Skip to content

feat(eventhubs): add Azure managed identity authentication for Event Hubs sink - #318

Open
abhi-roop wants to merge 3 commits into
debezium:mainfrom
abhi-roop:feat/eventhubs-managed-identity
Open

abhi-roop wants to merge 3 commits into
debezium:mainfrom
abhi-roop:feat/eventhubs-managed-identity

Conversation

@abhi-roop

Copy link
Copy Markdown

## Summary

Adds support for Azure Entra ID authentication using DefaultAzureCredential, enabling secretless deployments of the Event Hubs sink on Azure Container Apps, AKS, VMs, and other Azure-hosted environments.

Fixes #2647.

New configuration

Property Default Description
debezium.sink.eventhubs.authmode connection-string Set to default-azure-credential to use Entra ID
debezium.sink.eventhubs.fullyqualifiednamespace — Required when authmode=default-azure-credential (e.g. myns.servicebus.windows.net)

The existing connectionstring configuration remains supported and is still the default, so there is no breaking change.

Notes

  • I used authmode and fullyqualifiednamespace to follow the existing flat naming convention in EventHubsChangeConsumerConfig (e.g. connectionstring, hubname, partitionid). Happy to switch to auth.mode / fully-qualified-namespace if preferred.
  • A user-assigned managed identity can be selected via the standard AZURE_CLIENT_ID environment variable consumed by Azure Identity.
  • The workload identity needs the Azure Event Hubs Data Sender role at namespace or hub scope.

Testing

  • mvn -pl debezium-server-eventhubs -am clean install passes locally, including integration tests via Testcontainers.
  • Added unit tests covering config parsing and validation of the new auth mode.

@github-actions

Copy link
Copy Markdown

Hi @abhi-roop, thanks for your contribution. Please prefix the commit message(s) with the debezium/dbz#xxx GitHub issue key.

…ication for Event Hubs sink

Signed-off-by: Abhiroop Kumar Singh <abhiroopkumar1234@gmail.com>

@Naros Naros left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @abhi-roop I've left a few inline comments.

One point about the PR description, you mention the use of AZURE_CLIENT_ID, but I don't recall that being documented in the docs PR that accompanies this change. We should probably be sure to include that somehow for users.

Signed-off-by: Abhiroop Kumar Singh <abhiroopkumar1234@gmail.com>
@abhi-roop

Copy link
Copy Markdown
Author

Hi @Naros, thanks for the review. I've addressed the feedback:

  • Removed the spurious reformatting — restored the file from upstream and re-applied only the feature changes.
  • Switched authmode to an AuthMode enum implementing EnumeratedValue, following the Fluss PrimaryKeyMode precedent.
  • Used Strings.isNullOrEmpty for the namespace check.

Also updated the docs PR #8082 to mention AZURE_CLIENT_ID for user-assigned managed identities, as you noted. Ready for another look when you have time.

@Naros Naros left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @abhi-roop, a few comments below if you could take a look.

Comment thread debezium-server-bom/pom.xml
Signed-off-by: Abhiroop Kumar Singh <abhiroopkumar1234@gmail.com>
@abhi-roop

Copy link
Copy Markdown
Author

Hi @Naros, thanks for the detailed review. Addressed all points:

  • Reordered the Azure dependencies so azure-identity is declared first, letting Maven nearest-wins resolve azure-core:1.59.1 instead of 1.53.0.
  • Moved the namespace check into EventHubsChangeConsumerConfig.init(...) and added a per-mode validate() that also covers the missing hubname case in credential mode and the missing connectionstring case in connection-string mode, with messages that name the full property.
  • Added a LOGGER.warn when connectionstring is set but ignored under default-azure-credential.
  • Replaced the two log lines with a single message that names the auth mode.
  • Expanded tests to cover both error paths (missing namespace, missing hubname), the missing connection string, and invalid authmode.

All seven tests run without Azure credentials. Ready for another look.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants