Azure / Azure/azure-libraries-for-java

Encrypting the VM fails due to invalid secret URL "Preparing machine for bitlocker".

オープン
#656 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
Compute Compute - VM customer-reported
主要言語
Java
スター
97
フォーク
102
PR マージ指標
30日以内にマージされた PR はありません

説明

Steps to reproduce
1. Created a win10 VM with osDisk and encrypt the VM.
2. Took the snapshot of the osDisk after the encryption.
3. Deleted the original VM and original osDisk
4. Recreated the VM with the same name in the same RG from the encrypted snapshot.
5. Added a datadisk to the new VM and then tried to encrypt the data disk using the following.

```
WindowsVMDiskEncryptionConfiguration config =
new WindowsVMDiskEncryptionConfiguration(
keyVault.id(),
applicationId,
applicationSecretEncrypted)
.withVolumeType(DiskVolumeType.DATA);
DiskVolumeEncryptionMonitor monitor = vm.diskEncryption().enable(config);
```

Azure throws the following exception

> com.microsoft.azure.CloudException:
> Preparing machine for bitlocker is not a valid versioned Key Vault Secret URL. It should be in the format `https:///secrets//.:` Preparing machine for bitlocker is not a valid versioned Key Vault Secret URL. It should be in the format `https:///secrets//.`

But retrying it after few minutes once it fails works.

I guess it's trying to re-install the "AzureDiskEncryption" extension since this was deleted as part of the original VM delete. But not waiting for extension's provisioning state to succeed (which will set the status message correctly to the secret URL) and using an intermediate status message "Preparing machine for bitlocker" as the secret URL.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start at WindowsVMDiskEncryptionConfiguration and the vm.diskEncryption().enable(config) entry point, then trace how the AzureDiskEncryption extension provisioning status supplies the secret URL. Reproduce the snapshot-based VM recreation flow and verify that encryption does not use the intermediate “Preparing machine for bitlocker” message; done means the first encryption attempt succeeds without a retry.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
azure, java
領域
cloud, security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。