Conversation
✅ Deploy Preview for cockroachdb-api-docs canceled.
|
✅ Deploy Preview for cockroachdb-interactivetutorials-docs canceled.
|
Files changed:
|
✅ Netlify Preview
To edit notification comments on pull requests, go to your Netlify project configuration. |
rgcase
left a comment
There was a problem hiding this comment.
Looks pretty good, thanks Joe. I left a few comments but nothing big.
|
|
||
| ## Step 1. Create a new Azure subscription | ||
|
|
||
| Provision a new Azure subscription with no existing infrastructure, dedicated to your CockroachDB {{ site.data.products.cloud }} deployment. This subscription can be reused for multiple CockroachDB clusters. |
There was a problem hiding this comment.
Do you think we should mention here why we want customers to create a new subscription (and later account or project)? The biggest reason we want this is because they're going to give us permissions to act on resources in this subscription and we don't want to have permissions that would let us affect any of their other infrastructure.
|
|
||
| ## Step 2. Grant IAM permissions to Cockroach Labs | ||
|
|
||
| When BYOC is enabled for your account, Cockroach Labs provisions a multi-tenant App Registration associated with your CockroachDB {{ site.data.products.cloud }} organization and provides you with a URL to grant tenant-wide admin consent to the application. Visit this URL with a user account that is [authorized to content on behalf of your organization](https://learn.microsoft.com/entra/identity/enterprise-apps/grant-admin-consent?pivots=portal#prerequisites). |
|
|
||
| When BYOC is enabled for your account, Cockroach Labs provisions a multi-tenant App Registration associated with your CockroachDB {{ site.data.products.cloud }} organization and provides you with a URL to grant tenant-wide admin consent to the application. Visit this URL with a user account that is [authorized to content on behalf of your organization](https://learn.microsoft.com/entra/identity/enterprise-apps/grant-admin-consent?pivots=portal#prerequisites). | ||
|
|
||
| Once the Cockroach Labs App Registration has been granted admin content in the tenant, grant the following set of roles to the app: |
|
|
||
| Provision a new Azure subscription with no existing infrastructure, dedicated to your CockroachDB {{ site.data.products.cloud }} deployment. This subscription can be reused for multiple CockroachDB clusters. | ||
|
|
||
| ## Step 2. Grant IAM permissions to Cockroach Labs |
There was a problem hiding this comment.
FYI this process is going to change some in the near future, but it might not be until after we've published these docs. Here are a couple Google docs describing the new process https://docs.google.com/document/d/1y9bxvTjMTPs7RuTw4APTSdTEGdMsWEju8hcuKIzz2h8 and https://docs.google.com/document/d/16MOr0f3f4-OOVSFVUd9d7fF2X09GLk831gjgs19PMOY.
d06d456 to
49002be
Compare
https://cockroachlabs.atlassian.net/browse/DOC-14974