Azure / AKS

Azure Kubernetes Service
https://azure.github.io/AKS/
1.95k stars 305 forks source link

support for Kubernetes Event-driven Autoscaling workload identity #3514

Open JonasCordsen opened 1 year ago

JonasCordsen commented 1 year ago

Describe the solution you'd like it would be great to support use of workload identity (With a managed identity) in KEDA in order to handle the secrets that is used by trigger

IE guide form keda https://keda.sh/docs/2.9/authentication-providers/azure-key-vault/

Describe alternatives you've considered I have considered to setup KEDA by hand, but the support for this would make it a lot easier

EppO commented 1 year ago

KEDA 2.10 add-on deployed within AKS 1.26 supports workload identity but it requires extra setup

I'm honestly not sure about overriding the service account manifest with the Managed Id's client ID, not sure it's future proof in terms of AKS upgrades. I would be nice if the AKS add-on provisioning was taking care about the Managed Id provisioning + federated credentials for us, or at least having CLI option to give the client ID ourselves, or even better support for both solutions.

kratkyzobak commented 1 year ago

azure.workload.identity/client-id annotation should not be required to modify. You should specify clientId in podIdentity.identityId for each specific TriggerAuthentication resource.

EppO commented 1 year ago

that's awesome! no need to do this ugly hack then, thanks for the tip!! I edited my original comment for the updated recipe

microsoft-github-policy-service[bot] commented 7 months ago

Action required from @Azure/aks-pm

microsoft-github-policy-service[bot] commented 7 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 6 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 6 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 5 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 5 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 4 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 4 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 3 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 3 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 2 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 2 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 1 month ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 1 month ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 3 weeks ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 1 week ago

Issue needing attention of @Azure/aks-leads