Skip to content

fix(ci): align Azure OIDC trust with renamed immutable repository identity #336

Description

@cristim

Summary

Azure Sanity fails before running its tests after the repository identity changed to LeanerCloud/reserved-instances-cli with immutable OIDC subjects enabled. This blocks normal merging of PR LeanerCloud/cloud-commitments-cli#1889; no check bypass is authorized.

Observed evidence

  • Exact PR head: 2b0310847db4232d0c7e28133c3ac1893a15fbf1.
  • Failed run: https://github.com/LeanerCloud/reserved-instances-cli/actions/runs/35037134858
  • Azure Login reports AADSTS700213, no matching federated identity record for repo:LeanerCloud@86753534/reserved-instances-cli@1106317010:pull_request.
  • Read-only GitHub actions/oidc/customization/sub response: use_default: true, use_immutable_subject: true, prefix repo:LeanerCloud@86753534/reserved-instances-cli@1106317010.
  • Read-only inspection of the cudly-terraform-deploy application shows its PR and main credentials still use repo:LeanerCloud/CUDly:pull_request and repo:LeanerCloud/CUDly:ref:refs/heads/main. A legacy feature-branch credential also uses the old repository name. No cloud state has been changed.

Reproduction and expected behavior

The Azure Sanity PR workflow receives the new GitHub subject and fails at login, before Build + Run Azure sanity. Its existing issuer and audience are https://token.actions.githubusercontent.com and api://AzureADTokenExchange.

Expected: the intended CI identity accepts the current repository's exact scoped subjects, without broadening issuer, audience or resource permissions, and the sanity tests run successfully. Main-branch trust needs checking before merging so the subsequent deployment is not stranded. Main deployment failure has not been exercised in this investigation.

Proposed fix and boundary

After explicit operator approval, verify the application's client ID against the configured CI identity and update the bootstrap-managed PR/main federated subjects to match current GitHub claims. Preserve scope and have a rollback to the prior subject values. Keep the Terraform source in terraform/environments/azure/ci-cd-permissions/sp.tf and associated configuration consistent with the actual trust; current expressions at lines39-58 use the old name-only subject format. Do not disable immutable subjects or skip Azure Sanity to make CI green.

Re-run failed Azure Sanity on the same head after the authorized trust correction. Require all other exact-head CI, substantive CodeRabbit review and independent local review before merge. The bootstrap module is privileged/manual by project policy; this report does not authorize its application.

Severity: high, urgency now, internal shipping impact. Found while following PR LeanerCloud/cloud-commitments-cli#1889; tracked separately from its audit-log changes.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions