diff --git a/pkg/plugins/backendplugin/manager/manager.go b/pkg/plugins/backendplugin/manager/manager.go index 71de05f321f..2417e16b4d6 100644 --- a/pkg/plugins/backendplugin/manager/manager.go +++ b/pkg/plugins/backendplugin/manager/manager.go @@ -81,6 +81,8 @@ func (m *manager) Register(pluginID string, factory backendplugin.PluginFactoryF } hostEnv = append(hostEnv, m.getAWSEnvironmentVariables()...) + hostEnv = append(hostEnv, m.getAzureEnvironmentVariables()...) + pluginSettings := getPluginSettings(pluginID, m.Cfg) env := pluginSettings.ToEnv("GF_PLUGIN", hostEnv) @@ -164,6 +166,21 @@ func (m *manager) getAWSEnvironmentVariables() []string { return variables } +func (m *manager) getAzureEnvironmentVariables() []string { + variables := []string{} + if m.Cfg.Azure.Cloud != "" { + variables = append(variables, "AZURE_CLOUD="+m.Cfg.Azure.Cloud) + } + if m.Cfg.Azure.ManagedIdentityClientId != "" { + variables = append(variables, "AZURE_MANAGED_IDENTITY_CLIENT_ID="+m.Cfg.Azure.ManagedIdentityClientId) + } + if m.Cfg.Azure.ManagedIdentityEnabled { + variables = append(variables, "AZURE_MANAGED_IDENTITY_ENABLED=true") + } + + return variables +} + //nolint: staticcheck // plugins.DataPlugin deprecated func (m *manager) GetDataPlugin(pluginID string) interface{} { p, _ := m.Get(pluginID) diff --git a/pkg/plugins/backendplugin/manager/manager_test.go b/pkg/plugins/backendplugin/manager/manager_test.go index 81ae11809c2..fba06c8e506 100644 --- a/pkg/plugins/backendplugin/manager/manager_test.go +++ b/pkg/plugins/backendplugin/manager/manager_test.go @@ -63,8 +63,16 @@ func TestManager(t *testing.T) { }) t.Run("Should provide expected host environment variables", func(t *testing.T) { - require.Len(t, ctx.env, 4) - require.EqualValues(t, []string{"GF_VERSION=7.0.0", "GF_EDITION=Open Source", fmt.Sprintf("%s=true", awsds.AssumeRoleEnabledEnvVarKeyName), fmt.Sprintf("%s=keys,credentials", awsds.AllowedAuthProvidersEnvVarKeyName)}, ctx.env) + require.Len(t, ctx.env, 7) + require.EqualValues(t, []string{ + "GF_VERSION=7.0.0", + "GF_EDITION=Open Source", + fmt.Sprintf("%s=true", awsds.AssumeRoleEnabledEnvVarKeyName), + fmt.Sprintf("%s=keys,credentials", awsds.AllowedAuthProvidersEnvVarKeyName), + "AZURE_CLOUD=AzureCloud", + "AZURE_MANAGED_IDENTITY_CLIENT_ID=client-id", + "AZURE_MANAGED_IDENTITY_ENABLED=true"}, + ctx.env) }) t.Run("When manager runs should start and stop plugin", func(t *testing.T) { @@ -282,8 +290,18 @@ func TestManager(t *testing.T) { require.NoError(t, err) t.Run("Should provide expected host environment variables", func(t *testing.T) { - require.Len(t, ctx.env, 6) - require.EqualValues(t, []string{"GF_VERSION=7.0.0", "GF_EDITION=Enterprise", "GF_ENTERPRISE_LICENSE_PATH=/license.txt", "GF_ENTERPRISE_LICENSE_TEXT=testtoken", fmt.Sprintf("%s=true", awsds.AssumeRoleEnabledEnvVarKeyName), fmt.Sprintf("%s=keys,credentials", awsds.AllowedAuthProvidersEnvVarKeyName)}, ctx.env) + require.Len(t, ctx.env, 9) + require.EqualValues(t, []string{ + "GF_VERSION=7.0.0", + "GF_EDITION=Enterprise", + "GF_ENTERPRISE_LICENSE_PATH=/license.txt", + "GF_ENTERPRISE_LICENSE_TEXT=testtoken", + fmt.Sprintf("%s=true", awsds.AssumeRoleEnabledEnvVarKeyName), + fmt.Sprintf("%s=keys,credentials", awsds.AllowedAuthProvidersEnvVarKeyName), + "AZURE_CLOUD=AzureCloud", + "AZURE_MANAGED_IDENTITY_CLIENT_ID=client-id", + "AZURE_MANAGED_IDENTITY_ENABLED=true"}, + ctx.env) }) }) }) @@ -304,6 +322,10 @@ func newManagerScenario(t *testing.T, managed bool, fn func(t *testing.T, ctx *m cfg.AWSAllowedAuthProviders = []string{"keys", "credentials"} cfg.AWSAssumeRoleEnabled = true + cfg.Azure.ManagedIdentityEnabled = true + cfg.Azure.Cloud = "AzureCloud" + cfg.Azure.ManagedIdentityClientId = "client-id" + license := &testLicensingService{} validator := &testPluginRequestValidator{} ctx := &managerScenarioCtx{