Skip to content

API's VM Contributor permissions are too wide #2389

@tamirkamara

Description

@tamirkamara

Describe the bug

We give Virtual Machine Contributor permission to the API identity and that is too wide. For instance, it gets full access to all storage accounts in the subscription.

A couple of options I see:

  • Remove the subscription level permission - not sure we event need it that wide and move to a workspace RG level one. Or even on the resource itself
  • Create a custom role that we can use together with the first point.

Metadata

Metadata

Assignees

No one assigned

    Labels

    apiComposition Service APIbugSomething isn't working

    Type

    No fields configured for Bug.

    Projects

    Status
    Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions