Trusted Launch SSE+CMK Azure Compute Gallery confusing error #29280
Labels
customer-reported
Issues that are reported by GitHub users external to the Azure organization.
Gallery
Mgmt
This issue is related to a management-plane library.
question
The issue doesn't require a change to the product in order to be resolved. Most issues start as that
Service Attention
Workflow: This issue is responsible by Azure service team.
API Spec link
compute/galleryimageversions
API Spec version
any that supports disk encryption set ids
Question/Query
When trying to capture a Trusted Launch VM using dobule encryption to ACG I get a very long error with a stack trace, this happens on any API client to any galleryimageversions version.
This was reported on a repo I maintain here hashicorp/packer-plugin-azure#418 and originally here hashicorp/packer-plugin-azure#304, the Packer Azure plugin invokes the API and runs into the same error.
The documentation for Trusted Launch and double encryption does not make it clear that this is not supported, however an Azure engineer who previously engaged on this issue let me know that the ACG product team says its not supported and there are no plans to support it. I've spent quite a bit of time trying to gather this information and understand that this just isn't supported on Azure.
Can we please update this error message in the API to make it clearer that this functionality is not supported, something simple like "Azure Compute Gallery does not support Trusted Launch images using Disk Encryption Sets" and document it. Users currently do not clearly know from reading the error and the Azure docs that ACG does not support this type of image.
Environment
No response
The text was updated successfully, but these errors were encountered: