Skip to content

Commit

Permalink
comment svc
Browse files Browse the repository at this point in the history
  • Loading branch information
Jenny Chen committed Nov 27, 2024
1 parent a6dba3a commit c05bc33
Showing 1 changed file with 44 additions and 44 deletions.
88 changes: 44 additions & 44 deletions dev-infrastructure/templates/mgmt-cluster.bicep
Original file line number Diff line number Diff line change
Expand Up @@ -248,50 +248,50 @@ module mgmtKeyVault '../modules/keyvault/keyvault.bicep' = {
}
}

var clusterServiceMISplit = split(clusterServiceMIResourceId, '/')
var clusterServiceMIResourceGroup = clusterServiceMISplit[4]
var clusterServiceMIName = last(clusterServiceMISplit)

resource clusterServiceMI 'Microsoft.ManagedIdentity/userAssignedIdentities@2023-01-31' existing = {
scope: resourceGroup(clusterServiceMIResourceGroup)
name: clusterServiceMIName
}

module cxClusterServiceKeyVaultAccess '../modules/keyvault/keyvault-secret-access.bicep' = [
for role in [
'Key Vault Secrets Officer'
'Key Vault Certificate User'
'Key Vault Certificates Officer'
]: {
name: guid(cxKeyVaultName, clusterServiceMIResourceId, role)
params: {
keyVaultName: cxKeyVaultName
roleName: role
managedIdentityPrincipalId: clusterServiceMI.properties.principalId
}
dependsOn: [
cxKeyVault
]
}
]

module msiClusterServiceKeyVaultAccess '../modules/keyvault/keyvault-secret-access.bicep' = [
for role in [
'Key Vault Secrets Officer'
'Key Vault Certificate User'
'Key Vault Certificates Officer'
]: {
name: guid(msiKeyVaultName, clusterServiceMIResourceId, role)
params: {
keyVaultName: msiKeyVaultName
roleName: role
managedIdentityPrincipalId: clusterServiceMI.properties.principalId
}
dependsOn: [
msiKeyVault
]
}
]
// var clusterServiceMISplit = split(clusterServiceMIResourceId, '/')
// var clusterServiceMIResourceGroup = clusterServiceMISplit[4]
// var clusterServiceMIName = last(clusterServiceMISplit)

// resource clusterServiceMI 'Microsoft.ManagedIdentity/userAssignedIdentities@2023-01-31' existing = {
// scope: resourceGroup(clusterServiceMIResourceGroup)
// name: clusterServiceMIName
// }

// module cxClusterServiceKeyVaultAccess '../modules/keyvault/keyvault-secret-access.bicep' = [
// for role in [
// 'Key Vault Secrets Officer'
// 'Key Vault Certificate User'
// 'Key Vault Certificates Officer'
// ]: {
// name: guid(cxKeyVaultName, clusterServiceMIResourceId, role)
// params: {
// keyVaultName: cxKeyVaultName
// roleName: role
// managedIdentityPrincipalId: clusterServiceMI.properties.principalId
// }
// dependsOn: [
// cxKeyVault
// ]
// }
// ]

// module msiClusterServiceKeyVaultAccess '../modules/keyvault/keyvault-secret-access.bicep' = [
// for role in [
// 'Key Vault Secrets Officer'
// 'Key Vault Certificate User'
// 'Key Vault Certificates Officer'
// ]: {
// name: guid(msiKeyVaultName, clusterServiceMIResourceId, role)
// params: {
// keyVaultName: msiKeyVaultName
// roleName: role
// managedIdentityPrincipalId: clusterServiceMI.properties.principalId
// }
// dependsOn: [
// msiKeyVault
// ]
// }
// ]

//
// E V E N T G R I D P R I V A T E E N D P O I N T C O N N E C T I O N
Expand Down

0 comments on commit c05bc33

Please sign in to comment.