メインコンテンツまでスキップ
バージョン: 4.x

CREATE AUTHENTICATION INTEGRATION

CREATE AUTHENTICATION INTEGRATION creates an authentication integration, which specifies the authentication plugin and its configuration for VeloDB Enterprise.

Note:

Supported since VeloDB Enterprise 4.1.4.

Syntax​

CREATE AUTHENTICATION INTEGRATION [IF NOT EXISTS] <integration_name>
PROPERTIES (
'type' = '<authentication_type>'
[, '<property_key>' = '<property_value>' ...]
)
[COMMENT '<comment>'];

Required parameters​

ParameterDescription
<integration_name>Integration name. Use this name to modify or drop the integration, or to associate a role mapping with it.
PROPERTIES (...)Integration properties as key-value pairs. type specifies the plugin type, such as oidc. The plugin defines the other properties.

Optional parameters​

ParameterDescription
IF NOT EXISTSSuppresses the error if an integration with the same name already exists.
COMMENT '<comment>'Integration comment.

Access control requirements​

The user executing this statement must have the following privilege, either directly or through a role:

PrivilegeObjectDescription
ADMIN_PRIVUser or roleRequired to perform this operation.

Usage notes​

  • type is required and cannot be defined more than once in a PROPERTIES clause.
  • This statement creates a plugin configuration instance. It does not install the plugin. Ensure that the plugin is available in your deployment before running the statement.
  • You cannot change type with ALTER AUTHENTICATION INTEGRATION. To change the plugin type, drop and recreate the integration.
  • The plugin interprets properties other than type and validates them when the integration is loaded or used.

Example​

Create an OIDC integration:

CREATE AUTHENTICATION INTEGRATION corp_oidc
PROPERTIES (
'type' = 'oidc',
'oidc.issuer' = 'https://idp.example.com/realms/doris',
'oidc.jwks_uri' = 'https://idp.example.com/realms/doris/protocol/openid-connect/certs',
'oidc.allowed_audiences' = 'doris'
)
COMMENT 'Corporate OIDC authentication';

Replace the example issuer, JWKS URI, and audience with values from your identity provider.

See also​