From d1a7ae2b7d6293096892d5e00e6b3a6e6540c65c Mon Sep 17 00:00:00 2001 From: katarzyna_koltun Date: Wed, 30 Sep 2026 16:39:16 +0200 Subject: [PATCH 1/4] PMP - Added missing roles to K8s CI/CD --- .../configuration/pmp-configure-k8s.md | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/content/en/docs/private-platform/configuration/pmp-configure-k8s.md b/content/en/docs/private-platform/configuration/pmp-configure-k8s.md index cc1224616c8..085a686ad8b 100644 --- a/content/en/docs/private-platform/configuration/pmp-configure-k8s.md +++ b/content/en/docs/private-platform/configuration/pmp-configure-k8s.md @@ -140,7 +140,11 @@ The settings in this section configure the images. 1. Create a managed identity in the Azure portal 2. Configure federated credentials for the Kubernetes service account. - 3. In the **Managed Identity** section, add a role assignment with the **Storage Blob Data Reader** role scoped to the storage account. + 3. In the **Managed Identity** section, add a role assignment with the following roles scoped to the storage account: + + * **Storage Blob Data Contributor** - This role permits Private Mendix Platform to read and write MDA blobs (upload deployment packages, read package metadata and SBOM contents). Private Mendix Platform requires the role to upload deployment packages. Read only access is not sufficient. + * **Storage Blob Delegator** - This role permits Private Mendix Platform to delegate access to blobs by generating presigned (user delegation SAS) download URLs. It grants no data access of its own. MDA downloads may fail even when a blob data role is correctly assigned if Delegator is missing. + 4. Add an annotation to the service account, as in the following example: ```text @@ -209,7 +213,11 @@ The settings in this section configure the storage for build output artifacts. * **Mda Storage Option** - Configure where to store the build output artifacts. The supported values are S3 Bucket and Azure Blob. This option requires the Azure Workload identity authentication. The default service account is used in the build pod for uploading the build artifacts. To configure the managed identity and service account, perform the following steps: 1. Create or reuse a managed identity on Azure portal, and configure federated credentials for the Kubernetes service account. - 2. In the **Managed Identity**, add a role assignment with the **Storage Blob Data Contributor** role scoped to the storage account. + 2. In the **Managed Identity**, add a role assignment with the following roles scoped to the storage account: + + * **Storage Blob Data Contributor** - This role permits Private Mendix Platform to read and write MDA blobs (upload deployment packages, read package metadata and SBOM contents). Private Mendix Platform requires the role to upload deployment packages. Read only access is not sufficient. + * **Storage Blob Delegator** - This role permits Private Mendix Platform to delegate access to blobs by generating presigned (user delegation SAS) download URLs. It grants no data access of its own. MDA downloads may fail even when a blob data role is correctly assigned if Delegator is missing. + 3. Add the correct annotation to the Service Account for build pod and PMP. 4. Add annotations for the build pod and Private Mendix Platform to the service account, as in the following example: @@ -222,7 +230,7 @@ The settings in this section configure the storage for build output artifacts. azure.workload.identity/client-id: {client-id-build} ``` - 5. Add a role assignment with the Storage Blob Data Reader role scoped to the storage account to ensure that Private Mendix Platform can access the build metadata after the build is completed. If you are already using Azure Blob Storage (Azure managed identity authentication) for Private Mendix Platform, you can reuse the managed identity which was created by the Mendix Operator. + 5. Add a role assignment with the Storage Blob Data Contributor role scoped to the storage account to ensure that Private Mendix Platform can access the build metadata after the build is completed. If you are already using Azure Blob Storage (Azure managed identity authentication) for Private Mendix Platform, you can reuse the managed identity which was created by the Mendix Operator. ```text kind: ServiceAccount From a3f4678147582318208723a7a52477313901b95b Mon Sep 17 00:00:00 2001 From: katarzyna_koltun Date: Wed, 30 Sep 2026 17:06:28 +0200 Subject: [PATCH 2/4] sme review --- .../configuration/pmp-configure-k8s.md | 33 ++++++++++--------- 1 file changed, 18 insertions(+), 15 deletions(-) diff --git a/content/en/docs/private-platform/configuration/pmp-configure-k8s.md b/content/en/docs/private-platform/configuration/pmp-configure-k8s.md index 085a686ad8b..a40b1ab0a43 100644 --- a/content/en/docs/private-platform/configuration/pmp-configure-k8s.md +++ b/content/en/docs/private-platform/configuration/pmp-configure-k8s.md @@ -140,10 +140,9 @@ The settings in this section configure the images. 1. Create a managed identity in the Azure portal 2. Configure federated credentials for the Kubernetes service account. - 3. In the **Managed Identity** section, add a role assignment with the following roles scoped to the storage account: + 3. In the **Managed Identity** section, add a role assignment with the following role scoped to the storage account: - * **Storage Blob Data Contributor** - This role permits Private Mendix Platform to read and write MDA blobs (upload deployment packages, read package metadata and SBOM contents). Private Mendix Platform requires the role to upload deployment packages. Read only access is not sufficient. - * **Storage Blob Delegator** - This role permits Private Mendix Platform to delegate access to blobs by generating presigned (user delegation SAS) download URLs. It grants no data access of its own. MDA downloads may fail even when a blob data role is correctly assigned if Delegator is missing. + * **Storage Blob Data Contributor** - This role permits Private Mendix Platform to read and write MDA blobs (upload deployment packages, read package metadata and SBOM contents). Private Mendix Platform requires the role to upload deployment packages. Read only access is not sufficient. As a best practice, for increased security, this role should be scoped at the container level, although scoping it to the storage account is also permitted. 4. Add an annotation to the service account, as in the following example: @@ -213,10 +212,9 @@ The settings in this section configure the storage for build output artifacts. * **Mda Storage Option** - Configure where to store the build output artifacts. The supported values are S3 Bucket and Azure Blob. This option requires the Azure Workload identity authentication. The default service account is used in the build pod for uploading the build artifacts. To configure the managed identity and service account, perform the following steps: 1. Create or reuse a managed identity on Azure portal, and configure federated credentials for the Kubernetes service account. - 2. In the **Managed Identity**, add a role assignment with the following roles scoped to the storage account: + 2. In the **Managed Identity**, add a role assignment with the following role scoped to the storage account: - * **Storage Blob Data Contributor** - This role permits Private Mendix Platform to read and write MDA blobs (upload deployment packages, read package metadata and SBOM contents). Private Mendix Platform requires the role to upload deployment packages. Read only access is not sufficient. - * **Storage Blob Delegator** - This role permits Private Mendix Platform to delegate access to blobs by generating presigned (user delegation SAS) download URLs. It grants no data access of its own. MDA downloads may fail even when a blob data role is correctly assigned if Delegator is missing. + * **Storage Blob Data Contributor** - This role permits Private Mendix Platform to read and write MDA blobs (upload deployment packages, read package metadata and SBOM contents). Private Mendix Platform requires the role to upload deployment packages. Read only access is not sufficient. As a best practice, for increased security, this role should be scoped at the container level, although scoping it to the storage account is also permitted. 3. Add the correct annotation to the Service Account for build pod and PMP. 4. Add annotations for the build pod and Private Mendix Platform to the service account, as in the following example: @@ -230,16 +228,21 @@ The settings in this section configure the storage for build output artifacts. azure.workload.identity/client-id: {client-id-build} ``` - 5. Add a role assignment with the Storage Blob Data Contributor role scoped to the storage account to ensure that Private Mendix Platform can access the build metadata after the build is completed. If you are already using Azure Blob Storage (Azure managed identity authentication) for Private Mendix Platform, you can reuse the managed identity which was created by the Mendix Operator. + 5. Add the following role assignments to ensure that Private Mendix Platform can access the