Looks like not possible to deploy workload identity with role microsoft.directory/applications/create in Bicep
@dkershaw10 ya está trabajando en esto.
Desde el 12/7/2024.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
Bicep version
az bicep version
Bicep CLI version 0.28.1 (ba1e9f8c1e)
Resource and API version
Which Microsoft.Graph resource and API version has the issue?
Microsoft.Graph/[email protected]
Auth flow
User signed to deploy a Bicep script from a command line using az deployment create ... .
Deployment details
I can provide if it makes sense.
Describe the bug
A clear and concise description of what the bug is vs what you expected to happen
I am using the new Bicep Graph module to create a workload identity that can then be assigned to e.g. GitHub to a certain repository. The purpose is to assign further workload identities from this repository that are defined in Bicep files there.
When I try to deploy a service principal with a role that I think has some of the right assignableScopes, I get an error
see https://aka.ms/arm-deployment-operations for usage details.","details":[{"code":"InvalidActionOrNotAction","message":"The resource provider referenced in the action 'microsoft.directory/applications/create' is not returned in the list of providers from Azure Resource Manager."}]}]}]}}
It feels to me I should be able do to this in Bicep and just put wrong assignableScopes. But on the other hand there's probably more into this. This may be related to https://github.com/microsoftgraph/msgraph-bicep-types/issues/134. I am not sure if this is a bug or would be a feature. It may also very well be I don't know just how to make this happen in Bicep. :)
To Reproduce
Additional context
The Bicep I use are like follows. I have permuted all kinds of things to assignableScopes, but as expected, the error message stays the same.
main.bicep:
resource azureRootManagementGroup 'Microsoft.Management/managementGroups@2023-04-01' existing = {
scope: tenant()
name: '<guid>'
}
var applicationIdentityRegistrationDisplayName = 'GitHub Actions Identity Application Deployer'
var applicationIdentityRegistrationName = 'root-appident-deployer'
var githubOIDCProvider = 'https://token.actions.githubusercontent.com'
var microsoftEntraAudience = 'api://AzureADTokenExchange'
var gitHubActionsFederatedIdentitySubject = 'repo:${gitHubOwner}/${gitHubRepo}:ref:refs/heads/main'
resource identityGithubActionsApplication 'Microsoft.Graph/[email protected]' = {
uniqueName: applicationIdentityRegistrationName
displayName: applicationIdentityRegistrationDisplayNamef
resource githubFederatedIdentityCredential '[email protected]' = {
name: '${identityGithubActionsApplication.uniqueName}/githubFederatedIdentityCredential'
audiences: [microsoftEntraAudience]
description: 'Identity for application to deploy the root identity infrastructure.'
issuer: githubOIDCProvider
subject: gitHubActionsFederatedIdentitySubject
}
}
resource gitHubIdentityActionsServicePrincipal 'Microsoft.Graph/[email protected]' = {
displayName: applicationIdentityRegistrationDisplayName
appId: identityGithubActionsApplication.appId
}
module companyIdentityPipelineRoleDefinitionAndAssignment './companyIdentityPipelineRoleDefinitionAndAssignment.bicep' = {
name: 'bootstrapIdentityRoleDeployment'
scope: tenant()
params: {
gitHubIdentityActionsServicePrincipalId: gitHubIdentityActionsServicePrincipal.id
azureRootManagementGroupId: azureRootManagementGroup.name
}
}
companyIdentityPipelineRoleDefinitionAndAssignment.bicep:
param azureRootManagementGroupName string
resource companyIdentityPipelineRoleDefinitionAndAssignment 'Microsoft.Authorization/roleDefinitions@2022-04-01' = {
name: guid(tenant().tenantId, 'CompanyIdentityPipelineRole')
properties: {
roleName: ' identity deployment role'
description: 'Grants rights to manage identity resources.'
type: 'CustomRole'
assignableScopes: [
/* Here e.g. slash, '/' won't work. */
'/providers/Microsoft.Management/managementGroups/${azureRootManagementGroupName}'
]
permissions: [
{
actions: [
'microsoft.directory/applications/create'
'microsoft.directory/applications/read'
'microsoft.directory/applications/credentials/update'
'microsoft.directory/servicePrincipals/create'
'microsoft.directory/servicePrincipals/read'
'microsoft.directory/servicePrincipals/credentials/update'
]
notActions: []
dataActions: []
notDataActions: []
}
]
}
}
- Lenguaje dominante
- TypeScript
- Estrellas
- 81
- Forks
- 15
- Merge medio
- 3 d 8 h
- PR fusionados (30 d)
- 7
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de microsoftgraph/msgraph-bicep-types
-
bug
Dificultad 4/5 3-5 días Aptitud para principiantes 55/100
microsoftgraph/msgraph-bicep-types#311 · 3 comentarios ·
-
enhancement new type
Dificultad 5/5 Más de una semana Aptitud para principiantes 45/100
-
enhancement
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
microsoftgraph/msgraph-bicep-types#304 · 3 comentarios · 1 reacción ·
-
enhancement new type
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
microsoftgraph/msgraph-bicep-types#296 · 2 reacciones ·
-
Issue with servicePrincipals and appRoleAssignedTo in some Entra TenantsQuizá libre de nuevo @eketo-msft la tomó hace 261 días y no hay ningún pull request abierto. Abiertobug
microsoftgraph/msgraph-bicep-types#275 · 5 comentarios · 1 asignado ·
Todos los issues de microsoftgraph/msgraph-bicep-types
Issues similares
-
bug via-triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
pingdotgg/t3code#14452 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
solana-foundation/program-examples#747 · 1 comentario ·
Los mantenedores suelen responder en 9 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
remotion-dev/remotion#11847 ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
openwatersio/slackwater#355 ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
melgarafael/DeskcommCRM#1998 · 3 comentarios ·
Los mantenedores suelen responder en 1 día