Now I want to upgrade to a proper OAuth wall. Some server needs to act as a reverse proxy that has permission to access the private resource but checks your identity as a, say, Google Apps user.
Assuming a private bucket on S3, what's the easiest way to accomplish this today?
This is where LDAP and similar are really strong. Unfortunately a lot of companies know that and charge big bucks for this simple feature, often hiding it behind "enterprise" subscriptions where you need to contact them for pricing.
It's also the reason why companies love Exchange and the rest of Microsoft's ecosystem.
However I have yet to encounter such setup used in a professional environment for humans. Is the complexity of such approach just too high compared to LDAP and the passwords?
https://awslabs.github.io/aws-cloudfront-extensions/deploy/d...
https://aws.amazon.com/blogs/security/protect-public-clients...
You could intercept every HTTP request before it reaches CF, check auth data and decide to let it through or respond with 401 already. The CF auth password could be kept as an internal secret. You rotate temporary passwords on Lambda environment variables (bit insecure) or using AWS Secrets Manager (very safe).
Requests successfully authenticated on Lambda level gets rewritten with the master CF password to make them succeed there.
It's a lot more trouble than simply setting up basic auth, but you setup only once and theoretically it works.
The nginx auth_request module authenticates each request against vouch-proxy before it executes the proxy_pass. Vouch-proxy can be configured to authenticate users against google apps or other oauth/iodc providers. And there are some options to pass along username, groups or other data as headers to the proxied service.
VP can be found at https://github.com/vouch/vouch-proxy
Here's to a safe, secure and authenticated 2022!
Don't be sure about that!
There's an additional setting to check to be sure dns goes through the proxy.
Can't recall the details now, but it's there!
Or maybe it was due to dns over tls not being proxied?