AuthN: Use tokens for unified storage server authentication (#95086)
* Extract server code --------- Co-authored-by: Claudiu Dragalina-Paraipan <drclau@users.noreply.github.com>
This commit is contained in:
co-authored by
Claudiu Dragalina-Paraipan
parent
9ab064bfc5
commit
b68b69c2b4
@@ -240,6 +240,14 @@ Make sure you have the gRPC address in the `[grafana-apiserver]` section of your
|
||||
address = localhost:10000
|
||||
```
|
||||
|
||||
You also need the `[grpc_server_authentication]` section to authenticate incoming requests:
|
||||
```ini
|
||||
[grpc_server_authentication]
|
||||
; http url to Grafana's signing keys to validate incoming id tokens
|
||||
signing_keys_url = http://localhost:3000/api/signing-keys/keys
|
||||
mode = "on-prem"
|
||||
```
|
||||
|
||||
This currently only works with a separate database configuration (see previous section).
|
||||
|
||||
Start the storage-server with:
|
||||
|
||||
@@ -11,6 +11,7 @@ import (
|
||||
"github.com/grafana/grafana/pkg/infra/log"
|
||||
"github.com/grafana/grafana/pkg/infra/tracing"
|
||||
"github.com/grafana/grafana/pkg/modules"
|
||||
"github.com/grafana/grafana/pkg/services/authn/grpcutils"
|
||||
"github.com/grafana/grafana/pkg/services/featuremgmt"
|
||||
"github.com/grafana/grafana/pkg/services/grpcserver"
|
||||
"github.com/grafana/grafana/pkg/services/grpcserver/interceptors"
|
||||
@@ -67,7 +68,12 @@ func ProvideUnifiedStorageGrpcService(
|
||||
return nil, err
|
||||
}
|
||||
|
||||
authn := &grpc.Authenticator{}
|
||||
// FIXME: This is a temporary solution while we are migrating to the new authn interceptor
|
||||
// grpcutils.NewGrpcAuthenticator should be used instead.
|
||||
authn, err := grpcutils.NewGrpcAuthenticatorWithFallback(cfg, prometheus.DefaultRegisterer, &grpc.Authenticator{})
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
s := &service{
|
||||
cfg: cfg,
|
||||
|
||||
Reference in New Issue
Block a user