Skip to content

Commit 4d4983e

Browse files
committed
DTSPO-30178 - Grant new Jenkins MIs access to keyvault
1 parent ed5564c commit 4d4983e

1 file changed

Lines changed: 7 additions & 0 deletions

File tree

key-vault.tf

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@ module "vault" {
55
env = var.env
66
tenant_id = var.tenant_id
77
object_id = var.jenkins_AAD_objectId
8+
jenkins_object_id = data.azurerm_user_assigned_identity.jenkins.principal_id
89
resource_group_name = azurerm_resource_group.rg.name
910
product_group_name = "dcd_ccd"
1011

@@ -14,6 +15,12 @@ module "vault" {
1415
create_managed_identity = true
1516
}
1617

18+
data "azurerm_user_assigned_identity" "jenkins" {
19+
name = "jenkins-${var.env}-mi"
20+
resource_group_name = "managed-identities-${var.env}-rg"
21+
}
22+
23+
1724
data "azurerm_key_vault" "s2s_vault" {
1825
name = "s2s-${var.env}"
1926
resource_group_name = "rpe-service-auth-provider-${var.env}"

0 commit comments

Comments
 (0)