/** * Azure App Configuration store for environment config documents. * * On AKS the natural per-environment config home is Azure App Configuration: * it speaks hierarchical keys, supports both connection-string auth (for ops * out-of-cluster) and `DefaultAzureCredential` (managed identity / workload * identity in-cluster), and exposes a paged list API that lets us enumerate * every environment the store knows about without maintaining an external * index. * * Key shape: `log10x/env-config/${env_id}`. Forward-slashes are legal in * App Configuration keys and group naturally in the portal UI. * * Auth precedence (mirrors `siem/azure-monitor.ts`): * 1. `LOG10X_AZURE_APP_CONFIG_CONNECTION_STRING` — explicit conn string. * 2. `LOG10X_AZURE_APP_CONFIG_ENDPOINT` (or `AZURE_APP_CONFIG_ENDPOINT`) + * `DefaultAzureCredential` — the ambient identity flow. * * Reads accept either an env_id or a nickname. We look up the env_id-keyed * row directly first; on miss we scan the list and match by nickname so the * caller never has to know which form they have. * * isAvailable() never throws — it returns `{ available: false, reason }` so * the resolver can fall through to the next store. Read/write/list/delete * surface their underlying RestErrors verbatim because at that point the * caller has already committed to this store and silent fallback would hide * IAM bugs. */ import { type EnvironmentConfig } from './types.js'; import type { EnvConfigStore } from './store-interface.js'; export interface AzureAppConfigStoreOptions { /** * Optional override for the connection string. Falls back to * `LOG10X_AZURE_APP_CONFIG_CONNECTION_STRING` when not supplied. */ connectionString?: string; /** * Optional override for the endpoint URL when using * `DefaultAzureCredential`. Falls back to * `LOG10X_AZURE_APP_CONFIG_ENDPOINT` (and `AZURE_APP_CONFIG_ENDPOINT`) * when not supplied. */ endpoint?: string; } export declare class AzureAppConfigStore implements EnvConfigStore { readonly kind: "azure_ac"; private readonly connectionString?; private readonly endpoint?; private cachedClient; constructor(opts?: AzureAppConfigStoreOptions); isAvailable(): Promise<{ available: boolean; reason: string; }>; read(envIdOrNickname: string): Promise; write(config: EnvironmentConfig): Promise; list(): Promise; delete(envId: string): Promise; private getClient; private tryGet; private parseSetting; }