-
Bug
-
Resolution: Done
-
Major
-
4.14, 4.15, 4.16, 4.17, 4.18
-
Quality / Stability / Reliability
-
False
-
-
None
-
None
-
None
-
None
-
None
-
None
-
Done
-
Release Note Not Required
-
N/A
-
None
-
None
-
None
-
None
This is a clone of issue OCPBUGS-52359. The following is the description of the original issue:
—
This is a clone of issue OCPBUGS-44056. The following is the description of the original issue:
—
https://github.com/openshift/machine-api-provider-azure/tree/main/pkg/cloud/azure/services/virtualnetworks
This package is not used within MAPI, but its presence indicates that the operator needs permissions over VNets, specifically to delete VNets. This is a sensitive permission that if exercised could lead to an unrecoverable cluster, or deletion of other critical infrastructure within the same Azure subscription or resource group that's not related to the cluster itself. This package should be removed as well as the relevant permissions from the CredentialsRequest.
- clones
-
OCPBUGS-52359 MAPI operator for Azure has overly permissive actions over VNets
-
- Verified
-
- is blocked by
-
OCPBUGS-52359 MAPI operator for Azure has overly permissive actions over VNets
-
- Verified
-
- links to