市值: $2.2043T 0.58%
成交额(24h): $56.8553B 3.76%
  • 市值: $2.2043T 0.58%
  • 成交额(24h): $56.8553B 3.76%
  • 恐惧与贪婪指数:
  • 市值: $2.2043T 0.58%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密货币新闻

使用 IAM Identity Center 从 Tableau 单点登录到 Amazon Redshift

2024/06/04 01:44

本博文由 Salesforce 的 Sid Wray 和 Jake Koskela 以及 Tableau 的 Adiascar Cisneros 共同撰写。 Amazon Redshift 是一个快速、可扩展的云数据仓库,旨在为任何规模的工作负载提供服务。使用 Amazon Redshift 作为数据仓库,您可以使用复杂的查询优化来运行复杂的查询,以快速将结果交付给 Tableau,Tableau 为分析师提供了一套全面的功能和连接选项,以便在整个企业内高效地准备、发现和共享见解。对于想要使用单点登录功能将 Amazon Redshift 与 Tableau 集成的客户,我们引入了 AWS IAM Identity Center 集成来无缝实施身份验证和授权。

使用 IAM Identity Center 从 Tableau 单点登录到 Amazon Redshift

Amazon Redshift is a fast, fully managed, petabyte-scale cloud data warehouse service that makes it simple and cost-effective to analyze all your data using standard SQL and advanced analytics capabilities. It’s designed to handle massive volumes of structured and semi-structured data, and it scales up or down quickly to meet your changing needs.

Amazon Redshift 是一种快速、完全托管的 PB 级云数据仓库服务,可让您使用标准 SQL 和高级分析功能轻松且经济高效地分析所有数据。它旨在处理大量结构化和半结构化数据,并且可以快速扩展或缩小以满足您不断变化的需求。

With Amazon Redshift as your data warehouse, you can run complex queries using sophisticated query optimization to quickly deliver results to Tableau, which offers a comprehensive set of capabilities and connectivity options for analysts to efficiently prepare, discover, and share insights across the enterprise. For customers who want to integrate Amazon Redshift with Tableau using single sign-on capabilities, we introduced AWS IAM Identity Center integration to seamlessly implement authentication and authorization.

使用 Amazon Redshift 作为数据仓库,您可以使用复杂的查询优化来运行复杂的查询,以快速将结果交付给 Tableau,Tableau 为分析师提供了一套全面的功能和连接选项,以便在整个企业内高效地准备、发现和共享见解。对于想要使用单点登录功能将 Amazon Redshift 与 Tableau 集成的客户,我们引入了 AWS IAM Identity Center 集成来无缝实施身份验证和授权。

IAM Identity Center provides capabilities to centrally manage single sign-on access to AWS accounts and applications. Redshift now integrates with IAM Identity Center, and supports trusted identity propagation, making it possible to integrate with third-party identity providers (IdP) such as Microsoft Entra ID (Azure AD), Okta, Ping, and OneLogin. This integration positions Amazon Redshift as an IAM Identity Center-managed application, enabling you to use database role-based access control on your data warehouse for enhanced security. Role-based access control allows you to apply fine grained access control using row level, column level, and dynamic data masking in your data warehouse.

IAM Identity Center 提供集中管理对 AWS 账户和应用程序的单点登录访问的功能。 Redshift 现在与 IAM Identity Center 集成,并支持可信身份传播,从而可以与 Microsoft Entra ID (Azure AD)、Okta、Ping 和 OneLogin 等第三方身份提供商 (IdP) 集成。此集成将 Amazon Redshift 定位为 IAM Identity Center 管理的应用程序,使您能够在数据仓库上使用基于数据库角色的访问控制来增强安全性。基于角色的访问控制允许您在数据仓库中使用行级别、列级别和动态数据屏蔽来应用细粒度访问控制。

AWS and Tableau have collaborated to enable single sign-on support for accessing Amazon Redshift from Tableau. Tableau now supports single sign-on capabilities with Amazon Redshift connector to simplify the authentication and authorization. The Tableau Desktop 2024.1 and Tableau Server 2023.3.4 releases support trusted identity propagation with IAM Identity Center. This allows users to seamlessly access Amazon Redshift data within Tableau using their external IdP credentials without needing to specify AWS Identity and Access Management (IAM) roles in Tableau. This single sign-on integration is available for Tableau Desktop, Tableau Server, and Tableau Prep.

AWS 和 Tableau 合作为从 Tableau 访问 Amazon Redshift 提供单点登录支持。 Tableau 现在支持使用 Amazon Redshift 连接器的单点登录功能,以简化身份验证和授权。 Tableau Desktop 2024.1 和 Tableau Server 2023.3.4 版本支持使用 IAM 身份中心进行可信身份传播。这允许用户使用其外部 IdP 凭证无缝访问 Tableau 中的 Amazon Redshift 数据,而无需在 Tableau 中指定 AWS Identity and Access Management (IAM) 角色。此单点登录集成适用于 Tableau Desktop、Tableau Server 和 Tableau Prep。

In this post, we outline a comprehensive guide for setting up single sign-on to Amazon Redshift using integration with IAM Identity Center and Okta as the IdP. By following this guide, you’ll learn how to enable seamless single sign-on authentication to Amazon Redshift data sources directly from within Tableau Desktop, streamlining your analytics workflows and enhancing security.

在这篇文章中,我们概述了使用 IAM Identity Center 和 Okta 作为 IdP 集成来设置 Amazon Redshift 单点登录的综合指南。通过遵循本指南,您将了解如何直接从 Tableau Desktop 内对 Amazon Redshift 数据源启用无缝单点登录身份验证,从而简化分析工作流程并增强安全性。

Prerequisites

先决条件

Before you begin implementing the solution, make sure that you have the following in place:

在开始实施该解决方案之前,请确保您已做好以下准备:

Walkthrough

演练

In this walkthrough, you build the solution with following steps:

在本演练中,您将通过以下步骤构建解决方案:

Set up the Okta OIDC application

设置 Okta OIDC 应用程序

To create an OIDC web app in Okta, follow the instructions in this video, or use the following steps to create the wep app in Okta admin console:

要在 Okta 中创建 OIDC Web 应用程序,请按照本视频中的说明操作,或使用以下步骤在 Okta 管理控制台中创建 wep 应用程序:

Note: The Tableau Desktop redirect URLs should always use localhost. The examples below also use localhost for the Tableau Server hostname for ease of testing in a test environment. For this setup, you should also access the server at localhost in the browser. If you decide to use localhost for early testing, you will also need to configure the gateway to accept localhost using this tsm command:

注意:Tableau Desktop 重定向 URL 应始终使用 localhost。下面的示例还使用 localhost 作为 Tableau Server 主机名,以便于在测试环境中进行测试。对于此设置,您还应该在浏览器中访问本地主机上的服务器。如果您决定使用 localhost 进行早期测试,您还需要使用以下 tsm 命令配置网关以接受 localhost:

In a production environment, or Tableau Cloud, you should use the full hostname that your users will access Tableau on the web, along with https. If you already have an environment with https configured, you may skip the localhost configuration and use the full hostname from the start.

在生产环境或 Tableau Cloud 中,您应该使用用户将在 Web 上访问 Tableau 的完整主机名以及 https。如果您已经配置了 https 环境,则可以跳过 localhost 配置并从一开始就使用完整主机名。

Set up the Okta authorization server

设置 Okta 授权服务器

Okta allows you to create multiple custom authorization servers that you can use to protect your own resource servers. Within each authorization server you can define your own OAuth 2.0 scopes, claims, and access policies. If you have an Okta Developer Edition account, you already have a custom authorization server created for you called default.

Okta 允许您创建多个自定义授权服务器,您可以使用它们来保护您自己的资源服务器。在每个授权服务器中,您可以定义自己的 OAuth 2.0 范围、声明和访问策略。如果您有 Okta Developer Edition 帐户,则已经为您创建了一个名为默认的自定义授权服务器。

For this blog post, we use the default custom authorization server. If your application has requirements such as requiring more scopes, customizing rules for when to grant scopes, or you need more authorization servers with different scopes and claims, then you can follow this guide.

对于本博文,我们使用默认的自定义授权服务器。如果您的应用程序有诸如需要更多范围、自定义何时授予范围的规则等要求,或者您需要更多具有不同范围和声明的授权服务器,那么您可以遵循本指南。

Set up the Okta claims

设置 Okta 声明

Tokens contain claims that are statements about the subject (for example: name, role, or email address). For this example, we use the default custom claim sub. Follow this guide to create claims.

令牌包含有关主题的声明(例如:姓名、角色或电子邮件地址)。对于此示例,我们使用默认的自定义声明子。请按照本指南创建索赔。

Setup the Okta access policies and rules

设置 Okta 访问策略和规则

Access policies are containers for rules. Each access policy applies to a particular OpenID Connect application. The rules that the policy contains define different access and refresh token lifetimes depending on the nature of the token request. In this example, you create a simple policy for all clients as shown in Figure 7 that follows. Follow this guide to create access policies and rules.

访问策略是规则的容器。每个访问策略适用于特定的 OpenID Connect 应用程序。策略包含的规则根据令牌请求的性质定义不同的访问和刷新令牌生存期。在此示例中,您为所有客户端创建一个简单的策略,如下面的图 7 所示。按照本指南创建访问策略和规则。

Rules for access policies define token lifetimes for a given combination of grant type, user, and scope. They’re evaluated in priority order and after a matching rule is found, no other rules are evaluated. If no matching rule is found, then the authorization request fails. This example uses the role depicted in Figure 8 that follows. Follow this

访问策略规则定义给定的授权类型、用户和范围组合的令牌生命周期。它们按优先级顺序进行评估,并且在找到匹配规则后,不会评估其他规则。如果没有找到匹配的规则,则授权请求失败。此示例使用下面图 8 中描述的角色。按照这个

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年08月11日 发表的其他文章