Skip to content

Commit

Permalink
Azure HA Template | Updated managed identity permissions
Browse files Browse the repository at this point in the history
  • Loading branch information
chkp-yairra committed Sep 27, 2023
1 parent ea1c72d commit 820cab3
Show file tree
Hide file tree
Showing 2 changed files with 9 additions and 3 deletions.
5 changes: 4 additions & 1 deletion azure/templates/marketplace-ha/mainTemplate.json
Original file line number Diff line number Diff line change
Expand Up @@ -1115,7 +1115,7 @@
},
{
"condition": "[and(equals(parameters('managedSystemAssigned'), 'yes'), not(parameters('deployNewNSG')))]",
"dependsOn": ["[resourceId('Microsoft.Compute/virtualMachines/', concat(parameters('vmName'), '1'))]"],
"dependsOn": "[resourceId('Microsoft.Compute/virtualMachines/', concat(parameters('vmName'), '1'))]",
"name": "[concat('ExistingNsgRoleAssignment', copyIndex())]",
"copy": {
"name": "ExistingNsgRoleAssignmentCopy",
Expand Down Expand Up @@ -1146,6 +1146,9 @@
},
"principalId2": {
"value": "[reference(resourceId('Microsoft.Compute/virtualMachines/', concat(parameters('vmName'), '2')), '2022-11-01', 'Full').identity.principalId]"
},
"index": {
"value": "[copyIndex()]"
}
}
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,14 +18,17 @@
},
"principalId2": {
"type": "string"
},
"index": {
"type": "int"
}
},
"resources": [
{
"type": "Microsoft.Authorization/roleAssignments",
"apiVersion": "2022-04-01",
"scope": "[concat('Microsoft.Network/networkSecurityGroups/', parameters('ExistingNSG').name)]",
"name": "[guid(resourceGroup().id, concat(parameters('vmName'), parameters('roleDefinitionId'), parameters('principalId1'), '1', '-nsg'))]",
"name": "[guid(resourceGroup().id, concat(parameters('vmName'), parameters('principalId1'), '1', '-nsg', parameters('index')))]",
"properties": {
"roleDefinitionId": "[parameters('roleDefinitionId')]",
"principalId": "[parameters('principalId1')]"
Expand All @@ -35,7 +38,7 @@
"type": "Microsoft.Authorization/roleAssignments",
"apiVersion": "2022-04-01",
"scope": "[concat('Microsoft.Network/networkSecurityGroups/', parameters('ExistingNSG').name)]",
"name": "[guid(resourceGroup().id, concat(parameters('vmName'), parameters('roleDefinitionId'), parameters('principalId2'), '2', '-nsg'))]",
"name": "[guid(resourceGroup().id, concat(parameters('vmName'), parameters('roleDefinitionId'), parameters('principalId2'), '2', '-nsg', parameters('index')))]",
"properties": {
"roleDefinitionId": "[parameters('roleDefinitionId')]",
"principalId": "[parameters('principalId2')]"
Expand Down

0 comments on commit 820cab3

Please sign in to comment.