|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Amazon Redshift와 Thoughtspot의 AI 기반 분석 서비스의 조합은 조직이 원시 데이터를 실행 가능한 통찰력으로 변환 할 수 있습니다.

This post shows how to integrate ThoughtSpot with Amazon Redshift using the IAM Identity Center authentication. The combination of Amazon Redshift and ThoughtSpot’s AI-powered analytics service enables organizations to transform their raw data into actionable insights with unprecedented speed and efficiency.
이 게시물은 IAM Identity Center 인증을 사용하여 Thoughtspot을 Amazon Redshift와 통합하는 방법을 보여줍니다. Amazon Redshift와 Thoughtspot의 AI 기반 분석 서비스의 조합을 통해 조직은 원시 데이터를 전례없는 속도와 효율성으로 실행 가능한 통찰력으로 변환 할 수 있습니다.
Tens of thousands of customers use Amazon Redshift to process large amounts of data, modernize their data analytics workloads, and provide insights for their business users.
수만 명의 고객이 Amazon Redshift를 사용하여 대량의 데이터를 처리하고 데이터 분석 워크로드를 현대화하며 비즈니스 사용자에게 통찰력을 제공합니다.
To streamline this integration even further, Amazon Redshift now supports AWS IAM Identity Center integration with ThoughtSpot. This single sign-on (SSO) integration spans ThoughtSpot’s entire cloud landscape and can be used for both embedded and standalone analytics implementations.
이 통합을 더욱 간소화하기 위해 Amazon Redshift는 이제 AWS IAM Identity Center 통합과 ThinkingSpot과의 통합을 지원합니다. 이 SSO (Single Sign-On) 통합은 ThinkingSpot의 전체 클라우드 환경에 걸쳐 있으며 내장 및 독립형 분석 구현에 사용할 수 있습니다.
Prior to the IAM Identity Center integration, ThoughtSpot users didn’t have native connectivity to integrate Amazon Redshift with their identity providers (IdPs), which can provide unified governance and identity propagation across multiple AWS services like AWS Lake Formation and Amazon Simple Storage Service (Amazon S3).
IAM Identity Center 통합 이전에 ThinksPot 사용자는 AWS Lake Formation 및 Amazon Simple Storage Service (Amazon S3)와 같은 여러 AWS 서비스에서 통합 거버넌스 및 신원 전파를 제공 할 수있는 IDP (Idps)와 Amazon Redshift를 통합하기위한 기본 연결이 없었습니다.
Now, ThoughtSpot users can natively connect to Amazon Redshift using the IAM Identity Center integration, which streamlines data analytics access management while maintaining robust security. By configuring Amazon Redshift as an AWS managed application, organizations benefit from SSO capabilities with trusted identity propagation and a trusted token issuer (TTI). The IAM Identity Center integration with Amazon Redshift provides centralized user management, automatically synchronizing access permissions with organizational changes—whether employees join, transition roles, or leave the organization. The solution uses Amazon Redshift role-based access control features that align with IdP groups synced in IAM Identity Center. Organizations can further enhance their security posture by using Lake Formation to define granular access control permissions on catalog resources for IdP identities. From a compliance and security standpoint, the integration offers comprehensive audit trails by logging end-user identities both in Amazon Redshift and AWS CloudTrail, providing visibility into data access patterns and user activities.
이제 Thoughtspot 사용자는 IAM Identity Center 통합을 사용하여 기본적으로 Amazon Redshift에 연결하여 데이터 분석 액세스 관리를 간소화하면서 강력한 보안을 유지할 수 있습니다. Amazon Redshift를 AWS 관리 응용 프로그램으로 구성함으로써 조직은 신뢰할 수있는 신원 전파 및 신뢰할 수있는 토큰 발급자 (TTI)를 통해 SSO 기능의 혜택을받습니다. Amazon Redshift와의 IAM Identity Center 통합은 중앙 집중식 사용자 관리를 제공하며 직원이 참여하거나 전환 또는 조직을 떠나는 경우 직원과 같은 조직 변경과 액세스 권한을 자동으로 동기화합니다. 이 솔루션은 IAM Identity Center에 동기화 된 IDP 그룹과 일치하는 Amazon Redshift 역할 기반 액세스 제어 기능을 사용합니다. 조직은 Lake Formation을 사용하여 IDP ID를위한 카탈로그 리소스에 대한 세분화 된 액세스 제어 권한을 정의함으로써 보안 자세를 더욱 향상시킬 수 있습니다. 규정 준수 및 보안 관점에서 통합은 Amazon Redshift 및 AWS CloudTrail에 최종 사용자 ID를 기록하여 데이터 액세스 패턴 및 사용자 활동에 대한 가시성을 제공하여 포괄적 인 감사 트레일을 제공합니다.
Dime Dimovski, a Data Warehousing Architect at Merck, shares:
Merck의 데이터웨어 하우스 아키텍트 인 Dime Dimovski는 다음과 같습니다.
“The recent integration of Amazon Redshift with our identity access management center will significantly enhance our data access management because we can propagate user identities across various tools. By using OAuth authentication from ThoughtSpot to Amazon Redshift, we will benefit from a seamless single sign-on experience—giving us granular access controls as well as the security and efficiency we need.”
“최근 Amazon Redshift와 Identity Access Management Center와의 통합은 다양한 도구에서 사용자 ID를 전파 할 수 있기 때문에 Data Access Management Center를 크게 향상시킬 것입니다. Thoughtspot에서 Amazon Redshift로 OAUTH 인증을 사용하여 원활한 단일 사인 온 경험을 활용하여 보안 및 효율성을 활용할 수 있습니다. "
In this post, we walk you through the process of setting up ThoughtSpot integration with Amazon Redshift using IAM Identity Center authentication. The solution provides a secure, streamlined analytics environment that empowers your team to focus on what matters most: discovering and sharing valuable business insights.
