๐Ÿ“—
smiley book
  • Smiley Books
  • AI
    • Readme
    • openai-whisper
      • ์ƒ˜ํ”Œ ์‹คํ–‰ํ•ด๋ณด๊ธฐ
      • GPU ์„œ๋ฒ„ ์ค€๋น„ํ•˜๊ธฐ
      • API๋กœ whisper๋ฅผ ์™ธ๋ถ€์— ์˜คํ”ˆํ•˜๊ธฐ
      • ํ”„๋กฌํ”„ํŠธ ์ง€์›
      • ์‹ค์‹œ๊ฐ„ message chat
      • ํ™”๋ฉด ์ด์˜๊ฒŒ ๋งŒ๋“ค๊ธฐ์™€ ๋กœ๊ทธ์ธ
      • ํŒŒ์ด์ฌ ๊ฐ€์ƒํ™˜๊ฒฝ
      • ์‹ค์‹œ๊ฐ„ voice chat
      • fine tunning(๋ฏธ์„ธ ์กฐ์ •) ์œผ๋กœ ์„ฑ๋Šฅ ์˜ฌ๋ฆฌ๊ธฐ
      • app์—์„œ api๋ฅผ ํ˜ธ์ถœํ•˜์—ฌ ์‹ค์‹œ๊ฐ„์œผ๋กœ ํ…์ŠคํŠธ๋กœ ๋ฐ”๊ฟ”๋ณด๊ธฐ
    • ollama - llm์„ ์‰ฝ๊ฒŒ ๋‚ด์ปด์—์„œ ์‹คํ–‰
      • ollama webui
      • ollama docker
    • stable diffusion
      • SDXL - text to image
      • SD-webui
    • ChatGPT
      • ๋‹ต๋ณ€์ด ๋Š๊ธธ๋•Œ
      • ์—ญํ• ์„ ์ •ํ•˜์ž
      • ๊ตฌ์ฒด์ ์ธ ์งˆ๋ฌธ
      • ๊ฒฐ๊ณผํ˜•ํƒœ๋ฅผ ์ง€์ •
      • ํ”„๋กฌํ”„ํŠธ๋ฅผ ์—ฌ๋Ÿฌ์ค„๋กœ ์‚ฌ์šฉํ•˜์ž.
      • ๋งˆํ‹ด ํŒŒ์šธ๋Ÿฌ ๊ธ€ ๋ฒˆ์—ญ๋ณธ
    • Prompt Engineering
    • Auto-GPT
    • Gemini
      • google ai studio
      • gemini-api
      • embedding guide
    • Huggingface
      • huggingface ์‚ฌ์šฉ๋ฒ•
      • huggingface nlp ๊ณต๋ถ€์ค‘
    • kaggle
      • download dataset
    • langchain
      • langchain์„ ๊ณต๋ถ€ํ•˜๋ฉฐ ์ •๋ฆฌ
      • basic
      • slackbot
      • rag
      • document-loader
      • website-loader
      • confluence
      • memory
      • function-call
      • langsmith
      • agent-toolkit
  • Ansible
    • templates vs files and jinja2
    • dynamic inventory
    • limit ์˜ต์…˜ ๊ฐ•์ œํ•˜๊ธฐ
    • limit ์‚ฌ์šฉํ›„ gather_fact ๋ฌธ์ œ
  • AWS
    • AWS CLI
    • EKS
      • cluster manage
      • ALB Controller
      • external-dns
      • fargate
    • ECR
    • S3
    • Certificate Manager
  • Azure
    • Azure AD OAuth Client Flow
  • Container
    • Registry
    • ๋นŒ๋“œ์‹œ์— env๊ฐ’ ์„ค์ •ํ•˜๊ธฐ
  • DB
    • PXC
      • Operator
      • PMM
      • ์‚ญ์ œ
      • GTID
      • Cross Site Replication
    • Mssql
    • Mysql
  • dotnet
    • Thread Pool
    • Connection Pool
    • Thread Pool2
  • Devops
    • Recommendation
  • GIT
    • Basic
    • Submodule
  • GitHub
    • Repository
    • GitHub Action
    • GitHub PR
    • Self Hosted Runner
    • GitHub Webhook
  • GitLab
    • CI/CD
    • CI/CD Advance
    • Ssl renew
    • CI/CD Pass env to other job
  • Go Lang
    • ๊ฐœ๋ฐœ ํ™˜๊ฒฝ ๊ตฌ์ถ•
    • multi os binary build
    • kubectl๊ฐ™์€ cli๋งŒ๋“ค๊ธฐ
    • azure ad cli
    • embed static file
    • go study
      • pointer
      • module and package
      • string
      • struct
      • goroutine
  • Kubernetes
    • Kubernetes๋Š” ๋ฌด์—‡์ธ๊ฐ€
    • Tools
    • Install with kubespray
    • Kubernetes hardening guidance
    • 11 ways not to get hacked
    • ArgoCD
      • Install
      • CLI
      • Repository
      • Apps
      • AWS ALB ์‚ฌ์šฉ
      • Notification slack
      • Backup / DR
      • Ingress
      • 2021-11-16 Github error
      • Server Config
      • auth0 ์ธ์ฆ ์ถ”๊ฐ€(oauth,OIDC)
    • Extension
      • Longhorn pvc
      • External dns
      • Ingress nginx
      • Cert Manager
      • Kube prometheus
    • Helm
      • Subchart
      • Tip
    • Loki
    • Persistent Volume
    • TIP
      • Job
      • Pod
      • Log
  • KAFKA
    • raft
  • KVM
    • kvm cpu model
  • Linux
    • DNS Bind9
      • Cert-Manager
      • Certbot
      • Dynamic Update
      • Log
    • Export and variable
    • Grep ์‚ฌ์šฉ๋ฒ•
  • Modeling
    • C4 model introduce
    • Mermaid
    • reference
  • Monitoring
    • Readme
    • 0. What is Monitoring
    • 1. install prometheus and grafana
    • 2. grafana provisioning
    • 3. grafana dashboard
    • 4. grafana portable dashboard
    • 5. prometheus ui
    • 6. prometheus oauth2
    • Prometheus
      • Metric type
      • basic
      • rate vs irate
      • k8s-prometheus
    • Grafana
      • Expolorer
    • Node Exporter
      • advance
      • textfile collector
  • Motivation
    • 3 Simple Rule
  • OPENNEBULA
    • Install(ansible)
    • Install
    • Tip
    • Windows vm
  • Reading
    • comfort zone
    • ๋ฐฐ๋ ค
    • elon musk 6 rule for insane productivity
    • Feynman Technique
    • how to interview - elon musk
    • ๊ฒฝ์ฒญ
    • Readme
  • Redis
    • Install
    • Master-slave Architecture
    • Sentinel
    • Redis Cluster
    • Client programming c#
  • SEO
    • Readme
  • Security
    • criminalip.io
      • criminalip.io
  • Stock
    • robinhood-python
  • Terraform
    • moved block
    • output
  • vault
    • Readme
  • VS Code
    • dev container
    • dev container on remote server
  • Old fashione trend
    • curity
    • MAAS
      • Install maas
      • Manage maas
      • Tip
Powered by GitBook
On this page
  • api key
  • ๊ตฌ์กฐ
  • client ๋งŒ๋“ค๊ธฐ
  • mycli ์„ค์ •
  • api app์— role ์ถ”๊ฐ€
  • mycli ์•ฑ์—์„œ ๋ฐฉ๊ธˆ ์ถ”๊ฐ€ํ•œ ๋กค์„ ์‚ฌ์šฉ
  • ํ…Œ์ŠคํŠธ
  • ์ด์ œ ์™„๋ฃŒ
  • ๋‹ค์Œ ๋‹จ๊ณ„

Was this helpful?

  1. Azure

Azure AD OAuth Client Flow

ํšŒ์‚ฌ์—์„œ ์›น์‚ฌ์ดํŠธ๋ฅผ ๋งŒ๋“ค๋‹ค ๋ณด๋ฉด api ์™€ front๋ฅผ ๋งŒ๋“ค์–ด์•ผ ํ•œ๋‹ค.

์—ฌ๊ธฐ์— ์ธ์ฆ์„ azure ad(ํšŒ์‚ฌ์˜ ์œ ์ €์ •๋ณด)์™€ ๊ฐ™์œผ๋ฉด ํŽธํ• ๋•Œ๊ฐ€ ์žˆ๋‹ค.

Azure AD๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์œ ์ € ๋กœ๊ทธ์ธ ํ•˜๋Š” ๋ถ€๋ถ„์€ ๋”ฐ๋กœ ์ •๋ฆฌํ•˜๊ธฐ๋กœ ํ•˜๊ณ  ์˜ค๋Š˜์€ api key์ฒ˜๋Ÿผ ์‚ฌ์šฉํ• ์ˆ˜ ์ž‡๋Š” ๋ถ€๋ถ„์„ ํ™•์ธํ•ด๋ณด์ž.

api key

Azure ad๋Š” oauth2๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค.

api key๋Š” oauth2์—์„œ client credential flow๋กœ ์‚ฌ์šฉํ•œ๋‹ค.

ํด๋ผ์ด์–ธํŠธ์— ์‹œํฌ๋ฆฟ์„ ๋ณด๋‚ด๋ฉด azure ad๊ฐ€ access token์„ ๋ฐœ๊ธ‰ํ•ด์ค€๋‹ค.

๊ตฌ์กฐ

azure ad์— ๊ธฐ์กด์— resource-api๋ผ๋Š” api์•ฑ์ด ์žˆ๋‹ค๊ณ  ํ•˜์ž.

postman์œผ๋กœ ์ด๊ฒƒ์„ ํ…Œ์ŠคํŠธํ•ด๋ณด๊ณ  ์‹ถ๋‹ค.

postman๋„ code flow๋ฅผ ์ง€์›ํ•˜๋‚˜ ์—ฌ๊ธฐ์„œ๋Š” client credential flow๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค.

client ๋งŒ๋“ค๊ธฐ

azure ad์—์„œ app์„ ํ•˜๋‚˜ ๋” ์ถ”๊ฐ€ํ•œ๋‹ค.

์ด๋ฆ„์€ mycli๋กœ ํ•˜์ž.

๋งŒ๋“ค๊ณ  ๋‚˜๋ฉด ๋‹ค์Œ์ฒ˜๋Ÿผ ๋ณด์ธ๋‹ค.

mycli ์„ค์ •

์ด์ œ ์„ค์ •์„ ํ•˜์ž.

์ผ๋‹จ ์ด ์ •๋ณด๋ฅผ ์ž˜ ์ ์–ด๋‘์ž.

endpoint๋Š” ํด๋ฆญํ•˜๊ณ  ๋‚˜๋ฉด ๋‹ค์Œ ์ฃผ์†Œ๋ฅผ ๋ณต์‚ฌํ•ด๋‘”๋‹ค.

token end point๋ฅผ ์ž˜ ๋ณต์‚ฌํ•ด๋‘”๋‹ค.

์ด์ œ client secret๋ฅผ ๋ฐœ๊ธ‰ํ•˜์ž.

์ด์ œ ๋ฐœ๊ธ‰๊นŒ์ง€ ๋ฌ๋‹ค.

์ด์ œ Api permission์„ ์„ค์ •ํ•ด์•ผํ•˜๋Š”๋ฐ ์—ฌ๊ธฐ์—์„œ๋Š” ์‚ฌ์šฉํ•˜๊ณ  ์‹ถ์€ api์—์„œ ๊ถŒํ•œ์„ ์˜คํ”ˆ์„ ํ•ด์ค˜์•ผํ•œ๋‹ค.

api ์•ฑ์— ๊ฐ€์„œ ๋‹ค์Œ์ฒ˜๋Ÿผ ๊ถŒํ•œ์„ ๋งŒ๋“ค์–ด์ค€๋‹ค.

api app์— role ์ถ”๊ฐ€

api ์•ฑ์—์„œ app roles๋ฅผ ์ถ”๊ฐ€ํ•ด์ค€๋‹ค.

