Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion terraform/azure_foofrix/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,8 @@ The workflow needs `id-token: write` and audience `api://AzureADTokenExchange`.
No image-build client secret is needed.

Configure Packer to use the existing `image_build_resource_group` output for
temporary resources. Publish to `image_gallery_name` in
temporary resources in West US 3. The original Central US build group is retained;
the gallery, storage, and identities remain in Central US. Publish to `image_gallery_name` in
`image_gallery_resource_group`, using the definition from
`windows_image_definition_id`. The workflow logs in with `image_build_client_id`.
Attach `image_build_identity_id` to the temporary VM. The guest bootstrap must
Expand Down
12 changes: 10 additions & 2 deletions terraform/azure_foofrix/images.tf
Original file line number Diff line number Diff line change
Expand Up @@ -83,6 +83,13 @@ resource "azurerm_resource_group" "image_build" {
tags = local.common_tags
}

# Packer uses the build resource group's location for its temporary VM.
resource "azurerm_resource_group" "image_build_westus3" {
name = "rg-foofrix-image-build-westus3"
location = "westus3"
tags = local.common_tags
}

resource "azurerm_user_assigned_identity" "image_build" {
name = "id-foofrix-image-build"
resource_group_name = azurerm_resource_group.foofrix.name
Expand All @@ -94,8 +101,9 @@ resource "azurerm_user_assigned_identity" "image_build" {

resource "azurerm_role_assignment" "image_build_contributor" {
for_each = {
build = azurerm_resource_group.image_build.id
gallery = azurerm_shared_image_gallery.foofrix.id
build = azurerm_resource_group.image_build.id
build_westus3 = azurerm_resource_group.image_build_westus3.id
gallery = azurerm_shared_image_gallery.foofrix.id
}
scope = each.value
role_definition_name = "Contributor"
Expand Down
2 changes: 1 addition & 1 deletion terraform/azure_foofrix/outputs.tf
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ output "image_build_client_id" {
}

output "image_build_resource_group" {
value = azurerm_resource_group.image_build.name
value = azurerm_resource_group.image_build_westus3.name
}

output "image_build_identity_id" {
Expand Down
13 changes: 11 additions & 2 deletions terraform/azure_foofrix/tests/access.tftest.hcl
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,12 @@ override_resource {
values = { id = "/subscriptions/00000000-0000-0000-0000-000000000001/resourceGroups/rg-foofrix-image-build" }
}

override_resource {
target = azurerm_resource_group.image_build_westus3
override_during = plan
values = { id = "/subscriptions/00000000-0000-0000-0000-000000000001/resourceGroups/rg-foofrix-image-build-westus3" }
}

override_resource {
target = azurerm_shared_image_gallery.foofrix
override_during = plan
Expand All @@ -35,8 +41,11 @@ run "build_and_team_access" {

assert {
condition = (
length(azurerm_role_assignment.image_build_contributor) == 2 &&
length(azurerm_role_assignment.image_build_contributor) == 3 &&
azurerm_role_assignment.image_build_contributor["build"].scope == azurerm_resource_group.image_build.id &&
azurerm_resource_group.image_build_westus3.location == "westus3" &&
output.image_build_resource_group == azurerm_resource_group.image_build_westus3.name &&
azurerm_role_assignment.image_build_contributor["build_westus3"].scope == azurerm_resource_group.image_build_westus3.id &&
azurerm_role_assignment.image_build_contributor["gallery"].scope == azurerm_shared_image_gallery.foofrix.id &&
azurerm_role_assignment.image_build_identity_operator.scope == azurerm_user_assigned_identity.image_build.id &&
alltrue([for grant in azurerm_role_assignment.image_build_blob_reader : grant.scope == azurerm_storage_container.artifacts.id]) &&
Expand All @@ -45,7 +54,7 @@ run "build_and_team_access" {
length(azurerm_role_assignment.image_build_blob_reader) == 2 &&
azurerm_role_assignment.image_build_identity_operator.role_definition_name == "Managed Identity Operator"
)
error_message = "The builder needs two Contributor grants, identity attachment, and read access for both build identities."
error_message = "The builder needs three Contributor grants, identity attachment, and read access for both build identities."
}

assert {
Expand Down
Loading