From e7b9670da3f6b6a43956444eff4a9db772553db1 Mon Sep 17 00:00:00 2001 From: Mark Cornmesser Date: Wed, 16 Sep 2026 16:15:45 -0700 Subject: [PATCH] Add FooFrix image build resource group in West US 3 --- terraform/azure_foofrix/README.md | 3 ++- terraform/azure_foofrix/images.tf | 12 ++++++++++-- terraform/azure_foofrix/outputs.tf | 2 +- terraform/azure_foofrix/tests/access.tftest.hcl | 13 +++++++++++-- 4 files changed, 24 insertions(+), 6 deletions(-) diff --git a/terraform/azure_foofrix/README.md b/terraform/azure_foofrix/README.md index 6d033dbb..d870b842 100644 --- a/terraform/azure_foofrix/README.md +++ b/terraform/azure_foofrix/README.md @@ -62,7 +62,8 @@ The workflow needs `id-token: write` and audience `api://AzureADTokenExchange`. No image-build client secret is needed. Configure Packer to use the existing `image_build_resource_group` output for -temporary resources. Publish to `image_gallery_name` in +temporary resources in West US 3. The original Central US build group is retained; +the gallery, storage, and identities remain in Central US. Publish to `image_gallery_name` in `image_gallery_resource_group`, using the definition from `windows_image_definition_id`. The workflow logs in with `image_build_client_id`. Attach `image_build_identity_id` to the temporary VM. The guest bootstrap must diff --git a/terraform/azure_foofrix/images.tf b/terraform/azure_foofrix/images.tf index d1daa5ab..74d3e47c 100644 --- a/terraform/azure_foofrix/images.tf +++ b/terraform/azure_foofrix/images.tf @@ -83,6 +83,13 @@ resource "azurerm_resource_group" "image_build" { tags = local.common_tags } +# Packer uses the build resource group's location for its temporary VM. +resource "azurerm_resource_group" "image_build_westus3" { + name = "rg-foofrix-image-build-westus3" + location = "westus3" + tags = local.common_tags +} + resource "azurerm_user_assigned_identity" "image_build" { name = "id-foofrix-image-build" resource_group_name = azurerm_resource_group.foofrix.name @@ -94,8 +101,9 @@ resource "azurerm_user_assigned_identity" "image_build" { resource "azurerm_role_assignment" "image_build_contributor" { for_each = { - build = azurerm_resource_group.image_build.id - gallery = azurerm_shared_image_gallery.foofrix.id + build = azurerm_resource_group.image_build.id + build_westus3 = azurerm_resource_group.image_build_westus3.id + gallery = azurerm_shared_image_gallery.foofrix.id } scope = each.value role_definition_name = "Contributor" diff --git a/terraform/azure_foofrix/outputs.tf b/terraform/azure_foofrix/outputs.tf index 7d1ef253..04c7b84a 100644 --- a/terraform/azure_foofrix/outputs.tf +++ b/terraform/azure_foofrix/outputs.tf @@ -43,7 +43,7 @@ output "image_build_client_id" { } output "image_build_resource_group" { - value = azurerm_resource_group.image_build.name + value = azurerm_resource_group.image_build_westus3.name } output "image_build_identity_id" { diff --git a/terraform/azure_foofrix/tests/access.tftest.hcl b/terraform/azure_foofrix/tests/access.tftest.hcl index 03bba726..5e153b09 100644 --- a/terraform/azure_foofrix/tests/access.tftest.hcl +++ b/terraform/azure_foofrix/tests/access.tftest.hcl @@ -12,6 +12,12 @@ override_resource { values = { id = "/subscriptions/00000000-0000-0000-0000-000000000001/resourceGroups/rg-foofrix-image-build" } } +override_resource { + target = azurerm_resource_group.image_build_westus3 + override_during = plan + values = { id = "/subscriptions/00000000-0000-0000-0000-000000000001/resourceGroups/rg-foofrix-image-build-westus3" } +} + override_resource { target = azurerm_shared_image_gallery.foofrix override_during = plan @@ -35,8 +41,11 @@ run "build_and_team_access" { assert { condition = ( - length(azurerm_role_assignment.image_build_contributor) == 2 && + length(azurerm_role_assignment.image_build_contributor) == 3 && azurerm_role_assignment.image_build_contributor["build"].scope == azurerm_resource_group.image_build.id && + azurerm_resource_group.image_build_westus3.location == "westus3" && + output.image_build_resource_group == azurerm_resource_group.image_build_westus3.name && + azurerm_role_assignment.image_build_contributor["build_westus3"].scope == azurerm_resource_group.image_build_westus3.id && azurerm_role_assignment.image_build_contributor["gallery"].scope == azurerm_shared_image_gallery.foofrix.id && azurerm_role_assignment.image_build_identity_operator.scope == azurerm_user_assigned_identity.image_build.id && alltrue([for grant in azurerm_role_assignment.image_build_blob_reader : grant.scope == azurerm_storage_container.artifacts.id]) && @@ -45,7 +54,7 @@ run "build_and_team_access" { length(azurerm_role_assignment.image_build_blob_reader) == 2 && azurerm_role_assignment.image_build_identity_operator.role_definition_name == "Managed Identity Operator" ) - error_message = "The builder needs two Contributor grants, identity attachment, and read access for both build identities." + error_message = "The builder needs three Contributor grants, identity attachment, and read access for both build identities." } assert {