how to enable authentication for airbyte web inter...
# replication-ask-ai
s
how to enable authentication for airbyte web interface
k
Airbyte Open Source currently does not include any user management or role-based access controls (RBAC) to prevent unauthorized access to the API or UI. However, you can secure access to Airbyte using the following methods: 1. Deploy Airbyte in a private network or use a firewall to filter which IP is allowed to access your host. 2. Deploy Airbyte behind a reverse proxy and handle the access control and SSL encryption on the reverse proxy side. Here is an example of an nginx reverse proxy config:
Copy code
nginx server {    listen 443 ssl;    server_name airbyte.<your-domain>.com;    client_max_body_size 200M; # required for Airbyte API    ssl_certificate <path-to-your-cert>.crt.pem;     ssl_certificate_key <path-to-your-key>.key.pem;        location / {    proxy_pass <http://127.0.0.1:8000;>    proxy_set_header Cookie $http_cookie; # if you use Airbytes basic auth    proxy_read_timeout 3600; # set a number in seconds suitable for you    }   }
3. Change the default username and password in your environment's
.env
file:
Copy code
bash  # Proxy Configuration    # Set to empty values, e.g. "" to disable basic auth    BASIC_AUTH_USERNAME=your_new_username_here    BASIC_AUTH_PASSWORD=your_new_password_here
Please note that controlling who has access to the hardware and network your Airbyte deployment runs on is your responsibility. For more details, you can refer to the [Airbyte Security documentation](https://docs.airbyte.com/operator-guides/security).
j
In AWS you can also offload AuthN from an ALB to an OIDC such as Okta (but Okta makes you pay for the feature) https://docs.aws.amazon.com/elasticloadbalancing/latest/application/listener-authenticate-users.html Note that this does not handle AuthZ at all as the AI previously mentioned there is no RBAC in Airbyte. Logged in users can do anything.