Hello Outerbounds Team: We (as Roblox) are curren...
# ask-metaflow
c
Hello Outerbounds Team: We (as Roblox) are currently evaluating Metaflow to run on a Kubernetes cluster that is managed by an Istio service mesh. As we scale our usage, we're exploring best practices for securing access to Metaflow's components and UI in a multi-tenant environment. Our security model for other applications on the cluster leverages the Istio Ingress Gateway with an OIDC provider for end-user authentication. We are interested in understanding how this pattern can be applied to Metaflow. Specifically, we have a few questions: 1. What is the recommended approach for user authentication and authorization when multiple data scientists are using Metaflow on a shared Kubernetes cluster? 2. For the Metaflow UI, if we expose it via an ingress, have you seen customers successfully place it behind an OIDC-aware proxy for authentication? 3. Are there any reference architectures for integrating Metaflow with a service mesh like Istio, particularly concerning identity propagation for jobs and fine-grained access control for the metadata service? We are essentially looking to achieve a similar end-user authentication experience as one might find with a platform like Kubeflow, and we would appreciate any guidance or best practices you can share. Thank you for your time and help.
1
a
Hi Jack, it might be useful to schedule a quick chat to learn more about your setup. Let me DM you
a
yep I think we even had an example of an OIDC-based setup somewhere in the terraform repo, happy to share more
c
Thanks for your reply. I am looking forward to meeting your folks to talk more about it.
b
I'd be keen to listen in here if poss. We have a similar setup - Istio is deployed I'm planning to look at auth for the UI.
c
At this moment, I'd like to keep the meeting limited to Outerbounds folks only due to privacy concerns etc. Thanks for understanding. I can send a summary after our meeting.
👍 1