Skip to content

fix(ri-exchange): resolve Azure credentials via per-subscription resolver so Active Convertible RIs stop 500ing in Lambda #932

Description

@cristim

Repro

On the RI Exchange page, selecting the Azure provider tab shows:

Failed to load Azure reservations: Internal server error

Exchange History is empty as a downstream symptom.

Root cause

internal/api/handler_ri_exchange.go ~line 181, buildAzureExchangeClient calls azidentity.NewDefaultAzureCredential(nil) directly, bypassing the project's per-subscription credential resolver (internal/credentials/resolver.go, internal/secrets/azure_resolver.go, OIDC/WIF). In Lambda there is no ambient Azure identity in the default chain, so credential construction or armreservations NextPage fails, ListExchangeableReservations/collectExchangeableReservations wraps it, and the handler returns 500. The subscription_id query param is effectively ignored for auth.

PR #906 only added AWS account scoping and did not touch the Azure path.

Expected behaviour

  • When an Azure CloudAccount is registered for the requested subscription, the page loads the Active Convertible RIs table.
  • When no Azure account is configured, the page shows a graceful empty state rather than an opaque 500 error banner.

Fix

Replace azidentity.NewDefaultAzureCredential with credentials.ResolveAzureTokenCredentialWithOpts, scoped to the subscription_id query param. Mirror the exact pattern used by scheduler.collectAzureForAccount and purchase/execution.go:resolveAzureProvider.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions