Skip to content

Commit 3a6e211

Browse files
authored
Merge pull request #5667 from nojnhuh/fic-audience
Add audience for FIC create
2 parents bfba927 + 774c524 commit 3a6e211

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

scripts/kind-with-registry.sh

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -191,13 +191,15 @@ EOF
191191
--identity-name "${USER_IDENTITY}" \
192192
-g "${AZWI_RESOURCE_GROUP}" \
193193
--issuer "${SERVICE_ACCOUNT_ISSUER}" \
194+
--audiences "api://AzureADTokenExchange" \
194195
--subject "system:serviceaccount:capz-system:capz-manager" --output none --only-show-errors
195196

196197
echo "Creating federated credentials for aso-federated-identity"
197198
az identity federated-credential create -n "aso-federated-identity" \
198199
--identity-name "${USER_IDENTITY}" \
199200
-g "${AZWI_RESOURCE_GROUP}" \
200201
--issuer "${SERVICE_ACCOUNT_ISSUER}" \
202+
--audiences "api://AzureADTokenExchange" \
201203
--subject "system:serviceaccount:capz-system:azureserviceoperator-default" --output none --only-show-errors
202204
fi
203205
}

0 commit comments

Comments
 (0)