[v10.0.x] Azure: Settings for Azure AD Workload Identity (#75686)
* Azure: Settings for Azure AD Workload Identity (#75283)
* Settings for Azure AD Workload Identity
* Update dependency on Grafana Azure SDK
* Documentation
* Fix JS code
* Cleanup Prometheus backend code
* Making prettier happy
(cherry picked from commit 3ee40d3a5a)
# Conflicts:
# conf/defaults.ini
# conf/sample.ini
# docs/sources/setup-grafana/configure-grafana/_index.md
# go.mod
# go.sum
# packages/grafana-runtime/src/config.ts
# pkg/api/dtos/frontend_settings.go
# pkg/api/frontendsettings.go
# pkg/setting/setting_azure.go
# public/app/plugins/datasource/mssql/azureauth/AzureAuth.testMocks.ts
* Fix build
---------
Co-authored-by: Sergey Kostrukov <sekost@microsoft.com>
This commit is contained in:
co-authored by
Sergey Kostrukov
parent
6a1427d439
commit
7e0d8c3556
@@ -1140,6 +1140,32 @@ The client ID to use for user-assigned managed identity.
|
||||
|
||||
Should be set for user-assigned identity and should be empty for system-assigned identity.
|
||||
|
||||
### workload_identity_enabled
|
||||
|
||||
Specifies whether Azure AD Workload Identity authentication should be enabled in datasources that support it.
|
||||
|
||||
For more documentation on Azure AD Workload Identity, review [Azure AD Workload Identity](https://azure.github.io/azure-workload-identity/docs/) documentation.
|
||||
|
||||
Disabled by default, needs to be explicitly enabled.
|
||||
|
||||
### workload_identity_tenant_id
|
||||
|
||||
Tenant ID of the Azure AD Workload Identity.
|
||||
|
||||
Allows to override default tenant ID of the Azure AD identity associated with the Kubernetes service account.
|
||||
|
||||
### workload_identity_client_id
|
||||
|
||||
Client ID of the Azure AD Workload Identity.
|
||||
|
||||
Allows to override default client ID of the Azure AD identity associated with the Kubernetes service account.
|
||||
|
||||
### workload_identity_token_file
|
||||
|
||||
Custom path to token file for the Azure AD Workload Identity.
|
||||
|
||||
Allows to set a custom path to the projected service account token file.
|
||||
|
||||
## [auth.jwt]
|
||||
|
||||
Refer to [JWT authentication]({{< relref "../configure-security/configure-authentication/jwt" >}}) for more information.
|
||||
|
||||
Reference in New Issue
Block a user