Skip to content

Commit 0965f1f

Browse files
authored
fix(mssql): remove invalid auth modes; suppress azure-identity log noise (#1756)
ActiveDirectoryAzCli and ActiveDirectoryWorkloadIdentity do not exist in the mssql-jdbc 12.6.1 SqlAuthentication enum — they are .NET/Go driver concepts only. Remove both from docs and tests. Add ActiveDirectoryIntegrated (Kerberos) and ActiveDirectoryServicePrincipalCertificate to the docs table as they are valid mssql-jdbc modes confirmed by javap. Suppress verbose azure-identity DefaultAzureCredential chain probe messages (EnvironmentCredential unavailable, WorkloadIdentity unavailable, ManagedIdentityCredential unavailable, etc.) in logback.xml by setting com.azure.identity to WARN and com.microsoft.aad.msal4j to ERROR. These INFO-level messages are expected on a developer machine but extremely noisy when multiple connection threads each walk the full credential chain. Reported by audunsolemdal in #1754.
1 parent 3c90c0d commit 0965f1f

3 files changed

Lines changed: 28 additions & 28 deletions

File tree

‎clojure/resources/logback.xml‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,13 @@
2121
</encoder>
2222
</appender>
2323

24+
<!-- azure-identity logs every credential it tries in its DefaultAzureCredential
25+
chain (EnvironmentCredential unavailable, WorkloadIdentity unavailable,
26+
ManagedIdentity unavailable, etc.) at INFO/WARN — expected on a developer
27+
machine but very noisy. Suppress to WARN/ERROR respectively. -->
28+
<logger name="com.azure.identity" level="WARN"/>
29+
<logger name="com.microsoft.aad.msal4j" level="ERROR"/>
30+
2431
<root level="INFO">
2532
<appender-ref ref="CONSOLE"/>
2633
<appender-ref ref="FILE"/>

‎clojure/test/pgloader/load_file/ast_test.clj‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -95,12 +95,12 @@
9595
"com.microsoft.aad.msal4j must be on the classpath for ActiveDirectoryPassword / ActiveDirectoryServicePrincipal auth")))
9696

9797
(deftest test-azure-identity-on-classpath
98-
(testing "azure-identity is bundled — ActiveDirectoryDefault / AzCli / WorkloadIdentity auth modes are available"
98+
(testing "azure-identity is bundled — ActiveDirectoryDefault auth mode is available"
9999
(is (try (Class/forName "com.azure.identity.DefaultAzureCredentialBuilder")
100100
true
101101
(catch ClassNotFoundException _
102102
false))
103-
"com.azure.identity must be on the classpath for ActiveDirectoryDefault / ActiveDirectoryAzCli / ActiveDirectoryWorkloadIdentity auth")))
103+
"com.azure.identity must be on the classpath for ActiveDirectoryDefault auth")))
104104

105105
(deftest test-parse-postgresql-synthesises-jdbc-url
106106
(testing "postgresql:// synthesises jdbc-url"

‎docs/ref/mssql.rst‎

Lines changed: 19 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -356,21 +356,21 @@ and ``authentication=`` reach the driver exactly as written.
356356

357357
Quick reference:
358358

359-
+--------------------------------------+------------------------------------------------+
360-
| Mode | Typical use case |
361-
+======================================+================================================+
362-
| ``ActiveDirectoryServicePrincipal`` | CI/CD — app registration (client ID + secret) |
363-
+--------------------------------------+------------------------------------------------+
364-
| ``ActiveDirectoryManagedIdentity`` | Azure VM / App Service / AKS — no credentials |
365-
+--------------------------------------+------------------------------------------------+
366-
| ``ActiveDirectoryDefault`` | Developer laptop: ``az login`` fallback chain |
367-
+--------------------------------------+------------------------------------------------+
368-
| ``ActiveDirectoryAzCli`` | Developer laptop: explicit ``az login`` token |
369-
+--------------------------------------+------------------------------------------------+
370-
| ``ActiveDirectoryWorkloadIdentity`` | Kubernetes OIDC workload identity |
371-
+--------------------------------------+------------------------------------------------+
372-
| ``ActiveDirectoryPassword`` | **Deprecated** — blocked by MFA enforcement |
373-
+--------------------------------------+------------------------------------------------+
359+
+--------------------------------------------+------------------------------------------------+
360+
| Mode | Typical use case |
361+
+============================================+================================================+
362+
| ``ActiveDirectoryServicePrincipal`` | CI/CD — app registration (client ID + secret) |
363+
+--------------------------------------------+------------------------------------------------+
364+
| ``ActiveDirectoryServicePrincipalCertif.`` | CI/CD — app registration with certificate |
365+
+--------------------------------------------+------------------------------------------------+
366+
| ``ActiveDirectoryManagedIdentity`` | Azure VM / App Service / AKS — no credentials |
367+
+--------------------------------------------+------------------------------------------------+
368+
| ``ActiveDirectoryDefault`` | Developer laptop: ``az login`` fallback chain |
369+
+--------------------------------------------+------------------------------------------------+
370+
| ``ActiveDirectoryIntegrated`` | Windows / Kerberos domain-joined machine |
371+
+--------------------------------------------+------------------------------------------------+
372+
| ``ActiveDirectoryPassword`` | **Deprecated** — blocked by MFA enforcement |
373+
+--------------------------------------------+------------------------------------------------+
374374

375375
``ActiveDirectoryServicePrincipal``
376376
Authenticate as an Azure AD application (client ID + client secret) —
@@ -402,19 +402,12 @@ authentication=ActiveDirectoryDefault;encrypt=true;trustServerCertificate=false"
402402
get-access-token`` using your existing ``az login`` session — no browser
403403
popup is needed.
404404

405-
``ActiveDirectoryAzCli``
406-
Like ``ActiveDirectoryDefault`` but always uses the Azure CLI token
407-
exclusively. Useful when you want a predictable, unambiguous credential
408-
source on a developer machine::
405+
``ActiveDirectoryIntegrated``
406+
Authenticate via Kerberos on a domain-joined machine. Requires a valid
407+
Kerberos ticket (``kinit`` on Linux/macOS, automatic on Windows)::
409408

410409
FROM "jdbc:sqlserver://myserver.database.windows.net:1433;databaseName=mydb;\
411-
authentication=ActiveDirectoryAzCli;encrypt=true;trustServerCertificate=false"
412-
413-
``ActiveDirectoryWorkloadIdentity``
414-
For Kubernetes pods with OIDC workload identity federation::
415-
416-
FROM "jdbc:sqlserver://myserver.database.windows.net:1433;databaseName=mydb;\
417-
authentication=ActiveDirectoryWorkloadIdentity;encrypt=true"
410+
authentication=ActiveDirectoryIntegrated;encrypt=true"
418411

419412
``ActiveDirectoryPassword``
420413
.. note::

0 commit comments

Comments
 (0)