mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-09-08 00:03:07 +00:00
* [ee] feat(secret-backend): add Workload Identity Federation for Azure Key Vault Make `client_secret` optional. When omitted, Windmill falls back to Azure Workload Identity Federation: it reads the projected service-account JWT from AZURE_FEDERATED_TOKEN_FILE and exchanges it with Entra ID via `client_assertion`, no long-lived secret stored on the instance. Same code path covers AKS (workload-identity admission webhook auto-injects the env vars) and any other Kubernetes cluster federated to Entra ID (EKS/GKE/self-hosted). - backend: relax client_secret to Option (already was), update doc comment + OpenAPI description; the actual auth-branching logic lives in the EE companion file (azure_kv_ee.rs). - frontend: drop client_secret/token from canSubmit so saving with an empty secret is allowed; add inline help under the Client Secret field pointing to AZURE_FEDERATED_TOKEN_FILE; mark the field optional. - ee-repo-ref: bump to the EE companion commit. EE companion: see windmill-ee-private branch azure-keyvault-managed-identity. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * [ee] chore: bump ee-repo-ref for blank-client_secret fix Picks up the EE-side fix (windmill-ee-private c7c0a23) that treats blank `client_secret` as workload-identity instead of POSTing an empty string to Entra ID. Addresses Codex review on PR #9061. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * chore: update ee-repo-ref to c8d100d74b8de6bd26fc973d5edbd8853d54dd8b This commit updates the EE repository reference after PR #561 was merged in windmill-ee-private. Previous ee-repo-ref: c7c0a23459b0e7416a045a279346cc48b30eed32 New ee-repo-ref: c8d100d74b8de6bd26fc973d5edbd8853d54dd8b Automated by sync-ee-ref workflow. --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com> Co-authored-by: Ruben Fiszel <ruben@windmill.dev>
Windmill Backend
This folder holds all backend components, the src/ folder only contains files used to build the "root" binary.
Components
| name | description |
|---|---|
| windmill-api | The API server, exposing functionality to other components and the frontend |
| windmill-audit | Contains audit functionality, allowing different components to record important actions |
| windmill-common | Common code shared by all crates |
| windmill-queue | Contains job & flow queuing functionality, commonly written to by the API server and read from by workers |
| windmill-worker | The worker. Used to process and execute flows & jobs. |
| parsers | Contains code to parse signatures in different langauges. |
Compile sqlx for offline ci
cargo sqlx prepare --workspace -- --bin windmill --features enterprise