-
Notifications
You must be signed in to change notification settings - Fork 311
RBAC Propagations can cause failure. #414
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
The command : az role assignment create --assignee $imgBuilderCliId --role "$imageRoleDefName" --scope /subscriptions/$subscriptionID/resourceGroups/$sigResourceGroup is offered along with several others in the copy code block, but it does require RBAC propagation and different errors can occur depending on the RBAC propagation stage. recommend either breaking this command out of the copy code block or at least adding a warning about the delay so users are not sidetracked by troubleshooting something that is not actually broken, just requires a slight delay prior to executing.
|
@mbiver : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change. |
|
Learn Build status updates of commit b91b90f: ✅ Validation status: passed
For more details, please refer to the build report. |
|
Can you review the proposed changes? Important: When the changes are ready for publication, adding a #label:"aq-pr-triaged" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
This PR updates the Azure VM Image Builder documentation to warn users about potential RBAC propagation delays when assigning a role to a user-assigned identity. The goal is to reduce confusion and unnecessary troubleshooting when the az role assignment create command fails due to propagation lag rather than a misconfiguration.
Changes:
- Expanded the inline comment preceding
az role assignment createin the Linux Image Builder CLI sample to explain that the command’s success depends on RBAC propagation. - Advised users to wait before running the command and to retry after a delay if an error occurs.
|
Learn Build status updates of commit d0f6aee: ✅ Validation status: passed
For more details, please refer to the build report. |
The command :
az role assignment create --assignee $imgBuilderCliId --role "$imageRoleDefName" --scope /subscriptions/$subscriptionID/resourceGroups/$sigResourceGroup
is offered along with several others in the copy code block, but it does require RBAC propagation and different errors can occur depending on the RBAC propagation stage. recommend either breaking this command out of the copy code block or at least adding a warning about the delay so users are not sidetracked by troubleshooting something that is not actually broken, just requires a slight delay prior to executing.