-
Notifications
You must be signed in to change notification settings - Fork 3.3k
[Compute] az vm/vmss identity assign: Add warning log and modify help to inform that the default value Contributor of --role will be removed
#25283
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
az vm/vmss identity assign: Add warning log and modify help to inform that the default value Contributor of --role will be removed
|
Compute warning refinement |
az vm/vmss identity assign: Add warning log and modify help to inform that the default value Contributor of --role will be removedaz vm/vmss identity assign: Add warning log and modify help to inform that the default value Contributor of --role will be removed
az vm/vmss identity assign: Add warning log and modify help to inform that the default value Contributor of --role will be removedaz vm/vmss identity assign: Add warning log and modify help to inform that the default value Contributor of --role will be removed
az vm/vmss identity assign: Add warning log and modify help to inform that the default value Contributor of --role will be removedaz vm/vmss identity assign: Add warning log and modify help to inform that the default value Contributor of --role will be removed
|
@dcaro Could you please help review this PR? |
|
@zhoxing-ms can you reuse the messages that have been discussed in #24755 ? |
|
@dcaro, From a doc's perspective, there are 770 GitHub lines that have various combinations of |
️✔️acr
️✔️acs
️✔️advisor
️✔️ams
️✔️apim
️✔️appconfig
️✔️appservice
️✔️aro
️✔️backup
️✔️batch
️✔️batchai
️✔️billing
️✔️botservice
️✔️cdn
️✔️cloud
️✔️cognitiveservices
️✔️config
️✔️configure
️✔️consumption
️✔️container
️✔️core
️✔️cosmosdb
️✔️databoxedge
️✔️dla
️✔️dls
️✔️dms
️✔️eventgrid
️✔️eventhubs
️✔️feedback
️✔️find
️✔️hdinsight
️✔️identity
️✔️iot
️✔️keyvault
️✔️kusto
️✔️lab
️✔️managedservices
️✔️maps
️✔️marketplaceordering
️✔️monitor
️✔️natgateway
️✔️netappfiles
️✔️network
️✔️policyinsights
️✔️privatedns
️✔️profile
️✔️rdbms
️✔️redis
️✔️relay
️✔️resource
️✔️role
️✔️search
️✔️security
️✔️servicebus
️✔️serviceconnector
️✔️servicefabric
️✔️signalr
️✔️sql
️✔️sqlvm
️✔️storage
️✔️synapse
️✔️telemetry
️✔️util
️✔️vm
|
…lp to inform that the default value Contributor of `--role` will be removed (Azure#25283)
Related command
az vm/vmss identity assignDescription
Similar to #20924
As the security team raised the security concern: the permission of
Contributoris too high to be used as the default role foraz vm/vmss identity assign, so the default valueContributorof--rolewill be removed in the future.Therefore, the first step is to prompt users that parameters
--roleand--scopeshould be passed in at the same time when assigning role to the managed identity to reduce the impact of breaking change.The specific effects are as follows:
warning message

help message

help example

Testing Guide
History Notes
[Component Name 1] BREAKING CHANGE:
az command a: Make some customer-facing breaking change[Component Name 2]
az command b: Add some customer-facing featureThis checklist is used to make sure that common guidelines for a pull request are followed.
The PR title and description has followed the guideline in Submitting Pull Requests.
I adhere to the Command Guidelines.
I adhere to the Error Handling Guidelines.