grafana-iam: Adds config opts for RBACRemoteClient for load balancing (#110819)
This commit is contained in:
@@ -31,6 +31,13 @@ listen = false
|
||||
mode = "inproc"
|
||||
```
|
||||
|
||||
For load balancing you would want to enable the load balancing configuration. This sets sane default for multiple pods to be evenly distributed with load across the different pods.
|
||||
|
||||
```ini
|
||||
[authorization]
|
||||
load_balancing_enabled = true
|
||||
```
|
||||
|
||||
### Example
|
||||
|
||||
Here is an example to connect the authorization client to a remote grpc server.
|
||||
|
||||
@@ -180,6 +180,16 @@ func newRemoteRBACClient(clientCfg *authzClientSettings, tracer trace.Tracer, re
|
||||
grpc.WithChainStreamInterceptor(streamInterceptors...),
|
||||
}
|
||||
|
||||
// // if we serve the client as a load balancer
|
||||
if clientCfg.loadBalancingEnabled {
|
||||
// Use round_robin to balances requests more evenly over the available Grafana replicas.
|
||||
opts = append(opts, grpc.WithDefaultServiceConfig(`{"loadBalancingPolicy": "round_robin"}`))
|
||||
|
||||
// Disable looking up service config from TXT DNS records.
|
||||
// This reduces the number of requests made to the DNS servers.
|
||||
opts = append(opts, grpc.WithDisableServiceConfig())
|
||||
}
|
||||
|
||||
conn, err := grpc.NewClient(clientCfg.remoteAddress, opts...)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("failed to create authz client to remote server: %w", err)
|
||||
|
||||
@@ -23,9 +23,10 @@ const (
|
||||
)
|
||||
|
||||
type authzClientSettings struct {
|
||||
remoteAddress string
|
||||
certFile string
|
||||
mode clientMode
|
||||
remoteAddress string
|
||||
certFile string
|
||||
mode clientMode
|
||||
loadBalancingEnabled bool
|
||||
|
||||
token string
|
||||
tokenExchangeURL string
|
||||
@@ -51,6 +52,7 @@ func readAuthzClientSettings(cfg *setting.Cfg) (*authzClientSettings, error) {
|
||||
if s.mode == clientModeInproc {
|
||||
return s, nil
|
||||
}
|
||||
s.loadBalancingEnabled = authzSection.Key("load_balancing_enabled").MustBool(false)
|
||||
|
||||
s.remoteAddress = authzSection.Key("remote_address").MustString("")
|
||||
s.certFile = authzSection.Key("cert_file").MustString("")
|
||||
|
||||
Reference in New Issue
Block a user