Private Cloud 환경에서 Management Console 인증을 LDAP(FreeIPA)으로 설정한 뒤, FreeIPA 사용자가 Cloudera AI 워크벤치에 들어가려 하면 SAML 오류가 났다. 원인은 Management Console 의 Email Mapping Attribute 가 uid 로 잡혀 있어 이메일 자리에 로그인 ID 가 들어간 것이었다. 워크벤치는 SAML SP, Control Plane 은 IdP 로 동작하며 기본 NameID Format 이 emailAddress 라서 이메일 형식이 아닌 값은 검증에서 거부된다.
[LDAP/FreeIPA] → [Control Plane / Management Console] → [Cloudera AI Workbench]
사용자 원본 IdP 역할 (LDAP 조회) SP 역할
←──── 이 구간이 SAML ────→
Management Console 에서 LDAP 으로 바꿔도 워크벤치와 Control Plane 사이의 SSO 는 여전히 SAML 이다. SAML 오류는 "SAML 을 써서" 가 아니라 LDAP 에서 넘어온 사용자 속성이 assertion 요건(username, email, cn)을 못 맞춰서 난다. 워크벤치 내부 Admin > Security 의 LDAP 설정은 Cloudera 가 권장하지 않으며 Private Cloud 에서는 쓰지 않는다.
Cloudera Management Console → Administration → Authentication.
| 항목 | 값 |
|---|---|
| LDAP URL | ldaps://<ipa-host>:636 |
| CA Certificate | ldaps 사용 시 PEM |
| LDAP Bind DN | uid=<binduser>,cn=users,cn=accounts,dc=example,dc=com |
| LDAP User Search Base | cn=users,cn=accounts,dc=example,dc=com |
| LDAP User Search Filter | (&(uid={0})(objectClass=person)) |
| LDAP Group Search Base | cn=groups,cn=accounts,dc=example,dc=com |
| LDAP Group Search Filter | (&(member={0})(objectClass=posixgroup)(!(cn=admins))) |
| Email Mapping Attribute | mail (비우면 기본값 mail) |
| Username Mapping Attribute | uid (Show Other Options 안, 필수) |
AD 를 쓰면 Global Catalog 포트 3268/3269 를 써야 환경 활성화가 실패하지 않는다. LDAP User Bind Property 와 Group DN Property 는 dn 으로 둔다. Test Connection → Save 후 User Management 에 사용자가 이메일과 함께 표시되는지 확인한다.
ipa user-show <username> --all | grep -i mail # mail 속성이 있어야 함
ipa user-mod <username> --email=<username>@<domain> # 비어 있으면 채움
ipa user-find --all --raw | awk '/^ uid:/{u=$2} /^ mail:/{m=1} /^$/{if(u && !m) print u; u=""; m=0}'
uid → mail 로 변경(또는 공란).@cdp.example 대체값이 아닌 실제 값인지 확인.MLUser 또는 MLAdmin 부여. 워크벤치 최초 로그인 사용자는 EnvironmentAdmin 이어야 한다.이메일은 Cloudera 에서 필수값이며 값이 없으면 {username}@cdp.example 로 대체된다. 이 도메인은 존재하지 않아 나중에 사용자 식별이 꼬이므로 FreeIPA 사용자의 mail 을 미리 채워 둔다. 역할(5번)을 빼먹으면 SAML 은 통과해도 워크벤치에서 권한 없음으로 튕긴다.
chronyc tracking).kubectl -n <workbench-ns> logs deploy/web --tail=200 | grep -i saml 와 kubectl -n cdp-services logs -l app=cdp-release-thunderhead-management-console-ui 로 본다.