GoogleCloudPlatform / GoogleCloudPlatform/cloud-trace-data-source-plugin

Authentication with default GCE Service account - trace in different project where Grafana deploted

オープン
#16 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Go
スター
16
フォーク
6
PR マージ指標
30日以内にマージされた PR はありません

説明

Hello,

We are using Google GMP (Google Cloud Managed Service for Prometheus) with several clusters , each one on different project.
Our infra resources like Prometheus UI & Grafana are deployed in one cluster but our trace sent to a different project (central) from all our gke projects (scoped project for several monitored projects)

Issue is when trying to authenticate Google trace plugin with default GCE Service account (after giving the SA the needed permissions) it fail.
So I also generate json file in the SA and used Google GWT file authentication and it worked. Than I switch back to default GCE Service account hit save&test and it worked (also deleted the generated json from the SA)

Seems when trying to authenticate with default GCE Service account it doesnt know where is the scope project.

Please advise
Thank you
Daniel

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

デフォルトのGCEサービスアカウントを使用して、監視対象プロジェクトと中央プロジェクトにまたがるGoogle Cloud trace pluginの認証フローを再現し、動作するJSONファイル認証設定と比較します。スコーププロジェクトがどのように選択されるかを確認し、生成されたJSONファイルなしでSave & testが成功することを確認します。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
go, google-cloud
領域
authentication, cloud
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。