Skip to content

Why are the Azure permissions needed for deployment and CI so high and what can we do about it? #1610

Discussion options

You must be logged in to vote

Hey @Farmerobot, Thanks for your feedback.

I want to ensure I’ve understood your query correctly. Below is based on my understanding.

Yes, we are currently using the same tenant for azd up and azd down, but this is strictly for testing the Bicep template. We ensure that the resources are destroyed immediately after the deployment is successfully verified.

Having a separate tenant for the CI pipeline is certainly an option, but we would like to understand the specific reason or concern behind this suggestion. Could you please elaborate?

Additionally, we can create custom roles with permissions tailored specifically to certain resource groups (RGs) to enhance security and limit access.

Coul…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@Farmerobot
Comment options

Answer selected by Farmerobot
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants