Skip to content

upgrade vault-plugin-auth-azure to v0.20.2 into release/1.19.x #30052

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Mar 27, 2025

Conversation

thyton
Copy link
Contributor

@thyton thyton commented Mar 27, 2025

Description

What does this PR do?
The PR upgrades vault-plugin-auth-azure to v0.20.2 into release/1.19.x

TODO only if you're a HashiCorp employee

  • Backport Labels: If this fix needs to be backported, use the appropriate backport/ label that matches the desired release branch. Note that in the CE repo, the latest release branch will look like backport/x.x.x, but older release branches will be backport/ent/x.x.x+ent.
    • LTS: If this fixes a critical security vulnerability or severity 1 bug, it will also need to be backported to the current LTS versions of Vault. To ensure this, use all available enterprise labels.
  • ENT Breakage: If this PR either 1) removes a public function OR 2) changes the signature
    of a public function, even if that change is in a CE file, double check that
    applying the patch for this PR to the ENT repo and running tests doesn't
    break any tests. Sometimes ENT only tests rely on public functions in CE
    files.
  • Jira: If this change has an associated Jira, it's referenced either
    in the PR description, commit message, or branch name.
  • RFC: If this change has an associated RFC, please link it in the description.
  • ENT PR: If this change has an associated ENT PR, please link it in the
    description. Also, make sure the changelog is in this PR, not in your ENT PR.

@thyton thyton requested a review from a team as a code owner March 27, 2025 15:51
@thyton thyton requested a review from lursu March 27, 2025 15:51
@github-actions github-actions bot added the hashicorp-contributed-pr If the PR is HashiCorp (i.e. not-community) contributed label Mar 27, 2025
Copy link

CI Results:
All Go tests succeeded! ✅

Copy link

Build Results:
All builds succeeded! ✅

@thyton thyton added this to the 1.19.1 milestone Mar 27, 2025
@thyton thyton force-pushed the thyton/VAULT-27393/bump-vault-plugin-auth-azure-1.19.x branch from 8b475f7 to e025477 Compare March 27, 2025 16:17
@@ -0,0 +1,3 @@
```release-note:change
auth/azure: Update plugin to v0.20.2. Login requires `resource_group_name`, `vm_name`, and `vmss_name` to match token claims
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we still need to update the changelog in the plugin repo: https://github.com/hashicorp/vault-plugin-auth-azure/blob/main/CHANGELOG.md#unreleased

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we can do it in this PR: hashicorp/vault-plugin-auth-azure#198

Copy link
Contributor Author

@thyton thyton Mar 27, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@fairclothjm
do you think the note is clear on the requirement and doesn't mislead users?
resource_group_name is always required. vm_name is not required but will be validated against token claims if provided . vmss_name is similar to vm_name

cc @tvoran for other PRs you're working on

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it is probably ok, but if we wanted to be very clear, we could change it a bit to something like:

Login now requires `resource_group_name` to match token claims.  `vm_name` and `vmss_name` are also now required if present in the token claims.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Login now requires `resource_group_name` to match token claims.  `vm_name` and `vmss_name` are also now required to match the token claims if provided on login.

I edited a bit the second sentence. What do you think? @fairclothjm

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we can keep the original version. The Azure docs captures the details well

@thyton thyton merged commit dd2a5ef into main Mar 27, 2025
97 checks passed
@thyton thyton deleted the thyton/VAULT-27393/bump-vault-plugin-auth-azure-1.19.x branch March 27, 2025 19:01
@thyton
Copy link
Contributor Author

thyton commented Mar 27, 2025

I think we still need to update the changelog in the plugin repo: https://github.com/hashicorp/vault-plugin-auth-azure/blob/main/CHANGELOG.md#unreleased

@fairclothjm I will create it tomorrow. Thanks for the reminder :)!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
hashicorp-contributed-pr If the PR is HashiCorp (i.e. not-community) contributed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy