-
Bug
-
Resolution: Done-Errata
-
Major
-
4.14.0
-
No
-
Rejected
-
False
-
Description of problem:
CredentialsRequest for Azure AD Workload Identity contains unnecessary network permissions. - Microsoft.Network/applicationSecurityGroups/delete - Microsoft.Network/applicationSecurityGroups/write - Microsoft.Network/loadBalancers/delete - Microsoft.Network/networkSecurityGroups/delete - Microsoft.Network/routeTables/delete - Microsoft.Network/routeTables/write - Microsoft.Network/virtualNetworks/subnets/delete - Microsoft.Network/virtualNetworks/subnets/write - Microsoft.Network/virtualNetworks/write - Microsoft.Resources/subscriptions/resourceGroups/delete - Microsoft.Resources/subscriptions/resourceGroups/write
Version-Release number of selected component (if applicable):
4.14.0
How reproducible:
N/A
Steps to Reproduce:
1. Remove above permissions from the Azure Credentials request and validate that MAO continues to function in Azure AD Workload Identity cluster.
Actual results:
Unnecessary network write permissions enumerated in CredentialsRequest.
Expected results:
Only necessary permissions enumerated in CredentialsRequest.
Additional info:
Additional unnecessary permissions will be hard to pin point but these specific permissions were questioned by MSFT and are likely only needed by the installer as output by CORS-1870 investigation.
- is related to
-
OCPCLOUD-2014 Update Azure Credentials Request manifest of the Machine API Operator to use new API field for requesting permissions
- Closed
- links to
-
RHSA-2023:5006 OpenShift Container Platform 4.14.z security update