access policies. If you have an Okta Developer Edition account, you already have a custom authorization server created for you called default.

Okta を使用すると、独自のリソース サーバーを保護するために使用できる複数のカスタム承認サーバーを作成できます。各認可サーバー内で、独自の OAuth 2.0 スコープ、クレーム、アクセス ポリシーを定義できます。 Okta Developer Edition アカウントをお持ちの場合は、デフォルトと呼ばれるカスタム認証サーバーがすでに作成されています。

For this blog post, we use the default custom authorization server. If your application has requirements such as requiring more scopes, customizing rules for when to grant scopes, or you need more authorization servers with different scopes and claims, then you can follow this guide.

このブログ投稿では、デフォルトのカスタム認証サーバーを使用します。アプリケーションに、より多くのスコープが必要な場合、スコープを付与するタイミングに関するルールのカスタマイズなどの要件がある場合、または異なるスコープとクレームを持つさらに多くの認可サーバーが必要な場合は、このガイドに従うことができます。

Set up the Okta claims

Okta クレームを設定する

Tokens contain claims that are statements about the subject (for example: name, role, or email address). For this example, we use the default custom claim sub. Follow this guide to create claims.

トークンには、件名 (名前、役割、電子メール アドレスなど) に関するステートメントであるクレームが含まれています。この例では、デフォルトのカスタム クレーム サブルーチンを使用します。このガイドに従ってクレームを作成します。

Setup the Okta access policies and rules

Okta のアクセス ポリシーとルールをセットアップする

Access policies are containers for rules. Each access policy applies to a particular OpenID Connect application. The rules that the policy contains define different access and refresh token lifetimes depending on the nature of the token request. In this example, you create a simple policy for all clients as shown in Figure 7 that follows. Follow this guide to create access policies and rules.

アクセス ポリシーはルールのコンテナです。各アクセス ポリシーは、特定の OpenID Connect アプリケーションに適用されます。ポリシーに含まれるルールは、トークン リクエストの性質に応じて、さまざまなアクセス トークンの有効期間とリフレッシュ トークンの有効期間を定義します。この例では、次の図 7 に示すように、すべてのクライアントに対して単純なポリシーを作成します。このガイドに従って、アクセス ポリシーとルールを作成します。

Rules for access policies define token lifetimes for a given combination of grant type, user, and scope. They’re evaluated in priority order and after a matching rule is found, no other rules are evaluated. If no matching rule is found, then the authorization request fails. This example uses the role depicted in Figure 8 that follows. Follow this

アクセス ポリシーのルールは、付与タイプ、ユーザー、スコープの特定の組み合わせに対するトークンの有効期間を定義します。これらは優先順位に従って評価され、一致するルールが見つかった後は、他のルールは評価されません。一致するルールが見つからない場合、認可リクエストは失敗します。この例では、次の図 8 に示す役割を使用します。これに従ってください

オリジナルソース:4443b82727f03ab3429b3d4ce598be6f

免責事項:info@kdj.com

提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。

このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

2026年08月07日 に掲載されたその他の記事