Create local users :: Kloudfuse Docs

Create local users

After installing Kloudfuse, add users and manage their credentials.

The user appears in the Admin > Users tab after they log in for the first time.

Follow these steps:

  1. Connect to your Kloudfuse kubernetes cluster.

  2. Drop the content of the users.txt file.

If it exists, the file is in htpassword format.

rm -f users.txt
  1. Retrieve the users.txt file in the kfuse-auth-users secret, and save it locally. Otherwise, create a users.txt file.
kubectl get secret -n kfuse kfuse-auth-users -o json | jq -r '.data."users.txt"' | base64 -d > users.txt
  1. (Optional) If changing the password of a user, then remove existing entry for that user from users.txt file.

  2. Create or change the user’s password.

This example is for user testuser. For an admin user, use admin.

htpasswd -Bn testuser >> users.txt
htpasswd supports users with empty passwords. Ensure that you provide a password for the user after running the above command.
  1. Ensure that the users.txt file does not have empty lines between users.
sed -i '' '/^$/d' users.txt
  1. If the users.txt file does not end with a new line, ensure that it does by running the following command.
echo "" >> users.txt
  1. Encode the users.txt file using base64 format.
cat users.txt | base64
  1. Use the following command to edit the existing kfuse-auth-users secret.
kubectl edit secret kfuse-auth-users
  1. Otherwise, create a new Kubernetes secret, kfuse-auth-users.
kubectl apply -f kfuse-auth-users
  1. Use the output of cat users.txt| base64 as the value of users.txt entry in the secret.
apiVersion: v1
data:
     users.txt: |-
       <base64-encoded-value>
kind: Secret
metadata:
     name: kfuse-auth-users
type: Opaque
  1. For fresh installations, update your custom-values.yaml to point to the kfuse-auth-users secret.
kfuse-auth:
     oauth2-proxy:
       htpasswdFile:
         existingSecret: kfuse-auth-users
  1. Restart kfuse-auth deployment.
kubectl -n kfuse rollout restart deployment kfuse-auth
  1. After you log in with the new user/password credentials for the first time, these appear in the Admin > Users interface.