Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 8 Next »

Introduction

To work with Azure ARM in Abiquo, you'll need to add credentials to your Abiquo enterprise.

You can add one set of credentials from a subscription to one Abiquo enterprise only.

  1. Create an Azure Subscription.
    1. You may require separate credentials for some groups of regions, for example, regions in China.
  2. Obtain details of the subscription and create an Application with the following Azure attributes:
    1. Subscription ID
    2. Application (client) ID
    3. Directory (tenant) ID
    4. Application password
  3. Follow this guide to obtain give consent for the Application to work with 
    1. AccessToken
    2. RefreshToken


Abiquo provides these instructions as a guide only and we update them occasionally. 

Abiquo recommends that customers follow the instructions of the cloud provider, for example, at the time of writing for Azure:



Obtain details of your Azure subscription

To obtain details of your Azure subscription, do the following steps.

  1. Log in to the Azure portal
  2. In the Home view, under Azure services, click Subscriptions. Or in the search box in the top menu bar, enter Subscriptions. Then select Subscriptions
  3. Click on your subscription

    Troubleshooting

    If the subscription does not display, check that you have selected the correct directory. Click on the directory name in the top right corner. From here you can switch directory

  4. Save the Subscription ID to enter in the Abiquo credentials.

  5. If you purchased the subscription directly from Azure, you can also save the Offer ID for the pricing credentials.  

Create an ARM application using Azure Portal

Abiquo uses the ARM application ID to access the ARM API and compute features.

To use the platform's billing features only (without the compute features), you do not need an ARM application. See Add credentials of reseller customers for billing only

To create an ARM application using the Azure Portal and obtain details of the application, do these steps.

  1. Log in to the Azure portal
  2. In the Home view, under Azure services, click Azure Active Directory. Or in the search box, enter Azure Active Directory. Select Azure Active Directory

  3. On the left, click App registrations
  4. Click New registration
  5. To register the application, enter a Name, select the Supported account types, and enter a URL. If you know the URI of the partner consent service, enter it now. Or you can enter any URL and edit the application and change this value later. Click Register

  6. Save the Application (client) ID and the Directory (tenant) ID, because you will need to configure them in Abiquo. Then click Certificates & secrets

  7. To configure the password for the application, click New client secret, which will open the Add a client secret section. Enter a Description and an Expiry duration, then click Add

    The Azure portal will display the application password ONCE ONLY. You must use this password in Abiquo, so make sure to save it, because Azure will not display it again.

  8. Go to the Subscriptions menu, select the subscription you want to associate the application with, and add a new permission for it with these steps.

    1. Select Access control (IAM)

    2. Click Add

    3. Click Add role assignment
    4. In the dialog, select the Contributor role, and in the Select box, enter the name of the application. Then click Save

  9. Go to the Subscriptions menu again and select Resource providers

    1. Search for the Microsoft.Compute provider and click Register to add it for the subscription if it is not already added

    2. Search for the Microsoft.Network provider and click Register to add it for the subscription if it is not already added


Configure authorization for the use of Azure Arm credentials in the multi-cloud platform

As Azure now requires multi-factor authentication for CSP credentials, you must authorize the use of your credentials in the multi-cloud platform to obtain your access and refresh tokens for use in pricing credentials. The refresh tokens will expire if you do not use them during a 90-day period.

To create your own server to grant consent for the use of your Azure credentials, follow the instructions in the Azure documentation. For general instructions, see https://docs.microsoft.com/en-us/partner-center/develop/partner-center-authentication#app--user-authentication and for Java instructions: https://docs.microsoft.com/en-us/partner-center/develop/partner-center-authentication#java-appuser-authentication.

To complete the configuration:

  1. Log in to the Azure portal
  2. Edit your Azure application
  3. In the Redirect URI, enter the URL of the partner consent service.

Generate new Azure access and refresh tokens for use in the multi-cloud platform

To obtain access and refresh tokens for your Azure credentials:

  1. Log in to the Microsoft Azure portal .

  2. Go to Azure Active Directory → Manage → App registrations

  3. Find the app for which you generated the credentials

  4. Go to Redirect URIs

  5. Find the Redirect URI that is used to grant consent for the use of the credentials: please contact Abiquo Support to get it. See Working with Abiquo support

  6. Go to this consent URI and log in

  7. Get the new access token and the new refresh token

  8. Add these to the Abiquo multi-cloud platform as part of your pricing credentials in the format

    csp#tenantId#applicationId#accessToken#refreshToken

The platform will now be able to retrieve your cloud provider's pricing and billing data again for use in pricing and for display on the billing widgets that appear on the default Hybrid billing dashboard.

Add the Azure ARM compute credentials to Abiquo

Before you add credentials, an administrator must create at least one compatible public cloud region in Azure ARM, and allow your enterprise to access this region. Some regions may require separate credentials, for example regions in China, and you will need to obtain credentials and create these regions separately. See Create a public cloud region.

To connect Abiquo to your Azure ARM account, add the Azure ARM credentials obtained in the above steps to Abiquo, with the following steps.

  1. Log in to Abiquo
  2. Go to Users view
  3. Edit the enterprise and go to Credentials → Public
  4. Select the Azure ARM provider, and enter the credentials in the following format.
  • Identity: 

    subscription-id#app-id#tenant-id

    This means you should enter the Subscription ID, Application ID and Tenant ID, as a single string and separate each element with a '#'. For example: 

    566058dd-80bc-4ccc-8d6e-e9ac00c4b4a1#8927a710-4f4d-4d11-811c-94c36e9b2c3f#fbb96b71-f92c-4f78-acf7-cd88bdee36b1
  • Credential: Enter the password for the Application.

Add the Azure CSP pricing and billing credentials to Abiquo

Before you add credentials, your administrator must create at least one compatible public cloud region in Azure ARM, and allow your enterprise to access this region. Some regions may require separate credentials, for example regions in China, and you will need to obtain credentials and create these regions separately. See Create a public cloud region

For CSP accounts, the main tenant should add the pricing credentials in the following format:

csp#tenantId#clientId#accessToken#refreshToken

The customer tenants do not need to add pricing credentials. The platform will use the CSP credentials for the customer tenants in the hierarchy.

  • No labels