Fix workload identity certificate validation #31
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There is an issue with the certificate creation for workload identity on AKS. Due to the way the validation works, we need an NSG rule to allow inbound port 80 on the cluster IP.
This has been added on the build and deploy action as an additional step. A NSG rule is created prior to the certificate deployment. Once the certificate has been created successfully, the NSG rule is removed. If the certificate isn't verified, the deployment fails.
Redundant NSG rules allowing ports 80,443 inbound to both the AKS and ACA subnets have been removed.