[
https://issues.apache.org/jira/browse/NIFI-14183?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
David Handermann updated NIFI-14183:
------------------------------------
Issue Type: Improvement (was: Bug)
> NiFi cluster UI fails to proxy user requests with OIDC Authentication due to
> missing node authorization
> -------------------------------------------------------------------------------------------------------
>
> Key: NIFI-14183
> URL: https://issues.apache.org/jira/browse/NIFI-14183
> Project: Apache NiFi
> Issue Type: Improvement
> Components: Configuration, Core UI, Docker
> Affects Versions: 2.1.0
> Reporter: christofe lintermans
> Priority: Major
>
> The official NiFi Docker image (e.g., {{{}apache/nifi:2.1.0{}}}) does not
> provide a way to dynamically configure users with the {{proxy}} policy when
> using {{AUTH=oidc, tls,...}} and setting {{{}INITIAL_ADMIN_IDENTITY{}}}.
> While I understand that requests to the NiFi UI are proxied by the receiving
> node to the cluster coordinator, which replicates the request across all
> nodes, configuring dynamic clusters remains a challenge.
> To authorize new nodes, I must manually add the Common Name (CN) of each node
> to the {{authorizers.xml or }}{{users.xml}} and {{{}authorizations.xml{}}}.
> Even when adding the node's CN to {{{}authorizers.xml{}}}, deleting
> {{{}{}}}{{{}users.xml{}}} and {{authorizations.xml, restarting nifi nodes
> }}the required {{proxy}} policy is missing. This requires additional manual
> edits to {{users.xml}} and {{{}authorizations.xml{}}}, which makes the
> process impractical for dynamic, scalable environments such as Kubernetes.
> *Impact:*
> * Prevents automated scaling of NiFi clusters in environments like
> Kubernetes.
> * Requires manual intervention to authorize new nodes, breaking automation
> workflows and dynamic scaling capabilities.
> *Proposed Solution:*
> # Add support for defining node proxy user policies through environment
> variables.
> # Document best practices for dynamic user and node authorization in the
> official Docker image.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)