-
Notifications
You must be signed in to change notification settings - Fork 80
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Added a crawler for creating an inventory of Azure Service Principals #326
Conversation
Codecov Report
@@ Coverage Diff @@
## main #326 +/- ##
==========================================
+ Coverage 83.48% 83.80% +0.32%
==========================================
Files 31 31
Lines 2555 2810 +255
Branches 448 532 +84
==========================================
+ Hits 2133 2355 +222
- Misses 319 332 +13
- Partials 103 123 +20
|
…ix/azure-SPNs-inventory # Conflicts: # src/databricks/labs/ucx/assessment/crawlers.py # tests/unit/assessment/test_assessment.py
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
yes, _list_all_cluster_with_spn_in_spark_conf
in AzureServicePrincipalCrawler
is a bit better. see other comments
|
GitGuardian id | Secret | Commit | Filename | |
---|---|---|---|---|
8289420 | Generic High Entropy Secret | 784c7f9 | tests/unit/assessment/test_assessment.py | View secret |
8289420 | Generic High Entropy Secret | 020f631 | tests/unit/assessment/test_assessment.py | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secrets safely. Learn here the best practices.
- Revoke and rotate these secrets.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
Our GitHub checks need improvements? Share your feedbacks!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
tiny comment
Added the following -
Did not do - List of all Azure SPNs from all the init scripts. Lets discuss about it. It makes sense to me to add a separate issue for the same and merge this one. |
# Version changelog ## 0.4.0 * Added exception handling for secret scope not found. ([#418](#418)). * Added a crawler for creating an inventory of Azure Service Principals ([#326](#326)). * Added check if account group already exists during failure recovery ([#446](#446)). * Added checking for index out of range. ([#429](#429)). * Added hyperlink to UCX releases in the main readme ([#408](#408)). * Added integration test to check backup groups get deleted ([#387](#387)). * Added logging of errors during threadpool operations. ([#376](#376)). * Added recovery mode for workspace-local groups from temporary groups ([#435](#435)). * Added support for migrating Legacy Table ACLs from workspace-local to account-level groups ([#412](#412)). * Added detection for installations of unreleased versions ([#399](#399)). * Decoupled `PermissionsManager` from `GroupMigrationToolkit` ([#407](#407)). * Enabled debug logging for every job task run through a file, which is accessible from both workspace UI and Databricks CLI ([#426](#426)). * Ensured that table exists, even when crawlers produce zero records ([#373](#373)). * Extended test suite for HMS->HMS TACL migration ([#439](#439)). * Fixed handling of secret scope responses ([#431](#431)). * Fixed `crawl_permissions` task to respect 'workspace_start_path' config ([#444](#444)). * Fixed broken logic in `parallel` module and applied hardened error handling design for parallel code ([#405](#405)). * Fixed codecov.io reporting ([#403](#403)). * Fixed integration tests for crawlers ([#379](#379)). * Improved README.py and logging messages ([#433](#433)). * Improved cleanup for workspace backup groups by adding more retries on errors ([#375](#375)). * Improved dashboard queries to show unsupported storage types. ([#398](#398)). * Improved documentation for readme notebook ([#257](#257)). * Improved test coverage for installer ([#371](#371)). * Introduced deterministic `env_or_skip` fixture for integration tests ([#396](#396)). * Made HMS & UC fixtures return `CatalogInfo`, `SchemaInfo`, and `TableInfo` ([#409](#409)). * Merge `workspace_access.Crawler` and `workspace_access.Applier` interfaces to `workspace_access.AclSupport` ([#436](#436)). * Moved examples to docs ([#404](#404)). * Properly isolated integration testing for workflows on an existing shared cluster ([#414](#414)). * Removed thread pool for any IAM Group removals and additions ([#394](#394)). * Replace plus char with minus in version tag for GCP dev installation of UCX ([#420](#420)). * Run integration tests on shared clusters for a faster devloop ([#397](#397)). * Show difference between serverless and PRO warehouses during installation ([#385](#385)). * Split `migrate-groups` workflow into three different stages for reliability ([#442](#442)). * Use groups instead of usernames in code owners file ([#389](#389)).
# Version changelog ## 0.4.0 * Added exception handling for secret scope not found. ([#418](#418)). * Added a crawler for creating an inventory of Azure Service Principals ([#326](#326)). * Added check if account group already exists during failure recovery ([#446](#446)). * Added checking for index out of range. ([#429](#429)). * Added hyperlink to UCX releases in the main readme ([#408](#408)). * Added integration test to check backup groups get deleted ([#387](#387)). * Added logging of errors during threadpool operations. ([#376](#376)). * Added recovery mode for workspace-local groups from temporary groups ([#435](#435)). * Added support for migrating Legacy Table ACLs from workspace-local to account-level groups ([#412](#412)). * Added detection for installations of unreleased versions ([#399](#399)). * Decoupled `PermissionsManager` from `GroupMigrationToolkit` ([#407](#407)). * Enabled debug logging for every job task run through a file, which is accessible from both workspace UI and Databricks CLI ([#426](#426)). * Ensured that table exists, even when crawlers produce zero records ([#373](#373)). * Extended test suite for HMS->HMS TACL migration ([#439](#439)). * Fixed handling of secret scope responses ([#431](#431)). * Fixed `crawl_permissions` task to respect 'workspace_start_path' config ([#444](#444)). * Fixed broken logic in `parallel` module and applied hardened error handling design for parallel code ([#405](#405)). * Fixed codecov.io reporting ([#403](#403)). * Fixed integration tests for crawlers ([#379](#379)). * Improved README.py and logging messages ([#433](#433)). * Improved cleanup for workspace backup groups by adding more retries on errors ([#375](#375)). * Improved dashboard queries to show unsupported storage types. ([#398](#398)). * Improved documentation for readme notebook ([#257](#257)). * Improved test coverage for installer ([#371](#371)). * Introduced deterministic `env_or_skip` fixture for integration tests ([#396](#396)). * Made HMS & UC fixtures return `CatalogInfo`, `SchemaInfo`, and `TableInfo` ([#409](#409)). * Merge `workspace_access.Crawler` and `workspace_access.Applier` interfaces to `workspace_access.AclSupport` ([#436](#436)). * Moved examples to docs ([#404](#404)). * Properly isolated integration testing for workflows on an existing shared cluster ([#414](#414)). * Removed thread pool for any IAM Group removals and additions ([#394](#394)). * Replace plus char with minus in version tag for GCP dev installation of UCX ([#420](#420)). * Run integration tests on shared clusters for a faster devloop ([#397](#397)). * Show difference between serverless and PRO warehouses during installation ([#385](#385)). * Split `migrate-groups` workflow into three different stages for reliability ([#442](#442)). * Use groups instead of usernames in code owners file ([#389](#389)).
No description provided.