Azure / Azure/azure-rest-api-specs

[Question] why does preflight require write access to resources?

Open
#35,444 0 comments 0 reactions 0 assignees View on GitHub
customer-reported question
Dominant language
TypeSpec
Stars
3.1k
Forks
6k
Avg merge
2d 22h
Merged PRs (30d)
444

Description

### API Spec link

na

### API Spec version

na

### Question/Query

I hope i have the right place for this...

The CAF recommends separating the identities for lint/plan operations vs deploy/apply

If preflight is enabled, this requires write access to resources, which is undesirable for a lint check.

I'm curious why this is needed and what recommendations there are to constrain.

This came up when using the terraform azapi provider, I raised a bug on that repo and was informed it is a preflight requirement.

Since provider features cannot be set dynamically in terraform this makes it tricky to run preflight with least privilege.

https://github.com/Azure/terraform-provider-azapi/issues/907

### Environment

_No response_

Contributor guide

Open the contributing guide

Research direction

Start with the CAF guidance and the linked Azure Terraform AzAPI provider issue 907, focusing on the preflight and least-privilege concerns described here. Done means documenting why preflight requires write access and giving actionable recommendations for constraining permissions or separating identities.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, terraform
Domain
cloud, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.