build metadata after the build is completed: - ```text - kind: ServiceAccount - metadata: - name: {pmp-serviceaccount-name} - namespace: {pmp-namespace} # The namespace where Private Mendix Platform is installed - annotations: - azure.workload.identity/client-id: {client-id-pmp} - ``` + * **Storage Blob Data Contributor** - This role permits Private Mendix Platform to read and write MDA blobs (upload deployment packages, read package metadata and SBOM contents). Private Mendix Platform requires the role to upload deployment packages. Read only access is not sufficient. As a best practice, for increased security, this role should be scoped at the container level, although scoping it to the storage account is also permitted. + * **Storage Blob Delegator** - This role permits Private Mendix Platform to delegate access to blobs by generating presigned (user delegation SAS) download URLs. It grants no data access of its own. MDA downloads may fail even when a blob data role is correctly assigned if Delegator is missing. This role must be scoped to the storage account. + + If you are already using Azure Blob Storage (Azure managed identity authentication) for Private Mendix Platform, you can reuse the managed identity which was created by the Mendix Operator. + + ```text + kind: ServiceAccount + metadata: + name: {pmp-serviceaccount-name} + namespace: {pmp-namespace} # The namespace where Private Mendix Platform is installed + annotations: + azure.workload.identity/client-id: {client-id-pmp} + ``` 6. Add **customPodLabels** to the Mendix Operator to label the Private Mendix Platform pod with the proper configuration. This configuration allows Private Mendix Platform to get build artifacts from Azure Storage Blob. From 562b0dac11669426b125da4e859299f595bc39ea Mon Sep 17 00:00:00 2001 From: katarzyna_koltun Date: Wed, 30 Sep 2026 17:07:10 +0200 Subject: [PATCH 3/4] fixed scope --- .../docs/private-platform/configuration/pmp-configure-k8s.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/content/en/docs/private-platform/configuration/pmp-configure-k8s.md b/content/en/docs/private-platform/configuration/pmp-configure-k8s.md index a40b1ab0a43..027c6990221 100644 --- a/content/en/docs/private-platform/configuration/pmp-configure-k8s.md +++ b/content/en/docs/private-platform/configuration/pmp-configure-k8s.md @@ -140,7 +140,7 @@ The settings in this section configure the images. 1. Create a managed identity in the Azure portal 2. Configure federated credentials for the Kubernetes service account. - 3. In the **Managed Identity** section, add a role assignment with the following role scoped to the storage account: + 3. In the **Managed Identity** section, add a role assignment with the following role: * **Storage Blob Data Contributor** - This role permits Private Mendix Platform to read and write MDA blobs (upload deployment packages, read package metadata and SBOM contents). Private Mendix Platform requires the role to upload deployment packages. Read only access is not sufficient. As a best practice, for increased security, this role should be scoped at the container level, although scoping it to the storage account is also permitted. @@ -212,7 +212,7 @@ The settings in this section configure the storage for build output artifacts. * **Mda Storage Option** - Configure where to store the build output artifacts. The supported values are S3 Bucket and Azure Blob. This option requires the Azure Workload identity authentication. The default service account is used in the build pod for uploading the build artifacts. To configure the managed identity and service account, perform the following steps: 1. Create or reuse a managed identity on Azure portal, and configure federated credentials for the Kubernetes service account. - 2. In the **Managed Identity**, add a role assignment with the following role scoped to the storage account: + 2. In the **Managed Identity**, add a role assignment with the following role: * **Storage Blob Data Contributor** - This role permits Private Mendix Platform to read and write MDA blobs (upload deployment packages, read package metadata and SBOM contents). Private Mendix Platform requires the role to upload deployment packages. Read only access is not sufficient. As a best practice, for increased security, this role should be scoped at the container level, although scoping it to the storage account is also permitted. From ddb6feeb41b4104d06b058ca477b6aced3455747 Mon Sep 17 00:00:00 2001 From: katarzyna_koltun Date: Wed, 30 Sep 2026 18:11:31 +0200 Subject: [PATCH 4/4] SME review --- .../configuration/pmp-configure-k8s.md | 31 +++++++------------ 1 file changed, 11 insertions(+), 20 deletions(-) diff --git a/content/en/docs/private-platform/configuration/pmp-configure-k8s.md b/content/en/docs/private-platform/configuration/pmp-configure-k8s.md index 027c6990221..84a5c658385 100644 --- a/content/en/docs/private-platform/configuration/pmp-configure-k8s.md +++ b/content/en/docs/private-platform/configuration/pmp-configure-k8s.md @@ -216,35 +216,25 @@ The settings in this section configure the storage for build output artifacts. * **Storage Blob Data Contributor** - This role permits Private Mendix Platform to read and write MDA blobs (upload deployment packages, read package metadata and SBOM contents). Private Mendix Platform requires the role to upload deployment packages. Read only access is not sufficient. As a best practice, for increased security, this role should be scoped at the container level, although scoping it to the storage account is also permitted. - 3. Add the correct annotation to the Service Account for build pod and PMP. - 4. Add annotations for the build pod and Private Mendix Platform to the service account, as in the following example: + 3. Optional: Add annotations for the build pod and Private Mendix Platform to the service account, as in the following example: ```text kind: ServiceAccount metadata: - name: default - namespace: default # The same as the one in Configuring Build Cluster Setting + name: {pmp-serviceaccount-name} + namespace: {pmp-namespace} # The namespace where Private Mendix Platform is installed annotations: - azure.workload.identity/client-id: {client-id-build} + azure.workload.identity/client-id: {client-id-pmp} ``` - 5. Add the following role assignments to ensure that Private Mendix Platform can access the build metadata after the build is completed: + This step is not required if Private Mendix Platform is using a MI from Azure Managed Identity-based storage plans. In that case, the ServiceAccount already has the correct annotation. + + 4. Add the following role assignments to the Private Mendix Platform Managed Identity: * **Storage Blob Data Contributor** - This role permits Private Mendix Platform to read and write MDA blobs (upload deployment packages, read package metadata and SBOM contents). Private Mendix Platform requires the role to upload deployment packages. Read only access is not sufficient. As a best practice, for increased security, this role should be scoped at the container level, although scoping it to the storage account is also permitted. * **Storage Blob Delegator** - This role permits Private Mendix Platform to delegate access to blobs by generating presigned (user delegation SAS) download URLs. It grants no data access of its own. MDA downloads may fail even when a blob data role is correctly assigned if Delegator is missing. This role must be scoped to the storage account. - If you are already using Azure Blob Storage (Azure managed identity authentication) for Private Mendix Platform, you can reuse the managed identity which was created by the Mendix Operator. - - ```text - kind: ServiceAccount - metadata: - name: {pmp-serviceaccount-name} - namespace: {pmp-namespace} # The namespace where Private Mendix Platform is installed - annotations: - azure.workload.identity/client-id: {client-id-pmp} - ``` - - 6. Add **customPodLabels** to the Mendix Operator to label the Private Mendix Platform pod with the proper configuration. This configuration allows Private Mendix Platform to get build artifacts from Azure Storage Blob. + 5. Optional: Add **customPodLabels** to the Mendix Operator to label the Private Mendix Platform pod with the proper configuration. This configuration allows Private Mendix Platform to get build artifacts from Azure Storage Blob. ```text kind: OperatorConfiguration @@ -256,8 +246,9 @@ The settings in this section configure the storage for build output artifacts. general: azure.workload.identity/use: "true" ``` - - 7. Restart Private Mendix Platform to ensure that the label is applied. + This step is not required if Private Mendix Platform is using a MI from Azure Managed Identity-based storage plans. In that case, the customPodLabel is already configured. + + 6. Restart Private Mendix Platform to ensure that the labels are applied. * **S3 Endpoint** - For example, `https://s3.ap-southeast-1.amazonaws.com`. * **No Verify SSL** - Select this checkbox if you use your own bucket server, and its certificate is self-signed. Selecting this option adds *--no-verify-ssl* to the AWS CLI command to avoid failure.