# OpenMetadata 배포 ## 1. 배포 방법 ### 1) 배포 시 주의 사항 - openmetadata를 배포하기 전에 `openmetadata-dependencies`(MySQL, OpenSearch, Airflow)가 먼저 배포되어 있어야 한다. - HTTPS 접근을 위해 `java-truststore` Secret이 배포 네임스페이스에 사전 생성되어 있어야 한다. - Keycloak OIDC 연동 시 `oidc-secrets` Secret이 사전 생성되어 있어야 한다. ### 2) Secret 사전 생성 - java-truststore Secret 생성 (내부 CA 인증서 포함 truststore) ``` sh kubectl create secret generic java-truststore \ --from-file=cacerts= \ -n openmetadata ``` - Keycloak OIDC 연동 시 oidc-secrets Secret 생성 ``` sh kubectl create secret generic oidc-secrets \ --from-literal=openmetadata-oidc-client-id= \ --from-literal=openmetadata-oidc-client-secret= \ -n openmetadata ``` ### 3) 배포 방법 ``` sh git clone https://github.com/paasup/dip-catalog.git cd manifests/helm/openmetadata/1.12.1 helm upgrade openmetadata ./ -f custom-values.yaml --install -n openmetadata --create-namespace ``` --- ## 2. custom-values.yaml 설명 ### 1) 인가(Authorizer) 설정 | Name | 설명 | 기본값 | | ---- | ---- | ------ | | `openmetadata.config.authorizer.initialAdmins` | 최초 관리자 계정 목록. 이메일의 `@` 앞 부분을 입력 | `["admin", "paasup"]` | | `openmetadata.config.authorizer.principalDomain` | 조직의 기본 도메인 (예: `paasup.io`) | `"paasup.io"` | | `openmetadata.config.authorizer.allowedDomains` | 로그인을 허용할 도메인 목록 | `["paasup.io"]` | ### 2) 인증(Authentication) 설정 #### 2.1) Basic 인증 (기본값) - OpenMetadata 자체 계정/비밀번호 인증을 사용한다. ``` yaml openmetadata: config: authentication: provider: "basic" callbackUrl: "https://open-metadata.example.org/callback" authority: "https://open-metadata.example.org" publicKeys: - "https://open-metadata.example.org/api/v1/system/config/jwks" ``` #### 2.2) Keycloak OIDC 연동 - `provider`를 `custom-oidc`로 변경하고 `oidcConfiguration`을 활성화한다. - 사전에 `oidc-secrets` Secret이 생성되어 있어야 한다. ``` yaml openmetadata: config: authentication: clientType: confidential provider: "custom-oidc" publicKeys: - "https://open-metadata.example.org/api/v1/system/config/jwks" - "https://keycloak.example.org/realms/paasup/protocol/openid-connect/certs" clientId: "open-metadata" callbackUrl: "https://open-metadata.example.org/callback" jwtPrincipalClaims: - "email" - "preferred_username" - "sub" oidcConfiguration: enabled: true oidcType: "Keycloak" clientId: secretRef: oidc-secrets secretKey: openmetadata-oidc-client-id clientSecret: secretRef: oidc-secrets secretKey: openmetadata-oidc-client-secret discoveryUri: "https://keycloak.example.org/realms/paasup/.well-known/openid-configuration" serverUrl: "https://open-metadata.example.org" callbackUrl: "https://open-metadata.example.org/callback" ``` ### 3) Ingress 설정 #### 3.1) cert-manager를 이용한 자동 생성 - cert-manager를 통해 인증서 자동 생성 시 `custom-values.yaml`을 수정한다. - `ingress.annotations.cert-manager.io/cluster-issuer`에 미리 배포된 Cluster Issuer의 이름으로 변경한다. - Kong Ingress Controller를 사용하며 HTTPS 리다이렉트를 적용한다. ``` yaml ingress: enabled: true className: "kong" annotations: cert-manager.io/cluster-issuer: root-ca-issuer cert-manager.io/duration: 8760h cert-manager.io/renew-before: 720h konghq.com/protocols: https konghq.com/https-redirect-status-code: "301" hosts: - host: open-metadata.example.org # 사용할 도메인으로 변경 paths: - path: / pathType: ImplementationSpecific tls: - secretName: openmetadata-tls hosts: - open-metadata.example.org # 사용할 도메인으로 변경 ``` #### 3.2) TLS Secret 직접 생성 - 인증서를 직접 관리하는 경우 Secret을 생성하여 제공한다. ``` sh kubectl create secret tls openmetadata-tls \ --cert= \ --key= \ -n openmetadata ``` ### 4) Java TrustStore 설정 - 내부 CA 인증서를 신뢰하기 위해 `java-truststore` Secret을 마운트하고 JVM 옵션을 설정한다. ``` yaml extraVolumes: - name: java-truststore secret: secretName: java-truststore extraVolumeMounts: - name: java-truststore mountPath: /etc/ssl/java readOnly: true extraEnvs: - name: OPENMETADATA_OPTS value: > -Djavax.net.ssl.trustStore=/etc/ssl/java/cacerts -Djavax.net.ssl.trustStorePassword=changeit ``` ### 5) 리소스 설정 ``` yaml resources: limits: cpu: 1 memory: 2048Mi requests: cpu: 500m memory: 1024Mi ``` ### 6) 환경변수 설정 | Name | 설명 | 기본값 | | ---- | ---- | ------ | | `OPENMETADATA_PUBLIC_URL` | 외부에서 접근하는 OpenMetadata URL. HTTPS 환경에서 반드시 설정 | `"https://open-metadata.example.org"` | | `LOG_LEVEL` | 로그 레벨 (`INFO`, `DEBUG`, `WARN`, `ERROR`) | `"INFO"` | | `OPENMETADATA_OPTS` | JVM 옵션. TrustStore 경로 및 패스워드 설정 | `custom-values.yaml 참조` |