Kong Authorization
kong-authz is a Kong plugin that does request authorization with lua-casbin. You define models and policies as usual; the plugin enforces them on Kong routes.
Prerequisites
- Kong
- 4daysorm-adapter (optional, for database-backed policy storage)
- luasql-adapter (optional, for database-backed policy storage)
ข้อมูล
By default, policies are loaded from files. To use database-backed policies, install either 4daysorm-adapter or luasql-adapter.
การติดตั้ง
Install Casbin's system dependencies:
- For systems with
apt:
sudo apt install gcc libpcre3 libpcre3-dev
- For Alpine-based systems:
sudo apk add gcc pcre pcre-dev libc-dev
Install Casbin's latest release from LuaRocks:
sudo luarocks install casbin
Install the kong-authz plugin:
sudo luarocks install https://raw.githubusercontent.com/casbin-lua/kong-authz/master/kong-authz-0.0.1-1.rockspec
Add the plugin to your kong.conf by appending kong-authz (comma-separated) to the plugins variable:
# kong.conf
plugins = bundled, kong-authz
Start or restart Kong:
kong start [-c /path/to/kong.conf]
Configuration
Configure this plugin at the service, API, or global level through the Kong Admin API.