이 게시물에서는 IAM Identity Center 인증을 사용하여 Amazon Redshift와 Thoughtspot 통합을 설정하는 프로세스를 안내합니다. 이 솔루션은 안전하고 간소화 된 분석 환경을 제공하여 팀이 가장 중요한 것에 집중할 수있게 해주는 귀중한 비즈니스 통찰력을 발견하고 공유 할 수 있습니다.
Solution overview
솔루션 개요
The following diagram illustrates the architecture of the ThoughtSpot SSO integration with Amazon Redshift, IAM Identity Center, and your IdP.
다음 다이어그램은 Amazon Redshift, IAM Identity Center 및 IDP와의 Thoughtspot SSO 통합의 아키텍처를 보여줍니다.
The solution includes the following steps:
솔루션에는 다음 단계가 포함됩니다.
In this post, you will use the following steps to build the solution:
이 게시물에서는 다음 단계를 사용하여 솔루션을 작성합니다.
Prerequisites
전제 조건
Before you begin implementing the solution, you must have the following in place:
솔루션 구현을 시작하기 전에 다음과 같은 위치에 있어야합니다.
Set up an OIDC application
OIDC 응용 프로그램을 설정하십시오
In this section, we’ll show you the step-by-step process to set up an OIDC application using both Okta and EntraID as the identity providers.
이 섹션에서는 OKTA와 Entraid를 모두 신분 공급자로 사용하여 OIDC 응용 프로그램을 설정하는 단계별 프로세스를 표시합니다.
Set up an Okta OIDC application
OKTA OIDC 응용 프로그램을 설정하십시오
Complete the following steps to set up an Okta OIDC application:
Okta OIDC 응용 프로그램을 설정하려면 다음 단계를 완료하십시오.
Set up an EntraID OIDC application
Entraid OIDC 응용 프로그램을 설정하십시오
To create your EntraID application, follow these steps:
Entraid 응용 프로그램을 만들려면 다음 단계를 따르십시오.
The secret value will only be presented one time; after that you can’t read it. Make sure to copy it now. If you fail to save it, you must generate a new client secret.
비밀 가치는 한 번만 제시됩니다. 그 후 당신은 그것을 읽을 수 없습니다. 지금 복사하십시오. 저장하지 못하면 새로운 클라이언트 비밀을 생성해야합니다.
If you’re setting up for the first time, you can see Add to the right of the application ID URI.
처음으로 설정하는 경우 응용 프로그램 ID URI의 오른쪽에 추가 할 수 있습니다.
Set up a TTI in IAM Identity Center
IAM Identity Center에서 TTI를 설정하십시오
Assuming you have completed the prerequisites, you will establish your IdP as a TTI in your delegated administration account. To create a TTI, refer to How to add a trusted token issuer to the IAM Identity Center console. In this post, we walk through the steps to set up a TTI for both Okta and EntraID.
전제 조건을 완료했다고 가정하면 위임 된 관리 계정에서 IDP를 TTI로 설정합니다. TTI를 만들려면 신뢰할 수있는 토큰 발행자를 IAM Identity Center 콘솔에 추가하는 방법을 참조하십시오. 이 게시물에서는 Okta와 Entraid의 TTI를 설정하는 단계를 살펴 봅니다.
Set up a TTI for Okta
OKTA 용 TTI를 설정하십시오
To get the issuer URL from Okta, complete the following steps:
OKTA에서 발행자 URL을 얻으려면 다음 단계를 완료하십시오.
Set up a TTI for EntraID
Entraid를 위해 TTI를 설정하십시오
Complete the following steps to set up a TTI for EntraID:
Entraid에 대한 TTI를 설정하려면 다음 단계를 완료하십시오.
Next, you need to find the tenant ID value from EntraID.
다음으로 Entraid에서 임차인 ID 값을 찾아야합니다.
Set up client connections and TTIs in Amazon Redshift
Amazon Redshift에서 클라이언트 연결 및 TTI를 설정하십시오
In this step, we configure the Amazon Redshift applications that exchange externally generated tokens to use the TTI you created in the previous step. Also, the audience claim (or aud claim) from your IdP must be specified. You need to collect the audience value from the respective IdP.
이 단계에서는 외부에서 생성 된 토큰을 교환하여 이전 단계에서 만든 TTI를 사용하는 Amazon Redshift 응용 프로그램을 구성합니다. 또한 IDP의 청중 청구 (또는 AUD 청구)를 지정해야합니다. 각 IDP에서 청중 가치를 수집해야합니다.
Acquire the audience value from Okta
Okta에서 청중 가치를 얻으십시오
To acquire the audience value from Okta, complete the following steps:
Okta에서 잠재 고객 가치를 얻으려면 다음 단계를 완료하십시오.
Acquire the audience value from EntraID
Entraid로부터 청중 가치를 얻으십시오
Similarly, to get the audience value EntraID, complete the following steps:
마찬가지로, 청중의 가치를 사로 잡으려면 다음 단계를 완료하십시오.
Configure the application
응용 프로그램을 구성합니다
After you collect the audience value from the respective IdP, you need to configure the
각 IDP에서 잠재 고객 값을 수집 한 후에는
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































