Skip to content

Commit

Permalink
[PAGOPA-1176] login
Browse files Browse the repository at this point in the history
  • Loading branch information
jacopocarlini committed Sep 12, 2023
1 parent ab2dd02 commit 99510b1
Show file tree
Hide file tree
Showing 3 changed files with 14 additions and 2 deletions.
4 changes: 3 additions & 1 deletion .github/workflows/release_deploy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -132,7 +132,9 @@ jobs:
- name: 'Login via Azure CLI'
uses: azure/login@v1
with:
creds: ${{ secrets.AZURE_CREDENTIALS }}
client-id: ${{ secrets.CLIENT_ID }}
tenant-id: ${{ secrets.TENANT_ID }}
subscription-id: ${{ secrets.SUBSCRIPTION_ID }}

- name: 'Run Azure Functions Container Action'
uses: Azure/functions-container-action@v1.2.1
Expand Down
6 changes: 5 additions & 1 deletion .identity/00_data.tf
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,10 @@ data "github_organization_teams" "all" {
summary_only = true
}

data "azurerm_resource_group" "gpd_rg" {
name = "pagopa-${var.env_short}-weu-gps-gpd-rg"
}

data "azurerm_key_vault" "key_vault" {
name = "pagopa-${var.env_short}-kv"
resource_group_name = "pagopa-${var.env_short}-sec-rg"
Expand Down Expand Up @@ -45,4 +49,4 @@ data "azurerm_key_vault_secret" "key_vault_integration_test_subkey" {
data "azurerm_key_vault_secret" "flow_sa_connection_string" {
name = "flows-sa-${var.env_short}-connection-string"
key_vault_id = data.azurerm_key_vault.domain_key_vault.id
}
}
6 changes: 6 additions & 0 deletions .identity/02_application_action.tf
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,12 @@ resource "azurerm_role_assignment" "environment_terraform_resource_group_dashboa
principal_id = module.github_runner_app.object_id
}

resource "azurerm_role_assignment" "environment_function" {
scope = data.azurerm_resource_group.gpd_rg.id
role_definition_name = "Contributor"
principal_id = module.github_runner_app.object_id
}

resource "azurerm_role_assignment" "environment_key_vault" {
scope = data.azurerm_key_vault.key_vault.id
role_definition_name = "Reader"
Expand Down

0 comments on commit 99510b1

Please sign in to comment.