Azure / Azure/bicep-types-az

Microsoft.DesktopVirtualization/hostPools/sessionHostConfigurations@2024-08-08-preview should be an allowed trusted microsoft service for keyvault

Open
#2,383 1 comment 0 reactions 0 assignees View on GitHub
Needs: Triage :mag:
Dominant language
TypeScript
Stars
108
Forks
44
Avg merge
18h 53m
Merged PRs (30d)
29

Description

**Bicep version**
Bicep CLI version 0.31.92 (b06509316a)

**Describe the bug**
when deploying the new session host configuration the AVD service principal needs to have access to a keyvault. if we only allow access from specific virtual netowkrs and IP's and we enable "Allow trusted Microsoft services to bypass this firewall" it is not possible to deploy the sessionHostConfiguration. We get a error that a public Microsoft IP is not allowed to the keyvault.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reproducing the deployment described for sessionHostConfigurations@2024-08-08-preview with Key Vault firewall restrictions and trusted Microsoft services enabled. Then inspect the repository's type definitions for this resource and compare how trusted Microsoft service access is represented for related resources. Done means the session host configuration is accepted in that deployment scenario and the relevant validation is covered.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, typescript
Domain
cloud, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.