시가총액: $2.2043T 0.58%
거래량(24시간): $56.8553B 3.76%
  • 시가총액: $2.2043T 0.58%
  • 거래량(24시간): $56.8553B 3.76%
  • 공포와 탐욕 지수:
  • 시가총액: $2.2043T 0.58%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

암호화폐 뉴스 기사

IAM ID 센터를 사용하여 Tableau에서 Amazon Redshift에 대한 Single Sign-On

2024/06/04 01:44

이 블로그 게시물은 Salesforce의 Sid Wray와 Jake Koskela, Tableau의 Adiascar Cisneros와 공동으로 작성되었습니다. Amazon Redshift는 모든 규모의 워크로드를 처리하도록 구축된 빠르고 확장 가능한 클라우드 데이터 웨어하우스입니다. Amazon Redshift를 데이터 웨어하우스로 사용하면 정교한 쿼리 최적화를 사용하여 복잡한 쿼리를 실행하여 결과를 Tableau에 빠르게 전달할 수 있습니다. Tableau는 분석가가 기업 전체에서 통찰력을 효율적으로 준비, 발견 및 공유할 수 있도록 포괄적인 기능 및 연결 옵션 세트를 제공합니다. Single Sign-On 기능을 사용하여 Amazon Redshift를 Tableau와 통합하려는 고객을 위해 인증 및 권한 부여를 원활하게 구현하기 위해 AWS IAM Identity Center 통합을 도입했습니다.

IAM ID 센터를 사용하여 Tableau에서 Amazon Redshift에 대한 Single Sign-On

Amazon Redshift is a fast, fully managed, petabyte-scale cloud data warehouse service that makes it simple and cost-effective to analyze all your data using standard SQL and advanced analytics capabilities. It’s designed to handle massive volumes of structured and semi-structured data, and it scales up or down quickly to meet your changing needs.

Amazon Redshift는 표준 SQL 및 고급 분석 기능을 사용하여 모든 데이터를 간단하고 비용 효율적으로 분석할 수 있는 빠르고 완벽하게 관리되는 페타바이트 규모의 클라우드 데이터 웨어하우스 서비스입니다. 대용량의 정형 및 반정형 데이터를 처리하도록 설계되었으며, 변화하는 요구 사항에 맞게 빠르게 확장하거나 축소할 수 있습니다.

With Amazon Redshift as your data warehouse, you can run complex queries using sophisticated query optimization to quickly deliver results to Tableau, which offers a comprehensive set of capabilities and connectivity options for analysts to efficiently prepare, discover, and share insights across the enterprise. For customers who want to integrate Amazon Redshift with Tableau using single sign-on capabilities, we introduced AWS IAM Identity Center integration to seamlessly implement authentication and authorization.

Amazon Redshift를 데이터 웨어하우스로 사용하면 정교한 쿼리 최적화를 사용하여 복잡한 쿼리를 실행하여 결과를 Tableau에 빠르게 전달할 수 있습니다. Tableau는 분석가가 기업 전체에서 통찰력을 효율적으로 준비, 발견 및 공유할 수 있도록 포괄적인 기능 및 연결 옵션 세트를 제공합니다. Single Sign-On 기능을 사용하여 Amazon Redshift를 Tableau와 통합하려는 고객을 위해 인증 및 권한 부여를 원활하게 구현하기 위해 AWS IAM Identity Center 통합을 도입했습니다.

IAM Identity Center provides capabilities to centrally manage single sign-on access to AWS accounts and applications. Redshift now integrates with IAM Identity Center, and supports trusted identity propagation, making it possible to integrate with third-party identity providers (IdP) such as Microsoft Entra ID (Azure AD), Okta, Ping, and OneLogin. This integration positions Amazon Redshift as an IAM Identity Center-managed application, enabling you to use database role-based access control on your data warehouse for enhanced security. Role-based access control allows you to apply fine grained access control using row level, column level, and dynamic data masking in your data warehouse.

IAM Identity Center는 AWS 계정 및 애플리케이션에 대한 Single Sign-On 액세스를 중앙에서 관리하는 기능을 제공합니다. 이제 Redshift는 IAM Identity Center와 통합되고 신뢰할 수 있는 ID 전파를 지원하므로 Microsoft Entra ID(Azure AD), Okta, Ping 및 OneLogin과 같은 타사 ID 공급자(IdP)와 통합할 수 있습니다. 이 통합을 통해 Amazon Redshift는 IAM Identity Center 관리형 애플리케이션으로 자리매김하여 데이터 웨어하우스에서 데이터베이스 역할 기반 액세스 제어를 사용하여 보안을 강화할 수 있습니다. 역할 기반 액세스 제어를 사용하면 데이터 웨어하우스에서 행 수준, 열 수준 및 동적 데이터 마스킹을 사용하여 세분화된 액세스 제어를 적용할 수 있습니다.

AWS and Tableau have collaborated to enable single sign-on support for accessing Amazon Redshift from Tableau. Tableau now supports single sign-on capabilities with Amazon Redshift connector to simplify the authentication and authorization. The Tableau Desktop 2024.1 and Tableau Server 2023.3.4 releases support trusted identity propagation with IAM Identity Center. This allows users to seamlessly access Amazon Redshift data within Tableau using their external IdP credentials without needing to specify AWS Identity and Access Management (IAM) roles in Tableau. This single sign-on integration is available for Tableau Desktop, Tableau Server, and Tableau Prep.

AWS와 Tableau는 Tableau에서 Amazon Redshift에 액세스하기 위한 Single Sign-On 지원을 활성화하기 위해 협력했습니다. 이제 Tableau는 인증 및 권한 부여를 단순화하기 위해 Amazon Redshift 커넥터를 통해 Single Sign-On 기능을 지원합니다. Tableau Desktop 2024.1 및 Tableau Server 2023.3.4 릴리스는 IAM ID 센터를 통해 신뢰할 수 있는 ID 전파를 지원합니다. 이를 통해 사용자는 Tableau에서 AWS Identity and Access Management(IAM) 역할을 지정할 필요 없이 외부 IdP 자격 증명을 사용하여 Tableau 내에서 Amazon Redshift 데이터에 원활하게 액세스할 수 있습니다. 이 Single Sign-On 통합은 Tableau Desktop, Tableau Server 및 Tableau Prep에서 사용할 수 있습니다.

In this post, we outline a comprehensive guide for setting up single sign-on to Amazon Redshift using integration with IAM Identity Center and Okta as the IdP. By following this guide, you’ll learn how to enable seamless single sign-on authentication to Amazon Redshift data sources directly from within Tableau Desktop, streamlining your analytics workflows and enhancing security.

이 게시물에서는 IAM Identity Center 및 Okta를 IdP로 통합하여 Amazon Redshift에 대한 Single Sign-On을 설정하기 위한 포괄적인 가이드를 간략하게 설명합니다. 이 가이드를 따르면 Tableau Desktop 내에서 직접 Amazon Redshift 데이터 원본에 대한 원활한 Single Sign-On 인증을 활성화하여 분석 워크플로를 간소화하고 보안을 강화하는 방법을 배우게 됩니다.

Prerequisites

전제조건

Before you begin implementing the solution, make sure that you have the following in place:

솔루션 구현을 시작하기 전에 다음 사항이 준비되어 있는지 확인하세요.

Walkthrough

연습

In this walkthrough, you build the solution with following steps:

이 연습에서는 다음 단계에 따라 솔루션을 빌드합니다.

Set up the Okta OIDC application

Okta OIDC 애플리케이션 설정

To create an OIDC web app in Okta, follow the instructions in this video, or use the following steps to create the wep app in Okta admin console:

Okta에서 OIDC 웹 앱을 생성하려면 이 비디오의 지침을 따르거나 다음 단계를 사용하여 Okta 관리 콘솔에서 wep 앱을 생성하십시오.

Note: The Tableau Desktop redirect URLs should always use localhost. The examples below also use localhost for the Tableau Server hostname for ease of testing in a test environment. For this setup, you should also access the server at localhost in the browser. If you decide to use localhost for early testing, you will also need to configure the gateway to accept localhost using this tsm command:

참고: Tableau Desktop 리디렉션 URL은 항상 localhost를 사용해야 합니다. 아래 예에서는 테스트 환경에서 쉽게 테스트할 수 있도록 Tableau Server 호스트 이름으로 localhost를 사용합니다. 이 설정을 위해서는 브라우저의 localhost에서 서버에 액세스해야 합니다. 초기 테스트에 localhost를 사용하기로 결정한 경우 다음 tsm 명령을 사용하여 localhost를 허용하도록 게이트웨이도 구성해야 합니다.

