ForbiddenByRbac when using azure key vault backend with version 3.8+
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 23.1k
- Forks
- 1.1k
- Avg merge
- 1d 11h
- Merged PRs (30d)
- 9
Description
Hi!
We successfully using sops 3.7.3 with azure key vault as backend.
But when we try to use same flow with 3.8+ version it fails with ForbiddenByRbac error.
I tried both login type - az login and service principle credentials. Both fails.
I have next roles permission to resource: [Key Vault Crypto Officer, Key Vault Crypto User]
Something changed in how sops authenticate with azure resources?
./sops-v3.8.1.linux.amd64 ~/git/environments/aks-saas/secrets.yaml
Failed to get the data key required to decrypt the SOPS file.
Group 0: FAILED
https://*******.vault.azure.net/keys/sops-aks-saas-key/*********************: FAILED
- | failed to decrypt sops data key with Azure Key Vault key
| 'https://*******.vault.azure.net/keys/sops-aks-saas-key/*********************':
| POST
| https://*******.vault.azure.net/keys/sops-aks-saas-key/*********************/decrypt
| --------------------------------------------------------------------------------
| RESPONSE 403: 403 Forbidden
| ERROR CODE: Forbidden
| --------------------------------------------------------------------------------
| {
| "error": {
| "code": "Forbidden",
| "message": "Caller is not authorized to perform action
| on resource.\r\nIf role assignments, deny assignments or
| role definitions were changed recently, please observe
| propagation time.\r\nCaller:
| appid=********************;oid=*********************;iss=https://sts.windows.net/**************/\r\nAction:
| 'Microsoft.KeyVault/vaults/keys/decrypt/action'\r\nResource:
| '/subscriptions/************************/resourcegroups/****/providers/microsoft.keyvault/vaults/*******/keys/sops-aks-saas-key'\r\nAssignment:
| (not found)\r\nDenyAssignmentId: null\r\nDecisionReason:
| null \r\nVault: *******;location=********\r\n",
| "innererror": {
| "code": "ForbiddenByRbac"
| }
| }
| }
| --------------------------------------------------------------------------------
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the Azure Key Vault backend and compare authentication and decrypt behavior between sops 3.7.3 and 3.8.1. Reproduce the provided command with both az login and service-principal credentials; the work is done when an authorized caller can decrypt using the 3.8+ flow without ForbiddenByRbac.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure
- Domain
- cloud, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100