Altinn / altinn-platform

Altinn Platform infrastructure
6 stars 1 forks source link

Service principals for Altinn-Correspondence with federated credentials #760

Closed Ceredron closed 3 months ago

Ceredron commented 4 months ago

Description

Altinn-Correspondence will start deploying to Azure soon from their Github pipeline. They need service principals with federated credentials for their main branch to do this.

Additional Information

Ref: https://altinndevops.slack.com/archives/C06U42BEDJS/p1714031061392649 < How it was done for Altinn-Broker

https://github.com/Altinn/altinn-correspondence

Attached draft for credential file.

credential-main.json

Tasks

No response

Acceptance Criterias

No response

### Tasks
- [x] Create Azure subscriptions @herskis
- [x] Create management groups for broker/correspondence
- [x] Put subscription for broker/correspondence in management groups
- [x] Create user groups for correspondence
- [x] Add permission on Azure subs to user groups
- [x] Create app registration for github actions for github repo and give access to azure subscriptions
- [x] Set up github federated credentials for app registration
bengtfredh commented 4 months ago

This ticket includes to create and setup Azure Subscriptions for: altinn-correspondence-test altinn-correspondence-staging

Including SP with federated credentials with subject altinn-correspondence:main

bengtfredh commented 3 months ago

@Ceredron This issue is done.