Gabriel MABILLE
81b868ae91
grafana-iam: Split AuthZ apis feature toggle per apis (#116010 )
...
* WIP: switched to feature toggles
* Add timeout
2026-01-12 09:00:51 +01:00
Gabriel MABILLE
e95f8bf843
grafana-iam: Split UpdateAPIGroupInfo in multiple resource specific functions. (#116037 )
...
* OnGoing fixing cyclomatic complexity
* Reduce cyclo complexity
* Spaces
2026-01-08 21:50:44 +01:00
Gabriel MABILLE
93566ce4ef
Chore: Unify token exchange round trippers ( #115609 )
...
* Chore: Unify token exchange rount trippers
* Remove the conditional provider for now
* Remove unecessary strategy
* test cleanup
* Lint
2026-01-05 11:23:35 +01:00
Gabriel MABILLE
e5b0353c41
grafana-iam: Use an API Installer interface (#115310 )
...
* `grafana-iam`: Add basic roles to the apis
* Fix validation
* chore: trigger CI
* Leave the hooks intact for now, moving them later
* Remove Role mention from the interface
* Refactor to use a NoopRest backend and Deny access
2025-12-18 10:29:50 +01:00
Gabriel MABILLE
657bf76922
grafana-iam: Instantiate parent provider (#115224 )
2025-12-15 15:47:12 +01:00
Gabriel MABILLE
478ae15f0e
grafana-iam: Use parent folder to authorize ResourcePermissions (#115008 )
...
* `grafana-iam`: Fetch target parent folder
* WIP add different ParentProviders
* Add version
* Move code to a different file
* Instantiate resourceParentProvider
* same import name
* imports
* Add tests
* Remove unecessary test
* forgot wire
* WIP integration tests
* Add test to cover list
* Fix caching problem in integration tests
* comments
* Logger and comments
* Add lazy creation and caching
* Instantiate clients only once
* Rerun wire gen
2025-12-12 11:43:12 +01:00
Gabriel MABILLE
9e1fe16873
AuthZ: Remove automatic Admin grant for root folders and dashboards (#115098 )
2025-12-10 10:00:24 -07:00
Gabriel MABILLE
d0977b5245
grafana-iam: Add role apis to the standalone app (#114897 )
2025-12-08 09:22:28 +01:00
Gabriel MABILLE
59ec85b936
grafana-iam: Fix missing UID (#114856 )
2025-12-04 18:00:57 +01:00
Gabriel MABILLE
1e82f99b12
grafana-iam: use apiserver errors (#114850 )
...
* `grafana-iam`: Use api server errors
* A bit more verbose
2025-12-04 16:47:06 +01:00
Gabriel MABILLE
e3afb0daf9
grafana-iam: Use the K8sStorage interface (#114799 )
2025-12-03 21:41:05 +00:00
Gabriel MABILLE
f7d9d22963
grafana-iam: standalone rely on storage layer resource permissions authorization (#114785 )
...
* : standalone resource permissions authorization done at storage layer
* instantiate the accessclient
2025-12-03 19:16:37 +01:00
Gabriel MABILLE
8998b1fde4
grafana-iam: Implement api level user authorization (#114498 )
...
* OnGoing
comment
* WIP on the wrapper
* Get before Delete
* WIP: add an unimplemented storage authorizer
* WIP implementing the resource permission authorize
* Implement beforeCreate
* Create, Delete, Update
* List
* Use a resource permissions wrapper
* Switch the main authorizer to service
* Add namespace
* Use compile for list
* Comment
* Remove unecessary comments
* fix bug with folder permissions
* Implement tests for List
* Test get
* List test small refactor
* Delete test
* Reorganize code
* imports
* Start splitting the tests
* test AfterDelete
* actually test beforeWrite
* Implement tests for wrapper create
* Test delete
* Test List and Get
* Fix List
* Remaining tests
* simplify
* Remove comments
* Reorder
* Change authorizer to allow access
2025-12-03 17:06:26 +01:00
Gabriel MABILLE
8c7170727b
grafana-iam: Prevent crashloops of the standalone IAM server (#114473 )
...
* `grafana-iam`: Prevent crashloops of the standalone IAM server
2025-11-26 12:54:50 +01:00
Gabriel MABILLE
b5a50e7772
grafana-iam: Use the UniStore as the default store (#113614 )
...
* `grafana-iam`: Use the UniStore as the default store
* Refactor all instantiations
* Remove enableDualWriter
* Nit. dw is clear enough
* Use the correct access control client
2025-11-20 15:51:50 +01:00
Gabriel MABILLE
97a6ab7b1c
AuthZ: Remove outdated comments (#113817 )
2025-11-13 11:06:02 +01:00
Gabriel MABILLE
b4b410f5be
grafana-iam: Register a flag to configure dualwrite modes (#113610 )
...
* `grafana-iam`: Register a flag to configure dualwrite modes
* Streamline helper code
* Launch sync job only with mode 1 to 3
2025-11-13 10:34:55 +01:00
Gabriel MABILLE
0a9f93436a
Docs: Fix grpc server key file param in config ini ( #113798 )
...
Docs: Fix config ini grpc server key param
2025-11-13 09:40:47 +01:00
Gabriel MABILLE and jguer
e90759e5af
grafana-iam: enable dual writing for resource permissions (#112793 )
...
* `grafana-iam`: enable dual writing for resource permissions
Co-authored-by: jguer <joao.guerreiro@grafana.com >
* copy paste mistake
* Reduce complexity
* nits to make the code easy to review
* Forgot to check the error
---------
Co-authored-by: jguer <joao.guerreiro@grafana.com >
2025-11-07 13:50:40 +01:00
Gabriel MABILLE and jguer
ff53276870
grafana-iam: Instantiate ExternalGroupMappingStorage as a NoopStorage (#113499 )
...
Co-authored-by: jguer <joao.guerreiro@grafana.com >
2025-11-06 11:00:37 +01:00
Gabriel MABILLE
6e66a98ef7
grafana-iam: skip flaky TestAfterResourcePermissionCreate test (#112504 )
...
`grafana-iam`: TestAfterResourcePermissionCreate flaky test skip
2025-10-16 09:54:38 +00:00
Gabriel MABILLE
0eb28d4f37
grafana-iam: Async write to zanzana (#112357 )
...
* `grafana-iam`: Async write to zanzana
* More succint
* Add a metric to keep track of waiting times for future calibration
* metrics
2025-10-16 08:33:06 +02:00
Gabriel MABILLE
0e34164329
grafana-iam: Populate Zanzana on resource permission creation (#111654 )
...
* `grafana-iam`: Populate Zanzana on resource permission creation
* use zanzana const
* Adding a toggle
* Add a new feature toggle to manage zanzana sync
* wire
* wire
* WIP
* Fix hook issue
* comments and tests
* Account for PR feedback
* Add a timeout to writes
* Check tuples len
* comment
* validate basic role
* shorter error
* object reads better than entry
2025-10-13 21:37:13 +02:00
Gabriel MABILLE
267848063d
AuthZService: Add a metric to count folder app requests ( #112258 )
2025-10-10 11:07:02 +02:00
Gabriel MABILLE
f4cd46504b
AuthZ: Add if user is allowed to the span attribute (#112197 )
...
* `AuthZ`: Add if user is allowed to the span attribute
* Suggestiong
2025-10-09 10:49:50 +02:00
Gabriel MABILLE
1cbe7c8848
AuthZ: log incomplete folder tree (#112151 )
2025-10-08 21:41:44 +02:00
Gabriel MABILLE
26e147d01f
AuthZ: Fix cacheHit computation ( #112088 )
...
* AuthZ: Fix cacheHit computation
* Remove the ok bool
2025-10-07 10:12:14 +02:00
Gabriel MABILLE
d6e362ade3
Server: Add possibility to register build-specific targets ( #111988 )
...
* Server: Add possibility to register Enterprise targets
* wip authz service
* Restore vscode
* Better comment
* Better comment v2'
2025-10-06 11:50:02 +02:00
Gabriel MABILLE
a98870f8f9
Extsvcacc: Split permission scope ( #111491 )
...
* Extsvcacc: Split permission scope
* Fix integration test
* Trigger CI/CD pipeline
* Change extsvc permission comparing
* Recreate unsplit permissions
2025-09-24 13:25:44 +02:00
Gabriel MABILLE
b63ba0269f
AuthZ: Recover from missing split scope ( #111492 )
...
* AuthZ: Recover from missing split scope
* Follow up changes
* Add test
* better log
* Add a comment to getScopeMap
* Punctuation
2025-09-24 13:24:21 +02:00
Gabriel MABILLE and Ieva
ee34c015ce
grafana-iam: Fix context for identity store queries to work (#111228 )
...
`grafana-iam`: Fix context for identity store
Co-authored-by: Ieva <ieva.vasiljeva@grafana.com >
2025-09-17 11:24:58 +01:00
Gabriel MABILLE
6c35bb2c6e
ExtSvcAccount: Remove expensive extsvc_total metric ( #111031 )
...
* ExtSvcAccount: Remove expensive `extsvc_total` metric
* Remove unused variables
2025-09-15 10:11:20 +02:00
Gabriel MABILLE
aecc2c9fe7
grafana-iam: init mt resourcepermission apis (#110821 )
...
* Init mt resource permissions
* Few fixes for the mt service to work
* Refactor NewAPIService to take the provider and enabledapis
2025-09-11 17:46:29 +02:00
Gabriel MABILLE and Ieva
5ce13061d5
AuthZ: Allow create without scope for specific resources ( #110867 )
...
* AuthZ: Create without scope for resources outside of folders
* Make it explicit that create requires a scope check
* Update pkg/services/authz/rbac/service.go
* Use skipScope instead of ReqScope
Co-authored-by: Ieva <ieva.vasiljeva@grafana.com >
* Explain why there is no need to skip scope for roles
---------
Co-authored-by: Ieva <ieva.vasiljeva@grafana.com >
2025-09-11 11:54:41 +02:00
Gabriel MABILLE
ddbc5bce4f
grafana-iam: Use namespace for dbHelper (#110888 )
2025-09-10 18:08:42 +02:00
5c6fd5e5af
grafana-iam: Implement resourcepermission list (#110769 )
...
* WIP: List
* make toV0ResourcePermissions work with an ordered list of assignments to ensure consistency in the results
* Test templates
* Split list query in two. I clearly need scopePatterns
* Add pagination with offsets
* Remove unecessary comment
* implement listiterator
* add listiterator tests
* return the correct resource version
* use SkipIntegrationTestInShortMode
* No need for the extra check on pagination being correctly set
Co-authored-by: Ieva <ieva.vasiljeva@grafana.com >
* Spec is out of date
* Remove wrong comment
* Add a test for the pagination token
---------
Co-authored-by: mohammad-hamid <mohammad.hamid@grafana.com >
Co-authored-by: Ieva <ieva.vasiljeva@grafana.com >
2025-09-10 11:17:53 +02:00
Gabriel MABILLE
d0f25b0cd7
Revert "Folders: Use authlib.AccessClient in authorizer" ( #110812 )
...
Revert "Folders: Use authlib.AccessClient in authorizer (#110602 )"
This reverts commit 0cb52b8be0 .
2025-09-09 15:45:37 +02:00
801fde02a7
grafana-iam: Implement resourcepermission creation (#110246 )
...
* Extract from #108753
Co-Authored-By: mohammad-hamid <mohammad.hamid@grafana.com >
* Tackle create
Co-Authored-By: mohammad-hamid <mohammad.hamid@grafana.com >
* WIP use identity store to resolve role names
* WIP
* create role
* Remove unecessary comments
* comments
* sql templates
* test role insert tplt
* Add tests 😅
* Test permission insert template
* Test permission delete template
* Test assignment_insert template
* Manually test insertion
* Remove delete permissions. This is a create case we don't have permissions for that resource
* generate name handled by the apiserver library
* Remove comment and conversion
* Small renaming nits
* changes from main
* Add storage backend tests
* Add test to sql
* Test role contains a unique permission
* linting
* Account for pr feedback
Co-authored-by: Ieva <ieva.vasiljeva@grafana.com >
* Reuse mappers
* Move function to models
* Add check between name and spec resource
* Check if the resource does not already exist
Co-authored-by: Ieva <ieva.vasiljeva@grafana.com >
* fix query
* Check basic roles
Co-authored-by: Ieva <ieva.vasiljeva@grafana.com >
* Account for error
* Make struct names consistent
* Nit. I prefer createAndAssignManagedRole
* Remove notifyign
* log errors instead of returning them
* Fix exist query join
* Test errors
* Remove dup
---------
Co-authored-by: mohammad-hamid <mohammad.hamid@grafana.com >
Co-authored-by: Ieva <ieva.vasiljeva@grafana.com >
2025-09-05 14:22:25 +02:00
Gabriel MABILLE
885812f694
AuthZ: Recover from an outdated cached folder tree ( #110293 )
2025-09-01 11:16:01 +02:00
Gabriel MABILLE
0284c3f1f9
grafana-iam: change resourcepermission to use a single verb (#110263 )
...
* `grafana-iam`: change resource permission to only allow a single action set for now
* api changes
2025-08-28 11:25:38 +02:00
Gabriel MABILLE and mohammad-hamid
b6226c6173
grafana-iam: Skeleton of the resource permission api backend (#110218 )
...
* Extract from #108753
Co-Authored-By: mohammad-hamid <mohammad.hamid@grafana.com >
* Tackle create
Co-Authored-By: mohammad-hamid <mohammad.hamid@grafana.com >
* WIP use identity store to resolve role names
* Commit empty service for now
* Clean
* For now only show name and created at
---------
Co-authored-by: mohammad-hamid <mohammad.hamid@grafana.com >
2025-08-27 15:00:09 +02:00
Gabriel MABILLE
69dc5a0b88
grafana-iam: Add resolver for permissions:type:delegate (#108789 )
...
* `grafana-iam`: Add resolver for `permissions:type:delegate`
* roles create -> write
2025-07-29 21:11:06 +02:00
Gabriel MABILLE
1a7a7f1d99
grafana-iam: Wire the roles api (#108577 )
2025-07-28 13:36:27 +02:00
Gabriel MABILLE and Ieva
4b217c601a
AuthZ: Scope resolution ( #107948 )
...
* AuthZ: Scope resolution
* Account for PR feedback
Co-authored-by: Ieva <ieva.vasiljeva@grafana.com >
2025-07-17 14:34:10 +02:00
Gabriel MABILLE
85a6a7b9c1
iam: add description field to roles (#107888 )
...
* iam: add description field to roles
* Openapi gen
* Revert launch change
2025-07-10 09:24:30 +02:00
Gabriel MABILLE and mohammad-hamid
1244f5c53d
AuthZ: Add CoreRoleStorageBackend to the extension set ( #103912 )
...
* Wiring
* Trigger CI
---------
Co-authored-by: mohammad-hamid <mohammad.hamid@grafana.com >
2025-07-07 20:08:44 +02:00
Gabriel MABILLE
3d543a336f
IAM: Register CoreRole apis ( #106924 )
...
* IAM: Register CoreRole apis
* one line store instantiation
* Small refactor for readability
* Add authorizer for CoreRole
* Nit
* Error strings should not end with punctiation
* Account for error
* Switch to use the local resource client
* error should not start with upper casing
* noopStorageErr should have a name starting with err
* Update workspace
* I don't know why I don't have the same output as the CI 🤷
* Dependency xOwnership
* imports
* Import order
* Rename alias to make it clear this is legacy
2025-06-26 10:11:28 +02:00
Gabriel MABILLE
aa3d09bd70
Docs: Updatebasic_grafana_admin role assignments ( #107112 )
...
RBAC: Update docs
2025-06-24 14:54:41 +02:00
Gabriel MABILLE
56c9dbf6e5
AuthZ: Add a feature toggle for the k8s apis ( #106795 )
2025-06-18 09:43:01 +02:00
Gabriel MABILLE and Alexander Zobnin
c012480fd6
Authz: Define app resources ( #105050 )
...
* Authz: Define app resources
* Add coreroles and cluster roles
* Restore CODEOWNERS from main
* ManagedPermissions -> ResourcePermissions
* Rework changes
* Update apps/authz/kinds/v0alpha1/rolebindingspec.cue
Co-authored-by: Alexander Zobnin <alexanderzobnin@gmail.com >
* Update apps/authz/kinds/v0alpha1/rolespec.cue
Co-authored-by: Alexander Zobnin <alexanderzobnin@gmail.com >
* Make
* WIP first set of comments
* typox
* Copy folder Makefile
* Remove uid
* Rename authz -> iam
* Rename to iam
* Dockerfile
* Remove name
* Mv up
* Try with postprocess
* linting
* Use same version
* apimachinery v0.32.3
* update-workspace
---------
Co-authored-by: Alexander Zobnin <alexanderzobnin@gmail.com >
2025-05-21 14:47:44 +02:00
Gabriel MABILLE
cb3cd021b7
AuthZ-Service: Add traces to cache ( #105718 )
2025-05-21 14:35:43 +02:00
Gabriel MABILLE
80898c14d0
AuthZ-Service: Add debug logs with the function execution duration ( #105621 )
...
AuthZ-Service: Add simple logs with the execution duration
2025-05-19 17:47:01 +02:00
Gabriel MABILLE
6b588f4c93
Migrations: Make sure users uid are set ( #104996 )
...
* Migrations: Make sure default admin has a uid
* Account for all users not only id 1
* Add spanner
* Wrong migration to add spanner
* Fix spanner mig
2025-05-07 13:40:32 +02:00
Gabriel MABILLE
ef91e627d1
.gitignore: devenv for spanner ( #104668 )
2025-05-05 09:59:28 +02:00
45d6bfe7cf
AuthZ: Make cache ttl configurable ( #103769 )
...
* AuthZ: Configure cache ttl
Co-authored-by: Eric Leijonmarck <eric.leijonmarck@gmail.com >
* Client side conf
Co-authored-by: Ieva <ieva.vasiljeva@grafana.com >
Co-authored-by: Eric Leijonmarck <eric.leijonmarck@gmail.com >
* 0 -> No caching
* Make it possible to disable cache on the remote client as well
* Comment
* Move ttl parsing up for in-proc to have it
---------
Co-authored-by: Eric Leijonmarck <eric.leijonmarck@gmail.com >
Co-authored-by: Ieva <ieva.vasiljeva@grafana.com >
2025-04-11 10:09:47 +02:00
Gabriel MABILLE
86bccc3c93
gitignore: ignore mt-db devenv ( #103371 )
...
Devenv: ignore mt-db devenv
2025-04-09 21:38:40 +02:00
Gabriel MABILLE
2d89b16d7e
Tracing: Add Insecure to NewOTLPTracingConfig ( #103174 )
2025-04-01 17:34:42 +02:00
Gabriel MABILLE
8767a8f9a1
AuthZ: Improve getUserPermissions query (INNER JOIN, UNION ALL) ( #102441 )
2025-03-19 16:54:32 +01:00
Gabriel MABILLE
9a556fbde6
AuthZService: Add attributes to traces ( #102433 )
2025-03-19 12:21:39 +01:00
Gabriel MABILLE
c8f810b422
Authz: Check namespace is set in the context ( #101723 )
...
* Authz: Test List
* Anonymous case
* Cover rendering
* Authz: Check namespace is set in the context
* Explicitly request a namespace check in the storage functions
* Revert logic
2025-03-11 12:04:33 +01:00
Gabriel MABILLE
6a1e5dd128
AuthZ: Test List ( #101721 )
...
* Authz: Test List
* Anonymous case
* Cover rendering
2025-03-07 15:01:39 +01:00
Gabriel MABILLE
6accf13597
AuthZService: Test Check ( #101675 )
...
* wip
* deny case
* Reorganise
* WIP
* Check cache
* Add anonymous test
* Add test for rendering
* Lint import
* Refactor slightly
* more input validation coverage
* Require user
* typo
2025-03-06 13:37:37 +01:00
Gabriel MABILLE
a91081a2fc
AuthZService: Add certificates to the client ( #101603 )
2025-03-06 10:18:58 +01:00
Gabriel MABILLE
c3505f0864
AuthZ: Make NewGrpcTokenAuth public ( #101352 )
...
* AuthZ: Expose NewGrpcTokenAuth
* Lint
2025-02-26 17:29:32 +01:00
Gabriel MABILLE
f3433fd472
RBAC: Remove accessControlOnCall feature toggle ( #101222 )
...
* RBAC: Remove accessControlOnCall feature toggle
* Leave the other one in place
* Tests
* frontend
* Readd empty ft to frontend test
* Remove legacy RBAC check
* Fix test
* no need for context
* Remove unused variable
* Remove unecessary param
* remove unecessary param from tests
* More tests :D
2025-02-25 13:44:40 +01:00
Gabriel MABILLE
0290da6aaa
AccessControl: Allow plugin roles to include plugins:write ( #101089 )
2025-02-21 08:23:04 +01:00
Gabriel MABILLE
90eb499b78
PublicDashboards: Fetch dashboard as Grafana ( #100344 )
2025-02-13 17:17:14 +01:00
Gabriel MABILLE
a9f0e15778
AuthZ: Change cache interface ( #99058 )
...
* Authz: Switch to remotecache
* Todos
* lint
* lint test
* test readibility
* Remove ttls
* implement a cache wrap
* Rm unused func
* Comment
* Update workspace:
* Use cache
* Fix comment
2025-01-24 09:51:39 +01:00
Gabriel MABILLE
05015a57b3
Chore: Upgrade authlib ( #99447 )
2025-01-23 15:52:03 +01:00
Gabriel MABILLE
70ddf9cb76
Authenticator: Return gRPC errors ( #99000 )
2025-01-16 14:33:57 +01:00
Gabriel MABILLE
b6fc695598
ExtJwtClient: Use user namespace for k8s allowed namespace ( #93687 )
...
* ExtJwtClient: Use user namespace for k8s allowed namespace
* fix test
2025-01-15 17:38:46 +01:00
Gabriel MABILLE
4c86de2678
Chore: Update authlib ( #98870 )
...
* Chore: Update authlib
* AccessChecker -> AccessClient
2025-01-14 09:42:17 +01:00
Gabriel MABILLE and ievaVasiljeva
4d699d4810
AuthZ: Use M3 AuthZ Service ( #98621 )
...
* AuthZ: Use M3 AuthZ Service
Co-authored-by: ievaVasiljeva <ieva.vasiljeva@grafana.com >
* Fix oss
* fake auth info
---------
Co-authored-by: ievaVasiljeva <ieva.vasiljeva@grafana.com >
2025-01-13 16:03:14 +01:00
Gabriel MABILLE
bc7e90bc28
AuthZ: Fix client dial options ( #98827 )
2025-01-10 17:41:56 +01:00
Gabriel MABILLE
efb7cc0343
Chore: Authlib upgrade ( #98319 )
...
* Chore: Authlib upgrade
* Upgrade authlib
* Uncommit file
2024-12-20 15:48:35 +01:00
Gabriel MABILLE
55f8be62a1
AuthZ Service: Use singleflight group to fetch and build the folder tree ( #98299 )
...
* AuthZ Service: Use singleflight group to fetch and build the folder tree
* Change the sfgroup key
* Future proof
2024-12-20 10:26:30 +01:00
Gabriel MABILLE
c175722dfd
AuthZService: Cache folder tree ( #98210 )
...
* AuthZService: Cache folder tree
* Remove fmt
* Suggestion
* Add tests
2024-12-19 13:55:59 +01:00
Gabriel MABILLE
987357327d
Chore: Update authlib ( #98191 )
2024-12-18 17:16:34 +01:00
Gabriel MABILLE
961211b21a
AuthZ Service: Add caching ( #98008 )
...
* AuthZ Service: Add caching
* split in functions
* Test getUserTeams
* Add tests to getUserBasicRole
* Test getUserPermissions
* Cache user identifiers
* fix test
2024-12-18 14:07:19 +01:00
Gabriel MABILLE
4c8d14270d
Docs: Read on the dashboard/datasource is required to view insights ( #98111 )
...
* Docs: Read on the dashboard/datasource is required to view insights
* ','
2024-12-17 15:22:21 +01:00
Gabriel MABILLE
65dfbd7731
go.mod: Update authlib ( #97833 )
...
* go.mod: Update authlib
* No clue why it was removed by my computer but not by CI
2024-12-12 13:56:01 +01:00
Gabriel MABILLE
9745555b6a
gitignore: signer devenv ( #97742 )
...
Forgot to add the gitignore
2024-12-10 15:36:12 +01:00
Gabriel MABILLE
d9cd5a3a2c
Setting: Fix redact of entity db pass ( #97568 )
2024-12-06 17:31:36 +01:00
Gabriel MABILLE
ef79450065
Settings: Redact token keyword ( #97395 )
...
* Settings: Redact token keyword
* Be more specific
* Given section is part of key, be more specific
* Fix test
2024-12-04 16:58:29 +01:00
Gabriel MABILLE and Irene Rodriguez
3f8c20907c
Docs: Make a clear distinction between Organization Roles and RBAC roles ( #97082 )
...
* Docs: Make a clear distinction between Organization Roles and RBAC roles
* Add section to assign fixed and custom roles using the HTTP api
* Remove </br>
* run prettier
* Suggestions
Co-authored-by: Irene Rodriguez <irene.rodriguez@grafana.com >
---------
Co-authored-by: Irene Rodríguez <irene.rodriguez@grafana.com >
2024-12-03 11:40:51 +01:00
Gabriel MABILLE
6e2d3cae5e
AuthN: Register flags for grpc_server_authentication configuration ( #97063 )
...
* AuthZServer: Add authenticator
* Add flags
2024-11-27 10:35:35 +01:00
Gabriel MABILLE
6d77c0e187
AuthZ client: Add tracing ( #96983 )
...
* AuthZ client: Add tracing
* InProc as well
2024-11-25 14:17:52 +01:00
Gabriel MABILLE
3c876f0208
AuthZ: Introduce cloud mode ( #96922 )
...
* AuthZ: Introduce cloud mode
* Update readme
2024-11-22 16:19:53 +01:00
Gabriel MABILLE
a9b938427e
Fix: Correct handling of base64 padding during aes-gcm private key decryption. ( #96761 )
...
* SecretsService: Use RawStdEncoding to avoid padding
* Commment
* Forgot one line
* Backward compatibility
2024-11-21 10:08:48 +01:00
Gabriel MABILLE
aa2b4751a0
AuthZ: Launch service within IAM app ( #96421 )
2024-11-20 11:13:33 +01:00
Gabriel MABILLE
cc9cdbe82d
Authz: Move extension proto up a layer ( #96254 )
...
* Authz: Move extension proto up a layer
* Lint
2024-11-12 10:19:12 +01:00
Gabriel MABILLE
bd53fa9580
LocalSigner: Remove unused dependency ( #96118 )
...
ID Token Signer: Remove unecessary deps
2024-11-08 15:46:16 +01:00
Gabriel MABILLE
df8b6e6862
Fix: Close grpc_authenticator fallback trace ( #96009 )
...
Fix: Close grpc_authenticator trace
2024-11-07 11:29:25 +01:00
Gabriel MABILLE
5a0ef46280
Add tracing to the gRPC Authentication flow ( #94466 )
...
commit ad4df4b3f63bdf3e16423ac8c3fdb1a7fae5582e
Author: gamab <gabriel.mabille@grafana.com >
Date: Thu Oct 24 10:24:04 2024 +0200
nit
commit eb8b9cf2f3e27cae258b3ae310f1584da5ba36b5
Author: gamab <gabriel.mabille@grafana.com >
Date: Thu Oct 24 10:23:25 2024 +0200
miss
commit aab1aed204a5dedcc6dd187b2f636995bbe2c5c6
Merge: 5aafdec9233 7fe710b141
Author: gamab <gabriel.mabille@grafana.com >
Date: Thu Oct 24 10:22:05 2024 +0200
Merge remote-tracking branch 'origin/main' into gamab/resourcestore/tracing
commit 5aafdec9233d6824cba977b069d71eabc3d21a8d
Author: gamab <gabriel.mabille@grafana.com >
Date: Wed Oct 16 18:03:56 2024 +0200
Did not fix the issue
commit 20522a7f64222fad27268ac640d4b4fb9259c748
Author: gamab <gabriel.mabille@grafana.com >
Date: Wed Oct 16 17:42:35 2024 +0200
Test
commit b45199a341b6a57e93927c9eb7de8d7758ed7619
Merge: c0fbbdb95d4 e9e2b11ba2
Author: gamab <gabriel.mabille@grafana.com >
Date: Wed Oct 16 17:31:59 2024 +0200
Merge remote-tracking branch 'origin/drclau/unistor/replace-authenticators-3' into gamab/resourcestore/tracing
commit e9e2b11ba2
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Wed Oct 16 18:28:31 2024 +0300
PR feedback: simplified fallback implementation
Co-Authored-By: Gabriel MABILLE <gamab@users.noreply.github.com >
commit b5209dba64
Author: Claudiu Dragalina-Paraipan <drclau@users.noreply.github.com >
Date: Wed Oct 16 18:03:06 2024 +0300
Update pkg/services/authn/grpcutils/grpc_authenticator.go
Co-authored-by: Gabriel MABILLE <gamab@users.noreply.github.com >
commit c0fbbdb95d4605f349b902ca8698e7b560433867
Author: gamab <gabriel.mabille@grafana.com >
Date: Wed Oct 16 10:32:52 2024 +0200
Add traces to fallback
commit 75aa8dcbd49288f1dca53cdf6e9a7b41688dff38
Merge: d92fafcaf0d 562d499e85
Author: gamab <gabriel.mabille@grafana.com >
Date: Wed Oct 16 10:29:41 2024 +0200
Merge remote-tracking branch 'origin/drclau/unistor/replace-authenticators-3' into gamab/resourcestore/tracing
commit 562d499e85
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Wed Oct 16 11:05:01 2024 +0300
switched to features.IsEnabledGlobally()
commit addc6aaca4
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Wed Oct 16 10:21:31 2024 +0300
imports cleanup
commit 7c6d80f6aa
Merge: 64a5e55d61 9dc2ccdbfd
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Wed Oct 16 10:18:54 2024 +0300
Merge branch 'main' into drclau/unistor/replace-authenticators-3
commit 64a5e55d61
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Oct 15 11:01:54 2024 +0300
cleanup
commit 4fe2c03457
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Oct 15 10:31:06 2024 +0300
always enable FlagAppPlatformGrpcClientAuth for k8s int tests
commit c7e36759cd
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Oct 15 10:30:43 2024 +0300
use sync.Once as it's more idiomatic
commit f5c2c79981
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Oct 14 20:43:48 2024 +0300
remove client side namespace extractor
commit 742295c89a
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Oct 14 20:04:11 2024 +0300
avoid double registration of metrics (fallbackCounter)
commit a45998c8d3
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Oct 14 19:03:41 2024 +0300
use FlagAppPlatformGrpcClientAuth to enable new behavior, instead of legacy
commit ffdc301718
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Oct 14 18:37:22 2024 +0300
remove the NamespaceAuthorizer
The NamespaceAuthorizer would fail in legacy mode. It will be added back in the future.
commit 4a03ed7d7d
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Oct 14 15:59:08 2024 +0300
allow using the legacy resource client via
commit a2c30f5328
Merge: ead390f608 2f3c539d9b
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Oct 14 14:08:32 2024 +0300
Merge branch 'main' into drclau/unistor/replace-authenticators-3
commit ead390f608
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Fri Oct 11 09:38:49 2024 +0300
added server side gRPC authn fallback-to-legacy mechanism
- brought back the old gRPC authenticator
- added `grpc_server_authentication.legacy_fallback` config option
- introduced `AuthenticatorWithFallback`
- added telemetry to track fallbacks
commit d92fafcaf0db9c8d97a5d071759fc21ede7d8848
Author: gamab <gabriel.mabille@grafana.com >
Date: Wed Oct 9 14:58:25 2024 +0200
Fix test
commit 54f05ff0fecf3d696a0e98621db6991282503917
Author: gamab <gabriel.mabille@grafana.com >
Date: Wed Oct 9 14:42:18 2024 +0200
Forgot the tracer 😁
commit 3948048880c7a0eb2360a35b0cc9f3686f2edfef
Author: gamab <gabriel.mabille@grafana.com >
Date: Wed Oct 9 14:02:41 2024 +0200
Add traces to NamespaceAuthorizer
commit cc695bb77c37a097174556303721fbc48b9464a0
Author: gamab <gabriel.mabille@grafana.com >
Date: Wed Oct 9 13:56:48 2024 +0200
Add traces to authentication flow
commit 8686c46be5
Merge: 08c3d237dc 4a3ce66193
Author: gamab <gabriel.mabille@grafana.com >
Date: Wed Oct 9 13:56:26 2024 +0200
Merge remote-tracking branch 'origin/main' into drclau/unistor/replace-authenticators-3
commit 08c3d237dc
Merge: 33fd104cfd 84d580179d
Author: gamab <gabriel.mabille@grafana.com >
Date: Wed Oct 9 12:41:57 2024 +0200
Merge remote-tracking branch 'origin/main' into drclau/unistor/replace-authenticators-3
commit 33fd104cfd
Merge: 68af25fbc3 38f57d270a
Author: gamab <gabriel.mabille@grafana.com >
Date: Wed Oct 9 12:13:25 2024 +0200
Merge remote-tracking branch 'origin/main' into drclau/unistor/replace-authenticators-3
commit 68af25fbc3
Author: Gabriel MABILLE <gamab@users.noreply.github.com >
Date: Mon Oct 7 16:31:09 2024 +0200
Update pkg/services/authz/config.go
commit 4fba5c9b32
Author: gamab <gabriel.mabille@grafana.com >
Date: Fri Oct 4 15:17:41 2024 +0200
PR Feedback
commit 86867a14ca
Author: Gabriel MABILLE <gamab@users.noreply.github.com >
Date: Fri Oct 4 15:13:06 2024 +0200
Update pkg/services/authn/grpcutils/config.go
Co-authored-by: Dan Cech <dcech@grafana.com >
commit c591631135
Merge: c80c46ca6a e37b43117b
Author: gamab <gabriel.mabille@grafana.com >
Date: Fri Oct 4 13:07:48 2024 +0200
Merge remote-tracking branch 'origin/main' into drclau/unistor/replace-authenticators-3
commit c80c46ca6a
Merge: 3acada9d47 4224d05934
Author: gamab <gabriel.mabille@grafana.com >
Date: Thu Oct 3 14:58:51 2024 +0200
Merge remote-tracking branch 'origin/main' into drclau/unistor/replace-authenticators-3
commit 3acada9d47
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Fri Sep 27 17:39:59 2024 +0300
introducing `mode` config for gRPC auth server & client side
commit 914ca237e2
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Thu Sep 26 20:47:57 2024 +0300
Fixed integration tests
commit 71c33dcbe3
Merge: 52f248eebb 920d79680d
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Thu Sep 26 19:25:33 2024 +0300
Merge branch 'main' into drclau/unistor/replace-authenticators-3
commit 52f248eebb
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Sep 24 18:44:38 2024 +0300
updated namespace extractor usage
commit a6c977ba4d
Merge: fb7bbf743b 8da1d78c92
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Sep 24 17:35:03 2024 +0300
Merge branch 'main' into drclau/unistor/replace-authenticators-3
commit fb7bbf743b
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Sep 24 17:34:36 2024 +0300
unistor client side updates
commit a28440c40b
Merge: 79d9969aa8 a8b07b0c81
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Sep 24 10:45:09 2024 +0300
Merge branch 'main' into drclau/unistor/replace-authenticators-3
commit 79d9969aa8
Author: gamab <gabriel.mabille@grafana.com >
Date: Mon Sep 9 16:14:02 2024 +0200
Rename NewResourceClient funcs
commit 36b3752490
Merge: 8ce354bb06 b89f3f8115
Author: gamab <gabriel.mabille@grafana.com >
Date: Mon Sep 9 16:00:54 2024 +0200
Merge remote-tracking branch 'origin/main' into drclau/unistor/replace-authenticators-3
commit 8ce354bb06
Author: gamab <gabriel.mabille@grafana.com >
Date: Mon Sep 9 10:40:06 2024 +0200
Align
commit bdf79f3b2f
Merge: 8f4df8973d 8eb7e55f8f
Author: gamab <gabriel.mabille@grafana.com >
Date: Mon Sep 9 10:38:45 2024 +0200
Merge remote-tracking branch 'origin/main' into drclau/unistor/replace-authenticators-3
commit 8f4df8973d
Merge: 2441cd8d53 9338e40dc3
Author: gamab <gabriel.mabille@grafana.com >
Date: Thu Sep 5 11:26:39 2024 +0200
Merge remote-tracking branch 'origin/main' into drclau/unistor/replace-authenticators-3
commit 2441cd8d53
Merge: 2904074a2f 2bbce8a7f7
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Sep 3 17:31:36 2024 +0300
Merge branch 'main' into drclau/unistor/replace-authenticators-3
commit 2904074a2f
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Sep 3 16:35:25 2024 +0300
refactoring
Co-Authored-By: Gabriel MABILLE <gamab@users.noreply.github.com >
commit 125cb3c834
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Sep 3 16:34:18 2024 +0300
refactoring (aesthetics)
Co-Authored-By: Gabriel MABILLE <gamab@users.noreply.github.com >
commit 499a31df53
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Sep 3 15:59:09 2024 +0300
update usage of ReadGprcServerConfig()
commit f5d383644d
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Sep 3 15:44:09 2024 +0300
make update-workspace
commit 755485751e
Author: gamab <gabriel.mabille@grafana.com >
Date: Tue Sep 3 14:43:22 2024 +0200
Fix trace
commit d09e14c26a
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Sep 3 15:42:50 2024 +0300
removed WithIDTokenExtractorOption, and other PR feedback
commit 21220c2cca
Author: gamab <gabriel.mabille@grafana.com >
Date: Tue Sep 3 14:36:59 2024 +0200
Else statement
commit 6cf1efdcc4
Author: gamab <gabriel.mabille@grafana.com >
Date: Tue Sep 3 14:35:02 2024 +0200
Mod update
commit 4b73a93883
Author: gamab <gabriel.mabille@grafana.com >
Date: Tue Sep 3 14:32:20 2024 +0200
Add Auth func overrides
commit 6032ab3ae1
Author: gamab <gabriel.mabille@grafana.com >
Date: Tue Sep 3 14:26:18 2024 +0200
Use NamespaceAuthorizer
commit 601beb5327
Author: gamab <gabriel.mabille@grafana.com >
Date: Tue Sep 3 14:20:47 2024 +0200
Update authlib
commit a1b6408127
Merge: 0d70225c1a 1128c417d8
Author: gamab <gabriel.mabille@grafana.com >
Date: Tue Sep 3 14:18:49 2024 +0200
Merge remote-tracking branch 'origin/main' into drclau/unistor/replace-authenticators-3
commit 0d70225c1a
Author: Claudiu Dragalina-Paraipan <drclau@users.noreply.github.com >
Date: Tue Sep 3 15:15:54 2024 +0300
Update pkg/services/authn/grpcutils/grpc_authenticator.go
Co-authored-by: Gabriel MABILLE <gamab@users.noreply.github.com >
commit 62f165f6f9
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Sep 3 10:55:45 2024 +0300
refactoring NamespaceAccessChecker usage and use CloudNamespaceFormatter in Cloud
Co-Authored-By: Gabriel MABILLE <gamab@users.noreply.github.com >
commit bb5ee88d4f
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Sep 3 10:39:11 2024 +0300
added stackIdExtractor for cloud mode
Co-Authored-By: Gabriel MABILLE <gamab@users.noreply.github.com >
commit 84866a8a51
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Sep 3 10:38:19 2024 +0300
authz client cfg changes
- removed ModeCloud, relying on ModeGrpc and stackID instead to discover if we're running in Cloud
- reusing settings from "grpc_client_authentication", instead of duplicating in "authorization" section
Co-Authored-By: Gabriel MABILLE <gamab@users.noreply.github.com >
commit 14a1021605
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Sep 2 21:44:35 2024 +0300
make update-workspace
commit 84f8c9be94
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Sep 2 21:36:10 2024 +0300
cleanup: refactoring leftover
commit 7fe8d62304
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Sep 2 19:30:51 2024 +0300
update authlib version (small fix)
commit 7c2353ae25
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Sep 2 19:17:11 2024 +0300
cleanup: remove unused `GrpcServerConfig.Mode`
commit 52b7cf8550
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Sep 2 19:06:59 2024 +0300
make update-workspace
commit 14ddfbd8fb
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Sep 2 19:02:40 2024 +0300
finalize authlib grpc interceptors usage
commit 884c4a8c24
Merge: 0fd1988bed a1190b165b
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Sep 2 19:00:07 2024 +0300
Merge branch 'main' into drclau/unistor/replace-authenticators-3
commit 0fd1988bed
Merge: b766bfb24f e0950a1283
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Fri Aug 30 10:45:51 2024 +0300
Merge branch 'main' into drclau/unistor/replace-authenticators-3
commit b766bfb24f
Merge: 6993f108a2 68751ed310
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Wed Aug 28 15:46:04 2024 +0300
Merge branch 'main' into drclau/unistor/replace-authenticators-3
commit 6993f108a2
Merge: 5f073b04d0 f1ba609b34
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Tue Aug 27 12:51:07 2024 +0300
Merge branch 'main' into drclau/unistor/replace-authenticators-3
commit 5f073b04d0
Merge: 0620891d45 ac5ebe6e4d
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Aug 19 21:09:44 2024 +0300
Merge branch 'main' into drclau/unistor/replace-authenticators-3
commit 0620891d45
Merge: 6a272e8e2a 15f2b08f00
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Mon Aug 12 14:14:44 2024 +0300
Merge branch 'main' into drclau/unistor/replace-authenticators-3
commit 6a272e8e2a
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Thu Aug 8 18:53:43 2024 +0300
allow insecure conns in dev mode + refactoring
commit 31c7b030ba
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Thu Aug 8 10:31:13 2024 +0300
allow insecure connections (for testing purposes); remove audience checks
audience checks will still need to be done for Access tokens, but not for ID tokens
commit 0fdd2ff802
Merge: 763961210c f384759ad1
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Wed Aug 7 14:42:39 2024 +0300
Merge branch 'main' into drclau/unistor/replace-authenticators-3
commit 763961210c
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Fri Aug 2 18:54:29 2024 +0300
wip
commit c46b42a595
Merge: 92aba937a9 0145b0fe70
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Fri Aug 2 14:44:06 2024 +0300
Merge branch 'main' into drclau/unistor/replace-authenticators-3
commit 92aba937a9
Author: Claudiu Dragalina-Paraipan <claudiu.dragalina@grafana.com >
Date: Thu Aug 1 18:32:19 2024 +0300
authn: client side updates
Co-Authored-By: Gabriel MABILLE <gamab@users.noreply.github.com >
2024-10-28 14:35:30 +02:00
Gabriel MABILLE and Alexander Zobnin
2788817107
AuthZ: Implement Check ( #95162 )
...
* AuthZ: Implement Check
---------
Co-authored-by: Alexander Zobnin <alexanderzobnin@gmail.com >
2024-10-25 14:57:39 +02:00
Gabriel MABILLE and Claudiu Dragalina-Paraipan
b68b69c2b4
AuthN: Use tokens for unified storage server authentication ( #95086 )
...
* Extract server code
---------
Co-authored-by: Claudiu Dragalina-Paraipan <drclau@users.noreply.github.com >
2024-10-23 15:04:15 +02:00
Gabriel MABILLE and Eric Leijonmarck
7aeb1adff2
Fix: Check JSON data is not nil ( #95189 )
...
* Fix: Fix panic when json data are nil
* Use Interface()
* Feedback
Co-authored-by: Eric Leijonmarck <eric.leijonmarck@gmail.com >
* Need to check inside the if statement
---------
Co-authored-by: Eric Leijonmarck <eric.leijonmarck@gmail.com >
2024-10-22 18:09:44 +01:00
Gabriel MABILLE and Claudiu Dragalina-Paraipan
0704ae734f
AuthZ: Refactor authentication modes for the Authz package ( #95120 )
...
* AuthZ: Fix authentication modes for the Authz package
Co-Authored-By: Claudiu Dragalina-Paraipan <drclau@users.noreply.github.com >
2024-10-22 13:38:59 +02:00
Gabriel MABILLE
ba3629c01c
Fix: Account for conflicting logins in dedupOrgInlogin migration ( #94669 )
2024-10-15 15:02:34 +02:00
Gabriel MABILLE
6dbd324ef9
Fix: Actually call the DedupOrgInLogin migration ( #94520 )
2024-10-10 10:53:31 +02:00