Add Azure spiffe oidc auth profile #3797
Open
+141
−16
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Signed-off-by: Jonathan Collinge [email protected]
Description
Adds a new Azure SPIFFE OIDC authentication profile. This allows Azure users to create federated credentials for Azure AD (EntraID) Applications that directly target the SPIFFE ID of the Dapr App. This allows users to natively integrate their Dapr SPIFFE IDs into their IAM and achieve cross cloud federation without needing to host the application on the same provider and leverage the native IAM providers. For instance Dapr deployment running on AWS could access resources on Azure without needing to use secrets via a federated app credential.
This PR builds on
Steps to reproduce
Helper to create jwt.key and jwks.json
Issue reference
We strive to have all PR being opened based on an issue, where the problem or feature have been discussed prior to implementation.
Please reference the issue this PR will close: #[issue number]
Checklist
Please make sure you've completed the relevant tasks for this PR, out of the following list: