Skip to content

Rely on AAD backend auth #40

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Aug 31, 2023
Merged

Rely on AAD backend auth #40

merged 1 commit into from
Aug 31, 2023

Conversation

marvinbuss
Copy link
Contributor

Proposed changes:

  • Rely on AAD backend auth

@marvinbuss marvinbuss self-assigned this Aug 31, 2023
@marvinbuss marvinbuss added the enhancement New feature or request label Aug 31, 2023
@github-actions
Copy link

Terraform Lint Results

  • Terraform Version 📎1.4.6
  • Working Directory 📂./code/infra
  • Terraform Format and Style 🖌success

@marvinbuss marvinbuss temporarily deployed to dev August 31, 2023 09:14 — with GitHub Actions Inactive
@github-actions
Copy link

Terraform Validation & Plan Results

  • Terraform Version 📎1.4.6
  • Working Directory 📂./code/infra
  • Terraform Initialization ⚙️success
  • Terraform Validation 🤖success
  • Terraform Plan 📖success
Show Plan

terraform
�[0m�[1mdata.azurerm_network_security_group.network_security_group: Reading...�[0m�[0m
�[0m�[1mdata.azurerm_client_config.current: Reading...�[0m�[0m
�[0m�[1mdata.azurerm_route_table.route_table: Reading...�[0m�[0m
�[0m�[1mdata.azurerm_virtual_network.virtual_network: Reading...�[0m�[0m
�[0m�[1mazurerm_resource_group.app_rg: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg]�[0m
�[0m�[1mazurerm_resource_group.logging_rg: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-logging-rg]�[0m
�[0m�[1mdata.azurerm_client_config.current: Read complete after 0s [id=Y2xpZW50Q29uZmlncy9jbGllbnRJZD1iYWFhNzg4NS05MGQ5LTQ5YTYtYmZmMC1jMTJlYzczOGJmOWI7b2JqZWN0SWQ9ZTlmOGE5ZDUtMmI0ZC00ZDY1LTg1ZTMtZGNiNmVmNDk4OGJlO3N1YnNjcmlwdGlvbklkPThmMTcxZmY5LTJiNWItNGYwZi1hZWQ1LTdmYTM2MGExZDA5NDt0ZW5hbnRJZD0zNTU2YmU3OS0yOTc5LTRiMTktYTFhZi00ZGQ0ZTZkOWVkN2U=]�[0m
�[0m�[1mazurerm_monitor_private_link_scope.mpls: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-logging-rg/providers/Microsoft.Insights/privateLinkScopes/myfunc-dev-ampls001]�[0m
�[0m�[1mazurerm_service_plan.service_plan: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Web/serverfarms/myfunc-dev-asp001]�[0m
�[0m�[1mazurerm_key_vault.key_vault: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.KeyVault/vaults/myfunc-dev-vault001]�[0m
�[0m�[1mazurerm_storage_account.storage: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Storage/storageAccounts/myfuncdevstg001]�[0m
�[0m�[1mazurerm_log_analytics_workspace.log_analytics_workspace: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-logging-rg/providers/Microsoft.OperationalInsights/workspaces/myfunc-dev-log001]�[0m
�[0m�[1mdata.azurerm_network_security_group.network_security_group: Read complete after 0s [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/mycrp-prd-function-network-rg/providers/Microsoft.Network/networkSecurityGroups/mycrp-prd-function-nsg001]�[0m
�[0m�[1mdata.azurerm_route_table.route_table: Read complete after 0s [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/mycrp-prd-function-network-rg/providers/Microsoft.Network/routeTables/mycrp-prd-function-rt001]�[0m
�[0m�[1mdata.azurerm_virtual_network.virtual_network: Read complete after 0s [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/mycrp-prd-function-network-rg/providers/Microsoft.Network/virtualNetworks/mycrp-prd-function-vnet001]�[0m
�[0m�[1mazapi_resource.subnet_function: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/mycrp-prd-function-network-rg/providers/Microsoft.Network/virtualNetworks/mycrp-prd-function-vnet001/subnets/FunctionSubnet]�[0m
�[0m�[1mazapi_resource.subnet_services: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/mycrp-prd-function-network-rg/providers/Microsoft.Network/virtualNetworks/mycrp-prd-function-vnet001/subnets/PeSubnet]�[0m
�[0m�[1mdata.azurerm_monitor_diagnostic_categories.diagnostic_categories_storage: Reading...�[0m�[0m
�[0m�[1mazurerm_storage_management_policy.storage_management_policy: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Storage/storageAccounts/myfuncdevstg001/managementPolicies/default]�[0m
�[0m�[1mazapi_resource.storage_file_share: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Storage/storageAccounts/myfuncdevstg001/fileServices/default/shares/logicapp]�[0m
�[0m�[1mdata.azurerm_monitor_diagnostic_categories.diagnostic_categories_storage: Read complete after 0s [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Storage/storageAccounts/myfuncdevstg001]�[0m
�[0m�[1mdata.azurerm_monitor_diagnostic_categories.diagnostic_categories_key_vault: Reading...�[0m�[0m
�[0m�[1mazurerm_role_assignment.current_role_assignment_key_vault: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.KeyVault/vaults/myfunc-dev-vault001/providers/Microsoft.Authorization/roleAssignments/ee0c54e7-f69a-0c60-8af8-855b820d5af2]�[0m
�[0m�[1mazurerm_private_endpoint.key_vault_private_endpoint: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Network/privateEndpoints/myfunc-dev-vault001-pe]�[0m
�[0m�[1mdata.azurerm_monitor_diagnostic_categories.diagnostic_categories_key_vault: Read complete after 0s [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.KeyVault/vaults/myfunc-dev-vault001]�[0m
�[0m�[1mazurerm_private_endpoint.storage_private_endpoint_queue: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Network/privateEndpoints/myfuncdevstg001-queue-pe]�[0m
�[0m�[1mazurerm_private_endpoint.storage_private_endpoint_file: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Network/privateEndpoints/myfuncdevstg001-file-pe]�[0m
�[0m�[1mazurerm_private_endpoint.storage_private_endpoint_table: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Network/privateEndpoints/myfuncdevstg001-table-pe]�[0m
�[0m�[1mazurerm_private_endpoint.mpls_private_endpoint: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-logging-rg/providers/Microsoft.Network/privateEndpoints/myfunc-dev-ampls001-pe]�[0m
�[0m�[1mazurerm_private_endpoint.storage_private_endpoint_blob: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Network/privateEndpoints/myfuncdevstg001-blob-pe]�[0m
�[0m�[1mazurerm_key_vault_secret.key_vault_secret_sample: Refreshing state... [id=https://myfunc-dev-vault001.vault.azure.net/secrets/MySampleSecret/fb47dff75e5c4db5b89a04e56f5c0fb1]�[0m
�[0m�[1mazurerm_monitor_private_link_scoped_service.mpls_log_analytics_workspace: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-logging-rg/providers/Microsoft.Insights/privateLinkScopes/myfunc-dev-ampls001/scopedResources/ampls-myfunc-dev-log001]�[0m
�[0m�[1mdata.azurerm_monitor_diagnostic_categories.diagnostic_categories_log_analytics_workspace: Reading...�[0m�[0m
�[0m�[1mazurerm_monitor_diagnostic_setting.diagnostic_setting_service_plan: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Web/serverfarms/myfunc-dev-asp001|logAnalytics]�[0m
�[0m�[1mazurerm_monitor_diagnostic_setting.diagnostic_setting_key_vault: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.KeyVault/vaults/myfunc-dev-vault001|logAnalytics]�[0m
�[0m�[1mazurerm_monitor_diagnostic_setting.diagnostic_setting_storage: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Storage/storageAccounts/myfuncdevstg001|logAnalytics]�[0m
�[0m�[1mazurerm_application_insights.application_insights: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-logging-rg/providers/Microsoft.Insights/components/myfunc-dev-appi001]�[0m
�[0m�[1mdata.azurerm_monitor_diagnostic_categories.diagnostic_categories_log_analytics_workspace: Read complete after 0s [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-logging-rg/providers/Microsoft.OperationalInsights/workspaces/myfunc-dev-log001]�[0m
�[0m�[1mazurerm_monitor_diagnostic_setting.diagnostic_setting_log_analytics_workspace: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-logging-rg/providers/Microsoft.OperationalInsights/workspaces/myfunc-dev-log001|logAnalytics]�[0m
�[0m�[1mdata.azurerm_monitor_diagnostic_categories.diagnostic_categories_application_insights: Reading...�[0m�[0m
�[0m�[1mazurerm_monitor_private_link_scoped_service.mpls_application_insights: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-logging-rg/providers/Microsoft.Insights/privateLinkScopes/myfunc-dev-ampls001/scopedResources/ampls-myfunc-dev-appi001]�[0m
�[0m�[1mazapi_resource.function: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Web/sites/myfunc-dev-fctn001]�[0m
�[0m�[1mdata.azurerm_monitor_diagnostic_categories.diagnostic_categories_application_insights: Read complete after 0s [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-logging-rg/providers/Microsoft.Insights/components/myfunc-dev-appi001]�[0m
�[0m�[1mazurerm_monitor_diagnostic_setting.diagnostic_setting_application_insights: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-logging-rg/providers/Microsoft.Insights/components/myfunc-dev-appi001|logAnalytics]�[0m
�[0m�[1mazurerm_role_assignment.function_role_assignment_storage: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Storage/storageAccounts/myfuncdevstg001/providers/Microsoft.Authorization/roleAssignments/b93591fa-c2c8-b793-4f71-3ed3a77316ac]�[0m
�[0m�[1mazurerm_role_assignment.function_role_assignment_key_vault: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.KeyVault/vaults/myfunc-dev-vault001/providers/Microsoft.Authorization/roleAssignments/81e022d5-d995-4d97-be83-489519e158ff]�[0m
�[0m�[1mazurerm_private_endpoint.function_private_endpoint: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Network/privateEndpoints/myfunc-dev-fctn001-pe]�[0m
�[0m�[1mazurerm_monitor_diagnostic_setting.diagnostic_setting_function: Refreshing state... [id=/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Web/sites/myfunc-dev-fctn001|logAnalytics]�[0m

Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  �[33m~�[0m update in-place�[0m
 �[36m<=�[0m read (data resources)�[0m

Terraform will perform the following actions:

�[1m  # data.azurerm_monitor_diagnostic_categories.diagnostic_categories_function�[0m will be read during apply
  # (depends on a resource or a module with changes pending)
�[0m �[36m<=�[0m�[0m data "azurerm_monitor_diagnostic_categories" "diagnostic_categories_function" {
      �[32m+�[0m�[0m id                  = (known after apply)
      �[32m+�[0m�[0m log_category_groups = (known after apply)
      �[32m+�[0m�[0m log_category_types  = (known after apply)
      �[32m+�[0m�[0m logs                = (known after apply)
      �[32m+�[0m�[0m metrics             = (known after apply)
      �[32m+�[0m�[0m resource_id         = "/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Web/sites/myfunc-dev-fctn001"
    }

�[1m  # data.azurerm_monitor_diagnostic_categories.diagnostic_categories_service_plan�[0m will be read during apply
  # (depends on a resource or a module with changes pending)
�[0m �[36m<=�[0m�[0m data "azurerm_monitor_diagnostic_categories" "diagnostic_categories_service_plan" {
      �[32m+�[0m�[0m id                  = (known after apply)
      �[32m+�[0m�[0m log_category_groups = (known after apply)
      �[32m+�[0m�[0m log_category_types  = (known after apply)
      �[32m+�[0m�[0m logs                = (known after apply)
      �[32m+�[0m�[0m metrics             = (known after apply)
      �[32m+�[0m�[0m resource_id         = "/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Web/serverfarms/myfunc-dev-asp001"
    }

�[1m  # azapi_resource.function�[0m will be updated in-place
�[0m  �[33m~�[0m�[0m resource "azapi_resource" "function" {
      �[33m~�[0m�[0m body                      = (sensitive value)
        id                        = "/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Web/sites/myfunc-dev-fctn001"
        name                      = "myfunc-dev-fctn001"
      �[33m~�[0m�[0m output                    = jsonencode({}) -> (known after apply)
        tags                      = {}
        �[90m# (7 unchanged attributes hidden)�[0m�[0m

        �[90m# (1 unchanged block hidden)�[0m�[0m
    }

�[1m  # azurerm_monitor_diagnostic_setting.diagnostic_setting_function�[0m will be updated in-place
�[0m  �[33m~�[0m�[0m resource "azurerm_monitor_diagnostic_setting" "diagnostic_setting_function" {
        id                         = "/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Web/sites/myfunc-dev-fctn001|logAnalytics"
        name                       = "logAnalytics"
        �[90m# (2 unchanged attributes hidden)�[0m�[0m

      �[31m-�[0m�[0m metric {
          �[31m-�[0m�[0m category = "AllMetrics" �[90m-> null�[0m�[0m
          �[31m-�[0m�[0m enabled  = true �[90m-> null�[0m�[0m

          �[31m-�[0m�[0m retention_policy {
              �[31m-�[0m�[0m days    = 30 �[90m-> null�[0m�[0m
              �[31m-�[0m�[0m enabled = true �[90m-> null�[0m�[0m
            }
        }

        �[90m# (4 unchanged blocks hidden)�[0m�[0m
    }

�[1m  # azurerm_monitor_diagnostic_setting.diagnostic_setting_service_plan�[0m will be updated in-place
�[0m  �[33m~�[0m�[0m resource "azurerm_monitor_diagnostic_setting" "diagnostic_setting_service_plan" {
        id                         = "/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Web/serverfarms/myfunc-dev-asp001|logAnalytics"
        name                       = "logAnalytics"
        �[90m# (2 unchanged attributes hidden)�[0m�[0m

      �[31m-�[0m�[0m metric {
          �[31m-�[0m�[0m category = "AllMetrics" �[90m-> null�[0m�[0m
          �[31m-�[0m�[0m enabled  = true �[90m-> null�[0m�[0m

          �[31m-�[0m�[0m retention_policy {
              �[31m-�[0m�[0m days    = 30 �[90m-> null�[0m�[0m
              �[31m-�[0m�[0m enabled = true �[90m-> null�[0m�[0m
            }
        }
    }

�[1m  # azurerm_service_plan.service_plan�[0m will be updated in-place
�[0m  �[33m~�[0m�[0m resource "azurerm_service_plan" "service_plan" {
        id                           = "/subscriptions/8f171ff9-2b5b-4f0f-aed5-7fa360a1d094/resourceGroups/myfunc-dev-app-rg/providers/Microsoft.Web/serverfarms/myfunc-dev-asp001"
        name                         = "myfunc-dev-asp001"
      �[33m~�[0m�[0m sku_name                     = "B1" �[33m->�[0m�[0m "P1v3"
        tags                         = {}
        �[90m# (9 unchanged attributes hidden)�[0m�[0m
    }

�[1mPlan:�[0m 0 to add, 4 to change, 0 to destroy.
�[0m�[90m
─────────────────────────────────────────────────────────────────────────────�[0m

Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.

@marvinbuss marvinbuss marked this pull request as ready for review August 31, 2023 09:15
Copy link
Contributor Author

@marvinbuss marvinbuss left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@marvinbuss marvinbuss merged commit d2e7e40 into main Aug 31, 2023
@marvinbuss marvinbuss deleted the marvinbuss/azure_ad_auth branch August 31, 2023 09:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant