Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix ImdsManagedIdentityProvider (#4096) #4193

Merged
merged 1 commit into from
May 10, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 15 additions & 6 deletions object_store/src/azure/credential.rs
Original file line number Diff line number Diff line change
Expand Up @@ -50,8 +50,17 @@ pub(crate) const RFC1123_FMT: &str = "%a, %d %h %Y %T GMT";
const CONTENT_TYPE_JSON: &str = "application/json";
const MSI_SECRET_ENV_KEY: &str = "IDENTITY_HEADER";
const MSI_API_VERSION: &str = "2019-08-01";

/// OIDC scope used when interacting with OAuth2 APIs
///
/// <https://learn.microsoft.com/en-us/azure/active-directory/develop/scopes-oidc#the-default-scope>
const AZURE_STORAGE_SCOPE: &str = "https://storage.azure.com/.default";

/// Resource ID used when obtaining an access token from the metadata endpoint
///
/// <https://learn.microsoft.com/en-us/azure/storage/blobs/authorize-access-azure-active-directory#microsoft-authentication-library-msal>
const AZURE_STORAGE_RESOURCE: &str = "https://storage.azure.com";

#[derive(Debug, Snafu)]
pub enum Error {
#[snafu(display("Error performing token request: {}", source))]
Expand Down Expand Up @@ -383,16 +392,16 @@ struct MsiTokenResponse {
/// This authentication type works in Azure VMs, App Service and Azure Functions applications, as well as the Azure Cloud Shell
/// <https://learn.microsoft.com/en-gb/azure/active-directory/managed-identities-azure-resources/how-to-use-vm-token#get-a-token-using-http>
#[derive(Debug)]
pub struct ImdsManagedIdentityOAuthProvider {
pub struct ImdsManagedIdentityProvider {
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I removed the OAuth part from the name to highlight that this isn't an OAuth flow

msi_endpoint: String,
client_id: Option<String>,
object_id: Option<String>,
msi_res_id: Option<String>,
client: Client,
}

impl ImdsManagedIdentityOAuthProvider {
/// Create a new [`ImdsManagedIdentityOAuthProvider`] for an azure backed store
impl ImdsManagedIdentityProvider {
/// Create a new [`ImdsManagedIdentityProvider`] for an azure backed store
pub fn new(
client_id: Option<String>,
object_id: Option<String>,
Expand All @@ -415,7 +424,7 @@ impl ImdsManagedIdentityOAuthProvider {
}

#[async_trait::async_trait]
impl TokenCredential for ImdsManagedIdentityOAuthProvider {
impl TokenCredential for ImdsManagedIdentityProvider {
/// Fetch a token
async fn fetch_token(
&self,
Expand All @@ -424,7 +433,7 @@ impl TokenCredential for ImdsManagedIdentityOAuthProvider {
) -> Result<TemporaryToken<String>> {
let mut query_items = vec![
("api-version", MSI_API_VERSION),
("resource", AZURE_STORAGE_SCOPE),
("resource", AZURE_STORAGE_RESOURCE),
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the entirety of the change

];

let mut identity = None;
Expand Down Expand Up @@ -709,7 +718,7 @@ mod tests {
))
});

let credential = ImdsManagedIdentityOAuthProvider::new(
let credential = ImdsManagedIdentityProvider::new(
Some("client_id".into()),
None,
None,
Expand Down
2 changes: 1 addition & 1 deletion object_store/src/azure/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1035,7 +1035,7 @@ impl MicrosoftAzureBuilder {
} else {
let client =
self.client_options.clone().with_allow_http(true).client()?;
let msi_credential = credential::ImdsManagedIdentityOAuthProvider::new(
let msi_credential = credential::ImdsManagedIdentityProvider::new(
self.client_id,
self.object_id,
self.msi_resource_id,
Expand Down