List application/service principal secret
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 25/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Necesita aclaración
- Estado de actividad
- Estancado
- Stack tecnológico
- azure
- Área
- authentication, cloud
Línea de trabajo
Comienza revisando las definiciones de tipos de recursos de Microsoft Graph del repositorio y la compatibilidad de Azure/Bicep relevante para las aplicaciones de Entra y las entidades de servicio. Determina si los valores de secretos se pueden enumerar o crear mediante las operaciones de Graph disponibles y, a continuación, define el comportamiento de recursos compatible y la validación necesaria para los escenarios solicitados.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Is your feature request related to a problem? Please describe.
For Azure resources we have the capability get secrets from some services via list functions (https://learn.microsoft.com/en-us/azure/azure-resource-manager/bicep/bicep-functions-resource#list) or getSecret (https://learn.microsoft.com/en-us/azure/azure-resource-manager/bicep/bicep-functions-resource#getsecret) for Key Vault secrets. As far as I understand there is no such option for Entra applications and service principals.
There are still a lot of Azure services that require application and secret in order to configure something. One such example is credential provider for Azure APIM https://learn.microsoft.com/en-us/azure/api-management/credentials-how-to-azure-ad but of course there are many other. Of course the APIM option is in that format so it can allow external Entra tenants to the APIM instance but in Bicep would be good if you can pull the secret directly by referencing the application, instead of getting the secret value and storing it in Key Vault and pulling it from there. I do not know if this is possible as there might not be the option to pull secret at all from Application besides the first time it is being created. Is there possibility such option to be added? Other method would be to be able to create secrets from Bicep to Entra applications. In such scenarios we should be able to create the secret by specifying its value. We could pull the value from Key Vault so we can add the secret to the application/service principal.
Describe the solution you'd like
A clear and concise description of what you want to happen.
Additional context
Add any other context or screenshots about the feature request here.
- Lenguaje dominante
- TypeScript
- Estrellas
- 81
- Forks
- 15
- Merge medio
- 3 d 8 h
- PR fusionados (30 d)
- 7
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de microsoftgraph/msgraph-bicep-types
-
bug
Dificultad 4/5 3-5 días Aptitud para principiantes 55/100
microsoftgraph/msgraph-bicep-types#311 · 3 comentarios ·
-
enhancement new type
Dificultad 5/5 Más de una semana Aptitud para principiantes 45/100
-
enhancement
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
microsoftgraph/msgraph-bicep-types#304 · 3 comentarios · 1 reacción ·
-
enhancement new type
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
microsoftgraph/msgraph-bicep-types#296 · 2 reacciones ·
-
Issue with servicePrincipals and appRoleAssignedTo in some Entra TenantsQuizá libre de nuevo @eketo-msft la tomó hace 259 días y no hay ningún pull request abierto. Abiertobug
microsoftgraph/msgraph-bicep-types#275 · 5 comentarios · 1 asignado ·
Todos los issues de microsoftgraph/msgraph-bicep-types
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
openedx/frontend-app-authoring#3274 ·
Los mantenedores suelen responder en 1 día
-
🎙️ task - fix(deployer): deploy --env prep runs deploy:dev where the repo declares deploy:prepAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
-
area/documentation status/need-triage
Dificultad 1/5 Menos de una hora Aptitud para principiantes 95/100
google-gemini/gemini-cli#29548 ·
Los mantenedores suelen responder en 1 día
-
sdk-typescript vector-store
Dificultad 2/5 Medio día Aptitud para principiantes 82/100
mem0ai/mem0#7495 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
Los mantenedores suelen responder en 1 día