説明
ゲストユーザーにも、割り当てられたAzureロールの権限が適用されます。ユーザーやロールをGuestと名付けても、リソース権限は自動的には制限されません。
想定される影響
外部の協力者のアカウントに広い権限があると、悪用や侵害によって意図しないリソース変更が行われるおそれがあります。
対処方法
カスタムロールのactionsには必要な操作だけを指定し、割り当てスコープを絞ってください。not_actionsは別のロールが付与した権限を拒否しないため、すべての割り当てを確認してください。
例
以下はゲストのオブジェクトIDを明示し、すべての操作を許可する構成から、特定のリソースグループの情報参照だけに絞る例です。
変更前
hcl
resource "azurerm_role_definition" "example" {
name = "my-custom-role"
scope = data.azurerm_subscription.primary.id
description = "This is a custom role created via Terraform"
permissions {
actions = ["*"]
not_actions = []
}
assignable_scopes = [
data.azurerm_subscription.primary.id,
]
}
resource "azurerm_role_assignment" "example" {
name = "00000000-0000-0000-0000-000000000000"
scope = data.azurerm_subscription.primary.id
role_definition_id = azurerm_role_definition.example.role_definition_resource_id
principal_id = var.guest_object_id
}
変更後
hcl
resource "azurerm_role_definition" "example" {
name = "my-custom-role"
scope = data.azurerm_subscription.primary.id
description = "This is a custom role created via Terraform"
permissions {
actions = ["Microsoft.Resources/subscriptions/resourceGroups/read"]
not_actions = []
}
assignable_scopes = [
data.azurerm_subscription.primary.id,
]
}
resource "azurerm_role_assignment" "example" {
name = "00000000-0000-0000-0000-000000000000"
scope = var.resource_group_id
role_definition_id = azurerm_role_definition.example.role_definition_resource_id
principal_id = var.guest_object_id
}