Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

azure: fix ccm config with correct uami client_id #2144

Merged
merged 2 commits into from
Aug 1, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions cli/internal/terraform/terraform.go
Original file line number Diff line number Diff line change
Expand Up @@ -254,13 +254,13 @@ func (c *Client) ShowCluster(ctx context.Context, provider cloudprovider.Provide
}
}

azureUAMIOutput, ok := tfState.Values.Outputs["user_assigned_identity"]
azureUAMIOutput, ok := tfState.Values.Outputs["user_assigned_identity_client_id"]
if !ok {
return ApplyOutput{}, errors.New("no user_assigned_identity output found")
return ApplyOutput{}, errors.New("no user_assigned_identity_client_id output found")
}
azureUAMI, ok := azureUAMIOutput.Value.(string)
if !ok {
return ApplyOutput{}, errors.New("invalid type in user_assigned_identity output: not a string")
return ApplyOutput{}, errors.New("invalid type in user_assigned_identity_client_id output: not a string")
}

rgOutput, ok := tfState.Values.Outputs["resource_group"]
Expand Down
7 changes: 7 additions & 0 deletions cli/internal/terraform/terraform/azure/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,8 @@ locals {
// wildcard_lb_dns_name is the DNS name of the load balancer with a wildcard for the name.
// example: given "name-1234567890.location.cloudapp.azure.com" it will return "*.location.cloudapp.azure.com"
wildcard_lb_dns_name = replace(data.azurerm_public_ip.loadbalancer_ip.fqdn, "/^[^.]*\\./", "*.")
uai_resource_group = element(split("/", var.user_assigned_identity), 4) // deduce from format /$ID/resourceGroups/$RG/providers/Microsoft.ManagedIdentity/userAssignedIdentities/$NAME"
uai_name = element(split("/", var.user_assigned_identity), length(split("/", var.user_assigned_identity)) - 1) // deduce as above
}

resource "random_id" "uid" {
Expand Down Expand Up @@ -280,6 +282,11 @@ module "scale_set_group" {
data "azurerm_subscription" "current" {
}

data "azurerm_user_assigned_identity" "uaid" {
name = local.uai_name
resource_group_name = local.uai_resource_group
}

moved {
from = module.scale_set_control_plane
to = module.scale_set_group["control_plane_default"]
Expand Down
4 changes: 2 additions & 2 deletions cli/internal/terraform/terraform/azure/outputs.tf
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,8 @@ output "loadbalancer_name" {
}


output "user_assigned_identity" {
value = var.user_assigned_identity
output "user_assigned_identity_client_id" {
value = data.azurerm_user_assigned_identity.uaid.client_id
}

output "resource_group" {
Expand Down
2 changes: 1 addition & 1 deletion cli/internal/terraform/terraform/azure/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ variable "resource_group" {
}
variable "user_assigned_identity" {
type = string
description = "The name of the user assigned identity to attache to the nodes of the cluster."
description = "The name of the user assigned identity to attach to the nodes of the cluster. Should be of format: /subscriptions/$ID/resourceGroups/$RG/providers/Microsoft.ManagedIdentity/userAssignedIdentities/$NAME"
}

variable "custom_endpoint" {
Expand Down
3 changes: 2 additions & 1 deletion cli/internal/terraform/terraform/iam/azure/outputs.tf
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,6 @@ output "tenant_id" {
}

output "uami_id" {
value = azurerm_user_assigned_identity.identity_uami.id
description = "Outputs the id in the format: /$ID/resourceGroups/$RG/providers/Microsoft.ManagedIdentity/userAssignedIdentities/$NAME. Not to be confused with the client_id"
value = azurerm_user_assigned_identity.identity_uami.id
}
2 changes: 1 addition & 1 deletion cli/internal/terraform/terraform_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -248,7 +248,7 @@ func TestCreateCluster(t *testing.T) {
"api_server_cert_sans": {
Value: []any{"192.0.2.100"},
},
"user_assigned_identity": {
"user_assigned_identity_client_id": {
Value: "test_uami_id",
},
"resource_group": {
Expand Down