This lab is currently in Beta, content may be updated as we refine the material
LABINTERMEDIATE

Kubernetes Authentication with Conjur

Enable authn-k8s on Conjur OSS, deploy the CyberArk Secrets Provider into minikube, and inject a Conjur-managed secret into a running pod using its Kubernetes identity

60 minutes
Kubernetes Authentication with Conjur - Platform Engineering Hands-On Lab Icon
Share this Lab

Lab Overview

In this lab you extend the canonical Conjur OSS v1.24.0 Docker Compose stack with a local minikube Kubernetes cluster and wire the two together with the authn-k8s authenticator. You load the authenticator webservice policy and an application-identity policy that authorizes a specific Kubernetes ServiceAccount, configure the authenticator with the cluster CA and a TokenReview-capable service account, then deploy the CyberArk Secrets Provider as an init container for a demo app. The Secrets Provider authenticates the pod to Conjur using its Kubernetes service account identity and writes a Conjur secret into a Kubernetes Secret that the app pod consumes. You finish by proving a pod running under the wrong ServiceAccount is denied.

What You'll Learn

Enable and configure the Conjur authn-k8s authenticator for a Kubernetes cluster

Load the authn-k8s webservice policy and an application-identity (host) policy that authorizes a Kubernetes ServiceAccount

Deploy the CyberArk Secrets Provider as an init container that authenticates a pod via its Kubernetes identity

Inject a Conjur-managed secret into a Kubernetes Secret consumed by an application pod

Demonstrate that a pod with an unauthorized ServiceAccount is denied by authn-k8s

Prerequisites

Completion of the "Deploy Conjur OSS with Docker Compose" lab (or equivalent Conjur familiarity)

Basic Kubernetes knowledge (pods, deployments, ServiceAccounts, Secrets)

Basic Conjur policy-as-code familiarity (loading policy, setting variables)

Basic Docker and command-line familiarity

Technologies Covered

conjurcyberarksecrets-managementkubernetesauthn-k8ssecrets-providermachine-identityintermediate

Choose your plan

Simple, Transparent Pricing

Unlock full access to TeKanAid courses, labs, and bootcamps

Buying for a team? Private corporate training is available for up to 15 learners.View team training
MonthlyQuarterly
Try Premium free for 7 days →

Just exploring? Start free below. Want the full experience? Try Premium free for 7 days (card required, $0 today).

Pro

All courses, with lab scripts to run on your own machine

$59/month

Renews automatically. Cancel anytime.

Final price verified at checkout.

  • Full access to all courses
  • Lab scripts to download and run on your own machine (hosted labs not included)
  • Progress tracking
  • Certificate of completion
  • Community access
  • Bootcamp participation
  • New content access
Recommended

Premium

Full access, including unlimited hosted labs

$99/month

Renews automatically. Cancel anytime.

Final price verified at checkout.

  • Everything in Pro
  • Unlimited hands-on labs, fully hosted on TeKanAid Academy (nothing to set up)
  • Lab AI Assistant
  • Accelerator bootcamps with live office hours
  • Priority support

Prefer a single course?

Purchase individual courses for a one-time fee of $79. Full access to course content, quizzes, certificates, and community features, lab access is not included.

Browse Courses

Just exploring? Start free, no account needed

Three free ways to start. All bridge into the paid Premium catalog when you're ready.

Not ready to commit? The crash course is email-only. No academy account required.

Ready to Get Started?

Start this hands-on lab and build real-world Platform Engineering skills

Get Access Now