-
Notifications
You must be signed in to change notification settings - Fork 0
Generalise to WorkloadIdentity: resource-first configuration, Managed Identity and Blob Storage #10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
Open
Changes from all commits
Commits
Show all changes
4 commits
Select commit
Hold shift + click to select a range
666bebd
Generalise into resource-first workload identity with managed identit…
neotrow 474c41d
Tests: cover cancellation during the shared IAM client creation
neotrow df9ad8e
Tests: cover a cancelled IAM client creation on the generalised provider
neotrow 62b8382
Docs: the hosted service is registered with TryAddEnumerable, not a r…
neotrow File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,44 @@ | ||
| --- | ||
| "@neolution-ch/csag-workload-identity": minor | ||
| --- | ||
|
|
||
| Generalise the library into a resource-first workload identity model: access tokens for Azure SQL and Azure Blob Storage, each obtained either with the Azure managed identity the application runs as or with its Google identity through workload identity federation. | ||
|
|
||
| - **Configuration is resource-first (breaking).** Each resource has its own section under `Csag.WorkloadIdentity` that selects a `Provider` (`ManagedIdentity` or `Google`) and carries that provider's settings. For the existing Azure SQL over Google federation case: | ||
|
|
||
| Before: | ||
|
|
||
| ```json | ||
| { | ||
| "Csag.WorkloadIdentity": { | ||
| "TenantId": "<tenant-id>", | ||
| "ClientId": "<client-id>", | ||
| "Google": { "ServiceAccountEmail": "<name>@<project-id>.iam.gserviceaccount.com" } | ||
| } | ||
| } | ||
| ``` | ||
|
|
||
| After: | ||
|
|
||
| ```json | ||
| { | ||
| "Csag.WorkloadIdentity": { | ||
| "AzureSql": { | ||
| "Provider": "Google", | ||
| "Google": { | ||
| "TenantId": "<tenant-id>", | ||
| "ClientId": "<client-id>", | ||
| "ServiceAccountEmail": "<name>@<project-id>.iam.gserviceaccount.com" | ||
| } | ||
| } | ||
| } | ||
| } | ||
| ``` | ||
|
|
||
| `RefreshAheadWindow` and `EnableBackgroundRefresh` stay at the root and apply to every resource. Startup validation requires at least one resource section and reports every missing value by its path, for example `AzureSql:Google:ServiceAccountEmail must be provided.` | ||
| - **Managed identity.** `"Provider": "ManagedIdentity"` with `"ManagedIdentity": { "UseSystemAssignedIdentity": true }` or `"ManagedIdentity": { "ClientId": "<user-assigned-client-id>" }` obtains the token from the managed identity endpoint of the Azure resource the application runs on. | ||
| - **Blob Storage.** A `BlobStorage` section (same shape as `AzureSql`) registers `IBlobStorageTokenProvider` with `GetBlobStorageAccessTokenAsync`, requesting the `https://storage.azure.com/.default` scope. | ||
| - **`AddWorkloadIdentity` replaces `AddAzureSqlFederatedIdentity`** with the same three overloads (host configuration, `Action<WorkloadIdentityOptions>`, `IConfiguration`). `WorkloadIdentityOptions` replaces `AzureSqlFederatedIdentityOptions`; the section name `Csag.WorkloadIdentity` is unchanged and exposed as `WorkloadIdentityOptions.ConfigurationSectionName`. Both providers are always registered; resolving the provider of a resource whose section is absent throws an `InvalidOperationException` naming the missing section. | ||
| - **`TokenCredential` adapter.** Both provider interfaces gain `GetAccessTokenAsync`, which returns the token together with its real expiry, and `WorkloadIdentityTokenCredential` presents a provider to Azure SDK clients, for example `new BlobServiceClient(uri, new WorkloadIdentityTokenCredential(blobStorageTokenProvider))`. | ||
| - `IGoogleIdTokenProvider.GetIdTokenAsync` takes the service account email, so resources can federate through different service accounts. `IAzureSqlTokenExchanger` is replaced by internal per-provider exchangers. | ||
| - Unchanged: `IAzureSqlTokenProvider.GetAzureSqlAccessTokenAsync`; the token is held in memory and concurrent callers share a single request; the background service refreshes ahead of expiry with exponential backoff, now in one loop per configured resource; every service is registered with `TryAdd`, so a consumer-registered provider wins and is left alone by the background refresh. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
149 changes: 0 additions & 149 deletions
149
Csag.WorkloadIdentity.UnitTests/AzureSqlFederatedIdentityOptionsValidatorTests.cs
This file was deleted.
Oops, something went wrong.
130 changes: 0 additions & 130 deletions
130
Csag.WorkloadIdentity.UnitTests/AzureSqlTokenExchangerTests.cs
This file was deleted.
Oops, something went wrong.
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.