Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

azurerm_windows[linux]_web[function]_app[app_slot] - remove restriction for client secret name and cert name #21834

Merged
merged 10 commits into from
Dec 11, 2023

Conversation

xiaxyi
Copy link
Contributor

@xiaxyi xiaxyi commented May 18, 2023

The client secret name and cert name can be empty according to the API behavior, so remove the restriction from Terraform as well.

fix #20676

--- PASS: TestAccLinuxWebApp_authV2AzureActiveDirectoryNoSecretName (267.97s)
--- PASS: TestAccLinuxWebAppSlot_withAuthV2AzureActiveDirectoryNoSecretName (339.99s)
--- PASS: TestAccLinuxFunctionApp_authV2AzureActiveDirectoryNoSecretName (304.82s)
--- PASS: TestAccLinuxFunctionAppSlot_authV2AzureActiveDirectoryNoSecretName (393.33s)
--- PASS: TestAccWindowsWebApp_authV2AzureActiveDirectoryNoSecretName (281.31s)
--- PASS: TestAccWindowsWebAppSlot_withAuthV2AzureActiveDirectoryNoSecretName (367.50s)
--- PASS: TestAccWindowsFunctionApp_authV2AzureActiveDirectoryNoSecretName (316.45s)
--- PASS: TestAccWindowsFunctionAppSlot_authV2AzureActiveDirectoryNoSecretName (394.88s)

@jackofallops jackofallops self-assigned this Jun 26, 2023
@ilmax
Copy link
Contributor

ilmax commented Jul 24, 2023

@jackofallops can this one be reviewed? I'm currently blocked on this very same issue

Copy link
Member

@jackofallops jackofallops left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @xiaxyi - Thanks for this PR. Just one comment to check on the docs (sadly it applies to all of the docs touched). If you can check and update, I think this will be good to merge.

Thanks!

@@ -291,11 +291,9 @@ An `active_directory_v2` block supports the following:

* `client_secret_setting_name` - (Optional) The App Setting name that contains the client secret of the Client.

!> **NOTE:** A setting with this name must exist in `app_settings` to function correctly.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This needs to remain I think. clientSecretCertificateThumbprint is not an app service app_setting value afaik, so does not need the note changing to the below, it can simply be removed. This will apply to all the docs changed in this way.

@ilmax
Copy link
Contributor

ilmax commented Dec 7, 2023

Hey @xiaxyi do you have time to follow up on this PR?

@xiaxyi
Copy link
Contributor Author

xiaxyi commented Dec 11, 2023

@jackofallops Thanks for the review, doc is updated.

@xiaxyi
Copy link
Contributor Author

xiaxyi commented Dec 11, 2023

@ilmax Thanks for the comment, PR is updated.

Copy link
Member

@jackofallops jackofallops left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @xiaxyi - Thanks for the update this LGTM now 👍

@jackofallops
Copy link
Member

Tests look good, failures are unrelated:

image

@jackofallops jackofallops merged commit f3310c3 into hashicorp:main Dec 11, 2023
24 checks passed
@github-actions github-actions bot added this to the v3.85.0 milestone Dec 11, 2023
jackofallops added a commit that referenced this pull request Dec 11, 2023
dduportal pushed a commit to jenkins-infra/azure that referenced this pull request Dec 15, 2023
<Actions>
<action
id="f410411e63aff4bb73a81c2aec1d373cf8a903e63b30dee2006b0030d8a94cc8">
        <h3>Bump Terraform `azurerm` provider version</h3>
<details
id="1d9343c012f5434ac9fe8a98135bae3667b399259be16d9b14302ea3bd424a24">
            <summary>Update Terraform lock file</summary>
<p>&#34;hashicorp/azurerm&#34; updated from &#34;3.84.0&#34; to
&#34;3.85.0&#34; in file &#34;.terraform.lock.hcl&#34;</p>
            <details>
                <summary>3.85.0</summary>
<pre>Changelog retrieved
from:&#xA;&#x9;https://github.com/hashicorp/terraform-provider-azurerm/releases/tag/v3.85.0&#xA;FEATURES:&#xA;&#xA;*
New Data Source: `azurerm_locations`
([#23324](https://github.com/hashicorp/terraform-provider-azurerm/issues/23324))&#xA;*
New Resource: `azurerm_iotcentral_organization`
([#23132](https://github.com/hashicorp/terraform-provider-azurerm/issues/23132))&#xA;&#xA;ENHANCEMENTS:&#xA;&#xA;*
provider: support for authenticating using Azure Kubernetes Service
Workload Identity
([#23965](https://github.com/hashicorp/terraform-provider-azurerm/issues/23965))&#xA;*
dependencies: updating to `v0.65.0` of
`github.com/hashicorp/go-azure-helpers`
([#24222](https://github.com/hashicorp/terraform-provider-azurerm/issues/24222))&#xA;*
dependencies: updating to `v0.20231214.1220802` of
`github.com/hashicorp/go-azure-sdk`
([#24246](https://github.com/hashicorp/terraform-provider-azurerm/issues/24246))&#xA;*
dependencies: updating to version `v0.20231214.1160726` of
`github.com/hashicorp/go-azure-sdk`
([#24241](https://github.com/hashicorp/terraform-provider-azurerm/issues/24241))&#xA;*
dependencies: update `security/automation` to use
`hashicorp/go-azure-sdk`
([#24156](https://github.com/hashicorp/terraform-provider-azurerm/issues/24156))&#xA;*
`dataprotection`: updating to API Version `2023-05-01`
([#24143](https://github.com/hashicorp/terraform-provider-azurerm/issues/24143))&#xA;*
`kusto`: removing the remnants of the old Resource ID Parsers now this
uses `hashicorp/go-azure-sdk`
([#24238](https://github.com/hashicorp/terraform-provider-azurerm/issues/24238))&#xA;*
Data Source: `azurerm_cognitive_account` - export the `identity` block
([#24214](https://github.com/hashicorp/terraform-provider-azurerm/issues/24214))&#xA;*
Data Source: `azurerm_monitor_workspace` - add support for the
`default_data_collection_endpoint_id` and
`default_data_collection_rule_id` properties
([#24153](https://github.com/hashicorp/terraform-provider-azurerm/issues/24153))&#xA;*
Data Source: `azurerm_shared_image_gallery` - add support for the
`image_names` property
([#24176](https://github.com/hashicorp/terraform-provider-azurerm/issues/24176))&#xA;*
`azurerm_dns_txt_record` - allow up to `4096` characters for the
property `record.value`
([#24169](https://github.com/hashicorp/terraform-provider-azurerm/issues/24169))&#xA;*
`azurerm_container_app` - support for the `workload_profile_name`
property
([#24219](https://github.com/hashicorp/terraform-provider-azurerm/issues/24219))&#xA;*
`azurerm_container_app` - suppot for the `init_container` block
([#23955](https://github.com/hashicorp/terraform-provider-azurerm/issues/23955))&#xA;*
`azurerm_hpc_cache_blob_nfs_target` - support for the
`verification_timer_in_seconds` and `write_back_timer_in_seconds`
properties
([#24207](https://github.com/hashicorp/terraform-provider-azurerm/issues/24207))&#xA;*
`azurerm_hpc_cache_nfs_target` - support for the
`verification_timer_in_seconds` and `write_back_timer_in_seconds`
properties
([#24208](https://github.com/hashicorp/terraform-provider-azurerm/issues/24208))&#xA;*
`azurerm_linux_web_app` - make `client_secret_setting_name` optional and
conflict with `client_secret_certificate_thumbprint`
([#21834](https://github.com/hashicorp/terraform-provider-azurerm/issues/21834))&#xA;*
`azurerm_linux_web_app_slot` - make `client_secret_setting_name`
optional and conflict with `client_secret_certificate_thumbprint`
([#21834](https://github.com/hashicorp/terraform-provider-azurerm/issues/21834))&#xA;*
`azurerm_linux_web_app` - fix a bug in `app_settings` where settings
could be lost
([#24221](https://github.com/hashicorp/terraform-provider-azurerm/issues/24221))&#xA;*
`azurerm_linux_web_app_slot` - fix a bug in `app_settings` where
settings could be lost
([#24221](https://github.com/hashicorp/terraform-provider-azurerm/issues/24221))&#xA;*
`azurerm_log_analytics_workspace` - add support for the
`immediate_data_purge_on_30_days_enabled` property
([#24015](https://github.com/hashicorp/terraform-provider-azurerm/issues/24015))&#xA;*
`azurerm_mssql_server` - support for other identity types for the key
vault key
([#24236](https://github.com/hashicorp/terraform-provider-azurerm/issues/24236))&#xA;*
`azurerm_machine_learning_datastore_blobstorage` - resource now skips
validation when being created
([#24078](https://github.com/hashicorp/terraform-provider-azurerm/issues/24078))&#xA;*
`azurerm_machine_learning_datastore_datalake_gen2` - resource now skips
validation when being created
([#24078](https://github.com/hashicorp/terraform-provider-azurerm/issues/24078))&#xA;*
`azurerm_machine_learning_datastore_fileshare` - resource now skips
validation when being created
([#24078](https://github.com/hashicorp/terraform-provider-azurerm/issues/24078))&#xA;*
