[ 
https://issues.apache.org/jira/browse/NIFI-16367?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

David Handermann updated NIFI-16367:
------------------------------------
    Fix Version/s: 2.13.0
       Resolution: Fixed
           Status: Resolved  (was: Patch Available)

> Add Azure Entra Database Password Provider
> ------------------------------------------
>
>                 Key: NIFI-16367
>                 URL: https://issues.apache.org/jira/browse/NIFI-16367
>             Project: Apache NiFi
>          Issue Type: New Feature
>            Reporter: Pierre Villard
>            Assignee: Pierre Villard
>            Priority: Major
>             Fix For: 2.13.0
>
>          Time Spent: 40m
>  Remaining Estimate: 0h
>
> NiFi DBCPConnectionPool supports DatabasePasswordProvider controller services 
> for obtaining short-lived database credentials, with existing implementations 
> for AWS RDS IAM and Google Cloud SQL IAM authentication.
> The goal is to add an AzureEntraDatabasePasswordProvider controller service 
> to the Azure extension bundle. The provider should:
>  * Use a configured AzureCredentialsService to obtain Azure credentials.
>  * Request a Microsoft Entra access token for the public Azure OSS RDBMS 
> scope:
> [https://ossrdbms-aad.database.windows.net/.default]
>  * Return the access token as the database password when DBCP creates a 
> physical JDBC connection.
>  * Support Azure Database for PostgreSQL Flexible Server and Azure Database 
> for MySQL Flexible Server.
>  * Resolve the current TokenCredential for each password request so that 
> credential-service reconfiguration is honored.
>  * Reject null, blank, or expired tokens using sanitized error messages that 
> do not expose credentials or upstream exception details.
>  * Provide configuration verification that exercises token acquisition using 
> the OSS RDBMS scope.
>  * Include controller-service registration, focused unit tests, and operator 
> documentation for PostgreSQL and MySQL JDBC configuration.
> This approach uses the existing AzureCredentialsService abstraction, so it 
> supports the available Azure credential strategies, including workload 
> identity federation, without coupling the database password provider to a 
> particular external identity issuer.
> Azure SQL Database is outside the scope because its JDBC driver requires an 
> access-token or driver-native authentication configuration rather than the 
> DatabasePasswordProvider password mechanism.
> Follow-up improvements will be made to support SQL Server which requires a 
> slightly different handling.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to