Extensions – OIDC
XProtect services have been configured to provide bearer tokens that contain information unique to services. The tokens can be validated using the OIDC authenticator extension:
extensions:
oidc/server: # OIDC extension with the unique name 'server' issuer_url: https://localhost/IDP # URL to IDP server
audience: serverlogs # Specific audience to verify on each incoming token issuer_ca_path: [PATH TO CERTIFICATE] # CA public certificate of IDP server attribute: authorization # Name of the header with the bearer token (Case sensitive!)
Please ensure that the “issuer_url” and the “issuer_ca_path” are set correctly, the other parameters must not be modified.
receivers:
otlp/server:
protocols:
http: # Use HTTP Protobuf
endpoint: "0.0.0.0:4318" # Listen on port 4318 and accept any address auth:
authenticator: oidc/server # OIDC extension configuration matching the unique name 'server' tls:
cert_file: [PATH TO SERVER CERTIFICATE] # Public server certificate key_file: [PATH TO SERVER CERTIFICATE KEY] # Private server key
processors:
resource/authtoken: # resource processor with the unique name 'authtoken' attributes:
- key: oidc.sub # Include the subject of the token in the log message action: upsert
from_context: auth.subject