feat: Subscription Vending PTN - UMI Role Assignments absolute scopes#6929
feat: Subscription Vending PTN - UMI Role Assignments absolute scopes#6929nsftwr wants to merge 1 commit intoAzure:mainfrom
Conversation
|
Important The "Needs: Triage 🔍" label must be removed once the triage process is complete! Tip For additional guidance on how to triage this issue/PR, see the BRM Issue Triage documentation. |
|
Important If this is a module-related PR, being submitted by the sole owner of the module, the AVM core team must review and approve it (as module owners can't approve their own PRs). To indicate this PR needs the core team''s attention, apply the "Needs: Core Team 🧞" label! The core team will only review and approve PRs that have this label applied! |
|
@sebassem what are your thoughts on this? Happy to also get on a call if need be to explain the thought, but essentially the idea is that a UMI can be provisioned together with the vended sub, but have the role assigned in a different sub or management group like connectivity sub, having the Private DNS Zone Contributor role. The current implementation adds an
Let me know what are your thoughts. I havent done any of the AVM specific bits, nor tests as wanted to get feedback first |
Description
The ability to assign roles to UMI's out of the scope of the provisioned subscription. It is incredibly useful if youre vending a subscription with a user managed identity, and the provisioned UMI needs to have a role in a different sub, like Private DNS Zone Contributor in the Connectivity Subscription.
Pipeline Reference
Type of Change
version.json:version.json.version.json.Checklist
Set-AVMModulelocally to generate the supporting module files.