diff --git a/docs/src/main/asciidoc/spring-cloud-vault.adoc b/docs/src/main/asciidoc/spring-cloud-vault.adoc index 6e9ca845..c7ec148b 100644 --- a/docs/src/main/asciidoc/spring-cloud-vault.adoc +++ b/docs/src/main/asciidoc/spring-cloud-vault.adoc @@ -369,6 +369,50 @@ as the authentication implementation uses AWS SDK types for credentials and requ See also: https://www.vaultproject.io/docs/auth/aws.html[Vault Documentation: Using the aws auth backend] +[[vault.config.authentication.azuremsi]] +=== Azure MSI authentication + +The https://www.vaultproject.io/docs/auth/azure.html[azure] +auth backend provides a secure introduction mechanism +for Azure VM instances, allowing automated retrieval of a Vault +token. Unlike most Vault authentication backends, this backend +does not require first-deploying, or provisioning security-sensitive +credentials (tokens, username/password, client certificates, etc.). +Instead, it treats Azure as a Trusted Third Party and uses the +managed service identity and instance metadata information that can be +bound to a VM instance. + +.bootstrap.yml with required Azure Authentication properties +==== +[source,yaml] +---- +spring.cloud.vault: + authentication: AZURE_MSI + azure-msi: + role: my-dev-role +---- +==== + +.bootstrap.yml with all Azure Authentication properties +==== +[source,yaml] +---- +spring.cloud.vault: + authentication: AZURE_MSI + azure-msi: + role: my-dev-role + azure-path: aws +---- +==== + +* `role` sets the name of the role against which the login is being attempted. +* `azure-path` sets the path of the Azure mount to use + +Azure MSI authentication fetches environmental details about the virtual machine +(subscription Id, resource group, VM name) from the instance metadata service. + +See also: https://www.vaultproject.io/docs/auth/azure.html[Vault Documentation: Using the azure auth backend] + [[vault.config.authentication.clientcert]] === TLS certificate authentication diff --git a/spring-cloud-vault-config/src/main/java/org/springframework/cloud/vault/config/ClientAuthenticationFactory.java b/spring-cloud-vault-config/src/main/java/org/springframework/cloud/vault/config/ClientAuthenticationFactory.java index 81e5e2be..44a2d57e 100644 --- a/spring-cloud-vault-config/src/main/java/org/springframework/cloud/vault/config/ClientAuthenticationFactory.java +++ b/spring-cloud-vault-config/src/main/java/org/springframework/cloud/vault/config/ClientAuthenticationFactory.java @@ -26,6 +26,7 @@ import lombok.RequiredArgsConstructor; import org.springframework.beans.BeanUtils; import org.springframework.cloud.vault.config.VaultProperties.AppRoleProperties; import org.springframework.cloud.vault.config.VaultProperties.AwsIamProperties; +import org.springframework.cloud.vault.config.VaultProperties.AzureMsiProperties; import org.springframework.util.Assert; import org.springframework.util.ClassUtils; import org.springframework.util.StringUtils; @@ -80,6 +81,9 @@ class ClientAuthenticationFactory { case AWS_IAM: return awsIamAuthentication(vaultProperties); + case AZURE_MSI: + return azureMsiAuthentication(vaultProperties); + case CUBBYHOLE: return cubbyholeAuthentication(); @@ -250,6 +254,19 @@ class ClientAuthenticationFactory { return new AwsIamAuthentication(options, restOperations); } + private ClientAuthentication azureMsiAuthentication(VaultProperties vaultProperties) { + + AzureMsiProperties azureMsi = vaultProperties.getAzureMsi(); + + Assert.hasText(azureMsi.getRole(), + "Azure role (spring.cloud.vault.azure-msi.role) must not be empty"); + + AzureMsiAuthenticationOptions options = AzureMsiAuthenticationOptions.builder() + .role(azureMsi.getRole()).build(); + + return new AzureMsiAuthentication(options, restOperations); + } + private ClientAuthentication cubbyholeAuthentication() { Assert.hasText(vaultProperties.getToken(), diff --git a/spring-cloud-vault-config/src/main/java/org/springframework/cloud/vault/config/VaultProperties.java b/spring-cloud-vault-config/src/main/java/org/springframework/cloud/vault/config/VaultProperties.java index 26185242..57406333 100644 --- a/spring-cloud-vault-config/src/main/java/org/springframework/cloud/vault/config/VaultProperties.java +++ b/spring-cloud-vault-config/src/main/java/org/springframework/cloud/vault/config/VaultProperties.java @@ -98,6 +98,8 @@ public class VaultProperties implements EnvironmentAware { private AwsIamProperties awsIam = new AwsIamProperties(); + private AzureMsiProperties azureMsi = new AzureMsiProperties(); + private KubernetesProperties kubernetes = new KubernetesProperties(); private Ssl ssl = new Ssl(); @@ -248,6 +250,21 @@ public class VaultProperties implements EnvironmentAware { private String serverName; } + @Data + public static class AzureMsiProperties { + + /** + * Mount path of the Azure MSI authentication backend. + */ + @NotEmpty + private String azurePath = "azure"; + + /** + * Name of the role. + */ + private String role = ""; + } + @Data public static class KubernetesProperties { @@ -328,6 +345,6 @@ public class VaultProperties implements EnvironmentAware { } public enum AuthenticationMethod { - TOKEN, APPID, APPROLE, AWS_EC2, AWS_IAM, CERT, CUBBYHOLE, KUBERNETES + TOKEN, APPID, APPROLE, AWS_EC2, AWS_IAM, AZURE_MSI, CERT, CUBBYHOLE, KUBERNETES } }