Validate workflow "hangs" on unauthorized template deployment #629

Description

Discussed in #628

Originally posted by matthewponzio May 17, 2022

Summary

I am continuing to PoC the concept of implementing AzOps Repos with various levels of permissions. Our intention would be to recommend something like the following:

Foundation Repo

  • Owner: Central Cloud Engineering Team
  • Scope: Manages the Azure foundation, inclusive of the entire Management Group hierarchy and the Platform Subscriptions and all constituent Resource Groups / Resources

Landing Zones Repo(s)

  • Owner: Central Cloud Engineering Team
  • Scope: Manages the Landing Zone (App Workload) Subscriptions - provisioning of the Subscriptions, Policies, RBAC and any centrally managed Resource Groups / Resources, such as networking.

Workload/App Repos

  • Owner: App Team
  • Scope: Provision and manage Application level Resource Groups and Resources

Based on this structure, the Workload/App Repo would utilize an SPN with limited permissions. For example, it would not have permission to read/write certain network resources.

Issue

I implemented the above setup and have tested it to pretty good success, however when I attempted to test making an unauthorized change from the Workload/App Repo (a change to the virtualNetwork subnet), the Validate pipeline appeared to "hang" during the Validate Step. I let it run for about 20 minutes before I manually cancelled the Workflow. Upon cancellation, you can see in the Validate Step log that it actually worked as intended, returning the following authorization error:

WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client '<redacted>' with object id '<redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.

The issue or unexpected behavior is that the pipeline didn't fail "quickly". Admittedly, this is a fairly minor issue, but nevertheless, an authorization error should probably fail the pipeline/workflow immediately.

Expected Behavior

When a Workflow attempts to validate or execute a deployment containing an unauthorized action, the workflow fails almost immediately.

Observed Behavior

The Workflow continued to run, appearing to hang during the Validate Step. Workflow ran for 20 minutes before manual cancellation. Manually cancelling the Workflow worked and revealed the expected authorization error.

Steps to Reproduce

  1. Create an AzOps Repo that uses an SPN with some kind of limited permission set
  2. Open a PR with a change that would not be authorized by the limited permission set
  3. See that the Validate Workflow continues run, appearing to hang
  4. Manually cancel the Workflow and verify that the expected authorization was returned

Full Log from Validate Step

Prepare all required actions
Run ./.github/actions/validate-deploy
Run if [ ! -z "$(git diff --name-status HEAD^ HEAD)" ]; then
M root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
Run Import-PSFConfig -Path settings.json -Schema MetaJson -EnableException
[[2](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:2)2:43:25][Initialize-AzOpsEnvironment] Processing AzOps environment
[22:43:25][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
[22:43:25][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
[22:43:26][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_20[15](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:15)-09-01
[22:43:27][Get-AzOpsSubscription] Number of subscriptions found: 1
[22:43:27][Get-AzOpsSubscription] Number of subscriptions included: 1
WARNING: [22:43:31][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
[22:43:31][Initialize-AzOpsEnvironment] Processing AzOps environment
[22:43:31][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
[22:43:31][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
[22:43:31][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_2015-09-01
[22:43:32][Get-AzOpsSubscription] Number of subscriptions found: 1
[22:43:32][Get-AzOpsSubscription] Number of subscriptions included: 1
WARNING: [22:43:36][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
[22:43:36][Invoke-AzOpsPush] Deployment required
[22:43:36][Invoke-AzOpsPush] Adding or modifying:
[22:43:36][Invoke-AzOpsPush] root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
[22:43:36][Invoke-AzOpsPush] Deleting:
[22:43:[37](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:37)][New-AzOpsDeployment] Processing deployment AzOps-microsoft.network_virtualnetworks_subnets-corp1-vnet1-B9EE for template /home/runner/work/azure-adventureworks-app1/azure-adventureworks-app1/root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json with parameter "" in mode Incremental
Getting the latest status of all resources...
Get-AzResourceGroupDeploymentWhatIfResult: InvalidTemplateDeployment - Long running operation failed with status
'Failed'. Additional Info:'The template deployment failed with error:
'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
of type 'Microsoft.Network/virtualNetworks/subnets'. The client
'[72](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:72)0e91c6-f516-44f1-af0f-f21e2[75](https://github.com/recacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:75)30c88' with object id
'redacted' does not have permission to perform
action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
'/subscriptions/***/resourceGroups/cloud-eng-ne
twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
1-subnet1'.'.'
WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client 'redacted' with object id 'redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.'
Exception: InvalidTemplateDeployment - Long running operation failed with status
'Failed'. Additional Info:'The template deployment failed with error:
'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
of type 'Microsoft.Network/virtualNetworks/subnets'. The client
'redacted' with object id
'redacted' does not have permission to perform
action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
'/subscriptions/***/resourceGroups/cloud-eng-ne
twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
1-subnet1'.'.'
Error: The operation was canceled.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

waiting-for-responseMaintainers have replied and are awaiting a response from the bug/issue/feature creator

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

    , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
     blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
    }
    } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
    })();
    (function(){
    try {
    var __m = "github.com";
    var __re = new RegExp('^' + "github\\.com" + '
    
    Skip to content

    Validate workflow "hangs" on unauthorized template deployment #629

    Description

    Discussed in #628

    Originally posted by matthewponzio May 17, 2022

    Summary

    I am continuing to PoC the concept of implementing AzOps Repos with various levels of permissions. Our intention would be to recommend something like the following:

    Foundation Repo

    • Owner: Central Cloud Engineering Team
    • Scope: Manages the Azure foundation, inclusive of the entire Management Group hierarchy and the Platform Subscriptions and all constituent Resource Groups / Resources

    Landing Zones Repo(s)

    • Owner: Central Cloud Engineering Team
    • Scope: Manages the Landing Zone (App Workload) Subscriptions - provisioning of the Subscriptions, Policies, RBAC and any centrally managed Resource Groups / Resources, such as networking.

    Workload/App Repos

    • Owner: App Team
    • Scope: Provision and manage Application level Resource Groups and Resources

    Based on this structure, the Workload/App Repo would utilize an SPN with limited permissions. For example, it would not have permission to read/write certain network resources.

    Issue

    I implemented the above setup and have tested it to pretty good success, however when I attempted to test making an unauthorized change from the Workload/App Repo (a change to the virtualNetwork subnet), the Validate pipeline appeared to "hang" during the Validate Step. I let it run for about 20 minutes before I manually cancelled the Workflow. Upon cancellation, you can see in the Validate Step log that it actually worked as intended, returning the following authorization error:

    WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client '<redacted>' with object id '<redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.
    

    The issue or unexpected behavior is that the pipeline didn't fail "quickly". Admittedly, this is a fairly minor issue, but nevertheless, an authorization error should probably fail the pipeline/workflow immediately.

    Expected Behavior

    When a Workflow attempts to validate or execute a deployment containing an unauthorized action, the workflow fails almost immediately.

    Observed Behavior

    The Workflow continued to run, appearing to hang during the Validate Step. Workflow ran for 20 minutes before manual cancellation. Manually cancelling the Workflow worked and revealed the expected authorization error.

    Steps to Reproduce

    1. Create an AzOps Repo that uses an SPN with some kind of limited permission set
    2. Open a PR with a change that would not be authorized by the limited permission set
    3. See that the Validate Workflow continues run, appearing to hang
    4. Manually cancel the Workflow and verify that the expected authorization was returned

    Full Log from Validate Step

    Prepare all required actions
    Run ./.github/actions/validate-deploy
    Run if [ ! -z "$(git diff --name-status HEAD^ HEAD)" ]; then
    M root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
    Run Import-PSFConfig -Path settings.json -Schema MetaJson -EnableException
    [[2](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:2)2:43:25][Initialize-AzOpsEnvironment] Processing AzOps environment
    [22:43:25][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
    [22:43:25][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
    [22:43:26][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_20[15](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:15)-09-01
    [22:43:27][Get-AzOpsSubscription] Number of subscriptions found: 1
    [22:43:27][Get-AzOpsSubscription] Number of subscriptions included: 1
    WARNING: [22:43:31][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
    [22:43:31][Initialize-AzOpsEnvironment] Processing AzOps environment
    [22:43:31][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
    [22:43:31][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
    [22:43:31][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_2015-09-01
    [22:43:32][Get-AzOpsSubscription] Number of subscriptions found: 1
    [22:43:32][Get-AzOpsSubscription] Number of subscriptions included: 1
    WARNING: [22:43:36][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
    [22:43:36][Invoke-AzOpsPush] Deployment required
    [22:43:36][Invoke-AzOpsPush] Adding or modifying:
    [22:43:36][Invoke-AzOpsPush] root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
    [22:43:36][Invoke-AzOpsPush] Deleting:
    [22:43:[37](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:37)][New-AzOpsDeployment] Processing deployment AzOps-microsoft.network_virtualnetworks_subnets-corp1-vnet1-B9EE for template /home/runner/work/azure-adventureworks-app1/azure-adventureworks-app1/root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json with parameter "" in mode Incremental
    Getting the latest status of all resources...
    Get-AzResourceGroupDeploymentWhatIfResult: InvalidTemplateDeployment - Long running operation failed with status
    'Failed'. Additional Info:'The template deployment failed with error:
    'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
    of type 'Microsoft.Network/virtualNetworks/subnets'. The client
    '[72](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:72)0e91c6-f516-44f1-af0f-f21e2[75](https://github.com/recacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:75)30c88' with object id
    'redacted' does not have permission to perform
    action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
    '/subscriptions/***/resourceGroups/cloud-eng-ne
    twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
    1-subnet1'.'.'
    WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client 'redacted' with object id 'redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.'
    Exception: InvalidTemplateDeployment - Long running operation failed with status
    'Failed'. Additional Info:'The template deployment failed with error:
    'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
    of type 'Microsoft.Network/virtualNetworks/subnets'. The client
    'redacted' with object id
    'redacted' does not have permission to perform
    action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
    '/subscriptions/***/resourceGroups/cloud-eng-ne
    twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
    1-subnet1'.'.'
    Error: The operation was canceled.
    

    Activity

    Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

    Metadata

    Metadata

    Labels

    waiting-for-responseMaintainers have replied and are awaiting a response from the bug/issue/feature creator

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
      Skip to content

      Validate workflow "hangs" on unauthorized template deployment #629

      Description

      Discussed in #628

      Originally posted by matthewponzio May 17, 2022

      Summary

      I am continuing to PoC the concept of implementing AzOps Repos with various levels of permissions. Our intention would be to recommend something like the following:

      Foundation Repo

      • Owner: Central Cloud Engineering Team
      • Scope: Manages the Azure foundation, inclusive of the entire Management Group hierarchy and the Platform Subscriptions and all constituent Resource Groups / Resources

      Landing Zones Repo(s)

      • Owner: Central Cloud Engineering Team
      • Scope: Manages the Landing Zone (App Workload) Subscriptions - provisioning of the Subscriptions, Policies, RBAC and any centrally managed Resource Groups / Resources, such as networking.

      Workload/App Repos

      • Owner: App Team
      • Scope: Provision and manage Application level Resource Groups and Resources

      Based on this structure, the Workload/App Repo would utilize an SPN with limited permissions. For example, it would not have permission to read/write certain network resources.

      Issue

      I implemented the above setup and have tested it to pretty good success, however when I attempted to test making an unauthorized change from the Workload/App Repo (a change to the virtualNetwork subnet), the Validate pipeline appeared to "hang" during the Validate Step. I let it run for about 20 minutes before I manually cancelled the Workflow. Upon cancellation, you can see in the Validate Step log that it actually worked as intended, returning the following authorization error:

      WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client '<redacted>' with object id '<redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.
      

      The issue or unexpected behavior is that the pipeline didn't fail "quickly". Admittedly, this is a fairly minor issue, but nevertheless, an authorization error should probably fail the pipeline/workflow immediately.

      Expected Behavior

      When a Workflow attempts to validate or execute a deployment containing an unauthorized action, the workflow fails almost immediately.

      Observed Behavior

      The Workflow continued to run, appearing to hang during the Validate Step. Workflow ran for 20 minutes before manual cancellation. Manually cancelling the Workflow worked and revealed the expected authorization error.

      Steps to Reproduce

      1. Create an AzOps Repo that uses an SPN with some kind of limited permission set
      2. Open a PR with a change that would not be authorized by the limited permission set
      3. See that the Validate Workflow continues run, appearing to hang
      4. Manually cancel the Workflow and verify that the expected authorization was returned

      Full Log from Validate Step

      Prepare all required actions
      Run ./.github/actions/validate-deploy
      Run if [ ! -z "$(git diff --name-status HEAD^ HEAD)" ]; then
      M root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
      Run Import-PSFConfig -Path settings.json -Schema MetaJson -EnableException
      [[2](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:2)2:43:25][Initialize-AzOpsEnvironment] Processing AzOps environment
      [22:43:25][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
      [22:43:25][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
      [22:43:26][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_20[15](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:15)-09-01
      [22:43:27][Get-AzOpsSubscription] Number of subscriptions found: 1
      [22:43:27][Get-AzOpsSubscription] Number of subscriptions included: 1
      WARNING: [22:43:31][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
      [22:43:31][Initialize-AzOpsEnvironment] Processing AzOps environment
      [22:43:31][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
      [22:43:31][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
      [22:43:31][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_2015-09-01
      [22:43:32][Get-AzOpsSubscription] Number of subscriptions found: 1
      [22:43:32][Get-AzOpsSubscription] Number of subscriptions included: 1
      WARNING: [22:43:36][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
      [22:43:36][Invoke-AzOpsPush] Deployment required
      [22:43:36][Invoke-AzOpsPush] Adding or modifying:
      [22:43:36][Invoke-AzOpsPush] root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
      [22:43:36][Invoke-AzOpsPush] Deleting:
      [22:43:[37](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:37)][New-AzOpsDeployment] Processing deployment AzOps-microsoft.network_virtualnetworks_subnets-corp1-vnet1-B9EE for template /home/runner/work/azure-adventureworks-app1/azure-adventureworks-app1/root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json with parameter "" in mode Incremental
      Getting the latest status of all resources...
      Get-AzResourceGroupDeploymentWhatIfResult: InvalidTemplateDeployment - Long running operation failed with status
      'Failed'. Additional Info:'The template deployment failed with error:
      'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
      of type 'Microsoft.Network/virtualNetworks/subnets'. The client
      '[72](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:72)0e91c6-f516-44f1-af0f-f21e2[75](https://github.com/recacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:75)30c88' with object id
      'redacted' does not have permission to perform
      action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
      '/subscriptions/***/resourceGroups/cloud-eng-ne
      twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
      1-subnet1'.'.'
      WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client 'redacted' with object id 'redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.'
      Exception: InvalidTemplateDeployment - Long running operation failed with status
      'Failed'. Additional Info:'The template deployment failed with error:
      'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
      of type 'Microsoft.Network/virtualNetworks/subnets'. The client
      'redacted' with object id
      'redacted' does not have permission to perform
      action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
      '/subscriptions/***/resourceGroups/cloud-eng-ne
      twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
      1-subnet1'.'.'
      Error: The operation was canceled.
      

      Activity

      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

      Metadata

      Metadata

      Labels

      waiting-for-responseMaintainers have replied and are awaiting a response from the bug/issue/feature creator

      Type

      No type

      Projects

      No projects

        Milestone

        No milestone

        Relationships

        None yet

        Development

        No branches or pull requests

        Issue actions

        , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
        Skip to content

        Validate workflow "hangs" on unauthorized template deployment #629

        Description

        Discussed in #628

        Originally posted by matthewponzio May 17, 2022

        Summary

        I am continuing to PoC the concept of implementing AzOps Repos with various levels of permissions. Our intention would be to recommend something like the following:

        Foundation Repo

        • Owner: Central Cloud Engineering Team
        • Scope: Manages the Azure foundation, inclusive of the entire Management Group hierarchy and the Platform Subscriptions and all constituent Resource Groups / Resources

        Landing Zones Repo(s)

        • Owner: Central Cloud Engineering Team
        • Scope: Manages the Landing Zone (App Workload) Subscriptions - provisioning of the Subscriptions, Policies, RBAC and any centrally managed Resource Groups / Resources, such as networking.

        Workload/App Repos

        • Owner: App Team
        • Scope: Provision and manage Application level Resource Groups and Resources

        Based on this structure, the Workload/App Repo would utilize an SPN with limited permissions. For example, it would not have permission to read/write certain network resources.

        Issue

        I implemented the above setup and have tested it to pretty good success, however when I attempted to test making an unauthorized change from the Workload/App Repo (a change to the virtualNetwork subnet), the Validate pipeline appeared to "hang" during the Validate Step. I let it run for about 20 minutes before I manually cancelled the Workflow. Upon cancellation, you can see in the Validate Step log that it actually worked as intended, returning the following authorization error:

        WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client '<redacted>' with object id '<redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.
        

        The issue or unexpected behavior is that the pipeline didn't fail "quickly". Admittedly, this is a fairly minor issue, but nevertheless, an authorization error should probably fail the pipeline/workflow immediately.

        Expected Behavior

        When a Workflow attempts to validate or execute a deployment containing an unauthorized action, the workflow fails almost immediately.

        Observed Behavior

        The Workflow continued to run, appearing to hang during the Validate Step. Workflow ran for 20 minutes before manual cancellation. Manually cancelling the Workflow worked and revealed the expected authorization error.

        Steps to Reproduce

        1. Create an AzOps Repo that uses an SPN with some kind of limited permission set
        2. Open a PR with a change that would not be authorized by the limited permission set
        3. See that the Validate Workflow continues run, appearing to hang
        4. Manually cancel the Workflow and verify that the expected authorization was returned

        Full Log from Validate Step

        Prepare all required actions
        Run ./.github/actions/validate-deploy
        Run if [ ! -z "$(git diff --name-status HEAD^ HEAD)" ]; then
        M root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
        Run Import-PSFConfig -Path settings.json -Schema MetaJson -EnableException
        [[2](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:2)2:43:25][Initialize-AzOpsEnvironment] Processing AzOps environment
        [22:43:25][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
        [22:43:25][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
        [22:43:26][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_20[15](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:15)-09-01
        [22:43:27][Get-AzOpsSubscription] Number of subscriptions found: 1
        [22:43:27][Get-AzOpsSubscription] Number of subscriptions included: 1
        WARNING: [22:43:31][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
        [22:43:31][Initialize-AzOpsEnvironment] Processing AzOps environment
        [22:43:31][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
        [22:43:31][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
        [22:43:31][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_2015-09-01
        [22:43:32][Get-AzOpsSubscription] Number of subscriptions found: 1
        [22:43:32][Get-AzOpsSubscription] Number of subscriptions included: 1
        WARNING: [22:43:36][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
        [22:43:36][Invoke-AzOpsPush] Deployment required
        [22:43:36][Invoke-AzOpsPush] Adding or modifying:
        [22:43:36][Invoke-AzOpsPush] root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
        [22:43:36][Invoke-AzOpsPush] Deleting:
        [22:43:[37](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:37)][New-AzOpsDeployment] Processing deployment AzOps-microsoft.network_virtualnetworks_subnets-corp1-vnet1-B9EE for template /home/runner/work/azure-adventureworks-app1/azure-adventureworks-app1/root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json with parameter "" in mode Incremental
        Getting the latest status of all resources...
        Get-AzResourceGroupDeploymentWhatIfResult: InvalidTemplateDeployment - Long running operation failed with status
        'Failed'. Additional Info:'The template deployment failed with error:
        'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
        of type 'Microsoft.Network/virtualNetworks/subnets'. The client
        '[72](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:72)0e91c6-f516-44f1-af0f-f21e2[75](https://github.com/recacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:75)30c88' with object id
        'redacted' does not have permission to perform
        action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
        '/subscriptions/***/resourceGroups/cloud-eng-ne
        twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
        1-subnet1'.'.'
        WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client 'redacted' with object id 'redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.'
        Exception: InvalidTemplateDeployment - Long running operation failed with status
        'Failed'. Additional Info:'The template deployment failed with error:
        'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
        of type 'Microsoft.Network/virtualNetworks/subnets'. The client
        'redacted' with object id
        'redacted' does not have permission to perform
        action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
        '/subscriptions/***/resourceGroups/cloud-eng-ne
        twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
        1-subnet1'.'.'
        Error: The operation was canceled.
        

        Activity

        Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

        Metadata

        Metadata

        Labels

        waiting-for-responseMaintainers have replied and are awaiting a response from the bug/issue/feature creator

        Type

        No type

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
          Skip to content

          Validate workflow "hangs" on unauthorized template deployment #629

          Description

          Discussed in #628

          Originally posted by matthewponzio May 17, 2022

          Summary

          I am continuing to PoC the concept of implementing AzOps Repos with various levels of permissions. Our intention would be to recommend something like the following:

          Foundation Repo

          • Owner: Central Cloud Engineering Team
          • Scope: Manages the Azure foundation, inclusive of the entire Management Group hierarchy and the Platform Subscriptions and all constituent Resource Groups / Resources

          Landing Zones Repo(s)

          • Owner: Central Cloud Engineering Team
          • Scope: Manages the Landing Zone (App Workload) Subscriptions - provisioning of the Subscriptions, Policies, RBAC and any centrally managed Resource Groups / Resources, such as networking.

          Workload/App Repos

          • Owner: App Team
          • Scope: Provision and manage Application level Resource Groups and Resources

          Based on this structure, the Workload/App Repo would utilize an SPN with limited permissions. For example, it would not have permission to read/write certain network resources.

          Issue

          I implemented the above setup and have tested it to pretty good success, however when I attempted to test making an unauthorized change from the Workload/App Repo (a change to the virtualNetwork subnet), the Validate pipeline appeared to "hang" during the Validate Step. I let it run for about 20 minutes before I manually cancelled the Workflow. Upon cancellation, you can see in the Validate Step log that it actually worked as intended, returning the following authorization error:

          WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client '<redacted>' with object id '<redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.
          

          The issue or unexpected behavior is that the pipeline didn't fail "quickly". Admittedly, this is a fairly minor issue, but nevertheless, an authorization error should probably fail the pipeline/workflow immediately.

          Expected Behavior

          When a Workflow attempts to validate or execute a deployment containing an unauthorized action, the workflow fails almost immediately.

          Observed Behavior

          The Workflow continued to run, appearing to hang during the Validate Step. Workflow ran for 20 minutes before manual cancellation. Manually cancelling the Workflow worked and revealed the expected authorization error.

          Steps to Reproduce

          1. Create an AzOps Repo that uses an SPN with some kind of limited permission set
          2. Open a PR with a change that would not be authorized by the limited permission set
          3. See that the Validate Workflow continues run, appearing to hang
          4. Manually cancel the Workflow and verify that the expected authorization was returned

          Full Log from Validate Step

          Prepare all required actions
          Run ./.github/actions/validate-deploy
          Run if [ ! -z "$(git diff --name-status HEAD^ HEAD)" ]; then
          M root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
          Run Import-PSFConfig -Path settings.json -Schema MetaJson -EnableException
          [[2](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:2)2:43:25][Initialize-AzOpsEnvironment] Processing AzOps environment
          [22:43:25][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
          [22:43:25][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
          [22:43:26][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_20[15](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:15)-09-01
          [22:43:27][Get-AzOpsSubscription] Number of subscriptions found: 1
          [22:43:27][Get-AzOpsSubscription] Number of subscriptions included: 1
          WARNING: [22:43:31][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
          [22:43:31][Initialize-AzOpsEnvironment] Processing AzOps environment
          [22:43:31][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
          [22:43:31][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
          [22:43:31][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_2015-09-01
          [22:43:32][Get-AzOpsSubscription] Number of subscriptions found: 1
          [22:43:32][Get-AzOpsSubscription] Number of subscriptions included: 1
          WARNING: [22:43:36][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
          [22:43:36][Invoke-AzOpsPush] Deployment required
          [22:43:36][Invoke-AzOpsPush] Adding or modifying:
          [22:43:36][Invoke-AzOpsPush] root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
          [22:43:36][Invoke-AzOpsPush] Deleting:
          [22:43:[37](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:37)][New-AzOpsDeployment] Processing deployment AzOps-microsoft.network_virtualnetworks_subnets-corp1-vnet1-B9EE for template /home/runner/work/azure-adventureworks-app1/azure-adventureworks-app1/root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json with parameter "" in mode Incremental
          Getting the latest status of all resources...
          Get-AzResourceGroupDeploymentWhatIfResult: InvalidTemplateDeployment - Long running operation failed with status
          'Failed'. Additional Info:'The template deployment failed with error:
          'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
          of type 'Microsoft.Network/virtualNetworks/subnets'. The client
          '[72](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:72)0e91c6-f516-44f1-af0f-f21e2[75](https://github.com/recacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:75)30c88' with object id
          'redacted' does not have permission to perform
          action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
          '/subscriptions/***/resourceGroups/cloud-eng-ne
          twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
          1-subnet1'.'.'
          WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client 'redacted' with object id 'redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.'
          Exception: InvalidTemplateDeployment - Long running operation failed with status
          'Failed'. Additional Info:'The template deployment failed with error:
          'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
          of type 'Microsoft.Network/virtualNetworks/subnets'. The client
          'redacted' with object id
          'redacted' does not have permission to perform
          action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
          '/subscriptions/***/resourceGroups/cloud-eng-ne
          twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
          1-subnet1'.'.'
          Error: The operation was canceled.
          

          Activity

          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

          Metadata

          Metadata

          Labels

          waiting-for-responseMaintainers have replied and are awaiting a response from the bug/issue/feature creator

          Type

          No type

          Projects

          No projects

            Milestone

            No milestone

            Relationships

            None yet

            Development

            No branches or pull requests

            Issue actions

            , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
            Skip to content

            Validate workflow "hangs" on unauthorized template deployment #629

            Description

            Discussed in #628

            Originally posted by matthewponzio May 17, 2022

            Summary

            I am continuing to PoC the concept of implementing AzOps Repos with various levels of permissions. Our intention would be to recommend something like the following:

            Foundation Repo

            • Owner: Central Cloud Engineering Team
            • Scope: Manages the Azure foundation, inclusive of the entire Management Group hierarchy and the Platform Subscriptions and all constituent Resource Groups / Resources

            Landing Zones Repo(s)

            • Owner: Central Cloud Engineering Team
            • Scope: Manages the Landing Zone (App Workload) Subscriptions - provisioning of the Subscriptions, Policies, RBAC and any centrally managed Resource Groups / Resources, such as networking.

            Workload/App Repos

            • Owner: App Team
            • Scope: Provision and manage Application level Resource Groups and Resources

            Based on this structure, the Workload/App Repo would utilize an SPN with limited permissions. For example, it would not have permission to read/write certain network resources.

            Issue

            I implemented the above setup and have tested it to pretty good success, however when I attempted to test making an unauthorized change from the Workload/App Repo (a change to the virtualNetwork subnet), the Validate pipeline appeared to "hang" during the Validate Step. I let it run for about 20 minutes before I manually cancelled the Workflow. Upon cancellation, you can see in the Validate Step log that it actually worked as intended, returning the following authorization error:

            WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client '<redacted>' with object id '<redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.
            

            The issue or unexpected behavior is that the pipeline didn't fail "quickly". Admittedly, this is a fairly minor issue, but nevertheless, an authorization error should probably fail the pipeline/workflow immediately.

            Expected Behavior

            When a Workflow attempts to validate or execute a deployment containing an unauthorized action, the workflow fails almost immediately.

            Observed Behavior

            The Workflow continued to run, appearing to hang during the Validate Step. Workflow ran for 20 minutes before manual cancellation. Manually cancelling the Workflow worked and revealed the expected authorization error.

            Steps to Reproduce

            1. Create an AzOps Repo that uses an SPN with some kind of limited permission set
            2. Open a PR with a change that would not be authorized by the limited permission set
            3. See that the Validate Workflow continues run, appearing to hang
            4. Manually cancel the Workflow and verify that the expected authorization was returned

            Full Log from Validate Step

            Prepare all required actions
            Run ./.github/actions/validate-deploy
            Run if [ ! -z "$(git diff --name-status HEAD^ HEAD)" ]; then
            M root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
            Run Import-PSFConfig -Path settings.json -Schema MetaJson -EnableException
            [[2](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:2)2:43:25][Initialize-AzOpsEnvironment] Processing AzOps environment
            [22:43:25][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
            [22:43:25][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
            [22:43:26][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_20[15](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:15)-09-01
            [22:43:27][Get-AzOpsSubscription] Number of subscriptions found: 1
            [22:43:27][Get-AzOpsSubscription] Number of subscriptions included: 1
            WARNING: [22:43:31][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
            [22:43:31][Initialize-AzOpsEnvironment] Processing AzOps environment
            [22:43:31][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
            [22:43:31][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
            [22:43:31][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_2015-09-01
            [22:43:32][Get-AzOpsSubscription] Number of subscriptions found: 1
            [22:43:32][Get-AzOpsSubscription] Number of subscriptions included: 1
            WARNING: [22:43:36][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
            [22:43:36][Invoke-AzOpsPush] Deployment required
            [22:43:36][Invoke-AzOpsPush] Adding or modifying:
            [22:43:36][Invoke-AzOpsPush] root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
            [22:43:36][Invoke-AzOpsPush] Deleting:
            [22:43:[37](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:37)][New-AzOpsDeployment] Processing deployment AzOps-microsoft.network_virtualnetworks_subnets-corp1-vnet1-B9EE for template /home/runner/work/azure-adventureworks-app1/azure-adventureworks-app1/root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json with parameter "" in mode Incremental
            Getting the latest status of all resources...
            Get-AzResourceGroupDeploymentWhatIfResult: InvalidTemplateDeployment - Long running operation failed with status
            'Failed'. Additional Info:'The template deployment failed with error:
            'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
            of type 'Microsoft.Network/virtualNetworks/subnets'. The client
            '[72](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:72)0e91c6-f516-44f1-af0f-f21e2[75](https://github.com/recacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:75)30c88' with object id
            'redacted' does not have permission to perform
            action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
            '/subscriptions/***/resourceGroups/cloud-eng-ne
            twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
            1-subnet1'.'.'
            WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client 'redacted' with object id 'redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.'
            Exception: InvalidTemplateDeployment - Long running operation failed with status
            'Failed'. Additional Info:'The template deployment failed with error:
            'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
            of type 'Microsoft.Network/virtualNetworks/subnets'. The client
            'redacted' with object id
            'redacted' does not have permission to perform
            action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
            '/subscriptions/***/resourceGroups/cloud-eng-ne
            twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
            1-subnet1'.'.'
            Error: The operation was canceled.
            

            Activity

            Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

            Metadata

            Metadata

            Labels

            waiting-for-responseMaintainers have replied and are awaiting a response from the bug/issue/feature creator

            Type

            No type

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              Validate workflow "hangs" on unauthorized template deployment #629

              Description

              Discussed in #628

              Originally posted by matthewponzio May 17, 2022

              Summary

              I am continuing to PoC the concept of implementing AzOps Repos with various levels of permissions. Our intention would be to recommend something like the following:

              Foundation Repo

              • Owner: Central Cloud Engineering Team
              • Scope: Manages the Azure foundation, inclusive of the entire Management Group hierarchy and the Platform Subscriptions and all constituent Resource Groups / Resources

              Landing Zones Repo(s)

              • Owner: Central Cloud Engineering Team
              • Scope: Manages the Landing Zone (App Workload) Subscriptions - provisioning of the Subscriptions, Policies, RBAC and any centrally managed Resource Groups / Resources, such as networking.

              Workload/App Repos

              • Owner: App Team
              • Scope: Provision and manage Application level Resource Groups and Resources

              Based on this structure, the Workload/App Repo would utilize an SPN with limited permissions. For example, it would not have permission to read/write certain network resources.

              Issue

              I implemented the above setup and have tested it to pretty good success, however when I attempted to test making an unauthorized change from the Workload/App Repo (a change to the virtualNetwork subnet), the Validate pipeline appeared to "hang" during the Validate Step. I let it run for about 20 minutes before I manually cancelled the Workflow. Upon cancellation, you can see in the Validate Step log that it actually worked as intended, returning the following authorization error:

              WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client '<redacted>' with object id '<redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.
              

              The issue or unexpected behavior is that the pipeline didn't fail "quickly". Admittedly, this is a fairly minor issue, but nevertheless, an authorization error should probably fail the pipeline/workflow immediately.

              Expected Behavior

              When a Workflow attempts to validate or execute a deployment containing an unauthorized action, the workflow fails almost immediately.

              Observed Behavior

              The Workflow continued to run, appearing to hang during the Validate Step. Workflow ran for 20 minutes before manual cancellation. Manually cancelling the Workflow worked and revealed the expected authorization error.

              Steps to Reproduce

              1. Create an AzOps Repo that uses an SPN with some kind of limited permission set
              2. Open a PR with a change that would not be authorized by the limited permission set
              3. See that the Validate Workflow continues run, appearing to hang
              4. Manually cancel the Workflow and verify that the expected authorization was returned

              Full Log from Validate Step

              Prepare all required actions
              Run ./.github/actions/validate-deploy
              Run if [ ! -z "$(git diff --name-status HEAD^ HEAD)" ]; then
              M root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
              Run Import-PSFConfig -Path settings.json -Schema MetaJson -EnableException
              [[2](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:2)2:43:25][Initialize-AzOpsEnvironment] Processing AzOps environment
              [22:43:25][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
              [22:43:25][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
              [22:43:26][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_20[15](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:15)-09-01
              [22:43:27][Get-AzOpsSubscription] Number of subscriptions found: 1
              [22:43:27][Get-AzOpsSubscription] Number of subscriptions included: 1
              WARNING: [22:43:31][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
              [22:43:31][Initialize-AzOpsEnvironment] Processing AzOps environment
              [22:43:31][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
              [22:43:31][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
              [22:43:31][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_2015-09-01
              [22:43:32][Get-AzOpsSubscription] Number of subscriptions found: 1
              [22:43:32][Get-AzOpsSubscription] Number of subscriptions included: 1
              WARNING: [22:43:36][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
              [22:43:36][Invoke-AzOpsPush] Deployment required
              [22:43:36][Invoke-AzOpsPush] Adding or modifying:
              [22:43:36][Invoke-AzOpsPush] root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
              [22:43:36][Invoke-AzOpsPush] Deleting:
              [22:43:[37](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:37)][New-AzOpsDeployment] Processing deployment AzOps-microsoft.network_virtualnetworks_subnets-corp1-vnet1-B9EE for template /home/runner/work/azure-adventureworks-app1/azure-adventureworks-app1/root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json with parameter "" in mode Incremental
              Getting the latest status of all resources...
              Get-AzResourceGroupDeploymentWhatIfResult: InvalidTemplateDeployment - Long running operation failed with status
              'Failed'. Additional Info:'The template deployment failed with error:
              'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
              of type 'Microsoft.Network/virtualNetworks/subnets'. The client
              '[72](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:72)0e91c6-f516-44f1-af0f-f21e2[75](https://github.com/recacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:75)30c88' with object id
              'redacted' does not have permission to perform
              action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
              '/subscriptions/***/resourceGroups/cloud-eng-ne
              twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
              1-subnet1'.'.'
              WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client 'redacted' with object id 'redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.'
              Exception: InvalidTemplateDeployment - Long running operation failed with status
              'Failed'. Additional Info:'The template deployment failed with error:
              'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
              of type 'Microsoft.Network/virtualNetworks/subnets'. The client
              'redacted' with object id
              'redacted' does not have permission to perform
              action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
              '/subscriptions/***/resourceGroups/cloud-eng-ne
              twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
              1-subnet1'.'.'
              Error: The operation was canceled.
              

              Activity

              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

              Metadata

              Metadata

              Labels

              waiting-for-responseMaintainers have replied and are awaiting a response from the bug/issue/feature creator

              Type

              No type

              Projects

              No projects

                Milestone

                No milestone

                Relationships

                None yet

                Development

                No branches or pull requests

                Issue actions

                , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                Skip to content

                Validate workflow "hangs" on unauthorized template deployment #629

                Description

                Discussed in #628

                Originally posted by matthewponzio May 17, 2022

                Summary

                I am continuing to PoC the concept of implementing AzOps Repos with various levels of permissions. Our intention would be to recommend something like the following:

                Foundation Repo

                • Owner: Central Cloud Engineering Team
                • Scope: Manages the Azure foundation, inclusive of the entire Management Group hierarchy and the Platform Subscriptions and all constituent Resource Groups / Resources

                Landing Zones Repo(s)

                • Owner: Central Cloud Engineering Team
                • Scope: Manages the Landing Zone (App Workload) Subscriptions - provisioning of the Subscriptions, Policies, RBAC and any centrally managed Resource Groups / Resources, such as networking.

                Workload/App Repos

                • Owner: App Team
                • Scope: Provision and manage Application level Resource Groups and Resources

                Based on this structure, the Workload/App Repo would utilize an SPN with limited permissions. For example, it would not have permission to read/write certain network resources.

                Issue

                I implemented the above setup and have tested it to pretty good success, however when I attempted to test making an unauthorized change from the Workload/App Repo (a change to the virtualNetwork subnet), the Validate pipeline appeared to "hang" during the Validate Step. I let it run for about 20 minutes before I manually cancelled the Workflow. Upon cancellation, you can see in the Validate Step log that it actually worked as intended, returning the following authorization error:

                WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client '<redacted>' with object id '<redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.
                

                The issue or unexpected behavior is that the pipeline didn't fail "quickly". Admittedly, this is a fairly minor issue, but nevertheless, an authorization error should probably fail the pipeline/workflow immediately.

                Expected Behavior

                When a Workflow attempts to validate or execute a deployment containing an unauthorized action, the workflow fails almost immediately.

                Observed Behavior

                The Workflow continued to run, appearing to hang during the Validate Step. Workflow ran for 20 minutes before manual cancellation. Manually cancelling the Workflow worked and revealed the expected authorization error.

                Steps to Reproduce

                1. Create an AzOps Repo that uses an SPN with some kind of limited permission set
                2. Open a PR with a change that would not be authorized by the limited permission set
                3. See that the Validate Workflow continues run, appearing to hang
                4. Manually cancel the Workflow and verify that the expected authorization was returned

                Full Log from Validate Step

                Prepare all required actions
                Run ./.github/actions/validate-deploy
                Run if [ ! -z "$(git diff --name-status HEAD^ HEAD)" ]; then
                M root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
                Run Import-PSFConfig -Path settings.json -Schema MetaJson -EnableException
                [[2](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:2)2:43:25][Initialize-AzOpsEnvironment] Processing AzOps environment
                [22:43:25][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
                [22:43:25][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
                [22:43:26][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_20[15](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:15)-09-01
                [22:43:27][Get-AzOpsSubscription] Number of subscriptions found: 1
                [22:43:27][Get-AzOpsSubscription] Number of subscriptions included: 1
                WARNING: [22:43:31][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
                [22:43:31][Initialize-AzOpsEnvironment] Processing AzOps environment
                [22:43:31][Initialize-AzOpsEnvironment] Starting AzOps environment initialization
                [22:43:31][Get-AzOpsSubscription] Excluded subscription states: Disabled,Deleted,Warned,Expired
                [22:43:31][Get-AzOpsSubscription] Excluded subscription offers: AzurePass_2014-09-01,FreeTrial_2014-09-01,AAD_2015-09-01
                [22:43:32][Get-AzOpsSubscription] Number of subscriptions found: 1
                [22:43:32][Get-AzOpsSubscription] Number of subscriptions included: 1
                WARNING: [22:43:36][Initialize-AzOpsEnvironment] No management group access, discovery will happen from subscription scope(s)
                [22:43:36][Invoke-AzOpsPush] Deployment required
                [22:43:36][Invoke-AzOpsPush] Adding or modifying:
                [22:43:36][Invoke-AzOpsPush] root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json
                [22:43:36][Invoke-AzOpsPush] Deleting:
                [22:43:[37](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:37)][New-AzOpsDeployment] Processing deployment AzOps-microsoft.network_virtualnetworks_subnets-corp1-vnet1-B9EE for template /home/runner/work/azure-adventureworks-app1/azure-adventureworks-app1/root/corporate 1 (***)/cloud-eng-network/microsoft.network_virtualnetworks_subnets-corp1-vnet1_corp1-vnet1-subnet1.json with parameter "" in mode Incremental
                Getting the latest status of all resources...
                Get-AzResourceGroupDeploymentWhatIfResult: InvalidTemplateDeployment - Long running operation failed with status
                'Failed'. Additional Info:'The template deployment failed with error:
                'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
                of type 'Microsoft.Network/virtualNetworks/subnets'. The client
                '[72](https://github.com/redacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:72)0e91c6-f516-44f1-af0f-f21e2[75](https://github.com/recacted/azure-adventureworks-app1/runs/6461309427?check_suite_focus=true#step:4:75)30c88' with object id
                'redacted' does not have permission to perform
                action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
                '/subscriptions/***/resourceGroups/cloud-eng-ne
                twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
                1-subnet1'.'.'
                WARNING: [22:43:54][New-AzOpsDeployment] Error returned from WhatIf API: InvalidTemplateDeployment - Long running operation failed with status 'Failed'. Additional Info:'The template deployment failed with error: 'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1' of type 'Microsoft.Network/virtualNetworks/subnets'. The client 'redacted' with object id 'redacted' does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/write' at scope '/subscriptions/***/resourceGroups/cloud-eng-network/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet1-subnet1'.'.'
                Exception: InvalidTemplateDeployment - Long running operation failed with status
                'Failed'. Additional Info:'The template deployment failed with error:
                'Authorization failed for template resource 'corp1-vnet1/corp1-vnet1-subnet1'
                of type 'Microsoft.Network/virtualNetworks/subnets'. The client
                'redacted' with object id
                'redacted' does not have permission to perform
                action 'Microsoft.Network/virtualNetworks/subnets/write' at scope
                '/subscriptions/***/resourceGroups/cloud-eng-ne
                twork/providers/Microsoft.Network/virtualNetworks/corp1-vnet1/subnets/corp1-vnet
                1-subnet1'.'.'
                Error: The operation was canceled.
                

                Activity

                Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                Metadata

                Metadata

                Labels

                waiting-for-responseMaintainers have replied and are awaiting a response from the bug/issue/feature creator

                Type

                No type

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions