Identity Providers
Lakehousecat supports OAuth/OIDC-based Single Sign-On as an optional authentication layer. When configured, users can sign in using their existing organizational credentials instead of (or in addition to) a native email/password account.
Identity provider integration is configured at the Operator level in the Lakehousecat CR YAML — not through the application UI. Configuration changes require access to the Kubernetes cluster.
Supported Providers
| Provider | Key |
|---|---|
google | |
| Microsoft Entra ID (Azure AD) | microsoft |
| Generic OIDC | oidc |
| Auth0 | auth0 |
| AWS Cognito | aws |
Configuration Structure
OAuth is configured under spec.auth.oauth in the Lakehousecat CR:
spec:
auth:
jwt:
expiresIn: "2d"
oauth:
enableSignup: false # Allow new users to sign up via OAuth
mergeAccountsByEmail: false # Merge OAuth accounts with existing users by email
providers:
google:
clientId: "your-client-id.apps.googleusercontent.com"
clientSecret: "your-client-secret"
scope: "openid email profile"
microsoft:
clientId: "your-client-id"
clientSecret: "your-client-secret"
tenantId: "common" # "common", "organizations", or specific tenant ID
scope: "openid email profile User.Read"
oidc:
clientId: "your-client-id"
clientSecret: "your-client-secret"
providerUrl: "https://sso.example.com/.well-known/openid-configuration"
providerName: "Company SSO"
scopes: "openid email profile"
claims:
username: "preferred_username"
email: "email"
picture: "picture"
auth0:
clientId: "your-client-id"
clientSecret: "your-client-secret"
domain: "myapp.auth0.com"
scope: "openid email profile"
aws:
clientId: "your-cognito-app-client-id"
clientSecret: "your-cognito-app-client-secret"
userPoolId: "us-east-1_AbCdEfGhI"
region: "us-east-1"
scope: "openid email profile"
Role Mapping from OAuth
Lakehousecat can automatically assign roles based on claims in the OAuth token:
spec:
auth:
roleManagement:
enableOAuthRoleManagement: false
rolesClaim: "roles" # JWT claim containing user roles
allowedRoles:
- "user"
- "admin"
adminRoles:
- "admin"
When enableOAuthRoleManagement is true, users whose token contains a role in adminRoles are assigned the Administrator role. All other users with a role in allowedRoles receive the User role.
Trusted Headers (Reverse Proxy)
For deployments where authentication is handled by an external reverse proxy (e.g., nginx, Traefik), Lakehousecat can accept authentication headers directly:
spec:
auth:
trustedHeaders:
emailHeader: "X-Auth-Email"
nameHeader: "X-Auth-Name"
When configured, the reverse proxy is responsible for authenticating the user and passing their email and name via the specified headers.
Setup Assistance
Configuring an identity provider requires registering Lakehousecat as an application in the provider's console (redirect URI, client credentials) and applying the configuration to the cluster. For detailed setup assistance, contact Lakehousecat support.