Skip to main content
Version: 0.0.42

Identity Providers

Lakehousecat supports OAuth/OIDC-based Single Sign-On as an optional authentication layer. When configured, users can sign in using their existing organizational credentials instead of (or in addition to) a native email/password account.

Operator Configuration

Identity provider integration is configured at the Operator level in the Lakehousecat CR YAML — not through the application UI. Configuration changes require access to the Kubernetes cluster.

Supported Providers​

ProviderKey
Googlegoogle
Microsoft Entra ID (Azure AD)microsoft
Generic OIDCoidc
Auth0auth0
AWS Cognitoaws

Configuration Structure​

OAuth is configured under spec.auth.oauth in the Lakehousecat CR:

spec:
auth:
jwt:
expiresIn: "2d"

oauth:
enableSignup: false # Allow new users to sign up via OAuth
mergeAccountsByEmail: false # Merge OAuth accounts with existing users by email

providers:
google:
clientId: "your-client-id.apps.googleusercontent.com"
clientSecret: "your-client-secret"
scope: "openid email profile"

microsoft:
clientId: "your-client-id"
clientSecret: "your-client-secret"
tenantId: "common" # "common", "organizations", or specific tenant ID
scope: "openid email profile User.Read"

oidc:
clientId: "your-client-id"
clientSecret: "your-client-secret"
providerUrl: "https://sso.example.com/.well-known/openid-configuration"
providerName: "Company SSO"
scopes: "openid email profile"
claims:
username: "preferred_username"
email: "email"
picture: "picture"

auth0:
clientId: "your-client-id"
clientSecret: "your-client-secret"
domain: "myapp.auth0.com"
scope: "openid email profile"

aws:
clientId: "your-cognito-app-client-id"
clientSecret: "your-cognito-app-client-secret"
userPoolId: "us-east-1_AbCdEfGhI"
region: "us-east-1"
scope: "openid email profile"

Role Mapping from OAuth​

Lakehousecat can automatically assign roles based on claims in the OAuth token:

spec:
auth:
roleManagement:
enableOAuthRoleManagement: false
rolesClaim: "roles" # JWT claim containing user roles
allowedRoles:
- "user"
- "admin"
adminRoles:
- "admin"

When enableOAuthRoleManagement is true, users whose token contains a role in adminRoles are assigned the Administrator role. All other users with a role in allowedRoles receive the User role.

Trusted Headers (Reverse Proxy)​

For deployments where authentication is handled by an external reverse proxy (e.g., nginx, Traefik), Lakehousecat can accept authentication headers directly:

spec:
auth:
trustedHeaders:
emailHeader: "X-Auth-Email"
nameHeader: "X-Auth-Name"

When configured, the reverse proxy is responsible for authenticating the user and passing their email and name via the specified headers.

Setup Assistance​

Configuring an identity provider requires registering Lakehousecat as an application in the provider's console (redirect URI, client credentials) and applying the configuration to the cluster. For detailed setup assistance, contact Lakehousecat support.