oauth.html 30 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947
  1. <!DOCTYPE html>
  2. <html>
  3. <head>
  4. <meta charset="utf-8" />
  5. <meta name="viewport" content="width=device-width, initial-scale=1.0" />
  6. <meta name="viewport" content="width=device-width,initial-scale=1">
  7. <meta http-equiv="x-ua-compatible" content="ie=edge">
  8. <meta name="lang:clipboard.copy" content="Copy to clipboard">
  9. <meta name="lang:clipboard.copied" content="Copied to clipboard">
  10. <meta name="lang:search.language" content="en">
  11. <meta name="lang:search.pipeline.stopwords" content="True">
  12. <meta name="lang:search.pipeline.trimmer" content="True">
  13. <meta name="lang:search.result.none" content="No matching documents">
  14. <meta name="lang:search.result.one" content="1 matching document">
  15. <meta name="lang:search.result.other" content="# matching documents">
  16. <meta name="lang:search.tokenizer" content="[\s\-]+">
  17. <link href="https://fonts.gstatic.com/" rel="preconnect" crossorigin>
  18. <link href="https://fonts.googleapis.com/css?family=Roboto+Mono:400,500,700|Roboto:300,400,400i,700&display=fallback" rel="stylesheet">
  19. <style>
  20. body,
  21. input {
  22. font-family: "Roboto", "Helvetica Neue", Helvetica, Arial, sans-serif
  23. }
  24. code,
  25. kbd,
  26. pre {
  27. font-family: "Roboto Mono", "Courier New", Courier, monospace
  28. }
  29. </style>
  30. <link rel="stylesheet" href="_static/stylesheets/application.css"/>
  31. <link rel="stylesheet" href="_static/stylesheets/application-palette.css"/>
  32. <link rel="stylesheet" href="_static/stylesheets/application-fixes.css"/>
  33. <link rel="stylesheet" href="_static/fonts/material-icons.css"/>
  34. <meta name="theme-color" content="#3f51b5">
  35. <script src="_static/javascripts/modernizr.js"></script>
  36. <title>Integrating OAuth &#8212; Netmaker 0.8.5 documentation</title>
  37. <link rel="stylesheet" href="_static/pygments.css" type="text/css" />
  38. <link rel="stylesheet" href="_static/material.css" type="text/css" />
  39. <script id="documentation_options" data-url_root="./" src="_static/documentation_options.js"></script>
  40. <script src="_static/jquery.js"></script>
  41. <script src="_static/underscore.js"></script>
  42. <script src="_static/doctools.js"></script>
  43. <link rel="author" title="About these documents" href="about.html" />
  44. <link rel="index" title="Index" href="genindex.html" />
  45. <link rel="search" title="Search" href="search.html" />
  46. <link rel="next" title="Client Installation" href="client-installation.html" />
  47. <link rel="prev" title="Advanced Server Installation" href="server-installation.html" />
  48. </head>
  49. <body dir=ltr
  50. data-md-color-primary=indigo data-md-color-accent=light-blue>
  51. <svg class="md-svg">
  52. <defs data-children-count="0">
  53. <svg xmlns="http://www.w3.org/2000/svg" width="416" height="448" viewBox="0 0 416 448" id="__github"><path fill="currentColor" d="M160 304q0 10-3.125 20.5t-10.75 19T128 352t-18.125-8.5-10.75-19T96 304t3.125-20.5 10.75-19T128 256t18.125 8.5 10.75 19T160 304zm160 0q0 10-3.125 20.5t-10.75 19T288 352t-18.125-8.5-10.75-19T256 304t3.125-20.5 10.75-19T288 256t18.125 8.5 10.75 19T320 304zm40 0q0-30-17.25-51T296 232q-10.25 0-48.75 5.25Q229.5 240 208 240t-39.25-2.75Q130.75 232 120 232q-29.5 0-46.75 21T56 304q0 22 8 38.375t20.25 25.75 30.5 15 35 7.375 37.25 1.75h42q20.5 0 37.25-1.75t35-7.375 30.5-15 20.25-25.75T360 304zm56-44q0 51.75-15.25 82.75-9.5 19.25-26.375 33.25t-35.25 21.5-42.5 11.875-42.875 5.5T212 416q-19.5 0-35.5-.75t-36.875-3.125-38.125-7.5-34.25-12.875T37 371.5t-21.5-28.75Q0 312 0 260q0-59.25 34-99-6.75-20.5-6.75-42.5 0-29 12.75-54.5 27 0 47.5 9.875t47.25 30.875Q171.5 96 212 96q37 0 70 8 26.25-20.5 46.75-30.25T376 64q12.75 25.5 12.75 54.5 0 21.75-6.75 42 34 40 34 99.5z"/></svg>
  54. </defs>
  55. </svg>
  56. <input class="md-toggle" data-md-toggle="drawer" type="checkbox" id="__drawer">
  57. <input class="md-toggle" data-md-toggle="search" type="checkbox" id="__search">
  58. <label class="md-overlay" data-md-component="overlay" for="__drawer"></label>
  59. <a href="#oauth" tabindex="1" class="md-skip"> Skip to content </a>
  60. <header class="md-header" data-md-component="header">
  61. <nav class="md-header-nav md-grid">
  62. <div class="md-flex navheader">
  63. <div class="md-flex__cell md-flex__cell--shrink">
  64. <a href="index.html" title="Netmaker 0.8.5 documentation"
  65. class="md-header-nav__button md-logo">
  66. <i class="md-icon">&#xe869</i>
  67. </a>
  68. </div>
  69. <div class="md-flex__cell md-flex__cell--shrink">
  70. <label class="md-icon md-icon--menu md-header-nav__button" for="__drawer"></label>
  71. </div>
  72. <div class="md-flex__cell md-flex__cell--stretch">
  73. <div class="md-flex__ellipsis md-header-nav__title" data-md-component="title">
  74. <span class="md-header-nav__topic">Netmaker Docs</span>
  75. <span class="md-header-nav__topic"> Integrating OAuth </span>
  76. </div>
  77. </div>
  78. <div class="md-flex__cell md-flex__cell--shrink">
  79. <label class="md-icon md-icon--search md-header-nav__button" for="__search"></label>
  80. <div class="md-search" data-md-component="search" role="dialog">
  81. <label class="md-search__overlay" for="__search"></label>
  82. <div class="md-search__inner" role="search">
  83. <form class="md-search__form" action="search.html" method="get" name="search">
  84. <input type="text" class="md-search__input" name="q" placeholder="Search"
  85. autocapitalize="off" autocomplete="off" spellcheck="false"
  86. data-md-component="query" data-md-state="active">
  87. <label class="md-icon md-search__icon" for="__search"></label>
  88. <button type="reset" class="md-icon md-search__icon" data-md-component="reset" tabindex="-1">
  89. &#xE5CD;
  90. </button>
  91. </form>
  92. <div class="md-search__output">
  93. <div class="md-search__scrollwrap" data-md-scrollfix>
  94. <div class="md-search-result" data-md-component="result">
  95. <div class="md-search-result__meta">
  96. Type to start searching
  97. </div>
  98. <ol class="md-search-result__list"></ol>
  99. </div>
  100. </div>
  101. </div>
  102. </div>
  103. </div>
  104. </div>
  105. <div class="md-flex__cell md-flex__cell--shrink">
  106. <div class="md-header-nav__source">
  107. <a href="https://github.com/gravitl/netmaker/" title="Go to repository" class="md-source" data-md-source="github">
  108. <div class="md-source__icon">
  109. <svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" viewBox="0 0 24 24" width="28" height="28">
  110. <use xlink:href="#__github" width="24" height="24"></use>
  111. </svg>
  112. </div>
  113. <div class="md-source__repository">
  114. Netmaker
  115. </div>
  116. </a>
  117. </div>
  118. </div>
  119. <script src="_static/javascripts/version_dropdown.js"></script>
  120. <script>
  121. var json_loc = ""versions.json"",
  122. target_loc = "../",
  123. text = "Versions";
  124. $( document ).ready( add_version_dropdown(json_loc, target_loc, text));
  125. </script>
  126. </div>
  127. </nav>
  128. </header>
  129. <div class="md-container">
  130. <nav class="md-tabs" data-md-component="tabs">
  131. <div class="md-tabs__inner md-grid">
  132. <ul class="md-tabs__list">
  133. <li class="md-tabs__item"><a href="index.html" class="md-tabs__link">Netmaker 0.8.5 documentation</a></li>
  134. </ul>
  135. </div>
  136. </nav>
  137. <main class="md-main">
  138. <div class="md-main__inner md-grid" data-md-component="container">
  139. <div class="md-sidebar md-sidebar--primary" data-md-component="navigation">
  140. <div class="md-sidebar__scrollwrap">
  141. <div class="md-sidebar__inner">
  142. <nav class="md-nav md-nav--primary" data-md-level="0">
  143. <label class="md-nav__title md-nav__title--site" for="__drawer">
  144. <a href="index.html" title="Netmaker 0.8.5 documentation" class="md-nav__button md-logo">
  145. <i class="md-icon">&#xe869</i>
  146. </a>
  147. <a href="index.html"
  148. title="Netmaker 0.8.5 documentation">Netmaker Docs</a>
  149. </label>
  150. <div class="md-nav__source">
  151. <a href="https://github.com/gravitl/netmaker/" title="Go to repository" class="md-source" data-md-source="github">
  152. <div class="md-source__icon">
  153. <svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" viewBox="0 0 24 24" width="28" height="28">
  154. <use xlink:href="#__github" width="24" height="24"></use>
  155. </svg>
  156. </div>
  157. <div class="md-source__repository">
  158. Netmaker
  159. </div>
  160. </a>
  161. </div>
  162. <ul class="md-nav__list">
  163. <li class="md-nav__item">
  164. <a href="about.html" class="md-nav__link">About</a>
  165. <ul class="md-nav__list">
  166. <li class="md-nav__item">
  167. <a href="about.html#what-is-netmaker" class="md-nav__link">What is Netmaker?</a>
  168. </li>
  169. <li class="md-nav__item">
  170. <a href="about.html#how-does-netmaker-work" class="md-nav__link">How Does Netmaker Work?</a>
  171. </li>
  172. <li class="md-nav__item">
  173. <a href="about.html#use-cases-for-netmaker" class="md-nav__link">Use Cases for Netmaker</a>
  174. </li></ul>
  175. </li>
  176. <li class="md-nav__item">
  177. <a href="architecture.html" class="md-nav__link">Architecture</a>
  178. <ul class="md-nav__list">
  179. <li class="md-nav__item">
  180. <a href="architecture.html#core-concepts" class="md-nav__link">Core Concepts</a>
  181. </li>
  182. <li class="md-nav__item">
  183. <a href="architecture.html#components" class="md-nav__link">Components</a>
  184. </li>
  185. <li class="md-nav__item">
  186. <a href="architecture.html#technical-process" class="md-nav__link">Technical Process</a>
  187. </li>
  188. <li class="md-nav__item">
  189. <a href="architecture.html#compatible-systems-for-netclient" class="md-nav__link">Compatible Systems for Netclient</a>
  190. </li>
  191. <li class="md-nav__item">
  192. <a href="architecture.html#limitations" class="md-nav__link">Limitations</a>
  193. </li></ul>
  194. </li>
  195. <li class="md-nav__item">
  196. <a href="install.html" class="md-nav__link">Install</a>
  197. </li>
  198. <li class="md-nav__item">
  199. <a href="quick-start.html" class="md-nav__link">Quick Install</a>
  200. <ul class="md-nav__list">
  201. <li class="md-nav__item">
  202. <a href="quick-start.html#introduction" class="md-nav__link">Introduction</a>
  203. </li>
  204. <li class="md-nav__item">
  205. <a href="quick-start.html#prerequisites" class="md-nav__link">0. Prerequisites</a>
  206. </li>
  207. <li class="md-nav__item">
  208. <a href="quick-start.html#prepare-dns" class="md-nav__link">1. Prepare DNS</a>
  209. </li>
  210. <li class="md-nav__item">
  211. <a href="quick-start.html#install-dependencies" class="md-nav__link">2. Install Dependencies</a>
  212. </li>
  213. <li class="md-nav__item">
  214. <a href="quick-start.html#open-firewall" class="md-nav__link">3. Open Firewall</a>
  215. </li>
  216. <li class="md-nav__item">