In a production environment, or Tableau Cloud, you should use the full hostname that your users will access Tableau on the web, along with https. If you already have an environment with https configured, you may skip the localhost configuration and use the full hostname from the start.

프로덕션 환경 또는 Tableau Cloud에서는 사용자가 웹에서 Tableau에 액세스하는 전체 호스트 이름을 https와 함께 사용해야 합니다. https가 구성된 환경이 이미 있는 경우 localhost 구성을 건너뛰고 처음부터 전체 호스트 이름을 사용할 수 있습니다.

Set up the Okta authorization server

Okta 인증 서버 설정

Okta allows you to create multiple custom authorization servers that you can use to protect your own resource servers. Within each authorization server you can define your own OAuth 2.0 scopes, claims, and access policies. If you have an Okta Developer Edition account, you already have a custom authorization server created for you called default.

Okta를 사용하면 자신의 리소스 서버를 보호하는 데 사용할 수 있는 여러 사용자 정의 인증 서버를 생성할 수 있습니다. 각 인증 서버 내에서 자체 OAuth 2.0 범위, 클레임 및 액세스 정책을 정의할 수 있습니다. Okta Developer Edition 계정이 있는 경우 기본이라는 사용자 정의 인증 서버가 이미 생성되어 있습니다.

For this blog post, we use the default custom authorization server. If your application has requirements such as requiring more scopes, customizing rules for when to grant scopes, or you need more authorization servers with different scopes and claims, then you can follow this guide.

이 블로그 게시물에서는 기본 사용자 정의 인증 서버를 사용합니다. 애플리케이션에 더 많은 범위 요구, 범위 부여 시기에 대한 규칙 사용자 정의, 다양한 범위 및 클레임이 있는 더 많은 인증 서버가 필요한 경우 이 가이드를 따를 수 있습니다.

Set up the Okta claims

Okta 클레임 설정

Tokens contain claims that are statements about the subject (for example: name, role, or email address). For this example, we use the default custom claim sub. Follow this guide to create claims.

토큰에는 제목(예: 이름, 역할 또는 이메일 주소)에 대한 설명인 클레임이 포함되어 있습니다. 이 예에서는 기본 사용자 정의 클레임 sub를 사용합니다. 소유권 주장을 만들려면 이 가이드를 따르세요.

Setup the Okta access policies and rules

Okta 액세스 정책 및 규칙 설정

Access policies are containers for rules. Each access policy applies to a particular OpenID Connect application. The rules that the policy contains define different access and refresh token lifetimes depending on the nature of the token request. In this example, you create a simple policy for all clients as shown in Figure 7 that follows. Follow this guide to create access policies and rules.

액세스 정책은 규칙의 컨테이너입니다. 각 액세스 정책은 특정 OpenID Connect 애플리케이션에 적용됩니다. 정책에 포함된 규칙은 토큰 요청의 성격에 따라 다양한 액세스 및 새로 고침 토큰 수명을 정의합니다. 이 예에서는 다음 그림 7과 같이 모든 클라이언트에 대한 간단한 정책을 생성합니다. 이 가이드에 따라 액세스 정책 및 규칙을 만드세요.

Rules for access policies define token lifetimes for a given combination of grant type, user, and scope. They’re evaluated in priority order and after a matching rule is found, no other rules are evaluated. If no matching rule is found, then the authorization request fails. This example uses the role depicted in Figure 8 that follows. Follow this

액세스 정책 규칙은 부여 유형, 사용자 및 범위의 특정 조합에 대한 토큰 수명을 정의합니다. 우선순위에 따라 평가되며 일치하는 규칙이 발견되면 다른 규칙은 평가되지 않습니다. 일치하는 규칙이 없으면 승인 요청이 실패합니다. 이 예에서는 다음 그림 8에 설명된 역할을 사용합니다. 이것을 따르십시오

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年08月08日 에 게재된 다른 기사