From 1c0ab1266517c7b7bfd0ea85177b12f1736cb9c5 Mon Sep 17 00:00:00 2001 From: xenon898 <88700568+xenon898@users.noreply.github.com> Date: Thu, 17 Sep 2026 22:11:39 +0530 Subject: [PATCH 1/2] docs: document OAuth2 support for jira_config's http_config Signed-off-by: xenon898 <88700568+xenon898@users.noreply.github.com> Co-Authored-By: Claude Sonnet 5 --- docs/configuration.md | 20 +++++++++++++++++--- 1 file changed, 17 insertions(+), 3 deletions(-) diff --git a/docs/configuration.md b/docs/configuration.md index ead7ee0482..e3525808dd 100644 --- a/docs/configuration.md +++ b/docs/configuration.md @@ -1375,9 +1375,11 @@ fields: [ : ... ] -# The HTTP client's configuration. You must use this configuration to supply the personal access token (PAT) as part of the HTTP `Authorization` header. -# For Jira Cloud, use basic_auth with the email address as the username and the PAT as the password. -# For Jira Data Center, use the 'authorization' field with 'credentials: '. +# The HTTP client's configuration, see above. +# Personal access tokens (PAT) are supported via basic_auth (Jira Cloud: email +# address as the username, PAT as the password) or the 'authorization' field +# (Jira Data Center: 'credentials: '). OAuth2 is also supported for +# system-to-system authentication; see the example below. [ http_config: | default = global.http_config ] ``` @@ -1389,6 +1391,18 @@ labels: - '{{ .CommonLabels.severity }}' ``` +`http_config` also accepts an `oauth2` block for system-to-system authentication, +as an alternative to a personal access token. For example: + +```yaml +http_config: + oauth2: + client_id: alertmanager-jira + client_secret_file: /etc/alertmanager/secrets/jira_client_secret + token_url: https://auth.example.com/oauth2/token + scopes: [ jira-work-management ] +``` + #### `` Jira issue field can have multiple types. From 39eadcb10ac48caabafd2ef9c3ba58bac43e63be Mon Sep 17 00:00:00 2001 From: xenon898 <88700568+xenon898@users.noreply.github.com> Date: Tue, 22 Sep 2026 13:04:15 +0530 Subject: [PATCH 2/2] docs: address review feedback, drop the oauth2 example Signed-off-by: xenon898 <88700568+xenon898@users.noreply.github.com> Co-Authored-By: Claude Sonnet 5 --- docs/configuration.md | 24 +++++++----------------- 1 file changed, 7 insertions(+), 17 deletions(-) diff --git a/docs/configuration.md b/docs/configuration.md index e3525808dd..8224d7f317 100644 --- a/docs/configuration.md +++ b/docs/configuration.md @@ -1375,11 +1375,13 @@ fields: [ : ... ] -# The HTTP client's configuration, see above. -# Personal access tokens (PAT) are supported via basic_auth (Jira Cloud: email -# address as the username, PAT as the password) or the 'authorization' field -# (Jira Data Center: 'credentials: '). OAuth2 is also supported for -# system-to-system authentication; see the example below. +# The HTTP client's configuration. Personal access tokens (PAT) are supported +# via basic_auth (Jira Cloud: email address as the username, PAT as the +# password) or the 'authorization' field (Jira Data Center: 'credentials: +# '). OAuth2 client_credentials against an external identity +# provider is also supported via the standard http_config above; Jira's own +# OAuth2 requires interactive browser consent and cannot be used for +# Alertmanager's automated notifications. [ http_config: | default = global.http_config ] ``` @@ -1391,18 +1393,6 @@ labels: - '{{ .CommonLabels.severity }}' ``` -`http_config` also accepts an `oauth2` block for system-to-system authentication, -as an alternative to a personal access token. For example: - -```yaml -http_config: - oauth2: - client_id: alertmanager-jira - client_secret_file: /etc/alertmanager/secrets/jira_client_secret - token_url: https://auth.example.com/oauth2/token - scopes: [ jira-work-management ] -``` - #### `` Jira issue field can have multiple types.