`azurerm_monitor_workspace` - support for the
`default_data_collection_endpoint_id` and
`default_data_collection_rule_id` properties
([#24153](https://github.com/hashicorp/terraform-provider-azurerm/issues/24153))&#xA;*
`azurerm_redis_cache` - support for the
`storage_account_subscription_id` property
([#24101](https://github.com/hashicorp/terraform-provider-azurerm/issues/24101))&#xA;*
`azurerm_storage_blob` - support for the `source_content` type `Page`
([#24177](https://github.com/hashicorp/terraform-provider-azurerm/issues/24177))&#xA;*
`azurerm_web_application_firewall_policy` - support new values to the
`rule_group_name` property
([#24194](https://github.com/hashicorp/terraform-provider-azurerm/issues/24194))&#xA;*
`azurerm_windows_web_app` - make the `client_secret_setting_name`
property optional and conflicts with the
`client_secret_certificate_thumbprint` property
([#21834](https://github.com/hashicorp/terraform-provider-azurerm/issues/21834))&#xA;*
`azurerm_windows_web_app_slot` - make the `client_secret_setting_name`
property optional and conflicts with the
`client_secret_certificate_thumbprint` property
([#21834](https://github.com/hashicorp/terraform-provider-azurerm/issues/21834))&#xA;*
`azurerm_windows_web_app` - fix a bug in `app_settings` where settings
could be lost
([#24221](https://github.com/hashicorp/terraform-provider-azurerm/issues/24221))&#xA;*
`azurerm_windows_web_app_slot` - fix a bug in `app_settings` where
settings could be lost
([#24221](https://github.com/hashicorp/terraform-provider-azurerm/issues/24221))&#xA;*
`azurerm_cognitive_account` - add `ContentSafety` to the `kind` property
validation
([#24205](https://github.com/hashicorp/terraform-provider-azurerm/issues/24205))&#xA;&#xA;BUG
FIXES:&#xA;&#xA;* provider: fix an authentication issue with Azure
Storage when running in Azure China cloud
([#24246](https://github.com/hashicorp/terraform-provider-azurerm/issues/24246))&#xA;*
Data Source: `azurerm_role_definition` - fix bug where
`role_definition_id` and `scope` were being incorrectly set
([#24211](https://github.com/hashicorp/terraform-provider-azurerm/issues/24211))&#xA;*
`azurerm_batch_account` - fix bug where `UserAssigned, SystemAssigned`
could be passed to the resource even though it isn&#39;t supported
([#24204](https://github.com/hashicorp/terraform-provider-azurerm/issues/24204))&#xA;*
`azurerm_batch_pool` - fix bug where `settings_json` and
`protected_settings` were not being unmarshaled
([#24075](https://github.com/hashicorp/terraform-provider-azurerm/issues/24075))&#xA;*
`azurerm_bot_service_azure_bot` - fix bug where
`public_network_access_enabled` was being set as the value for `LuisKey`
([#24164](https://github.com/hashicorp/terraform-provider-azurerm/issues/24164))&#xA;*
`azurerm_cognitive_account_customer_managed_key` - `identity_client_id`
is no longer passed to the api when it is empty
([#24231](https://github.com/hashicorp/terraform-provider-azurerm/issues/24231))&#xA;*
`azurerm_linux_web_app_slot` - error when `service_plan_id` is identical
to the parent `service_plan_id`
([#23403](https://github.com/hashicorp/terraform-provider-azurerm/issues/23403))&#xA;*
`azurerm_management_group_template_deployment` - fixing a bug where
`template_spec_version_id` couldn&#39;t be updated
([#24072](https://github.com/hashicorp/terraform-provider-azurerm/issues/24072))&#xA;*
`azurerm_pim_active_role_assignment` - fix an importing issue by
filtering available role assignments based on the provided `scope`
([#24077](https://github.com/hashicorp/terraform-provider-azurerm/issues/24077))&#xA;*
`azurerm_pim_eligible_role_assignment` - fix an importing issue by
filtering available role assignments based on the provided `scope`
([#24077](https://github.com/hashicorp/terraform-provider-azurerm/issues/24077))&#xA;*
`azurerm_resource_group_template_deployment` - fixing a bug where
`template_spec_version_id` couldn&#39;t be updated
([#24072](https://github.com/hashicorp/terraform-provider-azurerm/issues/24072))&#xA;*
`azurerm_security_center_setting` - fix the casing for the
`setting_name` `Sentinel`
([#24210](https://github.com/hashicorp/terraform-provider-azurerm/issues/24210))&#xA;*
`azurerm_storage_account` - Fix crash when checking for
`routingInputs.PublishInternetEndpoints` and
`routingInputs.PublishMicrosoftEndpoints`
([#24228](https://github.com/hashicorp/terraform-provider-azurerm/issues/24228))&#xA;*
`azurerm_storage_share_file` - prevent panic when the file specified by
`source` is empty
([#24179](https://github.com/hashicorp/terraform-provider-azurerm/issues/24179))&#xA;*
`azurerm_subscription_template_deployment` - fixing a bug where
`template_spec_version_id` couldn&#39;t be updated
([#24072](https://github.com/hashicorp/terraform-provider-azurerm/issues/24072))&#xA;*
`azurerm_tenant_template_deployment` - fixing a bug where
`template_spec_version_id` couldn&#39;t be updated
([#24072](https://github.com/hashicorp/terraform-provider-azurerm/issues/24072))&#xA;*
`azurerm_virtual_machine` - prevent a panic by nil checking the first
element of `additional_capabilities`
([#24159](https://github.com/hashicorp/terraform-provider-azurerm/issues/24159))&#xA;*
`azurerm_windows_web_app_slot` - error when `service_plan_id` is
identical to the parent `service_plan_id`
([#23403](https://github.com/hashicorp/terraform-provider-azurerm/issues/23403))&#xA;&#xA;&#xA;</pre>
            </details>
        </details>
<a
href="https://infra.ci.jenkins.io/job/terraform-jobs/job/azure/job/main/942/">Jenkins
pipeline link</a>
    </action>
</Actions>

---

<table>
  <tr>
    <td width="77">
<img src="https://www.updatecli.io/images/updatecli.png" alt="Updatecli
logo" width="50" height="50">
    </td>
    <td>
      <p>
Created automatically by <a
href="https://www.updatecli.io/">Updatecli</a>
      </p>
      <details><summary>Options:</summary>
        <br />
<p>Most of Updatecli configuration is done via <a
href="https://www.updatecli.io/docs/prologue/quick-start/">its
manifest(s)</a>.</p>
        <ul>
<li>If you close this pull request, Updatecli will automatically reopen
it, the next time it runs.</li>
<li>If you close this pull request and delete the base branch, Updatecli
will automatically recreate it, erasing all previous commits made.</li>
        </ul>
        <p>
Feel free to report any issues at <a
href="https://github.com/updatecli/updatecli/issues">github.com/updatecli/updatecli</a>.<br
/>
If you find this tool useful, do not hesitate to star <a
href="https://github.com/updatecli/updatecli/stargazers">our GitHub
repository</a> as a sign of appreciation, and/or to tell us directly on
our <a
href="https://matrix.to/#/#Updatecli_community:gitter.im">chat</a>!
        </p>
      </details>
    </td>
  </tr>
</table>

Co-authored-by: Jenkins Infra Bot (updatecli) <60776566+jenkins-infra-bot@users.noreply.github.com>
Copy link

github-actions bot commented May 3, 2024

I'm going to lock this pull request because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active contributions.
If you have found a problem that seems related to this change, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators May 3, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

auth_settings_v2 on azurerm_linux_web_app requires client secret
3 participants