  217. <a href="quick-start.html#install-netmaker" class="md-nav__link">4. Install Netmaker</a>
  218. </li></ul>
  219. </li>
  220. <li class="md-nav__item">
  221. <a href="getting-started.html" class="md-nav__link">Getting Started</a>
  222. <ul class="md-nav__list">
  223. <li class="md-nav__item">
  224. <a href="getting-started.html#setup" class="md-nav__link">Setup</a>
  225. </li>
  226. <li class="md-nav__item">
  227. <a href="getting-started.html#deploy-nodes" class="md-nav__link">Deploy Nodes</a>
  228. </li>
  229. <li class="md-nav__item">
  230. <a href="getting-started.html#manage-nodes" class="md-nav__link">Manage Nodes</a>
  231. </li>
  232. <li class="md-nav__item">
  233. <a href="getting-started.html#uninstalling-the-netclient" class="md-nav__link">Uninstalling the netclient</a>
  234. </li>
  235. <li class="md-nav__item">
  236. <a href="getting-started.html#uninstalling-netmaker" class="md-nav__link">Uninstalling Netmaker</a>
  237. </li></ul>
  238. </li>
  239. <li class="md-nav__item">
  240. <a href="quick-start-nginx.html" class="md-nav__link">Install with Nginx (depreciated)</a>
  241. <ul class="md-nav__list">
  242. <li class="md-nav__item">
  243. <a href="quick-start-nginx.html#introduction" class="md-nav__link">0. Introduction</a>
  244. </li>
  245. <li class="md-nav__item">
  246. <a href="quick-start-nginx.html#prerequisites" class="md-nav__link">1. Prerequisites</a>
  247. </li>
  248. <li class="md-nav__item">
  249. <a href="quick-start-nginx.html#install-dependencies" class="md-nav__link">2. Install Dependencies</a>
  250. </li>
  251. <li class="md-nav__item">
  252. <a href="quick-start-nginx.html#prepare-vm" class="md-nav__link">3. Prepare VM</a>
  253. </li>
  254. <li class="md-nav__item">
  255. <a href="quick-start-nginx.html#install-netmaker" class="md-nav__link">4. Install Netmaker</a>
  256. </li></ul>
  257. </li>
  258. <li class="md-nav__item">
  259. <a href="server-installation.html" class="md-nav__link">Advanced Server Installation</a>
  260. <ul class="md-nav__list">
  261. <li class="md-nav__item">
  262. <a href="server-installation.html#system-compatibility" class="md-nav__link">System Compatibility</a>
  263. </li>
  264. <li class="md-nav__item">
  265. <a href="server-installation.html#server-configuration-reference" class="md-nav__link">Server Configuration Reference</a>
  266. </li>
  267. <li class="md-nav__item">
  268. <a href="server-installation.html#dns-mode-setup" class="md-nav__link">DNS Mode Setup</a>
  269. </li>
  270. <li class="md-nav__item">
  271. <a href="server-installation.html#docker-compose-install" class="md-nav__link">Docker Compose Install</a>
  272. </li>
  273. <li class="md-nav__item">
  274. <a href="server-installation.html#linux-install-without-docker" class="md-nav__link">Linux Install without Docker</a>
  275. </li>
  276. <li class="md-nav__item">
  277. <a href="server-installation.html#kubernetes-install" class="md-nav__link">Kubernetes Install</a>
  278. </li>
  279. <li class="md-nav__item">
  280. <a href="server-installation.html#nginx-reverse-proxy-setup-with-https" class="md-nav__link">Nginx Reverse Proxy Setup with https</a>
  281. </li>
  282. <li class="md-nav__item">
  283. <a href="server-installation.html#highly-available-installation-kubernetes" class="md-nav__link">Highly Available Installation (Kubernetes)</a>
  284. </li>
  285. <li class="md-nav__item">
  286. <a href="server-installation.html#highly-available-installation-vms-bare-metal" class="md-nav__link">Highly Available Installation (VMs/Bare Metal)</a>
  287. </li></ul>
  288. </li>
  289. <li class="md-nav__item">
  290. <input class="md-toggle md-nav__toggle" data-md-toggle="toc" type="checkbox" id="__toc">
