feat(ci): assert ARM/TF parity for CUDly Azure custom role (closes #753) - #761
Conversation
|
@coderabbitai review |
|
Warning Review limit reached
More reviews will be available in 45 minutes and 2 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (6)
📝 WalkthroughWalkthroughThis PR establishes a Terraform IAM module for a custom Azure RBAC role and adds automated CI checks to ensure role action definitions remain synchronized between the Terraform module and ARM template sources. ChangesAzure Role Definition Parity Validation
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
Suggested labels
Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Warning Review ran into problems🔥 ProblemsGit: Failed to clone repository. Please run the Comment |
✅ Actions performedReview triggered.
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@terraform/modules/iam/azure/cudly-reservation-role/main.tf`:
- Around line 29-41: The permissions actions list in the permissions block is
missing the purchase permission
"Microsoft.Capacity/reservationorders/purchase/action"; update the actions array
in the permissions block (the list under permissions { actions = [...] }) to
include that permission string so the role includes the reservation purchase
capability and avoids 403s.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: f7a4b1c4-c741-44ca-a035-eb9b384f277b
📒 Files selected for processing (9)
.github/workflows/ci.ymlscripts/check-azure-role-parity.shscripts/test-azure-role-parity.shscripts/testdata/role-parity/drifted-arm.jsonscripts/testdata/role-parity/matching-arm.jsonscripts/testdata/role-parity/matching-tf.tf.fixtureterraform/modules/iam/azure/cudly-reservation-role/main.tfterraform/modules/iam/azure/cudly-reservation-role/outputs.tfterraform/modules/iam/azure/cudly-reservation-role/variables.tf
|
@coderabbitai review |
20f846c to
a152287
Compare
✅ Actions performedReview triggered.
|
Add scripts/check-azure-role-parity.sh, which extracts the actions list from the azurerm_role_definition permissions block in the shared TF module (terraform/modules/iam/azure/cudly-reservation-role/main.tf) and the Microsoft.Authorization/roleDefinitions resource in the ARM onboarding template (arm/CUDly-CrossSubscription/template.json), sorts both, and diffs them case-insensitively. Exit 1 with a clear error message when they differ; exit 0 when in sync. Also adds: - scripts/test-azure-role-parity.sh: exercises the script against matching and drifted fixtures under scripts/testdata/role-parity/. - terraform/modules/iam/azure/cudly-reservation-role/: the shared custom- role module (main.tf + variables.tf + outputs.tf) whose actions list the script treats as the authoritative source. - .github/workflows/ci.yml: new azure-role-parity job that runs the check and the self-tests on every CI run; wired into the ci-success gate.
a152287 to
48c4094
Compare
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
…) (#761) Add scripts/check-azure-role-parity.sh, which extracts the actions list from the azurerm_role_definition permissions block in the shared TF module (terraform/modules/iam/azure/cudly-reservation-role/main.tf) and the Microsoft.Authorization/roleDefinitions resource in the ARM onboarding template (arm/CUDly-CrossSubscription/template.json), sorts both, and diffs them case-insensitively. Exit 1 with a clear error message when they differ; exit 0 when in sync. Also adds: - scripts/test-azure-role-parity.sh: exercises the script against matching and drifted fixtures under scripts/testdata/role-parity/. - terraform/modules/iam/azure/cudly-reservation-role/: the shared custom- role module (main.tf + variables.tf + outputs.tf) whose actions list the script treats as the authoritative source. - .github/workflows/ci.yml: new azure-role-parity job that runs the check and the self-tests on every CI run; wired into the ci-success gate.
Summary
CUDly's customer-onboarding stack carries the Azure custom-role actions list in two places: the shared Terraform module at
terraform/modules/iam/azure/cudly-reservation-role/main.tfand the ARM template atarm/CUDly-CrossSubscription/template.json. The two can drift silently — adding an action to one side without the other is exactly the kind of bug PR #744 was opened to fix.This adds a CI guard.
Changes
scripts/check-azure-role-parity.sh— extracts theactionsarray from both files, sorts them case-insensitively, and diffs. Exit 1 with a clear per-side delta when they differ.scripts/test-azure-role-parity.sh— self-test that runs the check againstscripts/testdata/role-parity/matching-*(expects exit 0) andscripts/testdata/role-parity/drifted-arm.json(expects exit 1)..github/workflows/ci.yml— newazure-role-parityjob runs both scripts on every CI run; wired into theci-successgate.Note on stacking
This branch was created off
feat/multicloud-web-frontend, which does not yet contain the shared module from PR #744's host-parity extension. The diff therefore includes a recreated copy of that module; the duplicate will disappear when this PR is rebased after #744 merges.Test plan
scripts/test-azure-role-parity.shexits 0 locally.Closes #753.
Summary by CodeRabbit
New Features
Chores