Azure / Azure/azure-rest-api-specs
[Question] why does preflight require write access to resources?
- Dominant language
- TypeSpec
- Stars
- 3.1k
- Forks
- 6k
- Avg merge
- 2d 22h
- Merged PRs (30d)
- 444
Description
### API Spec link
na
### API Spec version
na
### Question/Query
I hope i have the right place for this...
The CAF recommends separating the identities for lint/plan operations vs deploy/apply
If preflight is enabled, this requires write access to resources, which is undesirable for a lint check.
I'm curious why this is needed and what recommendations there are to constrain.
This came up when using the terraform azapi provider, I raised a bug on that repo and was informed it is a preflight requirement.
Since provider features cannot be set dynamically in terraform this makes it tricky to run preflight with least privilege.
https://github.com/Azure/terraform-provider-azapi/issues/907
### Environment
_No response_
Contributor guide
Research direction
Start with the CAF guidance and the linked Azure Terraform AzAPI provider issue 907, focusing on the preflight and least-privilege concerns described here. Done means documenting why preflight requires write access and giving actionable recommendations for constraining permissions or separating identities.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure, terraform
- Domain
- cloud, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100