Feedback: Cloud Storage Authentication
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 48/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- azure
- Domain
- authentication, cloud, documentation
Research direction
Start with the cloud-storage-authentication.html page and review its Azure authentication options, especially the managed identity and workload identity sections. Update the guidance to reflect Azure best practices by deprecating managed identity support and recommending Workload Identity first, with simpler choices for new users.
Written by the indexing model from the issue text.
Description
Page: https://cockroachlabs.com/docs/v25.3/cloud-storage-authentication.html
What is the reason for your feedback?
[ ] Missing the information I need
[ ] Too complicated
[x] Out of date
[ ] Something is broken
[ ] Other
Additional details
Simplify and follow best practices on Azure by recommending Workload Identity
- The current Azure related documents have 4 options - credential file, env variable, managed identity and workload identity. To new azure users it can be overwhelming.
- Deprecate support for Managed Identity as Azure Managed Identity uses pod identity add on https://github.com/Azure/aad-pod-identity which is now deprecated by Microsoft on 10/24/2022, and the project archived in Sept. 2023. Specifically "Pod identity is EoL and does not get security updates anymore."
- Recommend Workload Identity. CockroachDB 25.2+ supports Workload Identity and Workload Identity + Federated IAM is viewed as best practice on azure. Could we recommend Workload Identity or list it as the first option?
Jira issue: DOC-15400
- Dominant language
- HTML
- Stars
- 212
- Forks
- 479
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Similar issues
-
area/frontend area/v2 kind/bug priority/needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
kubeflow/notebooks#1498 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
splunk/security_content#4334 ·
Maintainers usually reply within 1 day
-
Streamable HTTP client: a 401 or 403 with a JSON-RPC error body and no WWW-Authenticate loses its HTTP statusPossibly taken A pull request linked to this issue is open or already merged. Openbug P2 ready for work T-security T-transport
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
modelcontextprotocol/rust-sdk#1339 ·
Maintainers usually reply within 3 days
-
bug : find_key() compares kty against "ocy" instead of "oct", breaking kid-less HS256 verificationOpen
Difficulty 2/5 1-3 hours Newbie friendliness 77/100
OpenPrinting/cups#1756 ·
Maintainers usually reply within 1 day