Skip to content

Commit c8c45a8

Browse files
refactor: make Entra ID group mandatory for Bicep deployments
Remove conditional group checks - screening_manbrs_[environment] group must exist before running resource-group-init. Script validation ensures clear error messaging if prerequisites are missing.
1 parent 383b851 commit c8c45a8

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

infrastructure/terraform/resource_group_init/keyVault.bicep

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ resource miRoleAssignment 'Microsoft.Authorization/roleAssignments@2022-04-01' =
6060
}]
6161

6262
// Entra ID Group RBAC assignments using loop
63-
resource groupRoleAssignment 'Microsoft.Authorization/roleAssignments@2022-04-01' = [for role in groupRoleAssignments: if (!empty(userGroupPrincipalID)) {
63+
resource groupRoleAssignment 'Microsoft.Authorization/roleAssignments@2022-04-01' = [for role in groupRoleAssignments: {
6464
name: guid(subscription().subscriptionId, userGroupPrincipalID, role.roleName)
6565
properties: {
6666
roleDefinitionId: subscriptionResourceId('Microsoft.Authorization/roleDefinitions', role.roleId)

0 commit comments

Comments
 (0)