influxdata/telegraf

SQL Server Input plugin - support for Azure Service Principals

Open

#11.126 geöffnet am 18. Mai 2022

Auf GitHub ansehen
 (3 Kommentare) (1 Reaktion) (0 zugewiesene Personen)Go (4.161 Forks)batch import
area/sqlserverfeature requesthelp wantedsize/l

Repository-Metriken

Stars
 (9.892 Stars)
PR-Merge-Metriken
 (Durchschn. Merge 2T 12h) (136 gemergte PRs in 30 T)

Beschreibung

Feature Request

Add support for Azure Service Principal logins to sqlserver input plugin.

Proposal:

Add the possibility to use Azure Service Principals as authentication method for Azure SQL databases.

Current behavior:

Currently DB internal logins and users and Azure Managed Identities are supported. The documentation does not say anything about support for Service Principals. The login with a Service Principal fails. The Go library used for access (https://github.com/denisenkom/go-mssqldb#azure-active-directory-authentication) says SPs are supported but the required fedauth parameter seems to be not understood or ignored by Telegraf.

Desired behavior:

Login for Azure Service Principals should be supported.

Use case:

Telegraf is not running in Azure but shall monitor a Azure SQL database where database internal logins are not allowed. In this case the use of a Service Principal is the only choice. Another use case would be Telegraf running in a Kubernetes Cluster where each VM would require the/a Managed Identity. For each of those machines a separate user would need to be created in the database (according to the docs) which is quite inconvenient.

Contributor Guide