Skip to content

Commit a03db0d

Browse files
Main repository azure managed identity support (opensearch-project#12559)
* Added support for Azure Managed Identity in repository-azure Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * Refactor tokenCredentialType as an enum when constructing AzureStorageSetting Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * fixed indentation Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * fixed syntax Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * removed unused imports Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * applied changes after running :plugins:repository-azure:spotlessApply Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * added transitive dependencies Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * changed getStorageBlobEndpoint to private and using asm version from buildSrc/version.properties Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * run spotlessApply Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * update shas for asm 9.7 Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * use version.jna for jna-platform Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * change string 'core.windows.net' to be a constant, use uri.create instead of new uri, and added a few comments for clarity Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * added one more comment line Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * refactor TokenCredentialType to not have NOT_APPLICABLE Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * refactored code based on recommended changes from Andriy Redko Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * added a jvm security policy for reactor-core jar Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * fixed failing forbidden api fix Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * removed the jvm security policy for reactor-core which was added Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * refactored code, such that storage endpoint is not evaluated at compiled time Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * refactored token credential types checks Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * changed clientlogger in azurestoragesetting to 'AzureStorageService' Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * added a nullable argument to getStorageEndpoint Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> * Fix IdentityClient security permissions, get rid of connection string (since it is not applicable to managed identity configuration) Signed-off-by: Andriy Redko <andriy.redko@aiven.io> * Responded to feedback from Andrew Ross, fixed typo, spelling, added shudownNow() and Thread.currentThread().interrupt() Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> --------- Signed-off-by: Chengwu Shi <chengwu.shi@netapp.com> Signed-off-by: Andriy Redko <andriy.redko@aiven.io> Co-authored-by: Andriy Redko <andriy.redko@aiven.io>
1 parent f8baa4a commit a03db0d

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

42 files changed

+2028
-155
lines changed

CHANGELOG.md

+1
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
55

66
## [Unreleased 2.x]
77
### Added
8+
- Add support for Azure Managed Identity in repository-azure ([#12423](https://github.com/opensearch-project/OpenSearch/issues/12423))
89
- Add useCompoundFile index setting ([#13478](https://github.com/opensearch-project/OpenSearch/pull/13478))
910
- Make outbound side of transport protocol dependent ([#13293](https://github.com/opensearch-project/OpenSearch/pull/13293))
1011

buildSrc/src/main/java/org/opensearch/gradle/precommit/LicenseAnalyzer.java

+1-1
Original file line numberDiff line numberDiff line change
@@ -145,7 +145,7 @@ public class LicenseAnalyzer {
145145
+ "AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\n"
146146
+ "LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\n"
147147
+ "OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\n"
148-
+ "SOFTWARE\\.\n").replaceAll("\\s+", "\\\\s*"),
148+
+ "SOFTWARE\\.?\n").replaceAll("\\s+", "\\\\s*"),
149149
Pattern.DOTALL
150150
)
151151
),

plugins/repository-azure/build.gradle

+85-1
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,21 @@ dependencies {
5656
api "io.netty:netty-transport-native-unix-common:${versions.netty}"
5757
implementation project(':modules:transport-netty4')
5858
api 'com.azure:azure-storage-blob:12.23.0'
59+
api 'com.azure:azure-identity:1.11.4'
60+
// Start of transitive dependencies for azure-identity
61+
api 'com.microsoft.azure:msal4j-persistence-extension:1.2.0'
62+
api "net.java.dev.jna:jna-platform:${versions.jna}"
63+
api 'com.microsoft.azure:msal4j:1.14.3'
64+
api 'com.nimbusds:oauth2-oidc-sdk:11.9.1'
65+
api 'com.nimbusds:nimbus-jose-jwt:9.37.3'
66+
api 'com.nimbusds:content-type:2.3'
67+
api 'com.nimbusds:lang-tag:1.7'
68+
// Both msal4j:1.14.3 and oauth2-oidc-sdk:11.9.1 has compile dependency on different versions of json-smart,
69+
// selected the higher version which is 2.5.0
70+
api 'net.minidev:json-smart:2.5.0'
71+
api 'net.minidev:accessors-smart:2.5.0'
72+
api "org.ow2.asm:asm:${versions.asm}"
73+
// End of transitive dependencies for azure-identity
5974
api "io.projectreactor.netty:reactor-netty-core:${versions.reactor_netty}"
6075
api "io.projectreactor.netty:reactor-netty-http:${versions.reactor_netty}"
6176
api "org.slf4j:slf4j-api:${versions.slf4j}"
@@ -180,7 +195,76 @@ thirdPartyAudit {
180195
'io.micrometer.observation.ObservationHandler',
181196
'io.micrometer.observation.ObservationRegistry',
182197
'io.micrometer.observation.ObservationRegistry$ObservationConfig',
183-
'io.micrometer.tracing.handler.DefaultTracingObservationHandler'
198+
'io.micrometer.tracing.handler.DefaultTracingObservationHandler',
199+
// Start of the list of classes from the optional compile/provided dependencies used in "com.nimbusds:oauth2-oidc-sdk".
200+
'com.google.crypto.tink.subtle.Ed25519Sign',
201+
'com.google.crypto.tink.subtle.Ed25519Sign$KeyPair',
202+
'com.google.crypto.tink.subtle.Ed25519Verify',
203+
'com.google.crypto.tink.subtle.X25519',
204+
'com.google.crypto.tink.subtle.XChaCha20Poly1305',
205+
'jakarta.servlet.ServletRequest',
206+
'jakarta.servlet.http.HttpServletRequest',
207+
'jakarta.servlet.http.HttpServletResponse',
208+
'javax.servlet.ServletRequest',
209+
'javax.servlet.http.HttpServletRequest',
210+
'javax.servlet.http.HttpServletResponse',
211+
// net.shibboleth.utilities:java-support.* is declared as optional in the plugin `bnd-maven-plugin` used in "com.nimbusds:oauth2-oidc-sdk"
212+
// Worth nothing that, the latest dependency "net.shibboleth.utilities:java-support:8.0.0" has many vulnerabilities.
213+
// Hence ignored.
214+
'net.shibboleth.utilities.java.support.xml.SerializeSupport',
215+
'org.bouncycastle.asn1.pkcs.PrivateKeyInfo',
216+
'org.bouncycastle.asn1.x509.AlgorithmIdentifier',
217+
'org.bouncycastle.asn1.x509.SubjectPublicKeyInfo',
218+
'org.bouncycastle.cert.X509CertificateHolder',
219+
'org.bouncycastle.cert.jcajce.JcaX509CertificateHolder',
220+
'org.bouncycastle.cert.jcajce.JcaX509v3CertificateBuilder',
221+
'org.bouncycastle.crypto.InvalidCipherTextException',
222+
'org.bouncycastle.crypto.engines.AESEngine',
223+
'org.bouncycastle.crypto.modes.GCMBlockCipher',
224+
'org.bouncycastle.jcajce.provider.BouncyCastleFipsProvider',
225+
'org.bouncycastle.jce.provider.BouncyCastleProvider',
226+
'org.bouncycastle.openssl.PEMKeyPair',
227+
'org.bouncycastle.openssl.PEMParser',
228+
'org.bouncycastle.openssl.jcajce.JcaPEMKeyConverter',
229+
'org.bouncycastle.operator.jcajce.JcaContentSignerBuilder',
230+
'org.cryptomator.siv.SivMode',
231+
'org.opensaml.core.config.InitializationException',
232+
'org.opensaml.core.config.InitializationService',
233+
'org.opensaml.core.xml.XMLObject',
234+
'org.opensaml.core.xml.XMLObjectBuilder',
235+
'org.opensaml.core.xml.XMLObjectBuilderFactory',
236+
'org.opensaml.core.xml.config.XMLObjectProviderRegistrySupport',
237+
'org.opensaml.core.xml.io.Marshaller',
238+
'org.opensaml.core.xml.io.MarshallerFactory',
239+
'org.opensaml.core.xml.io.MarshallingException',
240+
'org.opensaml.core.xml.io.Unmarshaller',
241+
'org.opensaml.core.xml.io.UnmarshallerFactory',
242+
'org.opensaml.core.xml.schema.XSString',
243+
'org.opensaml.core.xml.schema.impl.XSStringBuilder',
244+
'org.opensaml.saml.saml2.core.Assertion',
245+
'org.opensaml.saml.saml2.core.Attribute',
246+
'org.opensaml.saml.saml2.core.AttributeStatement',
247+
'org.opensaml.saml.saml2.core.AttributeValue',
248+
'org.opensaml.saml.saml2.core.Audience',
249+
'org.opensaml.saml.saml2.core.AudienceRestriction',
250+
'org.opensaml.saml.saml2.core.AuthnContext',
251+
'org.opensaml.saml.saml2.core.AuthnContextClassRef',
252+
'org.opensaml.saml.saml2.core.AuthnStatement',
253+
'org.opensaml.saml.saml2.core.Conditions',
254+
'org.opensaml.saml.saml2.core.Issuer',
255+
'org.opensaml.saml.saml2.core.NameID',
256+
'org.opensaml.saml.saml2.core.Subject',
257+
'org.opensaml.saml.saml2.core.SubjectConfirmation',
258+
'org.opensaml.saml.saml2.core.SubjectConfirmationData',
259+
'org.opensaml.saml.security.impl.SAMLSignatureProfileValidator',
260+
'org.opensaml.security.credential.BasicCredential',
261+
'org.opensaml.security.credential.Credential',
262+
'org.opensaml.security.credential.UsageType',
263+
'org.opensaml.xmlsec.signature.Signature',
264+
'org.opensaml.xmlsec.signature.support.SignatureException',
265+
'org.opensaml.xmlsec.signature.support.SignatureValidator',
266+
'org.opensaml.xmlsec.signature.support.Signer',
267+
// End of the list of classes from the optional compile/provided dependencies used in "com.nimbusds:oauth2-oidc-sdk".
184268
)
185269

186270
ignoreViolations(
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
aca011492dfe9c26f4e0659028a4fe0970829dd8
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,202 @@
1+
2+
Apache License
3+
Version 2.0, January 2004
4+
http://www.apache.org/licenses/
5+
6+
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
7+
8+
1. Definitions.
9+
10+
"License" shall mean the terms and conditions for use, reproduction,
11+
and distribution as defined by Sections 1 through 9 of this document.
12+
13+
"Licensor" shall mean the copyright owner or entity authorized by
14+
the copyright owner that is granting the License.
15+
16+
"Legal Entity" shall mean the union of the acting entity and all
17+
other entities that control, are controlled by, or are under common
18+
control with that entity. For the purposes of this definition,
19+
"control" means (i) the power, direct or indirect, to cause the
20+
direction or management of such entity, whether by contract or
21+
otherwise, or (ii) ownership of fifty percent (50%) or more of the
22+
outstanding shares, or (iii) beneficial ownership of such entity.
23+
24+
"You" (or "Your") shall mean an individual or Legal Entity
25+
exercising permissions granted by this License.
26+
27+
"Source" form shall mean the preferred form for making modifications,
28+
including but not limited to software source code, documentation
29+
source, and configuration files.
30+
31+
"Object" form shall mean any form resulting from mechanical
32+
transformation or translation of a Source form, including but
33+
not limited to compiled object code, generated documentation,
34+
and conversions to other media types.
35+
36+
"Work" shall mean the work of authorship, whether in Source or
37+
Object form, made available under the License, as indicated by a
38+
copyright notice that is included in or attached to the work
39+
(an example is provided in the Appendix below).
40+
41+
"Derivative Works" shall mean any work, whether in Source or Object
42+
form, that is based on (or derived from) the Work and for which the
43+
editorial revisions, annotations, elaborations, or other modifications
44+
represent, as a whole, an original work of authorship. For the purposes
45+
of this License, Derivative Works shall not include works that remain
46+
separable from, or merely link (or bind by name) to the interfaces of,
47+
the Work and Derivative Works thereof.
48+
49+
"Contribution" shall mean any work of authorship, including
50+
the original version of the Work and any modifications or additions
51+
to that Work or Derivative Works thereof, that is intentionally
52+
submitted to Licensor for inclusion in the Work by the copyright owner
53+
or by an individual or Legal Entity authorized to submit on behalf of
54+
the copyright owner. For the purposes of this definition, "submitted"
55+
means any form of electronic, verbal, or written communication sent
56+
to the Licensor or its representatives, including but not limited to
57+
communication on electronic mailing lists, source code control systems,
58+
and issue tracking systems that are managed by, or on behalf of, the
59+
Licensor for the purpose of discussing and improving the Work, but
60+
excluding communication that is conspicuously marked or otherwise
61+
designated in writing by the copyright owner as "Not a Contribution."
62+
63+
"Contributor" shall mean Licensor and any individual or Legal Entity
64+
on behalf of whom a Contribution has been received by Licensor and
65+
subsequently incorporated within the Work.
66+
67+
2. Grant of Copyright License. Subject to the terms and conditions of
68+
this License, each Contributor hereby grants to You a perpetual,
69+
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
70+
copyright license to reproduce, prepare Derivative Works of,
71+
publicly display, publicly perform, sublicense, and distribute the
72+
Work and such Derivative Works in Source or Object form.
73+
74+
3. Grant of Patent License. Subject to the terms and conditions of
75+
this License, each Contributor hereby grants to You a perpetual,
76+
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
77+
(except as stated in this section) patent license to make, have made,
78+
use, offer to sell, sell, import, and otherwise transfer the Work,
79+
where such license applies only to those patent claims licensable
80+
by such Contributor that are necessarily infringed by their
81+
Contribution(s) alone or by combination of their Contribution(s)
82+
with the Work to which such Contribution(s) was submitted. If You
83+
institute patent litigation against any entity (including a
84+
cross-claim or counterclaim in a lawsuit) alleging that the Work
85+
or a Contribution incorporated within the Work constitutes direct
86+
or contributory patent infringement, then any patent licenses
87+
granted to You under this License for that Work shall terminate
88+
as of the date such litigation is filed.
89+
90+
4. Redistribution. You may reproduce and distribute copies of the
91+
Work or Derivative Works thereof in any medium, with or without
92+
modifications, and in Source or Object form, provided that You
93+
meet the following conditions:
94+
95+
(a) You must give any other recipients of the Work or
96+
Derivative Works a copy of this License; and
97+
98+
(b) You must cause any modified files to carry prominent notices
99+
stating that You changed the files; and
100+
101+
(c) You must retain, in the Source form of any Derivative Works
102+
that You distribute, all copyright, patent, trademark, and
103+
attribution notices from the Source form of the Work,
104+
excluding those notices that do not pertain to any part of
105+
the Derivative Works; and
106+
107+
(d) If the Work includes a "NOTICE" text file as part of its
108+
distribution, then any Derivative Works that You distribute must
109+
include a readable copy of the attribution notices contained
110+
within such NOTICE file, excluding those notices that do not
111+
pertain to any part of the Derivative Works, in at least one
112+
of the following places: within a NOTICE text file distributed
113+
as part of the Derivative Works; within the Source form or
114+
documentation, if provided along with the Derivative Works; or,
115+
within a display generated by the Derivative Works, if and
116+
wherever such third-party notices normally appear. The contents
117+
of the NOTICE file are for informational purposes only and
118+
do not modify the License. You may add Your own attribution
119+
notices within Derivative Works that You distribute, alongside
120+
or as an addendum to the NOTICE text from the Work, provided
121+
that such additional attribution notices cannot be construed
122+
as modifying the License.
123+
124+
You may add Your own copyright statement to Your modifications and
125+
may provide additional or different license terms and conditions
126+
for use, reproduction, or distribution of Your modifications, or
127+
for any such Derivative Works as a whole, provided Your use,
128+
reproduction, and distribution of the Work otherwise complies with
129+
the conditions stated in this License.
130+
131+
5. Submission of Contributions. Unless You explicitly state otherwise,
132+
any Contribution intentionally submitted for inclusion in the Work
133+
by You to the Licensor shall be under the terms and conditions of
134+
this License, without any additional terms or conditions.
135+
Notwithstanding the above, nothing herein shall supersede or modify
136+
the terms of any separate license agreement you may have executed
137+
with Licensor regarding such Contributions.
138+
139+
6. Trademarks. This License does not grant permission to use the trade
140+
names, trademarks, service marks, or product names of the Licensor,
141+
except as required for reasonable and customary use in describing the
142+
origin of the Work and reproducing the content of the NOTICE file.
143+
144+
7. Disclaimer of Warranty. Unless required by applicable law or
145+
agreed to in writing, Licensor provides the Work (and each
146+
Contributor provides its Contributions) on an "AS IS" BASIS,
147+
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
148+
implied, including, without limitation, any warranties or conditions
149+
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
150+
PARTICULAR PURPOSE. You are solely responsible for determining the
151+
appropriateness of using or redistributing the Work and assume any
152+
risks associated with Your exercise of permissions under this License.
153+
154+
8. Limitation of Liability. In no event and under no legal theory,
155+
whether in tort (including negligence), contract, or otherwise,
156+
unless required by applicable law (such as deliberate and grossly
157+
negligent acts) or agreed to in writing, shall any Contributor be
158+
liable to You for damages, including any direct, indirect, special,
159+
incidental, or consequential damages of any character arising as a
160+
result of this License or out of the use or inability to use the
161+
Work (including but not limited to damages for loss of goodwill,
162+
work stoppage, computer failure or malfunction, or any and all
163+
other commercial damages or losses), even if such Contributor
164+
has been advised of the possibility of such damages.
165+
166+
9. Accepting Warranty or Additional Liability. While redistributing
167+
the Work or Derivative Works thereof, You may choose to offer,
168+
and charge a fee for, acceptance of support, warranty, indemnity,
169+
or other liability obligations and/or rights consistent with this
170+
License. However, in accepting such obligations, You may act only
171+
on Your own behalf and on Your sole responsibility, not on behalf
172+
of any other Contributor, and only if You agree to indemnify,
173+
defend, and hold each Contributor harmless for any liability
174+
incurred by, or claims asserted against, such Contributor by reason
175+
of your accepting any such warranty or additional liability.
176+
177+
END OF TERMS AND CONDITIONS
178+
179+
APPENDIX: How to apply the Apache License to your work.
180+
181+
To apply the Apache License to your work, attach the following
182+
boilerplate notice, with the fields enclosed by brackets "[]"
183+
replaced with your own identifying information. (Don't include
184+
the brackets!) The text should be enclosed in the appropriate
185+
comment syntax for the file format. We also recommend that a
186+
file or class name and description of purpose be included on the
187+
same "printed page" as the copyright notice for easier
188+
identification within third-party archives.
189+
190+
Copyright [yyyy] [name of copyright owner]
191+
192+
Licensed under the Apache License, Version 2.0 (the "License");
193+
you may not use this file except in compliance with the License.
194+
You may obtain a copy of the License at
195+
196+
http://www.apache.org/licenses/LICENSE-2.0
197+
198+
Unless required by applicable law or agreed to in writing, software
199+
distributed under the License is distributed on an "AS IS" BASIS,
200+
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
201+
See the License for the specific language governing permissions and
202+
limitations under the License.

plugins/repository-azure/licenses/accessors-smart-NOTICE.txt

Whitespace-only changes.
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
073d7b3086e14beb604ced229c302feff6449723
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
ASM: a very small and fast Java bytecode manipulation framework
2+
Copyright (c) 2000-2011 INRIA, France Telecom
3+
All rights reserved.
4+
5+
Redistribution and use in source and binary forms, with or without
6+
modification, are permitted provided that the following conditions
7+
are met:
8+
1. Redistributions of source code must retain the above copyright
9+
notice, this list of conditions and the following disclaimer.
10+
2. Redistributions in binary form must reproduce the above copyright
11+
notice, this list of conditions and the following disclaimer in the
12+
documentation and/or other materials provided with the distribution.
13+
3. Neither the name of the copyright holders nor the names of its
14+
contributors may be used to endorse or promote products derived from
15+
this software without specific prior written permission.
16+
17+
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
18+
AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
19+
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
20+
ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
21+
LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
22+
CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
23+
SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
24+
INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
25+
CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
26+
ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
27+
THE POSSIBILITY OF SUCH DAMAGE.

plugins/repository-azure/licenses/asm-NOTICE.txt

Whitespace-only changes.
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
59b5ce48888f638b80d85ef5aa0e22a265d3dc89
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
e3aa0be212d7a42839a8f3f506f5b990bcce0222

0 commit comments

Comments
 (0)