You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Superset集成Keycloak后实现基于组的仪表盘访问控制及代码修改

Group-Based Dashboard Access Control for Superset + Keycloak

Alright, let's walk through how to set up granular dashboard access based on Keycloak groups in your already integrated Superset instance. Most of this work happens in the UI, but I'll also cover scenarios where you might need to tweak code/config.

First: Prep Keycloak Groups (No Code Needed)

Before jumping into Superset, make sure your Keycloak setup is ready:

  • Create two groups in Keycloak: say dashboard-viewers-1-2 and dashboard-viewer-3
  • Add User 1 to dashboard-viewers-1-2, and User 3 to dashboard-viewer-3
  • Double-check that your existing Superset-Keycloak integration is syncing groups (this should be enabled in your OIDC config already, but if not, we'll fix that later)

Core Setup: Superset UI Configuration (No Code Needed)

This is where you'll map Keycloak groups to Superset permissions:

  1. Create Role for Each Dashboard Set

    • Head to Security > Roles in Superset
    • Make a new role named access-dash-1-2:
      • Go to the Permissions tab and add the can read on Dashboard permission (or use more granular permissions if you want tighter control)
      • Switch to the Dashboards tab, find Dashboard 1 and 2, and assign the read permission to this role
    • Repeat the process for a role access-dash-3, linking it only to Dashboard 3
  2. Link Keycloak Groups to Superset Roles

    • Back in Security > Roles, edit the access-dash-1-2 role
    • Go to the Groups tab, search for the synced Keycloak group dashboard-viewers-1-2, and add it
    • Do the same for access-dash-3 and its corresponding Keycloak group
  3. Test It Out

    • Log in as User 1: you should only see Dashboard 1 and 2
    • Log in as User 3: only Dashboard 3 should be visible

When You Need Code/Config Tweaks

If your Keycloak group names don't match what you want in Superset, or if group sync isn't working as expected, here's what to do:

1. Map Keycloak Groups to Superset Groups (Modify superset_config.py)

If you need to rename or filter groups coming from Keycloak, add this to your config:

# Enable group sync on every user login
OIDC_GROUPS_SYNC_AT_LOGIN = True

# Map Keycloak group names to your preferred Superset group names
OIDC_GROUP_MAP = {
    "keycloak-dash-group-1": "dashboard-viewers-1-2",
    "keycloak-dash-group-3": "dashboard-viewer-3"
}

2. Custom Group Sync Logic (Extend Security Manager)

For more complex scenarios—like filtering groups based on user attributes, or transforming group names dynamically—create a custom security manager:

  • Add this to superset_config.py:
from superset.security import SupersetSecurityManager

class CustomOIDCSecurityManager(SupersetSecurityManager):
    def oauth_user_info(self, provider, response=None):
        # Pull default user info from the OIDC response
        user_info = super().oauth_user_info(provider, response)
        # Extract groups from Keycloak's token payload
        keycloak_groups = response.get("groups", [])
        # Example: Filter groups to only those related to dashboards, and strip a prefix
        processed_groups = [g.replace("kc-", "") for g in keycloak_groups if "dashboard" in g]
        user_info["groups"] = processed_groups
        return user_info

# Tell Superset to use your custom security manager
CUSTOM_SECURITY_MANAGER = CustomOIDCSecurityManager
  • Restart your Superset service to apply the changes

Quick Notes

  • Always ensure OIDC_GROUPS_SYNC_AT_LOGIN is set to True so group updates in Keycloak reflect in Superset on the next user login
  • If users were logged in before you made changes, have them log out and back in (or manually refresh their group info in Security > Users)
  • Test in incognito windows to avoid browser cache messing with your results

内容的提问来源于stack exchange,提问作者kalyan4uonly

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 16:35:13