- 
                Notifications
    You must be signed in to change notification settings 
- Fork 3
fix: add missing Authorization Delegator role to s2s auth policy #554
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
| /run pipeline | 
| /run pipeline | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It is trivial, can we drop the word backup from the main encryption key in both places.
| source_service_name = "databases-for-elasticsearch" | ||
| source_resource_group_id = module.resource_group.resource_group_id | ||
| roles = ["Reader"] | ||
| roles = ["Reader", "Authorization Delegator"] # Authorization Delegator role required for backup encryption key | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is not the backup key.
| source_service_name = "databases-for-elasticsearch" | ||
| source_resource_group_id = var.resource_group_id | ||
| roles = ["Reader"] | ||
| roles = ["Reader", "Authorization Delegator"] # Authorization Delegator role required for backup encryption key | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is not the backup key
| @shemau They could be the backup key. If user doesn't explicitly pick a different key for backup, then the same one used for data encryption is used. Hence why I added to both policies | 
| /run pipeline | 
Description
Any key that is used for backup encryption also requires the "Authorization Delegator" role. This is also stated in the docs:

NOTE: I expect upgrade test fail but won't skip it until its confirmed auth policy will be update in place
Release required?
x.x.X)x.X.x)X.x.x)Release notes content
Run the pipeline
If the CI pipeline doesn't run when you create the PR, the PR requires a user with GitHub collaborators access to run the pipeline.
Run the CI pipeline when the PR is ready for review and you expect tests to pass. Add a comment to the PR with the following text:
Checklist for reviewers
For mergers