설명
게스트 사용자도 할당된 Azure 역할의 권한을 받습니다. 사용자나 역할의 이름이 Guest라고 해서 실제 리소스 권한이 자동으로 제한되지는 않습니다.
잠재적 영향
외부 협업 계정에 넓은 권한을 부여하면 계정 오용이나 침해로 의도하지 않은 리소스 변경이 발생할 수 있습니다.
해결 방법
사용자 지정 역할에는 필요한 actions만 넣고 역할 할당 범위를 좁히세요. not_actions는 다른 역할에서 부여한 권한까지 차단하지 않으므로 전체 할당을 함께 확인하세요.
예시
게스트 개체 ID를 명시하고, 모든 작업 권한을 특정 리소스 그룹의 정보 조회 권한으로 줄이는 예시입니다.
변경 전
hcl
resource "azurerm_role_definition" "example" {
name = "my-custom-role"
scope = data.azurerm_subscription.primary.id
description = "This is a custom role created via Terraform"
permissions {
actions = ["*"]
not_actions = []
}
assignable_scopes = [
data.azurerm_subscription.primary.id,
]
}
resource "azurerm_role_assignment" "example" {
name = "00000000-0000-0000-0000-000000000000"
scope = data.azurerm_subscription.primary.id
role_definition_id = azurerm_role_definition.example.role_definition_resource_id
principal_id = var.guest_object_id
}
변경 후
hcl
resource "azurerm_role_definition" "example" {
name = "my-custom-role"
scope = data.azurerm_subscription.primary.id
description = "This is a custom role created via Terraform"
permissions {
actions = ["Microsoft.Resources/subscriptions/resourceGroups/read"]
not_actions = []
}
assignable_scopes = [
data.azurerm_subscription.primary.id,
]
}
resource "azurerm_role_assignment" "example" {
name = "00000000-0000-0000-0000-000000000000"
scope = var.resource_group_id
role_definition_id = azurerm_role_definition.example.role_definition_resource_id
principal_id = var.guest_object_id
}