Skip to content

Authentication

User Authentication

lakeFS authenticates users from a built-in authentication database.

Built-in database

The built-in authentication database is always present and active. lakeFS Community holds a single administrator user, created during the initial setup, while lakeFS Enterprise lets you create additional users from the Web UI at Administration / Users.

Users have an access key AKIA... and an associated secret access key. These credentials are valid for logging into the Web UI or authenticating programmatic requests to the API Server or the S3 Gateway.

Info

On lakeFS Enterprise, the allowed authentication methods can be restricted (for example, disabling access keys in favor of SSO) with auth.allowed_authentication_methods.

Single sign-on and external authenticators

lakeFS Community authenticates users only against the built-in database, so its login form accepts the administrator's access key and secret access key and nothing else. lakeFS Enterprise adds single sign-on through OIDC and SAML, a pluggable Remote Authenticator that delegates the login form to an existing identity service, AWS IAM role authentication, and short-lived tokens issued through an identity provider. The editions comparison lists which capabilities each edition includes.

API Server Authentication

Authenticating against the API server is done using a key-pair, passed via Basic Access Authentication.

All HTTP requests must carry an Authorization header with the following structure:

Authorization: Basic <base64 encoded access_key_id:secret_access_key>

For example, assuming my access_key_id is my_access_key_id and my secret_access_key is my_secret_access_key, we'd send the following header with every request:

Authorization: Basic bXlfYWNjZXNzX2tleV9pZDpteV9zZWNyZXRfYWNjZXNzX2tleQ==

S3 Gateway Authentication

To provide API compatibility with Amazon S3, authentication with the S3 Gateway supports both SIGv2 and SIGv4. Clients such as the AWS SDK that implement these authentication methods should work without modification.

See this example for authenticating with the AWS CLI.

User permissions

lakeFS Community holds a single administrator user with full access, as described in Access Control in lakeFS Community. In lakeFS Enterprise, authorization is managed through groups and policies: users created by single sign-on join the groups configured for the identity provider, and their permissions can then be managed from the Administration pages in the lakeFS UI or with lakectl.