grafana-iam: Adds config opts for RBACRemoteClient for load balancing (#110819)

This commit is contained in:
Eric Leijonmarck
2025-09-16 09:49:37 +01:00
committed by GitHub
parent 22b96c7c3e
commit 868e3a5e8e
8 changed files with 123 additions and 8 deletions
+7
View File
@@ -31,6 +31,13 @@ listen = false
mode = "inproc"
```
For load balancing you would want to enable the load balancing configuration. This sets sane default for multiple pods to be evenly distributed with load across the different pods.
```ini
[authorization]
load_balancing_enabled = true
```
### Example
Here is an example to connect the authorization client to a remote grpc server.
+10
View File
@@ -180,6 +180,16 @@ func newRemoteRBACClient(clientCfg *authzClientSettings, tracer trace.Tracer, re
grpc.WithChainStreamInterceptor(streamInterceptors...),
}
// // if we serve the client as a load balancer
if clientCfg.loadBalancingEnabled {
// Use round_robin to balances requests more evenly over the available Grafana replicas.
opts = append(opts, grpc.WithDefaultServiceConfig(`{"loadBalancingPolicy": "round_robin"}`))
// Disable looking up service config from TXT DNS records.
// This reduces the number of requests made to the DNS servers.
opts = append(opts, grpc.WithDisableServiceConfig())
}
conn, err := grpc.NewClient(clientCfg.remoteAddress, opts...)
if err != nil {
return nil, fmt.Errorf("failed to create authz client to remote server: %w", err)
+5 -3
View File
@@ -23,9 +23,10 @@ const (
)
type authzClientSettings struct {
remoteAddress string
certFile string
mode clientMode
remoteAddress string
certFile string
mode clientMode
loadBalancingEnabled bool
token string
tokenExchangeURL string
@@ -51,6 +52,7 @@ func readAuthzClientSettings(cfg *setting.Cfg) (*authzClientSettings, error) {
if s.mode == clientModeInproc {
return s, nil
}
s.loadBalancingEnabled = authzSection.Key("load_balancing_enabled").MustBool(false)
s.remoteAddress = authzSection.Key("remote_address").MustString("")
s.certFile = authzSection.Key("cert_file").MustString("")