Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-17872

Azure MAO CredentialsRequest contains unnecessary network write permissions

XMLWordPrintable

    • No
    • Rejected
    • False
    • Hide

      None

      Show
      None

      Description of problem:

      CredentialsRequest for Azure AD Workload Identity contains unnecessary network permissions.
      
      - Microsoft.Network/applicationSecurityGroups/delete
      - Microsoft.Network/applicationSecurityGroups/write
      - Microsoft.Network/loadBalancers/delete
      - Microsoft.Network/networkSecurityGroups/delete
      - Microsoft.Network/routeTables/delete
      - Microsoft.Network/routeTables/write
      - Microsoft.Network/virtualNetworks/subnets/delete
      - Microsoft.Network/virtualNetworks/subnets/write
      - Microsoft.Network/virtualNetworks/write
      - Microsoft.Resources/subscriptions/resourceGroups/delete
      - Microsoft.Resources/subscriptions/resourceGroups/write

      Version-Release number of selected component (if applicable):

      4.14.0

      How reproducible:

      N/A

      Steps to Reproduce:

      1. Remove above permissions from the Azure Credentials request and validate that MAO continues to function in Azure AD Workload Identity cluster.

      Actual results:

      Unnecessary network write permissions enumerated in CredentialsRequest.

      Expected results:

      Only necessary permissions enumerated in CredentialsRequest.

      Additional info:

      Additional unnecessary permissions will be hard to pin point but these specific permissions were questioned by MSFT and are likely only needed by the installer as output by CORS-1870 investigation.

              abutcher@redhat.com Andrew Butcher
              abutcher@redhat.com Andrew Butcher
              Zhaohua Sun Zhaohua Sun
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: