Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Looks like not possible to deploy workload identity with role microsoft.directory/applications/create in Bicep

Abierto
#154 19 comentarios 0 reacciones 1 asignado Ver en GitHub

@dkershaw10 ya está trabajando en esto.

Desde el 12/7/2024.

Evaluación

Este issue todavía no se ha evaluado.

Descripción

template sample triaged

Bicep version

az bicep version
Bicep CLI version 0.28.1 (ba1e9f8c1e)

Resource and API version
Which Microsoft.Graph resource and API version has the issue?

Microsoft.Graph/[email protected]

Auth flow
User signed to deploy a Bicep script from a command line using az deployment create ... .

Deployment details
I can provide if it makes sense.

Describe the bug
A clear and concise description of what the bug is vs what you expected to happen

I am using the new Bicep Graph module to create a workload identity that can then be assigned to e.g. GitHub to a certain repository. The purpose is to assign further workload identities from this repository that are defined in Bicep files there.

When I try to deploy a service principal with a role that I think has some of the right assignableScopes, I get an error

see https://aka.ms/arm-deployment-operations for usage details.","details":[{"code":"InvalidActionOrNotAction","message":"The resource provider referenced in the action 'microsoft.directory/applications/create' is not returned in the list of providers from Azure Resource Manager."}]}]}]}}

It feels to me I should be able do to this in Bicep and just put wrong assignableScopes. But on the other hand there's probably more into this. This may be related to https://github.com/microsoftgraph/msgraph-bicep-types/issues/134. I am not sure if this is a bug or would be a feature. It may also very well be I don't know just how to make this happen in Bicep. :)

To Reproduce
Additional context

The Bicep I use are like follows. I have permuted all kinds of things to assignableScopes, but as expected, the error message stays the same.


main.bicep:

resource azureRootManagementGroup 'Microsoft.Management/managementGroups@2023-04-01' existing = {
    scope: tenant()
    name: '<guid>'
}

var applicationIdentityRegistrationDisplayName = 'GitHub Actions Identity Application Deployer'
var applicationIdentityRegistrationName = 'root-appident-deployer'
var githubOIDCProvider = 'https://token.actions.githubusercontent.com'
var microsoftEntraAudience = 'api://AzureADTokenExchange'
var gitHubActionsFederatedIdentitySubject = 'repo:${gitHubOwner}/${gitHubRepo}:ref:refs/heads/main'
resource identityGithubActionsApplication 'Microsoft.Graph/[email protected]' = {
  uniqueName: applicationIdentityRegistrationName
  displayName: applicationIdentityRegistrationDisplayNamef

  resource githubFederatedIdentityCredential '[email protected]' = {
    name: '${identityGithubActionsApplication.uniqueName}/githubFederatedIdentityCredential'
    audiences: [microsoftEntraAudience]
    description: 'Identity for application to deploy the root identity infrastructure.'
    issuer: githubOIDCProvider
    subject: gitHubActionsFederatedIdentitySubject
    }
}

resource gitHubIdentityActionsServicePrincipal 'Microsoft.Graph/[email protected]' = {
  displayName: applicationIdentityRegistrationDisplayName
  appId: identityGithubActionsApplication.appId
}

module companyIdentityPipelineRoleDefinitionAndAssignment './companyIdentityPipelineRoleDefinitionAndAssignment.bicep' = {
  name: 'bootstrapIdentityRoleDeployment'
  scope: tenant()
  params: {
    gitHubIdentityActionsServicePrincipalId: gitHubIdentityActionsServicePrincipal.id
    azureRootManagementGroupId: azureRootManagementGroup.name
  }
}

companyIdentityPipelineRoleDefinitionAndAssignment.bicep:

param azureRootManagementGroupName string

resource companyIdentityPipelineRoleDefinitionAndAssignment  'Microsoft.Authorization/roleDefinitions@2022-04-01' = {
  name: guid(tenant().tenantId, 'CompanyIdentityPipelineRole')
  properties: {
    roleName: ' identity deployment role'
    description: 'Grants rights to manage  identity resources.'
    type: 'CustomRole'
    assignableScopes: [
      /* Here e.g. slash, '/' won't work. */
      '/providers/Microsoft.Management/managementGroups/${azureRootManagementGroupName}'
    ]
    permissions: [
      {
        actions: [
            'microsoft.directory/applications/create'
            'microsoft.directory/applications/read'
            'microsoft.directory/applications/credentials/update'            
            'microsoft.directory/servicePrincipals/create'
            'microsoft.directory/servicePrincipals/read'
            'microsoft.directory/servicePrincipals/credentials/update'
        ]
        notActions: []
        dataActions: []
        notDataActions: []
      }
    ]
  }
}
Lenguaje dominante
TypeScript
Estrellas
81
Forks
15
Merge medio
3 d 8 h
PR fusionados (30 d)
7

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de microsoftgraph/msgraph-bicep-types

Todos los issues de microsoftgraph/msgraph-bicep-types

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.