Skip to content

Commit 2a8fa76

Browse files
authored
fix(azure): use built-in policy for redis (#521)
We used a custom access policy which is not required as Data Contributor meets our needs.
1 parent 3242233 commit 2a8fa76

File tree

2 files changed

+4
-22
lines changed

2 files changed

+4
-22
lines changed

.azure/applications/web-api-eu/main.bicep

+2-11
Original file line numberDiff line numberDiff line change
@@ -77,23 +77,14 @@ module containerApp '../../modules/containerApp/main.bicep' = {
7777
}
7878
}
7979

80-
resource redisCustomAccessPolicy 'Microsoft.Cache/redis/accessPolicies@2023-08-01' = {
80+
resource redisAccessPolicyAssignment 'Microsoft.Cache/redis/accessPolicyAssignments@2023-08-01' = {
8181
parent: redis
8282
name: containerAppName
8383
properties: {
84-
permissions: 'Contributor'
85-
}
86-
}
87-
88-
resource redisCustomAccessPolicyAssignment 'Microsoft.Cache/redis/accessPolicyAssignments@2023-08-01' = {
89-
parent: redis
90-
name: containerAppName
91-
properties: {
92-
accessPolicyName: containerAppName
84+
accessPolicyName: 'Data Contributor'
9385
objectId: containerApp.outputs.identityPrincipalId
9486
objectIdAlias: '${containerAppName}-access-policy-redis'
9587
}
96-
dependsOn: [redisCustomAccessPolicy]
9788
}
9889

9990
module keyVaultReaderAccessPolicy '../../modules/keyvault/addReaderRoles.bicep' = {

.azure/applications/web-api-so/main.bicep

+2-11
Original file line numberDiff line numberDiff line change
@@ -81,23 +81,14 @@ module containerApp '../../modules/containerApp/main.bicep' = {
8181
}
8282
}
8383

84-
resource redisCustomAccessPolicy 'Microsoft.Cache/redis/accessPolicies@2023-08-01' = {
84+
resource redisAccessPolicyAssignment 'Microsoft.Cache/redis/accessPolicyAssignments@2023-08-01' = {
8585
parent: redis
8686
name: containerAppName
8787
properties: {
88-
permissions: 'Contributor'
89-
}
90-
}
91-
92-
resource redisCustomAccessPolicyAssignment 'Microsoft.Cache/redis/accessPolicyAssignments@2023-08-01' = {
93-
parent: redis
94-
name: containerAppName
95-
properties: {
96-
accessPolicyName: containerAppName
88+
accessPolicyName: 'Data Contributor'
9789
objectId: containerApp.outputs.identityPrincipalId
9890
objectIdAlias: '${containerAppName}-access-policy-redis'
9991
}
100-
dependsOn: [redisCustomAccessPolicy]
10192
}
10293

10394
module keyVaultReaderAccessPolicy '../../modules/keyvault/addReaderRoles.bicep' = {

0 commit comments

Comments
 (0)