Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 18 additions & 16 deletions content/en/docs/private-platform/configuration/pmp-configure-k8s.md
Original file line number Diff line number Diff line change
Expand Up @@ -140,7 +140,10 @@ The settings in this section configure the images.

1. Create a managed identity in the Azure portal
2. Configure federated credentials for the Kubernetes service account.
3. In the **Managed Identity** section, add a role assignment with the **Storage Blob Data Reader** role scoped to the storage account.
3. In the **Managed Identity** section, add a role assignment with the following role:

* **Storage Blob Data Contributor** - This role permits Private Mendix Platform to read and write MDA blobs (upload deployment packages, read package metadata and SBOM contents). Private Mendix Platform requires the role to upload deployment packages. Read only access is not sufficient. As a best practice, for increased security, this role should be scoped at the container level, although scoping it to the storage account is also permitted.

4. Add an annotation to the service account, as in the following example:

```text
Expand Down Expand Up @@ -209,20 +212,11 @@ The settings in this section configure the storage for build output artifacts.
* **Mda Storage Option** - Configure where to store the build output artifacts. The supported values are S3 Bucket and Azure Blob. This option requires the Azure Workload identity authentication. The default service account is used in the build pod for uploading the build artifacts. To configure the managed identity and service account, perform the following steps:

1. Create or reuse a managed identity on Azure portal, and configure federated credentials for the Kubernetes service account.
2. In the **Managed Identity**, add a role assignment with the **Storage Blob Data Contributor** role scoped to the storage account.
3. Add the correct annotation to the Service Account for build pod and PMP.
4. Add annotations for the build pod and Private Mendix Platform to the service account, as in the following example:
2. In the **Managed Identity**, add a role assignment with the following role:

```text
kind: ServiceAccount
metadata:
name: default
namespace: default # The same as the one in Configuring Build Cluster Setting
annotations:
azure.workload.identity/client-id: {client-id-build}
```
* **Storage Blob Data Contributor** - This role permits Private Mendix Platform to read and write MDA blobs (upload deployment packages, read package metadata and SBOM contents). Private Mendix Platform requires the role to upload deployment packages. Read only access is not sufficient. As a best practice, for increased security, this role should be scoped at the container level, although scoping it to the storage account is also permitted.

5. Add a role assignment with the Storage Blob Data Reader role scoped to the storage account to ensure that Private Mendix Platform can access the build metadata after the build is completed. If you are already using Azure Blob Storage (Azure managed identity authentication) for Private Mendix Platform, you can reuse the managed identity which was created by the Mendix Operator.
3. Optional: Add annotations for the build pod and Private Mendix Platform to the service account, as in the following example:

```text
kind: ServiceAccount
Expand All @@ -233,7 +227,14 @@ The settings in this section configure the storage for build output artifacts.
azure.workload.identity/client-id: {client-id-pmp}
```

6. Add **customPodLabels** to the Mendix Operator to label the Private Mendix Platform pod with the proper configuration. This configuration allows Private Mendix Platform to get build artifacts from Azure Storage Blob.
This step is not required if Private Mendix Platform is using a MI from Azure Managed Identity-based storage plans. In that case, the ServiceAccount already has the correct annotation.

4. Add the following role assignments to the Private Mendix Platform Managed Identity:

* **Storage Blob Data Contributor** - This role permits Private Mendix Platform to read and write MDA blobs (upload deployment packages, read package metadata and SBOM contents). Private Mendix Platform requires the role to upload deployment packages. Read only access is not sufficient. As a best practice, for increased security, this role should be scoped at the container level, although scoping it to the storage account is also permitted.
* **Storage Blob Delegator** - This role permits Private Mendix Platform to delegate access to blobs by generating presigned (user delegation SAS) download URLs. It grants no data access of its own. MDA downloads may fail even when a blob data role is correctly assigned if Delegator is missing. This role must be scoped to the storage account.

5. Optional: Add **customPodLabels** to the Mendix Operator to label the Private Mendix Platform pod with the proper configuration. This configuration allows Private Mendix Platform to get build artifacts from Azure Storage Blob.

```text
kind: OperatorConfiguration
Expand All @@ -245,8 +246,9 @@ The settings in this section configure the storage for build output artifacts.
general:
azure.workload.identity/use: "true"
```

7. Restart Private Mendix Platform to ensure that the label is applied.
This step is not required if Private Mendix Platform is using a MI from Azure Managed Identity-based storage plans. In that case, the customPodLabel is already configured.

6. Restart Private Mendix Platform to ensure that the labels are applied.

* **S3 Endpoint** - For example, `https://s3.ap-southeast-1.amazonaws.com`.
* **No Verify SSL** - Select this checkbox if you use your own bucket server, and its certificate is self-signed. Selecting this option adds *--no-verify-ssl* to the AWS CLI command to avoid failure.
Expand Down
Loading