  291. <label class="md-nav__link md-nav__link--active" for="__toc"> Integrating OAuth </label>
  292. <a href="#" class="md-nav__link md-nav__link--active">Integrating OAuth</a>
  293. <nav class="md-nav md-nav--secondary">
  294. <label class="md-nav__title" for="__toc">Contents</label>
  295. <ul class="md-nav__list" data-md-scrollfix="">
  296. <li class="md-nav__item"><a href="#oauth--page-root" class="md-nav__link">Integrating OAuth</a><nav class="md-nav">
  297. <ul class="md-nav__list">
  298. <li class="md-nav__item"><a href="#introduction" class="md-nav__link">Introduction</a>
  299. </li>
  300. <li class="md-nav__item"><a href="#configuring-your-provider" class="md-nav__link">Configuring your provider</a>
  301. </li>
  302. <li class="md-nav__item"><a href="#configuring-netmaker" class="md-nav__link">Configuring Netmaker</a>
  303. </li>
  304. <li class="md-nav__item"><a href="#configuring-user-permissions" class="md-nav__link">Configuring User Permissions</a>
  305. </li></ul>
  306. </nav>
  307. </li>
  308. </ul>
  309. </nav>
  310. <ul class="md-nav__list">
  311. <li class="md-nav__item">
  312. <a href="#introduction" class="md-nav__link">Introduction</a>
  313. </li>
  314. <li class="md-nav__item">
  315. <a href="#configuring-your-provider" class="md-nav__link">Configuring your provider</a>
  316. </li>
  317. <li class="md-nav__item">
  318. <a href="#configuring-netmaker" class="md-nav__link">Configuring Netmaker</a>
  319. </li>
  320. <li class="md-nav__item">
  321. <a href="#configuring-user-permissions" class="md-nav__link">Configuring User Permissions</a>
  322. </li></ul>
  323. </li>
  324. <li class="md-nav__item">
  325. <a href="client-installation.html" class="md-nav__link">Client Installation</a>
  326. <ul class="md-nav__list">
  327. <li class="md-nav__item">
  328. <a href="client-installation.html#introduction-to-netclient" class="md-nav__link">Introduction to Netclient</a>
  329. </li>
  330. <li class="md-nav__item">
  331. <a href="client-installation.html#notes-on-windows" class="md-nav__link">Notes on Windows</a>
  332. </li>
  333. <li class="md-nav__item">
  334. <a href="client-installation.html#modes-and-system-compatibility" class="md-nav__link">Modes and System Compatibility</a>
  335. </li>
  336. <li class="md-nav__item">
  337. <a href="client-installation.html#prerequisites" class="md-nav__link">Prerequisites</a>
  338. </li>
  339. <li class="md-nav__item">
  340. <a href="client-installation.html#configuration" class="md-nav__link">Configuration</a>
  341. </li>
  342. <li class="md-nav__item">
  343. <a href="client-installation.html#installation" class="md-nav__link">Installation</a>
  344. </li>
  345. <li class="md-nav__item">
  346. <a href="client-installation.html#managing-netclient" class="md-nav__link">Managing Netclient</a>
  347. </li></ul>
  348. </li>
  349. <li class="md-nav__item">
  350. <a href="external-clients.html" class="md-nav__link">External Clients</a>
  351. <ul class="md-nav__list">
  352. <li class="md-nav__item">
  353. <a href="external-clients.html#introduction" class="md-nav__link">Introduction</a>
  354. </li>
  355. <li class="md-nav__item">
  356. <a href="external-clients.html#configuring-an-ingress-gateway" class="md-nav__link">Configuring an Ingress Gateway</a>
  357. </li>
  358. <li class="md-nav__item">
  359. <a href="external-clients.html#adding-clients-to-a-gateway" class="md-nav__link">Adding Clients to a Gateway</a>
  360. </li>
  361. <li class="md-nav__item">
  362. <a href="external-clients.html#configuring-dns-for-ext-clients-optional" class="md-nav__link">Configuring DNS for Ext Clients (OPTIONAL)</a>
  363. </li></ul>
  364. </li>
  365. <li class="md-nav__item">
  366. <a href="usage.html" class="md-nav__link">Using Netmaker</a>
  367. <ul class="md-nav__list">
  368. <li class="md-nav__item">
  369. <a href="usage.html#external-tutorials" class="md-nav__link">External Tutorials</a>
  370. </li></ul>
  371. </li>
  372. <li class="md-nav__item">
  373. <a href="api.html" class="md-nav__link">API Reference</a>
  374. <ul class="md-nav__list">
  375. <li class="md-nav__item">
  376. <a href="api.html#api-usage" class="md-nav__link">API Usage</a>
  377. </li>
  378. <li class="md-nav__item">
  379. <a href="api.html#authentication" class="md-nav__link">Authentication</a>
  380. </li>
  381. <li class="md-nav__item">
  382. <a href="api.html#format-of-calls-for-curl" class="md-nav__link">Format of Calls for Curl</a>
  383. </li>
  384. <li class="md-nav__item">
  385. <a href="api.html#api-documentation" class="md-nav__link">API Documentation</a>
  386. </li></ul>
  387. </li>
  388. <li class="md-nav__item">
  389. <a href="troubleshoot.html" class="md-nav__link">Troubleshooting</a>
  390. <ul class="md-nav__list">
  391. <li class="md-nav__item">
  392. <a href="troubleshoot.html#common-issues" class="md-nav__link">Common Issues</a>
  393. </li>
  394. <li class="md-nav__item">
  395. <a href="troubleshoot.html#server" class="md-nav__link">Server</a>
  396. </li>
  397. <li class="md-nav__item">
  398. <a href="troubleshoot.html#ui" class="md-nav__link">UI</a>
  399. </li>
  400. <li class="md-nav__item">
  401. <a href="troubleshoot.html#netclient" class="md-nav__link">Netclient</a>
  402. </li>
  403. <li class="md-nav__item">
  404. <a href="troubleshoot.html#coredns" class="md-nav__link">CoreDNS</a>
  405. </li></ul>
  406. </li>
  407. <li class="md-nav__item">
  408. <a href="support.html" class="md-nav__link">Support</a>
  409. <ul class="md-nav__list">
  410. <li class="md-nav__item">
  411. <a href="support.html#faq" class="md-nav__link">FAQ</a>
  412. </li>
  413. <li class="md-nav__item">
  414. <a href="support.html#contact" class="md-nav__link">Contact</a>
  415. </li></ul>
  416. </li>
  417. <li class="md-nav__item">
  418. <a href="conduct.html" class="md-nav__link">Code of Conduct</a>
  419. <ul class="md-nav__list">
  420. <li class="md-nav__item">
  421. <a href="conduct.html#our-pledge" class="md-nav__link">Our Pledge</a>
  422. </li>
  423. <li class="md-nav__item">
  424. <a href="conduct.html#our-standards" class="md-nav__link">Our Standards</a>
  425. </li>
  426. <li class="md-nav__item">
  427. <a href="conduct.html#our-responsibilities" class="md-nav__link">Our Responsibilities</a>
  428. </li>
  429. <li class="md-nav__item">
  430. <a href="conduct.html#scope" class="md-nav__link">Scope</a>
  431. </li>
  432. <li class="md-nav__item">
  433. <a href="conduct.html#enforcement" class="md-nav__link">Enforcement</a>
  434. </li>
  435. <li class="md-nav__item">
  436. <a href="conduct.html#attribution" class="md-nav__link">Attribution</a>
  437. </li></ul>
  438. </li>
  439. <li class="md-nav__item">
  440. <a href="license.html" class="md-nav__link">License</a>
  441. </li>
  442. </ul>
  443. </nav>
  444. </div>
  445. </div>
  446. </div>
  447. <div class="md-sidebar md-sidebar--secondary" data-md-component="toc">
  448. <div class="md-sidebar__scrollwrap">
  449. <div class="md-sidebar__inner">
  450. <nav class="md-nav md-nav--secondary">
  451. <label class="md-nav__title" for="__toc">Contents</label>
  452. <ul class="md-nav__list" data-md-scrollfix="">
  453. <li class="md-nav__item"><a href="#oauth--page-root" class="md-nav__link">Integrating OAuth</a><nav class="md-nav">
  454. <ul class="md-nav__list">
  455. <li class="md-nav__item"><a href="#introduction" class="md-nav__link">Introduction</a>
  456. </li>
  457. <li class="md-nav__item"><a href="#configuring-your-provider" class="md-nav__link">Configuring your provider</a>
  458. </li>
  459. <li class="md-nav__item"><a href="#configuring-netmaker" class="md-nav__link">Configuring Netmaker</a>
  460. </li>
  461. <li class="md-nav__item"><a href="#configuring-user-permissions" class="md-nav__link">Configuring User Permissions</a>
  462. </li></ul>
  463. </nav>
  464. </li>
  465. </ul>
  466. </nav>
  467. </div>
  468. </div>
  469. </div>
  470. <div class="md-content">
  471. <article class="md-content__inner md-typeset" role="main">
  472. <h1 id="oauth--page-root">Integrating OAuth<a class="headerlink" href="#oauth--page-root" title="Permalink to this headline">¶</a></h1>
  473. <h2 id="introduction">Introduction<a class="headerlink" href="#introduction" title="Permalink to this headline">¶</a></h2>
  474. <p>As of v0.8.5, Netmaker offers integration with the following OAuth providers:</p>
  475. <ul class="simple">
  476. <li><p>GitHub</p></li>
  477. <li><p>Google</p></li>
  478. <li><p>Microsoft Azure AD</p></li>
  479. </ul>
  480. <p>By integrating with an OAuth provider, your Netmaker users can log in via the provider, rather than the default simple auth.</p>
  481. <h2 id="configuring-your-provider">Configuring your provider<a class="headerlink" href="#configuring-your-provider" title="Permalink to this headline">¶</a></h2>
  482. <p>In order to use OAuth, configure your OAuth provider (GitHub, Google, Azure AD).</p>
  483. <p>You must configure your provider to use the Netmaker Dashboard URI dashboard.&lt;netmaker.base.domain&gt; as the origin URL.</p>
  484. <p>For example: <cite>https://dashboard.netmaker.mydomain.com</cite></p>
  485. <p>You must configure your provider to use the Netmaker API URI redirect route with the following format: <a class="reference external" href="https://api">https://api</a>.&lt;netmaker base domain&gt;/api/oauth2/callback.</p>
  486. <p>For example: <cite>https://api.netmaker.mydomain.com/api/oauth2/callback</cite></p>
  487. <p>General provider instructions can be found with the following links:</p>
  488. <p>Instructions for GitHub: <a class="reference external" href="https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#github-auth-provider">https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#github-auth-provider</a>
  489. Instructions for Google: <a class="reference external" href="https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#google-auth-provider">https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#google-auth-provider</a>
  490. Instructions for Microsoft Azure AD: <a class="reference external" href="https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#microsoft-azure-ad-provider">https://oauth2-proxy.github.io/oauth2-proxy/docs/configuration/oauth_provider/#microsoft-azure-ad-provider</a></p>
  491. <h2 id="configuring-netmaker">Configuring Netmaker<a class="headerlink" href="#configuring-netmaker" title="Permalink to this headline">¶</a></h2>
  492. <p>After you have configured your OAuth provider, take note of the CLIENT_ID and CLIENT_SECRET.</p>
  493. <p>Next, Configure Netmaker with the following environment variables. If any are left blank, OAuth will fail.</p>
  494. <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">AUTH_PROVIDER</span><span class="o">=</span><span class="s2">"&lt;azure-ad|github|google&gt;"</span>
  495. <span class="n">CLIENT_ID</span><span class="o">=</span><span class="s2">"&lt;client id of your oauth provider&gt;"</span>
  496. <span class="n">CLIENT_SECRET</span><span class="o">=</span><span class="s2">"&lt;client secret of your oauth provider&gt;"</span>
  497. <span class="n">SERVER_HTTP_HOST</span><span class="o">=</span><span class="s2">"https://&lt;your-netmaker-api-domain&gt;"</span>
  498. <span class="n">FRONTEND_URL</span><span class="o">=</span><span class="s2">"https://&lt;your-netmaker-dashboard-domain&gt;"</span>
  499. </pre></div>
  500. </div>
  501. <p>After restarting your server, the Netmaker logs will indicate if the OAuth provider was successfully initialized.</p>
  502. <p>Once successful, users can click the key symbol on the login page to sign-in with your configured OAuth provider.</p>
  503. <a class="reference internal image-reference" href="_images/oauth1.png"><img alt="Login Oauth" class="align-center" src="_images/oauth1.png" style="width: 80%;"/></a>
  504. <h2 id="configuring-user-permissions">Configuring User Permissions<a class="headerlink" href="#configuring-user-permissions" title="Permalink to this headline">¶</a></h2>
  505. <p>All users logging in will have zero permissions on first sign-in. An admin must configure all user permissions.</p>
  506. <p>Admins must navigate to the “Users” screen to configure permissions.</p>
  507. <p>For each user, an admin must specify which networks that user has access to configure. Additionally, an Admin can elevate a user to Admin permissions.</p>
  508. <a class="reference internal image-reference" href="_images/oauth3.png"><img alt="Edit User 2" class="align-center" src="_images/oauth3.png" style="width: 80%;"/></a>
  509. <a class="reference internal image-reference" href="_images/oauth2.png"><img alt="Edit User" class="align-center" src="_images/oauth2.png" style="width: 80%;"/></a>
  510. </article>
  511. </div>
  512. </div>
  513. </main>
  514. </div>
  515. <footer class="md-footer">
  516. <div class="md-footer-nav">
  517. <nav class="md-footer-nav__inner md-grid">
  518. <a href="server-installation.html" title="Advanced Server Installation"
  519. class="md-flex md-footer-nav__link md-footer-nav__link--prev"
  520. rel="prev">
  521. <div class="md-flex__cell md-flex__cell--shrink">
  522. <i class="md-icon md-icon--arrow-back md-footer-nav__button"></i>
  523. </div>
  524. <div class="md-flex__cell md-flex__cell--stretch md-footer-nav__title">
  525. <span class="md-flex__ellipsis">
  526. <span
  527. class="md-footer-nav__direction"> Previous </span> Advanced Server Installation </span>
  528. </div>
  529. </a>
  530. <a href="client-installation.html" title="Client Installation"
  531. class="md-flex md-footer-nav__link md-footer-nav__link--next"
  532. rel="next">
  533. <div class="md-flex__cell md-flex__cell--stretch md-footer-nav__title"><span
  534. class="md-flex__ellipsis"> <span
  535. class="md-footer-nav__direction"> Next </span> Client Installation </span>
  536. </div>
  537. <div class="md-flex__cell md-flex__cell--shrink"><i
  538. class="md-icon md-icon--arrow-forward md-footer-nav__button"></i>
  539. </div>
  540. </a>
  541. </nav>
  542. </div>
  543. <div class="md-footer-meta md-typeset">
  544. <div class="md-footer-meta__inner md-grid">
  545. <div class="md-footer-copyright">
  546. <div class="md-footer-copyright__highlight">
  547. &#169; Copyright 2021, Alex Feiszli.
  548. </div>
  549. Created using
  550. <a href="http://www.sphinx-doc.org/">Sphinx</a> 3.5.4.
  551. and
  552. <a href="https://github.com/bashtage/sphinx-material/">Material for
  553. Sphinx</a>
  554. </div>
  555. </div>
  556. </div>
  557. </footer>
  558. <script src="_static/javascripts/application.js"></script>
  559. <script>app.initialize({version: "1.0.4", url: {base: ".."}})</script>
  560. </body>
  561. </html>