Authentication¶
User Authentication¶
lakeFS authenticates users from a built-in authentication database.
Built-in database¶
The built-in authentication database is always present and active. lakeFS Community holds a single administrator user, created during the initial setup, while lakeFS Enterprise lets you create additional users from the Web UI at Administration / Users.
Users have an access key AKIA... and an associated secret access key. These credentials are valid
for logging into the Web UI or authenticating programmatic requests to the API Server or the S3 Gateway.
Info
On lakeFS Enterprise, the allowed authentication methods can be restricted (for example, disabling
access keys in favor of SSO) with auth.allowed_authentication_methods.
Single sign-on and external authenticators¶
lakeFS Community authenticates users only against the built-in database, so its login form accepts the administrator's access key and secret access key and nothing else. lakeFS Enterprise adds single sign-on through OIDC and SAML, a pluggable Remote Authenticator that delegates the login form to an existing identity service, AWS IAM role authentication, and short-lived tokens issued through an identity provider. The editions comparison lists which capabilities each edition includes.
API Server Authentication¶
Authenticating against the API server is done using a key-pair, passed via Basic Access Authentication.
All HTTP requests must carry an Authorization header with the following structure:
For example, assuming my access_key_id is my_access_key_id and my secret_access_key is my_secret_access_key, we'd send the following header with every request:
S3 Gateway Authentication¶
To provide API compatibility with Amazon S3, authentication with the S3 Gateway supports both SIGv2 and SIGv4. Clients such as the AWS SDK that implement these authentication methods should work without modification.
See this example for authenticating with the AWS CLI.
User permissions¶
lakeFS Community holds a single administrator user with full access, as described in Access Control in lakeFS Community. In lakeFS Enterprise, authorization is managed through groups and policies: users created by single sign-on join the groups configured for the identity provider, and their permissions can then be managed from the Administration pages in the lakeFS UI or with lakectl.