Summary
Azure Sanity fails before running its tests after the repository identity changed to LeanerCloud/reserved-instances-cli with immutable OIDC subjects enabled. This blocks normal merging of PR LeanerCloud/cloud-commitments-cli#1889; no check bypass is authorized.
Observed evidence
- Exact PR head:
2b0310847db4232d0c7e28133c3ac1893a15fbf1.
- Failed run: https://github.com/LeanerCloud/reserved-instances-cli/actions/runs/35037134858
- Azure Login reports
AADSTS700213, no matching federated identity record for repo:LeanerCloud@86753534/reserved-instances-cli@1106317010:pull_request.
- Read-only GitHub
actions/oidc/customization/sub response: use_default: true, use_immutable_subject: true, prefix repo:LeanerCloud@86753534/reserved-instances-cli@1106317010.
- Read-only inspection of the
cudly-terraform-deploy application shows its PR and main credentials still use repo:LeanerCloud/CUDly:pull_request and repo:LeanerCloud/CUDly:ref:refs/heads/main. A legacy feature-branch credential also uses the old repository name. No cloud state has been changed.
Reproduction and expected behavior
The Azure Sanity PR workflow receives the new GitHub subject and fails at login, before Build + Run Azure sanity. Its existing issuer and audience are https://token.actions.githubusercontent.com and api://AzureADTokenExchange.
Expected: the intended CI identity accepts the current repository's exact scoped subjects, without broadening issuer, audience or resource permissions, and the sanity tests run successfully. Main-branch trust needs checking before merging so the subsequent deployment is not stranded. Main deployment failure has not been exercised in this investigation.
Proposed fix and boundary
After explicit operator approval, verify the application's client ID against the configured CI identity and update the bootstrap-managed PR/main federated subjects to match current GitHub claims. Preserve scope and have a rollback to the prior subject values. Keep the Terraform source in terraform/environments/azure/ci-cd-permissions/sp.tf and associated configuration consistent with the actual trust; current expressions at lines39-58 use the old name-only subject format. Do not disable immutable subjects or skip Azure Sanity to make CI green.
Re-run failed Azure Sanity on the same head after the authorized trust correction. Require all other exact-head CI, substantive CodeRabbit review and independent local review before merge. The bootstrap module is privileged/manual by project policy; this report does not authorize its application.
Severity: high, urgency now, internal shipping impact. Found while following PR LeanerCloud/cloud-commitments-cli#1889; tracked separately from its audit-log changes.
Summary
Azure Sanity fails before running its tests after the repository identity changed to
LeanerCloud/reserved-instances-cliwith immutable OIDC subjects enabled. This blocks normal merging of PR LeanerCloud/cloud-commitments-cli#1889; no check bypass is authorized.Observed evidence
2b0310847db4232d0c7e28133c3ac1893a15fbf1.AADSTS700213, no matching federated identity record forrepo:LeanerCloud@86753534/reserved-instances-cli@1106317010:pull_request.actions/oidc/customization/subresponse:use_default: true,use_immutable_subject: true, prefixrepo:LeanerCloud@86753534/reserved-instances-cli@1106317010.cudly-terraform-deployapplication shows its PR and main credentials still userepo:LeanerCloud/CUDly:pull_requestandrepo:LeanerCloud/CUDly:ref:refs/heads/main. A legacy feature-branch credential also uses the old repository name. No cloud state has been changed.Reproduction and expected behavior
The Azure Sanity PR workflow receives the new GitHub subject and fails at login, before
Build + Run Azure sanity. Its existing issuer and audience arehttps://token.actions.githubusercontent.comandapi://AzureADTokenExchange.Expected: the intended CI identity accepts the current repository's exact scoped subjects, without broadening issuer, audience or resource permissions, and the sanity tests run successfully. Main-branch trust needs checking before merging so the subsequent deployment is not stranded. Main deployment failure has not been exercised in this investigation.
Proposed fix and boundary
After explicit operator approval, verify the application's client ID against the configured CI identity and update the bootstrap-managed PR/main federated subjects to match current GitHub claims. Preserve scope and have a rollback to the prior subject values. Keep the Terraform source in
terraform/environments/azure/ci-cd-permissions/sp.tfand associated configuration consistent with the actual trust; current expressions at lines39-58 use the old name-only subject format. Do not disable immutable subjects or skip Azure Sanity to make CI green.Re-run failed Azure Sanity on the same head after the authorized trust correction. Require all other exact-head CI, substantive CodeRabbit review and independent local review before merge. The bootstrap module is privileged/manual by project policy; this report does not authorize its application.
Severity: high, urgency now, internal shipping impact. Found while following PR LeanerCloud/cloud-commitments-cli#1889; tracked separately from its audit-log changes.