Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Tables] Multi tenant authentication #17525

Closed
wants to merge 17 commits into from

Conversation

seankane-msft
Copy link
Member

@seankane-msft seankane-msft commented Apr 11, 2022

Adds a challenge policy for clients created with an azidentity credential

#17332

@check-enforcer
Copy link

This pull request is protected by Check Enforcer.

What is Check Enforcer?

Check Enforcer helps ensure all pull requests are covered by at least one check-run (typically an Azure Pipeline). When all check-runs associated with this pull request pass then Check Enforcer itself will pass.

Why am I getting this message?

You are getting this message because Check Enforcer did not detect any check-runs being associated with this pull request within five minutes. This may indicate that your pull request is not covered by any pipelines and so Check Enforcer is correctly blocking the pull request being merged.

What should I do now?

If the check-enforcer check-run is not passing and all other check-runs associated with this PR are passing (excluding license-cla) then you could try telling Check Enforcer to evaluate your pull request again. You can do this by adding a comment to this pull request as follows:
/check-enforcer evaluate
Typically evaulation only takes a few seconds. If you know that your pull request is not covered by a pipeline and this is expected you can override Check Enforcer using the following command:
/check-enforcer override
Note that using the override command triggers alerts so that follow-up investigations can occur (PRs still need to be approved as normal).

What if I am onboarding a new service?

Often, new services do not have validation pipelines associated with them. In order to bootstrap pipelines for a new service, please perform following steps:

For track 2 SDKs Issue the following command as a pull request comment:

/azp run prepare-pipelines
This will run a pipeline that analyzes the source tree and creates the pipelines necessary to build and validate your pull request. Once the pipeline has been created you can trigger the pipeline using the following comment:
/azp run go - [service] - ci

@seankane-msft
Copy link
Member Author

/azp run go - aztables

@azure-pipelines
Copy link

Azure Pipelines successfully started running 1 pipeline(s).

sdk/data/aztables/internal/auth/challenge_policy.go Outdated Show resolved Hide resolved
)

// ClientOptions are the optional parameters for the NewClient method
type ClientOptions struct {
azcore.ClientOptions
}

func (c *ClientOptions) toPolicyOptions() *azcore.ClientOptions {
return &azcore.ClientOptions{
func (c *ClientOptions) toPolicyOptions() *policy.ClientOptions {
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

should we make it possible to disable the tenant discovery behavior through clientOptions?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Did you add that for .NET in storage? I don't have it in the KV clients, but if it's included in other languages I can add it in Go

@seankane-msft
Copy link
Member Author

/azp run go - aztables

@azure-pipelines
Copy link

Azure Pipelines failed to run 1 pipeline(s).


// Atomically, update the shared resource's new value & expiration.
er.cond.L.Lock()
if err == nil {
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The latest version of this, in azcore/internal/shared, is more resilient to transient failures

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If this code is going to be used in multiple places, can it be moved to internal instead?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I like that better than vendoring our own code but I think we want to extend azcore/runtime.BearerTokenPolicy (#17554) and share that instead of ExpiringResource.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agree with Charles, are we ok with adding this for now and migrating later or do we want to make the migration into core now?

sdk/data/aztables/client_test.go Outdated Show resolved Hide resolved
sdk/data/aztables/internal/auth/challenge_policy.go Outdated Show resolved Hide resolved
s.req.Raw().Context(),
policy.TokenRequestOptions{
Scopes: []string{*s.p.scope},
TenantID: *s.p.scope,
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This won't work with azidentity credentials until we address #14932. I thought we intended to remove this field to avoid suggesting it might have an effect; @jhendrixMSFT do you recall discussing that?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If that's the case, wouldn't this fail for keyvault which uses the same logic?
Reference: https://github.com/Azure/azure-sdk-for-go/blob/main/sdk/keyvault/internal/challenge_policy.go#L223-L236

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only when the resource isn't in the credential's configured tenant. You would need to ensure it isn't in order to test multitenancy (the live test you're adding here doesn't).

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chlowell we use it today in the implementation for ARM's multitenant auth here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants