Skip to content

Commit 37b4e66

Browse files
authored
Updating RBAC for all Standard Setup Templates (#402)
* updating with new role assignment * updating templates * updating rbac for standard setup
1 parent a9b6bfe commit 37b4e66

File tree

12 files changed

+18
-100
lines changed

12 files changed

+18
-100
lines changed

samples/microsoft/infrastructure-setup/15-private-network-standard-agent-setup/azuredeploy.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
"_generator": {
66
"name": "bicep",
77
"version": "0.39.26.7824",
8-
"templateHash": "1725231348910266693"
8+
"templateHash": "3024624923779287280"
99
}
1010
},
1111
"parameters": {
@@ -2629,7 +2629,7 @@
26292629
"_generator": {
26302630
"name": "bicep",
26312631
"version": "0.39.26.7824",
2632-
"templateHash": "16291470712974205281"
2632+
"templateHash": "17187611271934567223"
26332633
}
26342634
},
26352635
"parameters": {
@@ -2651,7 +2651,7 @@
26512651
},
26522652
"variables": {
26532653
"roleDefinitionId": "[resourceId('Microsoft.DocumentDB/databaseAccounts/sqlRoleDefinitions', parameters('cosmosAccountName'), '00000000-0000-0000-0000-000000000002')]",
2654-
"accountScope": "[format('/subscriptions/{0}/resourceGroups/{1}/providers/Microsoft.DocumentDB/databaseAccounts/{2}', subscription().subscriptionId, resourceGroup().name, parameters('cosmosAccountName'))]"
2654+
"accountScope": "[format('/subscriptions/{0}/resourceGroups/{1}/providers/Microsoft.DocumentDB/databaseAccounts/{2}/dbs/enterprise_memory', subscription().subscriptionId, resourceGroup().name, parameters('cosmosAccountName'))]"
26552655
},
26562656
"resources": [
26572657
{

samples/microsoft/infrastructure-setup/15-private-network-standard-agent-setup/modules-network-secured/cosmos-container-role-assignments.bicep

Lines changed: 0 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -8,24 +8,11 @@ param projectPrincipalId string
88

99
param projectWorkspaceId string
1010

11-
// var userThreadName = '${projectWorkspaceId}-thread-message-store'
12-
1311
resource cosmosAccount 'Microsoft.DocumentDB/databaseAccounts@2024-12-01-preview' existing = {
1412
name: cosmosAccountName
1513
scope: resourceGroup()
1614
}
1715

18-
// // Reference existing database
19-
// resource database 'Microsoft.DocumentDB/databaseAccounts/sqlDatabases@2024-12-01-preview' existing = {
20-
// parent: cosmosAccount
21-
// name: 'enterprise_memory'
22-
// }
23-
24-
// resource containerUserMessageStore 'Microsoft.DocumentDB/databaseAccounts/sqlDatabases/containers@2024-12-01-preview' existing = {
25-
// parent: database
26-
// name: userThreadName
27-
// }
28-
2916
var roleDefinitionId = resourceId(
3017
'Microsoft.DocumentDB/databaseAccounts/sqlRoleDefinitions',
3118
cosmosAccountName,
@@ -43,4 +30,3 @@ resource containerRoleAssignmentUserContainer 'Microsoft.DocumentDB/databaseAcco
4330
scope: accountScope
4431
}
4532
}
46-

samples/microsoft/infrastructure-setup/16-private-network-standard-agent-apim-setup-preview/azuredeploy.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
"_generator": {
66
"name": "bicep",
77
"version": "0.39.26.7824",
8-
"templateHash": "13333646941739374884"
8+
"templateHash": "12031247753870237603"
99
}
1010
},
1111
"parameters": {
@@ -2770,7 +2770,7 @@
27702770
"_generator": {
27712771
"name": "bicep",
27722772
"version": "0.39.26.7824",
2773-
"templateHash": "16291470712974205281"
2773+
"templateHash": "17187611271934567223"
27742774
}
27752775
},
27762776
"parameters": {
@@ -2792,7 +2792,7 @@
27922792
},
27932793
"variables": {
27942794
"roleDefinitionId": "[resourceId('Microsoft.DocumentDB/databaseAccounts/sqlRoleDefinitions', parameters('cosmosAccountName'), '00000000-0000-0000-0000-000000000002')]",
2795-
"accountScope": "[format('/subscriptions/{0}/resourceGroups/{1}/providers/Microsoft.DocumentDB/databaseAccounts/{2}', subscription().subscriptionId, resourceGroup().name, parameters('cosmosAccountName'))]"
2795+
"accountScope": "[format('/subscriptions/{0}/resourceGroups/{1}/providers/Microsoft.DocumentDB/databaseAccounts/{2}/dbs/enterprise_memory', subscription().subscriptionId, resourceGroup().name, parameters('cosmosAccountName'))]"
27962796
},
27972797
"resources": [
27982798
{

samples/microsoft/infrastructure-setup/16-private-network-standard-agent-apim-setup-preview/modules-network-secured/cosmos-container-role-assignments.bicep

Lines changed: 0 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -8,24 +8,11 @@ param projectPrincipalId string
88

99
param projectWorkspaceId string
1010

11-
// var userThreadName = '${projectWorkspaceId}-thread-message-store'
12-
1311
resource cosmosAccount 'Microsoft.DocumentDB/databaseAccounts@2024-12-01-preview' existing = {
1412
name: cosmosAccountName
1513
scope: resourceGroup()
1614
}
1715

18-
// // Reference existing database
19-
// resource database 'Microsoft.DocumentDB/databaseAccounts/sqlDatabases@2024-12-01-preview' existing = {
20-
// parent: cosmosAccount
21-
// name: 'enterprise_memory'
22-
// }
23-
24-
// resource containerUserMessageStore 'Microsoft.DocumentDB/databaseAccounts/sqlDatabases/containers@2024-12-01-preview' existing = {
25-
// parent: database
26-
// name: userThreadName
27-
// }
28-
2916
var roleDefinitionId = resourceId(
3017
'Microsoft.DocumentDB/databaseAccounts/sqlRoleDefinitions',
3118
cosmosAccountName,
@@ -43,4 +30,3 @@ resource containerRoleAssignmentUserContainer 'Microsoft.DocumentDB/databaseAcco
4330
scope: accountScope
4431
}
4532
}
46-

samples/microsoft/infrastructure-setup/17-private-network-standard-user-assigned-identity-agent-setup/azuredeploy.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
"_generator": {
66
"name": "bicep",
77
"version": "0.39.26.7824",
8-
"templateHash": "1485106587909607955"
8+
"templateHash": "290789416224749131"
99
}
1010
},
1111
"parameters": {
@@ -2737,7 +2737,7 @@
27372737
"_generator": {
27382738
"name": "bicep",
27392739
"version": "0.39.26.7824",
2740-
"templateHash": "16291470712974205281"
2740+
"templateHash": "17187611271934567223"
27412741
}
27422742
},
27432743
"parameters": {
@@ -2759,7 +2759,7 @@
27592759
},
27602760
"variables": {
27612761
"roleDefinitionId": "[resourceId('Microsoft.DocumentDB/databaseAccounts/sqlRoleDefinitions', parameters('cosmosAccountName'), '00000000-0000-0000-0000-000000000002')]",
2762-
"accountScope": "[format('/subscriptions/{0}/resourceGroups/{1}/providers/Microsoft.DocumentDB/databaseAccounts/{2}', subscription().subscriptionId, resourceGroup().name, parameters('cosmosAccountName'))]"
2762+
"accountScope": "[format('/subscriptions/{0}/resourceGroups/{1}/providers/Microsoft.DocumentDB/databaseAccounts/{2}/dbs/enterprise_memory', subscription().subscriptionId, resourceGroup().name, parameters('cosmosAccountName'))]"
27632763
},
27642764
"resources": [
27652765
{

samples/microsoft/infrastructure-setup/17-private-network-standard-user-assigned-identity-agent-setup/modules-network-secured/cosmos-container-role-assignments.bicep

Lines changed: 0 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -8,24 +8,11 @@ param projectPrincipalId string
88

99
param projectWorkspaceId string
1010

11-
// var userThreadName = '${projectWorkspaceId}-thread-message-store'
12-
1311
resource cosmosAccount 'Microsoft.DocumentDB/databaseAccounts@2024-12-01-preview' existing = {
1412
name: cosmosAccountName
1513
scope: resourceGroup()
1614
}
1715

18-
// // Reference existing database
19-
// resource database 'Microsoft.DocumentDB/databaseAccounts/sqlDatabases@2024-12-01-preview' existing = {
20-
// parent: cosmosAccount
21-
// name: 'enterprise_memory'
22-
// }
23-
24-
// resource containerUserMessageStore 'Microsoft.DocumentDB/databaseAccounts/sqlDatabases/containers@2024-12-01-preview' existing = {
25-
// parent: database
26-
// name: userThreadName
27-
// }
28-
2916
var roleDefinitionId = resourceId(
3017
'Microsoft.DocumentDB/databaseAccounts/sqlRoleDefinitions',
3118
cosmosAccountName,
@@ -43,4 +30,3 @@ resource containerRoleAssignmentUserContainer 'Microsoft.DocumentDB/databaseAcco
4330
scope: accountScope
4431
}
4532
}
46-

samples/microsoft/infrastructure-setup/31-customer-managed-keys-standard-agent/main.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
"_generator": {
66
"name": "bicep",
77
"version": "0.39.26.7824",
8-
"templateHash": "5355284057522929069"
8+
"templateHash": "9028717141391138763"
99
}
1010
},
1111
"parameters": {
@@ -1194,7 +1194,7 @@
11941194
"_generator": {
11951195
"name": "bicep",
11961196
"version": "0.39.26.7824",
1197-
"templateHash": "11286754940754531283"
1197+
"templateHash": "8346749807649424278"
11981198
}
11991199
},
12001200
"parameters": {
@@ -1213,7 +1213,7 @@
12131213
},
12141214
"variables": {
12151215
"roleDefinitionId": "[resourceId('Microsoft.DocumentDB/databaseAccounts/sqlRoleDefinitions', parameters('cosmosAccountName'), '00000000-0000-0000-0000-000000000002')]",
1216-
"accountScope": "[format('/subscriptions/{0}/resourceGroups/{1}/providers/Microsoft.DocumentDB/databaseAccounts/{2}', subscription().subscriptionId, resourceGroup().name, parameters('cosmosAccountName'))]"
1216+
"accountScope": "[format('/subscriptions/{0}/resourceGroups/{1}/providers/Microsoft.DocumentDB/databaseAccounts/{2}/dbs/enterprise_memory', subscription().subscriptionId, resourceGroup().name, parameters('cosmosAccountName'))]"
12171217
},
12181218
"resources": [
12191219
{

samples/microsoft/infrastructure-setup/31-customer-managed-keys-standard-agent/modules-standard/cosmos-container-role-assignments.bicep

Lines changed: 0 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -6,25 +6,11 @@ param cosmosAccountName string
66
@description('Project name')
77
param projectPrincipalId string
88

9-
10-
// var userThreadName = '${projectWorkspaceId}-thread-message-store'
11-
129
resource cosmosAccount 'Microsoft.DocumentDB/databaseAccounts@2024-12-01-preview' existing = {
1310
name: cosmosAccountName
1411
scope: resourceGroup()
1512
}
1613

17-
// // Reference existing database
18-
// resource database 'Microsoft.DocumentDB/databaseAccounts/sqlDatabases@2024-12-01-preview' existing = {
19-
// parent: cosmosAccount
20-
// name: 'enterprise_memory'
21-
// }
22-
23-
// resource containerUserMessageStore 'Microsoft.DocumentDB/databaseAccounts/sqlDatabases/containers@2024-12-01-preview' existing = {
24-
// parent: database
25-
// name: userThreadName
26-
// }
27-
2814
var roleDefinitionId = resourceId(
2915
'Microsoft.DocumentDB/databaseAccounts/sqlRoleDefinitions',
3016
cosmosAccountName,

samples/microsoft/infrastructure-setup/41-standard-agent-setup/azuredeploy.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
"_generator": {
66
"name": "bicep",
77
"version": "0.39.26.7824",
8-
"templateHash": "7504975286451014433"
8+
"templateHash": "7659596839548579132"
99
}
1010
},
1111
"parameters": {
@@ -1337,7 +1337,7 @@
13371337
"_generator": {
13381338
"name": "bicep",
13391339
"version": "0.39.26.7824",
1340-
"templateHash": "16291470712974205281"
1340+
"templateHash": "17187611271934567223"
13411341
}
13421342
},
13431343
"parameters": {
@@ -1359,7 +1359,7 @@
13591359
},
13601360
"variables": {
13611361
"roleDefinitionId": "[resourceId('Microsoft.DocumentDB/databaseAccounts/sqlRoleDefinitions', parameters('cosmosAccountName'), '00000000-0000-0000-0000-000000000002')]",
1362-
"accountScope": "[format('/subscriptions/{0}/resourceGroups/{1}/providers/Microsoft.DocumentDB/databaseAccounts/{2}', subscription().subscriptionId, resourceGroup().name, parameters('cosmosAccountName'))]"
1362+
"accountScope": "[format('/subscriptions/{0}/resourceGroups/{1}/providers/Microsoft.DocumentDB/databaseAccounts/{2}/dbs/enterprise_memory', subscription().subscriptionId, resourceGroup().name, parameters('cosmosAccountName'))]"
13631363
},
13641364
"resources": [
13651365
{

samples/microsoft/infrastructure-setup/41-standard-agent-setup/modules-standard/cosmos-container-role-assignments.bicep

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -8,24 +8,11 @@ param projectPrincipalId string
88

99
param projectWorkspaceId string
1010

11-
// var userThreadName = '${projectWorkspaceId}-thread-message-store'
12-
1311
resource cosmosAccount 'Microsoft.DocumentDB/databaseAccounts@2024-12-01-preview' existing = {
1412
name: cosmosAccountName
1513
scope: resourceGroup()
1614
}
1715

18-
// // Reference existing database
19-
// resource database 'Microsoft.DocumentDB/databaseAccounts/sqlDatabases@2024-12-01-preview' existing = {
20-
// parent: cosmosAccount
21-
// name: 'enterprise_memory'
22-
// }
23-
24-
// resource containerUserMessageStore 'Microsoft.DocumentDB/databaseAccounts/sqlDatabases/containers@2024-12-01-preview' existing = {
25-
// parent: database
26-
// name: userThreadName
27-
// }
28-
2916
var roleDefinitionId = resourceId(
3017
'Microsoft.DocumentDB/databaseAccounts/sqlRoleDefinitions',
3118
cosmosAccountName,

0 commit comments

Comments
 (0)