Skip to content

feat(ci): assert ARM/TF parity for CUDly Azure custom role (closes #753) - #761

Merged
cristim merged 1 commit into
feat/multicloud-web-frontendfrom
feat/753-iac-parity-guard
May 27, 2026
Merged

cristim merged 1 commit into
feat/multicloud-web-frontendfrom
feat/753-iac-parity-guard

Conversation

@cristim

@cristim cristim commented May 27, 2026 •

Copy link
Copy Markdown
Member

Summary

CUDly's customer-onboarding stack carries the Azure custom-role actions list in two places: the shared Terraform module at terraform/modules/iam/azure/cudly-reservation-role/main.tf and the ARM template at arm/CUDly-CrossSubscription/template.json. The two can drift silently — adding an action to one side without the other is exactly the kind of bug PR #744 was opened to fix.

This adds a CI guard.

Changes

  • scripts/check-azure-role-parity.sh — extracts the actions array from both files, sorts them case-insensitively, and diffs. Exit 1 with a clear per-side delta when they differ.
  • scripts/test-azure-role-parity.sh — self-test that runs the check against scripts/testdata/role-parity/matching-* (expects exit 0) and scripts/testdata/role-parity/drifted-arm.json (expects exit 1).
  • .github/workflows/ci.yml — new azure-role-parity job runs both scripts on every CI run; wired into the ci-success gate.

Note on stacking

This branch was created off feat/multicloud-web-frontend, which does not yet contain the shared module from PR #744's host-parity extension. The diff therefore includes a recreated copy of that module; the duplicate will disappear when this PR is rebased after #744 merges.

Test plan

  • scripts/test-azure-role-parity.sh exits 0 locally.
  • Manually break the ARM actions list and confirm the script exits 1 with a useful diff.

Closes #753.

Summary by CodeRabbit

  • New Features

    • New custom Azure role for reservation purchasing and capacity management with appropriate permissions for Azure Capacity and Billing Benefits operations.
  • Chores

    • Added automated validation to ensure Azure role definitions remain synchronized across infrastructure deployment templates.

Review Change Stack

@cristim cristim added priority/p3 Polish / idea / may never ship severity/low Minor harm urgency/eventually No deadline impact/internal Team-internal only enhancement New feature or request triaged Item has been triaged labels May 27, 2026
@cristim

cristim commented May 27, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 27, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@cristim, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 45 minutes and 2 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: bdb3b1af-79d1-4ee5-b1a2-8d21a03c414f

📥 Commits

Reviewing files that changed from the base of the PR and between 20f846c and 48c4094.

📒 Files selected for processing (6)
  • .github/workflows/ci.yml
  • scripts/check-azure-role-parity.sh
  • scripts/test-azure-role-parity.sh
  • scripts/testdata/role-parity/drifted-arm.json
  • scripts/testdata/role-parity/matching-arm.json
  • scripts/testdata/role-parity/matching-tf.tf.fixture
📝 Walkthrough

Walkthrough

This PR establishes a Terraform IAM module for a custom Azure RBAC role and adds automated CI checks to ensure role action definitions remain synchronized between the Terraform module and ARM template sources.

Changes

Azure Role Definition Parity Validation

Layer / File(s) Summary
Terraform custom role module definition
terraform/modules/iam/azure/cudly-reservation-role/variables.tf, terraform/modules/iam/azure/cudly-reservation-role/main.tf, terraform/modules/iam/azure/cudly-reservation-role/outputs.tf
Defines input variables scope and name_suffix, creates an azurerm_role_definition resource granting Microsoft.Capacity and Microsoft.BillingBenefits actions, and exports the role's ARM resource ID for downstream role assignments. Sets provider constraints (azurerm >= 3.0, Terraform >= 1.5).
Parity checker script
scripts/check-azure-role-parity.sh
Extracts role action lists from both Terraform module (awk parsing) and ARM template (jq parsing), normalizes and sorts both lists, and compares them via diff. Validates file existence and action extraction; exits zero on match, nonzero with diagnostic stderr output on mismatch. Accepts --tf-file and --arm-file CLI flag overrides.
Test fixtures and test runner
scripts/testdata/role-parity/matching-arm.json, scripts/testdata/role-parity/matching-tf.tf.fixture, scripts/testdata/role-parity/drifted-arm.json, scripts/test-azure-role-parity.sh
Provides JSON and Terraform role definition fixtures for success (matching actions) and failure (ARM drift) cases. Test runner test-azure-role-parity.sh invokes the parity checker against each fixture pair, verifies expected exit codes, reports PASS/FAIL results, and exits successfully only when all cases pass.
CI workflow integration
.github/workflows/ci.yml
Adds azure-role-parity GitHub Actions job to run the parity checker and test suite on ubuntu-latest. Updates ci-success aggregation job to require azure-role-parity, so the overall CI gate fails if role definitions diverge.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

  • LeanerCloud/CUDly#732: Introduces the ARM template role definition that this PR validates against for action parity.

Suggested labels

effort/m, type/chore

Poem

🐰 Hops with joy through Terraform's verdant fields,
Where custom roles now guard their secret yields,
Two sources dance—ARM and TF aligned,
A parity guard keeps them entwined,
No drift shall slip past CI's watchful eyes!

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the primary change: adding CI assertions to verify parity between ARM and Terraform role definitions for the CUDly Azure custom role.
Linked Issues check ✅ Passed All coding requirements from issue #753 are met: parity checks between ARM and Terraform role actions, self-test fixtures, CI workflow integration, and clear diff output on mismatch.
Out of Scope Changes check ✅ Passed All changes are scoped to implementing the parity guard solution requested in #753; no unrelated modifications or scope creep detected.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/753-iac-parity-guard

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai

coderabbitai Bot commented May 27, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@terraform/modules/iam/azure/cudly-reservation-role/main.tf`:
- Around line 29-41: The permissions actions list in the permissions block is
missing the purchase permission
"Microsoft.Capacity/reservationorders/purchase/action"; update the actions array
in the permissions block (the list under permissions { actions = [...] }) to
include that permission string so the role includes the reservation purchase
capability and avoids 403s.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: f7a4b1c4-c741-44ca-a035-eb9b384f277b

📥 Commits

Reviewing files that changed from the base of the PR and between f5b76eb and 20f846c.

📒 Files selected for processing (9)
  • .github/workflows/ci.yml
  • scripts/check-azure-role-parity.sh
  • scripts/test-azure-role-parity.sh
  • scripts/testdata/role-parity/drifted-arm.json
  • scripts/testdata/role-parity/matching-arm.json
  • scripts/testdata/role-parity/matching-tf.tf.fixture
  • terraform/modules/iam/azure/cudly-reservation-role/main.tf
  • terraform/modules/iam/azure/cudly-reservation-role/outputs.tf
  • terraform/modules/iam/azure/cudly-reservation-role/variables.tf

Comment thread terraform/modules/iam/azure/cudly-reservation-role/main.tf
@cristim

cristim commented May 27, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 27, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Add scripts/check-azure-role-parity.sh, which extracts the actions list
from the azurerm_role_definition permissions block in the shared TF module
(terraform/modules/iam/azure/cudly-reservation-role/main.tf) and the
Microsoft.Authorization/roleDefinitions resource in the ARM onboarding
template (arm/CUDly-CrossSubscription/template.json), sorts both, and
diffs them case-insensitively.  Exit 1 with a clear error message when
they differ; exit 0 when in sync.

Also adds:
- scripts/test-azure-role-parity.sh: exercises the script against
  matching and drifted fixtures under scripts/testdata/role-parity/.
- terraform/modules/iam/azure/cudly-reservation-role/: the shared custom-
  role module (main.tf + variables.tf + outputs.tf) whose actions list the
  script treats as the authoritative source.
- .github/workflows/ci.yml: new azure-role-parity job that runs the check
  and the self-tests on every CI run; wired into the ci-success gate.
@cristim
cristim force-pushed the feat/753-iac-parity-guard branch from a152287 to 48c4094 Compare May 27, 2026 17:21
@cristim

cristim commented May 27, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 27, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim
cristim merged commit 29805ac into feat/multicloud-web-frontend May 27, 2026
5 checks passed
@cristim
cristim deleted the feat/753-iac-parity-guard branch May 27, 2026 17:58
cristim added a commit that referenced this pull request Sep 27, 2026
…) (#761)

Add scripts/check-azure-role-parity.sh, which extracts the actions list
from the azurerm_role_definition permissions block in the shared TF module
(terraform/modules/iam/azure/cudly-reservation-role/main.tf) and the
Microsoft.Authorization/roleDefinitions resource in the ARM onboarding
template (arm/CUDly-CrossSubscription/template.json), sorts both, and
diffs them case-insensitively.  Exit 1 with a clear error message when
they differ; exit 0 when in sync.

Also adds:
- scripts/test-azure-role-parity.sh: exercises the script against
  matching and drifted fixtures under scripts/testdata/role-parity/.
- terraform/modules/iam/azure/cudly-reservation-role/: the shared custom-
  role module (main.tf + variables.tf + outputs.tf) whose actions list the
  script treats as the authoritative source.
- .github/workflows/ci.yml: new azure-role-parity job that runs the check
  and the self-tests on every CI run; wired into the ci-success gate.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request impact/internal Team-internal only priority/p3 Polish / idea / may never ship severity/low Minor harm triaged Item has been triaged urgency/eventually No deadline

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant