Skip to content

Commit 9154d03

Browse files
author
Sheyla Trudo
committed
fixup! Artifacts
1 parent 967acc1 commit 9154d03

File tree

2 files changed

+16
-6
lines changed

2 files changed

+16
-6
lines changed

.pipelines/templates/artifact-storage.steps.yaml

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,7 @@ steps:
4949
(( $INFRA_RG_LENGTH < $ACNCI_SA_POOL_SIZE )); then
5050
# Construct RG Name
5151
RG_NAME="${ACNCI_RG_PREFIX}${LOCAL_ACNCI_UNIQUE_ID}"
52+
echo >&2 "##vso[task.setvariable variable=RG_NAME;]$RG_NAME"
5253
echo >&2 "##vso[task.setvariable variable=CREATE_NEW_RG;]true"
5354
else
5455
echo >&2 "##vso[task.setvariable variable=CREATE_NEW_RG;]false"
@@ -224,12 +225,15 @@ steps:
224225
set -x
225226
pwd
226227
ls -la
227-
DEFS_FOUND=$(az role definition list --name "$ACNCI_BUILDUSER_ROLE_NAME" --custom-role-only -ojson | jq length)
228+
DEFS_FOUND=$(az role definition list \
229+
--name "$ACNCI_BUILDUSER_ROLE_NAME" \
230+
--resource-group "$ACNCI_BUILDUSER_ROLE_NAME" \
231+
--custom-role-only -ojson | jq length)
228232
229233
DEF=$(cat ./azure-container-networking/.pipelines/templates/mi-build-role.json | \
230234
jq -rc \
231-
--arg SUBSCRIPTION_RESOURCEID "/subscriptions/$SUBSCRIPTION_ID" \
232-
'.assignableScopes[] = $SUBSCRIPTION_RESOURCEID')
235+
--arg RESOURCEID "$ACNCI_BUILD_RESOURCEGROUP_ID" \
236+
'.assignableScopes[] = $RESOURCEID')
233237
234238
echo $DEF | jq .
235239
if (( $DEFS_FOUND < 1 )); then
@@ -240,7 +244,7 @@ steps:
240244
--role-definition "$DEF"
241245
fi
242246
env:
243-
ACNCI_BUILD_RESOURCEGROUP_ID: $(resourcegroups.ACNCI_BUILD_RESOURCEGROUP_ID)
247+
ACNCI_BUILD_RESOURCEGROUP_ID: $[ variables['resourcegroups.ACNCI_BUILD_RESOURCEGROUP_ID'] ]
244248

245249
- task: AzureCLI@2
246250
displayName: "[Check] Build User MI Roles"

.pipelines/templates/mi-build-role.json

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,12 @@
99
"Microsoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/action",
1010
"Microsoft.Storage/storageAccounts/blobServices/containers/read",
1111
"Microsoft.Storage/storageAccounts/blobServices/containers/write",
12-
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/*",
12+
13+
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write",
14+
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read",
15+
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete",
16+
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/tags/read",
17+
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/tags/write",
1318

1419
"Microsoft.Storage/storageAccounts/tableServices/tables/read",
1520
"Microsoft.Storage/storageAccounts/tableServices/tables/write",
@@ -23,6 +28,7 @@
2328
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read",
2429
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write",
2530
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete",
31+
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/filter/action",
2632
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/move/action",
2733
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/add/action",
2834

@@ -41,6 +47,6 @@
4147
],
4248
"notDataActions": [],
4349
"assignableScopes": [
44-
"/"
50+
"$RESOURCEID"
4551
]
4652
}

0 commit comments

Comments
 (0)