Skip to main content

Lock-Nessie provides a client and server pair for authentication to Nessie with OpenID.

Project description

Lock Nessie

Quickly and simply add OpenID auth to your Iceberg Nessie stack

Server

This component facilitiates your OpenID Oauth2 login flow.

Envars:

Required for all providers:

  • LOCKNESSIE_ENVIRONMENT: 'production' for released code, 'development' for local development
  • LOCKNESSIE_REDIRECT_BASE: The base URL for redirects
  • LOCKNESSIE_OPENID_ISSUER: The issuer of the OpenID client, one of:
    • microsoft # entra
    • keycloak
  • LOCKNESSIE_OPENID_CLIENT_ID: The client ID of the OpenID client
  • LOCKNESSIE_OPENID_CLIENT_SECRET: The client secret of the OpenID client
  • LOCKNESSIE_SECRET_PROVIDER: The provider where the secret is stored, one of:
    • aws_secrets_manager
    • hachicorp_vault

Required for microsoft:

  • LOCKNESSIE_OPENID_TENANT: The tenant of the OpenID client (required for Microsoft)

Required for keycloak:

  • LOCKNESSIE_OPENID_REALM: The realm of the OpenID client (required for Keycloak)
  • LOCKNESSIE_OPENID_URL: The URL of the OpenID provider

Required for aws: note: lock-nessie uses the standard boto3 credentials order. For lock-nessie to leverage AWS Secrets Manager, credentials must be provided that have:

    "secretsmanager:CreateSecret",       // Create a new secret
    "secretsmanager:GetSecretValue",     // Read the secret value
    "secretsmanager:DescribeSecret",     // Read secret metadata
    "secretsmanager:PutSecretValue"      // Write/update secret value

Optional:

  • LOCKNESSIE_MAX_AGE: The maximum age of the cookie in seconds (default: 31536000 - 1 year). Note this is not the same as the token age for the OpenID auth.

Client:

Required for all providers:

  • LOCKNESSIE_SECRET_PROVIDER: The provider where the secret is stored, one of:
    • aws_secrets_manager
    • hachicorp_vault
  • LOCKNESSIE_SECRET_IDENTIFIER: The resource id for the secret, like an arn in aws.

Optional:

  • LOCKNESSIE_CACHE_PATH: Where to store the cached OpenID token.
  • LOCKNESSIE_SERVER_URL: If provided, the client will attempt to pop open a login window when the token has expired.

Client integrations

PyIceberg

from locknessie.client.pyiceberg import load_catalog

catalog = load_catalog("nessie", uri="http://nessie:19120/iceberg/main/")

note: There is a bunch of auth bits in pyiceberg that indicate better integration may be possible, but it is non-obvious how a web-based login flow, refresh token etc would work in practice. TODO see if this can be refined.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

locknessie-0.0.1.tar.gz (390.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

locknessie-0.0.1-py3-none-any.whl (367.7 kB view details)

Uploaded Python 3

File details

Details for the file locknessie-0.0.1.tar.gz.

File metadata

  • Download URL: locknessie-0.0.1.tar.gz
  • Upload date:
  • Size: 390.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.12.9

File hashes

Hashes for locknessie-0.0.1.tar.gz
Algorithm Hash digest
SHA256 c6e7dbdfa3991a00d53c7a0ab20e9b7e99e299df7f32d009ac8b294c5916d65e
MD5 0f01d9371a271deb951b41249c7fd0b5
BLAKE2b-256 f8c5b42faa0cb150b6e0ddb8e2d6a1a03b3a84cbb514f8bb99fda398b49ccef6

See more details on using hashes here.

Provenance

The following attestation bundles were made for locknessie-0.0.1.tar.gz:

Publisher: publish.yml on pirate-baby/lock-nessie

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file locknessie-0.0.1-py3-none-any.whl.

File metadata

  • Download URL: locknessie-0.0.1-py3-none-any.whl
  • Upload date:
  • Size: 367.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.12.9

File hashes

Hashes for locknessie-0.0.1-py3-none-any.whl
Algorithm Hash digest
SHA256 fdc72bfab612d1fc2342aa01991f94c855d60b35e1a16130ab4694a87acf1633
MD5 1a902502d791b85c0a14dc9f3929f670
BLAKE2b-256 d7b9652068c7021f7767acbb3c96944e3d3b6c770be0bc5414d768c7483c21b7

See more details on using hashes here.

Provenance

The following attestation bundles were made for locknessie-0.0.1-py3-none-any.whl:

Publisher: publish.yml on pirate-baby/lock-nessie

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page