์ด๋ ‡๊ฒŒ ํ•˜๊ณ  ์ถ”๊ฐ€ํ•˜๋ฉด ๋กค์ด ์ถ”๊ฐ€๋œ๋‹ค.

mycli ์•ฑ์—์„œ ๋ฐฉ๊ธˆ ์ถ”๊ฐ€ํ•œ ๋กค์„ ์‚ฌ์šฉ

์ด์ œ role์„ ์‚ฌ์šฉํ•ด๋ณด์ž.

Api permission์„ ์„ค์ •ํ•˜์ž.

์„ค์ •ํ•˜๊ณ  ๋‚˜๋ฉด admin์— ๊ถŒํ•œ์„ ํ•„์š”๋กœ ํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋‹ค ์ด๊ฑด admin์—๊ฒŒ ์—ฐ๋ฝํ•˜์—ฌ ํ—ˆ๊ฐ€๋ฅผ ํ•ด๋‹ฌ๋ผ๊ณ  ํ•ด์•ผํ•œ๋‹ค.

ํ—ˆ๊ฐ€๊ฐ€ ๋˜๊ณ ๋‚˜๋ฉด ํฌ์ŠคํŠธ๋งจ์—์„œ ํ…Œ์ŠคํŠธ๋ฅผ ํ•ด๋ณด์ž.

ํ…Œ์ŠคํŠธ

๊ทธ๋ฆผ์ฒ˜๋Ÿผ ์„ค์ •ํ•˜๊ณ  ์š”์ฒญ์„ ๋‚ ๋ฆฌ๋ฉด access token์„ ๋ฐ›์•„์˜จ๋‹ค.

token endpoint์ฃผ์†Œ๋ฅผ ์‚ฌ์šฉ ํ•œ๋‹ค.

grant_type์€ client_credential์ด๋‹ค.

client_id๋Š” mycli์˜ client id๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค.

์ค‘์š”) scope๋Š” ์‚ฌ์šฉํ•˜๊ณ ์ž ํ•˜๋Š” api์— ํ•ด๋‹นํ•˜๋Š” scope๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค.

api์— ๊ฐ€์„œ ์ด ์ •๋ณด๋ฅผ ๊ฐ€์ ธ์™€์„œ ์‚ฌ์šฉํ•œ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ๊ทธ ๋’ค์— /.default๋ฅผ ๋ถ™์—ฌ์•ผํ•œ๋‹ค.

api://xxxxxxxx/.default

์ด๋Ÿฐ ํ˜•ํƒœ์ด๋‹ค.

์ด์ œ ์ด ์—‘์„ธ์Šค ํ† ํฐ์„ ์‚ฌ์šฉํ•˜์—ฌ api๋ฅผ ํ˜ธ์ถœํ•ด๋ณด์ž.

ํ† ํฐ์„ ๋ณต์‚ฌํ•ด์„œ ์—ฌ๊ธฐ์— ๋„ฃ๊ณ  send๋ฅผ ํ•˜๋ฉด ๊ฒฐ๊ณผ๋ฅผ ๊ฐ€์ ธ์˜จ๋‹ค.

์ด์ œ ์™„๋ฃŒ

์ด์ œ ์™„๋ฃŒ ๋˜์—ˆ๋‹ค. ๋‹ค์Œ์—๋Š” cli ํ”„๋กœ๊ทธ๋žจ์„ ๋งŒ๋“ค์–ด์„œ ์–ด๋–ป๊ฒŒ ์œ„ ๋‚ด์šฉ์„ ์–ด๋–ป๊ฒŒ ํ•˜๋Š”์ง€ ์•Œ์•„๋ณด์ž.

๋‹ค์Œ ๋‹จ๊ณ„

์ด๊ฑธ ์ฝ์–ด๋ณด์ž.

PreviousCertificate ManagerNextRegistry

Last updated 2 years ago

Was this helpful?

https://teamsmiley.gitbook.io/devops/go-lang/cli-azuread