GoogleCloudPlatform / GoogleCloudPlatform/cloud-trace-data-source-plugin
Authentication with default GCE Service account - trace in different project where Grafana deploted
- Vorherrschende Sprache
- Go
- Sterne
- 16
- Forks
- 6
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
Hello,
We are using Google GMP (Google Cloud Managed Service for Prometheus) with several clusters , each one on different project.
Our infra resources like Prometheus UI & Grafana are deployed in one cluster but our trace sent to a different project (central) from all our gke projects (scoped project for several monitored projects)
Issue is when trying to authenticate Google trace plugin with default GCE Service account (after giving the SA the needed permissions) it fail.
So I also generate json file in the SA and used Google GWT file authentication and it worked. Than I switch back to default GCE Service account hit save&test and it worked (also deleted the generated json from the SA)
Seems when trying to authenticate with default GCE Service account it doesnt know where is the scope project.
Please advise
Thank you
Daniel
Beitragsleitfaden
Rechercherichtung
Reproduziere den Authentifizierungsablauf des Google Cloud trace plugin mit dem standardmäßigen GCE-Dienstkonto über die überwachten und zentralen Projekte hinweg und vergleiche ihn anschließend mit der funktionierenden JSON-Datei-Authentifizierungskonfiguration. Prüfe, wie das Scope-Projekt ausgewählt wird, und bestätige, dass Save & test ohne die generierte JSON-Datei erfolgreich ist.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- go, google-cloud
- Bereich
- authentication, cloud
- Issue-Typ
- Bug
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Veraltet
- Klarheit
- Muss geklärt werden
- Anfängerfreundlichkeit
- 25/100