GoogleCloudPlatform / GoogleCloudPlatform/cloud-trace-data-source-plugin
Authentication with default GCE Service account - trace in different project where Grafana deploted
- 主要言語
- Go
- スター
- 16
- フォーク
- 6
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
Hello,
We are using Google GMP (Google Cloud Managed Service for Prometheus) with several clusters , each one on different project.
Our infra resources like Prometheus UI & Grafana are deployed in one cluster but our trace sent to a different project (central) from all our gke projects (scoped project for several monitored projects)
Issue is when trying to authenticate Google trace plugin with default GCE Service account (after giving the SA the needed permissions) it fail.
So I also generate json file in the SA and used Google GWT file authentication and it worked. Than I switch back to default GCE Service account hit save&test and it worked (also deleted the generated json from the SA)
Seems when trying to authenticate with default GCE Service account it doesnt know where is the scope project.
Please advise
Thank you
Daniel
コントリビューションガイド
調査の方向性
デフォルトのGCEサービスアカウントを使用して、監視対象プロジェクトと中央プロジェクトにまたがるGoogle Cloud trace pluginの認証フローを再現し、動作するJSONファイル認証設定と比較します。スコーププロジェクトがどのように選択されるかを確認し、生成されたJSONファイルなしでSave & testが成功することを確認します。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- go, google-cloud
- 領域
- authentication, cloud
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 停滞
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 25/100