Fix role assignment for existing Foundry resources - #42
Open
Changjian Wang (changjian-wang) wants to merge 1 commit into
Open
Changjian Wang (changjian-wang) wants to merge 1 commit into
Changjian Wang (changjian-wang) wants to merge 1 commit into
Conversation
Preserve explicit role choices in standalone generation and add account-scoped RBAC for existing Foundry resources. Cover frontend parity, template contracts, and launcher exit-code propagation; document permissions and defaults. Fixes #28
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #28.
--assign-roles trueandfalsevalues when standalonecu infra generatereuses an existing Foundry endpoint. Omitted values remainfalse, and existing-resource generation does not prompt for role assignment.Cognitive Services Userrole assignment scoped toaccountExistingin the shared Bicep template, using a deterministic assignment name. The new-resource path remains unchanged.Validation
bash cu-cli/scripts/ci.shcompleted with exit code0, including wheel builds, Ruff, mypy, unit tests, installed-wheel parity, and offline integration playback. Platform-specific/live-only skips remain in place.false/ explicittrueall exited0and producedAZD_ASSIGN_ROLES=false / false / true, respectively. The generated template containsroleCogUserOnExistingscoped toaccountExisting.git diff --checkpassed.Cloud Validation Limitation
azd provision --previewwas attempted but returned403 AuthorizationFailedforMicrosoft.Resources/deployments/whatIf/actionat subscription scope. The test identity therefore could not proceed to deployment.No real role-assignment deployment or cloud postprovision execution was performed. This preview permission failure is not counted as the role-assignment-deployment-failure regression scenario. Live success and role-assignment failure behavior still require verification with appropriately permissioned test identities.
Role assignment remains part of the required initial Bicep deployment; the existing postprovision contract and launchers are unchanged.