Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 9 additions & 3 deletions lib/auth/join_azure.go
Original file line number Diff line number Diff line change
Expand Up @@ -54,6 +54,8 @@ const (
azureUserAgent = "teleport"
// azureVirtualMachine specifies the Azure virtual machine resource type.
azureVirtualMachine = "virtualMachines"
// azureVirtualMachineScaleSet specifies the Azure virtual machine scale set resource type.
azureVirtualMachineScaleSet = "virtualMachineScaleSets"
)

// Structs for unmarshaling attested data. Schema can be found at
Expand Down Expand Up @@ -348,10 +350,14 @@ func claimsToIdentifiers(tokenClaims *accessTokenClaims) (subscriptionID, resour
if err != nil {
return "", "", trace.Wrap(err, "failed to parse resource id from claims")
}
if !slices.Contains(resourceID.ResourceType.Types, azureVirtualMachine) {
return "", "", trace.BadParameter("unexpected resource type: %q", resourceID.ResourceType.Type)

for _, resourceType := range resourceID.ResourceType.Types {
switch resourceType {
case azureVirtualMachine, azureVirtualMachineScaleSet:
return resourceID.SubscriptionID, resourceID.ResourceGroupName, nil
}
}
return resourceID.SubscriptionID, resourceID.ResourceGroupName, nil
return "", "", trace.BadParameter("unexpected resource type: %q", resourceID.ResourceType.Type)
}

func checkAzureAllowRules(vmID string, attrs *workloadidentityv1pb.JoinAttrsAzure, token *types.ProvisionTokenV2) error {
Expand Down
26 changes: 26 additions & 0 deletions lib/auth/join_azure_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -103,6 +103,10 @@ func withChallengeAzure(challenge string) azureChallengeResponseOption {
}
}

func vmssResourceID(subscription, resourceGroup, name string) string {
return resourceID("Microsoft.Compute/virtualMachineScaleSets", subscription, resourceGroup, name)
}

func vmResourceID(subscription, resourceGroup, name string) string {
return resourceID("Microsoft.Compute/virtualMachines", subscription, resourceGroup, name)
}
Expand Down Expand Up @@ -776,6 +780,28 @@ func TestAuth_RegisterUsingAzureClaims(t *testing.T) {
certs: []*x509.Certificate{tlsConfig.Certificate},
assertError: isAccessDenied,
},
{
name: "vmss resource type",
requestTokenName: "test-token",
tokenSubscription: "token-subscription",
tokenVMID: defaultVMID,
tokenManagedIdentityResourceID: vmssResourceID("token-subscription", defaultResourceGroup, defaultVMName),
tokenSpec: types.ProvisionTokenSpecV2{
Roles: []types.SystemRole{types.RoleNode},
Azure: &types.ProvisionTokenSpecV2Azure{
Allow: []*types.ProvisionTokenSpecV2Azure_Rule{
{
Subscription: "token-subscription",
ResourceGroups: []string{defaultResourceGroup},
},
},
},
JoinMethod: types.JoinMethodAzure,
},
verify: mockVerifyToken(nil),
certs: []*x509.Certificate{tlsConfig.Certificate},
assertError: require.NoError,
},
}

for _, tc := range tests {
Expand Down
Loading