Summary
The custom role added by PR #744 (and now shared via terraform/modules/iam/azure/cudly-reservation-role) grants Microsoft.Capacity/register/action but not Microsoft.BillingBenefits/register/action. On a customer subscription that has never used Azure Savings Plans, the resource provider Microsoft.BillingBenefits may not be registered. The first Savings Plan order in that subscription will return a 409 MissingSubscriptionRegistration error until the provider is registered out-of-band.
Repro
- Use a "Savings Plan virgin" customer subscription (never created a Savings Plan before).
- Attempt to create a Savings Plan via CUDly's two-step calculatePrice -> purchase flow.
- Observe 409
MissingSubscriptionRegistration for Microsoft.BillingBenefits.
Fix
Append Microsoft.BillingBenefits/register/action to the actions list in both:
terraform/modules/iam/azure/cudly-reservation-role/main.tf (shared Terraform module)
arm/CUDly-CrossSubscription/template.json (customer ARM template)
Workaround
Until fixed, the customer administrator can run the following once before onboarding:
az provider register --namespace Microsoft.BillingBenefits
Registration is idempotent and typically completes within a few minutes.
Summary
The custom role added by PR #744 (and now shared via
terraform/modules/iam/azure/cudly-reservation-role) grantsMicrosoft.Capacity/register/actionbut notMicrosoft.BillingBenefits/register/action. On a customer subscription that has never used Azure Savings Plans, the resource providerMicrosoft.BillingBenefitsmay not be registered. The first Savings Plan order in that subscription will return a 409MissingSubscriptionRegistrationerror until the provider is registered out-of-band.Repro
MissingSubscriptionRegistrationforMicrosoft.BillingBenefits.Fix
Append
Microsoft.BillingBenefits/register/actionto theactionslist in both:terraform/modules/iam/azure/cudly-reservation-role/main.tf(shared Terraform module)arm/CUDly-CrossSubscription/template.json(customer ARM template)Workaround
Until fixed, the customer administrator can run the following once before onboarding:
Registration is idempotent and typically completes within a few minutes.